U N C L A S S I F I E D
The Los Alamos Super Vault Type Room
Alex Kent
Advanced Computing Solutions Program/Cyber Futures Laboratory Los Alamos National Laboratory
May, 2008
The Los Alamos Super Vault Type Room May, 2008 Alex Kent Advanced - - PowerPoint PPT Presentation
The Los Alamos Super Vault Type Room May, 2008 Alex Kent Advanced Computing Solutions Program/Cyber Futures Laboratory Los Alamos National Laboratory U N C L A S S I F I E D Towards A Strategic Solution Space A decade of events
U N C L A S S I F I E D
Alex Kent
Advanced Computing Solutions Program/Cyber Futures Laboratory Los Alamos National Laboratory
May, 2008
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
actions resulting in loss
both at rest and while in use
– Yet still allow a productive work environment?
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
and data
Residual vulnerability reduced to the single threat of capturing low-bandwidth screen/keyboard/mouse data only
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
SuperVTR
Q-Cleared, Human Reliability Program Complete Visual Control Vault Protections 2-person Controls, Formal Conduct of Ops. Air-gapped classified computing network Minimal Desktop Footprint Two-factor user authentication Intrusion, anomaly detection
Physical Security Cyber Security
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
programmatic staff
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
Super VTR “Data at Rest” Expanded S/RD Red Network Medialess Desktop Computing
Shifted Risk Enabling Foundation R e d u c e d C
p l e x i t y
“Data in Motion” “Data in Use”
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
medialess computing protocols to transit
vulnerabilities of a classified, air-gapped network
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
Medialess IP-Terminal
SuperVTR
LANL Red Network
User Authenticated, Encrypted Tunnel
video/screen output and keyboard/mouse input
servers contained within multi-layered physical and cyber protections
See Ahmad Douglas’ NLIT08 talk on Medialess Computing for a comprehensive overview
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
and integration
Laboratory’s needs
ACREM
~150 users
classified computing with estimates to serve an additional 200 users
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
Customer Window Two-Person Controlled Entrance Professional Staff Computing ACREM and Document Storage
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
Metropolis NSSB SM-43 (D&D) NISC Proposed Site
North
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA
UNCLASSIFIED
Operated by Los Alamos National Security, LLC for DOE/NNSA