Cybersecurity Operations & Defense Bootcamp with AI-Driven Threat Analysis and Firewall Management

Attack  →  Observe  →  Analyze  →  Defend

วัตถุประสงค์ของหลักสูตร

  • สร้างความเข้าใจพื้นฐานเกี่ยวกับภัยคุกคาม ช่องโหว่ ความเสี่ยง และรูปแบบการโจมตีทางไซเบอร์
  • ให้ผู้เรียนเข้าใจมุมมองและกระบวนการของผู้โจมตี เพื่อนำไปสู่การตรวจจับและป้องกันที่มีประสิทธิภาพ
  • ฝึกใช้เครื่องมือมาตรฐานด้าน Cybersecurity เช่น Nmap, Wireshark, OpenVAS/Greenbone, Nikto, OWASP ZAP, Burp Suite และเครื่องมือวิเคราะห์ระบบ
  • ฝึกวิเคราะห์ Network Traffic, Authentication Log, Web Log และ Firewall Log เพื่อค้นหาพฤติกรรมผิดปกติ
  • ประยุกต์ใช้ MITRE ATT&CK เพื่อ Mapping พฤติกรรมและเชื่อมโยงกับมาตรการตรวจจับและป้องกัน
  • ใช้ AI ช่วยวิเคราะห์ Log, Vulnerability Findings, Firewall Events และสร้าง Remediation Plan โดยมี Human Validation
  • ออกแบบและบริหาร Firewall, VLAN, DMZ, Network Segmentation, NAT/PAT และ Site-to-Site IPsec VPN
  • เชื่อมโยงความรู้ทั้งหมดผ่าน Final Capstone แบบ Attack → Evidence → AI Analysis → Defense

ผู้ที่เหมาะกับหลักสูตร

  • Network Engineer / Network Administrator
  • System Administrator / IT Support
  • Firewall Administrator
  • Cybersecurity Analyst / SOC Analyst ระดับเริ่มต้น
  • Security Engineer
  • IT Manager / IT Supervisor / Team Lead
  • ผู้ที่ต้องการเริ่มต้นสายงาน Cybersecurity
  • ผู้ดูแลระบบหรือเจ้าของกิจการที่ต้องการเข้าใจความเสี่ยงและการป้องกันระบบขององค์กร

ผลลัพธ์หลังจบหลักสูตร

  • อธิบายภัยคุกคาม ช่องโหว่ ความเสี่ยง และรูปแบบการโจมตีได้
  • สำรวจและประเมิน Attack Surface ในระบบที่ได้รับอนุญาต
  • ใช้ Nmap, Wireshark, OpenVAS/Greenbone และเครื่องมือพื้นฐานด้าน Cybersecurity
  • วิเคราะห์ Vulnerability Scan และจัดลำดับความสำคัญของการแก้ไข
  • ตรวจสอบ Authentication, Network, Web และ Firewall Log
  • ระบุพฤติกรรม Port Scan, Brute Force, Web Attack และ Malware Communication
  • Mapping เหตุการณ์กับ MITRE ATT&CK
  • ออกแบบ Firewall Policy, VLAN, DMZ และ Network Segmentation
  • ติดตั้ง Site-to-Site IPsec VPN
  • ใช้ AI ช่วยวิเคราะห์ Log และสร้าง Remediation Plan
  • ตรวจสอบความถูกต้องและข้อจำกัดของผลลัพธ์จาก AI
  • จัดทำ Incident Summary และ Executive Summary เบื้องต้น
  •  
  • รายละเอียดหลักสูตร

Phase 1: Cybersecurity Fundamentals and Security Architecture

Module 1: Cybersecurity Threats, Vulnerabilities and Risks

1.1 พื้นฐานภัยคุกคามทางไซเบอร์

  • ความหมายของ Threat, Vulnerability, Exploit และ Risk
  • ความสัมพันธ์ระหว่าง Asset, Threat, Vulnerability และ Impact
  • ประเภทภัยคุกคาม: Malware, Phishing, Social Engineering, DoS/DDoS, Insider Threat, Credential Attack, Web Application Attack
  • Attack Surface และ Attack Vector
  • ช่องทางการโจมตีผ่าน Email, USB, Website, Remote Access, Wireless Network, Cloud Service และ Social Media

