Monday, August 12, 2024

Trusted CI Webinar: JSON Web Tokens for Science: Hands on Jupyter Notebook tutorial, Monday August 26th @10am Central

SciAuth's Jim Basney and Derek Weitzel are presenting the talk, JSON Web Tokens for Science: Hands on Jupyter Notebook tutorial, on August 26th at 10am, Central time.

Please register here.

NSF cyberinfrastructure is undergoing a security transformation: a migration from X.509 user certificates to IETF-standard JSON Web Tokens (JWTs). This migration has facilitated a re-thinking of authentication and authorization among cyberinfrastructure providers: enabling federated authentication as a core capability, improving support for attribute, role, and capability-based authorization, and reducing reliance on prior identity-based authorization methods that created security and usability problems. In this webinar, members of the SciAuth project (https://sciauth.org/ - NSF award #2114989) will provide a short, hands-on tutorial for cyberinfrastructure professionals to learn about JWTs, including SciTokens (https://scitokens.org/ - NSF award #1738962). Participants will use Jupyter Notebooks to validate the security of JWTs and experiment with JWT-based authentication and authorization. Participants will gain an understanding of JWT basics suitable for understanding their security and troubleshooting any problems with their use.

Speaker Bios: 

Dr. Jim Basney is a principal research scientist in the cybersecurity group at the National Center for Supercomputing Applications at the University of Illinois at Urbana-Champaign. He is the Director and PI of Trusted CI. Jim received his PhD in computer sciences from the University of Wisconsin-Madison.

Dr. Derek Weitzel is a research assistant professor in the School of Computing at the University of Nebraska - Lincoln. He has been providing distributed computing solutions to the national cyberinfrastructures since 2009. He is a member of the OSG’s production operations team and leads the operations of the National Research Platform. His current areas of research involve distributed data management for shared and opportunistic storage, secure credential management, and network monitoring and analytics.

---

Join Trusted CI's announcements mailing list for information about upcoming events. To submit topics or requests to present, see our call for presentations. Archived presentations are available on our site under "Past Events."

Monday, August 5, 2024

Registration is open for the 2024 NSF Cybersecurity Summit!

Registration is open for the 2024 NSF Cybersecurity Summit! Please join us at Carnegie Mellon University in Pittsburgh, PA from October 7-10. If you are unable to join in person, please register to join virtually instead. Attendees will include cybersecurity practitioners, technical leaders, and risk owners from within the NSF Major Facilities and CI community, as well as key stakeholders and thought leaders from the broader scientific and cybersecurity communities. The Summit provides a forum for National Science Foundation (NSF) funded scientists, researchers, cybersecurity, and cyberinfrastructure (CI) professionals, and stakeholders to develop a community and share best practices. The Summit will offer attendees training sessions and workshops with hands-on learning of security tools, security program development, and compliance for research. 

Please register by September 20. 

Thank you on behalf of the Program and Organizing Committees. We look forward to seeing you there!


Cyberinfrastructure Vulnerabilities 2024 Annual Report

Since 2014, Trusted CI (formerly the Center for Trustworthy Scientific Cyberinfrastructure, a.k.a., CTSC) has delivered concise announcements on critical vulnerabilities that affect the software and cyberinfrastructure (CI) of higher education and scientific research communities. The alerting service began informally in 2014 at Indiana University with the creation of two mailing lists specific to software and infrastructure vulnerabilities. In 2016, the process was formalized by the NSF solicitation for the Cybersecurity Center of Excellence (CCoE) which called for "situational awareness of the current cyber threats to the research and education environment, including those that impact scientific instruments." The two mailing lists were merged and a more formalized process of monitoring external information sources for potential threats was established. These information sources included:

The Trusted CI team monitored these sources for vulnerabilities, then determined which ones were of critical interest to the CI community. While there were many cybersecurity issues reported in the news, we strove to alert on issues that affected the CI community in particular. For issues that warranted alerts to the Trusted CI mailing list, we provided guidance on how operators and developers could reduce risks and mitigate threats.

In April of 2024, the Cyberinfrastructure Vulnerabilities alerting service was replaced by the OmniSOC Community Advisory. This semi-monthly newsletter highlights current events and information security news aimed at the research cyberinfrastructure community. We encourage the Trusted CI community to subscribe to the OmniSOC newsletter by sending email to omnisoc-community-advisory-l-subscribe@iu.edu . Additionally, users are encouraged to subscribe to other CVE/vulnerability announcement lists, including:

In the first quarter of 2024, the Cyberinfrastructure Vulnerabilities team discussed 11 vulnerabilities and issued 4 alerts to 188 subscribers. Since 2014, the team has issued nearly 200 alerts to the community. 

The archives of alerts issued since 2017 are available here and here.

Wednesday, July 17, 2024

Trusted CI helps FABRIC build secure scientific infrastructure

Trusted CI has posted a new success story on its collaboration with FABRIC, a national-scale testbed that is providing a new research infrastructure enabling scientists to share massive amounts of data. As FABRIC was being built in 2021, project leaders turned to Trusted CI, the NSF Cybersecurity Center of Excellence, to ensure they designed security into the project from the beginning. FABRIC continues its involvement with Trusted CI as a member of the Research Infrastructure Security Community. The cohort offers an opportunity to share challenges and solutions with others in the same research space. 


