Blog

Endpoint Security Rooted in Zero Trust

Learn how endpoint security rooted in zero trust. As legacy PAM systems that relied solely on perimeter security were no longer sufficient, Zero Trust emerged as the go-to cybersecurity strategy to defend against today’s sophisticated cybercriminals and threats. Traditional control strategies rely on static rules. Zero Trust takes a more adaptive and dynamic approach; access […]
PX
Propelex team July 14, 2023 - 7 minutes read

Learn how endpoint security rooted in zero trust. As legacy PAM systems that relied solely on perimeter security were no longer sufficient, Zero Trust emerged as the go-to cybersecurity strategy to defend against today’s sophisticated cybercriminals and threats.

Traditional control strategies rely on static rules. Zero Trust takes a more adaptive and dynamic approach; access is regulated case-by-case to protect identity, device health and location.

Adaptive Control

An adaptive system is one that adjusts its behavior according to changing conditions, such as changing temperatures or pressure, in real-time. Adaptive control refers to the area of process control where controllers adjust parameters in real time to accommodate these modifications.

Adaptive controls are often employed in systems with variable, uncertain or time-varying process parameters. Here, it’s essential to design a control law that adapts according to these changing parameters without using any predetermined information about their bounds.

One way to achieve this is by altering the controller’s output in real-time to match the model of the system. In such a case, it uses a reference model (or model reference adaptive control, MRAC) as guidance on which inputs should be utilized for driving desired outcomes.

Another way to guarantee your endpoints are secure is by implementing a remote application control program that can sandbox vulnerable applications and limit their communication with sensitive data. This helps prevent malware infections as well as reduces the risk of unintended consequences from vulnerable software that unauthorized users attempt to install on company devices.

If you want to block all zero prevalence behaviors in your environment, click the Block All Zero Prevalence> button within an Adaptive Protection policy. Symantec’s machine learning algorithms detect which zero prevalence behaviors have shown low prevalence over 365 days and recommend blocking them so as to reduce the attack surface of your devices.

You can also alter the default settings for a group of machines to enable adaptive application controls. To do this, open the Workload Protections dashboard and from the Advanced Protection area select Adaptive application controls.

Defender for Cloud’s machine learning algorithms provide adaptive application control policy recommendations based on potential legitimate behavior that wasn’t previously allowed. You have the option to review and modify existing definitions, or have adaptations automatically generated based on telemetry from your environment.

Continuous Authentication

Endpoint security refers to the strategies and technologies utilized for preventing, containment, mitigation, and remediation of threats on endpoint devices such as laptops, desktops, tablets, mobile phones and other user-facing systems requesting access to enterprise resources.

Endpoint security is essential to achieve zero trust, which requires that everyone accessing your network and IT resources be authenticated at all times – not just during logins but for every session that occurs. This includes not only logins but also any sessions made.

Continuous authentication can be achieved through various methods. One such approach is presence-based authentication, where a user’s computer continuously scans for the presence of a token they carry with them. If it detects that the token has left their vicinity, it locks out access until its return to its owner.

Another approach is to utilize behavioral biometrics to monitor user behaviors and detect deviations from normal patterns. This can be done through things like interactive gestures, typing style, finger pressure, and how long a user holds each key on their keyboard.

Other methods for continuous authentication may involve voice recognition, which utilizes the user’s voice to confirm their identity. This could be done through their speech pattern or pitch variation.

Furthermore, many Zero Trust solutions provide session recording for forensics and reporting in Security Information and Event Management (SIEM) systems.

Continuous authentication can be a beneficial component of endpoint security by blocking unauthorized access and spreading malware and insider threats – particularly ransomware.

Finally, continuous authentication can also be employed to guarantee only authorized personnel have access to sensitive data. This is accomplished by initiating step-up authentication after an initial login when a user attempts to access more confidential databases or resources.

Continuous authentication requires the balance between privacy concerns and security. This can be a difficult balance to strike when working with various technology types. Nonetheless, an ideal system will be able to incorporate multiple authentication mechanisms and offer the highest level of protection for its administrator.

Device Health & Hardware Protection

Zero Trust is a modern security model that adapts to the complexity of today’s world. It combines adaptive control and mutual authentication to verify each device’s identity and integrity regardless of location or owner. This helps protect company data, reduce breach risks and detection times, improve visibility into network traffic patterns, consolidate control across cloud environments, and conduct compliance auditing more efficiently.

Many organizations have relied on traditional malware protection technologies like antimalware or patching solutions to keep corporate systems secure. Unfortunately, these measures don’t always address the security risks posed by devices connecting to an organization’s networks and resources – especially when those devices run a new operating system.

Many companies rely on system health reporting to determine whether a device meets their policies. Unfortunately, this approach may not always be reliable since malware can spoof system health information and show an incorrect healthy state.

To resolve this issue, Windows 10-based devices use a new security feature called device health attestation. This involves creating an authentic root of trust with the Trusted Platform Module (TPM).

The TPM can store encrypted blobs containing measured boot data and a device ID, which are reported back to an relying party via remote health attestation service. The attestation service then verifies the TPM’s status, reviews logs, and issues an attestation statement that allows access to resources.

This approach helps secure the boot process by sending measured data to a remote service, which can detect if a low-level exploit has been installed and compromised. Furthermore, that service uses that data to validate device health attestation reports.

Additionally, a health attestation solution can detect when a device isn’t running the latest patches and security updates. This is an essential step when safeguarding high-value assets.

Health attestation also utilizes client and cloud components to restrict access to high-value assets, as well as conditional access capabilities that evaluate identity signals before granting permission to access corporate resources. This enables users to utilize corporate assets while remaining compliant with company policies and regulations.

Fine-Grained Access Control

Fine-grained access control is an integral component of endpoint security. It helps keep sensitive data out of the wrong hands while still enabling more flexible use of information.

Cloud computing and big data analytics often utilize fine-grained access control, which assigns each piece of data its own policy for who can view it. The policy can be determined based on several factors such as the user’s role and intended action on the data.

The most prevalent example of fine-grained authorization is attribute based access control (ABAC). ABAC creates policies that determine how users can access data based on their roles and other specific attributes.

Another application of fine-grained authorization is granting specific access to specific data to certain users. For instance, if a customer service representative needs to view their account balance, they can be granted only that customer’s unique account number; this will prevent them from altering or adding information to a record.

Controlling who has access to which data segments is paramount in large businesses. This is especially true when storing the information in the cloud.

As remote work becomes more commonplace, organizations must be able to restrict access to data based on context. This means granting certain pieces of information based on time and location rather than just the person’s role.

These restrictions help organizations meet new privacy laws and adhere to regulations pertaining to sensitive data. For instance, a business may only permit employees to access certain pieces of information during office hours or use only the last four digits of a customer’s social security number for identity verification purposes.

Implementing fine-grained access control helps companies protect sensitive data from harm while giving employees more freedom to distribute information across teams and departments. Doing so encourages innovation and accelerates business operations.

Fine-grained access control is an ideal method for safeguarding data in the cloud or analytics environment. It enables you to manage data with different access requirements without sacrificing the advantages of cloud storage or big data analytics.

Work with Propelex

Ready to build AI
into your stack?

Propelex helps teams evaluate, integrate, and scale AI workflows — from MCP strategy to full agentic architecture. Let's find the right entry point for your organization.