1.2 กระบวนการโจมตีทางไซเบอร์

  • Reconnaissance, Scanning, Enumeration และ Exploitation
  • Privilege Escalation, Persistence และ Lateral Movement
  • Data Collection, Exfiltration และ Impact

1.3 MITRE ATT&CK Framework เบื้องต้น

  • ความหมายของ Tactic, Technique และ Procedure (TTPs)
  • การใช้ MITRE ATT&CK วิเคราะห์พฤติกรรมผู้โจมตี
  • การ Mapping เหตุการณ์กับ ATT&CK Technique
  • การใช้ ATT&CK เพื่อออกแบบมาตรการตรวจจับและป้องกัน

Labs / AI Labs

  • Lab 1.1: วิเคราะห์ตัวอย่างเหตุการณ์และแยก Threat, Vulnerability และ Risk
  • Lab 1.2: Mapping ตัวอย่างการโจมตีกับ MITRE ATT&CK
  • AI Lab 1.3: ใช้ AI วิเคราะห์ Log ตัวอย่างและระบุประเภทการโจมตีตาม MITRE ATT&CK

Module 2: Network Security Controls, Protocols and Devices

2.1 Network Security Controls

  • ACL, VLAN, Network Segmentation, Port Security, NAT และ PAT
  • Least Privilege, Default Deny และ Defense in Depth

2.2 อุปกรณ์ด้านความปลอดภัย

  • Router และ Layer 3 Switch
  • Firewall / Next-Generation Firewall
  • IDS/IPS, Proxy Server, Web Application Firewall, VPN Gateway และ SIEM เบื้องต้น

2.3 Security Protocols

  • SSH, TLS, IPsec, SNMPv3, HTTPS และ Secure Remote Access

2.4 แนวคิดการป้องกันสมัยใหม่

  • Detection vs Prevention
  • Zero Trust Architecture
  • Identity-Based Access
  • Network Micro-Segmentation
  • User and Entity Behavior Analytics (UEBA)
  • Anomaly Detection

AI Integration

  • แนวคิด AI-Driven Micro-Segmentation
  • การใช้ AI วิเคราะห์พฤติกรรมผู้ใช้และอุปกรณ์
  • Rule-Based Detection เทียบกับ AI-Based Anomaly Detection

Phase 2: Reconnaissance and Attack Surface Discovery

Module 3: Footprinting, OSINT and Reconnaissance

3.1 แนวคิด Reconnaissance

  • Passive Reconnaissance
  • Active Reconnaissance
  • Footprinting
  • Open Source Intelligence (OSINT)
  • ขอบเขตและจริยธรรมของ OSINT

3.2 ข้อมูลที่ผู้โจมตีต้องการค้นหา

  • Domain Name, Email Address, IP Address และ IP Block, DNS Record
  • Employee Information
  • Metadata
  • Social Footprint
  • Technology Stack
  • Publicly Exposed Services

Labs

  • Lab 3.1: Gathering Information using Metasploit
  • Lab 3.2: Gathering Email Information using theHarvester
  • Lab 3.3: วิเคราะห์ Email Header และเส้นทางการส่งอีเมล
  • Lab 3.4: Footprinting a Target using Recon-ng
  • Lab 3.5: Footprinting and Relationship Mapping using Maltego

3.3 AI Integration / AI Lab

  • ใช้ AI ช่วยสรุปข้อมูล OSINT และวิเคราะห์ความสัมพันธ์ของข้อมูล
  • ใช้ AI ช่วยสร้างคำค้นหาเพื่อการตรวจสอบข้อมูลสาธารณะ
  • ใช้ AI ช่วยเขียน Python Script สำหรับดึง Metadata จากไฟล์ในระบบ Lab
  • AI Lab 3.6: นำผล OSINT มาให้ AI ช่วยสรุป Attack Surface และเสนอแนวทางลดการเปิดเผยข้อมูล

Module 4: Network Scanning and Service Discovery

4.1 แนวคิด Network Scanning

  • Host Discovery, Service Discovery
  • Port Scanning, TCP และ UDP Scanning
  • Network Mapping

