Www.egi.eu EGI-InSPIRE RI-261323 EGI-InSPIRE www.egi.eu EGI-InSPIRE RI-261323 SCI-FI Security Challenge Infrastructure for Federated Incident-response.

Slides:



Advertisements
Similar presentations
Breakout Discussion 1 Facilitators Karen Butler-Purry - TAMU Kevin Tomsovic - UTK.
Advertisements

1 PUNCH PUNCH (Purdue University Network Computing Hubs) is a distributed network-computing infrastructure that allows geographically dispersed users to.
April 13, 2004CS WPI1 CS 562 Advanced SW Engineering General Dynamics, Needham Tuesdays, 3 – 7 pm Instructor: Diane Kramer.
LHC Experiment Dashboard Main areas covered by the Experiment Dashboard: Data processing monitoring (job monitoring) Data transfer monitoring Site/service.
SICSA student induction day, 2009Slide 1 Social Simulation Tutorial Session 6: Introduction to grids and cloud computing International Symposium on Grid.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Unified Middleware Distribution (UMD): SW provisioning to EGI Mario David.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks From ROCs to NGIs The pole1 and pole 2 people.
EGI-Engage EGI-Engage Engaging the EGI Community towards an Open Science Commons Project Overview 9/14/2015 EGI-Engage: a project.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Future support of EGI services Tiziana Ferrari/EGI.eu Future support of EGI.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI SA2 services evolution (after the end of EGI-InSPIRE) Peter Solagna, Michel.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Federated Cloud F2F Security Issues in the cloud Introduction Linda Cornwall,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks ?? Athens, May 5-6th 2009 Community Support.
HPDC Report Domenico Vicinanza CERN IT-GD-OPS CERN, July 12 th weekly OPS section meeting.
RI EGI-InSPIRE RI EGI Future activities Peter Solagna – EGI.eu.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE-EGI Grid Operations Transition Maite.
Opérations : Statut et perspectives Gilles Mathieu Workshop opérations 10 mai - Lille Lille – Mai 2012.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks SA1: Grid Operations Maite Barroso (CERN)
Your university or experiment logo here The European Landscape John Gordon GridPP24 RHUL 15 th April 2010.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI (Present and) Future of the EGI Services for WLCG Peter Solagna – EGI.eu.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Fergusson, Emidio Giorgio, Gergely.
EGEE-III-INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE-III All Activity Meeting Brussels,
6/23/2005 R. GARDNER OSG Baseline Services 1 OSG Baseline Services In my talk I’d like to discuss two questions:  What capabilities are we aiming for.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGI Operations Tiziana Ferrari EGEE User.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Robin McConnell NA3 Activity Manager 28.
Globus: A Report. Introduction What is Globus? Need for Globus. Goal of Globus Approach used by Globus: –Develop High level tools and basic technologies.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI GGUS First Ops Tools Long Term Sustainability F2F T. Antoni, E. Buttitta,
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI How to integrate portals with the EGI monitoring system Dusan Vudragovic.
PIC port d’informació científica EGEE – EGI Transition for WLCG in Spain M. Delfino, G. Merino, PIC Spanish Tier-1 WLCG CB 13-Nov-2009.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Monitoring of the LHC Computing Activities Key Results from the Services.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks User Support for Distributed Computing Infrastructures.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Supporting Distributed Computing Infrastructures Torsten Antoni, KIT
European Middleware Initiative (EMI) – Training Kathryn Cassidy, TCD EMI NA2.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI strategy and Grand Vision Ludek Matyska EGI Council Chair EGI InSPIRE.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Grid Oversight in Service Level Agreement environment Małgorzata Krakowian,
1 st EGI CMMST VT meeting 19 February 2013 A. Laganà (UNIPG, Italy)
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Accounting Requirements Stuart Pullinger STFC 09/04/2013 EGI CF – Accounting.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI SSC5 a Multi Site Security Drill code name: “World Domination” Oscar Koeroo.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Plans for PY2 Steven Newhouse Project Director, EGI.eu 30/05/2011 Future.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI UMD Roadmap Steven Newhouse 14/09/2010.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Security Monitoring Daniel Kouřil EGI-TF 2011.
Breaking the frontiers of the Grid R. Graciani EGI TF 2012.
EMI INFSO-RI Testbed for project continuous Integration Danilo Dongiovanni (INFN-CNAF) -SA2.6 Task Leader Jozef Cernak(UPJŠ, Kosice, Slovakia)
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Training Marketplace Claire Devereux STFC, UK
EGI-InSPIRE RI EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Funding Global Tasks.
Setting up NGI operations Ron Trompert EGI-InSPIRE – ROD teams workshop1.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Regionalisation summary Prague 1.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Status of ARGUS support Peter Solagna – EGI.eu.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI TSA1.6 for OMB Torsten Antoni, KIT 1.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Services for Distributed e-Infrastructure Access Tiziana Ferrari on behalf.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Regional tools use cases overview Peter Solagna – EGI.eu On behalf of the.
EGI-InSPIRE RI Pakiti Michal Prochazka, (Daniel Kouril)
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks GOCDB4 Gilles Mathieu, RAL-STFC, UK An introduction.
EGI-InSPIRE EGI-InSPIRE RI The European Grid Infrastructure Steven Newhouse Director, EGI.eu Project Director, EGI-InSPIRE 29/06/2016CoreGrid.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI First Ops Tools Long Term Sustainability F2F David Collados 1First Ops Tools.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Engagement meeting Gergely Sipos EGI.eu 1.
EGI InSPIRE Report to the EGI Council Steven Newhouse On behalf of the Editorial Board.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI GGUS – the EGI Helpdesk Status and Plans T. Antoni Karlsruhe Institute of.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Overview for ENVRI Gergely Sipos, Malgorzata Krakowian EGI.eu
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI.eu Service Portfolio - EGI CF’13 - Apr 2013 EGI.eu Service Portfolio.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI SA1.2 Plans 2013 Security Operations David Kelsey (STFC) 26/02/2013 Operations.
1 The XMSF Profile Overlay to the FEDEP Dr. Katherine L. Morse, SAIC Mr. Robert Lutz, JHU APL
October 2014 HYBRIS ARCHITECTURE & TECHNOLOGY 01 OVERVIEW.
EGI towards H2020 Feedback (from survey)
JRA3 Introduction Åke Edlund EGEE Security Head
BDII Performance Tests
Advancements in Availability and Reliability computation Introduction and current status of the Comp Reports mini project C. Kanellopoulos GRNET.
Operations sustainability
<Name of the tool>
JRA1.4 New Types of Accounting
Presentation transcript:

EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI SCI-FI Security Challenge Infrastructure for Federated Incident-response First Ops Tools Long Term Sustainability F2F Sven Gabriel 1First Ops Tools long Term Sustainability F2F

EGI-InSPIRE RI Contents I.Tool and PT Description II.DoW Checkpoint III.RT Checkpoint IV.Effort Evaluation V.Future Involvement VI.Future Evolution First Ops Tools long Term Sustainability F2F 2

EGI-InSPIRE RI Tool and PT Description I.Quick tool overview (1 slide max) –Framework that provides an infrastructure to run security trainings in “Class-room” and “Distributed (Grid) Mode” –Class-room: Used at conferences like GridKa School, TF, CF. Participants have to solve realistic incidents on prepared systems, + Lectures – Distributed: SSCs, “infecting” RCs, trigger collaboration EGI/NGI/RC/VO/CA Security Teams for IR, assessment of the IR capabilities 3 First Ops Tools long Term Sustainability F2F

EGI-InSPIRE RI –PT composition/Duties Development/Maintenance: –Nikhef / NSC-SNIC / RedIris Central instance: Nikhef Allocated effort: ? 4 First Ops Tools long Term Sustainability F2F

EGI-InSPIRE RI Tool Components II.Tool components overview (2 slides max) –Web-application integrating: Job-Submission Interface, default gLite UI provided –Interface to any Job-Submission framework that provides ssh and a CLI for job-submission Real time Monitor of the “test-incident” (malware activity, user/access management at RCs, Communication (ticketstatus) Replay functionality for debriefing / Reporting Communication (RT-IR) 5 First Ops Tools long Term Sustainability F2F

EGI-InSPIRE RI Tool Components Web-Application: Apache web-server, MySQL / Web framework: Django Python, bash, JSON ldap to interface with IS, based on a VO-Name and Site-list the service endpoints are set-up for the challenge. Job-Submission: any method with a CLI can be used, has to be provided by the “Tester”, done for CRAB, gLiteUI Communication: RT-IR, endpoints are fetched via REST from GOC-DB Reporting/Replay: All events stored in DB, can be replayed, results exported to CSV 6 First Ops Tools long Term Sustainability F2F

EGI-InSPIRE RI DoW Checkpoint III.DoW Checkpoint (2 slides max) –Main DoW requirements met: Integration of job-submission frameworks –gLite, globus, PANDA, CRAB Used in SSCs: – global runs (ATLAS/PANDA, CMS/CRAB) – NGI Runs (Spain, NL/gLite) 7 First Ops Tools long Term Sustainability F2F

EGI-InSPIRE RI –Main Dow requirements under development : Multi User (Test-Operators) functionality –Multiple NGIs runs in parallel Extension to general Security-Training framework –Prototype used for a 3 days security workshop held at GridKa-School –14 participants, very positive feedback received 8 First Ops Tools long Term Sustainability F2F

EGI-InSPIRE RI Effort IV.Effort Evaluation and Splitting (2 slides max) –Development vs Maintenance effort Development of framework –Over past 2 years: 1200h –Protoyp used at GKS: 240h Contributions from 6 Persons –Effort to run the service: 0.5 FTE minimal maintenance/operations –No further development. 9 First Ops Tools long Term Sustainability F2F

EGI-InSPIRE RI Future Involvement IV.Involvement after EGI-InSPIRE (1 slide max) –Is current PT interested in continuing developing/maintaining the tool after EGI-InSPIRE? Yes The complete tool –Estimation of the effort considered minimal to continue the development/maintenance: 0.5 FTE –If no funding after EGI, we run it at best effort, as long as it's useful for both us and others, but we can’t do anything major or implement new requirement 10 First Ops Tools long Term Sustainability F2F

EGI-InSPIRE RI Future Evolution IV.Evolution after EGI-InSPIRE (2 slides max) –How would you like to evolve the tool? Framework for set-up / execution of advanced security trainings aiming at different skills/backgrounds of the participants Framework provides a mobile/flexible “Hands-On” lab useable at various events/conferences/schools, ranging from dedicated multiple days workshops (accompanied with lectures), to smaller hands-on trainings as a site-track during conferences, where the participants can train/check their skills in incident response. The framework at first addresses general topics in systems security, the particularities of providing operational security in distributed computing are building on top of it. Therefore different Grid and/or Cloud-Computing Infrastructures can be simulated here. Therefore it can be used in various IT projects. 11 First Ops Tools long Term Sustainability F2F