10 ms·
Zero Trust Strategy and Roadmap
- degenerate 4y agoThe actual roadmap document (PDF) is not linked directly from the press release: https://dodcio.defense.gov/Portals/0/Documents/Library/DoD-ZTExecutionRoadmap.pdf https://dodcio.defense.gov/Portals/0/Documents/Library/DoD-Z...
- oyashirochama 4y agoZero trust is fun, it's fine if the computers were all from the last decade and not circa. 2011-2013 HP mini's with HDD rather than SSDs or M.2 in the newest revisions of allowed devices on our networks.
- eikenberry 4y agoWhy would the hardware matter? Zero trust has zero (ha!) to do with hardware.
- jabl 4y agoDon't zero trust architectures often require secure boot as well as a functioning TPM-like secure enclave to do attestation on the client device before allowing the user to logon to some resource?
- PLG88 4y agoI would say thats a bonus. Zero trust should be based on strong identity (e.g., x509) and authentication/authorisation-before-connect, ideally that identity would come from HWRoT/TPM. Unfortunately, many vendors say they are zero trust while only implementing some aspects/principles. I wrote a blog on this topic earlier in the year - https://netfoundry.io/demystifying-the-magic-of-zero-trust-with-my-daughter-and-opensource/ https://netfoundry.io/demystifying-the-magic-of-zero-trust-w...
- daveevad 4y agoIt seems to me that distributing this information as a PDF undercuts the message a bit. It's tangential; sure, but also, it doesn't strike me as particularly good security either.
- eat_veggies 4y agowhat do you expect it to be distributed as?
- brookst 4y agoAdobe Flash wrapped in an executable player, of course.
- FpUser 4y agoThanks for making evening less boring ;) I also have my somewhat related strategy, it is called Zero Rust.
- daveevad 4y agoI was thinking text/plain would be best way to get the point across.
- nvr219 4y agoThe type of people that DoD wants to read this are not the type of people that prefer text/plain.
- daveevad 4y agoThose are the people that need to understand that a lot of security depends on simpler file formats.
- imwillofficial 4y agoExcept that’s completely false.
- deleted 4y ago[deleted]
- asynchronous 4y ago“The Department’s most consequential strategic competitor and the pacing challenge for the Department, the People’s Republic of China,3 as well as other state-sponsored adversaries and individual malicious actors often breach the Department’s defensive perimeter and roam freely within our information systems.” This statement from the actual PDF really is telling for how far the DoD has dropped the ball on protection- maybe spend less time fleshing out offensive capabilities and more time on defense of your citizens?
- edgyquant 4y ago>maybe spend less time fleshing out offensive capabilities and more time on defense of your citizens With our budget the two are not mutually exclusive
- prvit 4y agoAnd they’re often the same. Take cyber “offensive” capabilities for example. Why do those exist? To provide intelligence for defense.
- Godel_unicode 4y agoNot really? Cyber threat intelligence is an incredibly overblown industry, remarkably similar to the xkcd about crypto. Offensive capabilities are for Natanz. Everyone seems to think they need super ninja threat intel to protect them from elite nation state hackers, meanwhile they’re being randomware’d with metasploit modules from 8 months ago. Run A/V and patch, that’ll be $1.7million, thanks.
- prvit 4y agoNothing in my comment has anything to do with “cyber threat intelligence”. Did you reply to the wrong comment?
- Godel_unicode 4y ago
- edgyquant 4y agoThis is the kind of decentralized systems web3 is supposed to be. Not ethereum tokens
- toomuchtodo 4y agoWeb3 came and went to no fanfare in places like Estonia, who have cutting edge digital identity and trust systems built on boring, existing crypto primitives and smart cards, while in the US we’re stuck with checks and paper signatures. Everyone raves about distributed identity while Login.gov is now integrated with almost 220+ federal agency systems, is the primary identity provider for Social Security (and soon, IRS after the ID.me debacle), and is a bit of PKI and CAC/smart card infra away from being a huge leap forward. Hot take: real innovation is finding the right person’s metaphorical arm to twist to get enough leverage to get the tech implemented. The tech is the easy part. Bureaucracy hacking is underrated. https://e-estonia.com/solutions/e-identity/id-card/ https://e-estonia.com/solutions/e-identity/id-card/
- sangnoir 4y agoGemalto was hacked, possibly by GCHQ/NSA. How confident are you that the keys in the smartcards aren't compromised by an peer nation-state (e.g. China)? Security is always hard when you adversary is patient, motivated and well-resourced.
- toomuchtodo 4y agoMore confident than in blockchains.
- dhx 4y agoFor the following techniques: 1.6 Behavioral, Contextual ID and Biometrics & 7.4 User and Entity Behavior Analytics - focus monitoring/auditing on accounts that all of a sudden transfer 10GB data when they usually only transfer only 100MB/day, or where the employee has had to be asked for that one time of the year to login on a weekend at an office they don't usually visit. 5.1 Data Flow Mapping - detect unexpected egress of data by defining ahead of time the volumes of data being transferred between systems (e.g. 2AM backup transfers 100GB to systemX and between 9AM-5PM there is a usual data transfer rate of 1MB/s therefore 100MB/s transfer rate at 1PM would raise an alert). How well do these techniques work in practice, particularly in a huge organisation? I would have thought the number of false positives would be very high and the people monitoring the anomalous behaviour wouldn't have much or any context to know whether something is legitimate or not. A more feasible approach may be system owners installing a new system would have to specify rate limits (including per time of day, per API call and/or per user) and would have to lodge as part of a change request whether these limits need to be temporarily increased to cater for a one-off or rare event such as a major system upgrade. But given that some of the other techniques listed indicate a lack of awareness of what software is installed and is in use, it seems unlikely that specification of rate limits would happen any time soon.
