Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cloud
    • Cloud
    • Cybersecurity
    • Networking

    Five Pillars of Post-VPN Security

    Written by

    eWEEK EDITORS
    Published November 19, 2019
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      For years, the combination of a virtual private network (VPN) and firewalls has been the model of choice for enterprises seeking to secure connectivity to the internet. And for years, the model has been a highly successful one. 

      However, the era of perimeter security is almost over. Its demise has been accelerated by two trends:

      • First is the increasing sophistication of attacks that exploit users’ browsing habits to gain a foothold inside corporate networks. Once inside, attackers can move laterally for assets to steal or compromise.
      • The second is the move away from deploying applications in-house to hosting them in the cloud.

      Often, traffic from remote workers is backhauled over a VPN to a corporate data center or branch office, where it is subsequently re-routed over another VPN connection through less than optimal internet routes to IT services in the cloud. Such backhauling is slow and can introduce added cost, complexity and points of failure.

      Go here to see eWEEK’s listing of Top Network Monitoring Companies.

      Go here to see eWEEK’s listing of Top Next-Generation Firewall Vendors.

      This eWEEK Data Points article contains industry information from Alexander McMillen, Vice-President of Operations for Security as a Service Platform provider OPAQ. McMillen, an expert in systems and network engineering, as well as IT operations, is founder of the Washington, D.C. chapter of the Vyatta Secret Society, a user group that enables companies to perform software-defined networking functions on commodity hardware.

      To overcome these threats and performance bottlenecks, organizations are looking to VPN alternatives that embrace some or all five of the following elements:

      Data Point No. 1: Distributed Network Security

      The first step in creating a post-VPN security model is to eliminate the need for centralized firewalls and the related backhauling of traffic to a single location. This new approach involves connecting individual workstations and mobile devices to a cloud-based firewall service. These connections must be maintained in an always-on state behind the scenes without requiring any interaction from end users. 

      Such an architecture requires a service provider with a robust network that ensures end-users experience superior network performance wherever they travel. At the same time, this architecture should give IT security managers access to the same logs, dashboards, and security controls they are used to seeing from a traditional firewall.

      Data Point No. 2: Application Access Proxies 

      Sophisticated proxies are essential to this new security architecture. Properly designed, these proxies should give corporate users easy access to internal applications via their web browsers. Users must be able to simply type a URL, knowing they don’t have to fuss with a VPN client connection first.

      At the same time, these proxies protect applications from internet threats, giving IT departments complete visibility and control over who is using what services, from where, and when — all based on corporate policies, device and user identities and device configuration. The architecture enables IT to provide reliable services while managing applications in a central place.

      At their core, proxies need an HTTPS gateway that protects applications while it authenticates users. Ideally, this gateway automatically provisions cryptographic client certificates to each workstation and mobile device based on the unique identity of that device and its user.

      Data Point No. 3: User and Device Authentication

      For cloud-based hosting of applications to function smoothly and securely, the network security architecture underpinning it should use multi-factor authentication (MFA) to grant or deny user access to applications. Meanwhile, endpoint devices and their activity should be monitored and audited, including system status and configuration information. Visibility into device state and behaviors can be used to determine risk and whether access to applications should be approved or denied. 

      Finally, it is important to prevent unmanaged, bring-your-own-device and Internet-of-Things machines from connecting to applications. 

      Data Point No. 4: Zero-Trust 

      Corporate networks will likely never disappear, nor will the threats that they face. For this reason, it is vital to remove trust from internal networks in order to prevent threats from spreading laterally. Implementing Zero Trust requires the dynamic segmentation of networks and enforcing firewall policies on each endpoint in real time as users and hosts interact. Ideally, policies should be fashioned around user and device identity, as well as traditional IP addresses, ports and protocols. 

      In the real world, Zero Trust segmentation means that two different users on different teams can be attached to the same local network while having access to different resources. Such segmentation greatly enhances the speed and accuracy of security staff in responding to a potential threat.

      Data Point No. 5: Continuous Monitoring and Reporting 

      Today, the functionality of enterprise network security programs tends to be largely designed to meet compliance requirements. At the same time, these programs are becoming more distributed, making it more difficult for IT departments to effectively monitor security controls.

      A post-VPN security architecture can greatly alleviate, even entirely eliminate such monitoring challenges by continuously collecting data on security controls used on each network firewall and endpoint device. In addition, this intelligence can be used to demonstrate compliance with regulatory mandates and security frameworks such as NIST, PCI, HIPAA, CIS, etc. 

      Despite their widespread adoption and effectiveness, traditional firewalls and VPNs are struggling to keep pace with the evolution of corporate network architectures, user access patterns and hybrid on-premises/cloud hosted resources. A distributed approach that places many of the security controls, policy enforcement and networking elements of traditional firewalls and VPNs in the cloud is emerging as an attractive alternative.  

      If you have a suggestion for an eWEEK Data Points article, email [email protected].

      eWEEK EDITORS
      eWEEK EDITORS
      eWeek editors publish top thought leaders and leading experts in emerging technology across a wide variety of Enterprise B2B sectors. Our focus is providing actionable information for today’s technology decision makers.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.