Uncategorized

The Return to the NeverTrustTM Security Model

The Return to the NeverTrustTM Security Model

The Return to the NeverTrustTM Security Model

Do you remember the halcyon days of IT systems administration when there was complete control over the application delivery model and security from the user to the mainframe or servers? Everyone had to be on a secure and private network to connect to the applications. Even people who were in branch offices had to use private leased lines or PTSN (what?) dialup connections. These were still private point-to-point connections that maintained security. Most people reading this are probably too young to remember those days.

 

In any event, those days are gone. The Internet changed everything, and the change brought many benefits. People now expect to work from anywhere and be as productive as when they are at their desks in the office. If they still have a permanent desk that is, given the changes in working practices accelerated by the pandemic.

The radical change in how applications are delivered wasn't all beneficial. It became much harder to secure the connections from users to servers when traffic was passing over the public Internet. Many solutions exist to address the security issue in modern application delivery. But it's a full-time task and getting more challenging as the IT landscape expands and the threats increase.

Another issue with the new work from anywhere model that many businesses are adopting is giving access to legacy applications. Many applications were developed and deployed on legacy operating systems that cannot be updated or made available directly to remote users. Yet businesses need the functions the applications deliver at present. Virtualisation, thin-client technology, and container-based systems have made deployment easier, but security is still challenging in many scenarios.

Droplet Computing has taken the concept of containers and their security to the next level. They deliver a never trust approach based on a client and server container model that builds a bubble of security around legacy and modern applications. Droplet's never trust containers restrict inbound and outbound traffic flows, and they present no interface or APIs for cyberattacks to exploit. More info on this is below and on the Droplet Computing website. Renaissance and Droplet Computing partner in the Ireland market to make these container-based solutions available to Managed Service Providers (MSPs). Contact us for more info, and read on for a high-level overview of the Droplet Computing NeverTrustTM approach.

Droplet Computing NeverTrustTM Model

The Droplet Computing NeverTrustTM model isn't a single technology solution. Instead, it is a collection of security APIs, protocols, and configurations that work in harmony to protect both legacy and modern applications.

The security model has a dual container approach. There is a client-side container that hosts and runs the end-user components of an application. There are also server-side containers that run backend application components based on operating systems such as Windows Server 2003 to 2012, and more. The NeverTrustTM model protects both the client-side and server-side containers. Indeed, only the client-side containers can connect to the corresponding server-side containers.

Client-Side Containers

The Droplet Computing solution encapsulates everything needed to run the application on the client in a secure client-side container. Abstraction separates the containers from the underlying client operating system. This means that the device running the containerised client Windows-based application components can be a Windows 10/11 PC, a macOS computer, a Linux PC, or even a Chrome OS device.

Server-Side Containers

The same NeverTrustTM security boundaries wrap around the server-side containers. Each server-side container is only accessible from an associated client-side container by creating a secure tunnel between the client through an encrypted Droplet Secure Gateway (DSG). Of course, multiple client-side containers on different end-user devices can connect to the same server-side container running a business application. But each has its own secure tunnel (more on security below). At present, the DSG links to Active Directory for authentication, but there are plans on the product roadmap to eliminate this dependency via hardcoded authentication and encryption at the DSG tunnel level.

Sever-side containers run as instances in an existing virtual appliance or as a Linux instance in public cloud environments like Amazon AWS or Microsoft Azure. As with our client container, the server container runs on an already hardened hypervisor in a hardened Linux environment – thus, there are several degrees of isolation from the external network and potential cyberattacks.

Deep Security Protection

The Droplet Computing NeverTrustTM client-side and server-side container model takes application and data security to the next level. Even if an endpoint device is compromised and malware deployed on the base operating system, the client-side container software has no exposed APIs or SDK hooks that attackers can use to compromise the container and its data. NCC Group has verified this security abstraction and protection beyond the base operating system protections, as have many Droplet Computing customers via their own independent penetration tests.

The isolation and abstraction of the containers extend to the network traffic that is allowed as well. All inbound traffic that the container has not initiated is rejected and blocked. This builds a bubble of security isolation around the containers. Even if the host client device gets breached and an attacker has complete control, the attack will not compromise the Droplet Computing container or expose its data to the attackers.

Outbound traffic generated by the containers is also strictly limited and controlled. Only specific IP addresses and port numbers needed for client-side and server-side containers to communicate are allowed. As each set of these containers has specific settings, it means that client-side containers running a Windows-based client app can be single-use entities. They can only communicate with their associated server-side container and nothing else. Attackers can't use them as jumping-off points in cyberattacks.

Any cyber attacker looking to compromise a Droplet Computing NeverTrustTM deployment would need to —

  1. Breach the on-premises virtualised infrastructure.
  2. Break into the core hardened Linux environment.
  3. Compromise the Droplet Computing containers.

Most attacks that have got as far as point 1 above will most likely have already deployed ransomware and payment demands. But the Droplet Computing layer will remain untouched by any deployed malware, protecting your organisation from the destruction and ransom costs.

Conclusion

The Droplet Computing NeverTrustTM model can restore the security model from the halcyon days of application delivery where there was complete control over access. Plus, it can do it on top of the modern web-based world we now have. It allows system admins to configure and control environments from the client to the server, even if they use edge computing, cloud computing, BYOD. With a simple deployment model built for enterprise, government, and military scaled deployments, the Droplet Computing model puts organisations back in complete control of security. Contact Renaissance today to find out how to make it available to your MSP clients.