Layered network security
Bắt đầu từ threat và path: HTTP exploit, DDoS, unauthorized east-west traffic, private AWS service access hay hybrid route. Sau đó đặt WAF/Shield/SG/NACL/endpoint/TGW/VPN đúng lớp.
Bài tập
Vẽ public web, private app, S3 access và on-prem connection. Với mỗi path ghi route, identity, filter, log và failure behavior. Một control đúng nhưng đặt sai scope vẫn là thiết kế sai.
Bài giảng chuyên sâu
Network security theo threat và request path
WAF lọc HTTP exploit; Shield bảo vệ DDoS theo scope; SG lọc gần ENI; NACL là subnet guardrail; VPC endpoint giữ traffic tới AWS service trong network; VPN/Direct Connect tạo hybrid connection. Không dùng một control để giải quyết mọi threat.
Bắt đầu từ flow public web → ALB → private app → S3/database → on-prem. Với từng hop ghi route, identity, filter, log và expected failure. Endpoint policy và bucket policy có thể cùng giới hạn access; WAF không thay IAM, SG không hiểu HTTP path.
Bài tập: threat/control matrix cho SQL injection, DDoS, east-west access, S3 exfiltration và hybrid route. Failure drill: endpoint route thiếu, NACL chặn return và WAF false positive; ghi rollback và evidence.