4.2 TCP Flags และ Scan Types

  • TCP Three-Way Handshake
  • SYN Scan, FIN Scan, NULL Scan, XMAS Scan, TCP Connect Scan, UDP Scan

4.3  OS และ Service Fingerprinting

  • Operating System Detection, Service Version Detection
  • Banner Grabbing
  • Nmap Service Scripts
  • Network Latency และ Scan Timing

Labs / AI Labs

  • Lab 4.1: Port and Service Discovery
  • Lab 4.2: Network Scanning using hping3
  • Lab 4.3: Host Discovery using Netdiscover
  • Lab 4.4: Network Scanning using Metasploit
  • Lab 4.5: Nmap Vulnerability and Script Scanning
  • Lab 4.6: Nmap OS and Service Detection
  • Lab 4.7: ตรวจสอบ Firewall Log ที่เกิดจาก Port Scan
  • AI Lab 4.8: ใช้ AI วิเคราะห์ Nmap Output และสรุปบริการที่มีความเสี่ยง
  • AI Lab 4.9: ใช้ AI แนะนำขั้นตอนการตรวจสอบและป้องกันต่อไป

Module 5: Enumeration and Service Exposure Analysis

5.1 แนวคิด Enumeration

  • ความแตกต่างระหว่าง Scanning และ Enumeration
  • การรวบรวมรายละเอียดจากบริการที่เปิดใช้งาน
  • ความเสี่ยงจาก Information Disclosure

5.2 บริการที่ใช้ในการ Enumeration

  • SMB, NetBIOS, SNMP, DNS, LDAP, RPC

5.3 ข้อมูลที่อาจถูกเปิดเผย

  • User Account, Group, Computer Name, Domain Information
  • Shared Folder, DNS Record, SNMP Community
  • SID

Labs / AI Labs

  • Lab 5.1: DNS Enumeration and Zone Transfer Risk
  • Lab 5.2: NetBIOS Enumeration using Nmap NSE
  • Lab 5.3: SMB and RPC Enumeration
  • Lab 5.4: Service Enumeration using Nmap
  • Lab 5.5: DNS Network Mapping using DNSmap
  • Lab 5.6: SNMP Enumeration using snmpwalk
  • AI Lab 5.7: ใช้ AI วิเคราะห์ Enumeration Output
  • AI Lab 5.8: สรุปข้อมูลที่เปิดเผย ความเสี่ยง และแนวทาง Hardening

Phase 3: Vulnerability Assessment and System Security

Module 6: Vulnerability Analysis and Risk Prioritization

6.1 แนวคิด Vulnerability Management

  • Vulnerability Assessment
  • Vulnerability Scanning
  • Penetration Testing
  • Security Audit
  • Configuration Assessment

6.2 มาตรฐานและข้อมูลช่องโหว่

  • CVE, CVSS, CWE
  • Exploit Database
  • Vendor Security Advisory
  • Known Exploited Vulnerabilities
  • Asset Criticality
  • Business Impact

6.3 การวิเคราะห์ผล Scan

  • False Positive / False Negative
  • Severity
  • Exploitability
  • Exposure
  • Prioritization
  • Patch Strategy
  • Compensating Control
  • Re-scan และ Validation

Labs / AI Labs

  • Lab 6.1: Manual Vulnerability Assessment using Nmap
  • Lab 6.2: Web Server Vulnerability Assessment using Nikto
  • Lab 6.3: วิเคราะห์ผล Vulnerability Scan
  • Lab 6.4: จัดลำดับช่องโหว่ตาม Severity และผลกระทบ
  • Lab 6.5: จัดทำ Patch and Remediation Plan
  • AI Lab 6.6: นำผล Nmap, Nessus หรือ Nikto มาให้ AI สร้าง Remediation Plan
  • AI Lab 6.7: จัดทำ Executive Vulnerability Summary

Module 7: Password Security and System Compromise Concepts

7.1 Password and Authentication Security

  • Password Hash, Password Policy, Brute Force
  • Password Spraying
  • Dictionary Attack
  • Credential Stuffing
  • Multi-Factor Authentication

