CISSP Domain 4: Communication and Network Security
Domain 4 ว่าด้วยการออกแบบและป้องกันเส้นทางที่ข้อมูล ระบบ และผู้ใช้สื่อสารกัน ตั้งแต่สายสัญญาณ frame, packet และ session ไปจนถึง Virtual Private Network (VPN), wireless, Software-Defined Networking (SDN) และ cloud networking เป้าหมายไม่ใช่เพียงทำให้ packet ไปถึงปลายทาง แต่ต้องทำให้การสื่อสารสอดคล้องกับ classification, business requirement, trust boundary และ risk decision ขององค์กร
หลักคิดสำหรับข้อสอบ: เริ่มจาก data flow และ security requirement ก่อนเลือก protocol หรืออุปกรณ์ ใช้ segmentation จำกัด blast radius, ใช้ secure protocol ปกป้องข้อมูลระหว่างทาง และอย่าถือว่า network location เพียงอย่างเดียวทำให้ subject น่าเชื่อถือ
1. ภาพรวม Domain และน้ำหนักข้อสอบ
หัวข้อที่มีชื่อว่า “1. ภาพรวม Domain และน้ำหนักข้อสอบ”ตาม CISSP Certification Exam Outline ของ ISC2 Domain 4 มีน้ำหนักเฉลี่ย 13% ของข้อสอบ เนื้อหาหลักแบ่งได้เป็นสามกลุ่ม ได้แก่ การใช้ secure design principles กับ network architecture, การรักษาความปลอดภัยของ network components และการนำ secure communication channel ไปใช้ตาม design
คำว่า “น้ำหนักเฉลี่ย” ใช้สำหรับวางแผนอ่าน ไม่รับประกันจำนวนข้อของผู้สอบแต่ละคน ข้อสอบมักไม่ถามเพียงว่า protocol ทำงานที่ port ใด แต่ให้สถานการณ์ที่ต้องแยก requirement ออกจาก implementation เช่น ต้องปกป้อง data in transit ระหว่างสอง site, จำกัด lateral movement หลัง endpoint ถูกยึด หรือทำให้ remote administrator เข้าถึง management plane อย่างตรวจสอบย้อนหลังได้
ความสามารถสำคัญของ Domain นี้ประกอบด้วย
- อ่าน network เป็นชั้นและเป็น flow ใช้ Open Systems Interconnection (OSI) และ TCP/IP models เพื่อระบุตำแหน่งของ protocol, control, encapsulation และ failure
- ออกแบบ boundary และ segmentation แยก zone ตาม sensitivity, function และ trust requirement โดยมี policy ควบคุม traffic ระหว่าง zone
- เลือก preventive และ detective controls เข้าใจ firewall, proxy, Network Access Control (NAC), Intrusion Detection System (IDS), Intrusion Prevention System (IPS) และ telemetry โดยไม่คาดหวังว่า control เดียวจะหยุดทุก threat
- สร้าง secure communication channel เลือก Internet Protocol Security (IPsec), Transport Layer Security (TLS), Secure Shell (SSH) หรือกลไกอื่นให้ตรง use case พร้อม authentication, key establishment และ certificate validation
- รักษา modern network ประเมิน wireless, SDN, virtual network, cloud, container, hybrid connection และ third-party connectivity ภายใต้ shared responsibility
Domain 4 รับ classification และ handling requirement จาก Domain 2 และรับ trust boundary, cryptographic service, resilience requirement จาก Domain 3 Network architect เลือก topology, protocol และ control ส่วน Data owner, System owner และ Risk owner ยังคงกำหนด requirement และยอมรับ residual risk ตาม authority ของตน
2. แนวคิดหลักพร้อมคำอธิบาย
หัวข้อที่มีชื่อว่า “2. แนวคิดหลักพร้อมคำอธิบาย”2.1 Network security เริ่มจาก data flow ไม่ใช่รายการอุปกรณ์
หัวข้อที่มีชื่อว่า “2.1 Network security เริ่มจาก data flow ไม่ใช่รายการอุปกรณ์”Data flow อธิบายว่า data ชนิดใดเคลื่อนจาก source ใด ไป destination ใด ผ่าน protocol, interface, intermediary และ trust boundary อะไรบ้าง การวาดเพียง server กับ firewall แต่ไม่แสดง identity, direction, port, dependency, management path และ data classification ทำให้ประเมิน risk ได้ไม่ครบ
แต่ละ flow ควรตอบคำถามอย่างน้อยว่าใครเริ่ม connection, ใคร authenticate ใคร, ต้องรักษา Confidentiality หรือ Integrity ระดับใด, ยอมให้ latency และ outage เท่าใด, log ที่จุดใด และใครอนุมัติ flow นั้น ตัวอย่างเช่น “application ติดต่อ database” ยังไม่พอ ต้องรู้ว่าใช้ service identity ใด ผ่าน TLS หรือไม่ จำกัดเฉพาะ query service หรือเปิด administrative interface และมีเส้นทาง bypass หรือไม่
2.2 Layering ช่วยวิเคราะห์ แต่ attacker ไม่เคารพขอบเขตของ model
หัวข้อที่มีชื่อว่า “2.2 Layering ช่วยวิเคราะห์ แต่ attacker ไม่เคารพขอบเขตของ model”OSI และ TCP/IP เป็น conceptual models ช่วยจัดระเบียบหน้าที่ของ protocol และหาจุดวาง control ปัญหาหนึ่งอาจเกิดและถูกสังเกตได้หลายชั้น เช่น Distributed Denial-of-Service (DDoS) อาจทำให้ link เต็มที่ lower layer, ใช้ TCP state จน firewall หมดทรัพยากร หรือส่ง HTTP request ที่แพงต่อ application
Encapsulation คือการที่ชั้นหนึ่งห่อข้อมูลจากชั้นบนด้วย header หรือ trailer ของตน เมื่อใช้ tunnel จะเกิด packet ซ้อน packet เพิ่มอีกชั้น การวิเคราะห์เฉพาะ outer header อาจมองไม่เห็น payload ด้านใน ขณะที่การถอด TLS เพื่อ inspection เพิ่ม privacy, key custody, capacity และ legal considerations แนวคิดนี้เรียกว่า multilayer protocol implications: control ที่เห็นเพียงชั้นหนึ่งอาจตัดสินใจผิดเมื่อข้อมูลสำคัญอยู่คนละชั้น
2.3 Segmentation ลด blast radius แต่ต้องมี enforcement
หัวข้อที่มีชื่อว่า “2.3 Segmentation ลด blast radius แต่ต้องมี enforcement”Network segmentation แบ่ง network ออกเป็นส่วนตาม business function, sensitivity, environment หรือ trust requirement เป้าหมายคือจำกัด reachability, ลด lateral movement และทำให้ policy ตรวจสอบได้ การแบ่ง subnet หรือ Virtual Local Area Network (VLAN) อย่างเดียวไม่ใช่ security boundary หาก routing ระหว่าง segment เปิดกว้าง
Boundary ต้องมี enforcement เช่น firewall, router Access Control List (ACL), security group, host firewall, service mesh policy หรือ gateway พร้อม default-deny ตามความเหมาะสม Microsegmentation เพิ่ม policy ที่ละเอียดถึง workload, application หรือ identity และเหมาะกับ east-west traffic ที่ perimeter firewall มองไม่เห็น แต่ความละเอียดสูงทำให้ dependency mapping และ policy lifecycle ยากขึ้น
2.4 Trust ต้องสร้างจากหลายสัญญาณและตรวจซ้ำ
