SlideShare a Scribd company logo
1 of 25
Thoughts on Cybersecurity
informed by large international
science & the Open Science Grid
Frank Würthwein
OSG Executive Director
UCSD/SDSC
Let’s reset your perception first
Jensen Huang keynote @ SC19
3
The Largest Cloud Simulation in History
50k NVIDIA GPUs in the Cloud
350 Petaflops for 2 hours
Distributed across US, Europe & Asia
Saturday morning before SC19 we bought all GPU capacity that was for sale in
Amazon Web Services, Microsoft Azure, and Google Cloud Platform worldwide
Science with 51,000 GPUs
achieved as peak performance
4
Time in Minutes
Each color is a different
cloud region in US, EU, or Asia.
Total of 28 Regions in use.
Peaked at 51,500 GPUs
~380 Petaflops of fp32
I can purchase a 300PFLOP32 hour in the cloud for $15k today
and nobody asks me any questions about cybersecurity.
• Nothing about my nationality or visa or …
• Nothing about two-factor authentication or my software
• Everything is wide open on the internet
Should cybersecurity requirements imposed
on open academic research executed at on-
prem resources be adjusted to the realities of
executing the same research on cloud
resources ?
Science is an International Team Sport
Science is a Team Sport
7
The ATLAS Collaboration
8
∼200 institutions across ∼40 countries
Cybersecurity enabling Science
• Humanity has built extraordinary instruments by
pooling human and financial resources globally.
• To derive science from the data and simulations
for those instruments requires globally
integrated Cyberinfrastructure.
• Cybersecurity is enabling this science.
 Policy framework
 Operational security
 Infrastructure software
9
Disk space use per site by CMS
XENON Collaboration as
a “Midscale” Instrument Example
XENON1T Storage & Processing
Challenge
• Experiment in Gran Sasso, Italy
• Tape Archive in Sweden
• Disk storage in 7 locations across Holland, Italy,
Israel, France, USA
 Petabyte of data divided into 20k datasets
• Compute sites on EGI, OSG, and NSF HPC
allocation
11
OSG took on the integration challenge
via ”embedded” technical support.
XENON1T Globally
Integrated Infrastructure
12
NIKHEF
Amsterdam
SURFSara
Amsterdam
Comet
XD Allocation
IN2P3
Lyon
Weizman
Tel Aviv
OSG integrates HPC allocations, contributions from collaborators,
and opportunistic capacity into a single platform to do science on.
Resource Federation
OSG Compute Federation
14
OSG federates
~200 clusters
worldwide
Owners determine
policy of use.
Many allow
opportunistic use
of spare capacity.
> 2 Billion CPU core hours per year
Federation Principle
• Any provider can bring their resources to the
table.
• Truth in advertising:
 Resource providers accurately specify (some)
details about the resource.
• Any consumer can decide which of the
available resources they are willing to use.
15
OSG matches consumers to providers globally
following policies expressed locally.
“NETFLIX” for Open Science
• NETFLIX operates a CDN, providing streaming access to
searchable curated data from anywhere at anytime to any
subscriber.
• For open science, the CDN needs to (in addition) be federated.
 Anybody can share their data from their locally owned data origin into the
CDN.
 Data Access is mediated via caches in the network and at endpoints to
minimize requirements on origins to maximally stimulate sharing.
 Performance of data access is determined by location and performance of
the closest cache rather than the data’s origin.
 Locally defined and managed groups of users share data securely with
each other globally. Data access is global.
16
Locally defined policies are enforced globally by the CDN
The OSG Data Federation
17
Cur r ent st ashcache infr ast r uct ur e (US)
GaTech
We operate a production “prototype” of such a CDN
Two Challenges to think about
Authz: Person vs Capability
• Operations teams are a mix of ”permanent”
staff and transients.
 E.g. CERN pays for ”Operators” funded via
”authorship fees”.
• Delegating a person’s identity to a computing
activity in order to authenticate the activity at a
remote server makes little sense.
• Delegating a capability to a computing activity
in order to authenticate it at a remote server
makes a lot of sense.
19
Division of Responsibility
• To maximize the capacity provided we need
to minimize the effort required to provide it.
• The services required for the CDN and/or
compute federations are specialized and
non-trivial.
 Large learning curve to achieve low cost
operations.
20
Service Operations is most (cost) effective
when separated from hardware operations
Network Cache Ops Model
• OSG supports the researchers
using the Data Federation
• OSG deploys & operates the
caching middleware.
• PRP, TNRP, I2, Regionals, …
responsible for network
performance.
• Hardware owners operate
hardware, OS install, and join
K8S for container orchestration.
21
Science Applications
Data Federation Services
Network Performance
Hardware & OS
A layered approach to distributed DevOps Responsibility
Cybersecurity Issues (I)
• Hardware owners only provide hardware
 Deploy OS and Kubernetes.
• Service Operators (I)
 A team that operates the K8S cluster.
• Service Operators (II)
 A team that deploys and operates the CDN service as
containers inside (and across generally multiple) K8S
clusters.
• Software Operations
 A team that provides the container images
22
How do you design a security model that supports this structure?
Cybersecurity Issues (II)
• Container Security Model
• Security Model that allows hardware owners to give service
responsibility to service operators.
 Diverse requirements
 Some institutions will want to operate their own K8S simply because of the
level of control that implies.
 Others won’t because of the level of effort it requires.
 How do DOE and other National Labs fit into this?
 How can a service provider in the US operate a service on hardware in
EU and Asia? Or vice versa.
 What about India, Pakistan, China, Iran, … pick your favorite country ….
 How to deal with institutions that require US Citizenship even for SUDO
access?
23
The set of issues and diversity of constraints seems endless
And now think back to the beginning: All of this is trivial in the cloud!!!
Summary & Conclusions
24
• Humanity has built extraordinary instruments by
pooling human and financial resources globally.
• To derive science from the data and simulations
for those instruments requires globally
integrated Cyberinfrastructure.
• Cybersecurity is enabling this science.
 Policy framework
 Operational security
 Infrastructure software
Contact us at: help@opensciencegrid.org
Or me personally at: fkw@ucsd.edu
Acknowledgements
• This work was partially supported by the
NSF grants OAC-1941481, MPS-1148698,
OAC-1841530, OAC-1904444, and OAC-
1826967
25

