簡介
安全性不是事後才想到的——它必須從頭開始設計。 深度防禦意味著多層保護:如果繞過一層,則下一層提供保護。
1.縱深防禦模型
Layer 1: Edge/Perimeter
┌────────────────────────────────────────┐
│ WAF, DDoS Protection, CDN │
│ Rate Limiting, IP Filtering │
└────────────────────┬───────────────────┘
│
Layer 2: Network
┌────────────────────┼───────────────────┐
│ VPC, Subnets, Security Groups │
│ Network ACLs, Private endpoints │
└────────────────────┬───────────────────┘
│
Layer 3: Application
┌────────────────────┼───────────────────┐
│ Authentication, Authorization │
│ Input Validation, CSRF/XSS protection │
└────────────────────┬───────────────────┘
│
Layer 4: Data
┌────────────────────┼───────────────────┐
│ Encryption at rest, in transit │
│ Key management, Data masking │
└────────────────────┬───────────────────┘
│
Layer 5: Monitoring
┌────────────────────┼───────────────────┐
│ Audit logs, Anomaly detection │
│ SIEM, Incident response │
└────────────────────────────────────────┘
2. 身分驗證與授權
2.1 OAuth 2.0 + OpenID 連接
Authorization Code Flow:
User → App: "Login with Google"
App → Google: Redirect (client_id, redirect_uri, scope)
User → Google: Login + Consent
Google → App: Authorization Code
App → Google: Exchange code for tokens (+ client_secret)
Google → App: access_token + id_token (JWT)
App → API: Request + access_token
Tokens:
Access Token: Ngắn hạn (15 phút), dùng gọi API
Refresh Token: Dài hạn (7 ngày), dùng lấy access token mới
ID Token: User info (name, email), JWT format
2.2 JWT架構
JWT = Header.Payload.Signature
Header: { "alg": "RS256", "typ": "JWT" }
Payload: { "sub": "user-123", "role": "admin", "exp": 1705312200 }
Signature: RS256(header + payload, private_key)
Verification:
API Gateway nhận JWT
→ Verify signature bằng public key
→ Check expiration
→ Extract claims (user_id, roles)
→ Forward request + claims to services
Stateless: Không cần query database mỗi request
Revocation: Khó! (dùng short expiry + blacklist)
2.3 RBAC 與 ABAC
RBAC (Role-Based Access Control):
User → Role → Permissions
Role: "editor"
Permissions: [create_post, edit_post, delete_own_post]
Check: user.role == "editor" && action == "edit_post"
Simple, widely used
Limitation: Không handle complex policies
ABAC (Attribute-Based Access Control):
Policy based on attributes of User, Resource, Action, Environment
Policy: "User can edit post IF:
user.department == post.department AND
user.clearance >= post.classification AND
time.now BETWEEN 9:00 AND 18:00"
Flexible, fine-grained
Complex to manage
3. 網路安全
3.1 專有網路架構
┌──────────────────────────────────────────────┐
│ VPC (10.0.0.0/16) │
│ │
│ ┌──────────────────────────────────────────┐ │
│ │ Public Subnet (10.0.1.0/24) │ │
│ │ ┌──────────┐ ┌──────────┐ │ │
│ │ │ ALB │ │ NAT GW │ │ │
│ │ └──────────┘ └──────────┘ │ │
│ └──────────────────────────────────────────┘ │
│ │
│ ┌──────────────────────────────────────────┐ │
│ │ Private Subnet (10.0.2.0/24) │ │
│ │ ┌──────────┐ ┌──────────┐ │ │
│ │ │ App │ │ App │ │ │
│ │ │ Server │ │ Server │ │ │
│ │ └──────────┘ └──────────┘ │ │
│ └──────────────────────────────────────────┘ │
│ │
