The evolution of modern organizational environments has progressively reduced the effectiveness of traditional security models based on implicit trust and network boundaries. To address these limitations, Zero Trust Architecture (ZTA) introduces a security paradigm centered on continuous verification, where every access request must be evaluated according to the current security context, regardless of the user's location, device, or network position. This thesis investigates the practical adoption of Zero Trust principles through the development of methodologies and mechanisms supporting security assessment, authorization decisions, and automated enforcement. The work presents three main contributions. First, a Zero Trust Gap Analysis Framework is proposed to evaluate an organization's security posture across the eight fundamental pillars of Zero Trust Architecture. The framework combines qualitative assessments, weighted metrics, and contextual priorities to provide measurable maturity indicators and support security improvement planning. Second, a Risk-Aware Trust Algorithm is introduced to support authorization decisions based on both trust evaluation and contextual risk assessment. The proposed model combines multiple trust dimensions, including user behavior, device posture, network environment, and threat history, while maintaining a clear distinction between the trustworthiness of an entity and the criticality of the requested operation. This approach improves the transparency and explainability of authorization decisions while remaining aligned with Zero Trust principles. Third, a laboratory environment was designed and implemented to validate the proposed concepts through practical scenarios. The environment integrates FreeIPA for identity management, Wazuh for monitoring and event correlation, Kerio Control for policy enforcement, a Cisco switch for Layer 2 network segmentation, and a virtualized server infrastructure used to simulate organizational endpoints and protected resources. Several experimental scenarios were conducted, including identity-based access control validation, brute-force attack detection, protection of sensitive resources, event correlation, and automated response mechanisms. The obtained results demonstrate the feasibility of combining security posture assessment, risk-aware authorization, continuous monitoring, and dynamic enforcement within a unified Zero Trust framework. Although further validation in larger and more complex environments is required, the proposed approach provides a practical foundation for the progressive adoption of Zero Trust Architecture in modern organizations. While developed and validated within a laboratory environment, it may be particularly relevant for critical sectors such as healthcare, where security, privacy, and service continuity represent essential operational requirements.
Innovative solutions for the design and implementation of Zero-Trust networks
SANTINELLI, CRISTINA
2025/2026
Abstract
The evolution of modern organizational environments has progressively reduced the effectiveness of traditional security models based on implicit trust and network boundaries. To address these limitations, Zero Trust Architecture (ZTA) introduces a security paradigm centered on continuous verification, where every access request must be evaluated according to the current security context, regardless of the user's location, device, or network position. This thesis investigates the practical adoption of Zero Trust principles through the development of methodologies and mechanisms supporting security assessment, authorization decisions, and automated enforcement. The work presents three main contributions. First, a Zero Trust Gap Analysis Framework is proposed to evaluate an organization's security posture across the eight fundamental pillars of Zero Trust Architecture. The framework combines qualitative assessments, weighted metrics, and contextual priorities to provide measurable maturity indicators and support security improvement planning. Second, a Risk-Aware Trust Algorithm is introduced to support authorization decisions based on both trust evaluation and contextual risk assessment. The proposed model combines multiple trust dimensions, including user behavior, device posture, network environment, and threat history, while maintaining a clear distinction between the trustworthiness of an entity and the criticality of the requested operation. This approach improves the transparency and explainability of authorization decisions while remaining aligned with Zero Trust principles. Third, a laboratory environment was designed and implemented to validate the proposed concepts through practical scenarios. The environment integrates FreeIPA for identity management, Wazuh for monitoring and event correlation, Kerio Control for policy enforcement, a Cisco switch for Layer 2 network segmentation, and a virtualized server infrastructure used to simulate organizational endpoints and protected resources. Several experimental scenarios were conducted, including identity-based access control validation, brute-force attack detection, protection of sensitive resources, event correlation, and automated response mechanisms. The obtained results demonstrate the feasibility of combining security posture assessment, risk-aware authorization, continuous monitoring, and dynamic enforcement within a unified Zero Trust framework. Although further validation in larger and more complex environments is required, the proposed approach provides a practical foundation for the progressive adoption of Zero Trust Architecture in modern organizations. While developed and validated within a laboratory environment, it may be particularly relevant for critical sectors such as healthcare, where security, privacy, and service continuity represent essential operational requirements.| File | Dimensione | Formato | |
|---|---|---|---|
|
Tesi Cristina Santinelli Magistrale.pdf
embargo fino al 14/01/2028
Dimensione
6.54 MB
Formato
Adobe PDF
|
6.54 MB | Adobe PDF |
I documenti in UNITESI sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/20.500.12075/28035