Zero Trust Lateral Movement Lab (Interactive)
Compromise one laptop; count how far the attacker walks with and without micro-segmentation. Contrast flat VPN trust against BeyondCorp-style identity-aware proxy, SPIFFE mTLS, and Cilium policies by computing reachable nodes, exposed datastores, and traversal logs.
Castle-and-Moat vs Zero Trust Blast Radius
Compromise one foothold, then measure exactly how far the attacker walks. Network locality conveys zero privilege.
Initial foothold (phished / exploited)
Every east-west hop requires a valid, unexpired X.509 SVID bound to the workload's SPIFFE ID — stolen IPs alone cannot impersonate a service, and certs auto-rotate before exfiltration windows open.
Blast radius
33%
of internal nodes reachable
Sensitive stores exposed
1 / 3
HR PII · prod DB · backups
Attacker traversal log
- foothold acquired: Contractor Laptop (endpoint)
- Contractor Laptop → HR Web App: IAP: Okta SSO + FIDO2 + device posture → this one app only
- Contractor Laptop → Metrics Dashboard: IAP grant for observability team
- Contractor Laptop → CI Runner Pod: CiliumNetworkPolicy DROP + missing SVID: mTLS handshake aborts before bytes flow
- Contractor Laptop → Billing Service: CiliumNetworkPolicy DROP + missing SVID: mTLS handshake aborts before bytes flow
- Contractor Laptop → Prod PostgreSQL: CiliumNetworkPolicy DROP + missing SVID: mTLS handshake aborts before bytes flow
- Contractor Laptop → S3 Nightly Backups: CiliumNetworkPolicy DROP + missing SVID: mTLS handshake aborts before bytes flow
Contractor Laptop
● COMPROMISED
CI Runner Pod
■ ISOLATED
HR Web App
▲ REACHED
Billing Service
■ ISOLATED
Metrics Dashboard
▲ REACHED
Prod PostgreSQL
■ ISOLATED
S3 Nightly Backups
■ ISOLATED
Lateral movement succeeded — perimeter trust is breachedOne phished credential (or one supply-chained CI pod) placed the attacker on a flat east-west network — exactly the failure mode Google BeyondCorp eliminated after Operation Aurora. Data staged to S3 and exfiltrated over the same VPN tunnel the employee "legitimately" uses.
Interview framing (NIST SP 800-207): replace the VPN concentrator with an Identity-Aware Proxy that evaluates user identity + device posture (disk encrypted, OS patched, EDR heartbeat) on every request; replace static service credentials with SPIRE-issued 1-hour SVIDs rotated in-memory by the mesh sidecar; replace subnet ACLs with workload-identity network policies. Accept ~0.5–1ms mTLS overhead per hop and an internal PKI as the price of eliminating the inside-out attack class.
How It Works Under the Hood
Castle-and-moat security assumes anyone inside the perimeter is trusted, so one phished contractor VPN credential delivers unrestricted east-west movement: subnet scans, unpatched internal servers, and database dumps all reachable without re-authentication. Zero Trust (NIST SP 800-207) asserts network locality conveys zero privilege: an identity-aware proxy admits the user to exactly one application after checking device posture, services authenticate each RPC with short-lived SPIRE-issued SVIDs, and eBPF micro-segmentation denies workload-to-workload flows lacking an explicit least-privilege policy. The lab BFS-walks the live policy graph from whichever node you compromise, exposing how identity-at-ingress alone, without east-west enforcement, silently reverts to the flat network.
Core Architectural Principles
- VPN-mode reachability is a complete graph: every internal node accepts east-west connections.
- Zero Trust reachability is BFS over explicit policy edges like IAP app grants and billing-to-postgres:5432.
- Disabling micro-segmentation while keeping ingress checks leaves workload-to-workload movement unpoliced.
Open with the mantra: never trust, always verify; network locality conveys zero privilege. Tell the lateral-movement story, then name the building blocks: identity-aware proxy replacing the VPN, SPIFFE/SPIRE short-lived SVIDs for mTLS, and micro-segmented egress policies. Quantify the cost honestly: internal PKI, MDM agents, and ~0.5-1 ms per mesh hop.
Zero Trust eliminates the inside-out attack class but buys that containment with PKI, posture agents, and per-hop crypto overhead.