Friday, December 21, 2018

Report on the 2018 NSF Cybersecurity Summit

The 2018 NSF Cybersecurity Summit for Large Facilities and Cyberinfrastructure, a platform where communities with interest in supporting NSF science projects collaborate to address core cybersecurity challenges, took place August 21st - August 23rd in Alexandria, VA. One hundred seventeen community individuals, representing fifty-five NSF-funded projects, attended the summit. A summary of the event, as well as a detailed account and the culmination of the community members’ collaborative ideas, were captured in Report of the 2018 NSF Cybersecurity Summit for Cyberinfrastructure and Large Facilities, now available at http://hdl.handle.net/2022/22588.

The summit serves as a valuable means for securing NSF scientific cyberinfrastructure (CI) and increasing trust in the science it supports by providing a forum for education, sharing of experiences, and community building. It presents an excellent opportunity to highlight cybersecurity challenges to NSF program officers, leadership, and stakeholders, along with providing basic cybersecurity awareness and education. The summit also presents an opportunity for Trusted CI to gain insight into the needs, concerns, and challenges facing the community.

In the course of the plenary, attendees at the summit, over half having not attended the summit in 2017, discussed and debated cybersecurity best practices. Within that process, future challenges for the NSF community were identified, including:

  • NSF Large Facilities and cyberinfrastructure members could benefit from stronger trust communities in order to share sensitive security information. This requires re-evaluating how current trust relationships are established, as well as how information is shared between community members.
  • The human factor in security events is still continually overlooked. The community needs to better understand the interaction between humans and security, and to explore the possibility of users taking a larger role in security solutions.
  • Cybersecurity needs positive or proactive metrics, as opposed to presenting negative events and the risks associated with the lack of cybersecurity. Historically, the efficacy of security mechanisms has been presented in terms of attacks thwarted, e.g., the firewall has blocked n malicious packets, rather than in terms of positive productivity, e.g., n users accessed the database without complications. 

Along with the plenary, which consisted of two days of presentations, panels, and keynotes that focused on the security of cyberinfrastructure projects and Large Facilities, a full day of training was held on the first day. The summit’s training day featured focused workshops, including a full day workshop by the WISE (Wise Information Security for collaborating E-infrastructures) Community (https://wise-community.org/).

Based on the received summit evaluations and feedback, the attendees expressed overwhelmingly positive and constructive feedback. Stay tuned for more information regarding future summits.

Thursday, December 20, 2018

What Do Research Computing and Information Security Leaders Have in Common?

In September, Trusted CI and Internet2 co-hosted the “Enabling Trustworthy Campus Cyberinfrastructure for Science” workshop at the University of Maryland. This workshop brought together 37 invited leaders in research computing and information security from 18 institutions to explore challenges that exist between research computing and information security groups.

A blog post on the outcomes of that workshop is now available on the Internet2 blog: https://www.internet2.edu/blogs/detail/16960

Thursday, December 13, 2018

Save the Date:2019 NSF Cybersecurity Summit for Large Facilities and Cyberinfrastructure-Oct 15-17, 2019

Please mark your calendar for the 2019 NSF Cybersecurity Summit for Large Facilities and Cyberinfrastructure, planned for October 15-17, 2019, in San Diego, CA.

Stay tuned for more information by following the Trusted CI Blog (http://blog.trustedci.org/) & Twitter feed:  https://twitter.com/trustedci/

Information on prior summits is available at http://trustedci.org/summit/.


Tuesday, December 11, 2018

CCoE Webinar Series: Looking toward 2019, review of 2018

The 2018 season of the Trusted CI Webinar series has concluded and we are looking forward to the presentations scheduled in the next year.

The following topics and speakers have been booked in 2019:
(Webinars are scheduled the 4th Monday of the month at 11am Eastern time.)
  • January 28th: The Research Security Operations Center (ResearchSOC with Von Welch and RSOC leadership team
  • March 25th: SecureCloud with Casimer DeCusatis
  • April 22nd:  Supporting Controlled Unclassified Information with a Campus Awareness and Risk Management Framework with Justin Yang and colleagues
  • May 27th: Robust and Secure Internet Infrastructure for Scientific Collaboration with Amir Herzberg
  • June 24th: The Trusted CI Framework: An Architecture for Cybersecurity Programs with Trusted CI
  • July 22nd: Campus Infrastructure for Microscale, Privacy-Conscious, Data-Driven Planning with Jason Waterman
  • August 26th: Pegasus and IRIS with Anirban Mandal
  • December 9th: The DDIDD project with John Heidemann and colleagues
We still have openings for the months of February, September, and October.  See our call for presentations for more information.

