HomeYoutubeZero Trust: What is it and how does security architecture work?

Zero Trust: What is it and how does security architecture work?

Zero Trust architecture is a secure technique that helps protect a network from attacks. It inhibits potential lateral movement of threats and reduces the risk of data breaches.

See also: Cloudflare Zero Trust: New software is now available for free

Zero Trust

Such a model moves away from the traditional “network perimeter,” within which all devices and users are trusted and given broad permissions. Instead, it controls access to each device and verifies their identity, with practices like MFA.

Πριν εξετάσουμε λεπτομερέστερα την αρχιτεκτονική Zero Trust, αξίζει να ξεχωρίσουμε δύο συναφείς όρους:

1. The Zero Trust Architecture (ZTA) which is based on zero trust principles.

These principles include managing access with strict device and user identity controls as well as strong segmentation. This architecture differs from many perspectives and is designed to replace architectures that rely on default choices.

2. Zero Trust Network Access (ZTNA) provides secure access to applications and data, even if they are not in the traditional security zone. This is common in the era of cloud and hybrid working.

Zero Trust architecture means that it assumes all devices on the network are dangerous or may be compromised. Therefore, for a user to access an application, they must verify their identity, the device, and the business context and be subject to policy checks.

In this model, all traffic must be logged and inspected, requiring a more exhaustive security audit than regular models. A Zero Trust approach reduces the attack of an organization, prevents lateral spread of threats, and reduces the risk of a breach.

The optimal solution is to use an architecture with a proxy server, which allows users to connect directly to applications, instead of the network. To ensure that there is never automatic trust, a reliable Zero Trust checks each connection before it is created.

This is a three-step process:

Identity and context verification

Once the user or device requests a connection, regardless of the underlying network, the Zero Trust architecture first terminates the connection and verifies the identity and context by understanding the “who, what, and where” of the request.

Risk assessment

Once the identity and context of the requesting entity are verified and segmentation rules are applied, it evaluates the risk associated with the connection request.

Policy enforcement

Finally, a risk score is calculated for the user, workload, or device to determine whether a restriction is allowed or otherwise applied. If allowed, the Zero Trust architecture creates a secure connection to the internet, SaaS , or IaaS environment.

See also: Microsoft: “Zero trust” protects against sophisticated hacking attacks
Zero Trust

Zero Trust architecture provides an accurate and fast solution for accessing your data based on your rights, while protecting the security of your data. An effective Zero Trust architecture helps you:

Provide secure, fast access to data and applications for remote workers, improving the user experience.

Provide reliable remote access as well as management and enforcement of security policy more easily and consistently than you can with legacy technology such as VPN.

You protect sensitive data and applications with strict security controls, such as encryption, authentication, health checks, and others.

You stop internal threats by no longer granting default, silent trust to any user or device within the perimeter of your network.

You limit lateral movement with granular access policies down to the resource level, reducing the likelihood of a breach.

You detect, respond to, and recover from successful breaches faster and more efficiently to mitigate their impact.

You gain deeper insight into what, when, how, and where user and entity activities occur, with detailed monitoring and logging of session periods and the actions that were performed.

You assess your risk in real time with detailed authentication audit logs, device and resource health checks, user and entity behavior analytics, and much more.

Over the past three decades or so, organizations have built and restructured complex networks consisting of nodes and large-area spokes. In this environment, users and branch offices connect to the central data center via private links. Users must be on the network to be able to access the necessary applications.

See also: Five myths surrounding the Zero Trust approach!

architecture

The “ castle-and-moat ” network security architecture is used in Hub-and-Spoke networks and involves the use of security stacks, such as VPNs and firewalls, to enhance security. This approach was good for organizations when they had applications in their own data centers. But now with the growth of cloud services, the emergence of new technologies, and increased security concerns, it is lagging behind.

Today, organizations choose to evolve digitally, committed to technological innovations such as cloud, mobility, artificial intelligence, the Internet of Things (IoT) and operational technology (OT). All of this is done in order to enhance their flexibility and competitiveness.

Users exist everywhere and the organizations' data is not exclusively stored in their data centers. Users want to have immediacy in their applications from any location they are in, so that they can collaborate and remain effective.

There is no longer a need to route traffic back to the data center to securely access applications in the cloud. That is why many organizations are abandoning the hub-and-spoke network model and opting for a model that allows direct connection to the cloud.

Unlike static, legacy network architectures with a “front door” that carries data to processing centers, Zero Trust intelligently manages and optimizes direct connections to any cloud or Internet destination and enforces adaptive policies and protections built as close to the user as possible.

For the above reasons, the Zero Trust architecture is becoming increasingly popular among businesses.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS