Skip to main content

> ARCHITECTURE CANON // V1.0

Cybersecurity & Zero-Trust Canon

The Zero-Trust Architecture Bible: NIST SP 800-207, CISA ZTMM 2.0, eBPF & Cryptographic Workload Identity

CISA ZTMM 2.0 5 Core Pillars & Cross-Cutting Capabilities

Zero Trust is not a product; it is an architectural discipline removing implicit trust across identity, devices, networks, workloads, and data.

PILLAR // IDENTITYCISA ZTMM 2.0

Identity & Workload Authentication

Continuous cryptographic verification of human users and machine workloads with phishing-resistant FIDO2/WebAuthn, short-lived OIDC federation, and mutual TLS SPIFFE/SPIRE attestation.

Optimal Target:

Passwordless, ephemeral mTLS certificates (TTL < 1 hour), zero static long-lived credentials, hardware-bound security keys.

PILLAR // DEVICESCISA ZTMM 2.0

Devices & Endpoint Attestation

Hardware-rooted device health validation (TPM 2.0, Secure Boot, Secure Enclave), automated compliance telemetry, and dynamic quarantine of non-compliant hardware.

Optimal Target:

Continuous real-time posture validation, zero unmanaged bring-your-own-device (BYOD) access to sensitive data planes, automated micro-isolation.

PILLAR // NETWORKSCISA ZTMM 2.0

Network Microsegmentation & eBPF

Elimination of flat network perimeters through kernel-level eBPF traffic policing, software-defined perimeters (SDP), encrypted peer-to-peer WireGuard overlays, and zero implicit trust.

Optimal Target:

Default-deny egress and ingress, eBPF-enforced Layer 7 identity routing, zero open internal subnets, micro-segmented workload perimeters.

PILLAR // APPLICATIONS_WORKLOADSCISA ZTMM 2.0

Applications, Workloads & Supply Chain

Immutable container deployment, SLSA Level 3 cryptographic provenance, runtime system-call auditing via Tetragon, and fine-grained API authorization gateways.

Optimal Target:

Cosign/Sigstore verified image signatures, in-toto attestations, zero root privileges, read-only root filesystems, eBPF kernel enforcement.

PILLAR // DATACISA ZTMM 2.0

Data Protection & Cryptographic Sovereignty

Envelope encryption with Bring Your Own Key (BYOK), field-level cryptographic tokens, automated classification, and Post-Quantum Cryptography (PQC) readiness.

Optimal Target:

Hardware Security Module (HSM) rooted envelope keys, confidential computing with AMD SEV-SNP/Intel SGX, quantum-resistant Kyber hybrid TLS.

CROSS-CUTTING

Cross-Cutting Capabilities

  • Visibility & Analytics: Unified distributed tracing, kernel-level eBPF telemetry, and continuous behavioral anomaly detection across all five pillars.
  • Automation & Orchestration: Automated policy enforcement, dynamic secret rotation, automated quarantine of compromised nodes, and ephemeral runtime lifecycle.
  • Governance & Policy-as-Code: Continuous compliance auditing, Open Policy Agent (OPA) gatekeepers, and statutory adherence to NIST SP 800-207 and SOC 2 Type II.

24 Critical Threat Typologies & Attack Vectors

CVE/CWE mappings, MITRE ATT&CK techniques, eBPF Tetragon/Falco detection queries, and CLI playbooks.

Assess Your Vulnerability Posture
ZT-THR-01T1078.004

Long-Lived Static Cloud IAM Access Key Leakage

Hardcoded or committed long-lived AWS_ACCESS_KEY_ID or GCP Service Account JSON keys leaked into source code repositories, CI logs, or developer machines.

Detection Rule:eBPF / Falco / Tetragon
eventSource: "signin.amazonaws.com" AND eventName: "ConsoleLogin" AND responseElements.ConsoleLogin: "Success" AND NOT userIdentity.sessionContext.sessionIssuer.type: "Role"
ZT-THR-02T1606.002

Golden SAML & Forged Token Impersonation

Adversary compromises Active Directory Federation Services (AD FS) private signing keys, generating arbitrary SAML tokens that bypass multi-factor authentication (MFA).

Detection Rule:eBPF / Falco / Tetragon
EventID: 4624 AND LogonType: 3 AND AuthenticationPackageName: "Negotiate" AND TargetUserName: "Administrator" AND FailureReason: "None"
ZT-THR-03T1078.003

Kubernetes Service Account Token Theft

Compromised container reads the default mounted projected volume `/var/run/secrets/kubernetes.io/serviceaccount/token`, enabling lateral API server queries.