In case you missed them, here are the webinars from 2018:
  • February: SMARTDATA Blockchain with Murat Kantarcioglu (Video)(Slides
  • March: Data Quality & Security Evaluation Framework Dev. with Leon Reznik & Igor Khokhlov (Video)(Slides)
  • April: Toward Security-Managed Virtual Science Networks with Jeff Chase and Paul Ruth (Video)(Slides)
  • May: General Data Protection Regulation (GDPR) with Scott Russell (Video)(Slides)
  • June: Security Program at LSST with Alex Withers (Video)(Slides
  • July: Trustworthy Computing for Scientific Workflows with Mayank Varia and Andrei Lapets (Video)(Slides)
  • August: NIST 800-171 Compliance Program at University of Connecticut with Jason Pufahl (Video)(Slides)
  • September: SCI Trust Framework with David Kelsey (Video)(Slides)
  • October: Urgent Problems and (Mostly) Open Solutions with Jeff Spies (Video)(Slides)
  • December: December ’18: Best Practices for Academic Cloud Service Providers with Rion Dooley (Video)(Slides)
Join CTSC's announcements mailing list for information about upcoming events. Our complete catalog of webinars and other presentations are available on our YouTube channel.

Wednesday, November 28, 2018

Trusted CI Webinar December 10th at 11am ET: Security Best Practices for Academic Cloud Service Providers with Rion Dooley

Rion Dooley is presenting the talk "Security Best Practices for Academic Cloud Service Providers" on Monday December 10th at 11am (Eastern).

Please register here. Be sure to check spam/junk folder for registration confirmation email.
A “cloud resource” provides a hosted, self-service means for users to run virtual machines or containers such that they can have a custom software stack and isolation from other users. Virtual machines or container images can be curated and provided by the cloud resource operator, provided by the user, or provided by third parties.

Operating a cloud resource involves addressing security requirements of multiple stakeholders: those of the resource operator and those of the resource user.  These parties may have different incentives related to security as well as different levels of acumen. Operators may at times run images whose trustworthiness is not established and grant users privileged access within their running image that would be uncommon on non-virtualized computing resources.  Moreover, users, with their elevated privileges, can misconfigure services, expose sensitive data or choose protocols/solutions that offer less security for the sake of installation or operating costs. These factors can lead to an environment that, by its nature, is difficult to secure.

A community consisting of The Agave Platform, Cornell University Center for Advanced Computing, CyVerse, Jetstream and Trusted CI collaborated in authoring a set of Security Best Practices for developing in, and operating an academic cloud resource.  
In this webinar, we will discuss the nine use cases they deemed most important to academic cloud services.

This webinar will be relevant to cloud users, evangelists, and providers. All are encouraged to join and contribute to the conversation.

The full white paper is available online at http://hdl.handle.net/2022/22123.

Speaker Bio:
Rion Dooley is the Director of Platform Services and Solutions at Data Machines Corp. He has 15 years experience integrating emerging tech with HCP environments to build solutions that make it easier to conduct open, digital science. His prior research includes projects in the areas of cloud computing and security. He serves as PI for the Agave Project, and is active in the Open Source community.

Presentations are recorded and include time for questions with the audience.

Join Trusted CI's announcements mailing list for information about upcoming events. To submit topics or requests to present, see our call for presentations. Archived presentations are available on our site under "Past Events."

Wednesday, October 17, 2018

Trusted CI Extended through 2019, Trusted CI Expansion, ResearchSOC, and Hiring!

Dear Trusted CI community,

I’m writing to share a number of pieces of Trusted CI news, starting with the great news that Trusted CI, through the funding of a supplemental proposal from NSF, has been extended through 2019. This funding is also going to expand Trusted CI’s team and activities in a number of important ways:

  • Dr. Dana Brunson of Oklahoma State is joining Trusted CI to lead a new Fellows Program. This will broaden Trusted CI’s impact to underrepresented groups, NSF Ten Big Ideas, and across NSF directorates.

