Skip to main content
Skip to footer
Cybersecurity Operations & Defense Bootcamp with AI-Driven Threat Analysis and Firewall Management
Attack → Observe → Analyze → Defend
วัตถุประสงค์ของหลักสูตร
- สร้างความเข้าใจพื้นฐานเกี่ยวกับภัยคุกคาม ช่องโหว่ ความเสี่ยง และรูปแบบการโจมตีทางไซเบอร์
- ให้ผู้เรียนเข้าใจมุมมองและกระบวนการของผู้โจมตี เพื่อนำไปสู่การตรวจจับและป้องกันที่มีประสิทธิภาพ
- ฝึกใช้เครื่องมือมาตรฐานด้าน Cybersecurity เช่น Nmap, Wireshark, OpenVAS/Greenbone, Nikto, OWASP ZAP, Burp Suite และเครื่องมือวิเคราะห์ระบบ
- ฝึกวิเคราะห์ Network Traffic, Authentication Log, Web Log และ Firewall Log เพื่อค้นหาพฤติกรรมผิดปกติ
- ประยุกต์ใช้ MITRE ATT&CK เพื่อ Mapping พฤติกรรมและเชื่อมโยงกับมาตรการตรวจจับและป้องกัน
- ใช้ AI ช่วยวิเคราะห์ Log, Vulnerability Findings, Firewall Events และสร้าง Remediation Plan โดยมี Human Validation
- ออกแบบและบริหาร Firewall, VLAN, DMZ, Network Segmentation, NAT/PAT และ Site-to-Site IPsec VPN
- เชื่อมโยงความรู้ทั้งหมดผ่าน Final Capstone แบบ Attack → Evidence → AI Analysis → Defense
ผู้ที่เหมาะกับหลักสูตร
- Network Engineer / Network Administrator
- System Administrator / IT Support
- Firewall Administrator
- Cybersecurity Analyst / SOC Analyst ระดับเริ่มต้น
- Security Engineer
- IT Manager / IT Supervisor / Team Lead
- ผู้ที่ต้องการเริ่มต้นสายงาน Cybersecurity
- ผู้ดูแลระบบหรือเจ้าของกิจการที่ต้องการเข้าใจความเสี่ยงและการป้องกันระบบขององค์กร
ผลลัพธ์หลังจบหลักสูตร
- อธิบายภัยคุกคาม ช่องโหว่ ความเสี่ยง และรูปแบบการโจมตีได้
- สำรวจและประเมิน Attack Surface ในระบบที่ได้รับอนุญาต
- ใช้ Nmap, Wireshark, OpenVAS/Greenbone และเครื่องมือพื้นฐานด้าน Cybersecurity
- วิเคราะห์ Vulnerability Scan และจัดลำดับความสำคัญของการแก้ไข
- ตรวจสอบ Authentication, Network, Web และ Firewall Log
- ระบุพฤติกรรม Port Scan, Brute Force, Web Attack และ Malware Communication
- Mapping เหตุการณ์กับ MITRE ATT&CK
- ออกแบบ Firewall Policy, VLAN, DMZ และ Network Segmentation
- ติดตั้ง Site-to-Site IPsec VPN
- ใช้ AI ช่วยวิเคราะห์ Log และสร้าง Remediation Plan
- ตรวจสอบความถูกต้องและข้อจำกัดของผลลัพธ์จาก AI
- จัดทำ Incident Summary และ Executive Summary เบื้องต้น
-
- รายละเอียดหลักสูตร
Phase 1: Cybersecurity Fundamentals and Security Architecture
Module 1: Cybersecurity Threats, Vulnerabilities and Risks
1.1 พื้นฐานภัยคุกคามทางไซเบอร์
- ความหมายของ Threat, Vulnerability, Exploit และ Risk
- ความสัมพันธ์ระหว่าง Asset, Threat, Vulnerability และ Impact
- ประเภทภัยคุกคาม: Malware, Phishing, Social Engineering, DoS/DDoS, Insider Threat, Credential Attack, Web Application Attack
- Attack Surface และ Attack Vector
- ช่องทางการโจมตีผ่าน Email, USB, Website, Remote Access, Wireless Network, Cloud Service และ Social Media
1.2 กระบวนการโจมตีทางไซเบอร์
- Reconnaissance, Scanning, Enumeration และ Exploitation
- Privilege Escalation, Persistence และ Lateral Movement
