{"id":66851,"date":"2026-06-26T09:21:24","date_gmt":"2026-06-26T02:21:24","guid":{"rendered":"https:\/\/aws.cmctelecom.vn\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/"},"modified":"2026-06-30T17:45:55","modified_gmt":"2026-06-30T10:45:55","slug":"aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may","status":"publish","type":"post","link":"https:\/\/aws.cmctelecom.vn\/en\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/","title":{"rendered":"AWS: X\u00e2y d\u1ef1ng ph\u00f2ng tuy\u1ebfn nhi\u1ec1u l\u1edbp ch\u1ed1ng th\u1ea5t tho\u00e1t d\u1eef li\u1ec7u \u0111\u00e1m m\u00e2y"},"content":{"rendered":"<p>Trong khi c\u00e1c doanh nghi\u1ec7p t\u1eadp trung b\u1ea3o v\u1ec7 h\u1ec7 th\u1ed1ng kh\u1ecfi c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng t\u1eeb b\u00ean ngo\u00e0i, lu\u1ed3ng d\u1eef li\u1ec7u \u0111i ra (egress) th\u01b0\u1eddng b\u1ecb xem nh\u1eb9, t\u1ea1o ra m\u1ed9t \u0111i\u1ec3m m\u00f9 b\u1ea3o m\u1eadt nghi\u00eam tr\u1ecdng. Vi\u1ec7c b\u1ecf qua ki\u1ec3m so\u00e1t egress c\u00f3 th\u1ec3 d\u1eabn \u0111\u1ebfn r\u00f2 r\u1ec9 d\u1eef li\u1ec7u nh\u1ea1y c\u1ea3m, d\u00f9 l\u00e0 do c\u1ea5u h\u00ecnh sai, quy\u1ec1n truy c\u1eadp qu\u00e1 r\u1ed9ng, hay th\u1eadm ch\u00ed l\u00e0 do c\u00e1c AI agent b\u1ecb thao t\u00fang. AWS \u0111\u00e3 \u0111\u01b0a ra m\u1ed9t chi\u1ebfn l\u01b0\u1ee3c b\u1ea3o m\u1eadt to\u00e0n di\u1ec7n, nhi\u1ec1u l\u1edbp \u0111\u1ec3 gi\u00fap doanh nghi\u1ec7p ki\u1ec3m so\u00e1t ch\u1eb7t ch\u1ebd lu\u1ed3ng d\u1eef li\u1ec7u \u0111i ra, b\u1ea3o v\u1ec7 t\u00e0i s\u1ea3n s\u1ed1 tr\u01b0\u1edbc c\u00e1c m\u1ed1i \u0111e d\u1ecda ng\u00e0y c\u00e0ng tinh vi.<\/p>\n<p>C\u00e1c s\u1ef1 c\u1ed1 th\u1ef1c t\u1ebf cho th\u1ea5y t\u1ea7m quan tr\u1ecdng c\u1ee7a vi\u1ec7c ki\u1ec3m so\u00e1t egress, \u00e1p d\u1ee5ng cho c\u1ea3 c\u00e1c workload \u0111\u00e1m m\u00e2y truy\u1ec1n th\u1ed1ng v\u00e0 ki\u1ebfn tr\u00fac d\u1ef1a tr\u00ean AI m\u1edbi n\u1ed5i. V\u00ed d\u1ee5, l\u1ed7 h\u1ed5ng <strong>React2Shell (CVE-2025-55182)<\/strong> \u0111\u01b0\u1ee3c c\u00f4ng b\u1ed1 v\u00e0o th\u00e1ng 12\/2025 \u0111\u00e3 b\u1ecb khai th\u00e1c ch\u1ec9 trong v\u00e0i gi\u1edd \u0111\u1ec3 th\u1ef1c thi m\u00e3 t\u1eeb xa. Sau khi x\u00e2m nh\u1eadp, k\u1ebb t\u1ea5n c\u00f4ng th\u01b0\u1eddng thi\u1ebft l\u1eadp k\u00eanh ch\u1ec9 huy v\u00e0 ki\u1ec3m so\u00e1t (command-and-control) h\u01b0\u1edbng ra ngo\u00e0i \u0111\u1ec3 l\u1ea5y c\u1eafp d\u1eef li\u1ec7u. T\u01b0\u01a1ng t\u1ef1, c\u00e1c h\u1ec7 th\u1ed1ng <strong>AI agent<\/strong> c\u0169ng mang \u0111\u1ebfn r\u1ee7i ro m\u1edbi, nh\u01b0 vi\u1ec7c b\u1ecb chi\u1ebfm quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n m\u1ee5c ti\u00eau (<em>Agent Goal Hijack<\/em>) \u0111\u1ec3 \u00e2m th\u1ea7m tu\u1ed3n d\u1eef li\u1ec7u ra ngo\u00e0i. \u0110i\u1ec3m chung c\u1ee7a c\u00e1c k\u1ecbch b\u1ea3n n\u00e0y l\u00e0 lu\u1ed3ng traffic \u0111i ra ngo\u00e0i tr\u00e1i ph\u00e9p.<\/p>\n<p>B\u00e0i vi\u1ebft n\u00e0y s\u1ebd tr\u00ecnh b\u00e0y c\u00e1ch tri\u1ec3n khai c\u00e1c l\u1edbp ph\u00e1t hi\u1ec7n v\u00e0 b\u1ea3o v\u1ec7 egress b\u1eb1ng c\u00e1c d\u1ecbch v\u1ee5 c\u1ee7a AWS, gi\u00fap gi\u1ea3m thi\u1ec3u r\u1ee7i ro th\u1ea5t tho\u00e1t d\u1eef li\u1ec7u t\u1eeb c\u1ea3 \u1ee9ng d\u1ee5ng b\u1ecb x\u00e2m nh\u1eadp v\u00e0 AI agent b\u1ecb thao t\u00fang.<\/p>\n<h2>T\u1ed5ng quan ki\u1ebfn tr\u00fac<\/h2>\n<p>Ki\u1ebfn tr\u00fac d\u01b0\u1edbi \u0111\u00e2y minh h\u1ecda m\u1ed9t c\u00e1ch ti\u1ebfp c\u1eadn tri\u1ec3n khai m\u00f4 h\u00ecnh m\u1ea1ng hub-and-spoke cho m\u00f4i tr\u01b0\u1eddng AWS \u0111a t\u00e0i kho\u1ea3n. C\u00e1c workload \u1ee9ng d\u1ee5ng n\u1eb1m trong c\u00e1c <strong>spoke virtual private clouds (VPC)<\/strong>, k\u1ebft n\u1ed1i v\u1edbi m\u1ed9t <strong>AWS Transit Gateway<\/strong> \u0111\u00f3ng vai tr\u00f2 l\u00e0 trung t\u00e2m \u0111\u1ecbnh tuy\u1ebfn. Lu\u1ed3ng traffic \u0111i ra Internet \u0111\u01b0\u1ee3c \u0111\u1ecbnh tuy\u1ebfn qua <strong>AWS Network Firewall<\/strong> \u0111\u1ec3 ki\u1ec3m tra v\u00e0 l\u1ecdc tr\u01b0\u1edbc khi ra ngo\u00e0i.