  • Florence Hudson has joined Trusted CI to lead efforts to foster transitioning cybersecurity research to practice. She has already been in touch with a number of you in identifying cybersecurity gaps in our community that research could fill. If you have ideas in this area, please share them to info@trustedci.org.

  • Dr. Sean Peisert of Lawrence Berkeley National Laboratory will be joining Trusted CI to advance the Open Science Cyber Risk Profile and integrate it with the new Trusted CI Framework.


I shared some additional details on this expansion as well as Trusted CIs accomplishments on a recent NSF OAC webinar.

I’m also excited to announce the funding of the ResearchSOC. Funded as a collaborative security response center under NSF CICI 18-547, ResearchSOC will be led by myself, and my Trusted CI co-PI Jim Marsteller, along with colleagues from Duke, Indiana University, and the University of California San Diego. ResearchSOC and Trusted CI will be closely coordinated in delivering cybersecurity leadership and operational services respectively. For more details on the ResearchSOC, please see my recent presentation at the CICI PI meeting.

I also want to congratulate Trusted CI co-PI Craig Jackson on his new project, PACT, supported by $2m of funding from the Department of Defense to undertake assessments for the DoD community. On a bittersweet note, this means he will be reducing his time on Trusted CI and stepping down as a co-PI. Craig has been instrumental in that role in Trusted CI’s success and I thank him for his contributions and leadership. This project will be piloting assessments soon with an open call, so check out that unique opportunity for an in-depth cybersecurity assessment.

Finally, if Trusted CI or ResearchSOC sounds like something you would enjoy being a part of it, we have multiple positions open at Indiana University to be part of the CACR team and contribute to Trusted CI and our other activities. Please consider applying and sharing with those who may be interested.

Thanks to all the community for their support that makes Trusted CI possible. We look forward to continuing to serve you in meeting the cybersecurity needs of your trusted science.

Von Welch
Director and PI, Trusted CI, the NSF Cybersecurity Center of Excellence
Director, Indiana University Center for Applied Cybersecurity Research

Tuesday, October 9, 2018

Trusted CI Webinar October 22nd at 11am ET: Urgent Problems and (Mostly) Open Solutions with Jeff Spies

Jeffrey Spies is presenting the talk "Urgent Problems and (Mostly) Open Solutions" on Monday October 22nd at 11am (Eastern).

Please register here. Be sure to check spam/junk folder for registration confirmation email.
We're at an important stage in the history of science. The internet has dramatically accelerated the pace and scale of communication and collaboration. We have the computational resources to mine and discover complex relationships within massive datasets from diverse sources. This will usher in a new era of knowledge discovery that will undoubtedly lead to life-saving innovation, and access to content is paramount. But how do we balance transparency and privacy or transparency and IP concerns? How do we protect data from being selectively deleted? How do we decide what to make accessible with limited resources? How do we go from accessible to reusable and then to an ecosystem that fosters inclusivity and diversity?

And what if we no longer own the content we'd like to be made accessible? Such is the case with most journal articles. Skewed incentives have developed around centuries-old publishing practices that reward what is publishable rather than what is rigorous, reproducible, replicable, and reusable. In exchange for publications, we assign our copyrights to publishers, who then lease access back to us and our institutions at ever-increasing prices. And now publishers are turning their eyes--and very large profit margins--towards capturing the rest of the research workflow, including data and analytics. In contrast to the societal-level change that could occur if this research content were in an environment that maximized innovation and reuse, this is very dangerous.

This talk will discuss these urgent problems and the psychology that makes fixing them easier said than done as well as propose a practical, incremental approach to solving them via decentralized technologies, policy, and respect for researcher workflow.

Speaker Bio:
Jeffrey Spies is the founder of 221B LLC, a strategic consulting firm combining expertise in research technology, methodology, and workflow to accelerate projects across higher-ed. Previously, he co-founded and served as the CTO of the Center for Open Science, a non-profit formed to maintain his Open Science Framework. Jeff has a Ph.D. in Quantitative Psychology from the University of Virginia.

Presentations are recorded and include time for questions with the audience.

Join Trusted CI's announcements mailing list for information about upcoming events. To submit topics or requests to present, see our call for presentations. Archived presentations are available on our site under "Past Events."