Meeting Authentication
Require appropriate authentication before allowing access to protected meetings.
Prevent unidentified users from entering protected sessions.
Modern organizations increasingly use WebRTC-based real-time communication for video conferencing, audio communication, screen sharing, and collaborative meetings. WebRTC enables real-time communication between participants through browser-based applications. These applications depend on authentication, meeting access controls, session management, signaling services, and network communication to establish and maintain secure sessions.
Improper meeting-access controls can create a security risk when unauthorized users are able to access protected real-time communication sessions.
In this use case, Jitsi Meet is deployed as the controlled real-time communication application on an Ubuntu Linux virtual machine inside an isolated VirtualBox laboratory. A controlled meeting is created using laboratory test accounts. An authorized participant is allowed to access the meeting, while an unauthorized test account is used to perform a controlled meeting-access assessment.
OWASP ZAP is used to inspect the web application and session-related traffic. Wireshark is used to analyze network communication associated with the controlled WebRTC sessions. Wazuh is used for security monitoring, while OpenSearch is used for centralized investigation.
The security assessment determines whether Jitsi Meet correctly enforces meeting-access controls and prevents unauthorized users from accessing protected real-time communication sessions.
After identifying the access-control weakness, the meeting configuration is remediated and the same controlled access test is repeated to verify that unauthorized access is prevented while legitimate users continue to access the meeting.
Jitsi Meet is the real open-source WebRTC application used in this project. The application is deployed locally on Ubuntu Linux.
A WebRTC-based meeting should be accessible only to authorized participants. If meeting-access controls are incorrectly configured, an unauthorized user may attempt to enter a protected meeting or interact with an active communication session.
The security problem is therefore:
The controlled attack scenario evaluates whether an unauthorized laboratory user can access a protected Jitsi Meet meeting. The assessment is performed only against the locally deployed Jitsi Meet environment.
The primary security concept is secure real-time communication session management.
Jitsi Meet meetings containing sensitive business discussions or information should be protected against unauthorized participants. The security mechanism evaluates authentication, meeting-access requests, authorization decisions, session establishment, and real-time communication activity.
The secure processing flow is:
Require appropriate authentication before allowing access to protected meetings.
Prevent unidentified users from entering protected sessions.
Restrict meeting participation to authorized users.
Prevent unauthorized participants from joining protected meetings.
Configure Jitsi Meet meetings with appropriate access restrictions.
Reduce accidental exposure of real-time communication sessions.
Monitor participant and meeting-session activity.
Identify unexpected session behavior.
Ensure WebRTC communication uses the secure communication mechanisms supported by the Jitsi Meet deployment.
Protect real-time communication sessions.
Monitor relevant Jitsi Meet and Ubuntu activity.
Detect suspicious meeting-access behavior.
Analyze controlled WebRTC network traffic.
Understand normal and abnormal communication behavior.
Use Wazuh and OpenSearch to investigate security events.
Establish the activity timeline and support incident analysis.
Strengthen meeting-access restrictions when weaknesses are identified.
Prevent unauthorized meeting participation.
Repeat the original controlled access test after remediation.
Confirm that the implemented controls are effective.
Jitsi Meet is the real open-source WebRTC application used in the project.
OWASP ZAP is used to inspect the Jitsi Meet web application and relevant application traffic.
Wireshark is used to analyze controlled WebRTC network communication.
Wazuh is used for centralized security monitoring.
OpenSearch is used to investigate security events collected through Wazuh.
Kali Linux is used as the authorized security-testing environment.
Ubuntu hosts the Jitsi Meet environment.
VirtualBox provides the isolated cybersecurity laboratory.