More Related Content

What's hot

At the Crossroads of HPC and Cloud Computing with Openstack
At the Crossroads of HPC and Cloud Computing with OpenstackAt the Crossroads of HPC and Cloud Computing with Openstack
At the Crossroads of HPC and Cloud Computing with OpenstackRyan Aydelott
 
High Performance Cyberinfrastructure Enabling Data-Driven Science in the Biom...
High Performance Cyberinfrastructure Enabling Data-Driven Science in the Biom...High Performance Cyberinfrastructure Enabling Data-Driven Science in the Biom...
High Performance Cyberinfrastructure Enabling Data-Driven Science in the Biom...Larry Smarr
 
HPC Top 5 Stories: January 12, 2018
HPC Top 5 Stories: January 12, 2018HPC Top 5 Stories: January 12, 2018
HPC Top 5 Stories: January 12, 2018NVIDIA
 
Cloud Computing in D-Grid
Cloud Computing in D-GridCloud Computing in D-Grid
Cloud Computing in D-GridStefan Freitag
 
CloudLab Overview
CloudLab OverviewCloudLab Overview
CloudLab OverviewEd Dodds
 
Cloud Standards in the Real World: Cloud Standards Testing for Developers
Cloud Standards in the Real World: Cloud Standards Testing for DevelopersCloud Standards in the Real World: Cloud Standards Testing for Developers
Cloud Standards in the Real World: Cloud Standards Testing for DevelopersAlan Sill
 
Open Science Data Cloud (IEEE Cloud 2011)
Open Science Data Cloud (IEEE Cloud 2011)Open Science Data Cloud (IEEE Cloud 2011)
Open Science Data Cloud (IEEE Cloud 2011)Robert Grossman
 
Bionimbus - Northwestern CGI Workshop 4-21-2011
Bionimbus - Northwestern CGI Workshop 4-21-2011Bionimbus - Northwestern CGI Workshop 4-21-2011
Bionimbus - Northwestern CGI Workshop 4-21-2011Robert Grossman
 
OGF Standards Overview - ITU-T JCA Cloud
OGF Standards Overview - ITU-T JCA CloudOGF Standards Overview - ITU-T JCA Cloud
OGF Standards Overview - ITU-T JCA CloudAlan Sill
 
Open Science Data Cloud - CCA 11
Open Science Data Cloud - CCA 11Open Science Data Cloud - CCA 11
Open Science Data Cloud - CCA 11Robert Grossman
 
OGF Introductory Overview - FAS* 2014
OGF Introductory Overview -  FAS* 2014OGF Introductory Overview -  FAS* 2014
OGF Introductory Overview - FAS* 2014Alan Sill
 
Globus toolkit in grid
Globus toolkit in gridGlobus toolkit in grid
Globus toolkit in gridDeevena Dayaal
 
Grid computing ppt 2003(done)
Grid computing ppt 2003(done)Grid computing ppt 2003(done)
Grid computing ppt 2003(done)TASNEEM88
 
