Zero Trust Audit Logging: Reliable Meets Simple
For years we have used syslog and netflow style logging, convinced that we could easily correlate events, find security issues, forensically see what happened. Then reality sank in. Multiple devices on the same IP due to NAT. Proxy servers. Spoofed IP. Big investments in SIEM and correlation became big work to get the most out of them. There has to be a better way!
Well, there is. We swap that perimeter-security and port-forward-DMZ-firewall world for Zero Trust Network Architecture. We place a cryptographically-secure header (JWT) on each transaction. We audit based on the contents of the JWT.
Now it doesn’t matter about IP address, 5-tuple-lookup, who had that DHCP address, spoofing. Each transaction has a GUID, called a SUB (Subject, e.g. the user). Correlation becomes exact match, no complexity, no confusion, no time horizons, no inside the NAT vs outside. Simple. Secure. Learn more in the below video!
Zero Trust Network Architecture: Crypto Header Makes Audit Simple. NAT no more! - YouTube
Zero Trust Network Architecture: Crypto Header Makes Audit Simple. NAT no more!
Learn More?
Resource Library
Recent Articles
The Epitome of Absolute Trust: Why Legacy Virtual Private Networks Are a Liability
Defence in Depth: Zero Trust is a Critical Layer, Not a Panacea
Securing the Flow: GAO Highlights Persistent Cyber Threats to Water and Wastewater Systems
NERC CIP Compliance for Small Independent Power Producers: A Pragmatic Approach
Cyber Security Is Physical Safety: Lessons From a Thermal Runaway
Water utility cybersecurity: The nearly £1 million lesson from South Staffordshire Water