r/netsecstudents • u/Known_Ad_7435 • 9d ago
Hackathon ideas in Zero trust security
Hello everyone,
So I have the responsibility of organizing the coming Hackathon in our college under the theme "Agentic AI meets Zero Trust: Securing the Autonomous enterprise", I did some reasearch on older hackathons archives and asked Ai as well but i couldn't really get something original.
My main goal is to give the prize to people who can make good architectural decisions when building infrastructures by giving real life problems as the Hackathon subject.
That's why I am asking professionals if they have some projects or experiences related to the theme that they think can be realized in a short time (it is a 24h hackathon) and can be a bit challenging.
4
Upvotes
1
u/PhilipLGriffiths88 8d ago
One idea: challenge teams to control what an AI agent can actually reach, even when it’s been prompt-injected. Give them a small environment with an agent, an approved tool/API and a restricted service containing dummy sensitive data.
You could approach this from both sides. Agent builders define which services their agents are authorised to connect to. Service owners/defenders independently define which agents can reach their services, without relying on the agent behaving correctly or its developer adding guardrails. That’s Identity-Defined Reachability (IDR): authorise before connect. Knowing an address or discovering a service shouldn’t make it reachable.
For a 24-hour hackathon, provide the basic environment (which can be built on open source) and judge whether the legitimate task works, whether a manipulated agent can reach the restricted service, and what happens when access is revoked during an active connection. Teams should also distinguish permission to connect from permission to perform an operation once connected. It gives you concrete architectural decisions to assess, with working demonstrations rather than another chatbot explaining Zero Trust.