Presentation is loading. Please wait.

Presentation is loading. Please wait.

Sponsored by the National Science Foundation GENI Security Architecture What’s Up Next? GENI Engineering Conference 7 Durham, NC Stephen Schwab SPARTA/Cobham.

Similar presentations


Presentation on theme: "Sponsored by the National Science Foundation GENI Security Architecture What’s Up Next? GENI Engineering Conference 7 Durham, NC Stephen Schwab SPARTA/Cobham."— Presentation transcript:

1 Sponsored by the National Science Foundation GENI Security Architecture What’s Up Next? GENI Engineering Conference 7 Durham, NC Stephen Schwab SPARTA/Cobham Analytic Solutions 17 March 2010 www.geni.net

2 Sponsored by the National Science Foundation GENI Security Architecture “Space” Control Frameworks/Aggregates –Clearinghouses, Independent Testbeds with a GENI Control Framework, AMs, SMs, MAs, … Monitoring –Operations, Intrusion Detection/Response, Situational Awareness Source Code –Assurance of Designs & Implementation Long list of other issues and topics…

3 Sponsored by the National Science Foundation Security Mechanisms for Control Frameworks ProtoGENI –User (Researcher) Credentials, Slice Credentials, Tickets/Rspecs PlanetLab –SFA Interface and Credentials, Policy based federated resource allocation (BBP+09 paper) ORCA –Leasing/Tickets among Actors (SM, AM, Broker) Other trust mechanisms explored in spiral –DETER TIED, ABAC, Shibboleth in-commons

4 Sponsored by the National Science Foundation Security Issues for Operational Monitoring Monitoring / Intrusion Detection & Response / Situational Awareness Exporting: GENI AMs  Campus IT Importing: Campus IT  GENI *? Control Frameworks | Clearinghouse | GMOC GENI networks are deploying on campus now, but also will be “in the campus network”. How do we diagnose things that break? Or security break-ins?

5 Sponsored by the National Science Foundation Source Code Quality Assurance Rapid Development Spirals –Software is being written and re-written quickly –Not much time to review what is changing from version to version –Great for researchers during prototyping! Deploying new code on production networks –Should we encourage review of new software? –Code reviews? –Inspection? –Automatic Scanners? –Robustness… Connected to security DoS resilience –How do we fail gracefully …so production hardware continues to work, but GENI software “fails safe”?

6 Sponsored by the National Science Foundation 6 17 March 2010 Best Practices for Aggregate Providers Guidance to aggregate providers on managing portions of their network that affect GENI security


Download ppt "Sponsored by the National Science Foundation GENI Security Architecture What’s Up Next? GENI Engineering Conference 7 Durham, NC Stephen Schwab SPARTA/Cobham."

Similar presentations


Ads by Google