<\/p>\n<figure class=\"wp-block-image size-large aligncenter\" style=\"text-align:center;margin:1.5em 0;\">\n<img decoding=\"async\" data-src=\"https:\/\/aws.cmctelecom.vn\/wp-content\/uploads\/2026\/06\/ffe2e35fd9.png\" alt=\"S\u01a1 \u0111\u1ed3 ki\u1ebfn tr\u00fac ki\u1ec3m so\u00e1t egress theo m\u00f4 h\u00ecnh hub-and-spoke tr\u00ean AWS.\" style=\"--smush-placeholder-width: 1414px; --smush-placeholder-aspect-ratio: 1414\/1732;border-radius:8px;border:1px solid #e5e7eb;max-width:100%;max-height:560px;width:auto;height:auto;display:inline-block;\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\"><br \/>\n<\/figure>\n<p>C\u00e1c th\u00e0nh ph\u1ea7n ch\u00ednh trong ki\u1ebfn tr\u00fac n\u00e0y bao g\u1ed3m:<\/p>\n<ul>\n<li><strong>L\u1edbp ph\u00f2ng ng\u1eeba:<\/strong> S\u1eed d\u1ee5ng <strong>AWS Network Firewall<\/strong>, <strong>Amazon Route 53 Resolver DNS Firewall<\/strong>, v\u00e0 c\u00e1c v\u00e0nh \u0111ai d\u1eef li\u1ec7u (<strong>Data Perimeters<\/strong>) \u0111\u1ec3 ch\u1eb7n c\u00e1c h\u00e0nh vi tr\u00e1i ph\u00e9p.<\/li>\n<li><strong>L\u1edbp ph\u00e1t hi\u1ec7n:<\/strong> Bao g\u1ed3m <strong>Amazon GuardDuty<\/strong>, <strong>AWS Security Hub<\/strong>, v\u00e0 <strong>IAM Access Analyzer<\/strong> \u0111\u1ec3 li\u00ean t\u1ee5c gi\u00e1m s\u00e1t v\u00e0 ph\u00e1t hi\u1ec7n c\u00e1c m\u1ed1i \u0111e d\u1ecda.<\/li>\n<li><strong>L\u1edbp t\u00edch h\u1ee3p v\u00e0 t\u1ef1 \u0111\u1ed9ng h\u00f3a:<\/strong> S\u1eed d\u1ee5ng <strong>Amazon EventBridge<\/strong> v\u00e0 <strong>AWS Lambda<\/strong> \u0111\u1ec3 t\u1ef1 \u0111\u1ed9ng h\u00f3a c\u00e1c h\u00e0nh \u0111\u1ed9ng kh\u1eafc ph\u1ee5c v\u00e0 g\u1eedi c\u1ea3nh b\u00e1o qua <strong>Amazon SNS<\/strong>.<\/li>\n<li><strong>L\u1edbp gi\u00e1m s\u00e1t t\u1eadp trung:<\/strong> <strong>Amazon CloudWatch Logs<\/strong> v\u00e0 <strong>CloudWatch dashboards<\/strong> thu th\u1eadp log \u0111\u1ec3 ph\u1ee5c v\u1ee5 \u0111i\u1ec1u tra s\u1ef1 c\u1ed1 v\u00e0 b\u00e1o c\u00e1o tu\u00e2n th\u1ee7.<\/li>\n<\/ul>\n<p>Ki\u1ebfn tr\u00fac n\u00e0y \u00e1p d\u1ee5ng cho c\u1ea3 workload truy\u1ec1n th\u1ed1ng v\u00e0 workload AI. M\u1ed9t AI agent ch\u1ea1y tr\u00ean <strong>Amazon Bedrock<\/strong> c\u0169ng ph\u1ea3i tu\u00e2n th\u1ee7 c\u00e1c ch\u00ednh s\u00e1ch l\u1ecdc DNS, danh s\u00e1ch t\u00ean mi\u1ec1n cho ph\u00e9p v\u00e0 v\u00e0nh \u0111ai d\u1eef li\u1ec7u t\u01b0\u01a1ng t\u1ef1 nh\u01b0 m\u1ed9t m\u00e1y \u1ea3o <strong>Amazon EC2<\/strong> hay container.<\/p>\n<h2>C\u00e1c bi\u1ec7n ph\u00e1p ph\u00f2ng ng\u1eeba ch\u1ee7 \u0111\u1ed9ng (Preventive Controls)<\/h2>\n<p>\u0110\u00e2y l\u00e0 nh\u1eefng bi\u1ec7n ph\u00e1p ch\u1eb7n \u0111\u1ee9ng h\u00e0nh vi tr\u00edch xu\u1ea5t d\u1eef li\u1ec7u tr\u01b0\u1edbc khi n\u00f3 x\u1ea3y ra, \u0111\u01b0\u1ee3c \u00e1p d\u1ee5ng cho c\u00e1c ho\u1ea1t \u0111\u1ed9ng c\u00f3 nguy c\u01a1 g\u00e2y h\u1ea1i cao.<\/p>\n<h3>AWS Network Firewall<\/h3>\n<p>AWS Network Firewall ho\u1ea1t \u0111\u1ed9ng nh\u01b0 m\u1ed9t ch\u1ed1t ch\u1eb7n trung t\u00e2m, ki\u1ec3m tra s\u00e2u c\u00e1c g\u00f3i tin t\u1eeb L\u1edbp 3 \u0111\u1ebfn L\u1edbp 7. Trong k\u1ecbch b\u1ea3n m\u1ed9t m\u00e1y ch\u1ee7 EC2 b\u1ecb x\u00e2m nh\u1eadp ho\u1eb7c m\u1ed9t AI agent b\u1ecb chi\u1ebfm quy\u1ec1n, Network Firewall s\u1ebd ch\u1eb7n k\u1ebft n\u1ed1i \u0111\u1ebfn m\u00e1y ch\u1ee7 \u0111\u1ed9c h\u1ea1i b\u00ean ngo\u00e0i v\u00ec \u0111\u1ecba ch\u1ec9 \u0111\u00f3 kh\u00f4ng n\u1eb1m trong danh s\u00e1ch t\u00ean mi\u1ec1n \u0111\u01b0\u1ee3c ph\u00ea duy\u1ec7t. C\u00e1c kh\u1ea3 n\u0103ng ch\u00ednh bao g\u1ed3m:<\/p>\n<ul>\n<li><strong>L\u1ecdc theo t\u00ean mi\u1ec1n:<\/strong> Ch\u1eb7n traffic \u0111\u1ebfn c\u00e1c \u0111\u1ecba ch\u1ec9 kh\u00f4ng \u0111\u01b0\u1ee3c ph\u00e9p.<\/li>\n<li><strong>L\u1ecdc theo IP v\u00e0 port:<\/strong> Ch\u1ec9 cho ph\u00e9p k\u1ebft n\u1ed1i \u0111\u1ebfn c\u00e1c IP b\u00ean ngo\u00e0i th\u1ef1c s\u1ef1 c\u1ea7n thi\u1ebft.