A Reproducible Zero Trust Testbed for Dynamic Trust Evaluation Using Emulation and Virtualization Tools
Tiberius Nkinyili, Vincent Omwenga, Solomon Ogara
DOI: http://dx.doi.org/10.15439/2026F5993
Citation: Tiberius Nkinyili, Vincent Omwenga, Solomon Ogara (2026). A Reproducible Zero Trust Testbed for Dynamic Trust Evaluation Using Emulation and Virtualization Tools. In M. Bolanowski, M. Ganzha, M. Grzegorowski, L. Maciaszek, M. Paprzycki, A. Paszkiewicz, D. Ślęzak (eds), Proceedings of the 21st Conference on Computer Science and Intelligence Systems (FedCSIS). ACSIS, Vol. 49, pages 73–80.
Abstract. The practical evaluation of Zero Trust Architecture (ZTA) remains constrained by the lack of accessible, reproducible testbeds supporting dynamic trust experimentation. This paper presents a lightweight, containerized Zero Trust testbed integrating a Software Defined Perimeter (SDP), Software Defined Networking (SDN), network emulation, and policy-as-code enforcement. A pluggable Python trust engine implements progressively sophisticated trust models, culminating in Dempster--Shafer evidential fusion with temporal decay and residual inertia. Evaluation across six representative enterprise scenarios demonstrates low policy evaluation latency, modest session setup overhead, linear scalability, and rapid breach containment, while remaining deployable on commodity hardware. By combining reproducibility, open-source components, and advanced trust evaluation within a single platform, the proposed testbed provides an accessible environment for research, education, and the experimental validation of Zero Trust mechanisms.
References
- D. Horne, “Leveraging Software Defined Perimeter (SDP), Software Defined Networking (SDN), and Virtualization to Build a Zero Trust Testbed with Limited Resources,” 2022.
- D. T. Van, T. B. Hung, T. D. Thang, and N. K. Giao, “Application of Machine Learning in Malicious IoT Classification and Detection on Fog-IoT Architecture,” presented at the The Seventh International Conference on Research in Intelligent and Computing in Engineering, Feb. 2022, pp. 299–303. https://dx.doi.org/10.15439/2022R39.
- S. Rose, O. Borchert, S. Mitchell, and S. Connelly, “NIST Special Publication 800-207 -Zero Trust Architecture.” Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, Aug. 10, 2020. https://doi.org/10.6028/NIST.SP.800-207.
- R. Ward and B. Beyer, “BeyondCorp: A New Approach to Enterprise Security,” ;login:, vol. Vol. 39, No. 6, pp. 6–11, 2014.
- “Executive Order 14028,” Improving the Nation’s Cybersecurity. Accessed: Jun. 29, 2026. [Online]. Available: https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity
- National Institute of Standards and Technology, “Implementing a Zero Trust Architecture,” U.S. Department of Commerce, NIST Special Publication 1800-35, 2025.
- N. Ngema, B. Nleya, and R. C. Maswanganyi, “A Review of Zero Trust Architecture: Principles, Applications, and Implementation Challenges in Communication, Navigation, and Surveillance (CNS) Systems,” Sensors, vol. 26, no. 12, 2026, https://dx.doi.org/10.3390/s26123813.
- R. Vaughn, T. Adewale, and J. Ajayi, “Zero-Trust Architectures for Securing Cloud-Native Infrastructure,” Nov. 2024.
- N. F. Syed, S. W. Shah, A. Shaghaghi, A. Anwar, Z. Baig, and R. Doss, “Zero Trust Architecture (ZTA): A Comprehensive Survey,” IEEE Access, vol. 10, pp. 57143–57179, 2022, https://dx.doi.org/10.1109/ACCESS.2022.3174679.
- M. Lefebvre, S. Nair, D. W. Engels, and D. Horne, “Building a Software Defined Perimeter (SDP) for Network Introspection,” in 2021 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN), 2021, pp. 91–95. https://dx.doi.org/10.1109/NFV-SDN53031.2021.9665152.
- Y. Palmo, S. Tanimoto, H. Sato, and A. Kanai, “A Consideration of Scalability for Software Defined Perimeter Based on the Zero-trust Model,” in 2021 10th International Congress on Advanced Applied Informatics (IIAI-AAI), 2021, pp. 717–724. https://dx.doi.org/10.1109/IIAI-AAI53430.2021.00127.