7.2 System Compromise Lifecycle

  • Initial Access and Gaining Access
  • Privilege Escalation
  • Persistence
  • Command Execution
  • Lateral Movement
  • Evidence and Indicators
  • Recovery and Hardening

7.3 Windows และ Linux Security

  • User Privilege
  • Service Account
  • File Permission
  • Misconfiguration
  • Unpatched Services
  • Suspicious Process
  • Authentication Log

Labs / AI Labs

  • Lab 7.1: Password Auditing using Hydra in an Authorized Lab
  • Lab 7.2: MD5 Hash Auditing using John the Ripper
  • Lab 7.3: Password Hash Auditing using Hashcat
  • Lab 7.4: Simulate Windows System Compromise in a Controlled Lab
  • Lab 7.5: ตรวจสอบ Windows Log หลังเกิดเหตุการณ์
  • Lab 7.6: เปรียบเทียบ Log ก่อนและหลังการปรับปรุง Password Policy
  • AI Lab 7.7: วิเคราะห์ Authentication Log เพื่อค้นหา Brute Force
  • AI Lab 7.8: สร้าง Password Security Improvement Plan

Phase 4: Malware, Packet and Human-Centric Threats

Module 8: Malware Threats and Basic Malware Analysis

8.1 ประเภทของ Malware

  • Virus, Worm, Trojan, Spyware
  • Ransomware
  • Remote Access Trojan
  • Rootkit
  • Logic Bomb

8.2 เทคนิคที่ Malware ใช้

  • Obfuscation
  • Packing
  • Encoding
  • Polymorphism
  • Persistence
  • Process Injection Concept
  • Command and Control

8.3 Static และ Dynamic Analysis

  • File Hash, File Type
  • PE Structure
  • Strings
  • Import Table
  • Process Monitoring
  • Network Connection
  • Sandbox Analysis

Labs / AI Labs

  • Lab 8.1: Process Monitoring and Suspicious Behavior Analysis
  • Lab 8.2: Portable Executable Information Analysis
  • Lab 8.3: วิเคราะห์ Hash, Strings และ Metadata ของไฟล์ตัวอย่าง
  • Lab 8.4: วิเคราะห์พฤติกรรมจาก Sandbox Report
  • AI Lab 8.5: ใช้ AI วิเคราะห์ Malware Report และสรุป Indicator
  • AI Lab 8.6: Mapping พฤติกรรม Malware เข้ากับ MITRE ATT&CK

Module 9: Packet Capture, Sniffing and Network Attack Detection

9.1 Packet Capture Fundamentals

  • Frame, Packet, Segment และ Session
  • Capture Filter, Display Filter
  • Protocol Analysis
  • TCP Stream
  • DNS Traffic, HTTP Traffic, TLS Traffic

9.2 ความเสี่ยงจาก Protocol ที่ไม่เข้ารหัส

  • Telnet, FTP, HTTP
  • Cleartext Authentication
  • Plaintext Credential Exposure

9.3 Layer 2 Attack Concepts

  • ARP Spoofing
  • Man-in-the-Middle
  • DHCP Starvation
  • MAC Flooding
  • Rogue Device

Labs / AI Labs

  • Lab 9.1: Detect Cleartext Credential Exposure using Wireshark
  • Lab 9.2: Controlled ARP Poisoning using arpspoof
  • Lab 9.3: ARP Poisoning Demonstration using Ettercap
  • Lab 9.4: วิเคราะห์ TCP Session ด้วย Wireshark
  • Lab 9.5: ตรวจสอบ ARP Table ก่อนและหลังเกิด MITM
  • Lab 9.6: วิเคราะห์ Firewall และ Network Log จากเหตุการณ์ MITM
  • AI Lab 9.7: ใช้ AI วิเคราะห์ Wireshark Summary
  • AI Lab 9.8: สรุปพฤติกรรมผิดปกติและแนะนำแนวทางป้องกัน

Module 10: Social Engineering and Phishing Defense

10.1 ประเภทของ Social Engineering

  • Phishing, Spear Phishing, Vishing, Smishing
  • Pretexting
  • Baiting
  • Impersonation
  • Business Email Compromise