- Data Collection, Exfiltration และ Impact
1.3 MITRE ATT&CK Framework เบื้องต้น
- ความหมายของ Tactic, Technique และ Procedure (TTPs)
- การใช้ MITRE ATT&CK วิเคราะห์พฤติกรรมผู้โจมตี
- การ Mapping เหตุการณ์กับ ATT&CK Technique
- การใช้ ATT&CK เพื่อออกแบบมาตรการตรวจจับและป้องกัน
Labs / AI Labs
- Lab 1.1: วิเคราะห์ตัวอย่างเหตุการณ์และแยก Threat, Vulnerability และ Risk
- Lab 1.2: Mapping ตัวอย่างการโจมตีกับ MITRE ATT&CK
- AI Lab 1.3: ใช้ AI วิเคราะห์ Log ตัวอย่างและระบุประเภทการโจมตีตาม MITRE ATT&CK
Module 2: Network Security Controls, Protocols and Devices
2.1 Network Security Controls
- ACL, VLAN, Network Segmentation, Port Security, NAT และ PAT
- Least Privilege, Default Deny และ Defense in Depth
2.2 อุปกรณ์ด้านความปลอดภัย
- Router และ Layer 3 Switch
- Firewall / Next-Generation Firewall
- IDS/IPS, Proxy Server, Web Application Firewall, VPN Gateway และ SIEM เบื้องต้น
2.3 Security Protocols
- SSH, TLS, IPsec, SNMPv3, HTTPS และ Secure Remote Access
2.4 แนวคิดการป้องกันสมัยใหม่
- Detection vs Prevention
- Zero Trust Architecture
- Identity-Based Access
- Network Micro-Segmentation
- User and Entity Behavior Analytics (UEBA)
- Anomaly Detection
AI Integration
- แนวคิด AI-Driven Micro-Segmentation
- การใช้ AI วิเคราะห์พฤติกรรมผู้ใช้และอุปกรณ์
- Rule-Based Detection เทียบกับ AI-Based Anomaly Detection
Phase 2: Reconnaissance and Attack Surface Discovery
Module 3: Footprinting, OSINT and Reconnaissance
3.1 แนวคิด Reconnaissance
- Passive Reconnaissance
- Active Reconnaissance
- Footprinting
- Open Source Intelligence (OSINT)
- ขอบเขตและจริยธรรมของ OSINT
3.2 ข้อมูลที่ผู้โจมตีต้องการค้นหา
- Domain Name, Email Address, IP Address และ IP Block, DNS Record
- Employee Information
- Metadata
- Social Footprint
- Technology Stack
- Publicly Exposed Services
Labs
- Lab 3.1: Gathering Information using Metasploit
- Lab 3.2: Gathering Email Information using theHarvester
- Lab 3.3: วิเคราะห์ Email Header และเส้นทางการส่งอีเมล
- Lab 3.4: Footprinting a Target using Recon-ng
- Lab 3.5: Footprinting and Relationship Mapping using Maltego
3.3 AI Integration / AI Lab
- ใช้ AI ช่วยสรุปข้อมูล OSINT และวิเคราะห์ความสัมพันธ์ของข้อมูล
- ใช้ AI ช่วยสร้างคำค้นหาเพื่อการตรวจสอบข้อมูลสาธารณะ
- ใช้ AI ช่วยเขียน Python Script สำหรับดึง Metadata จากไฟล์ในระบบ Lab
- AI Lab 3.6: นำผล OSINT มาให้ AI ช่วยสรุป Attack Surface และเสนอแนวทางลดการเปิดเผยข้อมูล
Module 4: Network Scanning and Service Discovery
4.1 แนวคิด Network Scanning
- Host Discovery, Service Discovery
- Port Scanning, TCP และ UDP Scanning
- Network Mapping
4.2 TCP Flags และ Scan Types
- TCP Three-Way Handshake
- SYN Scan, FIN Scan, NULL Scan, XMAS Scan, TCP Connect Scan, UDP Scan
4.3 OS และ Service Fingerprinting
- Operating System Detection, Service Version Detection
- Banner Grabbing
- Nmap Service Scripts
- Network Latency และ Scan Timing
Labs / AI Labs