"Implementing the TensorFlow Deep Learning Framework on Qualcomm’s Low-power ...
"Implementing the TensorFlow Deep Learning Framework on Qualcomm’s Low-power ..."Implementing the TensorFlow Deep Learning Framework on Qualcomm’s Low-power ...
"Implementing the TensorFlow Deep Learning Framework on Qualcomm’s Low-power ...Edge AI and Vision Alliance
 
OCCI - The Open Cloud Computing Interface – flexible, portable, interoperable...
OCCI - The Open Cloud Computing Interface – flexible, portable, interoperable...OCCI - The Open Cloud Computing Interface – flexible, portable, interoperable...
OCCI - The Open Cloud Computing Interface – flexible, portable, interoperable...Alan Sill
 
Deep Learning Use Cases using OpenPOWER systems
Deep Learning Use Cases using OpenPOWER systemsDeep Learning Use Cases using OpenPOWER systems
Deep Learning Use Cases using OpenPOWER systemsGanesan Narayanasamy
 

What's hot (20)

Grid
GridGrid
Grid
 
At the Crossroads of HPC and Cloud Computing with Openstack
At the Crossroads of HPC and Cloud Computing with OpenstackAt the Crossroads of HPC and Cloud Computing with Openstack
At the Crossroads of HPC and Cloud Computing with Openstack
 
Grid computing
Grid computingGrid computing
Grid computing
 
High Performance Cyberinfrastructure Enabling Data-Driven Science in the Biom...
High Performance Cyberinfrastructure Enabling Data-Driven Science in the Biom...High Performance Cyberinfrastructure Enabling Data-Driven Science in the Biom...
High Performance Cyberinfrastructure Enabling Data-Driven Science in the Biom...
 
HPC Top 5 Stories: January 12, 2018
HPC Top 5 Stories: January 12, 2018HPC Top 5 Stories: January 12, 2018
HPC Top 5 Stories: January 12, 2018
 
Cloud Computing in D-Grid
Cloud Computing in D-GridCloud Computing in D-Grid
Cloud Computing in D-Grid
 
CloudLab Overview
CloudLab OverviewCloudLab Overview
CloudLab Overview
 
Cloud Standards in the Real World: Cloud Standards Testing for Developers
Cloud Standards in the Real World: Cloud Standards Testing for DevelopersCloud Standards in the Real World: Cloud Standards Testing for Developers
Cloud Standards in the Real World: Cloud Standards Testing for Developers
 
Grid Presentation
Grid PresentationGrid Presentation
Grid Presentation
 
Open Science Data Cloud (IEEE Cloud 2011)
Open Science Data Cloud (IEEE Cloud 2011)Open Science Data Cloud (IEEE Cloud 2011)
Open Science Data Cloud (IEEE Cloud 2011)
 
Bionimbus - Northwestern CGI Workshop 4-21-2011
Bionimbus - Northwestern CGI Workshop 4-21-2011Bionimbus - Northwestern CGI Workshop 4-21-2011
Bionimbus - Northwestern CGI Workshop 4-21-2011
 
OGF Standards Overview - ITU-T JCA Cloud
OGF Standards Overview - ITU-T JCA CloudOGF Standards Overview - ITU-T JCA Cloud
OGF Standards Overview - ITU-T JCA Cloud
 
Open Science Data Cloud - CCA 11
Open Science Data Cloud - CCA 11Open Science Data Cloud - CCA 11
Open Science Data Cloud - CCA 11
 
OGF Introductory Overview - FAS* 2014
OGF Introductory Overview -  FAS* 2014OGF Introductory Overview -  FAS* 2014
OGF Introductory Overview - FAS* 2014
 
Cloud vs grid
Cloud vs gridCloud vs grid
Cloud vs grid
 
Globus toolkit in grid
Globus toolkit in gridGlobus toolkit in grid
Globus toolkit in grid
 
Grid computing ppt 2003(done)
Grid computing ppt 2003(done)Grid computing ppt 2003(done)
Grid computing ppt 2003(done)
 
"Implementing the TensorFlow Deep Learning Framework on Qualcomm’s Low-power ...
"Implementing the TensorFlow Deep Learning Framework on Qualcomm’s Low-power ..."Implementing the TensorFlow Deep Learning Framework on Qualcomm’s Low-power ...
"Implementing the TensorFlow Deep Learning Framework on Qualcomm’s Low-power ...
 
OCCI - The Open Cloud Computing Interface – flexible, portable, interoperable...
OCCI - The Open Cloud Computing Interface – flexible, portable, interoperable...OCCI - The Open Cloud Computing Interface – flexible, portable, interoperable...
OCCI - The Open Cloud Computing Interface – flexible, portable, interoperable...
 