หัวข้อที่มีชื่อว่า “2.4 Trust ต้องสร้างจากหลายสัญญาณและตรวจซ้ำ”แนวคิด Zero Trust Architecture (ZTA) ไม่ให้ implicit trust เพียงเพราะ request มาจาก “เครือข่ายภายใน” การตัดสินใจควรพิจารณา identity, device state, requested resource, context, risk และ policy พร้อมบันทึก telemetry หลักนี้ไม่แปลว่าไม่เชื่อใครเลย และไม่ใช่ผลิตภัณฑ์ชนิดหนึ่ง
Network location ยังใช้เป็น risk signal และจุด enforcement ได้ แต่ไม่ควรเป็นหลักฐานเดียวว่า request ได้รับอนุญาต ตัวอย่างเช่น administrator ที่อยู่ใน corporate LAN ยังต้องใช้ Multi-Factor Authentication (MFA), privileged device, approved management path และ session logging
2.5 Prevention, detection และ response ต้องออกแบบร่วมกัน
หัวข้อที่มีชื่อว่า “2.5 Prevention, detection และ response ต้องออกแบบร่วมกัน”Firewall ลด traffic ที่ไม่อนุญาต แต่ไม่ยืนยันว่า traffic ที่อนุญาตไม่มี exploit IDS อาจตรวจพบ pattern ที่น่าสงสัยแต่ไม่หยุด packet IPS อาจ block ได้แต่เสี่ยง false positive กระทบ Availability ส่วน encryption ปกป้อง payload จากผู้ดักฟัง แต่ทำให้ passive sensor มองเห็นเนื้อหาน้อยลง
จึงต้องออกแบบ control เป็นระบบ: ลด attack surface, authenticate peer, encrypt channel, filter flow, ตรวจ anomaly, เก็บ log, correlate event และมี response playbook หลักฐานจาก firewall, DNS, proxy, endpoint และ cloud flow logs ต้องมีเวลาอ้างอิงที่สอดคล้องกัน มิฉะนั้นการสืบเหตุจะต่อ timeline ได้ยาก
2.6 Availability เป็นคุณสมบัติของเส้นทางทั้งหมด
หัวข้อที่มีชื่อว่า “2.6 Availability เป็นคุณสมบัติของเส้นทางทั้งหมด”Network resilience ไม่ได้เกิดจากมี link สำรองเพียงเส้นเดียว ต้องพิจารณา power, device, route, DNS, certificate, identity provider, cloud gateway, carrier และ configuration plane ที่อาจเป็น shared dependency Redundancy ที่อยู่ใน failure domain เดียวกัน เช่น circuit สองเส้นผ่านท่อเดียวกัน อาจล้มพร้อมกัน
High availability ต้องกำหนด failure mode, failover trigger, state synchronization, capacity และการทดสอบ หาก firewall pair สลับเครื่องได้แต่ session state หาย application อาจยังหยุดชะงัก Load balancer ช่วยกระจาย connection และ health check backend แต่ไม่แทน capacity planning, DDoS protection หรือ application resilience
3. เจาะลึกหัวข้อย่อยพร้อมตัวอย่าง
หัวข้อที่มีชื่อว่า “3. เจาะลึกหัวข้อย่อยพร้อมตัวอย่าง”3.1 OSI และ TCP/IP models
หัวข้อที่มีชื่อว่า “3.1 OSI และ TCP/IP models”OSI model มีเจ็ดชั้น ส่วน TCP/IP model ที่ใช้งานทั่วไปมักสรุปเป็นสี่ชั้น การจับคู่เป็นการประมาณเพื่อช่วยคิด ไม่ใช่ความสัมพันธ์แบบหนึ่งต่อหนึ่งที่ทุกตำราใช้เหมือนกัน
| OSI layer | หน้าที่และตัวอย่าง | TCP/IP โดยประมาณ | Security concern และ control ตัวอย่าง |
|---|---|---|---|
| 7 Application | HTTP, DNS, SMTP, SSH, API semantics | Application | authentication, input validation, WAF, secure protocol, application log |
| 6 Presentation | encoding, serialization, compression, encryption representation | Application | unsafe parser, downgrade, certificate/cryptographic configuration |
| 5 Session | สร้าง รักษา และยุติ dialogue/session | Application | session hijacking, replay, timeout, reauthentication |
| 4 Transport | TCP/UDP, port, reliability, flow control | Transport | port filtering, SYN flood, state exhaustion, TLS above transport |
| 3 Network | IPv4/IPv6, routing, ICMP, logical addressing | Internet | spoofing, route manipulation, ACL, IPsec, anti-spoofing |
| 2 Data Link | Ethernet frame, MAC, VLAN, switching, Wi-Fi framing | Link/Network access | ARP spoofing, VLAN hopping, port security, 802.1X |
| 1 Physical | copper, fiber, radio, connector, signal | Link/Network access | tapping, jamming, cable cut, locked facility, diverse path |
ตัวอย่างการแก้ปัญหา: ผู้ใช้ resolve ชื่อได้และ ping server ได้ แต่ HTTPS ใช้ไม่ได้ แสดงว่า lower layers บางส่วนทำงานแล้ว ควรตรวจ TCP connection, TLS handshake, certificate, proxy และ application ต่อ ไม่ควรสรุปว่า “network ปกติ” เพียงเพราะ ICMP ตอบ
TCP, UDP และ connection behavior
หัวข้อที่มีชื่อว่า “TCP, UDP และ connection behavior”Transmission Control Protocol (TCP) เป็น connection-oriented transport มี sequence, acknowledgement, retransmission และ flow control การเริ่ม connection ปกติใช้ three-way handshake: SYN, SYN-ACK, ACK คุณสมบัตินี้ช่วยส่งข้อมูลเชื่อถือได้ แต่สร้าง state ที่ถูกใช้โจมตีแบบ SYN flood หรือ state exhaustion ได้
User Datagram Protocol (UDP) เป็น connectionless และไม่มี reliability, ordering หรือ congestion behavior แบบ TCP ในตัว จึงมี overhead ต่ำและเหมาะกับ use case เช่น DNS query, streaming หรือ real-time traffic บางแบบ แต่ application ต้องจัดการ reliability และ security ที่ต้องการเอง UDP ไม่ได้ “ไม่ปลอดภัย” โดยธรรมชาติ และ TCP ไม่ได้ “ปลอดภัย” เพียงเพราะมี handshake
Port ระบุ service endpoint เชิงตรรกะ ไม่ใช่หลักฐานว่า application เป็น service ตามชื่อที่คาด Malware ใช้ TCP 443 ได้ และ HTTPS อาจอยู่ port อื่น Firewall ที่อนุญาตจาก port number อย่างเดียวจึงต้องทำงานร่วมกับ application awareness, identity และ monitoring ตาม risk
3.2 IPv4, IPv6, switching และ routing
หัวข้อที่มีชื่อว่า “3.2 IPv4, IPv6, switching และ routing”IPv4 ใช้ address 32 bits ส่วน IPv6 ใช้ 128 bits IPv4 มี unicast, broadcast และ multicast; IPv6 ไม่มี broadcast และใช้ multicast รวมถึง anycast Anycast ให้หลาย node ประกาศ address เดียวกัน แล้ว routing เลือก instance ตามเส้นทาง
Network Address Translation (NAT) แปลง address และบางกรณีแปลง port เพื่อประหยัด IPv4 address หรือเชื่อม address domains NAT ไม่ใช่ security control ทดแทน firewall แม้การแปล address อาจทำให้ inbound connection บางแบบเข้าถึงไม่ได้โดยค่าเริ่มต้น IPv6 ทำให้ต้องทบทวน policy, asset inventory, Neighbor Discovery, router advertisement และ monitoring แทนการพึ่ง NAT เป็นสมมติฐานการป้องกัน
