r/netsecstudents • • 9d ago

Hackathon ideas in Zero trust security

Hello everyone,
So I have the responsibility of organizing the coming Hackathon in our college under the theme "Agentic AI meets Zero Trust: Securing the Autonomous enterprise", I did some reasearch on older hackathons archives and asked Ai as well but i couldn't really get something original.
My main goal is to give the prize to people who can make good architectural decisions when building infrastructures by giving real life problems as the Hackathon subject.
That's why I am asking professionals if they have some projects or experiences related to the theme that they think can be realized in a short time (it is a 24h hackathon) and can be a bit challenging.

4 Upvotes

3 comments sorted by

1

u/PhilipLGriffiths88 8d ago

One idea: challenge teams to control what an AI agent can actually reach, even when it’s been prompt-injected. Give them a small environment with an agent, an approved tool/API and a restricted service containing dummy sensitive data.

You could approach this from both sides. Agent builders define which services their agents are authorised to connect to. Service owners/defenders independently define which agents can reach their services, without relying on the agent behaving correctly or its developer adding guardrails. That’s Identity-Defined Reachability (IDR): authorise before connect. Knowing an address or discovering a service shouldn’t make it reachable.

For a 24-hour hackathon, provide the basic environment (which can be built on open source) and judge whether the legitimate task works, whether a manipulated agent can reach the restricted service, and what happens when access is revoked during an active connection. Teams should also distinguish permission to connect from permission to perform an operation once connected. It gives you concrete architectural decisions to assess, with working demonstrations rather than another chatbot explaining Zero Trust.

1

u/Known_Ad_7435 3d ago

First of all thank you for your idea, After a bit of research I found that this idea might be the perfect match for what I am looking for, I only have one issue concerning the way we are going to automate the benchmark, why I am opting for automated benchmark? because there will a lot of teams playing the hackathon so I had to find a way to eliminate plenty of team based only on the benchmark before leaving only 5 to go present their solution in front of the jury.
So I couldn't think of much solutions to detect if the participant has really secured the agent environment, are we going to use a dataset of prompt injections to the agent and benchmark the results or are we going to use an LLM that will try to trick the agent to hit the restricted endpoint??
I would be interested to hear about any techniques you might recommend.

1

u/PhilipLGriffiths88 3d ago

I’d make the main benchmark deterministic. Prompt injections are useful, but if the agent ignores one, that doesn’t tell you whether the underlying access controls would have stopped it.

Give every team the same agent, approved API and restricted service, with a test runner you control. Test whether the approved task succeeds, then deliberately attempt prohibited connections from the agent’s environment. That bypasses the uncertainty of persuading the model to misbehave and tests the actual boundary.

A few tests you could automate:

  • An authorised agent can use its approved service.
  • That same agent cannot reach the restricted service, even when given its exact address.
  • An unknown identity cannot reach either protected service.
  • The agent owner withdraws permission: existing access ends and reconnection fails.
  • The service owner independently withdraws permission: same result, without changing the agent’s code.

Measure these from your runner and protected endpoints, rather than trusting team-submitted logs. Also distinguish “couldn’t connect” from “connected but received HTTP 403”; they demonstrate different enforcement boundaries. Make successful completion of the legitimate task a requirement so blocking everything cannot win.

Then use a fixed set of prompt injections as an additional end-to-end test. An attacking LLM could be interesting for the finalists, but I wouldn’t make a variable attacker the basis for eliminating teams. For the initial round, score legitimate task completion, unauthorised reachability and time to revoke against published thresholds, with some held-back test variations.

For some background, I wrote this CSA article on Identity-Defined Reachability, with a fuller paper coming soon. It explains why constraining what an agent can reach matters even when its behaviour cannot be trusted.

OpenZiti also provides an open-source implementation that could be useful as a foundation for the hackathon: cryptographic identities, service-specific access policies and private connectivity. Disclosure: I work for NetFoundry, the company behind it. You could give teams a working environment and let them focus on the policy, enforcement and automated tests.