[Fiware-secure-cloud] [FIWARE] - Task force security monitoring- Questions about security risk analysis

BISSON Pascal pascal.bisson at thalesgroup.com
Tue Nov 26 12:00:29 CET 2013


This email to inform you that our audio conf of tomorrow will start at 10:45 am instead of 10am.

Apologize for the inconvenience

Regards,
Pascal

De : BISSON Pascal
Envoyé : vendredi 22 novembre 2013 14:33
À : FERNANDO LOPEZ AGUILAR
Cc : JUAN JOSE HIERRO SUREDA; CAO Phong; MUSARAJ Kreshnik; JOSE IGNACIO CARRETERO GUARDE; GIDOIN Daniel; fiware-secure-cloud at lists.fi-ware.eu; BISSON Pascal; pascal.bisson at noos.fr
Objet : RE: [FIWARE] - Task force security monitoring- Questions about security risk analysis
Importance : Haute

Dear Fernando,

Ok so let's have our follow-audio conf of this Sec-Cloud Chapter on Wednesday 27/11 from 10am till 11am.

Here are the details for you and colleagues to join:


Meeting room number: 391581



LocalConnect numbers:

Belgium   Brussels   +32 (0) 2 789 8678

Denmark   Copenhagen   +45 3271 4340

Finland   Helsinki   +358 (0) 923 142 830

France   Lyon   +33 (0) 426 840 285

France   Marseille   +33 (0) 488 915 385

France   Paris   +33 (0) 170 994 816

Germany   Berlin   +49 (0) 3072 616 7342

Germany   Düsseldorf   +49 (0) 2115 407 3902

Germany   Frankfurt   +49 (0) 6971 044 5635

Germany   Hamburg   +49 (0) 4080 902 0684

Germany   Munich   +49 (0) 8924 443 2893

Germany   Stuttgart   +49 (0) 7111 856 2130

Greece   Greece Toll Free   0080 012 6344

Ireland   Dublin   +353 (0) 14 860 780

Israel   Israel Toll Free   1809 245 981

Italy   Milan   +39 0 230 413 017

Italy   Rome   +39 0 645 217 056

Italy   Turin   +39 0 112 179 2159

Netherlands   Amsterdam   +31 (0) 207 948 529

Norway   Oslo   +47 2153 3919

Poland   Poland Toll Free   0080 0121 1304

Portugal   Portugal Toll Free   800 814 183

Spain   Barcelona   +34 93 492 3235

Spain   Madrid   +34 91 788 9908

Sweden   Stockholm   +46 (0) 850 520 145

Switzerland   Geneva   +41 (0) 225 927 428

United Kingdom   Birmingham   +44 (0) 121 260 4686

United Kingdom   London   +44 (0) 207 153 9902

United Kingdom   Manchester   +44 (0) 161 250 0679

United States   USA & Canada Toll Free   1888 249 0050

United States   USA Toll   +1 954 334 1559





Regards,

Pascal


De : FERNANDO LOPEZ AGUILAR [mailto:fla at tid.es]
Envoyé : jeudi 21 novembre 2013 08:08
À : BISSON Pascal
Cc : JUAN JOSE HIERRO SUREDA; CAO Phong; MUSARAJ Kreshnik; JOSE IGNACIO CARRETERO GUARDE; GIDOIN Daniel; fiware-secure-cloud at lists.fi-ware.eu<mailto:fiware-secure-cloud at lists.fi-ware.eu>
Objet : Re: [FIWARE] - Task force security monitoring- Questions about security risk analysis
Importance : Haute

Dear Pascal,

I have no inconvenience in both, if you do not have any preference. I would like to have it on Wednesday from 10 to 11.

Best regards,

Fernando López Aguilar
Cloud Computing
fla at tid dot es
+34 914 832 729
Telefónica I+D (R&D)
Ronda de la Comunicación s/n
Distrito C, Edificio Oeste 1, Planta 9
28043 Madrid, Spain







Follow FI-WARE on the net



        Website:  http://www.fi-ware.eu<http://www.fi-ware.eu/>

        Facebook: http://www.facebook.com/pages/FI-WARE/251366491587242

        Twitter:  http://twitter.com/Fiware

        LinkedIn: http://www.linkedin.com/groups/FIWARE-4239932




El 20/11/2013, a las 18:01, BISSON Pascal <pascal.bisson at thalesgroup.com<mailto:pascal.bisson at thalesgroup.com>> escribió:

Dear Fernando,

Many thanks for the you performed and input you provided to us.