ที่ Layer 2 switch ส่ง frame ตาม MAC address และแบ่ง broadcast domain ด้วย VLAN ที่ Layer 3 router ส่ง packet ระหว่าง network ตาม routing table การกำหนด VLAN ต้องป้องกัน trunk ที่ไม่จำเป็น, unused port, native VLAN confusion และ management interface แต่ VLAN ไม่ใช่ cryptographic isolation และ configuration ผิดอาจเปิดทาง VLAN hopping
Address Resolution Protocol (ARP) จับคู่ IPv4 address กับ MAC address ใน local segment และไม่มี authentication โดยกำเนิด จึงเกิด ARP spoofing ได้ IPv6 ใช้ Neighbor Discovery Protocol (NDP) ซึ่งมี threat ของตน Control ใช้ switch features, segmentation และ monitoring ตาม platform Routing protocol ต้องป้องกัน route injection/hijacking ด้วย peer authentication เมื่อรองรับ, route filtering, change control และ monitoring
Data, control และ management planes
หัวข้อที่มีชื่อว่า “Data, control และ management planes”- Data plane หรือ forwarding plane ส่ง traffic ของผู้ใช้ตาม forwarding decision
- Control plane เรียนรู้ topology และสร้าง decision เช่น route หรือ forwarding state
- Management plane ใช้ configure, monitor และ administer อุปกรณ์
ทั้งสาม plane ต้องแยก policy และลด reachability โดยเฉพาะ management plane ควรใช้ dedicated management network หรือ out-of-band path เมื่อ requirement เหมาะสม พร้อม strong authentication, encrypted administration, role-based access, logging และ break-glass process หาก attacker ควบคุม management plane ได้ เขาอาจเปลี่ยน policy ทั้งระบบแม้ data-plane filtering เดิมถูกต้อง
ภาพนี้แสดงว่าแต่ละ plane มีหน้าที่ต่างกัน แต่การเปลี่ยนผ่าน management plane สามารถส่งผลต่อ decision และการ forward traffic ได้:
3.3 Protocols และ secure alternatives
หัวข้อที่มีชื่อว่า “3.3 Protocols และ secure alternatives”การเลือกว่า protocol “secure” ต้องดูมากกว่ามี encryption Channel ที่ดีควรให้ peer authentication, Confidentiality, Integrity, replay protection และ key establishment ตาม use case พร้อม algorithm และ certificate validation ที่องค์กรอนุมัติ
| Use case | ทางเลือกที่ควรหลีกเลี่ยงสำหรับข้อมูลสำคัญ | ทางเลือกที่ปลอดภัยกว่า | ประเด็นตรวจสอบ |
|---|---|---|---|
| Remote shell/admin | Telnet, rlogin | SSH | host key validation, MFA, key lifecycle, command/session logging |
| Web/API | HTTP | HTTPS ด้วย TLS | hostname, trust chain, version/cipher policy, mutual TLS เมื่อจำเป็น |
| File transfer | FTP, TFTP | SFTP, SCP หรือ FTPS ตาม requirement | อย่าสับสน SFTP กับ FTPS; จำกัด path และ account |
| E-mail access/relay | plaintext POP3/IMAP/SMTP | TLS-protected channel ตาม role | STARTTLS downgrade risk, server authentication, mail-layer protection |
| Network management | SNMPv1/v2c community string | SNMPv3 security features | authentication, privacy, least privilege, trap destination |
| Name resolution | DNS ปกติ | DNSSEC สำหรับ origin authenticity/integrity; encrypted DNS สำหรับ channel privacy | สองกลไกแก้คนละปัญหา |
| Time synchronization | unauthenticated time | authenticated/protected time source ตาม platform | hierarchy, trusted source, monitoring, effect ต่อ log/certificate |
TLS ทำงานเหนือ reliable transport ใน use case ทั่วไปและใช้ certificate หรือกลไกอื่น authenticate peer ตาม configuration การมีรูปกุญแจไม่ได้รับประกันว่า peer ถูกต้องหาก client ไม่ตรวจ hostname, chain หรือ trust anchor Mutual TLS (mTLS) ให้ทั้งสองฝั่งแสดง certificate แต่ authorization ยังต้องตัดสินว่าตัวตนนั้นเข้าถึง resource ใดได้
SSH ให้ encrypted channel สำหรับ remote administration, tunneling และ file transfer บางรูปแบบ จุดสำคัญคือ validate host key, ป้องกัน private key, จำกัด forwarding และไม่ใช้ shared administrator account หากผู้ใช้กดยอมรับ host key ที่เปลี่ยนโดยไม่ตรวจสอบ ก็อาจเปิดทาง Man-in-the-Middle (MITM)
DNSSEC ให้การตรวจ authenticity และ integrity ของ DNS data ผ่าน chain of trust ไม่ได้เข้ารหัสชื่อที่ query และไม่ได้รับประกันว่า destination ปลอดภัย ส่วน DNS over TLS (DoT) หรือ DNS over HTTPS (DoH) ปกป้อง channel ระหว่าง client กับ resolver แต่ไม่ได้แทน DNSSEC องค์กรต้องกำหนด resolver policy เพื่อไม่ให้ encrypted DNS กลายเป็นทาง bypass monitoring โดยไม่ได้ตั้งใจ
Dynamic Host Configuration Protocol (DHCP) แจก network configuration ให้ client แต่ server ปลอมอาจให้ gateway หรือ DNS ที่เป็นอันตราย Control เช่น authorized server, switch inspection feature และ NAC ช่วยลด risk ขณะที่ static address อย่างเดียวไม่ยืนยัน identity ของ device
3.4 Network architecture, topology และ segmentation
หัวข้อที่มีชื่อว่า “3.4 Network architecture, topology และ segmentation”Topology เชิงกายภาพบอกการเชื่อมสายและ device ส่วน logical topology บอก flow และ adjacency ที่ protocol เห็น แบบ star ดูแลง่ายแต่ central device อาจเป็น single point of failure ส่วน mesh มีหลายเส้นทางแต่ซับซ้อนกว่า
การแบ่ง network อาจใช้หลายระดับ
- Physical segmentation ใช้อุปกรณ์หรือสื่อแยก เหมาะกับ requirement ที่ต้องการ isolation สูง แต่ยังมี shared facility, power หรือ administration ได้
- Logical segmentation ใช้ VLAN, subnet, Virtual Routing and Forwarding (VRF), overlay หรือ virtual network พร้อม enforcement
- DMZ เป็น zone สำหรับ service ที่ต้องติดต่อกับ network ต่าง trust level เช่น Internet-facing reverse proxy ไม่ใช่ synonym ของ “ปลอดภัย” และไม่ควรเปิด DMZ เข้าสู่ internal network แบบกว้าง
- Microsegmentation กำหนด policy ระดับ workload หรือ identity ลด east-west movement ใน data center และ cloud
- Air gap ตัดการเชื่อม network โดยตรง แต่ยังมี risk จาก removable media, maintenance laptop, radio, supply chain และ human procedure จึงไม่เท่ากับปลอดภัยสมบูรณ์
