I was working on one of my “back of the envelope” diagrams for a post on microsegmentation and decided to draw the one pictured above as a warm-up exercise. It turned out well enough that I thought it was worth posting on its own. You might find it useful with clients when they look at you with puzzlement when you talk about “north-south” versus “east-west” in network security.
You can also use the text below when explaining the concepts; feel free to “copy, paste, and adjust to taste”:
North-south crosses the boundary of your environment. A browser hitting your web tier, an API call from outside, your service calling a third party. Up and down the diagram, in and out.
East-west stays inside. Web tier to app tier, app tier to database, service to service, pod to pod. Sideways across the diagram, and it typically never touches your perimeter controls at all.
The entire traditional security stack is pointed at north-south. Firewall, WAF, load balancer, the DMZ, the VPN concentrator, most of the alerting.
East-west traditionally get an implicit pass, because it’s inside, and inside was assumed to be fine. If this were true, we wouldn’t have expressions like “It was an inside job!”
An attacker who phishes a laptop or pops a container has already cleared every north-south control. From that point on they’re moving east-west, which is the direction that typically has the least in the way. The initial breach is usually small. The blast radius is what turns it into an incident, and the blast radius is all east-west.
That’s the gap microsegmentation exists to close: putting authorization on the connections between your own workloads, not just on the ones crossing your perimeter.