HomeMalware & ThreatsNo Zero Trust in Zero Trust

No Zero Trust in Zero Trust

Published on

spot_img

In January 2023, the Cloud Security Alliance conducted a survey which probed deep into the management of identities on which artificial intelligence (AI) systems depend. Alarmingly, the survey revealed that fewer than 25% of organizations have a documented and formally adopted policy in place for creating or removing identities used by these systems. Furthermore, over 16% of respondents indicated they do not even track the creation of new identities, even though these identities are responsible for holding access tokens to critical production systems. This situation raises serious concerns, as those tasked with governing access claim to have no record of the identities that pose significant risk.

The crux of this issue relates to a widely circulated axiom within the cybersecurity field: “identity is the new perimeter.” This phrase encapsulates a shift in focus from network-based controls to identity-based ones, thereby emphasizing the importance of managing who gains access to a system. However, this focus leaves out some vital questions: not only how to grant access but also what individuals can do once inside, the verifications that approved such access, and the potential consequences if a credential is compromised.

Access is now where the real attack surface lies. It’s characterized by the enduring permissions associated with an identity, regardless of whether those permissions are exercised. While multi-factor authentication and conditional access measures may secure entry points, they do not protect against the extended exposure that comes from standing permissions. The ironies of a Zero Trust architecture are particularly evident here; while it promotes a principle of minimal trust, some level of unavoidable trust must still be extended to any entity that possesses an entitlement. This results in a persistent, silent trust that exists until something compels it into action, marking an inherent gap in the Zero Trust ideology.

Moreover, existing security frameworks, such as NIST’s Cybersecurity Framework, presuppose a thorough inventory of assets as a precursor to access control. Several frameworks, including those from Germany’s BSI IT-Grundschutz and France’s ANSSI, prioritize inventory management as essential for implementing protective measures. This creates an underlying assumption: that every identity is registered during a structured onboarding process—a human enters, HR generates a record, and necessary approvals are obtained. However, the reality is starkly different when dealing with AI agents, which are often created spontaneously without undergoing the same rigor and accountability as human identities.

The construction of these AI identities often bypasses the established protocols. They can be generated through direct connections by developers or business users, sometimes without a requisition process or managerial approval. In many cases, these identities may not have a corresponding HR record, nor do they face a decommissioning process at project termination. This significant gap in oversight results in AI agents holding access with little to no accountability, which runs contrary to a framework designed for human interactions.

Evidence of this discrepancy is accumulating. According to a report from Netwrix, organizations that have significantly increased the number of identities through AI are reporting breach rates of 43%, compared to only 11% for those that have not. This stark contrast underscores the growing security vulnerabilities as AI expands its role within organizations.

An argument often posited is that behavioral detection systems may bridge these gaps, enabling real-time monitoring of AI actions—tracking tool calls, data access, and API interactions, while establishing a baseline from which deviations can be flagged. However, this method assumes that the entities being monitored exhibit stable behavior. In contrast, AI agents are frequently erratic; they operate under a non-deterministic framework, leading to unpredictable patterns that complicate monitoring. Unlike human agents, they do not adhere to working hours, and actions can occur abruptly and disappear quickly after achieving their necessary outcomes.

To mitigate these challenges, security teams must transition towards a more rigorous accounting principle, establishing that access should never exceed the limits of documented permissions. Not only should every identity possess standing permissions, but a comprehensive inventory of all identities—human or otherwise—should be maintained. Non-human identities should be subjected to the same lifecycle protocols as their human counterparts: they require defined ownership, consistent reviews, and appropriate decommissioning triggers.

Ultimately, this situation emphasizes the importance of understanding who and what exists within an organization’s ecosystem. With reliance on a perimeter-focused approach, organizations have left themselves vulnerable to internal risks that remain unchecked and unmonitored. An overarching audit of existing permissions and identities should be the priority, ensuring that a comprehensive inventory is established. Following this accounting, organizations can fine-tune their security frameworks to protect against both internal and external threats.

In summary, the evolution of cybersecurity must address the dual challenges of identity management and access control. While much effort has gone into scrutinizing who attempts to enter, equal importance must be accorded to what happens once those identities are inside. Establishing robust systems of accountability is essential to reducing risks associated with poorly managed identities, particularly as AI technology continues to reshape workplace dynamics. Through better understanding and management of these identities, organizations can move closer to achieving a truly secure environment while also embracing the efficiencies brought about by automation.

Source link

Latest articles

How China Built the Infrastructure for State-Sponsored Hacking

The Quartermaster Model of Hacking: A Deep Dive into QTFY Operations Over the past year,...

AI Vulnerability Surge Disrupts the OT Patch Cycle

IEC 62443: A Framework for Enhanced Operational Technology Security The IEC 62443 standard has emerged...

Filigran Introduces AI-Driven Attack Chaining to OpenAEV for Autonomous Pentesting

Filigran has recently unveiled an innovative attack chaining capability integrated into its OpenAEV platform,...

EP 179: Revisiting the Courthouse

In the latest episode of the popular podcast Darknet Diaries, listeners were taken on...

More like this

How China Built the Infrastructure for State-Sponsored Hacking

The Quartermaster Model of Hacking: A Deep Dive into QTFY Operations Over the past year,...

AI Vulnerability Surge Disrupts the OT Patch Cycle

IEC 62443: A Framework for Enhanced Operational Technology Security The IEC 62443 standard has emerged...

Filigran Introduces AI-Driven Attack Chaining to OpenAEV for Autonomous Pentesting

Filigran has recently unveiled an innovative attack chaining capability integrated into its OpenAEV platform,...