<\/li>\n<li><strong>Ph\u00e1t hi\u1ec7n v\u00e0 ng\u0103n ch\u1eb7n x\u00e2m nh\u1eadp (IDS\/IPS):<\/strong> S\u1eed d\u1ee5ng c\u00e1c quy t\u1eafc t\u01b0\u01a1ng th\u00edch Suricata \u0111\u1ec3 ch\u1eb7n c\u00e1c m\u1eabu t\u1ea5n c\u00f4ng \u0111\u00e3 bi\u1ebft.<\/li>\n<li><strong>Gi\u1ea3i m\u00e3 TLS:<\/strong> Ki\u1ec3m tra traffic \u0111\u00e3 m\u00e3 h\u00f3a \u0111\u1ec3 ph\u00e1t hi\u1ec7n c\u00e1c n\u1ed7 l\u1ef1c l\u1ea5y c\u1eafp d\u1eef li\u1ec7u \u1ea9n trong k\u1ebft n\u1ed1i HTTPS.<\/li>\n<\/ul>\n<p>\u0110\u1ed1i v\u1edbi m\u00f4i tr\u01b0\u1eddng \u0111a t\u00e0i kho\u1ea3n, <strong>AWS Firewall Manager<\/strong> gi\u00fap tri\u1ec3n khai v\u00e0 qu\u1ea3n l\u00fd Network Firewall m\u1ed9t c\u00e1ch nh\u1ea5t qu\u00e1n. Ngo\u00e0i ra, <strong>AWS Network Firewall Proxy<\/strong> (\u0111ang trong giai \u0111o\u1ea1n preview) cung c\u1ea5p kh\u1ea3 n\u0103ng l\u1ecdc HTTP\/HTTPS chi ti\u1ebft h\u01a1n.<\/p>\n<h3>Route 53 Resolver DNS Firewall<\/h3>\n<p>K\u1ebb t\u1ea5n c\u00f4ng c\u00f3 th\u1ec3 m\u00e3 h\u00f3a d\u1eef li\u1ec7u nh\u1ea1y c\u1ea3m v\u00e0o c\u00e1c truy v\u1ea5n DNS \u0111\u1ec3 g\u1eedi ra ngo\u00e0i, m\u1ed9t k\u1ef9 thu\u1eadt g\u1ecdi l\u00e0 <em>DNS tunneling<\/em> (\u0111\u01b0\u1eddng h\u1ea7m DNS), v\u1ed1n c\u00f3 th\u1ec3 v\u01b0\u1ee3t qua c\u00e1c t\u01b0\u1eddng l\u1eeda th\u00f4ng th\u01b0\u1eddng. <strong>Route 53 Resolver DNS Firewall<\/strong> gi\u1ea3i quy\u1ebft l\u1ed7 h\u1ed5ng n\u00e0y b\u1eb1ng c\u00e1ch l\u1ecdc v\u00e0 ch\u1eb7n c\u00e1c truy v\u1ea5n DNS \u0111\u00e1ng ng\u1edd ngay t\u1ea1i t\u1ea7ng resolver, tr\u01b0\u1edbc khi b\u1ea5t k\u1ef3 k\u1ebft n\u1ed1i m\u1ea1ng n\u00e0o \u0111\u01b0\u1ee3c thi\u1ebft l\u1eadp. C\u00e1c t\u00ednh n\u0103ng ch\u00ednh:<\/p>\n<ul>\n<li><strong>Ch\u1eb7n t\u00ean mi\u1ec1n \u0111\u1ed9c h\u1ea1i:<\/strong> S\u1eed d\u1ee5ng danh s\u00e1ch t\u00ean mi\u1ec1n \u0111\u01b0\u1ee3c qu\u1ea3n l\u00fd b\u1edfi AWS, bao g\u1ed3m c\u00e1c m\u1ed1i \u0111e d\u1ecda v\u1ec1 malware, ransomware, botnet.<\/li>\n<li><strong>Th\u1ef1c thi danh s\u00e1ch cho ph\u00e9p (allow-lists):<\/strong> Ch\u1ec9 cho ph\u00e9p truy v\u1ea5n \u0111\u1ebfn c\u00e1c t\u00ean mi\u1ec1n \u0111\u00e3 \u0111\u01b0\u1ee3c ph\u00ea duy\u1ec7t.<\/li>\n<li><strong>T\u00ednh n\u0103ng n\u00e2ng cao:<\/strong> S\u1eed d\u1ee5ng AI\/ML \u0111\u1ec3 ph\u00e1t hi\u1ec7n DNS tunneling v\u00e0 c\u00e1c thu\u1eadt to\u00e1n t\u1ea1o t\u00ean mi\u1ec1n ng\u1eabu nhi\u00ean (DGA).<\/li>\n<\/ul>\n<h3>V\u00e0nh \u0111ai d\u1eef li\u1ec7u (Data Perimeters)<\/h3>\n<p>V\u00e0nh \u0111ai d\u1eef li\u1ec7u l\u00e0 m\u1ed9t t\u1eadp h\u1ee3p c\u00e1c quy t\u1eafc ph\u00f2ng ng\u1eeba \u0111\u1ec3 \u0111\u1ea3m b\u1ea3o ch\u1ec9 nh\u1eefng danh t\u00ednh \u0111\u00e1ng tin c\u1eady m\u1edbi c\u00f3 th\u1ec3 truy c\u1eadp t\u00e0i nguy\u00ean \u0111\u00e1ng tin c\u1eady t\u1eeb c\u00e1c m\u1ea1ng d\u1ef1 ki\u1ebfn. Ngay c\u1ea3 khi k\u1ebb t\u1ea5n c\u00f4ng c\u00f3 \u0111\u01b0\u1ee3c th\u00f4ng tin \u0111\u0103ng nh\u1eadp h\u1ee3p l\u1ec7, ch\u00fang c\u0169ng kh\u00f4ng th\u1ec3 s\u1eed d\u1ee5ng API c\u1ee7a d\u1ecbch v\u1ee5 AWS \u0111\u1ec3 chuy\u1ec3n d\u1eef li\u1ec7u ra ngo\u00e0i t\u1ed5 ch\u1ee9c. C\u00e1c c\u00f4ng c\u1ee5 ch\u00ednh \u0111\u1ec3 x\u00e2y d\u1ef1ng v\u00e0nh \u0111ai d\u1eef li\u1ec7u bao g\u1ed3m:<\/p>\n<ul>\n<li><strong>Service Control Policies (SCPs):<\/strong> Ng\u0103n ch\u1eb7n ng\u01b0\u1eddi d\u00f9ng t\u1ea1o ra c\u00e1c t\u00e0i nguy\u00ean c\u00f3 th\u1ec3 bypass c\u00e1c ki\u1ec3m so\u00e1t egress.<\/li>\n<li><strong>Resource Control Policies (RCPs):<\/strong> H\u1ea1n ch\u1ebf quy\u1ec1n truy c\u1eadp API v\u00e0o t\u00e0i nguy\u00ean c\u1ee7a b\u1ea1n.<\/li>\n<li><strong>VPC Endpoint Policies:<\/strong> \u0110\u00e2y l\u00e0 l\u1edbp ki\u1ec3m so\u00e1t egress tr\u1ef1c ti\u1ebfp nh\u1ea5t, \u0111\u1ea3m b\u1ea3o traffic \u0111\u1ebfn c\u00e1c d\u1ecbch v\u1ee5 AWS kh\u00f4ng \u0111i ra internet v\u00e0 ch\u1ec9 c\u00f3 th\u1ec3 truy c\u1eadp c\u00e1c t\u00e0i nguy\u00ean trong ph\u1ea1m vi t\u1ed5 ch\u1ee9c. V\u00ed d\u1ee5, m\u1ed9t ch\u00ednh s\u00e1ch c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c \u00e1p d\u1ee5ng \u0111\u1ec3 ch\u1ec9 cho ph\u00e9p truy c\u1eadp c\u00e1c bucket S3 thu\u1ed9c v\u1ec1 t\u1ed5 ch\u1ee9c c\u1ee7a b\u1ea1n, ng\u0103n ch\u1eb7n vi\u1ec7c sao ch\u00e9p d\u1eef li\u1ec7u sang m\u1ed9t bucket S3 b\u00ean ngo\u00e0i.