North-south traffic โดยทั่วไปหมายถึง traffic เข้าออก environment ส่วน east-west traffic หมายถึง traffic ระหว่าง workloads ภายใน ความหมายขึ้นกับ boundary ที่กำหนด Perimeter control มักเห็น north-south ดี แต่การโจมตีหลัง compromise ใช้ east-west path จึงต้องมี internal segmentation, endpoint telemetry และ identity-aware policy
ตัวอย่าง: ระบบชำระเงินอาจแบ่ง Internet edge, web tier, application tier, database tier และ management zone Firewall อนุญาต Internet ถึง reverse proxy บน HTTPS, proxy ถึง application เฉพาะ service port, application ถึง database ด้วย service identity และ encrypted channel ส่วน administration ผ่าน privileged access path เท่านั้น การเปิด “any-any ชั่วคราว” โดยไม่มี expiry และ owner ทำลายคุณค่าของ segmentation
ภาพนี้ถ่ายทอดตัวอย่างระบบชำระเงินข้างต้นให้เห็น zone และ enforcement ที่คั่นแต่ละ data flow:
Resilience, carrier และ converged networks
หัวข้อที่มีชื่อว่า “Resilience, carrier และ converged networks”การออกแบบ redundant path ต้องตรวจ route diversity, carrier independence, device, power, DNS, certificate และ capacity ระหว่าง failover ค่า Maximum Transmission Unit (MTU) ที่ต่างกันหรือ tunnel overhead อาจทำให้ packet fragmentation, black hole หรือ performance ลดลง การทดสอบ failover ต้องดู application transaction ไม่ใช่ดูเพียง link LED
Converged network ส่ง data, Voice over IP (VoIP), iSCSI storage หรือ industrial traffic บน infrastructure ร่วม จึงใช้ทรัพยากรได้ดีแต่ failure, congestion และ compromise มีผลกว้างขึ้น ต้องใช้ Quality of Service (QoS), segmentation, authentication, capacity และ resilience ตาม criticality QoS จัดลำดับ traffic แต่ไม่ใช่ security boundary และ storage VLAN อย่างเดียวไม่สร้าง Confidentiality
3.5 Firewalls, proxies และ network enforcement
หัวข้อที่มีชื่อว่า “3.5 Firewalls, proxies และ network enforcement”Firewall บังคับ policy ว่า traffic ใดผ่าน boundary ได้ตามข้อมูลที่มองเห็น ประเภทสำคัญมีดังนี้
| ประเภท | วิธีตัดสินหลัก | จุดเด่น | ข้อจำกัดสำคัญ |
|---|---|---|---|
| Packet-filtering/stateless | source/destination, protocol, port, direction | เร็ว เรียบง่าย เหมาะกับ coarse filtering | ไม่เข้าใจ connection state หรือ application context มากนัก |
| Stateful inspection | ติดตาม connection/state table | แยก established flow และ packet ผิด state ได้ | state exhaustion และ encrypted payload ยังเป็นข้อจำกัด |
| Circuit-level gateway | ควบคุม session/circuit | ซ่อน internal connection detail บางส่วน | มอง application content จำกัด |
| Application proxy | ยุติ connection แล้วสร้างอีกฝั่งในนาม client | ตรวจ protocol และแยก connection ได้ลึก | latency, capacity, certificate และ compatibility complexity |
| Next-Generation Firewall (NGFW) | state + application/user/content awareness | policy ละเอียดและรวม inspection หลายแบบ | ต้อง tune, update และจัดการ encrypted traffic |
| Web Application Firewall (WAF) | HTTP/application request | ลด web attack บางแบบและใช้ virtual patching ได้ | ไม่แก้ business logic, broken authorization หรือ secure coding ทั้งหมด |
Policy ที่ดีระบุ source, destination, service, direction, business owner, justification, expiry/review และ logging Default deny ลด unintended access แต่ต้องมี dependency discovery และ exception process การเรียง rule สำคัญ เพราะ broad allow ที่อยู่ก่อน specific deny อาจทำให้ deny ไม่เคยถูกใช้ตาม firewall semantics
Egress filtering จำกัด traffic ออกจาก network ช่วยลด command-and-control, data exfiltration และ spoofed traffic แต่ต้องไม่สมมติว่า outbound traffic ปลอดภัย Ingress filtering ลด traffic เข้ามาที่ไม่ควรเห็นจากแหล่งนั้น Anti-spoofing ควรใช้ใกล้ source และ boundary หลายจุดตาม architecture
Forward proxy ทำงานแทน client ที่ออกไปหา server ส่วน reverse proxy ทำงานหน้า server เพื่อรับ request จาก client ทั้งสองสามารถ enforce authentication, filtering, caching หรือ TLS policy ได้ต่างกัน Network Address Translation (NAT) แปล address; proxy ยุติและสร้าง application connection ใหม่ จึงไม่ใช่สิ่งเดียวกัน
Firewall placement ต้องสัมพันธ์กับ trust boundary เช่น Internet edge, partner connection, data center tier, cloud subnet, host และ management plane การมี firewall หลายชั้นแต่ใช้ rule any-any ชุดเดียวกันไม่ใช่ defense in depth ที่มีประสิทธิผล
3.6 IDS, IPS และ network monitoring
หัวข้อที่มีชื่อว่า “3.6 IDS, IPS และ network monitoring”Intrusion Detection System (IDS) วิเคราะห์ event หรือ traffic แล้วแจ้งเตือน ส่วน Intrusion Prevention System (IPS) อยู่ในตำแหน่งที่ block, reject หรือเปลี่ยน traffic ได้ IDS มักเป็น detective control; IPS มี preventive/corrective effect แต่ทั้งคู่ต้องมี sensor coverage, detection logic, tuning และ response owner
แบ่งตามตำแหน่งข้อมูลได้เป็น
- Network-based IDS/IPS (NIDS/NIPS) เห็น traffic ที่จุดเครือข่าย เหมาะกับหลาย host แต่ visibility ลดลงเมื่อ traffic เข้ารหัสหรือ path ไม่ผ่าน sensor
- Host-based IDS/IPS (HIDS/HIPS) เห็น process, file, system call และ traffic หลัง endpoint ถอดรหัสบางส่วน แต่ต้อง deploy และป้องกัน agent
- Network Detection and Response (NDR) ใช้ network telemetry, metadata และ analytics เพื่อตรวจพฤติกรรมและช่วย response ไม่ได้ทำให้ signature หรือ human analysis หมดความจำเป็น
วิธีตรวจหลักคือ signature-based detection ซึ่งแม่นกับ pattern ที่รู้จักแต่พลาด variant ใหม่ และ anomaly/behavior-based detection ซึ่งหาความต่างจาก baseline แต่มี false positive หาก environment เปลี่ยน Rule-based หรือ protocol analysis ตรวจ violation ของ policy และ protocol semantics ได้อีกแบบ
False positive คือ alert เมื่อไม่มีเหตุร้าย ทำให้ analyst ล้า; false negative คือมีเหตุร้ายแต่ไม่ alert ทำให้เกิด blind spot Threshold ที่เข้มขึ้นอาจลด false negative แต่เพิ่ม false positive ไม่มีค่า sensitivity ที่ดีที่สุดสำหรับทุกระบบ ต้อง tune ตาม asset criticality, threat และ response capacity