Detection Rule:eBPF / Falco / Tetragon
k8s.audit.requestURI: "/api/v1/namespaces/kube-system/secrets" AND k8s.audit.responseStatus.code: 200 AND NOT user.username: "system:node:*"
ZT-THR-04T1539

Reverse-Proxy Phishing & Session Hijacking

Adversary deploys evilginx2 reverse proxy to intercept credentials and session cookies during login, bypassing standard SMS, TOTP, and Push-based MFA.

Detection Rule:eBPF / Falco / Tetragon
http.request.headers.referer NOT MATCHES "https://*.tinycto.tv" AND http.response.cookies.name CONTAINS "session_id"
ZT-THR-05T1021.002

Overprivileged Microservice Lateral Movement

Compromised frontend service communicates freely with internal payment or user databases due to an unsegmented, flat VPC network design.

Detection Rule:eBPF / Falco / Tetragon
cilium_drop_count{reason="PolicyDenied"} > 0 OR (src_workload="frontend" AND dst_workload="payment-db" AND dst_port=5432)
ZT-THR-06T1567.002

Flat VPC Egress Data Exfiltration via Public S3

Compromised compute node uploads sensitive proprietary database dumps to an attacker-controlled external AWS S3 bucket over unrestricted egress 0.0.0.0/0.

Detection Rule:eBPF / Falco / Tetragon
flow_log.dst_port: 443 AND flow_log.dst_bytes > 100000000 AND flow_log.vpc_id: "vpc-prod" AND NOT flow_log.dst_vpc_endpoint: "vpce-s3"
AI Summary & Agent Operating Digest
AEO / GEO / Perplexity Indexable

Canonical Zero-Trust Defense per NIST SP 800-207 & CISA ZTMM 2.0: Eliminate static credentials, enforce eBPF microsegmentation, and preempt threats with in-kernel runtime telemetry.

Standards & FrameworksNIST SP 800-207, CISA ZTMM 2.0, MITRE ATT&CK, SLSA v1.0, FIDO2 / WebAuthn
Canon Metrics18 Architectures, 24 Threats, 10 Manuals, 22 Tools
Core Tenet (NIST)Never Trust, Always Verify; Assume Breach; Least Privilege
Agent DirectivesReject static keys; enforce OIDC/SPIFFE mTLS and default-deny eBPF

Frequently Asked Questions

What is the core philosophical difference between traditional perimeter defense and Zero-Trust Architecture (ZTA)?

Traditional perimeter security relies on the "castle-and-moat" paradigm: once a user or machine crosses the network boundary (e.g. via VPN), they are implicitly trusted with wide lateral network access. Zero-Trust Architecture (NIST SP 800-207) asserts "Never Trust, Always Verify, Assume Breach". Every request—whether originating from outside the organization or inside a private Kubernetes cluster—must be dynamically authenticated, authorized, and cryptographically verified based on contextual signals.

How does NIST SP 800-207 define Policy Decision Points (PDP) and Policy Enforcement Points (PEP)?

Under NIST SP 800-207, the Policy Decision Point (PDP) is the logical brain comprising the Policy Engine (which evaluates continuous enterprise access rules) and the Policy Administrator (which issues or revokes access credentials). The Policy Enforcement Point (PEP) is the gatekeeper (e.g. an Envoy proxy, API gateway, or eBPF kernel hook) that intercepts traffic and strictly permits or terminates connections as instructed by the PDP.

Why are static long-lived credentials (API keys, passwords) considered a critical Zero-Trust anti-pattern?

Static credentials lack contextual temporal binding. Once leaked (via GitHub commit, compromised developer workstation, or CI log), an attacker can exploit them indefinitely from any location without triggering traditional perimeter alarms. Modern Zero-Trust mandates ephemeral credentials (TTL < 1 hour) issued via short-lived OpenID Connect (OIDC) federation, SPIFFE/SPIRE mutual TLS certificates, or hardware-bound FIDO2/WebAuthn passkeys.

How does kernel-level eBPF (Cilium/Tetragon) improve upon legacy iptables for microsegmentation?

Legacy iptables scales linearly O(N), causing severe CPU overhead and latency degradation when clusters scale to thousands of pods and network rules. Furthermore, iptables operates blindly on IP addresses and ports without application context. Cilium eBPF replaces iptables with in-kernel BPF hash maps operating in constant O(1) time, enabling cryptographic identity-based filtering, L7 protocol inspection (HTTP/gRPC/Kafka), and automated in-kernel process termination (SIGKILL) without user-space context switches.

