Zero-Trust Network Access (ZTNA) marks a significant shift in network security by adopting a "never trust, always verify" approach. This work provides an in-depth analysis of ZTNA, offering a comprehensive framework for understanding its principles, architectures, and applications. We discuss its role in securing modern, complex network environments, which include cloud platforms, Internet of Things (IoT) devices, and hybrid enterprise networks. Our objective is to create a key resource for researchers and practitioners by reviewing critical methodologies, analyzing current implementations, and highlighting open challenges and research directions.
翻译:零信任网络访问 (ZTNA) 通过采用“永不信任,始终验证”的原则,标志着网络安全领域的重大范式转变。本文对ZTNA进行了深入分析,为理解其基本原理、架构和应用提供了一个综合性框架。我们探讨了其在保护包含云平台、物联网 (IoT) 设备和混合企业网络在内的现代复杂网络环境安全中的作用。通过综述关键方法学、分析当前实施方案并强调开放挑战与研究方向,我们的目标是为研究人员和实践者创建一个重要的参考资源。