CHEP2006 Network Information and Management Infrastructure Igor Mandrichenko, Eileen Berman, Phil DeMar, Maxim Grigoriev, Joe Klemencic, Donna Lamore,

Slides:



Advertisements
Similar presentations
Resonance: Dynamic Access Control in Enterprise Networks Ankur Nayak, Alex Reimers, Nick Feamster, Russ Clark School of Computer Science Georgia Institute.
Advertisements

Forschungszentrum Karlsruhe in der Helmholtz-Gemeinschaft Torsten Antoni – LCG Operations Workshop, CERN 02-04/11/04 Global Grid User Support - GGUS -
Components of GIS.
The System Center Family Microsoft. Mobile Device Manager 2008.
The Case for Enterprise Ready Virtual Private Clouds Timothy Wood, Alexandre Gerber *, K.K. Ramakrishnan *, Jacobus van der Merwe *, and Prashant Shenoy.
Network+ Guide to Networks, Fourth Edition
LANs and WANs Network size, vary from –simple office system (few PCs) to –complex global system(thousands PCs) Distinguish by the distances that the network.
ITE PC v4.0 Chapter 1 1 Operating Systems Computer Networks– 2.
Chapter 21 Successfully Implementing The Information System
The Internet & The New IT Infrastructure Chapter 9.
NGOP J.Fromm K.Genser T.Levshina M.Mengel V.Podstavkov.
Network+ Guide to Networks, Fourth Edition Chapter 1 An Introduction to Networking.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 11 Managing and Monitoring a Windows Server 2008 Network.
Cross Platform Mobile Backend with Mobile Services James
Section 6.1 Explain the development of operating systems Differentiate between operating systems Section 6.2 Demonstrate knowledge of basic GUI components.
Acceleratio Ltd. is a software development company based in Zagreb, Croatia, founded in We create innovative software solutions for SharePoint,
By Mihir Joshi Nikhil Dixit Limaye Pallavi Bhide Payal Godse.
Network+ Guide to Networks, Fourth Edition Chapter 1 An Introduction to Networking.
Data Center Infrastructure
Technology Overview. Agenda What’s New and Better in Windows Server 2003? Why Upgrade to Windows Server 2003 ?  From Windows NT 4.0  From Windows 2000.
Networked Application Architecture Design. Application Building Blocks Application Software Data Infrastructure Software Local Area Network Server Desktop.
Operating System. Architecture of Computer System Hardware Operating System (OS) Programming Language (e.g. PASCAL) Application Programs (e.g. WORD, EXCEL)
2-3 note. 2 Peripheral Devices “Peripheral devices” are hardware plugged into ports or connected to a computer wirelessly. These devices can be for input,
Cloud Computing. What is Cloud Computing? Cloud computing is a model for enabling convenient, on-demand network access to a shared pool of configurable.
Microsoft Active Directory(AD) A presentation by Robert, Jasmine, Val and Scott IMT546 December 11, 2004.
IT Infrastructure Chap 1: Definition
Automatic Software Testing Tool for Computer Networks ADD Presentation Dudi Patimer Adi Shachar Yaniv Cohen
In the name of God :).
03/27/2003CHEP20031 Remote Operation of a Monte Carlo Production Farm Using Globus Dirk Hufnagel, Teela Pulliam, Thomas Allmendinger, Klaus Honscheid (Ohio.
Cloud Computing & Amazon Web Services – EC2 Arpita Patel Software Engineer.
© 2006 Cisco Systems, Inc. All rights reserved. Optimizing Converged Cisco Networks (ONT) Module 6: Implement Wireless Scalability.
Windows NT Chapter 13 Key Terms By Bill Ward NT Versions NT Workstation n A desktop PC that both accesses a network and works as a stand alone PC NT.
Configuring the network server GOUP 3 ® WORKGROUP: Mr. YUSUF Mr. BULHAN Mr. ABSHIR Mr. OSMAN.
The Grid System Design Liu Xiangrui Beijing Institute of Technology.
1 Introduction to Microsoft Windows 2000 Windows 2000 Overview Windows 2000 Architecture Overview Windows 2000 Directory Services Overview Logging On to.
6/26/01High Throughput Linux Clustering at Fermilab--S. Timm 1 High Throughput Linux Clustering at Fermilab Steven C. Timm--Fermilab.
Network Monitor By Zhenhong Zhao. What is the Network Monitor? The Network Monitor is a tool that gets information off of the host on the LAN. – Enumerating.
Jonathan Loving Fermi Lab Computing Division
A Software Solution for the Control, Acquisition, and Storage of CAPTAN Network Topologies Ryan Rivera, Marcos Turqueti, Alan Prosser, Simon Kwan Electronic.
Management of the LHCb DAQ Network Guoming Liu * †, Niko Neufeld * * CERN, Switzerland † University of Ferrara, Italy.
INTRODUCTION TO DBS Database: a collection of data describing the activities of one or more related organizations DBMS: software designed to assist in.
Lee Lueking 1 The Sequential Access Model for Run II Data Management and Delivery Lee Lueking, Frank Nagy, Heidi Schellman, Igor Terekhov, Julie Trumbo,
CS 127 Introduction to Computer Science. What is a computer?  “A machine that stores and manipulates information under the control of a changeable program”
1 OFF SYMB - 12/7/2015 Firewalls Basics. 2 OFF SYMB - 12/7/2015 Overview Why we have firewalls What a firewall does Why is the firewall configured the.
Globus and PlanetLab Resource Management Solutions Compared M. Ripeanu, M. Bowman, J. Chase, I. Foster, M. Milenkovic Presented by Dionysis Logothetis.
Communications & Networks National 4 & 5 Computing Science.
CERN - IT Department CH-1211 Genève 23 Switzerland t High Availability Databases based on Oracle 10g RAC on Linux WLCG Tier2 Tutorials, CERN,
James S. Rothfuss, Computer Protection Program COMPUTING SCIENCES NETS Network Equipment Tracking System.
Wireless Network Management SANDEEP. Network Management Network management is a service that employs a variety of tools, applications, and devices to.
R. Krempaska, October, 2013 Wir schaffen Wissen – heute für morgen Controls Security at PSI Current Status R. Krempaska, A. Bertrand, C. Higgs, R. Kapeller,
Gaia An Infrastructure for Active Spaces Prof. Klara Nahrstedt Prof. David Kriegman Prof. Dennis Mickunas
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Mario Reale – GARR NetJobs: Network Monitoring Using Grid Jobs.
TECHDOTCOMP SUPPORT TECHDOTCOMP nd Ave, Seattle, WA 98122, USA Phone:
COMP1321 Digital Infrastructure Richard Henson March 2016.
Development of the Fermilab Open Science Enclave Policy and Baseline Keith Chadwick Fermilab Work supported by the U.S. Department of.
Luz GUEVARA - Simon CHOLLET INGRID Database Proposal for Database.
Open source IP Address Management Software Review
2016 Global Seminar 按一下以編輯母片標題樣式 Virtualization apps simplify your IoT development Alfred Li.
Organizations Are Embracing New Opportunities
DEPARTMENT OF COMPUTER SCIENCE AND ENGINEERING CLOUD COMPUTING
Top 5 Open Source Firewall Software for Linux User
Computer Networks Part 1
Barbara Martelli INFN - CNAF
Platform as a Service.
Cloud based Open Source Backup/Restore Tool
Everything You Need To Know About Penetration Testing.
Network+ Guide to Networks, Fourth Edition
PLANNING A SECURE BASELINE INSTALLATION
Salesforce.com Salesforce.com is the world leader in on-demand customer relationship management (CRM) services Manages sales, marketing, customer service,
Overview of Computer system
Presentation transcript:

CHEP2006 Network Information and Management Infrastructure Igor Mandrichenko, Eileen Berman, Phil DeMar, Maxim Grigoriev, Joe Klemencic, Donna Lamore, Mark Leininger, Don Petravick, Vladimir Podstavkov, Randy Reitz Fermi National Accelerator Laboratory

CHEP2006 Challenges of FNAL LAN management Specifics of FNAL network Large Open, dynamic Exposed Successful network and network security management requires coordinated cooperation of key players: Data Communications Computer Security Users Desktop support

CHEP2006 What is NIMI ? NIMI stands for Network Information and Management Infrastructure Hardware – 2 Linux servers Database with quasi-real time network status data PostgreSQL Network Data Collector Data access and application building framework Python as programming language PostgreSQL as the database solution (Kerberized) SOAP as middleware communication mechanism Kerberos, X509 as authentication mechanisms Zope as Web interface development tool

CHEP2006 Big Picture

CHEP2006 NIMI Database PostgreSQL based Stores network state quasi-realtime data Uses PostgreSQL backup functionality to make backup in 3 locations Another disk on the same server Backup NIMI DB server FNAL CD Backup Server Data is kept since March 2004 < 5GB on disk

CHEP2006 NIMI Collector Collects network state information from network devices Stores data in NIMI Database and makes it available to applications Information collected: DHCP leases (quasi-realtime) ARP tables (periodic polls) VPN sessions (periodic polls) Switch forwarding tables (periodic polls)

CHEP2006 NIMI-Based Applications Network Inventory Up-to-date inventory of network devices and services Scanners Configuration problems Software version monitoring Vulnerabilities TIssue Computer Security Issue Tracking workflow system Fed by scanners

CHEP2006 Network Inventory Provides up-to-date information about network devices present on the LAN New node discovery Periodic subnet pings (every 2 minutes) ARP tables (delayed up to 15 minutes) Uses ping scans and ARP tables data for node discovery Collects information about OS version and services found on each computer Most of new nodes scanned within 5 minutes Helps optimize efficiency of other Scanners

CHEP2006 Scanners Run on Scanner Farm Use data from Inventory Scanner to scan new nodes within minutes of their arrival, and then re- scan them in lazy manner as they stay online Three areas: Vulnerabilities (Vulnerability Scanner) System misconfiguration Outdated software Vulnerability Scanner Uses nmap to detect vulnerabilities Scanners supply events for TIssue

CHEP2006 TIssue Workflow engine used to keep track of security vulnerabilities and network-related issues Provides flexible abstract interface to plug in Detectors (e.g. Scanners) Keeps track of events in detector-independent way Communicates with machine administrators via and web interface Requests blocks of network addresses as the enforcement tool Zope-based web GUI uses X509 certificates as the authentication mechanism

CHEP2006 Advantages of using NIMI Common data storage easily available to applications Simple modular design of the system Collector – deals with variety of vendor-specific network data Central database APIs Middleware Carefully chosen set of software tools covering all areas of application development PostgreSQL Python SOAP Zope Kerberos, X509

CHEP2006 NIMI: Success Story Recent computer security related events have demonstrated that applications such as TIssue and Inventory Scanner are very reliable, powerful and useful computer security and network management tools NIMI provides building blocks for rapid development of applications like these We continue new application development using NIMI as the framework