บทที่ 18 · Part 4 — Network Security

Network Security Foundations

TCP/UDP, DNS, routing/NAT, ports, TLS 1.2/1.3, certificate/service identity, 0-RTT replay และ packet/flow visibility

service อาจอยู่ใน private subnet และรับ traffic เฉพาะ port 443 แต่ request ยังมาจาก workload ที่ถูกยึด, DNS ถูกตั้งผิด หรือ client ปิด hostname verification การเข้าถึง network ได้และการใช้ TLS จึงยังไม่พิสูจน์ว่า peer มีสิทธิ์ทำ business action

Learning Outcomes

  • อธิบาย packet, connection, port, TCP/UDP, routing และ NAT ได้
  • แยก DNS resolution, network reachability, TLS peer identity และ application authorization ได้
  • อธิบาย TLS handshake และ certificate/service identity validation ได้
  • เลือก TLS version ตาม baseline ปัจจุบันและหลีกเลี่ยง 0-RTT กับ unsafe operation ได้
  • แยก packet capture, flow log และ application telemetry พร้อม blind spots ได้

Network Layers ที่ Security ใช้งานจริง

Layer/Conceptตัวอย่างคำถาม Security
LinkEthernet/Wi-Fi/VPC fabricใครอยู่ segment เดียวกันและ spoof/observe อะไรได้
NetworkIP/routingsource/destination/reachability ถูกกำหนดอย่างไร
TransportTCP/UDP + portsconnection/flow/resource limit เป็นอย่างไร
Secure channelTLSpeer identity, version, key/certificate lifecycle
ApplicationHTTP/gRPC/DNSrequest meaning, auth, authorization, parsing

layer ล่างไม่รู้ business resource Firewall ที่ allow TCP 443 ไม่รู้ว่า request เป็นการอ่าน statement หรืออนุมัติ payout

Packet, Flow และ Connection

  • Packet — หน่วยข้อมูลระดับ network มี source/destination และ payload ตาม protocol
  • Flow — การสรุป traffic ระหว่าง endpoints/protocol/ports ในช่วงเวลา
  • TCP connection — bidirectional byte stream ที่มี handshake/state
  • UDP datagram — message-oriented transport ไม่มี connection/reliability แบบ TCP

TCP รับประกัน ordered byte stream ระหว่าง endpoints แต่ไม่มี application message boundary, authentication หรือ exactly-once business semantics Parser ต้องรับ partial/coalesced bytes และตั้ง limits

UDP ไม่มี delivery/order/congestion semantics แบบเดียวกับ TCP Application protocol ต้องออกแบบ retry, amplification, spoofing และ state เองหรือใช้ protocol ที่ทำให้

Port ไม่ใช่ Identity

port ระบุ service endpoint convention ไม่พิสูจน์ process/peer:

  • process อื่นอาจ bind port เมื่อ configuration ผิด
  • proxy/load balancer terminate connection ก่อน service จริง
  • attacker ใน allowed network เรียก port เดียวกันได้
  • port forwarding/tunnel เปลี่ยน path

ใช้ network policy ลด reachability แล้วใช้ TLS/workload identity + application authorization บังคับ peer/action

Routing และ NAT

routing เลือก next hop ตาม destination/policy ส่วน NAT แปลง address/port

NAT ไม่ใช่ Security Boundary โดยตัวมันเอง

NAT มักขัดขวาง unsolicited inbound จาก state mapping แต่ไม่ได้ authenticate egress, จำกัด destination หรือป้องกัน compromised workload ต้องมี firewall/route/egress policy และ identity เพิ่ม

public/private subnet ถูกกำหนดจาก route/reachability ไม่ใช่ชื่อ tag และ private IP ไม่ได้แปลว่า trusted

DNS: Name → Endpoint

resolution path โดยย่อ:

DNS answer บอก address ที่ควรลองเชื่อมต่อ แต่ TLS client ยังต้อง verify service identity

ความเสี่ยง/controls:

  • cache poisoning/incorrect resolver → protected resolver/DNSSEC validation ตาม architecture
  • domain/subdomain takeover → ownership/inventory/decommission lifecycle
  • stale TTL/failover → tested resolver/cache behavior
  • rebinding → re-resolve/validate destination และ egress control สำหรับ URL fetcher
  • data exfiltration → DNS logging/policy แต่มี encrypted/custom resolver blind spot
  • sensitive query name → naming/minimization และ resolver trust

DNSSEC ช่วย authenticity/integrity ของ DNS data ใน validation chain ไม่เข้ารหัส query และไม่แทน TLS

TLS แยก Channel Security จาก Business Trust

TLS ให้ confidentiality/integrity ของ transport และ authenticate server เมื่อ client validate certificate ถูกต้อง mTLS เพิ่ม client certificate authentication แต่ application ยังต้อง map identity → permission

handshake สร้าง shared traffic keys และ authenticate transcript ตาม protocol TLS termination ที่ proxy หมายความว่า hop proxy→backend เป็น channel ใหม่ที่ต้อง threat model แยก

Certificate Validation ต้องครบ

client ต้องตรวจ:

  • chain ไปยัง trust anchor ที่ policy ยอมรับ
  • signature/key/algorithm ตาม baseline
  • validity time และ revocation/status ตาม ecosystem policy
  • service identity จาก Subject Alternative Name (SAN)
  • reference identifier/hostname ที่ตั้งใจเชื่อมจริง
  • Extended Key Usage/name constraints/policy ตาม PKI

RFC 9525 ไม่ให้ fallback ไป Common Name สำหรับ service identity และ wildcard ตรงได้เฉพาะ complete left-most label ตาม rule อย่าเขียน custom wildcard matcher