<\/li>\n<\/ul>\n<h2>C\u00e1c bi\u1ec7n ph\u00e1p ph\u00e1t hi\u1ec7n (Detective Controls)<\/h2>\n<p>C\u00e1c bi\u1ec7n ph\u00e1p n\u00e0y gi\u00fap ph\u00e1t hi\u1ec7n c\u00e1c n\u1ed7 l\u1ef1c tr\u00edch xu\u1ea5t d\u1eef li\u1ec7u sau khi ch\u00fang x\u1ea3y ra, cung c\u1ea5p th\u00f4ng tin \u0111\u1ec3 \u0111i\u1ec1u tra v\u00e0 c\u1ea3i thi\u1ec7n c\u00e1c bi\u1ec7n ph\u00e1p ph\u00f2ng ng\u1eeba.<\/p>\n<h3>Amazon GuardDuty<\/h3>\n<p>GuardDuty l\u00e0 l\u1edbp ph\u00e1t hi\u1ec7n quan tr\u1ecdng, li\u00ean t\u1ee5c gi\u00e1m s\u00e1t c\u00e1c h\u00e0nh vi b\u1ea5t th\u01b0\u1eddng v\u00e0 c\u00e1c m\u1eabu t\u1ea5n c\u00f4ng cho th\u1ea5y n\u1ed7 l\u1ef1c tr\u00edch xu\u1ea5t d\u1eef li\u1ec7u \u0111ang di\u1ec5n ra. C\u00e1c kh\u1ea3 n\u0103ng ph\u00e1t hi\u1ec7n t\u1eadp trung v\u00e0o egress bao g\u1ed3m:<\/p>\n<ul>\n<li><strong>Ph\u00e1t hi\u1ec7n tr\u00edch xu\u1ea5t d\u1eef li\u1ec7u qua DNS:<\/strong> C\u1ea3nh b\u00e1o khi c\u00e1c m\u00e1y ch\u1ee7 EC2 \u0111ang truy\u1ec1n d\u1eef li\u1ec7u qua k\u00eanh DNS.<\/li>\n<li><strong>Ph\u00e1t hi\u1ec7n t\u00e1c nh\u00e2n \u0111\u1ed9c h\u1ea1i \u0111\u00e3 bi\u1ebft:<\/strong> K\u00edch ho\u1ea1t c\u1ea3nh b\u00e1o khi API d\u1eef li\u1ec7u S3 \u0111\u01b0\u1ee3c g\u1ecdi t\u1eeb c\u00e1c \u0111\u1ecba ch\u1ec9 IP n\u1eb1m trong danh s\u00e1ch \u0111en c\u1ee7a AWS.<\/li>\n<li><strong>T\u01b0\u01a1ng quan chu\u1ed7i t\u1ea5n c\u00f4ng nhi\u1ec1u b\u01b0\u1edbc:<\/strong> Ph\u00e1t hi\u1ec7n c\u00e1c chi\u1ebfn d\u1ecbch tr\u00edch xu\u1ea5t d\u1eef li\u1ec7u ph\u1ee9c t\u1ea1p, v\u00ed d\u1ee5 nh\u01b0 khi k\u1ebb t\u1ea5n c\u00f4ng thay \u0111\u1ed5i ch\u00ednh s\u00e1ch bucket S3 r\u1ed3i b\u1eaft \u0111\u1ea7u l\u1ea5y d\u1eef li\u1ec7u m\u1ed9t c\u00e1ch c\u00f3 h\u1ec7 th\u1ed1ng.<\/li>\n<\/ul>\n<h3>IAM Access Analyzer v\u00e0 AWS Security Hub<\/h3>\n<p><strong>IAM Access Analyzer<\/strong> gi\u00fap x\u00e1c \u0111\u1ecbnh c\u00e1c \u0111\u01b0\u1eddng d\u1eabn r\u00f2 r\u1ec9 d\u1eef li\u1ec7u ti\u1ec1m \u1ea9n b\u1eb1ng c\u00e1ch ph\u00e1t hi\u1ec7n c\u00e1c t\u00e0i nguy\u00ean c\u00f3 th\u1ec3 truy c\u1eadp t\u1eeb b\u00ean ngo\u00e0i t\u00e0i kho\u1ea3n ho\u1eb7c t\u1ed5 ch\u1ee9c AWS c\u1ee7a b\u1ea1n. N\u00f3 li\u00ean t\u1ee5c gi\u00e1m s\u00e1t c\u00e1c ch\u00ednh s\u00e1ch v\u00e0 x\u00e1c \u0111\u1ecbnh t\u00e0i nguy\u00ean n\u00e0o \u0111ang \u0111\u01b0\u1ee3c chia s\u1ebb v\u1edbi c\u00e1c th\u1ef1c th\u1ec3 b\u00ean ngo\u00e0i v\u00f9ng tin c\u1eady.<\/p>\n<p><strong>AWS Security Hub<\/strong> t\u1ed5ng h\u1ee3p c\u00e1c ph\u00e1t hi\u1ec7n t\u1eeb nhi\u1ec1u d\u1ecbch v\u1ee5 b\u1ea3o m\u1eadt c\u1ee7a AWS (GuardDuty, Amazon Inspector, Amazon Macie) \u0111\u1ec3 cung c\u1ea5p m\u1ed9t c\u00e1i nh\u00ecn to\u00e0n di\u1ec7n v\u1ec1 c\u00e1c r\u1ee7i ro b\u1ea3o m\u1eadt. V\u00ed d\u1ee5, Security Hub c\u00f3 th\u1ec3 x\u00e1c \u0111\u1ecbnh m\u1ed9t bucket S3 ch\u1ee9a d\u1eef li\u1ec7u nh\u1ea1y c\u1ea3m \u0111ang b\u1ecb ph\u01a1i b\u00e0y c\u00f4ng khai v\u00e0 ch\u01b0a \u0111\u01b0\u1ee3c m\u00e3 h\u00f3a, \u0111\u00e1nh d\u1ea5u \u0111\u00e2y l\u00e0 m\u1ed9t r\u1ee7i ro th\u1ea5t tho\u00e1t d\u1eef li\u1ec7u c\u1ea7n \u0111\u01b0\u1ee3c x\u1eed l\u00fd ngay l\u1eadp t\u1ee9c.<\/p>\n<h2>Chi\u1ebfn l\u01b0\u1ee3c tri\u1ec3n khai b\u1ea3o m\u1eadt Egress<\/h2>\n<p>Doanh nghi\u1ec7p kh\u00f4ng c\u1ea7n ph\u1ea3i tri\u1ec3n khai t\u1ea5t c\u1ea3 c\u00e1c bi\u1ec7n ph\u00e1p ki\u1ec3m so\u00e1t c\u00f9ng m\u1ed9t l\u00fac. AWS \u0111\u1ec1 xu\u1ea5t m\u1ed9t c\u00e1ch ti\u1ebfp c\u1eadn theo t\u1eebng giai \u0111o\u1ea1n \u0111\u1ec3 x\u00e2y d\u1ef1ng h\u1ec7 th\u1ed1ng b\u1ea3o m\u1eadt egress m\u1ed9t c\u00e1ch t\u1eeb t\u1eeb, ph\u00f9 h\u1ee3p v\u1edbi m\u1ee9c \u0111\u1ed9 tr\u01b0\u1edfng th\u00e0nh v\u00e0 kh\u1ea3 n\u0103ng ch\u1ea5p nh\u1eadn r\u1ee7i ro c\u1ee7a t\u1ed5 ch\u1ee9c.