บทที่ 18 · Part 4 — Network Security
Network Security Foundations
TCP/UDP, DNS, routing/NAT, ports, TLS 1.2/1.3, certificate/service identity, 0-RTT replay และ packet/flow visibility
service อาจอยู่ใน private subnet และรับ traffic เฉพาะ port 443 แต่ request ยังมาจาก workload ที่ถูกยึด, DNS ถูกตั้งผิด หรือ client ปิด hostname verification การเข้าถึง network ได้และการใช้ TLS จึงยังไม่พิสูจน์ว่า peer มีสิทธิ์ทำ business action
Learning Outcomes
- อธิบาย packet, connection, port, TCP/UDP, routing และ NAT ได้
- แยก DNS resolution, network reachability, TLS peer identity และ application authorization ได้
- อธิบาย TLS handshake และ certificate/service identity validation ได้
- เลือก TLS version ตาม baseline ปัจจุบันและหลีกเลี่ยง 0-RTT กับ unsafe operation ได้
- แยก packet capture, flow log และ application telemetry พร้อม blind spots ได้
Network Layers ที่ Security ใช้งานจริง
| Layer/Concept | ตัวอย่าง | คำถาม Security |
|---|---|---|
| Link | Ethernet/Wi-Fi/VPC fabric | ใครอยู่ segment เดียวกันและ spoof/observe อะไรได้ |
| Network | IP/routing | source/destination/reachability ถูกกำหนดอย่างไร |
| Transport | TCP/UDP + ports | connection/flow/resource limit เป็นอย่างไร |
| Secure channel | TLS | peer identity, version, key/certificate lifecycle |
| Application | HTTP/gRPC/DNS | request meaning, auth, authorization, parsing |
layer ล่างไม่รู้ business resource Firewall ที่ allow TCP 443 ไม่รู้ว่า request เป็นการอ่าน statement หรืออนุมัติ payout
Packet, Flow และ Connection
- Packet — หน่วยข้อมูลระดับ network มี source/destination และ payload ตาม protocol
- Flow — การสรุป traffic ระหว่าง endpoints/protocol/ports ในช่วงเวลา
- TCP connection — bidirectional byte stream ที่มี handshake/state
- UDP datagram — message-oriented transport ไม่มี connection/reliability แบบ TCP
TCP รับประกัน ordered byte stream ระหว่าง endpoints แต่ไม่มี application message boundary, authentication หรือ exactly-once business semantics Parser ต้องรับ partial/coalesced bytes และตั้ง limits
UDP ไม่มี delivery/order/congestion semantics แบบเดียวกับ TCP Application protocol ต้องออกแบบ retry, amplification, spoofing และ state เองหรือใช้ protocol ที่ทำให้
Port ไม่ใช่ Identity
port ระบุ service endpoint convention ไม่พิสูจน์ process/peer:
- process อื่นอาจ bind port เมื่อ configuration ผิด
- proxy/load balancer terminate connection ก่อน service จริง
- attacker ใน allowed network เรียก port เดียวกันได้
- port forwarding/tunnel เปลี่ยน path
ใช้ network policy ลด reachability แล้วใช้ TLS/workload identity + application authorization บังคับ peer/action
Routing และ NAT
routing เลือก next hop ตาม destination/policy ส่วน NAT แปลง address/port
NAT ไม่ใช่ Security Boundary โดยตัวมันเอง
NAT มักขัดขวาง unsolicited inbound จาก state mapping แต่ไม่ได้ authenticate egress, จำกัด destination หรือป้องกัน compromised workload ต้องมี firewall/route/egress policy และ identity เพิ่ม
public/private subnet ถูกกำหนดจาก route/reachability ไม่ใช่ชื่อ tag และ private IP ไม่ได้แปลว่า trusted
DNS: Name → Endpoint
resolution path โดยย่อ:
DNS answer บอก address ที่ควรลองเชื่อมต่อ แต่ TLS client ยังต้อง verify service identity
ความเสี่ยง/controls:
- cache poisoning/incorrect resolver → protected resolver/DNSSEC validation ตาม architecture
- domain/subdomain takeover → ownership/inventory/decommission lifecycle
- stale TTL/failover → tested resolver/cache behavior
- rebinding → re-resolve/validate destination และ egress control สำหรับ URL fetcher
- data exfiltration → DNS logging/policy แต่มี encrypted/custom resolver blind spot
- sensitive query name → naming/minimization และ resolver trust
DNSSEC ช่วย authenticity/integrity ของ DNS data ใน validation chain ไม่เข้ารหัส query และไม่แทน TLS
TLS แยก Channel Security จาก Business Trust
TLS ให้ confidentiality/integrity ของ transport และ authenticate server เมื่อ client validate certificate ถูกต้อง mTLS เพิ่ม client certificate authentication แต่ application ยังต้อง map identity → permission
handshake สร้าง shared traffic keys และ authenticate transcript ตาม protocol TLS termination ที่ proxy หมายความว่า hop proxy→backend เป็น channel ใหม่ที่ต้อง threat model แยก
Certificate Validation ต้องครบ
client ต้องตรวจ:
- chain ไปยัง trust anchor ที่ policy ยอมรับ
- signature/key/algorithm ตาม baseline
- validity time และ revocation/status ตาม ecosystem policy
- service identity จาก Subject Alternative Name (SAN)
- reference identifier/hostname ที่ตั้งใจเชื่อมจริง
- Extended Key Usage/name constraints/policy ตาม PKI
