How to Fix Zero Trust Network Access Security

671 views
•
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How to Fix Zero Trust Network Access Security

TL;DR

Effective zero trust must grant access to named applications instead of broad networks, IP addresses, or ports, and it must continuously evaluate activity after access is approved. Broker-based ZTNA 1.0 falls short because its application definitions can remain tied to Layer 3 and Layer 4 controls, while its one-time authorization model can allow subsequent activity to proceed without ongoing inspection.

Transcript

It's great to see everyone in person. Uh, in February of twenty-twenty, I was actually driving from San Francisco Airport, which is probably where many of you landed if you're, uh, not local. And I was driving to my home in the East Bay. Uh, with traffic, that's a good, uh, little over an hour or so. And it was Friday evening, uh, it was the evenin... Read More

Key Insights

  • Work is no longer a fixed location because users can begin working from home, an office, or another location simply by opening a laptop. Infrastructure designed mainly around branches connecting to data centers does not adequately match this fluid model of users, applications, and access.
  • The pandemic compressed a major business and IT transformation into two years, according to the presentation. Organizations first scrambled to scale remote access, then accelerated digital and cloud adoption, and are now reconsidering how infrastructure and security should be designed for the next ten or twenty years.
  • Digital operations require every part of a business to connect fluidly with customers, partners, and supply chains. The fast-food example shows this shift clearly: service expanded beyond physical ordering to mobile or third-party ordering, touchless delivery, and touchless pickup during the pandemic.
  • The modern security surface is an expanding matrix of many users and many applications. Users may move among homes, offices, and other locations, while applications may also be fluid across data centers, clouds, and SaaS environments, creating a much larger area that requires protection.
  • ZTNA 1.0 works through a broker that evaluates an access request against policy. When access is permitted, the broker connects the user directly to the application and leaves the traffic path, limiting its ability to evaluate what happens throughout the resulting session.
  • Least privilege access is intended to provide only the resources needed to complete a task or transaction. The desired shift is from granting access to networks, IP addresses, and ports toward granting access to specifically named applications without exposing unrelated resources inside the environment.
  • ZTNA 1.0 application access can still be based on Layer 3 and Layer 4 IP addresses and ports. Naming an application does not create true application-level control when the underlying authorization remains network-based, especially if the broker does not stay continuously in the traffic path.
  • Modern applications can be distributed, cloud-native, microservices-based, or composite. A retail application may include selling, credit-card, help-desk, and chat functions, so representing the entire application with IP addresses and ports can open access to a much larger portion of the environment than intended.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why is traditional network security inadequate for hybrid work?

Traditional network security was designed largely around relatively static connections from branches to data centers, where users accessed applications located there or reached cloud applications through that architecture. Hybrid work changes the design problem because users can operate from homes, offices, or other locations, while applications may reside in data centers, clouds, or SaaS environments. Security must now protect a growing matrix of changing user-to-application connections.

Q: How does ZTNA 1.0 control access to an application?

ZTNA 1.0 typically places a broker between a user and an application during the initial request. The broker identifies the user and requested application, evaluates the request against policy, and either allows or denies access. When policy permits the connection, the broker brings the user and application together and then leaves the traffic path, allowing them to communicate directly rather than maintaining continuous oversight.

Q: What is least privilege access in zero trust security?

Least privilege access means avoiding a model in which a user gains access to every resource merely because that user is inside a network or environment. Instead, access should be narrowed to the resources required to complete a specific task or transaction. Because work generally requires applications, the intended change is to authorize named applications rather than granting broad access through networks, IP addresses, and ports.

Q: Why are IP addresses and ports insufficient for application access?

IP addresses and ports describe Layer 3 and Layer 4 network properties, but they do not provide the deeper application understanding required by web-based and cloud-native systems. If a supposedly named application is ultimately represented only by those properties, access remains network-based. For distributed or composite applications, that representation can expose a large part of the environment instead of limiting the user to the precise application resources required.

Q: How do composite applications complicate zero trust policies?

Composite applications combine multiple services and functions into what users experience as one application. The presentation gives a retail example that can include a core selling application, credit-card functionality, a help desk, and chat. When security represents that combined application only through IP addresses and ports, the resulting rule may open much broader access than intended, weakening the goal of restricting each user to necessary resources.

Q: Why must zero trust evaluate access continuously?

A single authorization check cannot account for everything that may happen after a connection begins. ZTNA 1.0 brokers can evaluate factors such as device posture, user behavior, and application behavior whenever a new access request is made. However, the broker may leave the traffic path after approval. The presentation characterizes this as an allow-and-ignore problem because subsequent activity is not continuously evaluated by that broker.

Q: How did the pandemic change enterprise IT architecture?

The pandemic first forced enterprises to scale infrastructure rapidly so that large numbers of people could work remotely from anywhere. It then accelerated digital and cloud adoption, making fluid connections with customers, partners, and supply chains essential across the business. According to the presentation, two years produced two decades' worth of business and IT shift, prompting enterprises to reconsider infrastructure and security architecture for the next ten or twenty years.

Q: What should a stronger zero trust architecture provide?

A stronger zero trust architecture should let users reach required applications without making security depend on whether those applications are in a data center, a cloud environment, or a SaaS service. It should provide security, compliance, and strong user experiences across changing locations. It should also enforce access at the application level and continue evaluating activity after the initial authorization instead of relying on broad network rules and one-time checks.

Summary & Key Takeaways

  • Work has shifted from a location people travel to into an activity performed from homes, offices, and other places. At the same time, applications can reside in data centers, clouds, or SaaS environments. Security architecture must therefore connect many mobile users to many fluid applications while preserving security, compliance, and strong user experiences.

  • ZTNA 1.0 uses a broker to review a user's request for an application. The broker applies policy, allows or denies the request, and, when access is approved, connects the user and application directly before leaving the traffic path. That design creates limitations because the broker cannot maintain a deep understanding of subsequent traffic.

  • Least privilege should provide only the application resources required for a particular task or transaction. ZTNA 1.0 can undermine that goal by representing applications through Layer 3 and Layer 4 IP addresses and ports. This becomes especially problematic for distributed, cloud-native, microservices-based, and composite applications containing multiple embedded services and functions.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