Designing, Simulating & Implementing a Zero Trust Network Architecture (ZTNA)

Abdel Rahman Alkharabsheh, Naeema Monther, Nabtah Hamdan, Shamma Mohamed, Khulood Hamad, Amna Ahmed · 2025

In the UAE SMEs constitute 94% of all businesses and are of strategic importance to the national economy. But they are also particularly susceptible to the sophisticated nature of cyber evils, given their meager resources, both financial and technical. Most SMEs are unable to protect themselves from advanced threats such as zero-day exploits, due to insufficient infrastructure, talent and budget for security. Existing solutions are generally piecemeal, expensive, and require a level of expertise not available to the typical small to medium scale enterprise (SME). In this paper, we present a holistic Zero Trust Network Architecture (ZTNA) for regional SMEs. Built on the “never trust, always verify” principle, where every access request is continuously authenticated using context (user, device, location, behaviors, etc.); not just static credentials. The presented solution is based on a modular and scalable multi-layered security architecture with a superior cost effectivity. It's built to ensure least privilege access, use endpoint detection and response (EDR), make use of deception technologies such as honeypots, apply AI-driven Adaptive Trust Algorithms (ATA) to analyze user behavior and context on-the-fly. Machine learning models improve invasive detection by adapting to new patterns of attack. The ability of the framework will be assessed by implementing tools NMAP, Wireshark, Snort, Kali Linux and full penetration testing on both physical and virtual platforms. Key parameters are the accuracy, the implementation time, the compatibility, and the global system performance. As an applied work, we designed and implemented a security enterprise network in Cisco Packet Tracer (the offered in-house model) for a medium-sized enterprise with 200 employees. The network was segmented with VLANs, and had integrated firewall, redundancy and monitoring based on the CIA triad. A simulated Python cybersecurity environment probed the resilience, initially detecting 120 attacks against multiple vectors. Success factors After the gradual addition of multifactor authentication, firewalls, intrusion prevention and detection systems, network segmentation and patch management, successful attacks fell by 96%, proving that multiple layers of protection work. Simulated data center and VMware-based penetration analysis also indicated that timeous patching and anti-exploit defines were critical in mitigating reallife exploit situations. These findings confirm the efficacy of the ZTNA framework in practice and underscore the value of fieldtesting to bolster SME cybersecurity.

Read the paper · More papers on PaperTik