- J. Adorno, “Evolution of Secure Access: From VPN to SDP-Enabled Zero Trust Network Access (ZTNA) | Zscaler.” Accessed: May 19, 2026. [Online]. Available: https://www.zscaler.com/blogs/product-insights/evolution-secure-access-vpn-sdp-enabled-zero-trust-network-access-ztna
- Trio.so, “CARTA: An Overview of Gartner’s Continuous Adaptive Risk and Trust Assessment,” Trio Security, 2025.
- A. Tripathi et al., “Real Time Adaptive Access Control with Behavioral Analytics for Enhanced Cybersecurity in IoT and Cloud Systems,” presented at the The Ninth International Conference on Research in Intelligent Computing in Engineering, May 2025, pp. 151–155. https://dx.doi.org/10.15439/2024R75.
- S. Munasinghe, N. Piyarathna, E. Wijerathne, U. Jayasinghe, and S. Namal, “Machine Learning Based Zero Trust Architecture for Secure Networking,” in 2023 IEEE 17th International Conference on Industrial and Information Systems (ICIIS), 2023, pp. 1–6. https://dx.doi.org/10.1109/ICIIS58898.2023.10253610.
- M. Aaqib, A. Ali, L. Chen, and O. Nibouche, “Behaviour-based trust assessment for the Internet of Things systems using multi-classifier ensemble learning and Dempster–Shafer fusion,” Neural Computing and Applications, vol. 37, no. 26, pp. 22191–22214, Sep. 2025, https://dx.doi.org/10.1007/s00521-025-11273-8.
- B. Lantz and B. O’Connor, “A Mininet-based Virtual Testbed for Distributed SDN Development,” ACM SIGCOMM Computer Communication Review, vol. 45, pp. 365–366, Aug. 2015, https://dx.doi.org/10.1145/2829988.2790030.
- O. Flauzac, E. Robledo, and F. Nolot, “Is Mininet the Right Solution for an SDN Testbed?,” Dec. 2019, pp. 1–6. https://dx.doi.org/10.1109/GLOBECOM38437.2019.9013145.
- F. Ullah et al., “Deep Trust: A Novel Framework for Dynamic Trust and Reputation Management in the Internet of Things (IoT) Based Networks,” IEEE Access, vol. PP, pp. 1–1, Jan. 2024, https://dx.doi.org/10.1109/ACCESS.2024.3409273.
- D. Haider, S. Mushtaq, H. Ali, and M. Su’ud, “Enhancing Zero Trust Cybersecurity using Machine Learning and Deep Learning Approaches,” Journal of Informatics and Web Engineering, vol. 4, pp. 24–34, Oct. 2025, https://dx.doi.org/10.33093/jiwe.2025.4.3.2.
- G. Shafer, “A Mathematical theory of Evidence,” 1976.
- M. Maliha and M. Atiquzzaman, “Q-ID: A Reinforcement Learning Framework for Adaptive Intrusion Detection,” presented at the 20th Conference on Computer Science and Intelligence Systems (FedCSIS), Kraków, Poland, Oct. 2025, pp. 35–42. https://dx.doi.org/10.15439/2025F1820.
- P. D. J. Fidalgo, A. Pasic, and S. G. Zarzosa, “Dynamic Threat Intelligence for Improvement of Resilience of Critical Infrastructure During Pandemics,” presented at the 19th Conference on Computer Science and Intelligence Systems (FedCSIS), Belgrade, Serbia, Oct. 2024, pp. 591–596. https://dx.doi.org/10.15439/2024F8106.
- N. Wang and D. Wei, “An Adaptive Dempster-Shafer Theory of Evidence Based Trust Model in Multiagent Systems,” Applied Sciences, vol. 12, no. 15, p. 7633, Jul. 2022, https://dx.doi.org/10.3390/app12157633.
- L. Xiong, X. Su, and H. Qian, “Conflicting evidence combination from the perspective of networks,” Inf. Sci., vol. 580, no. C, pp. 408–418, Nov. 2021, https://dx.doi.org/10.1016/j.ins.2021.08.088.
