Mohan, Ajay (2025) Integrating Zero Trust Security with Network Penetration Testing in Multi-Cloud Environments. Masters thesis, Dublin, National College of Ireland.
Preview |
PDF (Master of Science)
Download (671kB) | Preview |
Preview |
PDF (Configuration Manual)
Download (1MB) | Preview |
Abstract
The rise of multi-cloud infrastructures has created many new security challenges including inconsistency in how security policies are enforced across the multiple clouds, as well as a reduction in the amount of visibility there are into these types of setups, which are not supported by traditional perimeter-based security approaches. The Zero Trust Security Model has been developed as an alternative approach; this security model operates under "never trust, always verify". However, because the application of Zero Trust principles is theoretical, it needs to be proven through continuous validation in order to be fully functional in practice. This research project seeks to address the need for practical validation of the Zero Trust model by providing an automated framework to implement and test Zero Trust in a multi-cloud environment that includes Amazon Web Services (AWS) and Microsoft Azure. This framework provides automation across the entire security lifecycle, from the provisioning of the environment to discovering assets, applying baseline policies, running automated penetration testing and providing automated enforcement of baseline policies and analyzing the results. The main experiment performed in the research was to create a controlled multicloud environment, apply the established baseline Zero Trust Policies, and perform automated penetration tests to discover any gaps in security. The findings indicate that this framework can achieve asset discovery, application of security controls, and evaluation of actual security posture at network endpoint devices. A key finding of this work is the ability of the framework to expose a misapplication of policy. The penetration testing revealed that the real-world security posture of a virtual appliance was different than its intended state of being vulnerable. Even though the logic around remediation was designed conservatively, the framework returned a final score of 98 out of 100, demonstrating the efficacy of the framework's integrated approach. Therefore, this research provides a practical and automated means for continuously testing and enforcing the principles of Zero Trust within heterogenous and complex cloud environments.
| Item Type: | Thesis (Masters) |
|---|---|
| Supervisors: | Name Email Hafeez, Khadija UNSPECIFIED |
| Subjects: | T Technology > T Technology (General) > Information Technology > Cloud computing Q Science > QA Mathematics > Computer software > Computer Security T Technology > T Technology (General) > Information Technology > Computer software > Computer Security |
| Divisions: | School of Computing > Master of Science in Cyber Security |
| Depositing User: | Ciara O'Brien |
| Date Deposited: | 03 Sep 2026 11:47 |
| Last Modified: | 03 Sep 2026 11:47 |
| URI: | https://norma.ncirl.ie/id/eprint/9808 |
Actions (login required)
![]() |
View Item |
Tools
Tools