Deep Learning Use Cases using OpenPOWER systems
Deep Learning Use Cases using OpenPOWER systemsDeep Learning Use Cases using OpenPOWER systems
Deep Learning Use Cases using OpenPOWER systems
 

Similar to Thoughts on Cybersecurity

Frank Würthwein - NRP and the Path forward
Frank Würthwein - NRP and the Path forwardFrank Würthwein - NRP and the Path forward
Frank Würthwein - NRP and the Path forwardLarry Smarr
 
Using the Open Science Data Cloud for Data Science Research
Using the Open Science Data Cloud for Data Science ResearchUsing the Open Science Data Cloud for Data Science Research
Using the Open Science Data Cloud for Data Science ResearchRobert Grossman
 
Cloud computing infrastructure
Cloud computing infrastructure Cloud computing infrastructure
Cloud computing infrastructure Dr. Anita Goel
 
Panel: NRP Science Impacts​
Panel: NRP Science Impacts​Panel: NRP Science Impacts​
Panel: NRP Science Impacts​Larry Smarr
 
Webinar: OpenEBS - Still Free and now FASTEST Kubernetes storage
Webinar: OpenEBS - Still Free and now FASTEST Kubernetes storageWebinar: OpenEBS - Still Free and now FASTEST Kubernetes storage
Webinar: OpenEBS - Still Free and now FASTEST Kubernetes storageMayaData Inc
 
Cloud and Grid Computing
Cloud and Grid ComputingCloud and Grid Computing
Cloud and Grid ComputingLeen Blom
 
Cloud and grid computing by Leen Blom, Centric
Cloud and grid computing by Leen Blom, CentricCloud and grid computing by Leen Blom, Centric
Cloud and grid computing by Leen Blom, CentricCentric
 
ZCloud Consensus on Hardware for Distributed Systems
ZCloud Consensus on Hardware for Distributed SystemsZCloud Consensus on Hardware for Distributed Systems
ZCloud Consensus on Hardware for Distributed SystemsGokhan Boranalp
 
Cloud Busting: Understanding Cloud-based Digital Forensics
Cloud Busting: Understanding Cloud-based Digital ForensicsCloud Busting: Understanding Cloud-based Digital Forensics
Cloud Busting: Understanding Cloud-based Digital ForensicsKerry Hazelton
 
e-Infrastructure available for research, using the right tool for the right job
e-Infrastructure available for research, using the right tool for the right jobe-Infrastructure available for research, using the right tool for the right job
e-Infrastructure available for research, using the right tool for the right jobDavid Wallom
 
Data-intensive bioinformatics on HPC and Cloud
Data-intensive bioinformatics on HPC and CloudData-intensive bioinformatics on HPC and Cloud
Data-intensive bioinformatics on HPC and CloudOla Spjuth
 
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...Larry Smarr
 
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...Larry Smarr
 
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...Larry Smarr
 
Raspberry pi x kubernetes x tensorflow
Raspberry pi x kubernetes x tensorflowRaspberry pi x kubernetes x tensorflow
Raspberry pi x kubernetes x tensorflow霈萱 蔡
 
WF-IOT-2014, Seoul, Korea, 06 March 2014
WF-IOT-2014, Seoul, Korea, 06 March 2014WF-IOT-2014, Seoul, Korea, 06 March 2014
WF-IOT-2014, Seoul, Korea, 06 March 2014Charith Perera
 

Similar to Thoughts on Cybersecurity (20)

Frank Würthwein - NRP and the Path forward
Frank Würthwein - NRP and the Path forwardFrank Würthwein - NRP and the Path forward
Frank Würthwein - NRP and the Path forward
 
GRID COMPUTING.ppt
GRID COMPUTING.pptGRID COMPUTING.ppt
GRID COMPUTING.ppt
 
Using the Open Science Data Cloud for Data Science Research
Using the Open Science Data Cloud for Data Science ResearchUsing the Open Science Data Cloud for Data Science Research
Using the Open Science Data Cloud for Data Science Research
 
Cloud computing infrastructure
Cloud computing infrastructure Cloud computing infrastructure
Cloud computing infrastructure
 
Grid computing
Grid computingGrid computing
Grid computing
 
Panel: NRP Science Impacts​
Panel: NRP Science Impacts​Panel: NRP Science Impacts​
Panel: NRP Science Impacts​
 
Webinar: OpenEBS - Still Free and now FASTEST Kubernetes storage
Webinar: OpenEBS - Still Free and now FASTEST Kubernetes storageWebinar: OpenEBS - Still Free and now FASTEST Kubernetes storage
Webinar: OpenEBS - Still Free and now FASTEST Kubernetes storage
 
Cloud and Grid Computing
Cloud and Grid ComputingCloud and Grid Computing
Cloud and Grid Computing
 