- H. Wang, J. Jiang, and W. Li, “A Dynamic Trust Model Based on Time Decay Factor,” in 2018 IEEE SmartWorld, Ubiquitous Intelligence & Computing, Advanced & Trusted Computing, Scalable Computing & Communications, Cloud & Big Data Computing, Internet of People and Smart City Innovation (SmartWorld/SCALCOM/UIC/ATC/CBDCom/IOP/SCI), 2018, pp. 2048–2051. https://dx.doi.org/10.1109/SmartWorld.2018.00343.
- J. D. L. C. Kiguigouléli Ki and B. Zerbo, “Modeling Dynamic Trust for Cooperative Operations in Edge Computing Environments,” in 2025 IEEE Multi-conference on Natural and Engineering Sciences for Sahel’s Sustainable Development (MNE3SD), 2025, pp. 1–8. https://dx.doi.org/10.1109/MNE3SD67637.2025.11323241.
- IBM Security, “Cost of a Data Breach Report 2024,” p. 46, 2024.
- M. Ahmed, M. Mark, and M. Joy, “Intelligent Trust: Leveraging AI for Dynamic Policy Orchestration in Zero Trust Security Architectures,” International Journal of Artificial Intelligence, Aug. 2021.
- V. Kalekar, “Uncertainty-Aware Reinforcement Learning for Zero Trust: An Empirical Evaluation of PPO, MC Dropout, and Bayesian Neural Networks:,” in Proceedings of the 12th International Conference on Information Systems Security and Privacy, Marbella, Spain: SCITEPRESS - Science and Technology Publications, 2026, pp. 505–514. https://dx.doi.org/10.5220/0014245800004061.
- Dockerdocs, “DockerDocs Manuals,” Docker Documentation. Accessed: Apr. 14, 2026. [Online]. Available: https://docs.docker.com/desktop/
- D. Silva, J. Rafael, and A. Fonte, “Toward Optimal Virtualization: An Updated Comparative Analysis of Docker and LXD Container Technologies,” Computers, vol. 13, no. 4, p. 94, Apr. 2024, https://dx.doi.org/10.3390/computers13040094.
- “The SPIFFE Standard | SPIFFE.” Accessed: Jun. 29, 2026. [Online]. Available: https://spiffe.io/docs/latest/spiffe-specs/
- L. C. Cardoso, M. A. Marques, P. H. B. Correia, H. Z. Cochak, C. C. Miers, and M. A. Simplicio, “Next-Generation SPIFFE/SPIRE Identity Management Systems with Post-Quantum Cryptography Algorithms,” in 2025 IEEE 25th International Symposium on Cluster, Cloud and Internet Computing (CCGrid), 2025, pp. 154–163. https://dx.doi.org/10.1109/CCGRID64434.2025.00033.
- “eBPF Security: Top 5 Use Cases, Challenges & Best Practices.” Accessed: Jun. 29, 2026. [Online]. Available: https://www.oligo.security/academy/ebpf-security-top-5-use-cases-challenges-and-best-practices
- “Installation and Configuration,” Tetragon - eBPF-based Security Observability and Runtime Enforcement. Accessed: Jun. 29, 2026. [Online]. Available: https://tetragon.io/docs/installation/
- “Zeek: Get Zeek,” Zeek. Accessed: Jun. 29, 2026. [Online]. Available: https://zeek.org/get-zeek/
- “2. Quickstart guide — Suricata 9.0.0-dev documentation.” Accessed: Jun. 29, 2026. [Online]. Available: https://docs.suricata.io/en/latest/quickstart.html
- “ttnkinyili/DCTA: Dynamic and Context Aware Trust Algorithm for Zero Trust Enforcement in Heterogeneous Enterprise Environments,” GitHub. Accessed: Apr. 16, 2026. [Online]. Available: https://github.com/ttnkinyili/DCTA
- M. Alawneh and I. M. Abbadi, “Integrating Trusted Computing Mechanisms with Trust Models to Achieve Zero Trust Principles,” in 2022 9th International Conference on Internet of Things: Systems, Management and Security (IOTSMS), Milan, Italy: IEEE, Nov. 2022, pp. 1–6. https://dx.doi.org/10.1109/IOTSMS58070.2022.10062269.
- S. Thapaliya and S. Jha, “Harnessing AI for Enhanced Identity Management: Addressing Cybersecurity Challenges in the Digital Age,” presented at the The Ninth International Conference on Research in Intelligent Computing in Engineering, May 2025, pp. 71–77. https://dx.doi.org/10.15439/2024R34.