10.2 หลักการทางจิตวิทยา

  • Urgency
  • Fear
  • Authority
  • Curiosity
  • Trust
  • Scarcity

10.3 Phishing Indicators

  • Sender Address
  • Domain Spoofing
  • Suspicious Link
  • Attachment
  • Language Pattern
  • Header Information
  • QR Code Phishing
  • Fake Login Page

10.4 การป้องกัน

  • Security Awareness
  • Email Security Gateway
  • SPF
  • DKIM
  • DMARC
  • MFA
  • User Reporting
  • Incident Escalation

Labs / AI Labs

  • Lab 10.1: Detect Phishing using PhishTank
  • Lab 10.2: วิเคราะห์ตัวอย่าง Phishing Email
  • Lab 10.3: ตรวจสอบ Email Header
  • Lab 10.4: สร้าง Phishing Awareness Report
  • AI Lab 10.5: วิเคราะห์ Phishing Email ด้วย AI
  • AI Lab 10.6: สร้างคำแนะนำสำหรับผู้ใช้และ Help Desk

Module 11: Denial-of-Service Detection and Protection

11.1 DoS และ DDoS Concepts

  • SYN Flood
  • UDP Flood
  • ICMP Flood
  • HTTP Request Flood
  • Slow Connection Attack
  • Volumetric Attack
  • Application-Layer Attack

11.2 ผลกระทบต่อระบบ

  • CPU Utilization, Memory, Bandwidth
  • Connection Table
  • Service Availability
  • Response Time

11.3 การตรวจจับและป้องกัน

  • Firewall Session Monitoring
  • Rate Limiting
  • SYN Protection
  • Traffic Shaping
  • IPS
  • Threshold
  • Baseline
  • Anomaly Detection

Labs / AI Labs

  • Lab 11.1: Generate Controlled SYN Traffic in a Closed Lab
  • Lab 11.2: ตรวจสอบ Resource Usage ของ Target
  • Lab 11.3: วิเคราะห์ DoS Event จาก Firewall Log
  • Lab 11.4: ตั้งค่า Rate Limiting หรือ DoS Protection
  • Lab 11.5: ทดสอบก่อนและหลังใช้มาตรการป้องกัน
  • AI Lab 11.6: ใช้ AI วิเคราะห์ Traffic Pattern
  • AI Lab 11.7: แยก Normal Traffic กับ Suspicious Flood Behavior

Phase 5: Web, Session, Wireless and Cryptographic Security

Module 12: Web Server and Web Application Security

12.1 Web Architecture

  • Client
  • Web Server
  • Application Server
  • Database
  • API
  • Frontend และ Backend

12.2 Web Server Risks

  • Misconfiguration
  • Default Account
  • Exposed Directory
  • Outdated Software
  • Directory Traversal
  • Information Disclosure
  • Weak TLS Configuration

12.3 Web Application Risks

  • Injection
  • Cross-Site Scripting
  • Broken Access Control
  • Authentication Failure
  • IDOR
  • CSRF
  • Security Misconfiguration
  • Vulnerable Components

Labs / AI Labs

  • Lab 12.1: Web Server Vulnerability Scanning
  • Lab 12.2: Nikto and Directory Discovery
  • Lab 12.3: OWASP ZAP Web Application Assessment
  • Lab 12.4: Burp Suite Request and Response Analysis
  • Lab 12.5: Controlled SQL Injection Validation using DVWA หรือ bWAPP
  • Lab 12.6: ตรวจสอบ Web Server Log หลังเกิดเหตุการณ์
  • Lab 12.7: ปรับปรุง Input Validation และ Security Control
  • AI Lab 12.8: วิเคราะห์ SQL Injection และ Web Attack Log
  • AI Lab 12.9: สร้าง Web Application Remediation Plan

Module 13: Session Security and Hijacking Detection

13.1 Session Management

  • Session ID
  • Cookie
  • Token
  • Authentication State
  • Session Timeout
  • Reauthentication

13.2 Session Risks

  • Session Fixation
  • Session Hijacking
  • Cookie Theft
  • Cross-Site Scripting
  • Insecure Token Storage
  • Man-in-the-Middle

