EGEE-II INFSO-RI-031688 Enabling Grids for E-sciencE www.eu-egee.org EGEE and gLite are registered trademarks Handling Grid Security Vulnerabilities in.

Slides:



Advertisements
Similar presentations
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Grid Security Vulnerabilities Dr Linda Cornwall,
Advertisements

INFSO-RI Enabling Grids for E-sciencE Operational Security OSCT JSPG March 2006 Ian Neilson, CERN.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI The EGI Software Vulnerability Group and EMI Dr Linda Cornwall, STFC, Rutherford.
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
EGI-InSPIRE The EGI Software Vulnerability Group (SVG) What is a Software Vulnerability?SVG membership and interaction with other groups Most people are.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks gLite Release Process Maria Alandes Pradillo.
What if you suspect a security incident or software vulnerability? What if you suspect a security incident at your site? DON’T PANIC Immediately inform:
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks From ROCs to NGIs The pole1 and pole 2 people.
The Grid Services Security Vulnerability and Risk Assessment Activity in EGEE-II Enabling Grids for E-sciencE EGEE-II INFSO-RI
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
What if you suspect a security incident or software vulnerability? What if you suspect a security incident at your site? DON’T PANIC Immediately inform:
INFSO-RI Enabling Grids for E-sciencE SA1: Cookbook (DSA1.7) Ian Bird CERN 18 January 2006.
GGF12 – 20 Sept LCG Incident Response Ian Neilson LCG Security Officer Grid Deployment Group CERN.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks The Grid Security Vulnerability Group Dr.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Grid Security Vulnerability Handling and.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Interoperability Shibboleth - gLite Christoph.
Deployment Issues David Kelsey GridPP13, Durham 5 Jul 2005
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Federated Cloud F2F Security Issues in the cloud Introduction Linda Cornwall,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks GSVG issues handling Dr Linda Cornwall CCLRC.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Ake Edlund EGEE Sec Head 9th MWSG meeting, SLAC,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA2 – Dissemination, Outreach and Communication.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Multi-level monitoring - an overview James.
Update on the Grid Security Vulnerability Group Linda Cornwall, MWSG7, Amsterdam 14 th December 2005
Security Vulnerabilities Linda Cornwall, GridPP15, RAL, 11 th January 2006
JRA Execution Plan 13 January JRA1 Execution Plan Frédéric Hemmer EGEE Middleware Manager EGEE is proposed as a project funded by the European.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Linda Cornwall CCLRC (RAL) FP6 Security workshop.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks SA1: Grid Operations Maite Barroso (CERN)
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
INFSO-RI Enabling Grids for E-sciencE EGEE SA1 in EGEE-II – Overview Ian Bird IT Department CERN, Switzerland EGEE.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Dr Linda Cornwall CCLRC (RAL) FP6 Security workshop.
The Grid Security Vulnerability Group (GSVG) Enabling Grids for E-sciencE EGEE-III INFSO-RI Eliminating and Preventing.
EGEE-III INFSO-RI Enabling Grids for E-sciencE Antonio Retico CERN, Geneva 19 Jan 2009 PPS in EGEEIII: Some Points.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks ROC Security Contacts R. Rumler Lyon/Villeurbanne.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Progress on first user scenarios Stephen.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Threat Risk Assessment Dr Linda Cornwall Rutherford Appleton.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Vulnerability handling, Risk management,
Security Vulnerability Identification and Reduction Linda Cornwal, JRA1, Brno 20 th June 2005
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Task tracking SA3 All Hands Meeting Prague.
INFSO-RI Enabling Grids for E-sciencE An overview of EGEE operations & support procedures Jules Wolfrat SARA.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Grid Services Security Vulnerability and.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Additional Services: Security and IPv6 David Kelsey STFC-RAL.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA3 Activity – Training and Induction Robin.
INFSO-RI SA2 ETICS2 first Review Valerio Venturi INFN Bruxelles, 3 April 2009 Infrastructure Support.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Operations Automation Team Kickoff Meeting.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Ian Bird All Activity Meeting, Sofia
Security Vulnerability Detection and reduction Linda Cornwall MWSG, CERN 24 Feb 2005
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Patch Preparation SA3 All Hands Meeting.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Best Practice and Training Mingchao Ma Operation.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks MSA3.4.1 “The process document” Oliver Keeble.
Recent lessons learned: Operational Security David Kelsey CCLRC/RAL, UK GDB Meeting, BNL, 5 Sep 2006.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA5: Policy and International Cooperation.
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE Operations: Evolution of the Role of.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks What all NGIs need to do: Helpdesk / User.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Federated Cloud and Software Vulnerabilities Linda Cornwall, STFC 20.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA5: Policy and International Cooperation.
INFSO-RI Enabling Grids for E-sciencE JRA3 Åke Edlund On behalf of JRA3 EGEE 8th All-activity meeting January 18-19,
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
EGEE-II Enabling Grids for E-sciencE EGEE and gLite are registered trademarks The Grid Security Vulnerability Group Activity in Central.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks GSVG issue handling summary Dr Linda Cornwall.
Ian Bird GDB Meeting CERN 9 September 2003
Grid Services Security Vulnerability and Risk Analysis
Romain Wartel EGEE08 Conference, Istanbul, 23rd September 2008
EGI Security Risk Assessment
Prevention is better than Cure
Presentation transcript:

EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Handling Grid Security Vulnerabilities in EGEE-II Dr Linda Cornwall, Rutherford Appleton Laboratory, Chilton, Didcot, Oxon, England ISGC2007, 28 th March 2007

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 2 Contents Why we setup the Grid Security Vulnerability Group (GSVG) The EGEE-II Security Co-ordination Group (SCG) –How the GSVG fits in The Vulnerability Task in EGEE-II Issue Handling Risk Assessments Disclosure policy Other Grid Security Vulnerability work in EGEE-II

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 3 Why the Grid Security Vulnerability Group (GSVG) was set up GSVG started work before the beginning of EGEE-II using GridPP funded effort A lot was being done concerning Grid Security Functionality –Authentication, Authorization Not much was being done to ask “Is the Grid Secure” The software isn’t perfect – Some vulnerabilities are in the process of being fixed – Some are probably waiting to be exploited It will be really embarrassing if when the Large Hadron Collider comes on line at CERN we get a serious attack which prevents data being stored or processed Could be more than embarrassing if Grids were used to attack other systems or carry out illegal activities Hackers Conference HOPE mentioned Grids –Unfriendly people without credentials aware of us –Cannot rely on security through obscurity Real Grids are being deployed –No longer a research/proof of concept activity

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 4 The EGEE-II Security Co-ordination Group (SCG) EUGridPMA Joint Security Policy Group MiddleWare Security Group Policies Architecture gLite Security Trust anchor IGTF chair Grid Security Vulnerability Group Operational Security Coordination Team Operations

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 5 The Vulnerability Task in EGEE II In EGEE II there is manpower for the “Grid Services Security Vulnerability and Risk Assessment” Task The aim is “to incrementally make the Grid more secure and thus provide better availability and sustainability of the deployed infrastructure” –This is recognition that it cannot be made perfect immediately GSVG aims to prevent Grid Security incidents –Grid security incidents are handled by the EGEE incident handling process, not GSVG –GSVG may help handle a vulnerability issue that lead to an incident Handling of Specific Security Vulnerability issues is the largest activity in this task –Issues may be reported by anyone –Most issues are software vulnerabilities –Issues arising from lack of functionality and operational problems may also be reported

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 6 Setup of the issue handling in EGEE II The GSVG issues group in EGEE II consists of Core Group Members –Run the general process –Ensure information is passed on –1 on duty each working day Risk Assessment Team (RAT) –Carry out Risk Assessments –At present 8 full RAT members –Plus 4 others which confine their work to their own area of expertise RAT people are security experts, experienced system administrators, deployment experts and developers