Monday, July 15, 2024

Advancing the Cybersecurity of NSF Cyberinfrastructure: Trusted CI Graduates its Fifth Framework Cohort


Trusted CI’s fifth Framework Cohort, “Echo”, successfully completed the six-month program of training and workshop engagement focused on learning and applying the Trusted CI Framework. Cohort members entered the engagement with a commitment to adopting the Framework at their organizations. They then worked closely with Trusted CI to gather site information and create validated self-assessments of their facility’s cybersecurity programs based on the Framework. Each organization also emerged with a draft Cybersecurity Program Strategic Plan (CPSP) identifying priorities and directions for further refining their cybersecurity programs. Echo cohort included the following research cyberinfrastructure providers:

The foundation of the cohort program is the Trusted CI Framework. The Framework was created as a minimum standard for cybersecurity programs. In contrast to cybersecurity guidance focused narrowly on cybersecurity controls, the Trusted CI Framework provides a more holistic and mission-focused standard for managing cybersecurity. For these organizations, the cohort was their first formal training in the Trusted CI Framework “Pillars” and “Musts” and how to apply these fundamental principles to assess their cybersecurity programs.

Feedback on the program from cohort participants has been strongly positive.

Jim Berhalter, Director of IT for the National High Magnetic Field Laboratory at Florida State University, said: “The Trusted CI cohort has been invaluable to our organization and I would highly suggest participating.  While some of it can be daunting, it was a comprehensive way to structure a cybersecurity plan for our organization and made me think about things I would’ve never thought about for our cybersecurity infrastructure.”

Joe Saul, Privacy and Security Officer, Adjunct Research Assistant Professor for ICPSR at University of Michigan, said: “Participating in the Trusted CI cohort was a rare opportunity. You get to learn from others who are facing some of the same challenges you are, and share your own experiences. You get to work with the Trusted CI team, who have talked to a LOT of other groups in similar situations, and hear their read on how you’re doing. Maybe most importantly, they help you take a step back and evaluate your own program and where you’re going. All of this for free. If you get the chance, jump at it. It’s a lot of work, but you aren’t going to get this anywhere else. And certainly not for free.”

Concurrent with leading Echo, Trusted CI continued quarterly engagement with graduates of the four previous Framework cohorts through the Research Infrastructure Security Community (RISC). Trusted CI established RISC as a community of practice to provide a forum for cohort graduates to exchange cybersecurity experience, best practices, challenges, etc., within the NSF research cyberinfrastructure community.

Trusted CI plans to use the second half of 2024 to implement a number of cohort program improvements based on participant feedback and lessons learned during the previous five cohort engagements. The Framework Team plans to implement improvements that enhance cohort participants' experience and increase potential impacts.

For more information, please contact us at info@trustedci.org.

Labels: cybersecurity programs, framework, major facilities


Tuesday, July 9, 2024

Trusted CI Webinar: Automated Building and Deploy Testing — Using Zeek as an example, Monday July 22nd @ 11am Eastern

ESnet's Michael Dopheide is presenting the talk, Automated Building and Deploy Testing — Using Zeek as an example, on July 22nd at 11am Eastern time.

Please register here.

At ESnet, we pride ourselves on being cutting-edge, even if it causes a few scratches. Every new branch of Zeek is automatically built and tested in Gitlab CI. Then, every night, the latest successful 'master' build is deployed, along with all of our packages and scripts, to a test system via Ansible. As time permits, we roll out the latest build, in production, to over 40 servers.
 
Through this process we've both been able to provide early feedback to the Zeek project about potential bugs and give ourselves an early warning system when changes impact our production plugins and scripts.

Zeek is an open source network security monitoring tool.  This does not focus on the use of Zeek itself, but rather the care and feeding of our installation footprint.

Speaker Bio: Michael “Dop” Dopheide has spent the majority of his career working in the R&E community specializing in systems engineering, security research, incident response, and network intrusion detection. He especially enjoys helping coworkers debug problems at the packet and protocol levels. In addition to his operational security role, Dop helps support the open source Zeek community and volunteers every year to beta test the SANS Holiday Hack challenge.

---

Join Trusted CI's announcements mailing list for information about upcoming events. To submit topics or requests to present, see our call for presentations. Archived presentations are available on our site under "Past Events."

Monday, June 10, 2024

Trusted CI Webinar: The Transformative Twelve: Taking a Practical, Evidence-Based Approach to Cybersecurity Controls, Monday June 24th @ 11am Eastern

Indiana University's Craig Jackson is presenting the talk, The Transformative Twelve: Taking a Practical, Evidence-Based Approach to Cybersecurity Controls, on June 24th at 11am Eastern time.

Please register here.

Controls aren’t everything, but they are an important rubber-meets-the-road component of your cybersecurity strategy and program. This webinar will help you will understand the role controls play in a competent cybersecurity program through the lens of the Trusted CI Framework. And, with help cutting through the noise of the many, many controls and control sets in the wild, it will introduce you to the Transformative Twelve, a small, highly prioritized, evidence-based set of cybersecurity controls.

Speaker Bio: Craig Jackson is Deputy Director at the Indiana University Center for Applied Cybersecurity Research, where his R&D interests include evidence-based approaches to security, cybersecurity fundamentals, and cybersecurity program development and governance. He leads collaborative work with critical infrastructure partners. His work includes the Trusted CI Framework, the Information Security Practice Principles, and the Cybertrack and USN’s PACT assessment methodologies. Craig’s education background is in law, education, psychology, and philosophy.

---

Join Trusted CI's announcements mailing list for information about upcoming events. To submit topics or requests to present, see our call for presentations. Archived presentations are available on our site under "Past Events."