Training and Dissemination Enabling Grids for E-sciencE www.eu-egee.org Jinny Chien, ASGC 1 Training and Dissemination Jinny Chien Academia Sinica Grid.

Slides:



Advertisements
Similar presentations
Overview of local security issues in Campus Grid environments Bruce Beckles University of Cambridge Computing Service.
Advertisements

1 Chapter 8 Fundamentals of System Security. 2 Objectives In this chapter, you will: Understand the trade-offs among security, performance, and ease of.
NERC Security Requirements – What Vendors Should Provide James W. Sample, CISSP, CISM Manager of Information Security California ISO.
Network Security and Audits LITN Fall Conference 2006 Presented by Katie Givens Mosaic.
© 2005, QEI Inc. all characteristics subject to change. For clarity purposes, some displays may be simulated. Any trademarks mentioned remain the exclusive.
System and Network Security Practices COEN 351 E-Commerce Security.
Chapter 7 HARDENING SERVERS.
ITS Offsite Workshop 2002 PolyU IT Security Policy PolyU IT/Computer Systems Security Policy (SSP) By Ken Chung Senior Computing Officer Information Technology.
Lecture 11 Reliability and Security in IT infrastructure.
Potions of Protection Server Security. What does that do again? Familiarity Differing levels of protection –Low, does not exist –Medium, No private data.
Contact Center Security Strategies Grant Sainsbury Practice Director, Dimension Data.
Computer Security: Principles and Practice
Installing and Configuring a Secure Web Server COEN 351 David Papay.
Building a Campus Dshield Randy Marchany IT Security Lab VA Tech Blacksburg, VA 24060
Network Security. Trust Relationships (Trust Zones) High trust (internal) = f c (once you gain access); g p Low trust ( ) = more controls; fewer privileges.
Intrusion Prevention, Detection & Response. IDS vs IPS IDS = Intrusion detection system IPS = intrusion prevention system.
Site Security and Administration Steve Cobrin.
University of Missouri System 1 Security – Defending your Customers from Themselves StateNets Annual Meeting February, 2004.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.1 ISP Responsibility Working at a Small-to-Medium Business or ISP – Chapter 8.
1 Infrastructure Hardening. 2 Objectives Why hardening infrastructure is important? Hardening Operating Systems, Network and Applications.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 ISP Responsibility Working at a Small-to-Medium Business or ISP – Chapter.
Security Baseline. Definition A preliminary assessment of a newly implemented system Serves as a starting point to measure changes in configurations and.
Describe How Software and Network Security Can Keep Systems and Data Secure P3. M2 and D1 Unit 7.
EGEE-II INFSO-RI Enabling Grids for E-sciencE AP ROC Min-Hong Tsai ASGC SA1 Transition Meeting May 8 th, 2008
User Manager Pro Suite Taking Control of Your Systems Joe Vachon Sales Engineer November 8, 2007.
This courseware is copyrighted © 2015 gtslearning. No part of this courseware or any training material supplied by gtslearning International Limited to.
Module 14: Configuring Server Security Compliance
Enabling Grids for E-sciencE EGEE III Security Training and Dissemination Mingchao Ma, STFC – RAL, UK OSCT Barcelona 2009.
INFSO-RI Enabling Grids for E-sciencE SA1: Cookbook (DSA1.7) Ian Bird CERN 18 January 2006.
Unit 6b System Security Procedures and Standards Component 8 Installation and Maintenance of Health IT Systems This material was developed by Duke University,
Security Update Mingchao Ma HEPSYSMAN - Security 1 st July 2009.
Principles of Computer Security: CompTIA Security + ® and Beyond, Third Edition © 2012 Principles of Computer Security: CompTIA Security+ ® and Beyond,
Lesson 9-Information Security Best Practices. Overview Understanding administrative security. Security project plans. Understanding technical security.
2  Supervisor : MENG Sreymom  SNA 2012_Group4  Group Member  CHAN SaratYUN Sinot  PRING SithaPOV Sopheap  CHUT MattaTHAN Vibol  LON SichoeumBEN.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
Module 14: Securing Windows Server Overview Introduction to Securing Servers Implementing Core Server Security Hardening Servers Microsoft Baseline.
UKI ROC/GridPP/EGEE Security Mingchao Ma Oxford 22 October 2008.
EGEE-II INFSO-RI Enabling Grids for E-sciencE The GILDA training infrastructure.
Chapter 2 Securing Network Server and User Workstations.
Academia Sinica Grid Computing Certification Authority (ASGCCA) Jinny Chien.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Module 12: Responding to Security Incidents. Overview Introduction to Auditing and Incident Response Designing an Audit Policy Designing an Incident Response.
Lessons Learned from disaster recovery Jinny Chien April 20, th APGridPMA in Taipei.
Information Security In the Corporate World. About Me Graduated from Utica College with a degree in Economic Crime Investigation (ECI) in Spring 2005.
Implementing Server Security on Windows 2000 and Windows Server 2003 Fabrizio Grossi.
IPv6 security for WLCG sites (preparing for ISGC2016 talk) David Kelsey (STFC-RAL) HEPiX IPv6 WG, CERN 22 Jan 2016.
How to Mitigate Stay Safe. Patching Patches Software ‘fixes’ for vulnerabilities in operating systems and applications Why Patch Keep your system secure.
Training and Dissemination Enabling Grids for E-sciencE Jinny Chien, ASGC 1 Training and Dissemination Jinny Chien Academia Sinica Grid.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Best Practice and Training Mingchao Ma Operation.
26/01/2007Riccardo Brunetti OSCT Meeting1 Security at The IT-ROC Status and Plans.
EGEE-II INFSO-RI Enabling Grids for E-sciencE Using Certificate & Simple Job Submission Jinny Chien ASGC.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
Palindrome Technologies all rights reserved © 2016 – PG: Palindrome Technologies all rights reserved © 2016 – PG: 1 Peter Thermos President & CTO Tel:
Unit 2 Personal Cyber Security and Social Engineering Part 2.
© ITT Educational Services, Inc. All rights reserved. IS3220 Information Technology Infrastructure Security Unit 10 Network Security Management.
SemiCorp Inc. Presented by Danu Hunskunatai GGU ID #
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks CYFRONET site report Marcin Radecki CYFRONET.
Computer Security: Principles and Practice First Edition by William Stallings and Lawrie Brown Lecture slides by Lawrie Brown Chapter 17 – IT Security.
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
Lecture 19 Page 1 CS 236 Online 6. Application Software Security Why it’s important: –Security flaws in applications are increasingly the attacker’s entry.
INFSO-RI Enabling Grids for E-sciencE Workshop WLCG Security for Grid Sites Louis Poncet System Engineer SA3 - OSCT.
Defense In Depth: Minimizing the Risk of SQL Injection
Working at a Small-to-Medium Business or ISP – Chapter 8
Chapter 6 Application Hardening
CompTIA Server+ Certification (Exam SK0-004)
Identity & Access Management
Welcome to all Participants
Security week 1 Introductions Class website Syllabus review
Designing IIS Security (IIS – Internet Information Service)
6. Application Software Security
Presentation transcript:

Training and Dissemination Enabling Grids for E-sciencE Jinny Chien, ASGC 1 Training and Dissemination Jinny Chien Academia Sinica Grid Computing OSCT EGEE 08 Conference

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 2 Current Status Many Security materials How to find clear information easily OSCTISSeG Wiki LCG securityIGTF GSVG How to train site managers or new comers (ex: good tutorial) Do we have good materials are covered with grid security

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 3 How should we do - Identify what security training/dissemination material is available to the sites on the various EGEE websites and Wikis - Identify the most important security risks for the EGEE infrastructure - Review the material as appropriate, identify unnecessary information and possible missing parts - Propose a strategy for the material dissemination, in order to deliver relevant security information to the sites - Put information on OSCT public website

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 4 Conception

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 5 Diagram

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 6 Trust Site manager Trust Authentication Authorization PKI Certificate Account management VO management Access right management

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 7 Policies Site manager Policy Security Policy Risk Assessment Policy Incident Response Policy

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 8 Network Access Control Site manager Network Configuration Firewall TCP Wrapper M/W port Tool Nmap, Nessus, Netstat, iptables Maintenance Disabling and uninstalling unneeded services Control network bandwidth Secure communication Spam filter tool Network Traffic Attack methods XSS SQL Injection

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 9 Monitoring Site manager Monitoring Software Maintenance Security patch Maintenance Service status Backup CRLs/CAs SW alteration Physical Maintenance HD failure Network failure Electrical failure Air conditioning failure Tool Nagios SAM Pakiti

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 10 Operating System Site manager OS Password Management Good Password SSH key Patch Management Update Log Management central log server Disk Management The permission of File / Directory Anti-Virus IDS( Intrusion Detection System)

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 11 Middleware Site manager M / W Maintenance security patch Host certificate System backup Update CRL and CA rpm Configuration Port / Service Host certificate User mapping (UID/GID)

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 12 Forensics Site manager Forensics Execution Check the system and related log file Anti-Virus Toolkits Collect problematic Log files Inform related members refer to the incident response procedure Avoid more disaster Prevention How to prevent the same problem to happen again

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 13 Procedure Site manager Procedure Incident Response Procedure How to block users How to identify VO users Risk assessment Procedure Access control Procedure Strong password Modification How to control user jobs System documents

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 14 Audit Site manager Audit Provide the Checklist - Users - System Admin - Developers - Managers

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 15 EGEE III Training and Dissemination Site manager Forensics Procedure Audit Trust M / W OS Monitor Network Policy Useful

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 16 Future Plan OSCT website (~ Nov) –Provide clear information to users –Find information easily –Use OSCT web pages effectively and friendly Available information –What is missing –What should be added –What should be removed Training and dissemination –Workshop, tutorial –How to improve the security course Contributions: (Thanks) APROC (4 PM), ITALY (4 PM), SWE (4 PM), DECH (3 PM), FRANCE (2 PM)

Enabling Grids for E-sciencE Training and Dissemination Jinny Chien, ASGC 17 Question ?