<\/p>\n<ul>\n<li><strong>Giai \u0111o\u1ea1n 1 \u2013 Quick wins:<\/strong> K\u00edch ho\u1ea1t <strong>Route 53 DNS Firewall<\/strong> tr\u00ean c\u00e1c VPC \u0111\u1ec3 \u0111\u00f3ng l\u1ed7 h\u1ed5ng DNS exfiltration. K\u00edch ho\u1ea1t <strong>GuardDuty<\/strong> tr\u00ean c\u00e1c t\u00e0i kho\u1ea3n \u0111\u1ec3 c\u00f3 kh\u1ea3 n\u0103ng ph\u00e1t hi\u1ec7n m\u1ed1i \u0111e d\u1ecda c\u01a1 b\u1ea3n.<\/li>\n<li><strong>Giai \u0111o\u1ea1n 2 \u2013 N\u1ec1n t\u1ea3ng:<\/strong> Tri\u1ec3n khai <strong>Data Perimeters<\/strong> tr\u00ean to\u00e0n t\u1ed5 ch\u1ee9c (SCPs, RCPs, v\u00e0 VPC Endpoint Policies). Tri\u1ec3n khai <strong>Network Firewall<\/strong> \u0111\u00ednh k\u00e8m v\u1edbi Transit Gateway.<\/li>\n<li><strong>Giai \u0111o\u1ea1n 3 \u2013 T\u1ed1i \u01b0u h\u00f3a:<\/strong> K\u00edch ho\u1ea1t <strong>IAM Access Analyzer<\/strong> \u0111\u1ec3 ph\u00e1t hi\u1ec7n truy c\u1eadp t\u1eeb b\u00ean ngo\u00e0i m\u1ed9t c\u00e1ch li\u00ean t\u1ee5c. Tri\u1ec3n khai c\u00e1c c\u01a1 ch\u1ebf kh\u1eafc ph\u1ee5c t\u1ef1 \u0111\u1ed9ng qua <strong>EventBridge<\/strong> v\u00e0 <strong>Lambda<\/strong> \u0111\u1ec3 c\u1eadp nh\u1eadt quy t\u1eafc t\u01b0\u1eddng l\u1eeda theo th\u1eddi gian th\u1ef1c. T\u1eadp trung h\u00f3a c\u00e1c ph\u00e1t hi\u1ec7n trong <strong>Security Hub<\/strong> v\u1edbi c\u1ea3nh b\u00e1o t\u1ef1 \u0111\u1ed9ng.<\/li>\n<\/ul>\n<p>B\u1ea3o m\u1eadt egress kh\u00f4ng ph\u1ea3i l\u00e0 m\u1ed9t c\u00f4ng c\u1ee5 duy nh\u1ea5t m\u00e0 l\u00e0 m\u1ed9t chi\u1ebfn l\u01b0\u1ee3c nhi\u1ec1u l\u1edbp. B\u1eb1ng c\u00e1ch \u0111\u00e1nh gi\u00e1 hi\u1ec7n tr\u1ea1ng, x\u00e1c \u0111\u1ecbnh c\u00e1c l\u1ed7 h\u1ed5ng v\u00e0 tri\u1ec3n khai d\u1ea7n c\u00e1c bi\u1ec7n ph\u00e1p ki\u1ec3m so\u00e1t, doanh nghi\u1ec7p c\u00f3 th\u1ec3 bi\u1ebfn c\u00e1c \u0111i\u1ec3m m\u00f9 trong lu\u1ed3ng d\u1eef li\u1ec7u \u0111i ra th\u00e0nh c\u00e1c tr\u1ea1m ki\u1ec3m so\u00e1t \u0111\u01b0\u1ee3c gi\u00e1m s\u00e1t ch\u1eb7t ch\u1ebd.<\/p>","protected":false},"excerpt":{"rendered":"<p>Trong khi c\u00e1c doanh nghi\u1ec7p t\u1eadp trung b\u1ea3o v\u1ec7 h\u1ec7 th\u1ed1ng kh\u1ecfi c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng t\u1eeb b\u00ean ngo\u00e0i, lu\u1ed3ng d\u1eef li\u1ec7u \u0111i ra (egress) th\u01b0\u1eddng b\u1ecb xem nh\u1eb9, t\u1ea1o ra m\u1ed9t \u0111i\u1ec3m m\u00f9 b\u1ea3o m\u1eadt nghi\u00eam tr\u1ecdng. Vi\u1ec7c b\u1ecf qua ki\u1ec3m so\u00e1t egress c\u00f3 th\u1ec3 d\u1eabn \u0111\u1ebfn r\u00f2 r\u1ec9 d\u1eef li\u1ec7u nh\u1ea1y c\u1ea3m, d\u00f9&#8230;<\/p>","protected":false},"author":22,"featured_media":66849,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-66851","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ctelers-blogs"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>AWS: X\u00e2y d\u1ef1ng ph\u00f2ng tuy\u1ebfn nhi\u1ec1u l\u1edbp ch\u1ed1ng th\u1ea5t tho\u00e1t d\u1eef li\u1ec7u \u0111\u00e1m m\u00e2y | CMC Telecom<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/aws.cmctelecom.vn\/en\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AWS: X\u00e2y d\u1ef1ng ph\u00f2ng tuy\u1ebfn nhi\u1ec1u l\u1edbp ch\u1ed1ng th\u1ea5t tho\u00e1t d\u1eef li\u1ec7u \u0111\u00e1m m\u00e2y | CMC Telecom\" \/>\n<meta property=\"og:description\" content=\"Trong khi c\u00e1c doanh nghi\u1ec7p t\u1eadp trung b\u1ea3o v\u1ec7 h\u1ec7 th\u1ed1ng kh\u1ecfi c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng t\u1eeb b\u00ean ngo\u00e0i, lu\u1ed3ng d\u1eef li\u1ec7u \u0111i ra (egress) th\u01b0\u1eddng b\u1ecb xem nh\u1eb9, t\u1ea1o ra m\u1ed9t \u0111i\u1ec3m m\u00f9 b\u1ea3o m\u1eadt nghi\u00eam tr\u1ecdng. Vi\u1ec7c b\u1ecf qua ki\u1ec3m so\u00e1t egress c\u00f3 th\u1ec3 d\u1eabn \u0111\u1ebfn r\u00f2 r\u1ec9 d\u1eef li\u1ec7u nh\u1ea1y c\u1ea3m, d\u00f9...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/aws.cmctelecom.vn\/en\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/\" \/>\n<meta property=\"og:site_name\" content=\"CMC Telecom\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/CMCTelecomOfficial\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-26T02:21:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-06-30T10:45:55+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/aws.cmctelecom.vn\/wp-content\/uploads\/2026\/06\/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads.thumbnail.