- Lab 4.1: Port and Service Discovery
- Lab 4.2: Network Scanning using hping3
- Lab 4.3: Host Discovery using Netdiscover
- Lab 4.4: Network Scanning using Metasploit
- Lab 4.5: Nmap Vulnerability and Script Scanning
- Lab 4.6: Nmap OS and Service Detection
- Lab 4.7: ตรวจสอบ Firewall Log ที่เกิดจาก Port Scan
- AI Lab 4.8: ใช้ AI วิเคราะห์ Nmap Output และสรุปบริการที่มีความเสี่ยง
- AI Lab 4.9: ใช้ AI แนะนำขั้นตอนการตรวจสอบและป้องกันต่อไป
Module 5: Enumeration and Service Exposure Analysis
5.1 แนวคิด Enumeration
- ความแตกต่างระหว่าง Scanning และ Enumeration
- การรวบรวมรายละเอียดจากบริการที่เปิดใช้งาน
- ความเสี่ยงจาก Information Disclosure
5.2 บริการที่ใช้ในการ Enumeration
- SMB, NetBIOS, SNMP, DNS, LDAP, RPC
5.3 ข้อมูลที่อาจถูกเปิดเผย
- User Account, Group, Computer Name, Domain Information
- Shared Folder, DNS Record, SNMP Community
- SID
Labs / AI Labs
- Lab 5.1: DNS Enumeration and Zone Transfer Risk
- Lab 5.2: NetBIOS Enumeration using Nmap NSE
- Lab 5.3: SMB and RPC Enumeration
- Lab 5.4: Service Enumeration using Nmap
- Lab 5.5: DNS Network Mapping using DNSmap
- Lab 5.6: SNMP Enumeration using snmpwalk
- AI Lab 5.7: ใช้ AI วิเคราะห์ Enumeration Output
- AI Lab 5.8: สรุปข้อมูลที่เปิดเผย ความเสี่ยง และแนวทาง Hardening
Phase 3: Vulnerability Assessment and System Security
Module 6: Vulnerability Analysis and Risk Prioritization
6.1 แนวคิด Vulnerability Management
- Vulnerability Assessment
- Vulnerability Scanning
- Penetration Testing
- Security Audit
- Configuration Assessment
6.2 มาตรฐานและข้อมูลช่องโหว่
- CVE, CVSS, CWE
- Exploit Database
- Vendor Security Advisory
- Known Exploited Vulnerabilities
- Asset Criticality
- Business Impact
6.3 การวิเคราะห์ผล Scan
- False Positive / False Negative
- Severity
- Exploitability
- Exposure
- Prioritization
- Patch Strategy
- Compensating Control
- Re-scan และ Validation
Labs / AI Labs
- Lab 6.1: Manual Vulnerability Assessment using Nmap
- Lab 6.2: Web Server Vulnerability Assessment using Nikto
- Lab 6.3: วิเคราะห์ผล Vulnerability Scan
- Lab 6.4: จัดลำดับช่องโหว่ตาม Severity และผลกระทบ
- Lab 6.5: จัดทำ Patch and Remediation Plan
- AI Lab 6.6: นำผล Nmap, Nessus หรือ Nikto มาให้ AI สร้าง Remediation Plan
- AI Lab 6.7: จัดทำ Executive Vulnerability Summary
Module 7: Password Security and System Compromise Concepts
7.1 Password and Authentication Security
- Password Hash, Password Policy, Brute Force
- Password Spraying
- Dictionary Attack
- Credential Stuffing
- Multi-Factor Authentication
7.2 System Compromise Lifecycle
- Initial Access and Gaining Access
- Privilege Escalation
- Persistence
- Command Execution
- Lateral Movement
- Evidence and Indicators
- Recovery and Hardening
7.3 Windows และ Linux Security
- User Privilege
- Service Account
- File Permission
- Misconfiguration
- Unpatched Services