ตำแหน่ง sensor เป็น design decision Sensor นอก edge firewall เห็น hostile traffic ปริมาณมากและช่วย threat research แต่ noise สูง Sensor หลัง firewall เห็นสิ่งที่ผ่าน preventive control แล้ว Sensor ระหว่าง critical zones เห็น lateral movement การใช้ Switched Port Analyzer (SPAN), network tap หรือ cloud traffic mirroring ต้องตรวจ packet loss, capacity, privacy และ legal scope
Encrypted traffic สร้าง trade-off ระหว่าง Confidentiality กับ visibility ทางเลือกคือ TLS termination/inspection ในจุดที่อนุมัติ, endpoint telemetry, flow metadata, DNS log และ application log หากถอดรหัสเพื่อ inspection ต้องจัดการ private key, certificate trust, sensitive data exposure, excluded categories, performance และ accountability อย่างชัดเจน
3.7 VPN และ secure remote access
หัวข้อที่มีชื่อว่า “3.7 VPN และ secure remote access”VPN สร้าง logical protected channel ผ่าน network ที่ไม่เชื่อถือ แต่ไม่ได้ทำให้ endpoint ที่ปลาย tunnel ปลอดภัย VPN มีสอง use case หลัก
- Site-to-site VPN เชื่อม network หรือ gateway สองฝั่ง มักใช้ IPsec tunnel
- Remote-access VPN เชื่อม user/device เข้าสู่ resource ขององค์กร อาจใช้ IPsec หรือ TLS-based solution
IPsec ทำงานที่ network layer และใช้ Authentication Header (AH) หรือ Encapsulating Security Payload (ESP) ตาม design AH ให้ integrity, data-origin authentication และ anti-replay กับส่วนที่ครอบคลุม แต่ไม่ให้ Confidentiality และเข้ากับ NAT ได้ยาก ESP สามารถให้ Confidentiality พร้อม integrity/authentication ตาม configuration และใช้แพร่หลายกว่า
Transport mode ปกป้อง payload ของ IP packet เดิมและมักใช้ host-to-host ส่วน tunnel mode ห่อ packet เดิมไว้ใน packet ใหม่และเหมาะกับ gateway-to-gateway หรือ remote-access หลายแบบ Internet Key Exchange (IKE) ใช้เจรจา Security Association (SA), authenticate peer และสร้าง key material Policy ต้องกำหนด peer identity, approved algorithm, lifetime, rekey, revocation และ logging ไม่ใช้ pre-shared secret เดียวร่วมกับผู้ใช้จำนวนมากหากมีทางเลือกที่จัดการ identity ได้ดีกว่า
TLS VPN ทำงานผ่าน TLS และอาจให้ access ระดับ application หรือสร้าง tunnel กว้างตาม product/design ข้อสอบมักให้เลือกตาม requirement: ถ้าต้องปกป้องทุก IP traffic ระหว่าง gateways ให้คิดถึง IPsec tunnel; ถ้าต้องให้ผู้ใช้นอกองค์กรเข้าถึง web application เฉพาะรายการ application proxy หรือ ZTNA อาจลด exposure กว่า full network VPN
Split tunneling ส่งเฉพาะ corporate traffic ผ่าน VPN ขณะที่ Internet traffic ออก local network ช่วยลด latency และ concentrator load แต่ device อาจเชื่อม trusted กับ untrusted network พร้อมกัน เพิ่ม path สำหรับ bypass monitoring หรือ pivot Full tunneling ส่ง traffic ทั้งหมดผ่าน organization control เพิ่ม visibility แต่ต้องมี capacity, privacy และ resiliency รองรับ คำตอบขึ้นกับ risk ไม่ใช่มีแบบหนึ่งถูกเสมอ
Remote access ที่ดีใช้ MFA, managed device posture, least privilege, per-application access เมื่อเหมาะสม, session timeout, logging และ rapid revocation Administrator และ third party ควรผ่าน bastion/jump host หรือ Privileged Access Management (PAM) path ที่จำกัด ไม่เปิด management interface สู่ Internet โดยตรง
ภาพนี้สรุปเส้นทาง remote access หลังตรวจ identity และ device posture โดยแยก application access, protected tunnel และ privileged administration ตาม requirement:
3.8 Wireless security
หัวข้อที่มีชื่อว่า “3.8 Wireless security”Wireless ใช้ shared radio medium จึงไม่มีรั้วกายภาพตรงกับ signal boundary ผู้โจมตีอาจอยู่นอกอาคาร การสำรวจ coverage, access point placement, transmit power และ rogue device จึงเป็นส่วนหนึ่งของ design ไม่ใช่เพียง performance tuning
มาตรฐานสำคัญ ได้แก่
- WPA2 ใช้ AES-based CCMP ใน configuration ที่ปลอดภัย; legacy TKIP ไม่เหมาะกับ design ใหม่
- WPA3-Personal ใช้ Simultaneous Authentication of Equals (SAE) แทน shared PSK exchange แบบเก่าและเพิ่มการต้าน offline password guessing เมื่อใช้อย่างถูกต้อง
- WPA2/WPA3-Enterprise ใช้ IEEE 802.1X และ Extensible Authentication Protocol (EAP) กับ authentication server เช่น RADIUS ช่วยให้ identity ต่อผู้ใช้หรือ device และ revocation ดีกว่า shared password
- Protected Management Frames (PMF) ปกป้อง management frame บางชนิดจาก spoofing/tampering แต่ไม่หยุด jamming
Enterprise EAP method มี trust model ต่างกัน หากใช้ certificate ต้อง validate server certificate และชื่อที่คาดหวัง ไม่เช่นนั้น evil twin อาจหลอกเก็บ credential Pre-Shared Key (PSK) เดียวทั้งองค์กรกระจายและเพิกถอนยาก; การเปลี่ยนพนักงานหนึ่งคนอาจต้องเปลี่ยนทุก device
Threat ที่พบบ่อย ได้แก่ rogue access point ที่ติดตั้งโดยไม่ได้รับอนุญาต, evil twin ที่เลียนแบบชื่อเครือข่าย, deauthentication/disassociation abuse, weak passphrase, Wireless Protected Setup (WPS) ที่เปิดโดยไม่จำเป็น, jamming และ client ที่เชื่อม SSID อัตโนมัติ SSID ที่ซ่อนไม่ใช่ security control ที่แข็งแรง และ MAC filtering ถูก spoof ได้
Guest wireless ควรแยกจาก internal network ใช้ client isolation เมื่อเหมาะสม จำกัด egress และมี acceptable-use/privacy handling Captive portal แสดงหน้า login หรือเงื่อนไขการใช้ แต่ไม่ให้ link encryption โดยตัวมันเอง ต้องดู WPA/OWE/VPN/TLS ตาม use case
ตัวอย่าง enterprise design: ใช้ WPA3-Enterprise หรือ approved enterprise mode, 802.1X, certificate-based EAP, managed device certificate, separate employee/guest/IoT segments, NAC, wireless IDS/IPS, centralized logging และ lifecycle สำหรับ access point/controller เมื่อมี legacy IoT ที่รองรับเพียง PSK ให้แยก zone และจำกัด flow แทนการลด security ของเครือข่ายหลักทั้งหมด
3.9 SDN, NFV และ programmable networks
