Www.egi.eu EGI-InSPIRE RI-261323 EGI-InSPIRE www.egi.eu EGI-InSPIRE RI-261323 EGI Federated Cloud and Software Vulnerabilities Linda Cornwall, STFC 20.

Slides:



Advertisements
Similar presentations
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group Summary EGI TF David Kelsey 6/28/
Advertisements

EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI The EGI Software Vulnerability Group and EMI Dr Linda Cornwall, STFC, Rutherford.
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
EGI-InSPIRE The EGI Software Vulnerability Group (SVG) What is a Software Vulnerability?SVG membership and interaction with other groups Most people are.
What if you suspect a security incident or software vulnerability? What if you suspect a security incident at your site? DON’T PANIC Immediately inform:
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group EGI Technical Forum Sep 2010 David Kelsey.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Future support of EGI services Tiziana Ferrari/EGI.eu Future support of EGI.
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
What if you suspect a security incident or software vulnerability? What if you suspect a security incident at your site? DON’T PANIC Immediately inform:
European Grid Initiative Federated Cloud update Peter solagna Pre-GDB Workshop 10/11/
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Grid Security Vulnerability Handling and.
Deployment Issues David Kelsey GridPP13, Durham 5 Jul 2005
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Federated Cloud F2F Security Issues in the cloud Introduction Linda Cornwall,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks GSVG issues handling Dr Linda Cornwall CCLRC.
RI EGI-InSPIRE RI EGI Future activities Peter Solagna – EGI.eu.
Update on the Grid Security Vulnerability Group Linda Cornwall, MWSG7, Amsterdam 14 th December 2005
Security Vulnerabilities Linda Cornwall, GridPP15, RAL, 11 th January 2006
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Federated Cloud Security - what is needed Linda Cornwall (STFC) and the.
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
Trusted Virtual Machine Images a step towards Cloud Computing for HEP? Tony Cass on behalf of the HEPiX Virtualisation Working Group October 19 th 2010.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Threat Risk Assessment Dr Linda Cornwall Rutherford Appleton.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) WLCG GDB, CERN 10 Jul 2013.
Security Vulnerability Identification and Reduction Linda Cornwal, JRA1, Brno 20 th June 2005
Reflections “from around the block.” (Security) Ian Neilson GridPP Security Officer STFC RAL.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI and MeDIA Steven Newhouse EGI.eu MeDIA - April
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
APEL Cloud Accounting Status and Plans APEL Team John Gordon.
Additional Services: Security and IPv6 David Kelsey STFC-RAL.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Service Operations Security Policy the new generalised site operations security policy.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI SPG future work EGI Technical Forum Lyon, 21 Sep 2011 David Kelsey, STFC/RAL.
Chapter 3 Pre-Incident Preparation Spring Incident Response & Computer Forensics.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Running Big Data on the EGI Federated Cloud Javier Lopez Cacheiro, Álvaro.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Evolution of AAI for e- infrastructures Peter Solagna Senior Operations Manager.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
Why a Commercial Provider should Join the Academic Cloud Federation David Blundell Managing Director 100 Percent IT Ltd Simple, Flexible, Reliable.
3rd Helix Nebula Workshop on Interoperability among e-Infrastructures and Commercial Clouds Carmela ASERO, EGI.eu 17 September 2013, Madrid
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Draft Security Virtualisation Policy (for Romain Wartel – CERN) EGI Technical.
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
Ian Collier, STFC, Romain Wartel, CERN Maintaining Traceability in an Evolving Distributed Computing Environment Introduction Security.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Policy Development in EGI.eu/EGI-InSPIRE Damir Marinovic (EGI.eu)
EGI-InSPIRE RI EGI Webinar EGI-InSPIRE RI Porting your application to the EGI Federated Cloud 17 Feb
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI CSIRT Procedure for Compromised Certificates and Central Security Emergency.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI UMD Roadmap Steven Newhouse 14/09/2010.
EGI-InSPIRE RI SPG Tasks for Year 2011 Jan 2011 Kelsey/Security Policy Group1.
EGI-InSPIRE RI SPG Tasks for Year 2011 Jan 2011 Kelsey/Security Policy Group1.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI-InSPIRE PY5 new activities Peter Solagna – EGI.eu.
Instituto de Biocomputación y Física de Sistemas Complejos Cloud resources and BIFI activities in JRA2 Reunión JRU Española.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Enabling SSO capabilities in the EGI Cloud services Peter Solagna – EGI.eu.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Questionnaires to Cloud technology providers and sites Linda Cornwall, STFC,
Trusted Virtual Machine Images the HEPiX Point of View Tony Cass October 21 st 2011.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Storage Accounting John Gordon, STFC OMB August 2013.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI /09/14 1 Appliance lifecycle services Marios Chatziangelou, et al.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI /04/14 1 EGI Community Forum 2014 Federated Cloud image management Marios.
European Grid Initiative The EGI Federated Cloud as Educational and Training Infrastructure for Data Science Tiziana Ferrari/ EGI.eu.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI A pan-European Research Infrastructure supporting the digital European Research.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI John Gordon EGI Virtualisation and Cloud Workshop Amsterdam 13 th May 2011.
EGI-InSPIRE RI EGI Compute and Data Services for Open Access in H2020 Tiziana Ferrari Technical Director, EGI.eu
Cloud Security Session: Introduction 25 Sep 2014Cloud Security, Kelsey1 David Kelsey (STFC-RAL) EGI-Geant Symposium Amsterdam 25 Sep 2014.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI SA1.2 Plans 2013 Security Operations David Kelsey (STFC) 26/02/2013 Operations.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI D4.4 and the EGI review Dr Linda Cornwall 19 th Sept 2011 D4.41.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI SVG F2F Virtual Machines VM images, software run on VMS. 3 rd March 2015.
Directory/Inventory – info sharing for security people
EGI Software Vulnerability Group (SVG) report to CSIRT F2F
FedCloud Blueprint Update
EGI Security Risk Assessment
Software Vulnerability Group Status update
Prevention is better than Cure
Dr Linda Cornwall STFC/RAL EGI OMB 27th September 2013
Presentation transcript:

EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Federated Cloud and Software Vulnerabilities Linda Cornwall, STFC 20 th January 2015 EGI Fed Cloud F2F st January 20151

EGI-InSPIRE RI What do we want? Software deployed on the Cloud infrastructure to not cause security problems that lead to security incidents This means, as a minimum:-- Software doesn’t have obvious security problems or basic security errors If software security vulnerabilities are found, then they are handled appropriately, product teams are easy to contact, and problem is fixed in a timely manner according to the severity, parties deploying software notified and able to update. 20th January

EGI-InSPIRE RI And when a vulnerability is found EGI SVG is able to handle according to an approved procedure Investigation by SVG and the development team If valid – carry out a risk assessment (Critical, High, Moderate or Low) Set Target Date for resolution according to Risk Advisory issued to sites when problem is fixed For e.g. linux announcements – only risk assess for our environment - advisory for high or critical Since Vulnerabilities handled consistently across EGI Grid infrastructure (see last slide to find more info) 20 th January

EGI-InSPIRE RI Some progress since Sept (Big data) Acceptance that this activity continues to be important in the Fed Cloud 4 new SVG members Alvaro Lopez Garcia, Enol Fernandez del Castillo (both Fed Cloud) Edward Karavakis (WLCG), Bartlomiej Balcerek Other new members are welcome, especially those with FedCloud technical expertise

EGI-InSPIRE RI Some clarification has occurred Fed cloud says ‘User’ is in change – which is what the policy group has called ‘VM Operator’ High skill level instantiates VMs See Security Policy for the Endorsement and Operation of Virtual Machine Images ‘End User’ – (e.g. scientist) connects to VMs to carry out their work Less skilled

EGI-InSPIRE RI Software the fed cloud depends on must be O.K. Started on Technology provider questionnaire Good for security critical software which Fed Cloud depends on (I’ve had no time to work on this recently) Possibility of smaller checklist, for all software Very basic checks, e.g. for insecure constructs, not validating user input. More detailed assessment for some, e.g. AAI No clear source of effort for this

EGI-InSPIRE RI VM Operator software VM operators also need to use secure software within their VMs Possibly Checklist For ‘End User’ access, certain methods or software could be assessed by EGI and recommended for use This is something that could add value to the EGI Fed cloud compared to using others

EGI-InSPIRE RI Vulnerability handling Main next step is to revise SVG vulnerability issue handling procedure To take account of Fed Cloud situation Commercial announcements, community s/w Cloud enabling s/w, VO software Contacts etc. All s/w on which EGI Fed cloud depends must be maintained

EGI-InSPIRE RI Software Security Support All software on which EGI fed cloud depends MUST be under security support I.e. someone must be available to fix any vulnerabilities found Minimum is if a research institute says someone unfunded is providing support in working time Problem if someone doing work as a hobby Do we really want to depend on hobby support?

EGI-InSPIRE RI Contacts for S/W enabling fed cloud It should be clear how to contact software providers, who are providing software which enables fed cloud For a large commercial provider their web page may provide details on how to report problems For community software, SVG should have direct contact details (persons, list.)

EGI-InSPIRE RI Contact –VO software VO specific software – i.e. that instantiated by a VM Operator – VO contact details acceptable. Needs to be clear to which VO something belongs No more than 1 between SVG and the development team E.g. contact VO security contacts, they know the development team VO software, software instantiated by VM Operator may get stopped if security probs

EGI-InSPIRE RI VM images and updates (if not discussed previously in security session) Images in AppDB must be kept up to date Endorser's job doesn’t end with the production of the image VM images must be kept up to date Short lived and re-instantiate or patched? Training/certification for endorsers?

EGI-InSPIRE RI SVG (re)-invigorate Possibly a F2F meeting, with new members and old Need to combine experience of established SVG members and new Cloud members Establish how we do vulnerability handling in the Fed Cloud

EGI-InSPIRE RI Software dependencies generally There is an issue that EGI is dependent on a lot of 3 rd party software Linux, OpenStack, OpenNebula, java, ….. Possibly EGI should consider whether our infrastructure can influence such software development and maintenance

EGI-InSPIRE RI Questions/Discussion ??

EGI-InSPIRE RI More Info on EGI SVG EGI SVG Wiki Basic vulnerability handling summary Approved issue handling procedure Presentation from EGI Community Forum resId=0&materialId=slides&confId= th Sept 2014 Linda Cornwall, STFC, Software security 16