- Suspicious Process
- Authentication Log
Labs / AI Labs
- Lab 7.1: Password Auditing using Hydra in an Authorized Lab
- Lab 7.2: MD5 Hash Auditing using John the Ripper
- Lab 7.3: Password Hash Auditing using Hashcat
- Lab 7.4: Simulate Windows System Compromise in a Controlled Lab
- Lab 7.5: ตรวจสอบ Windows Log หลังเกิดเหตุการณ์
- Lab 7.6: เปรียบเทียบ Log ก่อนและหลังการปรับปรุง Password Policy
- AI Lab 7.7: วิเคราะห์ Authentication Log เพื่อค้นหา Brute Force
- AI Lab 7.8: สร้าง Password Security Improvement Plan
Phase 4: Malware, Packet and Human-Centric Threats
Module 8: Malware Threats and Basic Malware Analysis
8.1 ประเภทของ Malware
- Virus, Worm, Trojan, Spyware
- Ransomware
- Remote Access Trojan
- Rootkit
- Logic Bomb
8.2 เทคนิคที่ Malware ใช้
- Obfuscation
- Packing
- Encoding
- Polymorphism
- Persistence
- Process Injection Concept
- Command and Control
8.3 Static และ Dynamic Analysis
- File Hash, File Type
- PE Structure
- Strings
- Import Table
- Process Monitoring
- Network Connection
- Sandbox Analysis
Labs / AI Labs
- Lab 8.1: Process Monitoring and Suspicious Behavior Analysis
- Lab 8.2: Portable Executable Information Analysis
- Lab 8.3: วิเคราะห์ Hash, Strings และ Metadata ของไฟล์ตัวอย่าง
- Lab 8.4: วิเคราะห์พฤติกรรมจาก Sandbox Report
- AI Lab 8.5: ใช้ AI วิเคราะห์ Malware Report และสรุป Indicator
- AI Lab 8.6: Mapping พฤติกรรม Malware เข้ากับ MITRE ATT&CK
Module 9: Packet Capture, Sniffing and Network Attack Detection
9.1 Packet Capture Fundamentals
- Frame, Packet, Segment และ Session
- Capture Filter, Display Filter
- Protocol Analysis
- TCP Stream
- DNS Traffic, HTTP Traffic, TLS Traffic
9.2 ความเสี่ยงจาก Protocol ที่ไม่เข้ารหัส
- Telnet, FTP, HTTP
- Cleartext Authentication
- Plaintext Credential Exposure
9.3 Layer 2 Attack Concepts
- ARP Spoofing
- Man-in-the-Middle
- DHCP Starvation
- MAC Flooding
- Rogue Device
Labs / AI Labs
- Lab 9.1: Detect Cleartext Credential Exposure using Wireshark
- Lab 9.2: Controlled ARP Poisoning using arpspoof
- Lab 9.3: ARP Poisoning Demonstration using Ettercap
- Lab 9.4: วิเคราะห์ TCP Session ด้วย Wireshark
- Lab 9.5: ตรวจสอบ ARP Table ก่อนและหลังเกิด MITM
- Lab 9.6: วิเคราะห์ Firewall และ Network Log จากเหตุการณ์ MITM
- AI Lab 9.7: ใช้ AI วิเคราะห์ Wireshark Summary
- AI Lab 9.8: สรุปพฤติกรรมผิดปกติและแนะนำแนวทางป้องกัน
Module 10: Social Engineering and Phishing Defense
10.1 ประเภทของ Social Engineering
- Phishing, Spear Phishing, Vishing, Smishing
- Pretexting
- Baiting
- Impersonation
- Business Email Compromise
10.2 หลักการทางจิตวิทยา
- Urgency
- Fear
- Authority
- Curiosity
- Trust
- Scarcity
10.3 Phishing Indicators
- Sender Address
- Domain Spoofing
- Suspicious Link
- Attachment
- Language Pattern
- Header Information
- QR Code Phishing
- Fake Login Page
10.4 การป้องกัน
- Security Awareness
