www.egi.eu
EGI-Engage is co-funded by the Horizon 2020 Framework Programme
- f the European Union under grant number 654142
ISGC 2017 Security Workshop
Sven Gabriel
Security Incident handling in Federated Clouds
ISGC 2017 Security Workshop Sven Gabriel Security Incident - - PowerPoint PPT Presentation
ISGC 2017 Security Workshop Sven Gabriel Security Incident handling in Federated Clouds www.egi.eu EGI-Engage is co-funded by the Horizon 2020 Framework Programme of the European Union under grant number 654142 Introduction CSIRT 2017 March
www.egi.eu
EGI-Engage is co-funded by the Horizon 2020 Framework Programme
Security Incident handling in Federated Clouds
2017 March 5 2
CSIRT
2017 March 5 3
CSIRT
Introduction Security in Distributed Infrastructures Incident Prevention Incident/Intrusion Detection Incident Response (IR) IR Communications Containment Forensics
2017 March 5 4
CSIRT
2017 March 5 5
CSIRT
Why bother about Security, another business model Cyberbunker: Mind Your Own Business policy
2017 March 5 6
CSIRT
Why bother about Security Security always has in impact how users experience services. How much you want to care about security is dependent on your business model. This has a serious impact and is a management decision, see for example:
http://www.nytimes.com/2016/09/29/technology/yahoo-data-breach-hacking.html?_r=1
2017 March 5 7
CSIRT
How to sell security to the users/customers Some sociology:
https://static.googleusercontent.com/media/research.google.com/en//pubs/archive/43265.pdf http://www.nature.com/news/how-to-hack-the-hackers-the-human-side-of-cybercrime-1.19872
2017 March 5 8
CSIRT
Examples from our Infra
supercomputer
2017 March 5 9
CSIRT
Ingredients
(Advisories)
(Admin/User)
2017 March 5 10
CSIRT
Incidents, finally . . .
2017 March 5 11
CSIRT
Definition1: A security incident is the act of violating an explicit
Acceptable Use Policy) (https://documents.egi.eu/public/ShowDocument?docid=47)
rented out for illegal activities (Botnet, used for ddos, spam, distribute malware etc).
2017 March 5 12
CSIRT
prevented
2017 March 5 13
CSIRT
Watz)
2017 March 5 14
CSIRT
2017 March 5 15
CSIRT
2017 March 5 16
CSIRT
Vulnerability Handling Process:
2017 March 5 17
CSIRT
Why:
a lot background noise)
each other.
result in funding issues.
2017 March 5 18
CSIRT
Number of incidents using grid technology
2017 March 5 18
CSIRT
Number of incidents using grid technology 1
2017 March 5 19
CSIRT
Criteria (UMD)
by Admins
2017 March 5 20
CSIRT
Non System Experts (Users) are admins of their Infrastructure they deploy in the cloud.
developed.
2017 March 5 21
CSIRT
2017 March 5 22
CSIRT
Tue 16:00 Identifying Suspicious Network Activities in Grid Network Tue 16:30 Modern Monitoring Systems (Watz)
2017 March 5 23
CSIRT
2017 March 5 24
CSIRT
https://wiki.egi.eu/wiki/Security_Policy_Group
communication endpoints.
(https://wiki.egi.eu/wiki/SEC01)
2017 March 5 25
CSIRT
2017 March 5 26
CSIRT
2017 March 5 27
CSIRT
Questions:
2017 March 5 27
CSIRT
Questions:
and https://operations-portal.egi.eu/vo/security
2017 March 5 27
CSIRT
Questions:
and https://operations-portal.egi.eu/vo/security
2017 March 5 27
CSIRT
Questions:
and https://operations-portal.egi.eu/vo/security
Incident_reporting
2017 March 5 27
CSIRT
Questions:
and https://operations-portal.egi.eu/vo/security
Incident_reporting
2017 March 5 28
CSIRT
2017 March 5 29
CSIRT
2017 March 5 29
CSIRT
2017 March 5 29
CSIRT
2017 March 5 29
CSIRT
2017 March 5 30
CSIRT
2017 March 5 31
CSIRT
Talk: Computer Forensics Analysis (FyodorVincent)