OSG Security Review Mine Altunay June 19, 2008. June 19, 2008 2 Security Overview Current Initiatives  Incident response procedure – top priority (WBS.

Slides:



Advertisements
Similar presentations
Dec 14, 20061/10 VO Services Project – Status Report Gabriele Garzoglio VO Services Project WBS Dec 14, 2006 OSG Executive Board Meeting Gabriele Garzoglio.
Advertisements

Role Based VO Authorization Services Ian Fisk Gabriele Carcassi July 20, 2005.
9/25/08DLP1 OSG Operational Security D. Petravick For the OSG Security Team: Don Petravick, Bob Cowles, Leigh Grundhoefer, Irwin Gaines, Doug Olson, Alain.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 04/02/2014.
Authorization WG Update David Kelsey EU Grid PMA, Copenhagen 27 May 2008.
Open Science Grid Use of PKI: Wishing it was easy A brief and incomplete introduction. Doug Olson, LBNL PKI Workshop, NIST 5 April
OSG Area Coordinators Meeting Security Team Report Mine Altunay 05/15/2013.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
Open Science Grid Use of PKI: Wishing it was easy A brief and incomplete introduction. Doug Olson, LBNL PKI Workshop, NIST 5 April 2006.
Jan 2010 Current OSG Efforts and Status, Grid Deployment Board, Jan 12 th 2010 OSG has weekly Operations and Production Meetings including US ATLAS and.
WLCG Security TEG, risks and Identity Management David Kelsey GridPP28, Manchester 18 Apr 2012.
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
Key Accomplishments and Work Plans OSG Security Team July 11, 2012.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 01/29/2014.
Key Project Drivers - FY11 Ruth Pordes, June 15th 2010.
INFSO-RI Enabling Grids for E-sciencE Incident Response Policies and Procedures Carlos Fuentes
OSG Area Coordinators Meeting Security Team Report Kevin Hill 08/14/2013.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 12/21/2011.
OSG Security Program Review OSG Security Team M. Altunay, FNAL, OSG Security Officer, D. Olson LBNL, Ron Cudzewicz FNAL J. Basney NCSA, Anand Padmanabhan.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 06/25/2014.
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
May 8, 20071/15 VO Services Project – Status Report Gabriele Garzoglio VO Services Project – Status Report Overview and Plans May 8, 2007 Computing Division,
OSG Security Kevin Hill. Goals Operational Security – Identify software vulnerabilities – observing the practices of our VOs and sites, and sending alerts.
Blueprint Meeting Notes Feb 20, Feb 17, 2009 Authentication Infrastrusture Federation = {Institutes} U {CA} where both entities can be empty TODO1:
Apr 30, 20081/11 VO Services Project – Stakeholders’ Meeting Gabriele Garzoglio VO Services Project Stakeholders’ Meeting Apr 30, 2008 Gabriele Garzoglio.
Mine Altunay OSG Security Officer Open Science Grid: Security Gateway Security Summit January 28-30, 2008 San Diego Supercomputer Center.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 04/3/2013.
Mar 28, 20071/9 VO Services Project Gabriele Garzoglio The VO Services Project Don Petravick for Gabriele Garzoglio Computing Division, Fermilab ISGC 2007.
Evolution of the Open Science Grid Authentication Model Kevin Hill Fermilab OSG Security Team.
OSG Security Review Mine Altunay December 4, 2008.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay OSG Security Officer.
Rob Quick OSG Operations Area Coordinator Manager High Throughput Computing Indiana University Integrating OSG Operational Services Rob Quick OSG Operations.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
OSG PKI Contingency and Recovery Plans Mine Altunay, Von Welch OSG Council August 23, 2012.
Introduction to OSG Security Suchandra Thapa Computation Institute University of Chicago March 19, 20091GSAW 2009 Clemson.
UKI ROC/GridPP/EGEE Security Mingchao Ma Oxford 22 October 2008.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 11/02/2011.
Mine Altunay July 30, 2007 Security and Privacy in OSG.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 6/6/2012.
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
Meeting Minutes and TODOs TG has no distributed monitoring. During incident response, use a manual twiki page to distribute information TG monitors the.
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
9 Oct Overview Resource & Project Management Current Initiatives  Generate SOWs  8 written and 6 remain;  drafts will be complete next week 
G Z LIGO's Physics at the Information Frontier Grant and OSG: Update Warren Anderson for Patrick Brady (PIF PI) OSG Executive Board Meeting Caltech.
Status Organization Overview of Program of Work Education, Training It’s the People who make it happen & make it Work.
Top 10 Reasons to Upgrade to OSG Version Rob Quick OSG Operations Coordinator.
Open Science Grid Security Activities Mine Altunay, FNAL OSG Security Officer For the OSG Security Team: Doug Olson, Deputy Security Officer, LBNL, Jim.
Sergiu April 2006June 2006 Overview of TeraGrid Security Working Group Activities James Marsteller CISSP, Working Group Chair.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
Grid Security and Identity Management Mine Altunay Security Officer, Open Science Grid, Fermilab.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 4/11/2012.
Sep 25, 20071/5 Grid Services Activities on Security Gabriele Garzoglio Grid Services Activities on Security Gabriele Garzoglio Computing Division, Fermilab.
OSG Area Coordinator’s Report: Workload Management Maxim Potekhin BNL May 8 th, 2008.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 02/13/2012.
Identity Management in Open Science Grid Identity Management in Open Science Grid Challenges, Needs, and Future Directions Mine Altunay, James Basney,
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
LCG User, Site & VO Registration in EGEE/LCG Bob Cowles OSG Technical Meeting Dec 15-17, 2004 UCSD.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
Open Science Grid Security Activities D. Olson, LBNL OSG Deputy Security Officer For the OSG Security Team: M. Altunay, FNAL, OSG Security Officer, D.O.,
Cyber Security Issues in HEP and NP Grids Bob Cowles — SLAC NC August 2004.
OSG Area Coordinators Meeting Security Team Report Mine Altunay 8/15/2012.
OSG Facility Miron Livny OSG Facility Coordinator and PI University of Wisconsin-Madison Open Science Grid Scientific Advisory Group Meeting June 12th.
New OSG Virtual Organization Security Training OSG Security Team.
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
IGTF Risk Assessment Team 5/11/091.
OSG Security Review Mine Altunay March 12, Jan Security Overview Current Initiatives  OSG Security roadmap  Technical and operational.
OSG Security Kevin Hill.
LCG Security Status and Issues
Presentation transcript:

OSG Security Review Mine Altunay June 19, 2008

June 19, Security Overview Current Initiatives  Incident response procedure – top priority (WBS and 2.3.)  OSG Registration Policy and Requirements from members (WBS 2.3.1)  VO, and Site requirements, collected policies?  OSG Core Assets/Software in VDT Stack (WBS 2.1.7)  OSG security Officer’s duty wrt VDT’s consumers  DOEGrids RA workflow – introducing requested notifications (WBS 2.2)  VO incident response teams (WBS and 2.1.2)  Command Line Security Management Tools (WBS 2.1.1)  Banning tool requirements. With CDIGS. (WBS 2.1.9)  Including OSG Staff contact info into OIM (WNBS and 2.1.2)  Grid Tactical Plan (FNAL) and MOU with VO services/Privilege Project (WBS 2.1.9)  ST&E control deadlines are approaching (WBS 2.1.1) Accomplishments Since Last Report (some in progress)  Items completed from the roadmap (WBS 2.1.4)  Proxy Clean-Up for Jobs – completed. A bug in Globus is found  Proxy clean-up for storage is under investigation  Incident Response procedure – first draft completed  Security plan revision against NIST guidelines – completed (WBS 2.1.4)  Privacy Policy has been discussed at the board, comments are being addressed (WBS 2.3)  For implementation, I will ask Suchandra’s help  JSPG meeting, 4 policies are approved and comments sent to WLCG (WBS 2.3, 2.3.2, 2.3.1)

June 19, 2008  Forensics/Auditing tool Splunk (WBS )  Initial coding for testing completed  Data transfer from Gratia to Splunk is being worked on  NSF report to Large facilities  User’s meeting at BNL. Invited Security contacts with Jemise. Good participation and raised awareness Vulnerabilities/incidents  Debian openSSL problem  Report completed. Post-mortem actions: IGTF incident response procedures, LIGO’s openSSH library error mode  RPath problem: fix has been released.  Report is in progress. Post-mortem actions: Comm problems with EGEE. Announcement sent to Linux comm. Discussing SELinux and VDT. Changing VDT build practice to prevent this from happening again  IGTF distribution problem:  Newly accredited CAs and site policies. Still in discussion  INFN root exploit – joint report with EGEE is completed and sent to facility  The team is discussing the post-mortem actions listed 3

June 19, 2008 Security Overview Issues / Concerns  Effort: incident and vulnerability response and discussion takes a considerable amount of time from other work. Pending initiatives  Confusion over VDT/OSG relationship  Specific to past months : increasing time spent on fermi lab duties. Lay-offs and other procedures  Cooperation with other area coordinators: OSG 1.0 stalled many initiatives due to lack of effort 4

June 19, 2008 Initiatives/Concerns from the Last Report Initiatives  OSG Security roadmap  Technical and operational needs for long and short term (WBS 2.1.4)  Incident Mitigation Plans (WBS 2.3)  AuthN needs: GSI auth problems, CRLs, proxy clean up and VOMS-GUMS authN (WBS and and )  AuthZ needs: Banning tool, Uniform FQAN, MyProxy, AC validation (a request doc is written with Privilege project) (WBS and and )  More fire drills and site education (WBS 2.1)  Forensics -- splunk, incident training  Certify tool  Policy work  JSPG and OSG policies – incident response policy has priority (WBS and 2.3.)  Revising old security plan against NIST guidelines (WBS 2.1.4)  Risk assessment (WBS 2.1.4, 2.3) Issues / Concerns  Effort– Jim and Ron already started – very helpful  Incident sharing and privacy concerns, latest incident at INFN  Lack of security education, and incidents  We need more fire drills and discuss OSG responsibilities  Lack of attendance at security meetings – our facility team Color code: Completed, Work has started, No work 5