Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Razi Rais, Christina Morillo, Evan Gilman, Doug Barth

Rating No ratings yet

What Is a Zero Trust Network? A zero trust network is built upon five fundamental assertions: The network is always assumed to be hostile. External and internal threats exist on the network at all times. Network locality alone is not sufficient for deciding trust in a network. Every device, user, and network flow is authenticated and authorized. Policies must be dynamic and calculated from as many sources of data as possible.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# Zero Trust Networks, 2nd Edition — Reading Guide ## 【One-Line Pitch】 A practical, vendor-neutral blueprint for designing networks that assume hostility at all times, ideal for security architects, DevOps engineers, and IT leaders modernizing their infrastructure beyond traditional perimeter defenses. ## 【Book Arc】 - **Opening (~0%–10%)**: Establishes the five core assertions of zero trust—hostile networks, persistent internal/external threats, distrust of network locality, universal authentication/authorization, and dynamic policy—and explains why automation is the essential enabler for building such systems. - **Early (~10%–23%)**: Introduces trust management as the central discipline, covering how trust originates with operators, the concept of variable trust scores, and how context-aware agents expose data to applications for fine-grained authorization decisions. - **Early–Middle (~23%–32%)**: Details the control plane architecture—enforcement components (proxies, load balancers, firewalls), policy engines, and the importance of stable data schemas for agent compatibility—plus organizational workflows like policy reviews and version control to manage distributed policy definition. - **Middle (~32%–48%)**: Focuses on trusting devices, from bootstrapping trust via manufacturer inheritance to hardware security modules (HSMs) and TPMs, including attack vectors (ROCA, side-channel, fault injection) and mitigations like confidential computing and secure boot. - **Middle–Late (~48%–end)**: Explores behavioral trust signals—device location patterns, network communication norms, and anomaly detection—while acknowledging the tension between location-based signals and zero trust principles, culminating in practical scenario walkthroughs (e.g., user access requests). ## 【Key Takeaways】 - **Zero trust is a mindset, not a product** (Opening): Treat every host as internet-facing and every network as compromised; this reframing eliminates reliance on VPNs and traditional perimeter stopgaps. (Early) - **Automation is the critical enabler** (Opening): Dynamic policy enforcement between control and data planes requires automated, rapid updates; configuration management systems are a stepping stone toward this capability. (Early) - **Variable trust scores beat binary policies** (Early): Assigning numeric trust values to components lets policy engines adapt to novel threats without constant manual adjustment, avoiding the rigidity/looseness trap of traditional access rules. (Early) - **Agent data needs stable schemas** (Early): Exposing agent details to applications via trusted channels (e.g., reverse proxy headers) requires fixed, well-known data formats—like a database schema—to ensure compatibility across control plane systems. (Early) - **Policy definition should be distributed but reviewed** (Early): Fine-grained policies burden administrators, so organizations distribute definition across teams while using version control and peer review to prevent overly broad rules that expand attack surface. (Early) - **Device trust is the hardest problem** (Middle): Devices are the battleground for security; bootstrapping trust from manufacturers, using TPMs/HSMs, and choosing between local vs. remote measurement are all trade-offs between security and operational flexibility. (Middle) - **Hardware trust has known attack vectors** (Middle): ROCA, side-channel, and fault injection attacks against TPMs/HSMs require layered defenses—confidential computing, secure boot, patching, and vendor diligence. (Middle) - **Behavioral signals must be non-binary** (Middle): Location and network patterns can inform trust decisions, but absolute rules (e.g., "office-only access") violate zero trust principles; look for anomalies and patterns, not hard boundaries. (Middle) ## 【Reading Tips】 - **Skim the opening chapters (0–10%)** for the conceptual foundation; the five assertions and automation discussion are essential context but don't require deep technical reading. - **Deep-read the trust management and control plane sections (10–32%)**—these are the intellectual core, covering variable trust, agent schemas, and policy engine architecture; the Bob scenario walkthroughs help cement understanding. - **Pay attention to the device trust chapters (32–48%)** if you're implementing hardware security; the attack vector details (ROCA, side-channel, fault injection) are critical for real-world deployment decisions. - **Treat the later behavioral signal sections (48%+) as design guidance**—they're valuable for policy design but require careful interpretation to avoid violating zero trust principles. - **Don't expect vendor-specific instructions**—the book deliberately avoids product recommendations; read it as a conceptual framework to apply to your own stack. ## 【Coverage Limits】 This guide covers the book's core concepts through the device trust and behavioral signal chapters; excerpts do not cover later sections on users, applications, traffic, or deployment case studies in detail. ##
Page 9
nd philosophies that are used to build a zero trust network. We hope you will find it useful to have a clear mental model for how to construct this type of s...
View in text
Excerpt 2
you must source it from somewhere and manage it carefully. There’s a small wrinkle though: the operator won’t always be available to authorize and grant trus...
View in text
Excerpt 3
and on the scenario as we delve deeper into various aspects of zero trust, such as users, devices, applications, and traffic. Let’s look at a typical workflo...
View in text
Excerpt 4
software. If an attacker has managed to get an unauthorized process running in user space, the TPM will not be very useful in its detection; thus, it has lim...
View in text
Excerpt 5
of the Cloud Native Computing Foundation (CNCF). Figure 6-4. Activity logs record device activity and serve as an audit trail, which is useful for determinin...
View in text
Excerpt 6
from the general logging of security events throughout the infrastructure, such as failed or successful logins, which is considered passive monitoring, there...
View in text
Excerpt 7
ess of a zero trust implementation. Assessment and Planning Building a zero trust network starts with a strong foundation, so once you understand scope, the ...
View in text
Excerpt 8
network. For example, a network might have vendor-supplied components that need to be secured without changing the device itself. As a device progresses thro...
View in text
Tags
AI categories
CybersecurityCloud NativeDevOps
networkcybersecurity
Publisher: O'Reilly Media
Publish Year: 2024
Language: English
Pages: 486
File Format: PDF
File Size: 8.0 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…