Device Identity
Each authorized laboratory device is assigned a unique NetBird peer identity.
Distinguish authorized devices from unauthorized devices.
Modern organizations use Zero Trust Network Access (ZTNA) to provide controlled connectivity between users, devices, and internal resources without automatically trusting a device simply because it is connected to an internal network.
A core Zero Trust principle is that access should depend not only on user identity but also on the security state and trustworthiness of the requesting device.
NetBird is an open-source Zero Trust networking platform that provides identity-based networking and secure connectivity between authorized peers.
However, if device identity and access policies are incorrectly configured, an unauthorized or untrusted device may attempt to obtain network access to protected resources.
In this use case, NetBird is deployed as the controlled Zero Trust networking platform on Ubuntu Linux inside an isolated VirtualBox laboratory.
A controlled internal application is deployed as a protected resource. Authorized and unauthorized laboratory devices are created to represent different device-trust states.
A controlled Device Trust Bypass scenario is performed from Kali Linux. The assessment evaluates whether an unauthorized device can obtain or retain network access to a protected resource without satisfying the required Zero Trust device and access policies.
NetBird access policies are used to define which peers are permitted to communicate. NetBird management and peer information is used to establish device identity and connectivity state.
Wazuh is used for security monitoring, while OpenSearch is used for centralized investigation and event correlation.
After identifying the device-trust weakness, peer access policies are strengthened and unauthorized device connectivity is removed. The same controlled device-access scenario is then repeated to verify that untrusted devices cannot access protected resources while authorized devices continue to function normally.
The complete Zero Trust workflow is: Protected Resource → NetBird Zero Trust Network → Authorized Device → Device Identity → Access Policy → Controlled Untrusted Device → Device Trust Bypass Attempt → Access Decision → Security Detection → Policy Remediation → Device Restriction → Retesting → Zero Trust Validation
NetBird is the real open-source Zero Trust networking platform used in this project.
Traditional network access may rely heavily on network location. If a device is connected to an apparently trusted network, it may receive access to internal resources even when its security state has not been adequately validated.
The security problem is therefore:
The controlled attack scenario evaluates whether an unauthorized laboratory device can obtain network connectivity to a protected resource despite not satisfying the intended device-access policy.
The primary Zero Trust security concept is Device-Centric Zero Trust.
A user should not automatically receive access simply because the device is connected to the organization's Zero Trust network. Instead, access should be evaluated using: User Identity + Device Identity + Device Trust State + Destination + Access Policy - > Authorization Decision. The objective is to prevent an unauthorized device from obtaining network access to protected resources simply because it can reach the Zero Trust networking infrastructure.
The secure processing flow is:
Each authorized laboratory device is assigned a unique NetBird peer identity.
Distinguish authorized devices from unauthorized devices.
NetBird access policies determine which peers can communicate.
Prevent unauthorized device-to-device connectivity.
Devices receive only the network access required for their legitimate function.
Reduce unnecessary connectivity.
Sensitive services are placed behind explicit access policies.
Prevent unrestricted access from connected peers.
Unapproved device communication is denied.
Prevent implicit trust between network peers.
Unauthorized or compromised devices can be removed from the permitted access policy.
Prevent continued access by untrusted devices.
NetBird peer connectivity is monitored.
Identify unexpected devices and communication relationships.
Wazuh monitors relevant Ubuntu and NetBird activity.
Detect changes and suspicious access behavior.
OpenSearch is used to correlate device, network, and security events.
Establish the timeline of the device-trust violation.
The original device-access scenario is repeated after remediation.
Confirm that unauthorized devices remain unable to access protected resources.
NetBird is the primary Zero Trust networking platform.
WireGuard provides the secure network tunnel technology used by NetBird.
Nmap is used to validate protected-resource reachability.
Wazuh is used for centralized security monitoring.
OpenSearch is used for centralized security investigation.
A controlled web application is deployed as the protected resource.
Ubuntu hosts NetBird and the protected application.
Kali Linux provides the controlled untrusted-device testing environment.
VirtualBox provides the isolated Zero Trust laboratory.