13.3 การป้องกัน

  • HTTPS
  • Secure Flag
  • HttpOnly
  • SameSite
  • Token Rotation
  • Session Expiration
  • MFA
  • Reauthentication

Labs

  • Lab 13.1: Session Security Demonstration using Burp Suite
  • Lab 13.2: Session Analysis using OWASP ZAP
  • Lab 13.3: ตรวจสอบ Cookie Security Attributes
  • Lab 13.4: ปรับปรุง Session Security Configuration

Module 14: IDS, IPS, Firewall Evasion Awareness and Honeypots

14.1 IDS และ IPS

  • Signature-Based Detection
  • Anomaly-Based Detection
  • Network IDS
  • Host IDS
  • Alert และ Block Action

14.2 Evasion Awareness

  • Fragmentation
  • Encoding
  • Obfuscation
  • Encryption
  • Timing Variation
  • Tunneling Concepts
  • Detection Limitations

14.3 Honeypot Concepts

  • Low-Interaction Honeypot
  • High-Interaction Honeypot
  • Deception Technology
  • Honeypot Log
  • Attacker Behavior Observation

Labs / AI Labs

  • Lab 14.1: Detect Suspicious Network Traffic using a Honeypot
  • Lab 14.2: วิเคราะห์ Honeypot Log
  • Lab 14.3: ตรวจสอบผลของ Packet Fragmentation ต่อ IDS
  • Lab 14.4: ปรับปรุง Detection Rule
  • AI Lab 14.5: วิเคราะห์ IDS/Honeypot Alert และ Mapping กับ ATT&CK
  • AI Lab 14.6: เสนอแนวทางปรับปรุง Detection Coverage

Module 15: Wireless Network Security

15.1 Wireless Fundamentals

  • SSID
  • BSSID
  • Channel
  • 2.4 GHz, 5 GHz และ 6 GHz
  • Access Point
  • Client Association

15.2 Wireless Security

  • WPA2
  • WPA3
  • Personal และ Enterprise
  • 802.1X
  • EAP
  • Protected Management Frames
  • Client Isolation

15.3 Wireless Threats

  • Rogue Access Point
  • Evil Twin
  • Deauthentication
  • Weak Pre-Shared Key
  • Misconfiguration
  • Unauthorized Client

Labs

  • Lab 15.1: Wireless Network Discovery
  • Lab 15.2: ตรวจสอบ Channel และ Security Mode
  • Lab 15.3: Authorized WPA2 Password Strength Assessment
  • Lab 15.4: Evil Twin Awareness Demonstration
  • Lab 15.5: Wireless Security Hardening

Module 16: Cryptography, TLS and Certificate Security

16.1 Cryptography Fundamentals

  • Plaintext และ Ciphertext
  • Encryption และ Decryption
  • Symmetric Encryption
  • Asymmetric Encryption
  • Hashing
  • Digital Signature
  • Key Management

16.2 Algorithms

  • AES, RSA, ECC, SHA-2, SHA-3, HMAC

16.3 TLS และ Digital Certificate

  • TLS Handshake
  • Public Key Infrastructure
  • Certificate Authority
  • Certificate Chain
  • Certificate Validation
  • Expired Certificate
  • Self-Signed Certificate
  • Weak Cipher Suite

16.4 Cryptographic Risks

  • Weak Password Hash
  • Replay Attack
  • Brute Force
  • Key Exposure
  • Padding Oracle Concept
  • Legacy Protocol

Labs / AI Integration

  • Lab 16.1: File Encryption and Decryption using GPG
  • Lab 16.2: Hash Generation and Verification
  • Lab 16.3: TLS Certificate Inspection
  • Lab 16.4: วิเคราะห์ TLS Session ด้วย Wireshark
  • Lab 16.5: ตรวจสอบ Weak Cipher และ Certificate Problem
  • AI-Assisted Certificate Analysis และ AI ช่วยอธิบาย TLS Configuration
  • การใช้ AI โดยไม่เปิดเผย Private Key หรือข้อมูลลับ