Cloud and grid computing by Leen Blom, Centric
Cloud and grid computing by Leen Blom, CentricCloud and grid computing by Leen Blom, Centric
Cloud and grid computing by Leen Blom, Centric
 
ZCloud Consensus on Hardware for Distributed Systems
ZCloud Consensus on Hardware for Distributed SystemsZCloud Consensus on Hardware for Distributed Systems
ZCloud Consensus on Hardware for Distributed Systems
 
Grid computing
Grid computingGrid computing
Grid computing
 
Cloud Busting: Understanding Cloud-based Digital Forensics
Cloud Busting: Understanding Cloud-based Digital ForensicsCloud Busting: Understanding Cloud-based Digital Forensics
Cloud Busting: Understanding Cloud-based Digital Forensics
 
e-Infrastructure available for research, using the right tool for the right job
e-Infrastructure available for research, using the right tool for the right jobe-Infrastructure available for research, using the right tool for the right job
e-Infrastructure available for research, using the right tool for the right job
 
Grid Computing
Grid ComputingGrid Computing
Grid Computing
 
Data-intensive bioinformatics on HPC and Cloud
Data-intensive bioinformatics on HPC and CloudData-intensive bioinformatics on HPC and Cloud
Data-intensive bioinformatics on HPC and Cloud
 
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
 
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
 
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
Panel: Open Infrastructure for an Open Society: OSG, Commercial Clouds, and B...
 
Raspberry pi x kubernetes x tensorflow
Raspberry pi x kubernetes x tensorflowRaspberry pi x kubernetes x tensorflow
Raspberry pi x kubernetes x tensorflow
 
WF-IOT-2014, Seoul, Korea, 06 March 2014
WF-IOT-2014, Seoul, Korea, 06 March 2014WF-IOT-2014, Seoul, Korea, 06 March 2014
WF-IOT-2014, Seoul, Korea, 06 March 2014
 

Recently uploaded

TEST BANK For Radiologic Science for Technologists, 12th Edition by Stewart C...
TEST BANK For Radiologic Science for Technologists, 12th Edition by Stewart C...TEST BANK For Radiologic Science for Technologists, 12th Edition by Stewart C...
TEST BANK For Radiologic Science for Technologists, 12th Edition by Stewart C...ssifa0344
 
Orientation, design and principles of polyhouse
Orientation, design and principles of polyhouseOrientation, design and principles of polyhouse
Orientation, design and principles of polyhousejana861314
 
Presentation Vikram Lander by Vedansh Gupta.pptx
Presentation Vikram Lander by Vedansh Gupta.pptxPresentation Vikram Lander by Vedansh Gupta.pptx
Presentation Vikram Lander by Vedansh Gupta.pptxgindu3009
 
GBSN - Microbiology (Unit 1)
GBSN - Microbiology (Unit 1)GBSN - Microbiology (Unit 1)
GBSN - Microbiology (Unit 1)Areesha Ahmad
 
Animal Communication- Auditory and Visual.pptx
Animal Communication- Auditory and Visual.pptxAnimal Communication- Auditory and Visual.pptx
Animal Communication- Auditory and Visual.pptxUmerFayaz5
 
Botany 4th semester file By Sumit Kumar yadav.pdf
Botany 4th semester file By Sumit Kumar yadav.pdfBotany 4th semester file By Sumit Kumar yadav.pdf
Botany 4th semester file By Sumit Kumar yadav.pdfSumit Kumar yadav
 
Nanoparticles synthesis and characterization​ ​
Nanoparticles synthesis and characterization​  ​Nanoparticles synthesis and characterization​  ​
Nanoparticles synthesis and characterization​ ​kaibalyasahoo82800
 
Unlocking the Potential: Deep dive into ocean of Ceramic Magnets.pptx
Unlocking  the Potential: Deep dive into ocean of Ceramic Magnets.pptxUnlocking  the Potential: Deep dive into ocean of Ceramic Magnets.pptx
Unlocking the Potential: Deep dive into ocean of Ceramic Magnets.pptxanandsmhk
 
Chemistry 4th semester series (krishna).pdf
Chemistry 4th semester series (krishna).pdfChemistry 4th semester series (krishna).pdf
Chemistry 4th semester series (krishna).pdfSumit Kumar yadav
 
Green chemistry and Sustainable development.pptx
Green chemistry  and Sustainable development.pptxGreen chemistry  and Sustainable development.pptx
Green chemistry and Sustainable development.pptxRajatChauhan518211
 
Discovery of an Accretion Streamer and a Slow Wide-angle Outflow around FUOri...
Discovery of an Accretion Streamer and a Slow Wide-angle Outflow around FUOri...Discovery of an Accretion Streamer and a Slow Wide-angle Outflow around FUOri...
Discovery of an Accretion Streamer and a Slow Wide-angle Outflow around FUOri...Sérgio Sacani
 
