ba.net private cloud office beyond “fortress” security... · jumping through monopoly license...

32
BeyondCorp: Beyond fortress security BA.net Private Cloud Office

Upload: others

Post on 09-Jul-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

BeyondCorp: Beyond fortress securityBA.net Private Cloud Office

Page 2: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Open Source SoftwareFreedom, flexibility, low cost, no vendor lock-in, nojumping through monopoly license hoops, byod, localsoftware, hybrid cloud, retire old firewalls, new securitymodel zero trust, corporate access proxy.

Page 3: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

New hybrid cloud model:risks and threats

Page 4: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

How some enterprisesthink of security

But there are issues with this approach...

Page 5: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Four issues that are wrecking the castle approach

Mobileworkforce

Breaches Plethora ofdevices

Cloud services

5

Page 6: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

ERP

SERVER

Access yesterday:On-premises walled gardens

VPN

On Prem

IdentityCRM

SERVER» What about contractors?

6

Employee

Page 7: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

On-prem

ERP

SERVER

Evolution:Not just employees with corporate devices

VPN IdentityCRM

SERVERContractor

Unintended CRM accessfor contractor

Employee

» What about the cloud?7

Page 8: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

On-prem

Evolution:Infrastructure goeshybrid-cloud

VPN Identity

CRM

VM

ERP

VM

» What about single sign on?8

Contractor

Employee

Page 9: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Evolution:Identity goeshybrid-cloud

IdentityCRM

VM

ERP

VM

Now everything is either local softwareor cloud replicated

» What threats are there in this new cloud world?9

Contractor

Employee

Page 10: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Problems

IdentityCRM

VM

ERP

VM

Phishing? Malware?

Man in theMiddle?

No chokepoint to enforceaccess control?

» What should I do?

XSS/SQL injection?

10

Contractor

Employee

Page 11: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

WALLS DON’T WORK

BeyondCorp’s realization

Page 12: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Solutions

IdentityCRM

VM

ERP

VMSecurity

keysDevice

management

TLS

Proxy for accesscontrol, TLS

termination, basedon BeyondCorp

visionAc

cess

prox

y

» So what’s the ideal?

App securityscans

12

Contractor

Employee

Page 13: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

I want my Office application service to be:

● Accessed only by employees● From well-managed client devices● In home country● Using strong user authentication● And proper transport encryption and● Hardened against application attacks

13

Page 14: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Implementing BeyondCorp

Page 15: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

3Authenticated

AuthorizedEncrypted

Core principles of BeyondCorp:

Any network Context-basedaccess

2v1

15

Page 16: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

High level

Access proxy

Single sign on

Accesscontrolengine

Userinventory

Device inventory

Trust repository

Security policy

16

Page 17: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Know your people

User inventoryJob functionchanges

17

Page 18: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Know your devices

Procurement End oflife

Provisioning

Asset tracking Certificates

Device inventory

18

Page 19: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Dynamic trust repository

Policies Deviceinventory

PeopleLevel of trust

Certificates

Trust repository

19

Page 20: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Access policy

Service request

Accesscontrolengine

Userinventory

Device inventory

Trust repository

Security policy

20

Page 21: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Access from anywhere

Access proxy

Single sign on

Accesscontrolengine

21

Page 22: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Migrating to BeyondCorp

Page 23: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

New unprivileged network

New VLAN Add devices Deploy

+ +

23

Page 24: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Traffic analysis

24

Page 25: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Safely migrate devices

25

Page 26: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Better loaners

Page 27: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

● An overview: A New Approach to Enterprise Security● Front-end infrastructure: The Access Proxy● Migrating to BeyondCorp: Maintaining Productivity

While Improving Security● The Human Element: The User Experience

BeyondCorp Papers

27

Page 28: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Lessons learned:What 7 years taught us aboutmigrating services to the cloud

Page 29: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Lessons learned migrating to hybridcloud

Get, and retain, executive supportEnable painless migrationRun highly reliable systems

29

Page 30: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Lessons learned migrating to hybridcloud

Get, and retain, executive supportEnable painless migrationRun highly reliable systems

30

Page 31: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

31

Migrate carefullyso as not to breakexisting users

3Base all access

decisions on what youknow about the user

and their device

2Have zero trustin your network

v1

Remember:

Page 32: BA.net Private Cloud Office Beyond “fortress” security... · jumping through monopoly license hoops, byod, local software, hybrid cloud, retire old firewalls, new security model

Thank you