SysFlow: Toward a Programmable Zero Trust Framework for System Security

Sungmin Hong, Lei Xu, Jianwei Huang, Hongda Li, Hongxin Hu, Guofei Gu · IEEE Transactions on Information Forensics and Security · 2023

Zero Trust, as an emerging trend of cybersecurity paradigms in modern infrastructure (e.g., enterprise, cloud, edge, IoT, and 5G), is moving security defenses from static and perimeter-based control systems to focus on users and resources with no assumption of implicit trust. However, the current Zero Trust Architecture (ZTA) mainly focuses on the network security and lacks in-depth considerations on system-level security policies and abstractions, which leaves the realization of the principle incomplete. To bridge the gap, we propose an innovativeprogrammablesystem security framework called SYSFLOW to enable unified, dynamic, and fine-grained Zero Trust security control for system resources. SYSFLOW introduces a novelsystem flowabstraction to modelsystem activitiesacross the entire infrastructure, and provides a system-level data plane and control plane separation and abstraction. The new logically centralized controller accommodates a unifiedprogrammablePolicy Decision Point (PDP) that acquires a holistic view of system behaviors for controlling system resource accesses by translated programmable security policies into system flow rules. The SYSFLOW data plane, acting as Policy Enforcement Point (PEP), enforces translated system flow rules, which can be updated dynamically and facilitate fine-grained responsive actions. Our extensive evaluations demonstrate the effectiveness and scalability of SYSFLOW, which addresses the security issues in various scenarios with a minor performance overhead.

Read the paper · More papers on PaperTik