General design and security risk review for new SSO hub usage collection and analysis
- Using Globus Usage stats for GSISSH Servers to determine the number of logins from the SSO hub was found not to be possible because the server stats don't include client info.
- A suggestion for compiling the number of unique IP addresses for each user to determine potentially compromised accounts was found to be out of scope and also redundant since SSO Hub has other security measures in place for that kind of scenarios.
- A suggestion to determine how many logged in users are sitting idle (and for how long) on the SSOHub was determined to be out of scope.
- A suggestion for a metric on the total number of gsissh connections over the specified period was accepted.
- A suggestion to specify that filtered raw data would be generated on a daily basis and sent to a central repository being designed as part of XCI-187 was accepted and the design doc updated.
Review Input Documents
Please focus on these questions:
- Does the proposed design gather the most useful usage information?
- Are the methods proposed to gather capture usage information appropriate?
- Are the methods proposed to analyze usage appropriate?
- Are relevant XSEDE security policies and best practices followed?
- Is the proposed usage information data access and privacy reasonable?
and the following solution support scenarios:
- XSEDE has recent and historical SSO hub usage information (as a service and as a client to other SSH services)
ScheduleCurrent Date: 2020-06-03
Current Status: Closed (Design and Security Review)
|Target Date||Actual Date||Activity Milestone|
|2017-11-21||Review launch date|
|2017-12-01||2017-12-18||Written feedback due (Reviewers)|
|2017-12-08||2017-12-19||Written response date (Review Material Developers)|
|2017-12-19||Final approval due and completion date (Reviewers)|
Review Last Updated: 2018-02-16 9:33 am
If you are a reviewer, please login to sign or withdraw from this review.
- John-Paul Navarro
SIGNED: 2017-12-18 14:34
- Victor Hazlewood
- Jim Marsteller
- Derek Simmel
SIGNED: 2017-12-01 18:09
- Adam Slagell
- Shava Smallen
SIGNED: 2017-11-29 14:25
Review Material Developers