NOS Report Jeff Koerner Feb 10 TG Roundtable. Security-wg In Q4 2010 a total of 11 user accounts and one login node were compromised. The Security team.

Slides:



Advertisements
Similar presentations
Scaling TeraGrid Access A Testbed for Attribute-based Authorization and Leveraging Campus Identity Management
Advertisements

1 US activities and strategy :NSF Ron Perrott. 2 TeraGrid An instrument that delivers high-end IT resources/services –a computational facility – over.
Common User Environments Working Group Shawn T. Brown, PSC CUE Working Group Lead TeraGrid Annual Review 04/7/
Introducing… SSEDAC 7 April  DPI’s plans for a business intelligence tool  Tools  Implementation & Timeline  Why business intelligence?  Introductions.
Science Gateway Security Recommendations Jim Basney Von Welch This material is based upon work supported by the.
Technology Steering Group January 31, 2007 Academic Affairs Technology Steering Group February 13, 2008.
National Center for Supercomputing Applications University of Illinois at Urbana-Champaign This material is based upon work supported by the National Science.
Office of Science U.S. Department of Energy Grids and Portals at NERSC Presented by Steve Chan.
Federated Access to US CyberInfrastructure Jim Basney CILogon This material is based upon work supported by the National Science Foundation.
TeraGrid Science Gateway AAAA Model: Implementation and Lessons Learned Jim Basney NCSA University of Illinois Von Welch Independent.
Initial Findings  Secure all contracts with third party vendors immediately  Develop a strong understanding of the ‘Flow of PHI’ within and outside of.
TG QM Arlington: GIG User Support Coordination Plan Sergiu Sanielevici, GIG Area Director for User Support Coordination
System Design/Implementation and Support for Build 2 PDS Management Council Face-to-Face Mountain View, CA Nov 30 - Dec 1, 2011 Sean Hardman.
Website Hardening HUIT IT Security | Sep
Network, Operations and Security Area Tony Rimovsky NOS Area Director
Attribute-based Authentication for Gateways Jim Basney Terry Fleury Stuart Martin JP Navarro Tom Scavo Jon Siwek Von Welch Nancy Wilkins-Diehr.
NOS Objectives, YR 4&5 Tony Rimovsky. 4.2 Expanding Secure TeraGrid Access A TeraGrid identity management infrastructure that interoperates with campus.
GIG Software Integration: Area Overview TeraGrid Annual Project Review April, 2008.
TeraGrid Information Services December 1, 2006 JP Navarro GIG Software Integration.
Dao Dinh Kha National Centre of Digital Signature Authentication - Agency of Information Technology Application A vision on a national Electronic Authentication.
Scaling Account Creation and Management through the TeraGrid User Portal Contact: Eric Roberts
GIG Software Integration Project Plan, PY4-PY5 Lee Liming Mary McIlvain John-Paul Navarro.
1 TeraGrid ‘10 August 2-5, 2010, Pittsburgh, PA State of TeraGrid in Brief John Towns TeraGrid Forum Chair Director of Persistent Infrastructure National.
Set of priorities per WBS level 3 elements: (current numbering need to be mapped to new WBS version from Tim) (AD = member of wheels with oversight responsibility)
Time lag between discovering issue and resolving Difficult to find solutions and patches that can help resolve issue Service outages expensive and.
3 rd Party Registration & Account Management SMT Update To AMWG Status February 24, 2014.
GGF Fall 2004 Brussels, Belgium September 20th, 2004 James Marsteller Pittsburgh Supercomptuing Center
Coordinating the TeraGrid’s User Interface Areas Dave Hart, Amit Majumdar, Tony Rimovsky, Sergiu Sanielevici.
UFP/CS Update David Hart. Highlights Sept xRAC results POPS Allocations RAT follow-up User News AMIE WebSphere transition Accounting Updates Metrics,
1 PY4 Project Report Summary of incomplete PY4 IPP items.
Presented by: Presented by: Tim Cameron CommIT Project Manager, Internet 2 CommIT Project Update.
© 2008 Pittsburgh Supercomputing Center So you have a TeraGrid Allocation What now?
Appendix C: Designing an Operations Framework to Manage Security.
SMT Joint TDSPs AMWG 17 Change Requests Update To RMS May 6, 2014 Bob Frazier Senior Director of Electric Technology CenterPoint Energy (representing SMT.
TeraGrid CTSS Plans and Status Dane Skow for Lee Liming and JP Navarro OSG Consortium Meeting 22 August, 2006.
Shibboleth: An Introduction
Electronic Security Initiative 2005 Security Assessment & Security Services 23 August 2005.
Grid Middleware Tutorial / Grid Technologies IntroSlide 1 /14 Grid Technologies Intro Ivan Degtyarenko ivan.degtyarenko dog csc dot fi CSC – The Finnish.
NA-MIC National Alliance for Medical Image Computing UCSD: Engineering Core 2 Portal and Grid Infrastructure.
CaGrid 2.0 Security Prototype 1. Goals Prototype some proposed security solutions – Ensure interoperability across programming models – Ensure interoperability.
Biomedical and Bioscience Gateway to National Cyberinfrastructure John McGee Renaissance Computing Institute
Leveraging the InCommon Federation to access the NSF TeraGrid Jim Basney Senior Research Scientist National Center for Supercomputing Applications University.
Enabling Grids for E-sciencE EGEE Applications Registry Current status & latest developments Marios Chatziangelou.
TeraGrid NOS Turnover Jeff Koerner Q meeting December 8, 2010.
Information Services Internet Accounting Workshop 1 st Feb 2011 Peter Kurtz Manager, Network & Communication Services.
3 rd Party Registration & Account Management JDOA Update To RMS October 28, 2014.
1 1 Cybersecurity : Optimal Approach for PSAPs FCC Task Force on Optimal PSAP Architecture Working Group 1 Final Report December 10 th, 2015.
Biomedical and Bioscience Gateway to National Cyberinfrastructure John McGee Renaissance Computing Institute
Security Environment Assessment. Outline  Overview  Key Sources and Participants  General Findings  Policy / Procedures  Host Systems  Network Components.
System/SDWG Update Management Council Face-to-Face Flagstaff, AZ August 22-23, 2011 Sean Hardman.
User-Facing Projects Update David Hart, SDSC April 23, 2009.
Data, Visualization and Scheduling (DVS) TeraGrid Annual Meeting, April 2008 Kelly Gaither, GIG Area Director DVS.
Network, Operations and Security Area Tony Rimovsky NOS Area Director
GridChem Sciene Gateway and Challenges in Distributed Services Sudhakar Pamidighantam NCSA, University of Illinois at Urbaba- Champaign
National Energy Research Scientific Computing Center (NERSC) Visportal : interface to grid enabled NERC resources Cristina Siegerist NERSC Center Division,
TeraGrid-Wide Operations Von Welch Area Director for Networking, Operations and Security NCSA, University of Illinois April, 2009.
TeraGrid User Portal Migration Project Summery Jeff Koerner Director of Operations TeraGrid GIG Matt Heinzel Director TeraGrid GIG September 2009.
Enabling Grids for E-sciencE EGEE Applications Registry Current status & latest developments Marios Chatziangelou.
Attribute-based Authentication for Gateways Jim Basney Terry Fleury Stuart Martin JP Navarro Tom Scavo Nancy Wilkins-Diehr.
TeraGrid QA/INCA Turnover Jeff Koerner Q meeting December 8, 2010.
Quality Assurance (QA) Working Group Update July 1, 2010 Kate Ericson (SDSC) Shava Smallen (SDSC)
TeraGrid’s Common User Environment: Status, Challenges, Future Annual Project Review April, 2008.
Visualization Update June 18, 2009 Kelly Gaither, GIG Area Director DV.
TG ’08, June 9-13, State of TeraGrid John Towns Co-Chair, TeraGrid Forum Director, Persistent Infrastructure National Center for Supercomputing.
TeraGrid’s Process for Meeting User Needs. Jay Boisseau, Texas Advanced Computing Center Dennis Gannon, Indiana University Ralph Roskies, University of.
Gateways security Aashish Sharma Security Engineer National Center for Supercomputing Applications (NCSA) University of Illinois at Urbana-Champaign.
TeraGrid Software Integration: Area Overview (detailed in 2007 Annual Report Section 3) Lee Liming, JP Navarro TeraGrid Annual Project Review April, 2008.
Overview – SOE PatchTT November 2015.
Overview – SOE PatchTT December 2013.
Third Party Risk Governance in a Diverse Environment
Presentation transcript:

NOS Report Jeff Koerner Feb 10 TG Roundtable

Security-wg In Q a total of 11 user accounts and one login node were compromised. The Security team spent a significant amount of time responding to Linux vulnerabilities. –The height of which one vulnerability a week was announced with some vendors not having patches ready. The annual TeraGrid assessment project was completed in Q – This year’s effort focused on an assessment of the TeraGrid User portal (TGUP) operations and technologies.

cont. Security-wg –The TeraGrid user portal has become and increasingly important piece of the TeraGrid infrastructure Username and password logins into the TGUP can be used to generate short term proxied credentials that can be used for access to TeraGrid resources at the RPs. The assessment found that TGUP staff were well aware of and taking measures to prevent common web-based application vulnerabilities. –The team has defined and documented issues of properly handling and proxying user credentials while accessing the portal. However the Security-wg felt additional requirements were warranted for third party (i.e. no TeraGrid RP) hosted systems.

OAuth update OAuth (Open Authorization protocol) –This improvement will enable external non-TG web browser based services (third party), such as Globus Online (GO) and other Gateways, to authenticate TG users without having physical access to their TG username and password. Project Plan is currently being defined. –Once the plane is finalized developer resources will be allocated. –Optimistic estimate at this point we hope to have something to deliver to the TGUP team in June. –The Portal team then would incorporate the solution into the portal.

CUE-wg Update The CUE working group continues to work toward releasing the CUE to the Teragrid User Community. – The CUE group wrapped up the beta testing period – They are currently working with TG Public Relations team to announce the development. –The CUE implements and procedures have been finalized on all current TG architectures, and documentation has been created explaining its use. The group also continues to work on how to improve the commonality of queuing and testing throughout the TG.

INCA –The Inca team continued to support and maintain the Inca deployment on TeraGrid Four existing TeraGrid reporters were modified and one new reporter was created and deployed in Q At the end of Q ,976 pieces of test data are being collected across TeraGrid platforms. NCSA’s Ember was added to the Inca testing. NCSA’s Cobalt was removed from Inca testing. TACC's Lonestar was removed from testing in Q4 but was re-added Feb 1 st after it’s upgrade. The team updated Inca deployment to the 2.6 release. –The two most relevant features of this release are: »Data mirroring capabilities »Historical graphing abilities for performance data. This will facilitate the IS team to see response times of their monitored services.

System Performance Metrics Slight dip in delivered NUs for Q4 over Q3 –However, up over same period in 2010 by 1.7x

Cont. System Performance Metrics 873 different projects charged usage on TeraGrid –Down just slightly from 882 in Q –The top 20 PIs consumed 51% of the NUs used and the remaining 853 projects consumed the other 49%. Top 9 Disciplines with more than 2% of NUs: Physics Molecular Bioscience Astronomical Sciences Atmospheric Sciences Chemical, Thermal Systems Material Research Chemistry Advanced Scientific Computing Biological and Critical Systems