SOLUBLE PATTERN RECOGNITION RECEPTORS.pptx
SOLUBLE PATTERN RECOGNITION RECEPTORS.pptxSOLUBLE PATTERN RECOGNITION RECEPTORS.pptx
SOLUBLE PATTERN RECOGNITION RECEPTORS.pptxkessiyaTpeter
 
Hire 💕 9907093804 Hooghly Call Girls Service Call Girls Agency
Hire 💕 9907093804 Hooghly Call Girls Service Call Girls AgencyHire 💕 9907093804 Hooghly Call Girls Service Call Girls Agency
Hire 💕 9907093804 Hooghly Call Girls Service Call Girls AgencySheetal Arora
 
PossibleEoarcheanRecordsoftheGeomagneticFieldPreservedintheIsuaSupracrustalBe...
PossibleEoarcheanRecordsoftheGeomagneticFieldPreservedintheIsuaSupracrustalBe...PossibleEoarcheanRecordsoftheGeomagneticFieldPreservedintheIsuaSupracrustalBe...
PossibleEoarcheanRecordsoftheGeomagneticFieldPreservedintheIsuaSupracrustalBe...Sérgio Sacani
 
GBSN - Biochemistry (Unit 1)
GBSN - Biochemistry (Unit 1)GBSN - Biochemistry (Unit 1)
GBSN - Biochemistry (Unit 1)Areesha Ahmad
 
Pests of cotton_Sucking_Pests_Dr.UPR.pdf
Pests of cotton_Sucking_Pests_Dr.UPR.pdfPests of cotton_Sucking_Pests_Dr.UPR.pdf
Pests of cotton_Sucking_Pests_Dr.UPR.pdfPirithiRaju
 
Botany 4th semester series (krishna).pdf
Botany 4th semester series (krishna).pdfBotany 4th semester series (krishna).pdf
Botany 4th semester series (krishna).pdfSumit Kumar yadav
 
GBSN - Microbiology (Unit 2)
GBSN - Microbiology (Unit 2)GBSN - Microbiology (Unit 2)
GBSN - Microbiology (Unit 2)Areesha Ahmad
 
All-domain Anomaly Resolution Office U.S. Department of Defense (U) Case: “Eg...
All-domain Anomaly Resolution Office U.S. Department of Defense (U) Case: “Eg...All-domain Anomaly Resolution Office U.S. Department of Defense (U) Case: “Eg...
All-domain Anomaly Resolution Office U.S. Department of Defense (U) Case: “Eg...Sérgio Sacani
 

Recently uploaded (20)

TEST BANK For Radiologic Science for Technologists, 12th Edition by Stewart C...
TEST BANK For Radiologic Science for Technologists, 12th Edition by Stewart C...TEST BANK For Radiologic Science for Technologists, 12th Edition by Stewart C...
TEST BANK For Radiologic Science for Technologists, 12th Edition by Stewart C...
 
The Philosophy of Science
The Philosophy of ScienceThe Philosophy of Science
The Philosophy of Science
 
Orientation, design and principles of polyhouse
Orientation, design and principles of polyhouseOrientation, design and principles of polyhouse
Orientation, design and principles of polyhouse
 
Presentation Vikram Lander by Vedansh Gupta.pptx
Presentation Vikram Lander by Vedansh Gupta.pptxPresentation Vikram Lander by Vedansh Gupta.pptx
Presentation Vikram Lander by Vedansh Gupta.pptx
 
GBSN - Microbiology (Unit 1)
GBSN - Microbiology (Unit 1)GBSN - Microbiology (Unit 1)
GBSN - Microbiology (Unit 1)
 
Animal Communication- Auditory and Visual.pptx
Animal Communication- Auditory and Visual.pptxAnimal Communication- Auditory and Visual.pptx
Animal Communication- Auditory and Visual.pptx
 
Botany 4th semester file By Sumit Kumar yadav.pdf
Botany 4th semester file By Sumit Kumar yadav.pdfBotany 4th semester file By Sumit Kumar yadav.pdf
Botany 4th semester file By Sumit Kumar yadav.pdf
 
Nanoparticles synthesis and characterization​ ​
Nanoparticles synthesis and characterization​  ​Nanoparticles synthesis and characterization​  ​
Nanoparticles synthesis and characterization​ ​
 
Unlocking the Potential: Deep dive into ocean of Ceramic Magnets.pptx
Unlocking  the Potential: Deep dive into ocean of Ceramic Magnets.pptxUnlocking  the Potential: Deep dive into ocean of Ceramic Magnets.pptx
Unlocking the Potential: Deep dive into ocean of Ceramic Magnets.pptx
 
