{"id":{"repo_id":"vt","oai_identifier":"oai:vtechworks.lib.vt.edu:10919/140021"},"canonical_url":"https://search.dev.ndltd.org/etd/vt/oai:vtechworks.lib.vt.edu:10919/140021","repository":{"repo_id":"vt","name":"Virginia Tech","base_url":"https://vtechworks.lib.vt.edu/oai/request"},"display":{"title":"Towards Zero Trust Network Security via Programmable Data Planes","abstract":"Traditional enterprise security relies on network perimeters to define and enforce network security policies while granting ambient trust to entities within these perimeters. Zero Trust architecture eliminates this ambient trust and requires consistent verification of every access request with the least privileges granted. However, existing network-level and host-level defenses operate in isolation, limiting their ability to correlate inter-host and intra-host activities and thereby detect or contain sophisticated, cross-host attacks. In this dissertation, we present a unified approach for enforcing end-to-end security decisions across hosts and the network by leveraging programmable data planes to realize in-network Zero Trust security. Our approach transforms the existing network infrastructure into an active protection backbone capable of preventing sophisticated attacks in real time without requiring significant changes to existing infrastructures. To achieve our goal, we first design P4Control, an in-network information flow control mechanism that prevents cross-host attacks at line rate. P4Control leverages programmable switches and eBPF to correlate intra-host and inter-host activities to detect attackers that aim to laterally move in the network to evade existing defenses. Second, we leverage such hardware-software co-design to enable in-network fine-grained continuous authentication to grant network access to authorized processes. For this, we design NetCap, a novel continuous authentication scheme to validate every network access request and prevent attackers from stealing access tokens to gain unauthorized access to protected resources. Third, we present an identity-aware, fine-grained microsegmentation defense, called NetZone, that enforces least-privilege access on a per-user, process-level basis. The defense creates a custom access scope for each user, restricting their visibility to only resources authorized by their identity policies. These access scopes are bound to user processes and persist across hosts with user movement, ensuring consistent enforcement regardless of network location. Our dissertation paves the way for enforcing end-to-end security across hosts and networks, realizing the core principles of Zero Trust through programmable data planes to prevent various sophisticated attacks at line-rate network performance.","abstract_html":"Traditional enterprise security relies on network perimeters to define and enforce network security policies while granting ambient trust to entities within these perimeters. Zero Trust architecture eliminates this ambient trust and requires consistent verification of every access request with the least privileges granted. However, existing network-level and host-level defenses operate in isolation, limiting their ability to correlate inter-host and intra-host activities and thereby detect or contain sophisticated, cross-host attacks. In this dissertation, we present a unified approach for enforcing end-to-end security decisions across hosts and the network by leveraging programmable data planes to realize in-network Zero Trust security. Our approach transforms the existing network infrastructure into an active protection backbone capable of preventing sophisticated attacks in real time without requiring significant changes to existing infrastructures. To achieve our goal, we first design P4Control, an in-network information flow control mechanism that prevents cross-host attacks at line rate. P4Control leverages programmable switches and eBPF to correlate intra-host and inter-host activities to detect attackers that aim to laterally move in the network to evade existing defenses. Second, we leverage such hardware-software co-design to enable in-network fine-grained continuous authentication to grant network access to authorized processes. For this, we design NetCap, a novel continuous authentication scheme to validate every network access request and prevent attackers from stealing access tokens to gain unauthorized access to protected resources. Third, we present an identity-aware, fine-grained microsegmentation defense, called NetZone, that enforces least-privilege access on a per-user, process-level basis. The defense creates a custom access scope for each user, restricting their visibility to only resources authorized by their identity policies. These access scopes are bound to user processes and persist across hosts with user movement, ensuring consistent enforcement regardless of network location. Our dissertation paves the way for enforcing end-to-end security across hosts and networks, realizing the core principles of Zero Trust through programmable data planes to prevent various sophisticated attacks at line-rate network performance.","abstract_has_math":false,"creators":["Bajaber, Osama"],"institution":"Virginia Tech","degree_name":"Doctor of Philosophy","degree_level":"doctoral","degree_discipline":"Computer Science & Applications","degree_department":"Computer Science and Applications","school":null,"contributors":[],"advisors":[],"committee_chairs":["Ji, Bo","Gao, Peng"],"committee_members":["Chung, Taejoong