EGEE-II INFSO-RI-031688 Enabling Grids for E-sciencE www.eu-egee.org EGEE and gLite are registered trademarks Operational Security Coordination Team Ian.

Slides:



Advertisements
Similar presentations
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
Advertisements

INFSO-RI Enabling Grids for E-sciencE Operational Security OSCT JSPG March 2006 Ian Neilson, CERN.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE Grid Infrastructure and Operations Maite.
INFSO-RI Enabling Grids for E-sciencE Incident Response Policies and Procedures Carlos Fuentes
Operational Security Working Group Topics Incident Handling Process –OSG Document Review & Comments:
EGEE ARM-2 – 5 Oct LCG Security Coordination Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Enabling Grids for E-sciencE EGEE III Security Training and Dissemination Mingchao Ma, STFC – RAL, UK OSCT Barcelona 2009.
INFSO-RI Enabling Grids for E-sciencE SA1: Cookbook (DSA1.7) Ian Bird CERN 18 January 2006.
GGF12 – 20 Sept LCG Incident Response Ian Neilson LCG Security Officer Grid Deployment Group CERN.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Steven Newhouse EGEE’s plans for transition.
Responsibilities of ROC and CIC in EGEE infrastructure A.Kryukov, SINP MSU, CIC Manager Yu.Lazin, IHEP, ROC Manager
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks ROD model assessment ROC UKI John Walsh.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Ake Edlund EGEE Sec Head 9th MWSG meeting, SLAC,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
Training and Dissemination Enabling Grids for E-sciencE Jinny Chien, ASGC 1 Training and Dissemination Jinny Chien Academia Sinica Grid.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks The Bazaar Vision Ideas of RC/VO coordination,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Next steps with EGEE EGEE training community.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Multi-level monitoring - an overview James.
UKI ROC/GridPP/EGEE Security Mingchao Ma Oxford 22 October 2008.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Report from GGUS BoF Session at the WLCG.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Linda Cornwall CCLRC (RAL) FP6 Security workshop.
LCG/EGEE Security Operations HEPiX, Fall 2004 BNL, 22 October 2004 David Kelsey CCLRC/RAL, UK
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks SA1: Grid Operations Maite Barroso (CERN)
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
INFSO-RI Enabling Grids for E-sciencE EGEE SA1 in EGEE-II – Overview Ian Bird IT Department CERN, Switzerland EGEE.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE Security Coordination Group Dr Linda Cornwall CCLRC (RAL) FP6 Security workshop.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks The EGEE User Support Infrastructure Torsten.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks ROC Security Contacts R. Rumler Lyon/Villeurbanne.
Enabling Grids for E-sciencE EGEE-II Meeting EGEE-II SA2 activity Tziouvaras Chrysostomos, MSc NTUA, 14 th March 2006.
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
INFSO-RI Enabling Grids for E-sciencE An overview of EGEE operations & support procedures Jules Wolfrat SARA.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Resource Allocation in EGEEIII Overview &
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Communication tools between Grid Virtual.
PIC port d’informació científica EGEE – EGI Transition for WLCG in Spain M. Delfino, G. Merino, PIC Spanish Tier-1 WLCG CB 13-Nov-2009.
EGEE-II INFSO-RI Enabling Grids for E-sciencE Operations procedures: summary for round table Maite Barroso OCC, CERN
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks The EGEE User Support Infrastructure Alistair.
Last update 22/02/ :54 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD VO Registration procedure Presented by.
EGEE ARM-2 – 5 Oct LCG/EGEE Security Coordination Ian Neilson Grid Deployment Group CERN.
INFSO-RI SA2 ETICS2 first Review Valerio Venturi INFN Bruxelles, 3 April 2009 Infrastructure Support.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Operations Automation Team Kickoff Meeting.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Ian Bird All Activity Meeting, Sofia
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Best Practice and Training Mingchao Ma Operation.
Recent lessons learned: Operational Security David Kelsey CCLRC/RAL, UK GDB Meeting, BNL, 5 Sep 2006.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks SA2 Networking support for EGEE III Xavier.
Operations model Maite Barroso, CERN On behalf of EGEE operations WLCG Service Workshop 11/02/2006.
26/01/2007Riccardo Brunetti OSCT Meeting1 Security at The IT-ROC Status and Plans.
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks LHCOPN Operational model: Roles and functions.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks What all NGIs need to do: Helpdesk / User.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Best Practices and Use cases David Bouvet,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE Operational Procedures (Contacts, procedures,
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA5: Policy and International Cooperation.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Security aspects (based on Romain Wartel’s.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Grid is a Bazaar of Resource Providers and.
INFSO-RI Enabling Grids for E-sciencE Operational Security Coordination Team OSCT report EGEE-4, Pisa Ian Neilson, CERN.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks ROC model assessment AP ROC ShuTing Liao.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks NA5: Policy and International Cooperation.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks The Dashboard for Operations Cyril L’Orphelin.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks CYFRONET site report Marcin Radecki CYFRONET.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks COD-16 (Transition to EGEE-III) Report to.
Scuola Grid - Martina Franca, Thursday 08 November Il Sistema di Supporto INFNGrid & GGUS ( Global Grid User.
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
Enabling Grids for E-sciencE EGEE-II INFSO-RI ROC managers meeting at EGEE 2007 conference, Budapest, October 1, 2007 Admin Matters Vera Hanser.
David Kelsey CCLRC/RAL, UK
LCG Security Status and Issues
LCG/EGEE Incident Response Planning
The CCIN2P3 and its role in EGEE/LCG
Nordic ROC Organization
Presentation transcript:

EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Operational Security Coordination Team Ian Neilson, SA1 EGEE-II conference, Geneva, 2006

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 2 OSCT Overview –Policy Environment  Incident Handling and Response Guide –Security Contact Management –OSCT-1 Meeting –GGUS Security Support Unit –OSCT & Incident Handling –Security Service Challenges –Some Issues –NRENS –ISSeG –Tools

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 3 OSCT - Incident Response Guide The Incident Handling and Response Guide –Common policy for LCG, EGEE, OSG  –What it mandates (MUST do’s)  REPORT : RESPOND : PROTECT INFORMATION : ANALYSE Reporting –Provide contact information  Individual contacts  Monitored list (optional but HIGHLY desirable)  Management now through GOCDB –Reports go through LOCAL site security  = sites should have local plan  Does NOT replace or interfere with local plans –Report to project-{lcg,egee}-security-csirts.at. cern.ch  Incident notification only, no chat  Discussion to project-{lcg,egee}-security-contacts.at. cern.ch

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 4 OSCT - Security Contact Management Site Registration –JSPG Policy -  The name, address and telephone number of the Site Security Contact.  …  The address of a managed list for contact with the site security incident response team. Site entry of data into GOCDB Should be provided before site is approved Individual Contacts have GOCDB ‘role’ of Security Contact –View restricted to same site, other Sec. Contacts, Managers, … Populating IR lists –CSIRT s loaded to incident report list –CONTACT s loaded to discussion list –Still a manual periodic operation Some (many) missing CONTACTS Always some dead entries

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 5 OSCT - OSCT-1 Meeting OSCT-1 CERN, June 2006 –To more clearly define  WHO is the OSCT  WHAT the OSCT does  What LINKS the OSCT has with other groups –Define some basic responsibilities –Update on current activities –Near-term actions 9 out of 11 ROCs came

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 6 What the OSCT does? EGEE-II has a ROC-centric support model –From the EGEE-II Technical Annex ROC responsibilitiesTechnical Annex  Responsible for ensuring that operational problems in the region or in resource centres in the region are resolved and followed-up. The ROC owns the operational problems and is responsible for them;  Coordinate Grid security in the region; provide incident response teams (with members from the sites); –Operational support  Tickets raised from several sources (may result in Incident) ROC-on-duty process (SFT/SAM) GGUS Ticket Process Management (TPM) (User/VO) –Incident Support  Incident Handling Guide CSIRTS and CONTACTS lists –Representation of Operations Security in/to other groups  MWSG, GSVG, JSPG, SCG  ‘attitude’ of sites in the region to security developments  peer grids, NRENS

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 7 Operations Support Model Regional Operations Centre …… Resource Centre Resource Centre … Regional Operations Centre Resource Centre Resource Centre … Grid Operator on-duty ROC and Site work to resolve the problem OSCT Peer Grids

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 8 OSCT- Security Support Unit OSCT and GGUS Support –All ROCs register generic address of regional security support team  project-egee-security-support.at. cern.ch –Trouble tickets raised from any source: user, VO, site, …  Could be an incident (but should be reported to site sec. contact) –Responsible ROC unit takes ownership (assigns to self)  From affected site. OSCT “duty contact” (OSCT-DC) –To act as safety net for unassigned/idle problems  Does not deal with problems. Routing and negotiation role. –Follows same ROC rotation as ROC-on-duty –Monitor ‘unstructured’ data sources: rollout list, weekly operations meeting –Escalation to incident handling process