Chemistry 4th semester series (krishna).pdf
Chemistry 4th semester series (krishna).pdfChemistry 4th semester series (krishna).pdf
Chemistry 4th semester series (krishna).pdf
 
Green chemistry and Sustainable development.pptx
Green chemistry  and Sustainable development.pptxGreen chemistry  and Sustainable development.pptx
Green chemistry and Sustainable development.pptx
 
Discovery of an Accretion Streamer and a Slow Wide-angle Outflow around FUOri...
Discovery of an Accretion Streamer and a Slow Wide-angle Outflow around FUOri...Discovery of an Accretion Streamer and a Slow Wide-angle Outflow around FUOri...
Discovery of an Accretion Streamer and a Slow Wide-angle Outflow around FUOri...
 
SOLUBLE PATTERN RECOGNITION RECEPTORS.pptx
SOLUBLE PATTERN RECOGNITION RECEPTORS.pptxSOLUBLE PATTERN RECOGNITION RECEPTORS.pptx
SOLUBLE PATTERN RECOGNITION RECEPTORS.pptx
 
Hire 💕 9907093804 Hooghly Call Girls Service Call Girls Agency
Hire 💕 9907093804 Hooghly Call Girls Service Call Girls AgencyHire 💕 9907093804 Hooghly Call Girls Service Call Girls Agency
Hire 💕 9907093804 Hooghly Call Girls Service Call Girls Agency
 
PossibleEoarcheanRecordsoftheGeomagneticFieldPreservedintheIsuaSupracrustalBe...
PossibleEoarcheanRecordsoftheGeomagneticFieldPreservedintheIsuaSupracrustalBe...PossibleEoarcheanRecordsoftheGeomagneticFieldPreservedintheIsuaSupracrustalBe...
PossibleEoarcheanRecordsoftheGeomagneticFieldPreservedintheIsuaSupracrustalBe...
 
GBSN - Biochemistry (Unit 1)
GBSN - Biochemistry (Unit 1)GBSN - Biochemistry (Unit 1)
GBSN - Biochemistry (Unit 1)
 
Pests of cotton_Sucking_Pests_Dr.UPR.pdf
Pests of cotton_Sucking_Pests_Dr.UPR.pdfPests of cotton_Sucking_Pests_Dr.UPR.pdf
Pests of cotton_Sucking_Pests_Dr.UPR.pdf
 
Botany 4th semester series (krishna).pdf
Botany 4th semester series (krishna).pdfBotany 4th semester series (krishna).pdf
Botany 4th semester series (krishna).pdf
 
GBSN - Microbiology (Unit 2)
GBSN - Microbiology (Unit 2)GBSN - Microbiology (Unit 2)
GBSN - Microbiology (Unit 2)
 
All-domain Anomaly Resolution Office U.S. Department of Defense (U) Case: “Eg...
All-domain Anomaly Resolution Office U.S. Department of Defense (U) Case: “Eg...All-domain Anomaly Resolution Office U.S. Department of Defense (U) Case: “Eg...
All-domain Anomaly Resolution Office U.S. Department of Defense (U) Case: “Eg...
 