หัวข้อที่มีชื่อว่า “3.9 SDN, NFV และ programmable networks”Software-Defined Networking (SDN) แยก control plane ออกจาก data plane เชิงตรรกะ ทำให้ controller กำหนด forwarding และ policy ผ่าน software ได้แบบรวมศูนย์ องค์ประกอบทั่วไปมี application layer, controller/control layer และ infrastructure/data plane
- Northbound API เชื่อม application หรือ orchestration กับ controller
- Southbound interface/API เชื่อม controller กับ network devices หรือ virtual switches
- East-west interface อาจใช้ระหว่าง controllers หรือ domains ขึ้นกับ architecture
ข้อดีคือ automation, policy consistency, rapid provisioning, centralized visibility และ microsegmentation แต่ controller และ API กลายเป็น high-value target Risk รวม controller compromise, malicious application, weak API authentication, policy error ที่กระจายเร็ว, stale state, denial of service และ loss of controller connectivity
Controls ควรมี strong administrative identity, role separation, signed/approved application, API authentication/authorization, encrypted management channel, controller high availability, configuration versioning, change review, rate limit, telemetry และ tested fallback Data plane ต้องกำหนดว่าจะทำอย่างไรเมื่อ controller ติดต่อไม่ได้ เช่น fail static, preserve last known state หรือ deny new flow ตาม availability และ safety requirement
Network Functions Virtualization (NFV) นำ network function เช่น firewall, router หรือ load balancer มาทำงานเป็น software บน virtualized infrastructure SDN กับ NFV ใช้ร่วมกันได้แต่ไม่ใช่สิ่งเดียวกัน NFV เพิ่ม dependency ต่อ hypervisor, image, orchestrator และ resource isolation จึงต้องจัดการ supply chain, patching, tenant isolation และ performance exhaustion
Automation ลด manual inconsistency แต่ทำให้ mistake scale ได้เร็ว Infrastructure as Code (IaC) และ policy as code จึงต้องมี version control, peer review, automated validation, least-privileged deployment identity, drift detection และ rollback ที่ทดสอบแล้ว
3.10 Cloud networking และ hybrid connectivity
หัวข้อที่มีชื่อว่า “3.10 Cloud networking และ hybrid connectivity”Cloud networking ใช้ logical constructs เช่น Virtual Private Cloud (VPC) หรือ Virtual Network (VNet), subnet, route table, virtual gateway, load balancer, security group, network ACL, private endpoint และ cloud firewall ชื่อและ semantics ต่างตาม provider จึงต้องอ่าน behavior จริง ไม่สมมติว่า control ชื่อคล้ายกันทำงานเหมือนกัน
ประเด็นสำคัญมีดังนี้
- Shared responsibility: provider ป้องกัน physical network และ service layer ตาม model ส่วน customer มักรับผิดชอบ identity, route, firewall rule, exposed service, data และ workload configuration ระดับแบ่งหน้าที่เปลี่ยนตาม IaaS, PaaS, SaaS และ contract
- Logical isolation: tenant isolation ไม่ได้ทำให้ workload ภายใน tenant แยกกันโดยอัตโนมัติ ต้องกำหนด account/project/subscription, VPC/VNet, subnet, security group และ identity boundary
- East-west visibility: workload-to-workload traffic อาจไม่ผ่าน on-premises firewall ใช้ cloud-native flow log, workload firewall, service mesh, NDR หรือ microsegmentation ตาม architecture
- Management plane exposure: cloud API ควบคุม network ได้กว้าง ต้องใช้ MFA, workload identity, least privilege, organization guardrail, audit log และแยก deployment role
- Egress และ data exfiltration: private subnet อาจยังออก Internet ผ่าน NAT gateway หรือ service API ได้ ต้องกำหนด egress proxy/firewall, DNS policy, private endpoint และ allowlist ตาม requirement
- Resilience: availability zone และ region ลด failure บางประเภท แต่เพิ่ม routing, data consistency, cost และ failover complexity ต้องทดสอบ DNS, quota, key, identity และ dependency ไม่ใช่เพียงสร้าง subnet หลายแห่ง
Security group มักผูกกับ interface/workload และอาจเป็น stateful ขณะที่ network ACL มักผูกกับ subnet และอาจเป็น stateless แต่รายละเอียดขึ้นกับ provider จึงไม่ควรจำ generalization นี้เป็นสากล Route table กำหนดเส้นทาง ไม่ได้อนุญาต traffic แทน firewall และการไม่มี public IP ไม่ได้แปลว่าไม่มี outbound path หรือเข้าถึงจาก peered network ไม่ได้
การเชื่อม on-premises กับ cloud อาจใช้ Internet VPN, dedicated private circuit หรือ SD-WAN overlay Private circuit ให้ predictable connectivity และลดการผ่าน public Internet แต่ไม่ได้ให้ encryption โดยอัตโนมัติ ต้องกำหนด protection ตาม classification VPN บน private circuit อาจยังจำเป็นหาก threat model ต้องการ Confidentiality และ peer authentication
Peering เชื่อม virtual networks โดยตรง แต่ไม่ควรสมมติว่า routing transitive Transit hub/gateway ลด full mesh แต่เป็น critical dependency จึงต้องแบ่ง route domain, inspect traffic และป้องกัน route propagation ที่กว้างเกิน Hybrid DNS ต้องกำหนด authoritative zone, forwarding และ failure mode
Container และ Kubernetes เพิ่ม overlay network, ingress controller, service, pod identity และ NetworkPolicy หากไม่มี policy pod อาจสื่อสารกันกว้างกว่าที่ owner คาด ต้องบังคับ namespace/workload isolation, secure ingress/egress, service-to-service identity, secret/certificate lifecycle และ control ของ cluster management plane
Secure Access Service Edge (SASE) รวม wide-area networking กับ cloud-delivered security capabilities เพื่อรองรับ distributed users และ cloud applications แต่เพิ่ม dependency ต่อ provider, identity, policy synchronization และ telemetry ชื่อบริการไม่พิสูจน์ว่า Zero Trust หรือ least privilege ถูกนำไปใช้แล้ว