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"731\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"publisher-bot\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"publisher-bot\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/2026\\\/06\\\/26\\\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/2026\\\/06\\\/26\\\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\\\/\"},\"author\":{\"name\":\"publisher-bot\",\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/#\\\/schema\\\/person\\\/630c0582c38b5246ea44d055155d721e\"},\"headline\":\"AWS: X\u00e2y d\u1ef1ng ph\u00f2ng tuy\u1ebfn nhi\u1ec1u l\u1edbp ch\u1ed1ng th\u1ea5t tho\u00e1t d\u1eef li\u1ec7u \u0111\u00e1m m\u00e2y\",\"datePublished\":\"2026-06-26T02:21:24+00:00\",\"dateModified\":\"2026-06-30T10:45:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/2026\\\/06\\\/26\\\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\\\/\"},\"wordCount\":2620,\"publisher\":{\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/2026\\\/06\\\/26\\\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads.thumbnail.jpg\",\"articleSection\":[\"Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/2026\\\/06\\\/26\\\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\\\/\",\"url\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/2026\\\/06\\\/26\\\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\\\/\",\"name\":\"AWS: X\u00e2y d\u1ef1ng ph\u00f2ng tuy\u1ebfn nhi\u1ec1u l\u1edbp ch\u1ed1ng th\u1ea5t tho\u00e1t d\u1eef li\u1ec7u \u0111\u00e1m m\u00e2y | CMC Telecom\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/2026\\\/06\\\/26\\\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/2026\\\/06\\\/26\\\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads.thumbnail.jpg\",\"datePublished\":\"2026-06-26T02:21:24+00:00\",\"dateModified\":\"2026-06-30T10:45:55+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/2026\\\/06\\\/26\\\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/aws.cmctelecom.vn\\\/2026\\\/06\\\/26\\\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/2026\\\/06\\\/26\\\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\\\/#primaryimage\",\"url\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads.thumbnail.jpg\",\"contentUrl\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads.thumbnail.jpg\",\"width\":1280,\"height\":731},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/2026\\\/06\\\/26\\\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Trang ch\u1ee7\",\"item\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blogs\",\"item\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/danh-muc-tin-tuc\\\/ctelers-blogs\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"AWS: X\u00e2y d\u1ef1ng ph\u00f2ng tuy\u1ebfn nhi\u1ec1u l\u1edbp ch\u1ed1ng th\u1ea5t tho\u00e1t d\u1eef li\u1ec7u \u0111\u00e1m m\u00e2y\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/#website\",\"url\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/\",\"name\":\"CMC Telecom\",\"description\":\"\u0110\u1ed1i t\u00e1c D\u1ecbch v\u1ee5 C\u1ea5p cao c\u1ee7a AWS t\u1ea1i Vi\u1ec7t Nam\",\"publisher\":{\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/#organization\"},\"alternateName\":\"AWS Advanced Partner in Vietnam\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/#organization\",\"name\":\"CMC Telecom\",\"alternateName\":\"CMC Telecom\",\"url\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/cmc-telecom-logo.png\",\"contentUrl\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/wp-content\\\/uploads\\\/2023\\\/07\\\/cmc-telecom-logo.png\",\"width\":400,\"height\":96,\"caption\":\"CMC Telecom\"},\"image\":{\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/CMCTelecomOfficial\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/#\\\/schema\\\/person\\\/630c0582c38b5246ea44d055155d721e\",\"name\":\"publisher-bot\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/83ecf50e74202a2c7d2e2c924c1d66b874db607a909c8236b74cc4fb96581a00?