Tijay","Sun, Yixin","Yao, Danfeng"],"year":2025,"date_issued":"2025-12-17","date_published":"2025-12-17","updated_at":"2026-07-22T22:19:07Z","subjects":["Network Security","System Security","Software-Defined Networks"],"languages":["en"],"rights":["In Copyright"],"rights_urls":["http://rightsstatements.org/vocab/InC/1.0/"],"identifier_entries":[{"key":"dc:identifier.other","label":"Dc Identifier Other","values":["vt_gsexam:45027"],"render_values":[{"text":"vt_gsexam:45027","href":null,"code":true}]}]},"links":{"outbound_url":"https://hdl.handle.net/10919/140021","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.committeechair","label":"Committee Chair","values":["Ji, Bo","Gao, Peng"]},{"key":"dc:contributor.committeemember","label":"Committee Member","values":["Chung, Taejoong Tijay","Sun, Yixin","Yao, Danfeng"]},{"key":"dc:contributor.department","label":"Department","values":["Computer Science and Applications"]},{"key":"dc:creator","label":"Author","values":["Bajaber, Osama"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2025-12-18T09:00:53Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2025-12-18T09:00:53Z"]},{"key":"dc:date.issued","label":"Date","values":["2025-12-17"]},{"key":"dc:publisher","label":"Institution","values":["Virginia Tech"]},{"key":"dc:type","label":"Dc Type","values":["Dissertation"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science & Applications"]},{"key":"thesis:degree_level","label":"Degree Level","values":["doctoral"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Doctor of Philosophy"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["Virginia Polytechnic Institute and State University"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Network Security","System Security","Software-Defined Networks"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["In Copyright"]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://rightsstatements.org/vocab/InC/1.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.other","label":"Dc Identifier Other","values":["vt_gsexam:45027"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10919/140021"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Traditional enterprise security relies on network perimeters to define and enforce network security policies while granting ambient trust to entities within these perimeters. Zero Trust architecture eliminates this ambient trust and requires consistent verification of every access request with the least privileges granted. However, existing network-level and host-level defenses operate in isolation, limiting their ability to correlate inter-host and intra-host activities and thereby detect or contain sophisticated, cross-host attacks. In this dissertation, we present a unified approach for enforcing end-to-end security decisions across hosts and the network by leveraging programmable data planes to realize in-network Zero Trust security. Our approach transforms the existing network infrastructure into an active protection backbone capable of preventing sophisticated attacks in real time without requiring significant changes to existing infrastructures. To achieve our goal, we first design P4Control, an in-network information flow control mechanism that prevents cross-host attacks at line rate. P4Control leverages programmable switches and eBPF to correlate intra-host and inter-host activities to detect attackers that aim to laterally move in the network to evade existing defenses. Second, we leverage such hardware-software co-design to enable in-network fine-grained continuous authentication to grant network access to authorized processes. For this, we design NetCap, a novel continuous authentication scheme to validate every network access request and prevent attackers from stealing access tokens to gain unauthorized access to protected resources. Third, we present an identity-aware, fine-grained microsegmentation defense, called NetZone, that enforces least-privilege access on a per-user, process-level basis. The defense creates a custom access scope for each user, restricting their visibility to only resources authorized by their identity policies. These access scopes are bound to user processes and persist across hosts with user movement, ensuring consistent enforcement regardless of network location. Our dissertation paves the way for enforcing end-to-end security across hosts and networks, realizing the core principles of Zero Trust through programmable data planes to prevent various sophisticated attacks at line-rate network performance."]},{"key":"dc:description.abstractgeneral","label":"General Abstract","values":["Data breaches affecting large organizations and government entities are increasingly common, often making the headlines worldwide. These incidents occur because traditional cybersecurity solutions rely on outdated perimeter defenses and grant implicit trust to devices within the network, allowing attackers to move undetected once inside. This dissertation addresses this pressing challenge by introducing innovative defenses to stop such advanced threats in real-time, while requiring minimal modifications to an organization's network infrastructure. First, we design a defense system that tracks how attackers move within a breached organization and blocks them before they can access protected data. Second, we design a continuous authentication system that ensures every access request within the organization is verified, allowing only legitimate users to access resources. Finally, we design a framework that hides all organizational resources and reveals only the resources each user is authorized to access. This customized access view prevents attackers from discovering or accessing sensitive assets, even if they have already breached the network. Our dissertation paves the way to strengthen current organizations with defenses that can mitigate sophisticated attacks in real time without the need to undergo major changes in the network infrastructure."