ตัวอย่าง cloud design: Internet request เข้า DDoS protection และ load balancer/WAF จากนั้นถึง application subnet ที่ไม่รับ inbound โดยตรง Application ติดต่อ managed database ผ่าน private endpoint และ workload identity; egress ผ่าน controlled gateway; administrator ใช้ privileged access path; ทุก rule สร้างจาก reviewed IaC และส่ง flow, DNS, WAF, identity กับ control-plane logs ไปยัง monitoring กลาง Design นี้ยังต้องทดสอบ authorization ใน application เพราะ network control ไม่แทน application security
4. กรอบมาตรฐานที่เกี่ยวข้อง
หัวข้อที่มีชื่อว่า “4. กรอบมาตรฐานที่เกี่ยวข้อง”4.1 NIST
หัวข้อที่มีชื่อว่า “4.1 NIST”NIST Cybersecurity Framework (CSF) 2.0 ใช้จัดการ network risk ในระดับ outcome ได้ตลอด Govern, Identify, Protect, Detect, Respond และ Recover ตัวอย่างเช่น Govern กำหนด owner และ supplier requirement, Identify ทำ asset/data-flow inventory, Protect ใช้ segmentation และ secure protocol, Detect ใช้ telemetry, Respond จำกัดหรือ isolate flow และ Recover ทดสอบ route/service restoration
เอกสาร NIST ที่เกี่ยวข้องโดยตรงและใช้เป็นแนวทาง ไม่ใช่ checklist ที่ใช้แทน risk assessment ได้แก่
- NIST SP 800-41 Rev. 1, Guidelines on Firewalls and Firewall Policy อธิบายประเภท firewall, policy, deployment และ management
- NIST SP 800-77 Rev. 1, Guide to IPsec VPNs ครอบคลุม IPsec และการวางแผน VPN
- NIST SP 800-94, Guide to Intrusion Detection and Prevention Systems ครอบคลุม IDPS หลายประเภทและ lifecycle การใช้งาน
- NIST SP 800-153, Guidelines for Securing Wireless Local Area Networks ครอบคลุม WLAN security ตลอด lifecycle
- NIST SP 800-207, Zero Trust Architecture อธิบายหลักและองค์ประกอบของ ZTA โดยไม่ผูก trust กับ network location เพียงอย่างเดียว
เอกสารแต่ละฉบับมีขอบเขตและอายุ ต้องตรวจ version, organizational requirement และ technology context ก่อนใช้กับ production
4.2 ISO/IEC 27001 และ ISO/IEC 27002
หัวข้อที่มีชื่อว่า “4.2 ISO/IEC 27001 และ ISO/IEC 27002”ISO/IEC 27001:2022 กำหนด requirement ของ Information Security Management System (ISMS) ส่วน Annex A เป็นชุด reference controls ที่องค์กรเลือกตาม risk และบันทึกเหตุผลใน Statement of Applicability (SoA) ไม่จำเป็นต้องใช้ทุก control แบบเดียวกัน
หัวข้อที่สัมพันธ์กับ Domain 4 ได้แก่ security of networks, security of network services, segregation of networks, information transfer, logging, monitoring activities, configuration management และ supplier/cloud service controls ISO/IEC 27002:2022 ให้ guidance เพิ่มเติมในการนำ controls ไปใช้ จุดสำคัญคือกำหนด security requirement ใน service agreement, ระบุ responsibility, review configuration และเก็บ evidence ไม่ใช่เพียงซื้อ firewall แล้วถือว่าสอดคล้อง
4.3 COBIT
หัวข้อที่มีชื่อว่า “4.3 COBIT”COBIT 2019 เชื่อม network security เข้ากับ governance และ management objectives เช่น APO13 Managed Security, DSS05 Managed Security Services, DSS01 Managed Operations, BAI04 Managed Availability and Capacity และ MEA สำหรับ monitoring/evaluation ผู้บริหารใช้ COBIT กำหนด decision rights, responsibility, metric และ assurance มากกว่ากำหนด firewall syntax
ตัวอย่างการใช้ร่วมกัน: governance body กำหนด risk appetite, management ระบุ network service requirement และ control owner, operations ดูแล rule/configuration, security monitoring ตรวจ event และ independent assurance ประเมินว่า process กับ control ให้ผลตาม objective หรือไม่
4.4 ITIL
หัวข้อที่มีชื่อว่า “4.4 ITIL”ITIL 4 มอง network เป็นส่วนหนึ่งของ service value system Practices ที่เกี่ยวข้อง ได้แก่ information security management, infrastructure and platform management, monitoring and event management, incident management, change enablement, availability management, capacity and performance management และ service continuity management
ตัวอย่าง: การเปลี่ยน routing หรือ firewall rule ต้องมี risk-based change process, test, approval, communication และ rollback Emergency change อาจเร่งขั้นตอนแต่ไม่ควรละทิ้ง authorization กับ evidence ส่วน network alert ต้องเชื่อม event ไป incident ตาม impact ไม่สร้าง ticket ทุก packet จนทีมตอบสนองไม่ไหว
4.5 ใช้กรอบร่วมกันอย่างไร
หัวข้อที่มีชื่อว่า “4.5 ใช้กรอบร่วมกันอย่างไร”กรอบเหล่านี้ทำหน้าที่ต่างกัน ISO/IEC 27001 ให้ระบบบริหารและ auditable requirements, NIST ให้ outcome และ technical guidance, COBIT เชื่อม governance กับ management objectives และ ITIL จัดการ network ในฐานะบริการ ไม่มีกรอบใดแทน architecture หรือ risk decision เฉพาะองค์กรได้
ลำดับที่ใช้ได้จริงคือ owner กำหนด classification, criticality และ risk tolerance; architect สร้าง data flow, segmentation และ secure channel; engineer นำ control ไปใช้; operations monitor และเปลี่ยนแปลงอย่างควบคุม; assessor ตรวจ evidence; Risk owner ตัดสิน residual risk
5. คำศัพท์สำคัญพร้อมนิยาม
หัวข้อที่มีชื่อว่า “5. คำศัพท์สำคัญพร้อมนิยาม”| คำศัพท์ | นิยาม |
|---|---|
| OSI model | แบบจำลองการสื่อสารเจ็ดชั้น ใช้จัดหน้าที่ protocol และวิเคราะห์ control/failure |
| TCP/IP model | แบบจำลอง protocol suite ของ Internet ที่มักแบ่ง Application, Transport, Internet และ Link/Network access |
| Encapsulation | การห่อข้อมูลจากชั้นบนด้วย header/trailer ของชั้นล่าง |
| Data flow | เส้นทางและเงื่อนไขที่ data เคลื่อนระหว่าง source, destination และ intermediary |
| Segmentation | การแบ่ง network เป็นส่วนและควบคุมการสื่อสารระหว่างส่วน |
| Microsegmentation | การบังคับ policy ละเอียดระดับ workload, application หรือ identity |
| DMZ | zone คั่นกลางสำหรับ service ที่ติดต่อระหว่าง network ต่าง trust level |
| Data plane | ส่วนที่ forward traffic ตาม decision ที่มีอยู่ |
| Control plane | ส่วนที่เรียนรู้ topology และสร้าง routing/forwarding decision |
| Management plane | interface และ service สำหรับ configure, monitor และ administer network |
| Stateful firewall | firewall ที่ติดตาม state ของ connection เพื่อประกอบการตัดสินใจ |
