the current security policy of jinr

12
The current security policy of JINR ______________________ __

Upload: errol

Post on 14-Jan-2016

38 views

Category:

Documents


0 download

DESCRIPTION

The current security policy of JINR. ________________________. The current JINR local network structure. GRID Cluster Network Structure. Cluster organized on L2 technology with one broadcast domain . Cluster connect to JINR BackBone by two redundant links. Site network security. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: The current security policy of JINR

The current security policy of JINR

________________________

Page 2: The current security policy of JINR

The current JINR local network structure

Page 3: The current security policy of JINR
Page 4: The current security policy of JINR

GRID Cluster Network Structure

Cluster organized on L2 technology with one broadcast domain.Cluster connect to JINR BackBone by two redundant links

Page 5: The current security policy of JINR

Site network security Центральный firewall построен на двух взаимо-

резервируемых Cisco 6500 FW модулях и Cisco ACL. Firewall ОИЯИ контролируют доступ до каждого из

незапрещенных сервисов внутри ОИЯИ. ACL на лабораторных свитчах обеспечивают

безопасность локальной сети ОИЯИ. Доступ к сетевому оборудованию обеспечивается

TACACS сервером и Cisco ACL (Login, DualUP, VPN). Kerberos V обеспечивает заход на центральный

информационно-вычислительный комплекс. Доступ до домашних пользовательских директорий

контролируется при помощи AFS token.

Page 6: The current security policy of JINR

Accounts policy and system security

Все пользовательские пароли сохранены в Kerberos V

Домашние директории находятся на AFS

Разрешены только безопасные прото-колы (SSL, SSH or Kerberos)

Каждая лаборатория может иметь собственный Kerberos Server

Page 7: The current security policy of JINR

AFS использует Kerberos V

База Kerberos сохранена в LDAP

LDAP используется для хранения пользовательской информации

Kerberos V with LDAP backend

Page 8: The current security policy of JINR

JINR Network DataBase (IPDB)

Page 9: The current security policy of JINR

Monitoring (NMIS)Each cluster element use central logging server.Monitoring for alarms and troubles provided by NMIS.

Page 10: The current security policy of JINR

AUDIT

Network and System audit based on analyzing logs from central routers, firewalls and local switchboards.

IDS (intrusion detect system) build on freeware flow-tools (Cisco NetFlow).

In progress development works on own PDS, based on ROOT package.

Page 11: The current security policy of JINR

Problem

Problems with hardware filtration of hi speed incoming dataflow (more then 1Gb).

Deficiency of common account dependent information system which provides information of security options for each node and possibility for tuning this options for each node.

Deficiency of hardware dataflow encryption devices, for security data transfer.

Page 12: The current security policy of JINR

Near Future Plans

Particle replacement Linux “iptable” on Cisco ACL for increase data speed transmission.

Installation LDAP authentication instead of /etc/passwd

Future modification IDS and PDS system