security for escience m. angela sasse & brock craft university college london...

9
Security for eScience M. Angela Sasse & Brock Craft University College London [email protected], [email protected]

Upload: hilda-walsh

Post on 19-Jan-2016

212 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: Security for eScience M. Angela Sasse & Brock Craft University College London a.sasse@cs.ucl.ac.uk, b.craft@cs.ucl.ac.uk

Security for eScience

M. Angela Sasse & Brock Craft

University College London

[email protected], [email protected]

Page 2: Security for eScience M. Angela Sasse & Brock Craft University College London a.sasse@cs.ucl.ac.uk, b.craft@cs.ucl.ac.uk

2

They call it anaudit …

• But not of you and your project, but of security policies and tools

• How well do they meet the need of the eScience community?

• What’s wrong with tools, and how we can improve them.

• Knowledge, skills and support you need.

Page 3: Security for eScience M. Angela Sasse & Brock Craft University College London a.sasse@cs.ucl.ac.uk, b.craft@cs.ucl.ac.uk

3

Aim of the survey

• Identify current and future security needs of e-Science users

• Encounters with eScience security needs so far – how was it for you?

• Input into – future security strategy– Selection and improvement of tools – Knowledge and skills training

Page 4: Security for eScience M. Angela Sasse & Brock Craft University College London a.sasse@cs.ucl.ac.uk, b.craft@cs.ucl.ac.uk

4

Focus on users

• eScientists

• eScience software developers

• System administrators and other support roles

Page 5: Security for eScience M. Angela Sasse & Brock Craft University College London a.sasse@cs.ucl.ac.uk, b.craft@cs.ucl.ac.uk

5

Security tool audit

• Authentication– Knowledge-based authentication– Digital certificates

• Authorization– Writing polies for eScience– Implementing policies

• Firewalls• Globus security

Page 6: Security for eScience M. Angela Sasse & Brock Craft University College London a.sasse@cs.ucl.ac.uk, b.craft@cs.ucl.ac.uk

6

Auditing

• What do users need to know?

• How much effort is technology for different stakeholders?

• How well does security fit into your typical eScience day?

Page 7: Security for eScience M. Angela Sasse & Brock Craft University College London a.sasse@cs.ucl.ac.uk, b.craft@cs.ucl.ac.uk

7

Problems with passwords?

Page 8: Security for eScience M. Angela Sasse & Brock Craft University College London a.sasse@cs.ucl.ac.uk, b.craft@cs.ucl.ac.uk

8

5

Page 9: Security for eScience M. Angela Sasse & Brock Craft University College London a.sasse@cs.ucl.ac.uk, b.craft@cs.ucl.ac.uk

9

How to talk to us

• Security discussion session – 16.00 today (Dean Room)

• Make an appointment any time to discuss your specific project needs

• Email us after the meeting, tell your colleagues

[email protected]@cs.ucl.ac.uk