Network Security
The GÉANT network made significant advances in the field of network security. During its lifetime, procedures and tools for detecting, preventing and eliminating attempts to disrupt service to the research communities across Europe developed rapidly, to reach the current state-of-the-art implementation on GÉANT.
Alongside GÉANT, TERENA’s Task Force (TF-CSIRT) has also been developing co-operation between Computer Security Incident Response Teams (CSIRTs) from the academic, government and business sectors in Europe. The GÉANT2 network will build on the foundations laid by these technical achievements.
The joint research activity on network security will seek to equip both GÉANT2 and connected NRENs with the capability to take a more proactive approach to security services, and to enable stronger co-operation, in line with the end-to-end philosophy that pervades the project’s work areas. The activity will also continue to collaborate closely with TF-CSIRT, with the creation of dedicated communication channels for regular information exchange.
The Security activity will focus on several key areas:
- Securing the network elements of GÉANT2 and its services, through the design and implementation of recommended security policies for GÉANT2 and its connected NRENs
- Building proactive security services: for example, developing monitoring tools and an events database, producing anomaly detection tools, providing facilities for detecting and mitigating denial of service (DoS) attacks, generating alerts
- Drawing up a proposal for an infrastructure for co-ordinated security handling, and producing a proof-of-concept implementation.
As with all the tools created for research and education networks, the security toolset will be designed in recognition of the unique environment in which the networks operate. Tools and systems need to accommodate the management structure that is produced by separate entities participating in a federated environment. They must also be capable of continuing to operate successfully in the multi-domain environment.
It is imperative that the vision for implementation in the community as a whole (providing a seamless and reliable experience) is maintained. The Security activity anticipates an iterative cycle of deployment and refinement. Key to the success of this approach will be strong involvement from the user community.