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["Doctor of Philosophy"]},{"key":"dc:format.medium","label":"Dc Format Medium","values":["ETD"]},{"key":"dc:title","label":"Title","values":["Towards Zero Trust Network Security via Programmable Data Planes"]}]}],"canonical_facts":{"dc:contributor.committeechair":["Ji, Bo","Gao, Peng"],"dc:contributor.committeemember":["Chung, Taejoong Tijay","Sun, Yixin","Yao, Danfeng"],"dc:contributor.department":["Computer Science and Applications"],"dc:creator":["Bajaber, Osama"],"dc:date.accessioned":["2025-12-18T09:00:53Z"],"dc:date.available":["2025-12-18T09:00:53Z"],"dc:date.issued":["2025-12-17"],"dc:description.abstract":["Traditional enterprise security relies on network perimeters to define and enforce network security policies while granting ambient trust to entities within these perimeters. Zero Trust architecture eliminates this ambient trust and requires consistent verification of every access request with the least privileges granted. However, existing network-level and host-level defenses operate in isolation, limiting their ability to correlate inter-host and intra-host activities and thereby detect or contain sophisticated, cross-host attacks. In this dissertation, we present a unified approach for enforcing end-to-end security decisions across hosts and the network by leveraging programmable data planes to realize in-network Zero Trust security. Our approach transforms the existing network infrastructure into an active protection backbone capable of preventing sophisticated attacks in real time without requiring significant changes to existing infrastructures. To achieve our goal, we first design P4Control, an in-network information flow control mechanism that prevents cross-host attacks at line rate. P4Control leverages programmable switches and eBPF to correlate intra-host and inter-host activities to detect attackers that aim to laterally move in the network to evade existing defenses. Second, we leverage such hardware-software co-design to enable in-network fine-grained continuous authentication to grant network access to authorized processes. For this, we design NetCap, a novel continuous authentication scheme to validate every network access request and prevent attackers from stealing access tokens to gain unauthorized access to protected resources. Third, we present an identity-aware, fine-grained microsegmentation defense, called NetZone, that enforces least-privilege access on a per-user, process-level basis. The defense creates a custom access scope for each user, restricting their visibility to only resources authorized by their identity policies. These access scopes are bound to user processes and persist across hosts with user movement, ensuring consistent enforcement regardless of network location. Our dissertation paves the way for enforcing end-to-end security across hosts and networks, realizing the core principles of Zero Trust through programmable data planes to prevent various sophisticated attacks at line-rate network performance."],"dc:description.abstractgeneral":["Data breaches affecting large organizations and government entities are increasingly common, often making the headlines worldwide. These incidents occur because traditional cybersecurity solutions rely on outdated perimeter defenses and grant implicit trust to devices within the network, allowing attackers to move undetected once inside. This dissertation addresses this pressing challenge by introducing innovative defenses to stop such advanced threats in real-time, while requiring minimal modifications to an organization's network infrastructure. First, we design a defense system that tracks how attackers move within a breached organization and blocks them before they can access protected data. Second, we design a continuous authentication system that ensures every access request within the organization is verified, allowing only legitimate users to access resources. Finally, we design a framework that hides all organizational resources and reveals only the resources each user is authorized to access. This customized access view prevents attackers from discovering or accessing sensitive assets, even if they have already breached the network. Our dissertation paves the way to strengthen current organizations with defenses that can mitigate sophisticated attacks in real time without the need to undergo major changes in the network infrastructure."],"dc:description.degree":["Doctor of Philosophy"],"dc:format.medium":["ETD"],"dc:identifier.other":["vt_gsexam:45027"],"dc:identifier.uri":["https://hdl.handle.net/10919/140021"],"dc:language.iso":["en"],"dc:publisher":["Virginia Tech"],"dc:rights":["In Copyright"],"dc:rights.uri":["http://rightsstatements.org/vocab/InC/1.0/"],"dc:subject":["Network Security","System Security","Software-Defined Networks"],"dc:title":["Towards Zero Trust Network Security via Programmable Data Planes"],"dc:type":["Dissertation"],"thesis:degree_discipline":["Computer Science & Applications"],"thesis:degree_level":["doctoral"],"thesis:degree_name":["Doctor of Philosophy"],"thesis:institution_name":["Virginia Polytechnic Institute and State University"]},"updated_at":"2026-07-22T22:19:07Z"}