Service Identity
Each controlled service receives a distinct identity within the service-mesh environment.
Identify services independently of network location.
Modern organizations use distributed applications in which multiple services communicate across internal networks. Traditional network architectures may allow broad internal connectivity, creating opportunities for an attacker who compromises one service to move toward other internal services.
Lateral Movement occurs when an attacker uses access from one compromised system to reach additional systems or services within an environment.
Zero Trust Security addresses this risk by removing implicit trust between internal systems. Instead of assuming that internal traffic is trusted, every service-to-service connection should be evaluated according to identity, authorization policy, and communication requirements.
In this use case, HashiCorp Consul is deployed as the controlled service-discovery and service-mesh platform on Ubuntu Linux inside an isolated VirtualBox laboratory.
Multiple controlled application services are deployed to represent a distributed application architecture.
A controlled lateral movement attack is simulated from one compromised laboratory service toward another protected service.
Consul Connect is used to provide service-to-service security and identity-based communication controls. Open Policy Agent (OPA) is used to define explicit authorization policies. Wazuh monitors security activity, while OpenSearch provides centralized investigation and event correlation.
The assessment determines whether a service that has been compromised can communicate with another protected service without satisfying the required Zero Trust access policy.
After identifying the lateral-movement weakness, service-to-service authorization and network segmentation controls are strengthened. The same controlled lateral-movement scenario is then repeated to verify that unauthorized service communication is prevented while legitimate service-to-service communication continues to function.
The complete Zero Trust workflow is: Distributed Services → Service Identity → Access Policy → Controlled Service Compromise → Lateral Movement Attempt → Continuous Authorization → Communication Decision → Security Detection → Micro-Segmentation → Policy Remediation → Retesting → Zero Trust Validation
HashiCorp Consul is the real open-source service-discovery and service-mesh platform used in this project.
In a traditional internally trusted network, once an attacker compromises one application service, the attacker may attempt to communicate directly with other internal services. The security decision should therefore be based on who the requesting service is and whether that service is explicitly authorized to communicate with the destination service, rather than simply trusting the internal network.
The security problem is therefore:
The controlled attack scenario evaluates whether a compromised laboratory service can communicate with another protected service that it should not be authorized to access.
The primary Zero Trust security concept is Micro-Segmentation with Continuous Authorization.
Internal network location should not automatically grant access. Instead, every service-to-service request should satisfy an explicit policy: Source Service + Service Identity + Destination Service + Request Context -> Authorization Policy -> Allow / Deny. The objective is to ensure that compromising one service does not automatically provide access to other internal services.
The secure processing flow is:
Each controlled service receives a distinct identity within the service-mesh environment.
Identify services independently of network location.
Service-to-service communication is authenticated through the service-mesh security mechanism.
Ensure that services can verify the identity of communicating peers.
Services are separated according to their communication requirements.
Prevent unnecessary service-to-service connectivity.
Communication is allowed only when the source service is explicitly authorized to access the destination.
Enforce least-privilege service communication.
OPA evaluates defined access policies.
Apply consistent authorization decisions based on service identity and context.
Unapproved service-to-service communication is denied.
Prevent implicit internal trust.
Service requests are evaluated against the current access policy.
Prevent previously permitted access from becoming permanent implicit trust.
Internal service communication is monitored for unexpected access patterns.
Identify possible lateral movement.
Wazuh collects relevant host and service activity.
Provide centralized security visibility.
OpenSearch is used to correlate service, authorization, and security events.
Establish the lateral-movement activity timeline.
The original lateral-movement scenario is repeated after remediation.
Confirm that unauthorized service communication is blocked.
HashiCorp Consul is the primary service-discovery and service-mesh platform.
Open Policy Agent (OPA) is used for policy-based authorization.
Wazuh is used for centralized security monitoring.
OpenSearch is used for centralized investigation.
Nmap is used to validate network-level service exposure.
Multiple controlled web services are deployed behind the Consul service-mesh environment.
Ubuntu hosts the Consul and controlled services.
Kali Linux provides the controlled security-testing environment.
VirtualBox provides the isolated Zero Trust laboratory.