Beyond “Zero Trust:” Selective High Assurance for Commodity Software Systems

No ratings

Presented at ESORICS 2023 by

We review the basic notions of trust, trust minimization, zero trust, and trust establishment. We show that zero trust impossible in any enterprise network and has meaning only as an unreachable limit of trust establishment. We present the key characteristics of zero-trust architectures (ZTAs) and show that they have low breach-prevention value as they cannot address common attacks, much less advanced ones. Furthermore, evidence shows that their goal of limiting the effects of security breaches (i.e., “lateral” adversary movement) is often unachieved. Nevertheless, mature ZTAs assure backward software compatibility and reduce breach recovery costs, but not as much as AI/ML methods and tools. In view of these observations, we are asking how to demonstrably increase breach-prevention value and further decrease expected breach-recovery costs for rational defenders (e.g., enterprises) that have already employed ZTAs and advanced AI/ML tools. We introduce the notion of selective high assurance for commodity software1 and show that it is economically justified for producers and necessary for rational defenders. We address the challenge of finding a lower bound on the economic value of selective high assurance independent of the defenders’ risk preferences; i.e., a value that depends only on the commodity software itself and the attacks it withstands. We present an approach to determine such a value and illustrate it for SCION, a networking software system with provable security properties.