SEcure Clud cmputing fr CRitical Infrastructure IT Methds and Technlgies fr Secure Clud Cmputing fr Critical InfrastructureIT Dr Markus Tauber SECCRIT Crdinatr AIT Austrian Institute f Technlgy AIT Austrian Institute f Technlgy ETRA Investigación y Desarrll Fraunhfer Institute fr Experimental Sftware Engineering IESE Karlsruhe Institute f Technlgy NEC Eurpe Lancaster University Mirasys Hellenic Telecmmunicatins Organizatin OTE Ayuntamient de Valencia Amaris
Why we are here SECCRIT Intrductin Technical & Legal Mtivatins Applicatin f Research Outputs Increase the real-wrld implicatins via yu 14.01.2015 SECCRIT Cnsrtium 2
The SECCRIT Prject Research prject n secure Clud Cmputing fr critical infrastructure IT 10 Partners frm Austria, Finland, Germany, Greece, Spain and the UK. Prject budget 4.8 Mi, partly funded by EC FP7 Prgramme Prject duratin 1.1.2013 31.12.2015 60% f the prject cmpleted 25 public deliverables 14.01.2015 SECCRIT Cnsrtium 3
SECCRIT s Overall Gal analyse and evaluate clud cmputing with respect t security risks in sensitive envirnments i.e. critical infrastructures t develp Traffic Cntrl Public Safety (CCTV) methdlgies technlgies, best practices fr secure, trustwrthy, high assurance legal cmpliant clud cmputing envirnments fr critical infrastructure IT. Investigate real-wrld prblems 14.01.2015 SECCRIT Cnsrtium 5
Prblem Definitin High Level Everything ges clud Cnsumer data like ur emails r phts (ggle mail and ther ggle services) Public administratin IT services Sn all kinds f applicatins (incl. Critical Infrastructure - CI) Requirements fr clud applicatins vary Cmmercial applicatins mainly fcus n scalability & elasticity Requirements in CI regarding: verall redundancy, data availability, authenticity, secure access, trust and prtectin f the citizens are typically higher than in cmmercial applicatins. Cmmn Users Requirements cnverge with what is CI standard What is the prblem? Clud services abstract ver used resurces, are paque and make it hard t determine technical reasns fr (security) failure and hence make the develpment f cuntermeasures This als implies, frm a legal perspective, that it is hard t determine wh s fault it is and t shw ne hasn t acted negligent 14.01.2015 SECCRIT Cnsrtium 6
Key Objectives Legal Guidance n Data Prtectin and Evidence Understand and manage risk assciated with clud envirnments Understand clud behavir in the face f challenges Establish best practices fr secure clud service implementatins Demnstratin f utput in real-wrld applicatin scenaris 14.01.2015 SECCRIT Cnsrtium 9
Key Objectives Activities & Output Legal Guidance n Data Prtectin and Evidence Understand and manage risk assciated with clud envirnments Understand clud behavir in the face f challenges Establish best practices fr secure clud service implementatins Demnstratin f utput in real-wrld applicatin scenaris Definitin f legal guidance n SLA cmpliance, prvisin f evidence, and data prtectin fr clud services Risk Assessment and Management Methdlgy Plicy Specificatin Methdlgy and Tl Clud Assurance Prfile and Evaluatin Methd Anmaly Detectin Techniques and Tls Plicy Decisin and Enfrcement Tls Clud Resilience Management Framewrk Tls fr Audit Trails and Rt Cause Analysis Mdel Driven Clud Security Guidelines Orchestratin Secure Clud Strage Dem 1: Strage and Prcessing f Sensitive Data Dem 2: Hsting Critical Urban Mbility Services 14.01.2015 SECCRIT Cnsrtium 10
Key Objectives Activities & Output Legal Guidance n Data Prtectin and Evidence Understand and manage risk assciated with clud envirnments Understand clud behavir in the face f challenges Establish best practices fr secure clud service implementatins Demnstratin f utput in real-wrld applicatin scenaris Definitin f legal guidance n SLA cmpliance, prvisin f evidence, and data prtectin fr clud services Risk Assessment and Management Methdlgy Plicy Specificatin Methdlgy and Tl Clud Assurance Prfile and Evaluatin Methd Anmaly Detectin Techniques and Tls Plicy Decisin and Enfrcement Tls Clud Resilience Management Framewrk Tls fr Audit Trails and Rt Cause Analysis Mdel Driven Clud Security Guidelines Orchestratin Secure Clud Strage Dem 1: Strage and Prcessing f Sensitive Data Dem 2: Hsting Critical Urban Mbility Services Please nte, Clrs describe clustered SECCRIT Research Output 14.01.2015 SECCRIT Cnsrtium 11
SECCRIT Outputs 14.01.2015 SECCRIT Cnsrtium 13
Cmmn Terminlgy - SECCRIT Architecture R. Bless, Flittner, M., Hrneber, J., Hutchisn, D., Jung, C., Pallas, F., Schöller, M., Shirazi, S. Nr ul Ha, Simpsn, S., and Smith, P., Whitepaper "AF 1.0" SECCRIT Architectural Framewrk. 2014. (and IEEE CludCm) 14.01.2015 SECCRIT Cnsrtium 14
SECCRIT Demnstratr: Public Safety (CCTV) MetrSub CitySec TelCm TenSys CludCrp The Subway Operatr The Security Service Prvider The Telecm Operatr The Tenant System Mgmt The Clud Mgmt Prvider 14.01.2015 SECCRIT Cnsrtium 15
SECCRIT Demnstratr: Traffic Cntrl Gather traffic data frm traffic sensrs n the rad OPERATOR Stre traffic data in data bases Generate data and reprts abut traffic status and traffic evlutin Analyse and relate the whle f mbility data Supprt t define mbility plices and traffic cntrl strategies Cntrl traffic n the rad by Traffic Cntrllers, Traffic Ligths, Variable Messages Signals, etc. Incidents Surveillance VIDEO SURVEILLANCE AUTOMATIC INCIDENTS DETECTION Actins Actins Incidents PUBLIC INFORMATION CONTROL SCHEDULED ACTIONS Actins Actins EXPERT SYSTEM Incidents Actins TRAFFIC CONTROL SDCTU STRATEGIC CONTROL Public transprtatin pririty by strategies like ffering traffic lights pririty Execute traffic cntrl strategies by peratrs manual actins r by autmatic prcedures. 14.01.2015 SECCRIT Cnsrtium 16
Bard Members, wh supprt SECCRIT Mre.. 14.01.2015 SECCRIT Cnsrtium 17
SEcure Clud cmputing fr CRitical Infrastructure IT Cntact Dr. Markus Tauber M +43 (0) 664 8251011 markus.tauber@ait.ac.at Austrian Institute f Technlgy (AIT) www.ait.ac.at/ict-security www.seccrit.eu AIT Austrian Institute f Technlgy ETRA Investigación y Desarrll Fraunhfer Institute fr Experimental Sftware Engineering IESE Karlsruhe Institute f Technlgy NEC Eurpe Lancaster University Mirasys Hellenic Telecmmunicatins Organizatin OTE Ayuntamient de Valencia Amaris