| Proxy | intermediary ที่รับ connection ฝั่งหนึ่งและติดต่ออีกฝั่งในนาม client/server |
| WAF | firewall ที่ตรวจและบังคับ policy กับ HTTP/application traffic |
| IDS | ระบบตรวจ event/traffic ที่น่าสงสัยและสร้าง alert |
| IPS | ระบบตรวจและสามารถ block หรือเปลี่ยน traffic ที่ตรงเงื่อนไข |
| VPN | logical protected channel ผ่าน network ที่ไม่เชื่อถือ |
| IPsec | ชุด protocol ที่ปกป้อง IP communication ด้วย AH/ESP และ Security Associations |
| TLS | protocol สำหรับปกป้อง application communication ด้วย authentication, key establishment และ record protection ตาม configuration |
| Split tunneling | การส่งเฉพาะ traffic บางส่วนผ่าน VPN และให้อีกส่วนออก local path |
| NAC | control ที่ตัดสินหรือจำกัด network access จาก identity, device หรือ posture ตาม policy |
| 802.1X | port-based network access control framework ที่ใช้ EAP กับ wired/wireless access |
| Evil twin | access point ปลอมที่เลียนแบบเครือข่ายเพื่อหลอก client |
| SDN | architecture ที่แยก control plane จาก data plane เชิงตรรกะและควบคุมผ่าน software |
| NFV | การทำ network function เป็น software บน virtualized infrastructure |
| ZTA | architecture ที่ไม่ให้ implicit trust จาก location และประเมิน access request ตาม policy/context |
| SASE | architecture/service model ที่รวม WAN capabilities กับ cloud-delivered security functions |
| VPC/VNet | logical cloud network boundary ที่ customer กำหนด address, subnet, route และ controls |
| Private endpoint | interface/address ส่วนตัวสำหรับเข้าถึง service โดยไม่ต้อง expose ผ่าน public endpoint ตาม provider design |
| Flow log | metadata ของ network flow เช่น source, destination, port, action และเวลา ไม่ใช่ full packet capture |
| Air gap | การแยก network โดยไม่มี direct connectivity ตาม design แต่ยังต้องควบคุมช่องทางอื่น |
| Blast radius | ขอบเขตผลกระทบที่ incident หรือ failure แพร่ไปถึงได้ |
6. Exam Tips: จุดที่ข้อสอบชอบหลอก
หัวข้อที่มีชื่อว่า “6. Exam Tips: จุดที่ข้อสอบชอบหลอก”- OSI เป็น model ไม่ใช่ packet capture จริงทั้งหมด ใช้หาชั้นที่เกี่ยวข้อง แต่อย่าฝืนให้ protocol หนึ่งอยู่ชั้นเดียวในทุกบริบท
- NAT ไม่ใช่ firewall การแปล address ไม่แทน traffic policy
- VLAN ไม่พอถ้า inter-VLAN routing เปิดกว้าง Segmentation ต้องมี enforcement
- Port 443 ไม่พิสูจน์ว่า traffic ปลอดภัย ต้องดู protocol, certificate, identity และ behavior
- Encryption ไม่เท่ากับ authentication Channel ที่ไม่ validate peer ยังเสี่ยง MITM
- DNSSEC ไม่ได้เข้ารหัส DNS query DoT/DoH จึงแก้คนละปัญหา
- Firewall กับ WAF แก้คนละระดับ WAF ไม่แทน application authorization และ secure coding
- IDS แจ้งเตือน; IPS หยุดได้ แต่ inline IPS มี Availability risk
- IPsec AH ไม่ให้ Confidentiality ESP ใช้ให้ encryption ตาม configuration
- VPN ปกป้อง channel ไม่ได้ทำให้ endpoint trusted ยังต้องมี MFA, posture และ least privilege
- Split tunnel มี trade-off ลด load แต่เพิ่ม path ที่อาจ bypass monitoring
- SSID hiding และ MAC filtering เป็น weak controls ไม่แทน WPA2/WPA3 และ 802.1X
- Captive portal ไม่ให้ link encryption โดยตัวมันเอง เป็น access/terms mechanism
- Zero Trust ไม่ได้ลบ network controls ใช้ identity/context ร่วมกับ segmentation
- Private cloud circuit ไม่ได้แปลว่า encrypted Private path กับ Confidentiality เป็นคนละ property
- ไม่มี public IP ไม่ได้แปลว่า isolated Peering, VPN, gateway และ API ยังสร้าง reachability ได้
- Redundant ไม่เท่ากับ resilient หากมี common failure ตรวจ path, power, DNS และ identity dependency
- ถ้าโจทย์ถาม FIRST ให้เริ่มจาก requirement/data flow อย่าเลือกผลิตภัณฑ์ก่อนรู้ allowed flow
- ถ้าโจทย์ถาม BEST ให้มอง lifecycle Control ต้อง monitor, review, test และ recover ได้
7. Cross-reference ไป Domain อื่น
หัวข้อที่มีชื่อว่า “7. Cross-reference ไป Domain อื่น”- Domain 1: Security and Risk Management — ใช้ governance, risk appetite, policy, supplier agreement, Business Impact Analysis (BIA), Recovery Time Objective (RTO), Recovery Point Objective (RPO) และ residual risk กำหนด network requirement และ resilience
- Domain 2: Asset Security — Data classification และ data states บอกว่า flow ใดต้อง encrypt, segment, monitor, retain log หรือห้ามออกนอก jurisdiction; Data owner กำหนด handling requirement
- Domain 3: Security Architecture and Engineering — Trust boundary, defense in depth, cryptography, Public Key Infrastructure (PKI), Zero Trust, SASE, cloud shared responsibility, OT/ICS/IoT และ fail securely เป็นฐานของ network design
- Domain 5: Identity and Access Management — 802.1X, EAP, RADIUS, MFA, service identity, federated identity, NAC, PAM และ certificate-based authentication ต้องเชื่อมกับ identity lifecycle และ authorization
- Domain 6: Security Assessment and Testing — ตรวจ firewall rule, segmentation, wireless coverage, VPN configuration, detection coverage, failover, penetration path และ evidence ว่า control ทำงานตาม requirement
- Domain 7: Security Operations — ดูแล configuration, patching, log, NDR/IDS alert, incident containment, DDoS response, change, backup, recovery และ third-party remote access ในงานประจำ
- Domain 8: Software Development Security — Secure API, TLS validation, service mesh, application authorization, Infrastructure as Code, container network policy, CI/CD identity และ WAF ต้องออกแบบร่วมกับ Software Development Life Cycle (SDLC)
Network security ที่มีคุณภาพจึงไม่จบที่ “ต่อถึง” หรือ “ping ผ่าน” แต่ต้องพิสูจน์ได้ว่าเฉพาะ flow ที่ได้รับอนุมัติเท่านั้นที่ผ่าน, peer ถูก authenticate, data in transit ได้รับ protection ตาม classification, anomaly ถูกตรวจพบ, failure ถูกจำกัด และ owner เข้าใจ residual risk ที่ยังเหลืออยู่