SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsNetwork-layer virtual private network (VPN) appliances still anchor enterprise remote access, and repeated mass exploitation of these appliances has made them a recurring initial access vector for ransomware operators. Identity-aware reverse proxies (IAPs), usually marketed under the Zero Trust Network Access (ZTNA) label, are positioned as the replacement.
Whether they actually align better with Zero Trust than a modern VPN, or only claim to, has not been tested objectively. To answer that question, a controlled lab was built, six products were deployed across both architectures, and each was put through a 21-test battery mapped to the five pillars of the CISA Zero Trust Maturity Model, with every outcome scored against predictions registered in advance and the raw evidence retained for audit.
The architectural advantage is strongest on the Networks pillar, where identity-aware proxy access withholds default network reachability and shrinks blast radius. For the Applications and Data pillars, the results depend primarily on the security features bundled with each product and its platform, and the two architectures converge on Identity because both draw their authentication strength from the same identity provider. The study contributes a repeatable methodology and a scored matrix that shows where the architectures genuinely diverge.
For security architects, it offers evidence-based grounds to make identity-aware proxy access the default for internal web applications, while recognizing that architecture alone does not settle every pillar.


