Trust-All ทำลาย Peer Authentication

การเปิด InsecureSkipVerify, accept-all certificate หรือ ignore hostname เพื่อให้ test ผ่าน ทำให้ attacker ที่คั่น connection ใช้ certificate ใดก็ได้ ควรแก้ test CA, trust store, SAN หรือ lifecycle

TLS Version Baseline ปี 2026

  • TLS 1.0/1.1 ถูก deprecated
  • TLS 1.3 specification ปัจจุบันคือ RFC 9846 ซึ่ง obsoletes RFC 8446
  • protocol ใหม่ควรใช้ TLS 1.3 เป็น default ตาม BCP ปัจจุบัน
  • TLS 1.2 อาจเปิดแบบ non-default เพื่อ compatibility เมื่อ configuration/key exchange ตรง current BCP
  • cipher/version policy ต้องอัปเดตจาก centralized baseline และ inventory ไม่ copy config เก่า

คำว่า “รองรับ TLS 1.3” ไม่พอถ้ายัง negotiate version/cipher อ่อน, validate identity ผิด หรือ endpoint อื่นยังเปิด plaintext

0-RTT และ Replay

TLS 1.3 early data (0-RTT) ลด latency สำหรับ resumed connection แต่ไม่มี inherent replay protection attacker อาจส่ง early data ซ้ำไปยัง server/instance อื่น

สำหรับ operation ที่ไม่ idempotent เช่น transfer, withdrawal, approval หรือสร้าง beneficiary:

  • ปิด/reject 0-RTT โดย default
  • หรือ protocol ต้องกำหนด operation safety, anti-replay และ idempotency/state controls ชัด
  • อย่าถือว่า TLS ป้องกัน replay ของ application transaction

safe HTTP method label ก็ไม่แทน server-side invariant ถ้า endpoint implementation มี side effect

mTLS และ Workload Identity

mTLS เหมาะกับ service/partner boundary เมื่อมี:

  • certificate issuance/identity naming ที่ชัด
  • short lifetime/rotation และ revocation/compromise response
  • trust bundle distribution
  • proxy ส่ง verified identity โดย spoof header ไม่ได้
  • authorization map จาก certificate identity ไป action/resource
  • telemetry ของ certificate/key/use

certificate ที่ valid จาก CA เดียวกันไม่ควรกลายเป็น access ทุก service Namespace/SAN/policy ต้องจำกัด

Proxy และ Original Client Information

load balancer/proxy อาจส่ง Forwarded/X-Forwarded-* หรือ client certificate header backend เชื่อได้เฉพาะเมื่อ:

  • network รับ request จาก trusted proxy เท่านั้น
  • proxy ล้าง header ที่ client ส่งมาแล้วสร้างใหม่
  • application กำหนดจำนวน/ลำดับ trusted hops
  • header ถูก integrity-protect ใน hop หลัง termination
  • direct origin bypass ถูกปิด

client IP เป็น signal ที่เปลี่ยนจาก NAT/mobile/proxy ไม่ใช่ user identity

Network Failure Semantics

Eventสิ่งที่ Application เห็นจริง
connect timeoutไม่รู้ว่า endpoint reachable/route/firewall/load สูงจุดใด
read timeoutrequest อาจถึงและ side effect อาจเกิดแล้ว
connection resetpeer/proxy/network ปิด แต่ไม่บอก business outcome
DNS failurename resolution unavailable/stale ไม่ใช่ proof ว่า service ล่ม
TLS alertversion/certificate/proof/policy failure ต้องแยก reason ภายใน

retry ต้องผูก idempotency/status query/backoff และ deadline budget ไม่ retry ทุก error แบบเดียว

Packet Capture, Flow Log และ Application Log

Sourceเห็นมองไม่เห็น/ข้อจำกัด
Packet capturepacket/header/payload ถ้าไม่ encryptedtraffic ที่ sensor ไม่อยู่, plaintext ใน TLS
Flow logmetadata endpoints/ports/bytes/actionapplication payload, บาง excluded/skipped record
TLS telemetryversion/cert/handshake outcomebusiness action/data ภายใน
Proxy/access logHTTP metadata ตาม configinternal call/async state และอาจรั่ว sensitive field
Application auditactor/action/resource/outcomepacket/network path ถ้าไม่มี correlation

ไม่มีแหล่งเดียวพิสูจน์ว่า “ไม่มี attack” ต้องใช้ time sync, correlation ID, identity และ retention ร่วมกัน พร้อมควบคุมข้อมูลละเอียดใน capture/log

Testing Checklist

  • diagram ระบุ DNS, route, proxy, TLS termination และ direct path
  • network reachability ไม่ถูกใช้แทน peer identity/authorization
  • TCP parser/timeout/size และ UDP replay/amplification ถูกพิจารณา
  • DNS resolver/ownership/TTL/rebinding และ custom resolver blind spot มี owner
  • TLS validate chain, SAN/service identity, time และ policy โดยไม่มี trust-all
  • TLS 1.3 ใช้ current RFC/BCP; TLS 1.2 compatibility ถูกจำกัด
  • 0-RTT ปิดหรือมี explicit safe operation/replay design
  • mTLS identity map ไป authorization และ rotate/revoke ได้
  • proxy ล้าง forwarded identity headers และ origin bypass ถูกปิด
  • packet/flow/TLS/app telemetry มี correlation และรู้ข้อจำกัด

สรุป

Network Security ต้องแยก reachability, name resolution, secure channel, peer identity และ business authorization ออกจากกัน TLS ปกป้อง channel แต่ไม่บอกว่า request มีสิทธิ์หรือ fresh และ 0-RTT ต้องถูกปิดหรือออกแบบ replay safety สำหรับ operation ที่มีผลทางการเงิน

Further Reading