Introducing TypingDNA Human Likeness – A Novel Bot Detection Approach for the AI Age 

Zero Trust Security

Simply put, zero trust is a security approach based on the principle that no user, device, or connection should be implicitly trusted based only on its location, network, or previous authentication. Instead, access to resources should be explicitly verified and continuously evaluated based on identity, device, and other relevant security signals.

Why is zero trust important?

Zero trust has become increasingly important as employees, contractors, applications, and data operate across office, remote, hybrid, cloud, and BYOD environments. Zero trust follows the commonly used "never trust, always verify" principle when granting access, regardless of where a user is signing in from. Strong authentication and ongoing verification can both play important roles in a zero trust architecture.

At login, organizations can use multi-factor authentication (MFA) to establish greater confidence that the person requesting access is the authorized user. TypingDNA Verify 2FA, for example, provides phone-free two-factor authentication using typing biometrics, allowing users to verify their identity by typing 4 short words directly on their work computer.

But authentication at login does not guarantee that the same authorized person remains behind the device throughout the session. A computer can be left unlocked and unattended, intentionally shared, or accessed by another person after login. Continuous endpoint authentication can provide an additional identity signal throughout an active session.

Insider and endpoint security risks do not always involve malicious attackers. Employees may fall victim to phishing, share devices with unauthorized users, or leave authenticated computers unattended. A zero trust approach aims to limit implicit trust and continuously evaluate whether access to sensitive resources should remain permitted.

One way to extend identity verification beyond login is through behavioral biometrics. TypingDNA ActiveLock continuously verifies the person behind a Windows or macOS company computer primarily based on how they type. If an unauthorized user is detected, ActiveLock can lock the computer or alert administrators, helping organizations maintain identity assurance after the initial authentication event.

Zero trust is broader than any single authentication technology. It combines identity, device, access, network, application, and data security controls to protect resources. Technologies such as MFA and continuous authentication can support this approach by verifying identity before access and continuing to evaluate trust during an active session.

Learn more about continuous authentication with ActiveLock and how TypingDNA can help organizations support zero trust authentication goals.