(476) What is Secure Access Service Edge (SASE) ?

Secure Access Service Edge (SASE)

Definition

SASE is a term coined by Gartner that merges multiple network and security technologies into a unified offering. This approach aims to provide secure network services regardless of the user's location, effectively combining both online and offline security measures to protect sensitive data and maintain network integrity.

Problem

The increasing number of distributed workloads and the shift towards remote work environments have led to significant challenges. Organizations face difficulties with disparate technologies (often involving a mix of legacy and modern systems), managing multiple security policies, and dealing with efficiency and scalability issues that diminish overall organizational effectiveness.

Evolution of Remote Work

Changing Landscape

The landscape of work has transformed dramatically. Notably, 74% of Chief Financial Officers (CFOs) reported plans to maintain a remote workforce even after the pandemic. This reflects a broader change in organizational culture and operations towards embracing flexibility and adaptability in employee work arrangements.

SaaS Usage

In contemporary workplaces, employees typically engage with approximately eight different Software as a Service (SaaS) applications. This is in addition to using internal resources such as softphones, file shares, and collaboration tools, creating a wide array of touchpoints that must be monitored and secured.

Limitations of Traditional VPN

Traditional Virtual Private Networks (VPNs) present several limitations. Users are required to connect to a central location, which results in higher latency, the need for costly circuits, and larger inspection devices that can hinder performance and user experience.

SASE Framework Levels

Core Levels

Essential components of the SASE framework include:

  • SD-WAN (Software-Defined Wide Area Network): Optimizes connectivity and application performance across geographically dispersed locations.

  • Secure Web Gateway (SWG): Protects users from internet-based threats while allowing secure access to web applications.

  • Firewall as a Service (FWaaS): Cloud-based firewall services that provide security for all edges of the network without on-premise limitations.

  • Cloud Access Security Broker (CASB): Acts as a gatekeeper to ensure compliance and govern usage of cloud services effectively.

  • Zero Trust Network Access (ZTNA): Enforces the principle of least privilege, allowing minimal access necessary for users.

Recommended Levels

Additional services recommended for a robust SASE deployment include:

  • Sandboxing: An isolated environment where suspicious files can be executed to detect harmful behavior without affecting the network.

  • Browser Isolation: Protects users by creating a remote browsing session that keeps malicious websites away from the endpoint.

  • Web Application Firewall (WAF): Monitors and filters HTTP traffic to and from web applications, providing protection against common attacks.

  • Network Access Control (NAC): Ensures devices comply with security policies before granting access to the network.

  • Next-Gen Antivirus/Endpoint Detection and Response (EDR): Advanced threats and malware protection, offering real-time monitoring of endpoint activities.

Optional Levels

For organizations still reliant on traditional mechanisms, the following optional services can be integrated:

  • Wireless LAN (WLAN): To provide secure wireless connectivity for mobile and stationary devices.

  • VPN: Retained for legacy users and specific business cases requiring traditional access methods.

Key Concepts in SASE

Zero Trust Network Access (ZTNA)
  • Principle: Focuses on continuously verifying user identities and devices, regardless of their location. Only authenticated users can access specific resources.

  • Software Defined Perimeter (SDP) is emerging as an integral part of this technology, which establishes a secure connection via a Transport Layer Security (TLS) tunnel, ensuring secure access paths.

Endpoint Client and Connections
  • Functionality of the Client: Provides ZTNA and routes users to the nearest inspection point, no matter their geographical position. This ensures that when accessing applications such as Office 365, users are securely inspected in the cloud.

  • Distributed Security Model: Inspection services are regionally distributed to enhance security measures while significantly reducing latency in comparison to conventional VPN setups.

Integration of SD-WAN with SASE

Role of SD-WAN
  • Enhances decision-making regarding the routing of traffic efficiently while upholding stringent security protocols.

  • Supports critical services such as VoIP, Quality of Service (QoS) optimization, and overall latency reduction, leading to improved user experience.

  • Service Chaining: Facilitates the offloading of security inspection to secure web gateways, allowing seamless transitions as users change connections without compromising security.

Security Policy Consistency

Unified Policy Framework
  • Optimal SASE solutions employ a single policy approach, where policy changes can be applied uniformly across on-net and off-net environments ensuring consistent security enforcement irrespective of access method.

  • CASB Importance: Acts like a firewall specifically for cloud applications, centralizing security policies to enforce access control and monitor potentially suspicious behavior in SaaS applications.

Conclusion

Summary of SASE Functionality

The SASE model begins with ZTNA, employing strict user authentication no matter the location of the user. This architecture ensures that all security services are integrated and readily accessible, routing users through necessary inspection points as required. Ultimately, SASE provides a streamlined and singular approach to network security that aligns with the evolving needs of modern enterprises, addressing the challenges presented by the increasingly mobile work environment.