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 7 What we do - to first order Issue is submitted –Anyone can submit an issue The GSVG then carries out a Risk Assessment –At least 3 RAT members assess each issue –Target Date (TD) for resolution is set according to Risk –Mirror bug entered in EGEE middleware bug handling system –Aim to complete this within 2 working days of issue being submitted The issue is then in the hands of the Developers and the Engineering Management Team (EMT) –EMT co-ordinates fixing the issue and the release An advisory is issued when the problem is fixed or on the Target Date, whichever is the sooner. –When the issue is fixed the advisory is included in the release notes

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 8 Risk Assessment Strategy An agreed strategy where risk assessments are objective not subjective is required Site security officers most fear an attack that gives access to the whole site –Especially if it can be carried out anonymously –DoS tends to be considered no more than medium risk A vulnerability that can be exploited by an authorized user is considered by most less serious than one that can be exploited without credentials –Especially if their actions are clearly logged We can’t ignore the possibility that credentials may be stolen Issues that can be exploited trivially and reliably are considered more serious than those that are harder to exploit and can only be exploited in rare circumstances Decided on 4 risk categories –Extremely Critical –High –Moderate –Low

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 9 4 Risk Categories Extremely Critical –Examples  Trivial Grid Wide DoS with no Credentials  Remote Root access with or without Credentials –Target Date – 2 days High –Examples  Identity theft or impersonation  Exploit against MW component that gives elevated access  Grid-wide disruption  Information leakage which is illegal or embarrassing –Target Date – 3 weeks

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 10 4 Risk Categories (contd) Moderate –Examples  Confidential issues in user information  Local DoS  Potentially serious, but hard to exploit problem. E.g. hard to exploit buffer overflow –Target Date = 3 months Low –Examples  Small system information leak  Issue which is only exploitable in unlikely circumstances, or where an exploit cannot be found  Issue where impact on service minimal –Target Date = 6 months

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 11 Disclosure Policy and Target Date By carrying out Risk Assessments and setting a TD we are allowing the resolution of issues to be prioritized The TD can also be seen as the maximum length of time the issue can be lived with, without taking action We are moving to a responsible public disclosure policy On Target Date, information on the issue is made public –Regardless of whether a fix is available –This only applies to EGEE software This is to ensure confidence in the system –People less likely to discuss issues on public mailing list rather than use our system Public disclosure ensures all those who install the software have access to information on known vulnerabilities

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 12 Issues that do not result in software bugs Some issues are purely operational –The Operational Security Co-ordination Team (OSCT) are informed –Risk Category not necessary Some issues are due to missing functionality –The EGEE Technical Co-ordination Group (TCG) and the EGEE Security Co-ordination Group (SCG) are informed Some issues are more general concerns –Discuss with TCG and SCG

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 13 GSVG Users sysadmins Developers Anyone! Submit issue OSCT TCG SCG EMT/JRA1 disclosure Operational issue Patch available with advisory Patch not available on TD Security bug in middleware (most issues) Missing functionality and other concerns

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 14 Other Vulnerability Work Programming guidelines –By producing developers guidelines developers should be helped to write in a secure manner so as not to introduce new vulnerabilities into their code. –Checklist for developers produced (prior to EGEE-II) Certification and vulnerability testing –The EGEE Integration, Testing and Certification activity carry out certification testing before software is released. This may include testing to ensure that a vulnerability that has been fixed is no longer present –Vulnerability testing is carried out by the Security Team at Poznan Penetration testing –Price Waterhouse Cooper (Switzerland) are a Business associate for EGEE-II –Carrying out penetration testing using their own tools - initially on VOMS

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 15 More information The GSVG web page summarizes the activities of the group Details of the issue handling process are available at pdf pdf The GSVG has produced the EGEE EU deliverable DSA 1.3, "Grid Services Security Vulnerability and Risk Analysis" document. This is available at

Enabling Grids for E-sciencE EGEE-II INFSO-RI ISGC Linda Cornwall - Grid Security Vulnerabilities 16 Questions/Discussion ???