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 9 OSCT - Incident Handling Flat incident reporting structures –Computer Security Incident Response Teams –Computer Security Contacts –Responsibilities on the reporter for follow-up What is the role for the OSCT?  At times when a Team Leader should be required to coordinate response (Section 6.2) it is expected that this will initially be organised between the reporting site(s) and the Regional Operations Centre (ROC) security contact(s). The ROC contact will ensure that an appropriate mailing list is available and populated for incident follow-up. Incident Team needs - –Clear process for formation to avoid confusion/duplication  Responsibilities should be clear –Basic facilities to be available –  Access to contacts  Access to communications channels  Access to expertise –To communicate  Report to sites (contacts)  Report to management

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 10 OSCT – Incident Handling Responsibilities must be clear: Ownership 1.Regional ROC contact 2.OSCT-DC or backup 3.Other OSCT –Announced to OSCT Core, followed by general notice  Can be delegated if appropriate but must be clearly notified –OSCT contact is not always the TEAM leader but is responsible Access to contacts –GOCDB Communications –OSCT to maintain – (?authentication) IM id’s Telephone details Per-ROC telephone conference facilities/details –We must test these regularly!!

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 11 OSCT – Some Issues Incident follow-up can be VERY time consuming –Do we retain the resources and expertise? –Tools to help? “Grid” incidents and “non-grid” incidents –Can we really draw a boundary (should we) ? –Confusion over whether to report Must encourage a culture of reporting –Must keep the “noise” to acceptable levels  Off-topic chat, SPAM Must prevent unintended leakage –Can be damaging and discourage reporting  e.g. onto public web mail archives Can we deploy fixes or mitigation fast enough?

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 12 OSCT – Security Service Challenges Service Challenge 1 review –Summary of OSCT presentation by Pal AndersenOSCT presentation  –Principal site of each ROC challenged:June 2005  9 of 11 ROCs were able to respond  Debriefing report outAugust 2005 –Challenge passed over to the ROCS14 October 2005  Response from the first ROCNovember 2005  First reminder sent 9 January incorrect Security Contact, 4 acknowledgements  Escalation reminder sent 3 February additional acknowledgement –Status30 April 2006  9 of 11 ROCs executed the challenge  ~130 sites out of ~190 have responded, ~ 68%

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 13 OSCT – Security Service Challenges Service Challenge 2 plans –Traceability of storage operations –Three pieces of information will be provided to the challenged site:  A time interval (~ 15 minutes)  The Distinguished Name (DN) used by the challenger  The Worker Node (WN) from which operations were executed –The question asked is:  What sequence of storage operations affected which files? –Delay because some logging clearly absent from configuration. Has a long cycle time ~ 1 year –This should speed up with practice What to challenge next ? –Apart from the real ones!

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 14 OSCT- ISSeG Grid Security depends on site security EU-funded ISSeG project - Integrated Site Security for Grids Milestones & achievements –Integrated Site Security deployments at CERN & FZK sites progressing well –Input for recommendations is being collected from deployment experience –Training and dissemination plan is being created –Web site is active: –Information sheets are published Issues –Currently discussing scope of site security assessments/audits with the EU Plans –2 year project (February 2006 – January 2008) –To document experience with Integrated Site Security: combining technical, administrative and educational security solutions relevant for academic and research sites –To disseminate recommendations and training to Grid sites for improving site security based on a practical approach and best practices, to complement work on Grid security: –Strengthening general site security helps to protect Grids.

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 15 OSCT - NRENS NRENS –More involved in regional grid infrastructure projects  SWITCH, RedIRIS, DFN, …. –Existing CSIRTs network –Terena workshop focus on security – April 2006  –Still not clear how to link up with EGEE/LCG security  “…vital that the Grid community experts and NREN CERT teams develop collaborative links and formal communications links.” – Workshop Report

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 16 OSCT - Tools There is lots that can be done and discussed Monitoring –Sites using Pakiti for patch monitoringPakiti –Logging and auditing services  e.g. central syslog servers  (see also Security For Open Science proposal Monday’s EGEE/OSG meeting)Security For Open Science proposal –Firewall configuration  Local and ?grid Testing –? SAM for security testing

Enabling Grids for E-sciencE EGEE-II INFSO-RI OSCT - EGEE-II conference, Geneva. 17 OSCT Thank You