Phase 6: Secure Firewall Configuration and AI-Driven Defense

Module 17: Firewall Fundamentals and Security Policy Design

17.1 ประเภทของ Firewall

  • Packet Filtering Firewall
  • Stateful Firewall
  • Application-Layer Firewall
  • Next-Generation Firewall
  • Host-Based Firewall
  • Network Firewall

17.2 Firewall Policy

  • Source
  • Destination
  • Service
  • Schedule
  • User
  • Action
  • Logging
  • Security Profile

17.3 หลักการออกแบบ Rule Set

  • Least Privilege
  • Default Deny
  • Rule Order
  • Specific Rule Before General Rule
  • Any-to-Any Risk
  • Shadowed Rule
  • Duplicate Rule
  • Unused Rule
  • Rule Review

Labs

  • Lab 17.1: Firewall Interface and Internet Connectivity
  • Lab 17.2: Basic Firewall Policy
  • Lab 17.3: Filter Traffic by Network and Service
  • Lab 17.4: Logging Allowed and Denied Traffic
  • Lab 17.5: ตรวจสอบ Session และ Policy Match

Module 18: Firewall Network Design, Segmentation and VPN

18.1 Network Segmentation

  • Security Zone, User Zone, Server Zone, Management Zone, Guest Zone, DMZ, Inter-Zone Policy

18.2 VLAN และ Routing

  • VLAN Interface, Trunk, Access Port, Inter-VLAN Routing
  • Routing Table, Static Route

18.3 NAT และ WAN

  • Source NAT,  Destination NAT
  • Port Forwarding, PAT
  • Multi-WAN Concept, WAN Connectivity

18.4 Link Aggregation

  • LACP
  • Redundancy
  • Throughput
  • Member Interface
  • Link Failure

18.5 VPN

  • Site-to-Site VPN
  • IPsec
  • Phase 1 และ Phase 2
  • Encryption Domain
  • Routing through VPN
  • VPN Log

Labs

  • Lab 18.1: Link Aggregation Configuration
  • Lab 18.2: VLAN and Inter-VLAN Communication
  • Lab 18.3: DMZ Network Design
  • Lab 18.4: Network Segmentation Policy
  • Lab 18.5: WAN-to-WAN Connectivity through FortiGate
  • Lab 18.6: Site-to-Site IPsec VPN with Two FortiGates
  • Lab 18.7: ตรวจสอบ VPN Log และ Troubleshooting

Module 19: AI-Driven Firewall Log Analysis and Rule Optimization

19.1 Firewall Log Fundamentals

  • Traffic Log, Event Log, Security Log, VPN Log
  • Source และ Destination
  • Service และ Port
  • Action
  • Policy ID
  • User
  • Bytes และ Session Duration

19.2 การวิเคราะห์เหตุการณ์

  • Port Scan
  • Brute Force
  • Denied Connection
  • Unusual Country Connection
  • Malware Communication
  • Web Attack
  • Policy Violation
  • Abnormal Traffic Volume

19.3 AI-Assisted Firewall Management

  • Log Summarization
  • Event Classification
  • Severity Assessment
  • MITRE ATT&CK Mapping
  • Incident Timeline
  • Remediation Recommendation
  • Firewall Rule Review
  • Duplicate Rule Detection
  • Overly Permissive Rule Identification

19.4 Responsible AI for Cybersecurity

  • การลบข้อมูลสำคัญก่อนส่งให้ AI
  • การปกปิด IP, Username และข้อมูลลูกค้า
  • Hallucination
  • Human Validation
  • Evidence-Based Conclusion
  • Cloud AI และ Local AI
  • ข้อจำกัดของ AI ในการตัดสินใจด้านความปลอดภัย

AI Labs

  • AI Lab 19.1: ใช้ AI วิเคราะห์ FortiGate Traffic Log
  • AI Lab 19.2: ตรวจจับ Port Scan และ Brute Force
  • AI Lab 19.3: สร้าง Incident Summary
  • AI Lab 19.4: Mapping เหตุการณ์กับ MITRE ATT&CK
  • AI Lab 19.5: ใช้ AI ตรวจสอบ Firewall Rule ที่ซ้ำซ้อน
  • AI Lab 19.6: จัดทำ Remediation and Prevention Plan
  • AI Lab 19.7: สร้าง Executive Security Report