RFC 9525 ไม่ให้ fallback ไป Common Name สำหรับ service identity และ wildcard ตรงได้เฉพาะ complete left-most label ตาม rule อย่าเขียน custom wildcard matcher
Trust-All ทำลาย Peer Authentication
การเปิด InsecureSkipVerify, accept-all certificate หรือ ignore hostname เพื่อให้ test ผ่าน
ทำให้ attacker ที่คั่น connection ใช้ certificate ใดก็ได้ ควรแก้ test CA, trust store, SAN หรือ lifecycle
TLS Version Baseline ปี 2026
- TLS 1.0/1.1 ถูก deprecated
- TLS 1.3 specification ปัจจุบันคือ RFC 9846 ซึ่ง obsoletes RFC 8446
- protocol ใหม่ควรใช้ TLS 1.3 เป็น default ตาม BCP ปัจจุบัน
- TLS 1.2 อาจเปิดแบบ non-default เพื่อ compatibility เมื่อ configuration/key exchange ตรง current BCP
- cipher/version policy ต้องอัปเดตจาก centralized baseline และ inventory ไม่ copy config เก่า
คำว่า “รองรับ TLS 1.3” ไม่พอถ้ายัง negotiate version/cipher อ่อน, validate identity ผิด หรือ endpoint อื่นยังเปิด plaintext
0-RTT และ Replay
TLS 1.3 early data (0-RTT) ลด latency สำหรับ resumed connection แต่ไม่มี inherent replay protection attacker อาจส่ง early data ซ้ำไปยัง server/instance อื่น
สำหรับ operation ที่ไม่ idempotent เช่น transfer, withdrawal, approval หรือสร้าง beneficiary:
- ปิด/reject 0-RTT โดย default
- หรือ protocol ต้องกำหนด operation safety, anti-replay และ idempotency/state controls ชัด
- อย่าถือว่า TLS ป้องกัน replay ของ application transaction
safe HTTP method label ก็ไม่แทน server-side invariant ถ้า endpoint implementation มี side effect
mTLS และ Workload Identity
mTLS เหมาะกับ service/partner boundary เมื่อมี:
- certificate issuance/identity naming ที่ชัด
- short lifetime/rotation และ revocation/compromise response
- trust bundle distribution
- proxy ส่ง verified identity โดย spoof header ไม่ได้
- authorization map จาก certificate identity ไป action/resource
- telemetry ของ certificate/key/use
certificate ที่ valid จาก CA เดียวกันไม่ควรกลายเป็น access ทุก service Namespace/SAN/policy ต้องจำกัด
Proxy และ Original Client Information
load balancer/proxy อาจส่ง Forwarded/X-Forwarded-* หรือ client certificate header
backend เชื่อได้เฉพาะเมื่อ:
- network รับ request จาก trusted proxy เท่านั้น
- proxy ล้าง header ที่ client ส่งมาแล้วสร้างใหม่
- application กำหนดจำนวน/ลำดับ trusted hops
- header ถูก integrity-protect ใน hop หลัง termination
- direct origin bypass ถูกปิด
client IP เป็น signal ที่เปลี่ยนจาก NAT/mobile/proxy ไม่ใช่ user identity
Network Failure Semantics
| Event | สิ่งที่ Application เห็นจริง |
|---|---|
| connect timeout | ไม่รู้ว่า endpoint reachable/route/firewall/load สูงจุดใด |
| read timeout | request อาจถึงและ side effect อาจเกิดแล้ว |
| connection reset | peer/proxy/network ปิด แต่ไม่บอก business outcome |
| DNS failure | name resolution unavailable/stale ไม่ใช่ proof ว่า service ล่ม |
| TLS alert | version/certificate/proof/policy failure ต้องแยก reason ภายใน |
retry ต้องผูก idempotency/status query/backoff และ deadline budget ไม่ retry ทุก error แบบเดียว
Packet Capture, Flow Log และ Application Log
| Source | เห็น | มองไม่เห็น/ข้อจำกัด |
|---|---|---|
| Packet capture | packet/header/payload ถ้าไม่ encrypted | traffic ที่ sensor ไม่อยู่, plaintext ใน TLS |
| Flow log | metadata endpoints/ports/bytes/action | application payload, บาง excluded/skipped record |
| TLS telemetry | version/cert/handshake outcome | business action/data ภายใน |
| Proxy/access log | HTTP metadata ตาม config | internal call/async state และอาจรั่ว sensitive field |
| Application audit | actor/action/resource/outcome | packet/network path ถ้าไม่มี correlation |
ไม่มีแหล่งเดียวพิสูจน์ว่า “ไม่มี attack” ต้องใช้ time sync, correlation ID, identity และ retention ร่วมกัน พร้อมควบคุมข้อมูลละเอียดใน capture/log
Testing Checklist
- diagram ระบุ DNS, route, proxy, TLS termination และ direct path
- network reachability ไม่ถูกใช้แทน peer identity/authorization
- TCP parser/timeout/size และ UDP replay/amplification ถูกพิจารณา
- DNS resolver/ownership/TTL/rebinding และ custom resolver blind spot มี owner
- TLS validate chain, SAN/service identity, time และ policy โดยไม่มี trust-all
- TLS 1.3 ใช้ current RFC/BCP; TLS 1.2 compatibility ถูกจำกัด
- 0-RTT ปิดหรือมี explicit safe operation/replay design
- mTLS identity map ไป authorization และ rotate/revoke ได้
- proxy ล้าง forwarded identity headers และ origin bypass ถูกปิด
- packet/flow/TLS/app telemetry มี correlation และรู้ข้อจำกัด
สรุป
Network Security ต้องแยก reachability, name resolution, secure channel, peer identity และ business authorization ออกจากกัน TLS ปกป้อง channel แต่ไม่บอกว่า request มีสิทธิ์หรือ fresh และ 0-RTT ต้องถูกปิดหรือออกแบบ replay safety สำหรับ operation ที่มีผลทางการเงิน