│ ┌──────────────────────────────────────────┐ │
│ │ Isolated Subnet (10.0.3.0/24) │ │
│ │ ┌──────────┐ ┌──────────┐ │ │
│ │ │ Database │ │ Redis │ │ │
│ │ └──────────┘ └──────────┘ │ │
│ └──────────────────────────────────────────┘ │
└──────────────────────────────────────────────┘
Security Groups:
ALB: Inbound 443 from 0.0.0.0/0
App: Inbound 8080 from ALB SG only
DB: Inbound 5432 from App SG only
3.2 WAF(網路應用程式防火牆)
WAF Rules:
- Block SQL injection patterns
- Block XSS payloads
- Rate limit: Max 1000 req/min per IP
- Geo blocking: Block countries không phục vụ
- Bot detection: Block scrapers, bad bots
- Custom rules: Block specific URLs/patterns
Traffic flow:
Internet → CloudFlare/WAF → ALB → App
Attack blocked at edge (trước khi đến app)
4. 資料安全
4.1 加密
In Transit:
Client ←── TLS 1.3 ──→ Server
Service A ←── mTLS ──→ Service B
App ←── TLS ──→ Database
At Rest:
Database: AES-256 encrypted storage
S3: Server-side encryption (SSE-S3, SSE-KMS)
Disk: LUKS / BitLocker
Key Management:
❌ Hardcode keys trong code
❌ Lưu keys trong database
✅ KMS (AWS KMS, HashiCorp Vault)
✅ Envelope encryption:
Master Key (KMS) → encrypts → Data Key
Data Key → encrypts → Data
Rotate Data Key dễ dàng
4.2 資料分類
Level 1 - Public: Marketing content, public APIs
Level 2 - Internal: Internal docs, employee directory
Level 3 - Confidential: Customer PII, financial data
Level 4 - Restricted: Passwords, encryption keys, PHI
Mỗi level có controls khác nhau:
Level 4: Encrypted + access log + MFA + need-to-know
Level 1: No special controls
5. API 安全
1. Authentication: Ai đang gọi?
API Key, OAuth2 Bearer Token, mTLS
2. Authorization: Được phép gọi endpoint này?
RBAC/ABAC check per endpoint
3. Input Validation: Data có hợp lệ?
Schema validation, sanitize input
4. Rate Limiting:
Per user: 100 req/min
Per IP: 1000 req/min
Per endpoint: /login → 5 req/min (brute force)
5. Request Size Limit:
Max body: 10MB
Max header: 8KB
6. Output Filtering:
Không trả về sensitive fields
Mask PII in logs
6. 零信任架構
Traditional (Castle & Moat):
┌─────────────────────────┐
│ Trusted Network │
│ Everything inside = OK │ ← Flat network
│ Firewall at perimeter │ Once in, full access
└─────────────────────────┘
Zero Trust:
"Never trust, always verify"
"Assume breach"
Principles:
1. Verify explicitly (every request)
2. Least privilege access
3. Assume breach
Implementation:
┌───────────────────────────────────────┐
│ Every request verified: │
│ - Identity (who?) │
│ - Device health (patched? compliant?) │
│ - Location (expected?) │
│ - Data sensitivity (what access?) │
│ - Anomaly detection (normal pattern?) │
└───────────────────────────────────────┘
Service Mesh (mTLS): Service ↔ Service encrypted + authenticated
Identity-aware proxy: Google BeyondCorp style
總結
| 層 | 控制 |
|---|---|
| 邊緣 | WAF、DDoS、CDN、速率限制 |
| 網路 | VPC、安全群組、私人子網路 |
| 應用 | AuthN/AuthZ、輸入驗證、CSRF |
| 資料 | 加密、金鑰管理、分類 |
| 監控 | 審核日誌、SIEM、異常偵測 |
練習
-
安全架構: 設計醫療保健應用程式 (HIPAA) 的安全架構:病患資料、醫生入口網站、行動應用程式。涵蓋:網路、認證、加密、稽核。
-
威脅模型: 電商結帳流程:使用者→購物車→付款→確認。列出 5 種威脅(STRIDE 模型)以及每個威脅的對策。
-
零信任遷移: 公司擁有基於 VPN 的訪問(城堡和護城河)。 500 名開發人員,50 個微服務。撰寫零信任遷移計劃。哪個階段先出現?