Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management //

Access Management

6/27/2019
02:20 PM
Larry Loeb
Larry Loeb
Larry Loeb
50%
50%

Zero Trust Doesn't Trust You at All

Enterprise security practitioners who deal with identity day in and day out come together to find out the current status of the field.

At the tenth IDentiverse conference in Washington, DC, this week, enterprise security practitioners who deal with identity day in and day out met to find out the current status of the field.

While there are all sorts of specific solutions being hawked by their manufacturers, some companies have taken advantage of the gathering to spread what they think the future will look like from an identity-centric standpoint.

Rick Smith and Morteza Ansari of Cisco gave a presentation about Zero Trust (ZT) that started with a wider perspective than usually is found.

They think the security problem can be modeled by a popped kernel of popcorn, and that ZT tries to secure that popcorn. Once you are inside that kernel, you are all the way in. There really isn't a perimeter to it.

You can't make assumptions about authorization or access under ZT just by what the IP address says. Just because a request comes in on the enterprise VPN does not force you to automatically trust it, for example.

The Internet has a lot of signals that can help to make a dynamic decision about a particular access request.

In many ways, ZT inverts the current models by focusing of the trustworthiness of the user. The device being used in a request, the history of the user regarding the requested access can allow dynamic security decisions to be made. That dynamic range of choices available is central to the ZT ideals. ZT can allow differing base line analyses be done by enabling differing sets of transactions to be analyzed for different requests.

But Smith also made some very telling points. He said that, "We've done amazing well at identification and authentication over the last two decades. But in authorization we haven't gone as far. There is a lot more work that is needed… The signals used in making a decision on a particular transaction need to be the same for similar transactions for consistency. We basically have no way to deal with authorization when it crosses a security boundary."

ZT, despite vendor claims, is not a product in Smith and Ansara's view. It's an ecosystem with multiple products from multiple vendors all working together.

Paul Lanzi of Remidiant would agree with that. He works with Privileged Access Management systems that have a twist. He responded to what he saw attackers doing, which is go after privileged users. But the twist was adding a "just-in-time" factor. He co-founded a company in 2013 that focused on one problem with a solution that built upon past work (think NetWare) that had never been applied in this particular area before.

He told Security Now that, "Once we figured out that it was technically feasible to do that, we decided on it as a core concept of our company."

They keep Lockheed-Martin locked up, so they seem to have made some real word success in actually advancing security methods by being a part of a wider landscape rather than their own separate world. They work within the customer's ecosystem without connection to the deployed product.

While the conference is just beginning, the theme of vendors needing to cooperate and standardize is a big and pervasive one on the show floor.

— Larry Loeb has written for many of the last century's major "dead tree" computer magazines, having been, among other things, a consulting editor for BYTE magazine and senior editor for the launch of WebWeek.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/2/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9498
PUBLISHED: 2020-07-02
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
CVE-2020-3282
PUBLISHED: 2020-07-02
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
CVE-2020-5909
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
CVE-2020-5910
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
CVE-2020-5911
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.