Cybersecurity · Flagship

Zero Trust Network Access Framework for Enterprise IT

Designs and implements a Zero Trust access framework that continuously verifies every device and user request instead of trusting the internal network.

PythonOAuth2/OIDCmTLSPostgreSQL

Traditional company networks trust anything inside the firewall, so an attacker who gets one laptop or stolen password can move freely. Remote work and cloud services have made the perimeter meaningless. Zero Trust replaces the assumption of trust with continuous verification of every user, device and request. This project designs and implements a Zero Trust access framework for an enterprise.

An identity-aware proxy sits in front of internal applications and lets a request through only after checking who the user is, using OAuth2 and OpenID Connect with multi-factor authentication, and the state of the device, such as an up-to-date operating system and disk encryption. Traffic between services is protected with mutual TLS so that each side proves its identity. Micro-segmentation policies grant each user and service the least access needed, written as policy rules stored in PostgreSQL and evaluated on every request. A risk engine scores each session from signals such as location changes and unusual behaviour, and can require re-authentication or end the session. The project includes threat modelling and a comparison with a traditional VPN.

You will learn identity protocols, device posture, policy design and continuous risk assessment. The Project Reference Guide is a thesis-grade security architecture document, and the Reference Implementation provides a working proxy, policy engine and demonstration applications.