- Email Security Gateway
- SPF
- DKIM
- DMARC
- MFA
- User Reporting
- Incident Escalation
Labs / AI Labs
- Lab 10.1: Detect Phishing using PhishTank
- Lab 10.2: วิเคราะห์ตัวอย่าง Phishing Email
- Lab 10.3: ตรวจสอบ Email Header
- Lab 10.4: สร้าง Phishing Awareness Report
- AI Lab 10.5: วิเคราะห์ Phishing Email ด้วย AI
- AI Lab 10.6: สร้างคำแนะนำสำหรับผู้ใช้และ Help Desk
Module 11: Denial-of-Service Detection and Protection
11.1 DoS และ DDoS Concepts
- SYN Flood
- UDP Flood
- ICMP Flood
- HTTP Request Flood
- Slow Connection Attack
- Volumetric Attack
- Application-Layer Attack
11.2 ผลกระทบต่อระบบ
- CPU Utilization, Memory, Bandwidth
- Connection Table
- Service Availability
- Response Time
11.3 การตรวจจับและป้องกัน
- Firewall Session Monitoring
- Rate Limiting
- SYN Protection
- Traffic Shaping
- IPS
- Threshold
- Baseline
- Anomaly Detection
Labs / AI Labs
- Lab 11.1: Generate Controlled SYN Traffic in a Closed Lab
- Lab 11.2: ตรวจสอบ Resource Usage ของ Target
- Lab 11.3: วิเคราะห์ DoS Event จาก Firewall Log
- Lab 11.4: ตั้งค่า Rate Limiting หรือ DoS Protection
- Lab 11.5: ทดสอบก่อนและหลังใช้มาตรการป้องกัน
- AI Lab 11.6: ใช้ AI วิเคราะห์ Traffic Pattern
- AI Lab 11.7: แยก Normal Traffic กับ Suspicious Flood Behavior
Phase 5: Web, Session, Wireless and Cryptographic Security
Module 12: Web Server and Web Application Security
12.1 Web Architecture
- Client
- Web Server
- Application Server
- Database
- API
- Frontend และ Backend
12.2 Web Server Risks
- Misconfiguration
- Default Account
- Exposed Directory
- Outdated Software
- Directory Traversal
- Information Disclosure
- Weak TLS Configuration
12.3 Web Application Risks
- Injection
- Cross-Site Scripting
- Broken Access Control
- Authentication Failure
- IDOR
- CSRF
- Security Misconfiguration
- Vulnerable Components
Labs / AI Labs
- Lab 12.1: Web Server Vulnerability Scanning
- Lab 12.2: Nikto and Directory Discovery
- Lab 12.3: OWASP ZAP Web Application Assessment
- Lab 12.4: Burp Suite Request and Response Analysis
- Lab 12.5: Controlled SQL Injection Validation using DVWA หรือ bWAPP
- Lab 12.6: ตรวจสอบ Web Server Log หลังเกิดเหตุการณ์
- Lab 12.7: ปรับปรุง Input Validation และ Security Control
- AI Lab 12.8: วิเคราะห์ SQL Injection และ Web Attack Log
- AI Lab 12.9: สร้าง Web Application Remediation Plan
Module 13: Session Security and Hijacking Detection
13.1 Session Management
- Session ID
- Cookie
- Token
- Authentication State
- Session Timeout
- Reauthentication
13.2 Session Risks
- Session Fixation
- Session Hijacking
- Cookie Theft
- Cross-Site Scripting
- Insecure Token Storage
- Man-in-the-Middle
13.3 การป้องกัน
- HTTPS
- Secure Flag
- HttpOnly
- SameSite
- Token Rotation
- Session Expiration
- MFA
- Reauthentication
Labs
- Lab 13.1: Session Security Demonstration using Burp Suite