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/83ecf50e74202a2c7d2e2c924c1d66b874db607a909c8236b74cc4fb96581a00?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/83ecf50e74202a2c7d2e2c924c1d66b874db607a909c8236b74cc4fb96581a00?s=96&d=mm&r=g\",\"caption\":\"publisher-bot\"},\"url\":\"https:\\\/\\\/aws.cmctelecom.vn\\\/en\\\/author\\\/publisher-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AWS: X\u00e2y d\u1ef1ng ph\u00f2ng tuy\u1ebfn nhi\u1ec1u l\u1edbp ch\u1ed1ng th\u1ea5t tho\u00e1t d\u1eef li\u1ec7u \u0111\u00e1m m\u00e2y | CMC Telecom","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/aws.cmctelecom.vn\/en\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/","og_locale":"en_US","og_type":"article","og_title":"AWS: X\u00e2y d\u1ef1ng ph\u00f2ng tuy\u1ebfn nhi\u1ec1u l\u1edbp ch\u1ed1ng th\u1ea5t tho\u00e1t d\u1eef li\u1ec7u \u0111\u00e1m m\u00e2y | CMC Telecom","og_description":"Trong khi c\u00e1c doanh nghi\u1ec7p t\u1eadp trung b\u1ea3o v\u1ec7 h\u1ec7 th\u1ed1ng kh\u1ecfi c\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng t\u1eeb b\u00ean ngo\u00e0i, lu\u1ed3ng d\u1eef li\u1ec7u \u0111i ra (egress) th\u01b0\u1eddng b\u1ecb xem nh\u1eb9, t\u1ea1o ra m\u1ed9t \u0111i\u1ec3m m\u00f9 b\u1ea3o m\u1eadt nghi\u00eam tr\u1ecdng. Vi\u1ec7c b\u1ecf qua ki\u1ec3m so\u00e1t egress c\u00f3 th\u1ec3 d\u1eabn \u0111\u1ebfn r\u00f2 r\u1ec9 d\u1eef li\u1ec7u nh\u1ea1y c\u1ea3m, d\u00f9...","og_url":"https:\/\/aws.cmctelecom.vn\/en\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/","og_site_name":"CMC Telecom","article_publisher":"https:\/\/www.facebook.com\/CMCTelecomOfficial","article_published_time":"2026-06-26T02:21:24+00:00","article_modified_time":"2026-06-30T10:45:55+00:00","og_image":[{"width":1280,"height":731,"url":"http:\/\/aws.cmctelecom.vn\/wp-content\/uploads\/2026\/06\/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads.thumbnail.jpg","type":"image\/jpeg"}],"author":"publisher-bot","twitter_card":"summary_large_image","twitter_misc":{"Written by":"publisher-bot","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/aws.cmctelecom.vn\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/#article","isPartOf":{"@id":"https:\/\/aws.cmctelecom.vn\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/"},"author":{"name":"publisher-bot","@id":"https:\/\/aws.cmctelecom.vn\/#\/schema\/person\/630c0582c38b5246ea44d055155d721e"},"headline":"AWS: X\u00e2y d\u1ef1ng ph\u00f2ng tuy\u1ebfn nhi\u1ec1u l\u1edbp ch\u1ed1ng th\u1ea5t tho\u00e1t d\u1eef li\u1ec7u \u0111\u00e1m m\u00e2y","datePublished":"2026-06-26T02:21:24+00:00","dateModified":"2026-06-30T10:45:55+00:00","mainEntityOfPage":{"@id":"https:\/\/aws.cmctelecom.vn\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/"},"wordCount":2620,"publisher":{"@id":"https:\/\/aws.cmctelecom.vn\/#organization"},"image":{"@id":"https:\/\/aws.cmctelecom.vn\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/#primaryimage"},"thumbnailUrl":"https:\/\/aws.cmctelecom.vn\/wp-content\/uploads\/2026\/06\/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads.thumbnail.jpg","articleSection":["Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/aws.cmctelecom.vn\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/","url":"https:\/\/aws.cmctelecom.vn\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/","name":"AWS: X\u00e2y d\u1ef1ng ph\u00f2ng tuy\u1ebfn nhi\u1ec1u l\u1edbp ch\u1ed1ng th\u1ea5t tho\u00e1t d\u1eef li\u1ec7u \u0111\u00e1m m\u00e2y | CMC