首页> 外文期刊>Computers & Security >Never trust, always verify: A multivocal literature review on current knowledge and research gaps of zero-trust
【24h】

Never trust, always verify: A multivocal literature review on current knowledge and research gaps of zero-trust

机译:永远不要信任,始终验证:多因素文献综述关于零信任的当前知识和研究差距

获取原文
获取原文并翻译 | 示例
       

摘要

In response to weaknesses of current network security solutions, the zero-trust model follows the idea that no network - whether internal or external - is trustworthy. The concept of zero-trust is enjoying increasing attention in both research and practice due to its promise to fulfil complex new network security requirements. Despite zero-trust's advantages over traditional solutions, it has not yet succeeded in replacing existing approaches. Uncertainty remains regarding the concept's distinct benefits and drawbacks for organisations and individuals, which hinders a holistic understanding of zero-trust and wide-spread adoption. Research can make valuable contributions to the field by systematically providing new insights into zero-trust. To support researchers in this endeavour, we aim to consolidate the current state of the knowledge about zero-trust and to identify gaps in the literature. Thus, we conduct a multivocal literature review, analysing both academic and practice-oriented publications. We develop a research framework for zero-trust to structure the identified literature and to highlight future research avenues. Our results show that the academic literature has focused mainly on the architecture and performance improvements of zero-trust. In contrast, the practice-oriented literature has focused on organisational advantages of zero-trust and on potential migration strategies. However, economic analyses and user-related studies have been neglected by both academia and practice. Future research may rely on our findings to advance the field in meaningful ways.
机译:响应当前网络安全解决方案的弱点,零信任模型遵循无网络的想法 - 无论是内部还是外部 - 是值得信赖的。由于其承诺履行复杂的新网络安全要求,零信任的概念越来越受到研究和实践。尽管对传统解决方案的零信任的优势,但它尚未成功更换现有方法。不确定性仍然是关于组织和个人的概念的截然效益和缺点,阻碍了对零信任和广泛采用的全面了解。通过系统地向零信任提供新的洞察,研究可以对本领域进行有价值的贡献。为了支持这一努力的研究人员,我们的目标是巩固当前关于零信任的知识状态,并识别文献中的差距。因此,我们进行多元文献综述,分析了学术和实践导向的出版物。我们开发了一个零信任的研究框架,构建了所识别的文献,并突出未来的研究途径。我们的研究结果表明,学术文献主要集中在零信任的架构和绩效改进。相比之下,以实践为导向的文献专注于零信任和潜在移民策略的组织优势。然而,学术界和实践都忽视了经济分析和与用户相关的研究。未来的研究可能依靠我们的研究结果以有意义的方式推进领域。

著录项

  • 来源
    《Computers & Security》 |2021年第11期|102436.1-102436.26|共26页
  • 作者单位

    Project Group Business & Information Systems Engineering of the Fraunhofer FIT University of Bayreuth Wittelsbacherring 10 95444 Bayreuth Germany Centre for Future Enterprise QUT Business School Queensland University of Technology QUT Gardens Point Campus 2 George St Brisbane City QLD 4000 Brisbane Australia;

    FIM Research Center University of Augsburg Project Group Business & Information Systems Engineering of the Fraunhofer FIT Uniuersitaetsstrasse 12 86159 Augsburg Germany;

    Centre for Blockchain Technologies at University College London qbound Friedrichshafener Str. 1 82205 Gilching Germany;

    FIM Research Center University of Bayreuth Project Group Business & Information Systems Engineering of the Fraunhofer FIT Wittelsbacherring 10 95444 Bayreuth Germany;

    Chair of Information Systems Management University of Bayreuth Project Group Business & Information Systems Engineering of the Fraunhofer FIT Universitaetsstrasse 30 95447 Bayreuth Germany;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Zero-trust; Network security; Access control; Software-defined perimeter; SDP; Multivocal literature review;

    机译:零信任;网络安全;访问控制;软件定义的周边;SDP;多元文献综述;
  • 入库时间 2022-08-19 02:55:14

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号