S. Tanimoto, Sogen Hori, Hiroyuki Sato, Atsushi Kanai
{"title":"Operation Management Method of Software Defined Perimeter for Promoting Zero-Trust Model","authors":"S. Tanimoto, Sogen Hori, Hiroyuki Sato, Atsushi Kanai","doi":"10.1109/SERA57763.2023.10197716","DOIUrl":null,"url":null,"abstract":"Telework has been on the rise since the advent of COVID-19, and concerns have arisen about issues such as information leakage due to internal fraud. The zero-trust model is attracting attention as a countermeasure. This model reduces risk by constantly performing authentication and authorization, thus leading to improved security levels and safer operation. However, currently less than 40% of the companies in Japan have introduced zero trust into their security policies, mainly due to the lack of specific guidelines for operational management. We have therefore developed a security policy (service authorization conditions) for the software defined perimeter (SDP) zero-trust model as a universal operational management method to promote zero-trust implementation. Specifically, we simplify the time/place/occasion (TPO) conditions of users as T (inside/outside working hours), P (inside/outside the company, telework), and O (with/without visitors), resulting in 12 patterns, and for each of these TPO conditions, we propose detailed new service authorization conditions for SDP. The results of qualitative evaluation demonstrated the effectiveness of the proposed method. Our findings will contribute to the introduction of the zero-trust model and pave the way for safer and more secure corporate networks.","PeriodicalId":211080,"journal":{"name":"2023 IEEE/ACIS 21st International Conference on Software Engineering Research, Management and Applications (SERA)","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-05-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE/ACIS 21st International Conference on Software Engineering Research, Management and Applications (SERA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SERA57763.2023.10197716","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Telework has been on the rise since the advent of COVID-19, and concerns have arisen about issues such as information leakage due to internal fraud. The zero-trust model is attracting attention as a countermeasure. This model reduces risk by constantly performing authentication and authorization, thus leading to improved security levels and safer operation. However, currently less than 40% of the companies in Japan have introduced zero trust into their security policies, mainly due to the lack of specific guidelines for operational management. We have therefore developed a security policy (service authorization conditions) for the software defined perimeter (SDP) zero-trust model as a universal operational management method to promote zero-trust implementation. Specifically, we simplify the time/place/occasion (TPO) conditions of users as T (inside/outside working hours), P (inside/outside the company, telework), and O (with/without visitors), resulting in 12 patterns, and for each of these TPO conditions, we propose detailed new service authorization conditions for SDP. The results of qualitative evaluation demonstrated the effectiveness of the proposed method. Our findings will contribute to the introduction of the zero-trust model and pave the way for safer and more secure corporate networks.