- Lab 13.2: Session Analysis using OWASP ZAP
- Lab 13.3: ตรวจสอบ Cookie Security Attributes
- Lab 13.4: ปรับปรุง Session Security Configuration
Module 14: IDS, IPS, Firewall Evasion Awareness and Honeypots
14.1 IDS และ IPS
- Signature-Based Detection
- Anomaly-Based Detection
- Network IDS
- Host IDS
- Alert และ Block Action
14.2 Evasion Awareness
- Fragmentation
- Encoding
- Obfuscation
- Encryption
- Timing Variation
- Tunneling Concepts
- Detection Limitations
14.3 Honeypot Concepts
- Low-Interaction Honeypot
- High-Interaction Honeypot
- Deception Technology
- Honeypot Log
- Attacker Behavior Observation
Labs / AI Labs
- Lab 14.1: Detect Suspicious Network Traffic using a Honeypot
- Lab 14.2: วิเคราะห์ Honeypot Log
- Lab 14.3: ตรวจสอบผลของ Packet Fragmentation ต่อ IDS
- Lab 14.4: ปรับปรุง Detection Rule
- AI Lab 14.5: วิเคราะห์ IDS/Honeypot Alert และ Mapping กับ ATT&CK
- AI Lab 14.6: เสนอแนวทางปรับปรุง Detection Coverage
Module 15: Wireless Network Security
15.1 Wireless Fundamentals
- SSID
- BSSID
- Channel
- 2.4 GHz, 5 GHz และ 6 GHz
- Access Point
- Client Association
15.2 Wireless Security
- WPA2
- WPA3
- Personal และ Enterprise
- 802.1X
- EAP
- Protected Management Frames
- Client Isolation
15.3 Wireless Threats
- Rogue Access Point
- Evil Twin
- Deauthentication
- Weak Pre-Shared Key
- Misconfiguration
- Unauthorized Client
Labs
- Lab 15.1: Wireless Network Discovery
- Lab 15.2: ตรวจสอบ Channel และ Security Mode
- Lab 15.3: Authorized WPA2 Password Strength Assessment
- Lab 15.4: Evil Twin Awareness Demonstration
- Lab 15.5: Wireless Security Hardening
Module 16: Cryptography, TLS and Certificate Security
16.1 Cryptography Fundamentals
- Plaintext และ Ciphertext
- Encryption และ Decryption
- Symmetric Encryption
- Asymmetric Encryption
- Hashing
- Digital Signature
- Key Management
16.2 Algorithms
- AES, RSA, ECC, SHA-2, SHA-3, HMAC
16.3 TLS และ Digital Certificate
- TLS Handshake
- Public Key Infrastructure
- Certificate Authority
- Certificate Chain
- Certificate Validation
- Expired Certificate
- Self-Signed Certificate
- Weak Cipher Suite
16.4 Cryptographic Risks
- Weak Password Hash
- Replay Attack
- Brute Force
- Key Exposure
- Padding Oracle Concept
- Legacy Protocol
Labs / AI Integration
- Lab 16.1: File Encryption and Decryption using GPG
- Lab 16.2: Hash Generation and Verification
- Lab 16.3: TLS Certificate Inspection
- Lab 16.4: วิเคราะห์ TLS Session ด้วย Wireshark
- Lab 16.5: ตรวจสอบ Weak Cipher และ Certificate Problem
- AI-Assisted Certificate Analysis และ AI ช่วยอธิบาย TLS Configuration
- การใช้ AI โดยไม่เปิดเผย Private Key หรือข้อมูลลับ
Phase 6: Secure Firewall Configuration and AI-Driven Defense
Module 17: Firewall Fundamentals and Security Policy Design
17.1 ประเภทของ Firewall
- Packet Filtering Firewall
- Stateful Firewall
- Application-Layer Firewall