- nekoashide 4y agoA big problem is insiders selling information or ransoming it under the guise of a breach. Employees are the single greatest threat to any organization so behavior analytics is starting to become really big. As I tell people, "We don't care if you browse Reddit, we only care if you start doing things an employee shouldn't". But to answer your questions we would just ingest those alerts into Splunk, build a KB on how to handle the alerts when they trigger and then begin the process of filtering out the noise. The SOC Analyst who works these alerts will get numb to them but still pick out the unusual ones to investigate.
- CDT-MLT 4y agoThat is something right there. I am intrigued by this.
- 4y ago
- _HMCB_ 4y agoDidn’t know much about Zero Trust. This article was helpful: https://www.csoonline.com/article/3247848/what-is-zero-trust-a-model-for-more-effective-security.html https://www.csoonline.com/article/3247848/what-is-zero-trust...
- rkagerer 4y agoWhen I think of "zero trust" I think concepts like zksnarks where all the information is already out there (go ahead and let your org leak, in fact you can even deliberately publish it) but protected in such a way that only legitimate uses can decipher / make use of it. What they're talking about here sounds more like things that ought to be obvious but the industry got lazy about.
- imwillofficial 4y agoYour understanding is an uncommon one. What they are talking about here is the more common understanding.
- manbash 4y agoFirewall and VPN is the obvious part, and that's the industry standard. Zero-trust means that Access Control is more finely-grained, down to the machine/user level. In this approach we don't trust any machine/user inside the organization as well.
- PLG88 4y agoI think its goes beyond this, its doing authentication-before-connect using strong identity so that we can have 'zero trust' of the network, whether internet/WAN (e.g., closed inbound ports), LAN or even host OS.
- mtgx 4y ago
- CDT-MLT 4y agoWhat is a real joke is how you can make into the phone system at the DOD and speak to a human and they give you information without even verifying who the hell you are. Still happens all the time.
- desimone 4y ago> Our adversaries are in our networks, exfiltrating our data, and exploiting the Department’s users. I'm happy to see this admission lead the document; it's bold coming from an org as conservative as the DoD. To see critical mass around the idea that -- like it or not -- adversaries (both malicious insiders and outsiders) are already on trusted networks is really encouraging to see. First, let's be clear what this document is and isn't. > Importantly, this document serves only as a strategy, not a solution architecture. Zero Trust Solution Architectures can and should be designed and guided by the details found within this document. This is a long term strategy doc, not an implementer's guide. Operators looking for zero-trust easy mode won't find it here. It's also very DoD specific. But there are some good parts. I read the doc so (maybe?) you don't have to. I made some screenshots of the portions I thought most relevant. https://imgur.com/a/Dhm7yvi https://imgur.com/a/Dhm7yvi The comments will make more sense if you are viewing those. > Zero Trust uses continuous multi-factor authentication, micro-segmentation, advanced encryption, endpoint security, analytics, and robust auditing, among other capabilities, to fortify data, applications, assets, and services to deliver cyber resiliency. The Department is evolving to become a more agile, more mobile, cloud-supported workforce, collaborating with the entirety of DoD enterprise, including federal and non-federal organizations and mission partners working on a variety of missions. If you somehow managed to read the above without going into a post word salad coma, I'm sorry. I highlighted the section just to bring up there's an awful lot of enterprise security buzzword and DoD acronym bingo going on. But there are some good thoughts too. > Zero Trust is much more than an IT solution. Zero Trust may include certain products but is not a capability or device that may be bought. It's nice to hear this being reiterated so often. A good start! > Zero Trust security eliminates the traditional idea of perimeters, trusted networks, ... Zero trust is -- to me at least -- mostly about the idea of removing perimeters and trusted networks as the basis for trust and access control. So I'm with you so far. > ... devices, personas, or processes and shifts to multi-attribute-based levels of confidence that enable authentication and authorization policies founded on the concept of least privileged access concept of least privileged access But it's interesting here that the authors are also calling out and devices, personas which is what I'd argue are the fundamental contextual attributes that allow you to replace a "trusted perimeter"; if we aren't using perimeters, devices, personas... what is the DoD suggesting we use? I can't find it. > At its core, ZT assumes no implicit trust is granted to assets or users based solely on their physical or network location (i.e., local area networks versus the Internet) or asset ownership (enterprise or personally owned).12 I strongly agree with the first point, but disagree and am perplexed by the second. Zero trust is all about getting rid of a trusted network location. However, asset ownership *matters* because it affects not only the identity of the user, but also the _state_ of the device. It's totally reasonable to have different levels of trust for a managed company owned device with a known set of endpoint protection tools, vs a BYOD device whose device state is largely unknown. The doc does a good job of outlining the "Why" of zero trust. And what's required from an org to make it possible. Unfortunately, while the document starts out strong, it quickly becomes "actually, zero trust is every security thing you've ever heard of". Paired with a timeline no one will ever meet ever.
- teleforce 4y agoNIST Zero Trust Architecture recommendation: https://www.nist.gov/publications/zero-trust-architecture https://www.nist.gov/publications/zero-trust-architecture
- imwillofficial 4y agoI was pushing this stuff in DoD for years. Glad to see it catch on.
- nonrandomstring 4y agoTake some solace in the fact that you probably _did_ make a difference. Just one you couldn't see while being ignored for years.
- imwillofficial 4y agoIt’s exhausting to the soul to yell into the void for so long.
- headsoup 4y agoIs zero trust just the same idea as agile 'fixing' waterfall? I.e. is it just another 'practice' marketed to solve an existing people and process issue that can be readily solved with proper focus , which just introduces its own issues anyway? Like sure, zero trust will work IF you do it really well, but then so will the existing environment.