Adding Zero Trust in BYOD Environments through Network Inspection

Afshin Zivi, Christian Doerr · 2022

The integration of new enterprise computing practices and the emergence of sophisticated adversarial tactics has severely threatened the established security model of perimeter defense, in which controls placed at the organization’s or segment boundary shall fend off or contain attacks. While zero trust networking promises angles to cope with new workplace habits and advanced adversaries, it requires a comprehensive collection and evaluation of sensor data on network devices. While from the organization’s and end user’s perspective it is desirable to integrate personal devices as part of a bring-your-own-device policy, collecting the necessary sensor data on user-owned devices raises severe privacy concerns for many users.In this paper, we investigate how zero trust may be applied in BYOD environment without requiring users to install monitoring software, but indirectly infer the device’s status from sensor information passively collected in the network. We find that this collected information can provide high visibility, and can thus balance both the requirement for security and user acceptance.

Read the paper · More papers on PaperTik