- Next-Generation Firewall
- Host-Based Firewall
- Network Firewall
17.2 Firewall Policy
- Source
- Destination
- Service
- Schedule
- User
- Action
- Logging
- Security Profile
17.3 หลักการออกแบบ Rule Set
- Least Privilege
- Default Deny
- Rule Order
- Specific Rule Before General Rule
- Any-to-Any Risk
- Shadowed Rule
- Duplicate Rule
- Unused Rule
- Rule Review
Labs
- Lab 17.1: Firewall Interface and Internet Connectivity
- Lab 17.2: Basic Firewall Policy
- Lab 17.3: Filter Traffic by Network and Service
- Lab 17.4: Logging Allowed and Denied Traffic
- Lab 17.5: ตรวจสอบ Session และ Policy Match
Module 18: Firewall Network Design, Segmentation and VPN
18.1 Network Segmentation
- Security Zone, User Zone, Server Zone, Management Zone, Guest Zone, DMZ, Inter-Zone Policy
18.2 VLAN และ Routing
- VLAN Interface, Trunk, Access Port, Inter-VLAN Routing
- Routing Table, Static Route
18.3 NAT และ WAN
- Source NAT, Destination NAT
- Port Forwarding, PAT
- Multi-WAN Concept, WAN Connectivity
18.4 Link Aggregation
- LACP
- Redundancy
- Throughput
- Member Interface
- Link Failure
18.5 VPN
- Site-to-Site VPN
- IPsec
- Phase 1 และ Phase 2
- Encryption Domain
- Routing through VPN
- VPN Log
Labs
- Lab 18.1: Link Aggregation Configuration
- Lab 18.2: VLAN and Inter-VLAN Communication
- Lab 18.3: DMZ Network Design
- Lab 18.4: Network Segmentation Policy
- Lab 18.5: WAN-to-WAN Connectivity through FortiGate
- Lab 18.6: Site-to-Site IPsec VPN with Two FortiGates
- Lab 18.7: ตรวจสอบ VPN Log และ Troubleshooting
Module 19: AI-Driven Firewall Log Analysis and Rule Optimization
19.1 Firewall Log Fundamentals
- Traffic Log, Event Log, Security Log, VPN Log
- Source และ Destination
- Service และ Port
- Action
- Policy ID
- User
- Bytes และ Session Duration
19.2 การวิเคราะห์เหตุการณ์
- Port Scan
- Brute Force
- Denied Connection
- Unusual Country Connection
- Malware Communication
- Web Attack
- Policy Violation
- Abnormal Traffic Volume
19.3 AI-Assisted Firewall Management
- Log Summarization
- Event Classification
- Severity Assessment
- MITRE ATT&CK Mapping
- Incident Timeline
- Remediation Recommendation
- Firewall Rule Review
- Duplicate Rule Detection
- Overly Permissive Rule Identification
19.4 Responsible AI for Cybersecurity
- การลบข้อมูลสำคัญก่อนส่งให้ AI
- การปกปิด IP, Username และข้อมูลลูกค้า
- Hallucination
- Human Validation
- Evidence-Based Conclusion
- Cloud AI และ Local AI
- ข้อจำกัดของ AI ในการตัดสินใจด้านความปลอดภัย
AI Labs
- AI Lab 19.1: ใช้ AI วิเคราะห์ FortiGate Traffic Log
- AI Lab 19.2: ตรวจจับ Port Scan และ Brute Force
- AI Lab 19.3: สร้าง Incident Summary
- AI Lab 19.4: Mapping เหตุการณ์กับ MITRE ATT&CK
- AI Lab 19.5: ใช้ AI ตรวจสอบ Firewall Rule ที่ซ้ำซ้อน
- AI Lab 19.6: จัดทำ Remediation and Prevention Plan
- AI Lab 19.7: สร้าง Executive Security Report