End 2 End Zero Trust Network Security Framework
Philip Wong
Principal Solution Architect
Cisco Greater China
Agenda
• Trends and Challenges
• A Practical Zero Trust Approach
• Use Case
• Call for Collaboration
© 2020 Cisco and/or its affiliates. All rights reserved.
Shift in IT Landscape
Users, devices and apps are everywhere
Remote Users Cloud
Applications
Evolving
Perimeter
Hybrid
Personal & Infrastructure
Mobile Devices
Cloud
IOT Devices Infrastructure
© 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public
© 2020 Cisco and/or its affiliates. All rights reserved.
Traditional Security
is like a castle
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
© 2020 Cisco and/or its affiliates. All rights reserved.
üFocus on data protection,
What about not on attacks
üAssumes all environments
“Least-Privilege Access” are hostile and breached
(i.e. grant access, but üNo access until user +
device is proven “trusted”
make a very specific) üAuthentication not equal to
Authorization
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
© 2020 Cisco and/or its affiliates. All rights reserved.
A brief history of Zero Trust
Jericho Forum ZT BeyondCorp CARTA & ZTX ZTA
2004 2010 2014 2017 TODAY
De-perimeterisation Multiple Models Emerge Generalized
An international group of Forrester coined Zero Trust. The industry has
CISOs and Vendors largely accepted
Google published their ZT Zero Trust
Focus on solving “de- solution as BeyondCorp. Architecture as
perimeterisation” problem the general term.
Forrester expands to Zero
Early output calling for “the Trust eXtended.
need for trust”
Gartner named their model
Continuous Adaptive Risk
and Trust Assessment.
© 2020 Cisco and/or its affiliates. All rights reserved.
v Eliminate Network Trust
v External and internal threats
exist at all times
v Every user, device, app and
network flow is authenticated
and authorized
Zero Trust v Policies-based and must be
Architectural “Pillars” dynamic; postures calculated
from as many sources as
possible
v Constant logging, monitoring
and re-scoring
v Automation is key to build and
operate a ZT architecture
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
© 2020 Cisco and/or its affiliates. All rights reserved.
Cisco Zero Trust Approach
v Multi-factors of User Identity “Least Privilege Access” to: v Original tenets used to
v Device context and Identity v Network establish trusts still true?
v Device posture & health v Applications v Threat Traffic?
v Location v Resources v Behavior baselining
v Relevant attributes & contect v Users & Devices v Malicious or anomalous
actions?
© 2020 Cisco and/or its affiliates. All rights reserved.
Sample Zero Trust Architecture Policies Establishment
Policy Information Point (PiP) Policy Administration Point (PaP) Policy Information Point (PiP)
Policy Decision Point (PdP)
User
Inventory
Other ZT Policy Engine Trust Engine
Device
Sources Inventory
Workload / App
Inventory Feedback Loop
Control Plane
Data Plane
Policy Enforcement Point (PEP)
Mode 2
App
Network Equipment
Endpoint Internet
IPS, FW
Applications
SaaS
Network Legacy
App
Legacy CLOUDs
SaaS
App
Legacy
On-Premise App
© 2020 Cisco and/or its affiliates. All rights reserved. Mode 1 Polices Enforcement
Zero Trust Use Case Scenarios
Policies Policies
WORKFORCE WORKLOAD WORKPLACE
User User
Inventory Inventory
Device Workload / App Device
Inventory Inventory Inventory
+ Network / Location Context
© 2020 Cisco and/or its affiliates. All rights reserved.
WORKLOAD
Workload
Ø “No more network centric authentication”
Ø Shifting to “a serverless world”
Ø Application Services relationship @uto-discovery
Ø Constantly Monitor flows
Ø Apply Machine Learning, baselining activities, identify anomalous, …
Ø Establish and Simulate Trust Policies
Ø Multi-domain enforcement
ØAgents
ØPolicy-based network
Ø3rd party OPEN integration
© 2020 Cisco and/or its affiliates. All rights reserved.
WORKLOAD
• Mode 1 Applications transition to Micro-
Services
• Safeguard Interaction between Mode 1 and
Mode 2
• Securely expose Mode 2 Services to ultimate
consumers
© 2020 Cisco and/or its affiliates. All rights reserved.
Embracing Other contextual data
© 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
© 2020 Cisco and/or its affiliates. All rights reserved.
© 2020 Cisco and/or its affiliates. All rights reserved. #CiscoLiveLA © 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public
Expand to a much wider scope with context data exchange
© 2020 Cisco and/or its affiliates. All rights reserved.
Cisco Platform Exchange Grid (pxGrid)
• Publish/Subscribe Model with Bi-directional Context Sharing and
Consuming Control
IOT Ecosystem partner (e.g. MRI)
Policy Enforcement Point
© 2020 Cisco and/or its affiliates. All rights reserved.
Call for Collaboration
• Platform Exchange for context sharing and innovative integration
between
• IOT Devices
• Thin Applications
• Further information
• Cisco Zero Trust
• [Link]
• pxGrid White Paper
• [Link]
api/docs/overview/Cisco_pxGrid_White_Paper_09192018_JE.pdf
• [Link]
© 2020 Cisco and/or its affiliates. All rights reserved.