Thoughts on Cybersecurity

  • 1. Thoughts on Cybersecurity informed by large international science & the Open Science Grid Frank Würthwein OSG Executive Director UCSD/SDSC
  • 2. Let’s reset your perception first
  • 3. Jensen Huang keynote @ SC19 3 The Largest Cloud Simulation in History 50k NVIDIA GPUs in the Cloud 350 Petaflops for 2 hours Distributed across US, Europe & Asia Saturday morning before SC19 we bought all GPU capacity that was for sale in Amazon Web Services, Microsoft Azure, and Google Cloud Platform worldwide
  • 4. Science with 51,000 GPUs achieved as peak performance 4 Time in Minutes Each color is a different cloud region in US, EU, or Asia. Total of 28 Regions in use. Peaked at 51,500 GPUs ~380 Petaflops of fp32 I can purchase a 300PFLOP32 hour in the cloud for $15k today and nobody asks me any questions about cybersecurity. • Nothing about my nationality or visa or … • Nothing about two-factor authentication or my software • Everything is wide open on the internet
  • 5. Should cybersecurity requirements imposed on open academic research executed at on- prem resources be adjusted to the realities of executing the same research on cloud resources ?
  • 6. Science is an International Team Sport
  • 7. Science is a Team Sport 7
  • 8. The ATLAS Collaboration 8 ∼200 institutions across ∼40 countries
  • 9. Cybersecurity enabling Science • Humanity has built extraordinary instruments by pooling human and financial resources globally. • To derive science from the data and simulations for those instruments requires globally integrated Cyberinfrastructure. • Cybersecurity is enabling this science.  Policy framework  Operational security  Infrastructure software 9 Disk space use per site by CMS
  • 10. XENON Collaboration as a “Midscale” Instrument Example
  • 11. XENON1T Storage & Processing Challenge • Experiment in Gran Sasso, Italy • Tape Archive in Sweden • Disk storage in 7 locations across Holland, Italy, Israel, France, USA  Petabyte of data divided into 20k datasets • Compute sites on EGI, OSG, and NSF HPC allocation 11 OSG took on the integration challenge via ”embedded” technical support.
  • 12. XENON1T Globally Integrated Infrastructure 12 NIKHEF Amsterdam SURFSara Amsterdam Comet XD Allocation IN2P3 Lyon Weizman Tel Aviv OSG integrates HPC allocations, contributions from collaborators, and opportunistic capacity into a single platform to do science on.
  • 14. OSG Compute Federation 14 OSG federates ~200 clusters worldwide Owners determine policy of use. Many allow opportunistic use of spare capacity. > 2 Billion CPU core hours per year
  • 15. Federation Principle • Any provider can bring their resources to the table. • Truth in advertising:  Resource providers accurately specify (some) details about the resource. • Any consumer can decide which of the available resources they are willing to use. 15 OSG matches consumers to providers globally following policies expressed locally.
  • 16. “NETFLIX” for Open Science • NETFLIX operates a CDN, providing streaming access to searchable curated data from anywhere at anytime to any subscriber. • For open science, the CDN needs to (in addition) be federated.  Anybody can share their data from their locally owned data origin into the CDN.  Data Access is mediated via caches in the network and at endpoints to minimize requirements on origins to maximally stimulate sharing.  Performance of data access is determined by location and performance of the closest cache rather than the data’s origin.  Locally defined and managed groups of users share data securely with each other globally. Data access is global. 16 Locally defined policies are enforced globally by the CDN
  • 17. The OSG Data Federation 17 Cur r ent st ashcache infr ast r uct ur e (US) GaTech We operate a production “prototype” of such a CDN
  • 18. Two Challenges to think about
  • 19. Authz: Person vs Capability • Operations teams are a mix of ”permanent” staff and transients.  E.g. CERN pays for ”Operators” funded via ”authorship fees”. • Delegating a person’s identity to a computing activity in order to authenticate the activity at a remote server makes little sense. • Delegating a capability to a computing activity in order to authenticate it at a remote server makes a lot of sense. 19
  • 20. Division of Responsibility • To maximize the capacity provided we need to minimize the effort required to provide it. • The services required for the CDN and/or compute federations are specialized and non-trivial.  Large learning curve to achieve low cost operations. 20 Service Operations is most (cost) effective when separated from hardware operations
  • 21. Network Cache Ops Model • OSG supports the researchers using the Data Federation • OSG deploys & operates the caching middleware. • PRP, TNRP, I2, Regionals, … responsible for network performance. • Hardware owners operate hardware, OS install, and join K8S for container orchestration. 21 Science Applications Data Federation Services Network Performance Hardware & OS A layered approach to distributed DevOps Responsibility
  • 22. Cybersecurity Issues (I) • Hardware owners only provide hardware  Deploy OS and Kubernetes. • Service Operators (I)  A team that operates the K8S cluster. • Service Operators (II)  A team that deploys and operates the CDN service as containers inside (and across generally multiple) K8S clusters. • Software Operations  A team that provides the container images 22 How do you design a security model that supports this structure?
  • 23. Cybersecurity Issues (II) • Container Security Model • Security Model that allows hardware owners to give service responsibility to service operators.  Diverse requirements  Some institutions will want to operate their own K8S simply because of the level of control that implies.  Others won’t because of the level of effort it requires.  How do DOE and other National Labs fit into this?  How can a service provider in the US operate a service on hardware in EU and Asia? Or vice versa.  What about India, Pakistan, China, Iran, … pick your favorite country ….  How to deal with institutions that require US Citizenship even for SUDO access? 23 The set of issues and diversity of constraints seems endless And now think back to the beginning: All of this is trivial in the cloud!!!
  • 24. Summary & Conclusions 24 • Humanity has built extraordinary instruments by pooling human and financial resources globally. • To derive science from the data and simulations for those instruments requires globally integrated Cyberinfrastructure. • Cybersecurity is enabling this science.  Policy framework  Operational security  Infrastructure software Contact us at: help@opensciencegrid.org Or me personally at: fkw@ucsd.edu
  • 25. Acknowledgements • This work was partially supported by the NSF grants OAC-1941481, MPS-1148698, OAC-1841530, OAC-1904444, and OAC- 1826967 25