Telecom","isPartOf":{"@id":"https:\/\/aws.cmctelecom.vn\/#website"},"primaryImageOfPage":{"@id":"https:\/\/aws.cmctelecom.vn\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/#primaryimage"},"image":{"@id":"https:\/\/aws.cmctelecom.vn\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/#primaryimage"},"thumbnailUrl":"https:\/\/aws.cmctelecom.vn\/wp-content\/uploads\/2026\/06\/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads.thumbnail.jpg","datePublished":"2026-06-26T02:21:24+00:00","dateModified":"2026-06-30T10:45:55+00:00","breadcrumb":{"@id":"https:\/\/aws.cmctelecom.vn\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/aws.cmctelecom.vn\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/aws.cmctelecom.vn\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/#primaryimage","url":"https:\/\/aws.cmctelecom.vn\/wp-content\/uploads\/2026\/06\/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads.thumbnail.jpg","contentUrl":"https:\/\/aws.cmctelecom.vn\/wp-content\/uploads\/2026\/06\/prevent-data-exfiltration-aws-egress-controls-for-cloud-workloads.thumbnail.jpg","width":1280,"height":731},{"@type":"BreadcrumbList","@id":"https:\/\/aws.cmctelecom.vn\/2026\/06\/26\/aws-xay-dung-phong-tuyen-nhieu-lop-chong-that-thoat-du-lieu-dam-may\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Trang ch\u1ee7","item":"https:\/\/aws.cmctelecom.vn\/"},{"@type":"ListItem","position":2,"name":"Blogs","item":"https:\/\/aws.cmctelecom.vn\/danh-muc-tin-tuc\/ctelers-blogs\/"},{"@type":"ListItem","position":3,"name":"AWS: X\u00e2y d\u1ef1ng ph\u00f2ng tuy\u1ebfn nhi\u1ec1u l\u1edbp ch\u1ed1ng th\u1ea5t tho\u00e1t d\u1eef li\u1ec7u \u0111\u00e1m m\u00e2y"}]},{"@type":"WebSite","@id":"https:\/\/aws.cmctelecom.vn\/#website","url":"https:\/\/aws.cmctelecom.vn\/","name":"CMC Telecom","description":"CMC Telecom holds the position of a Advanced Tier Service Partner of AWS in Vietnam and has closely","publisher":{"@id":"https:\/\/aws.cmctelecom.vn\/#organization"},"alternateName":"AWS Advanced Partner in Vietnam","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/aws.cmctelecom.vn\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/aws.cmctelecom.vn\/#organization","name":"CMC Telecom","alternateName":"CMC Telecom","url":"https:\/\/aws.cmctelecom.vn\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/aws.cmctelecom.vn\/#\/schema\/logo\/image\/","url":"https:\/\/aws.cmctelecom.vn\/wp-content\/uploads\/2023\/07\/cmc-telecom-logo.png","contentUrl":"https:\/\/aws.cmctelecom.vn\/wp-content\/uploads\/2023\/07\/cmc-telecom-logo.png","width":400,"height":96,"caption":"CMC Telecom"},"image":{"@id":"https:\/\/aws.cmctelecom.vn\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/CMCTelecomOfficial"]},{"@type":"Person","@id":"https:\/\/aws.cmctelecom.vn\/#\/schema\/person\/630c0582c38b5246ea44d055155d721e","name":"publisher-bot","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/83ecf50e74202a2c7d2e2c924c1d66b874db607a909c8236b74cc4fb96581a00?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/83ecf50e74202a2c7d2e2c924c1d66b874db607a909c8236b74cc4fb96581a00?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/83ecf50e74202a2c7d2e2c924c1d66b874db607a909c8236b74cc4fb96581a00?s=96&d=mm&r=g","caption":"publisher-bot"},"url":"https:\/\/aws.cmctelecom.vn\/en\/author\/publisher-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/aws.cmctelecom.vn\/en\/wp-json\/wp\/v2\/posts\/66851","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aws.cmctelecom.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aws.cmctelecom.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aws.cmctelecom.vn\/en\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/aws.cmctelecom.vn\/en\/wp-json\/wp\/v2\/comments?post=66851"}],"version-history":[{"count":1,"href":"https:\/\/aws.cmctelecom.vn\/en\/wp-json\/wp\/v2\/posts\/66851\/revisions"}],"predecessor-version":[{"id":66877,"href":"https:\/\/aws.cmctelecom.vn\/en\/wp-json\/wp\/v2\/posts\/66851\/revisions\/66877"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aws.cmctelecom.vn\/en\/wp-json\/wp\/v2\/media\/66849"}],"wp:attachment":[{"href":"https:\/\/aws.cmctelecom.vn\/en\/wp-json\/wp\/v2\/media?parent=66851"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aws.cmctelecom.vn\/en\/wp-json\/wp\/v2\/categories?post=66851"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aws.cmctelecom.vn\/en\/wp-json\/wp\/v2\/tags?post=66851"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}