60 likes | 286 Views
Security Activities Brent Draney Networking, Security, Servers and Workstations BRDraney@nersc.gov NERSC User Group Meeting September 17, 2007. Security and Compliance. Security Maintaining Systems Detecting compromises Compliance Meeting laws, regulations and guidance
E N D
Security Activities Brent Draney Networking, Security, Servers and Workstations BRDraney@nersc.gov NERSC User Group Meeting September 17, 2007
Security and Compliance • Security • Maintaining Systems • Detecting compromises • Compliance • Meeting laws, regulations and guidance • Demonstrating that NERSC is doing a good job • Goals: • Security should be a net enabler of science • Security should be easy for a person to follow • Security should make sense NERSC User Group Meeting, September 17, 2007
Site Assist Visit Authority to Operate • Compliance schedule • May 06Site Assist Visit (SAV) • June 06 Documentation • May 07Site Assist ends • June 07Readiness Review • July 07Annual Disaster Recovery Test, Self Assessment, Risk Assessment • July 07Security Test and Evaluation • August 07Certification to DOE Berkeley Site Office • October 07Berkeley Site Office accepts residual risk Authority to Operate (ATO) NERSC User Group Meeting, September 17, 2007
Risks • Single biggest risk is a compromised user account • Part of the nature of large scale scientific computing • 1000’s of users on a single system • Most commercial technologies do not address this risk • Firewalls • network based Intrusion Detection Systems (IDS) • Mitigations • User training • Sshd based Intrusion Detection Systems (IDS) NERSC User Group Meeting, September 17, 2007
User Training • Voluntary User Training in Nov 07 • Web based • Specific to scientific computing • 10 minute user effort • Recorded in NIM • Mandatory User Training in CY 08 NERSC User Group Meeting, September 17, 2007
Sshd Monitoring • Modified Sshd in January 08 • Sshd sends keystrokes to an IDS • Open modification to Openssh • IDS analyses keystrokes for anomalies • Scientific activity is very different from hacker activity • Sshd performance improvements added • Pittsburg patches • Scp performance greatly improved NERSC User Group Meeting, September 17, 2007