What is SPIFFE/SPIRE and how does it establish workload attestation without secrets?

SPIFFE (Secure Production Identity Framework for Everyone) is a CNCF open standard defining uniform, cryptographic identity strings (SPIFFE IDs) for workloads. SPIRE is its reference implementation. A local SPIRE Agent inspects the Linux kernel (/proc) and container runtime to attest workload attributes (container image SHA, namespace, service account) without the workload ever possessing a private key. It dynamically injects an ephemeral X.509 SVID into the workload's memory via the SPIFFE Workload API.

What is SLSA Level 3 and why is keyless signing via Sigstore Cosign critical for software supply chains?

SLSA (Supply-chain Levels for Software Artifacts) Level 3 certifies that source code was built in an isolated, hermetic, and verifiable build platform where intermediate inputs cannot be tampered with. Sigstore Cosign keyless signing uses short-lived OpenID Connect tokens from the CI runner (GitHub Actions / GitLab CI) and Fulcio Certificate Authority to sign artifacts, recording the cryptographic proof permanently in the public Rekor transparency log without developers needing to manage or store private keys.

How does envelope encryption with Customer Managed Keys (CMK) and BYOK prevent insider cloud threats?

In envelope encryption, plaintext data is encrypted locally using a unique, ephemeral Data Encryption Key (DEK). The DEK is then encrypted under a Master Key (KEK) managed in a dedicated Hardware Security Module (HSM). Under Bring Your Own Key (BYOK), the customer controls the HSM master key policy. Even if a rogue cloud provider administrator or compromised tenant process gains raw disk snapshots or database dumps, the data remains cryptographically unintelligible without access to the customer-controlled HSM.

How does Post-Quantum Cryptography (PQC) protect against "Harvest Now, Decrypt Later" adversaries?

Hostile nation-states and sophisticated adversaries are actively recording and storing high-value encrypted enterprise internet traffic today, anticipating the arrival of Cryptanalytically Relevant Quantum Computers (CRQCs) that will break RSA-2048 and ECC via Shor's algorithm. Post-Quantum Cryptography (NIST FIPS 203 ML-KEM / Kyber-768) relies on lattice-based mathematics that quantum computers cannot solve in polynomial time. Deploying hybrid TLS 1.3 (X25519 + ML-KEM) immediately eliminates this vulnerability.

What unique Zero-Trust challenges arise from autonomous AI agents and tool-calling LLMs?

Autonomous agents blur the boundary between untrusted user input and executable code. Indirect prompt injection attacks embed concealed directives in data (web pages, PDFs, emails) that hijack the LLM to execute destructive tool calls (e.g. database deletion, funds transfer). A Zero-Trust posture treats the LLM itself as an untrusted computation engine: tool calls must pass through a strict authorization proxy with parameter schema validation, execution must run in air-gapped MicroVM/WASM sandboxes, and state-mutating actions mandate cryptographic Human-in-the-Loop approval.

How does CISA Zero Trust Maturity Model 2.0 measure organizational progress across its five pillars?

CISA ZTMM 2.0 categorizes progress across 4 maturity stages: Traditional (manual configurations, static perimeter firewalls, password auth), Initial (basic SSO, siloed MFA, lifecycle scripts), Advanced (cross-pillar policy coordination, centralized identity, automated device health, microsegmentation), and Optimal (fully automated dynamic policy decision points, ephemeral cryptographic workloads, machine-speed orchestration, continuous behavioral visibility).

Why is Software-Defined Perimeter (SDP) Single Packet Authorization (SPA) superior to traditional VPN ports?

Traditional corporate VPN gateways (OpenVPN, IPsec) leave public internet ports open (e.g. 443, 1194, 500) that are readily discoverable by mass internet scanners (Shodan, Censys), exposing zero-day buffer overflows or authentication bypasses. Single Packet Authorization (SPA) keeps firewall ports completely dark (drop 100%). A client must transmit an encrypted, HMAC-authenticated single packet that dynamically opens a temporary firewall pinhole for only that specific source IP for a matter of seconds to complete the handshake.

How does Continuous Breach & Attack Simulation (BAS) prove Zero-Trust efficacy in live production?

Annual penetration tests represent a point-in-time assessment that rapidly drifts as engineering teams continuously push code, update Kubernetes manifests, and modify cloud security groups. Continuous Breach & Attack Simulation (e.g. Stratus Red Team, Atomic Red Team) programmatically detonates synthetic, non-destructive MITRE ATT&CK techniques in production, asserting mathematically that alerts trigger in the SIEM, eBPF Tetragon policies kill processes, and network microsegmentation drops lateral packets.