Yesterday we had an internal meeting with Phong and Daniel where we reviewed the analysis performed of your data.

In order to discuss with you this analysis also to discuss the next steps (including additional information we may need from you) I would like to go for an audio conference with you and other members of this Security-Cloud Tzsk force on SecMon GE.

Would it be feasible for you to have this audio conf next Tuesday (26/11) from 10am till 11am or alternatively 27/11 (same time slot 10am-11am).

Hearing from you

Best Regards,
Pascal

PS: @Alex I remember Juanjo made a reference  two attack scenarios that had been identified during the Cloud WP F2F meeting in Haifa. Could you please share those scenarios with us to get them also considered under the light of the work engaged through this cross chapter team.






De : FERNANDO LOPEZ AGUILAR [mailto:fla at tid.es]
Envoyé : vendredi 25 octobre 2013 11:55
À : GIDOIN Daniel
Cc : JUAN JOSE HIERRO SUREDA; BISSON Pascal; CAO Phong; MUSARAJ Kreshnik; JOSE IGNACIO CARRETERO GUARDE
Objet : Re: [FIWARE] - Task force security monitoring- Questions about security risk analysis

Dear Daniel et all,

We have several problems due to the jesus license allows us only scanning 16 IPs, after that we have to uninstall it and install again.

We have the following 5 scanning files made:

* 130.206.82.0/28  - This is the public network of the hosts that we have.
* 172.30.1.0/24      - This is the first 16 hosts of the private networks corresponding to the compute nodes, the rest of compute nodes are in the following files.
* 172.30.1.16/28    - The second part of the scanning compute nodes of the private network.
* 172.30.1.112/28  - This is the result of the scanning swift nodes (only 5).
* 172.30.1.192/28  - This is the result of the DB, Storage, etc. hosts.

If we need more information like IP publics of virtual machines, we can work with, we estimate some 8 hours of work.

Greetings,


Fernando López Aguilar
Cloud Computing
fla at tid dot es
+34 914 832 729
Telefónica I+D (R&D)
Ronda de la Comunicación s/n
Distrito C, Edificio Oeste 1, Planta 9
28043 Madrid, Spain




Follow FI-WARE on the net



        Website:  http://www.fi-ware.eu<http://www.fi-ware.eu/>

        Facebook: http://www.facebook.com/pages/FI-WARE/251366491587242

        Twitter:  http://twitter.com/Fiware

        LinkedIn: http://www.linkedin.com/groups/FIWARE-4239932



El 25/10/2013, a las 10:41, GIDOIN Daniel <daniel.gidoin at thalesgroup.com<mailto:daniel.gidoin at thalesgroup.com>> escribió:

Dear Fernando,

Error excepted, I do not receive any answer to my email.

Best regards

Daniel

De : GIDOIN Daniel
Envoyé : vendredi 18 octobre 2013 12:06
À : 'FERNANDO LOPEZ AGUILAR'
Cc : JUAN JOSE HIERRO SUREDA; BISSON Pascal; CAO Phong; MUSARAJ Kreshnik
Objet : [FIWARE] - Task force security monitoring- Questions about security risk analysis

Dear  Fernando,

Thank a lot for your information but can you use a Nessus scanner and send us the file produced by the scanner.

Best regards

Daniel


De : FERNANDO LOPEZ AGUILAR [mailto:fla at tid.es]
Envoyé : vendredi 27 septembre 2013 15:49
À : BISSON Pascal; GIDOIN Daniel
Cc : JUAN JOSE HIERRO SUREDA
Objet : Re: [FIWARE] Questions about security risk analysis

Hi Pascal, Daniel,

I do not receive any answer to my email. I send the information that I have know and
let me know if you need anything else. You can notice that the information regarding
CPE or CAVE is not provided due to I do not know how to obtain it. Let me know how
can obtain it and I send it again the document.


Best regards,

Fernando López Aguilar
Cloud Computing
fla at tid dot es
+34 914 832 729
Telefónica I+D (R&D)
Ronda de la Comunicación s/n
Distrito C, Edificio Oeste 1, Planta 9
28043 Madrid, Spain





Follow FI-WARE on the net



        Website:  http://www.fi-ware.eu<http://www.fi-ware.eu/>

        Facebook: http://www.facebook.com/pages/FI-WARE/251366491587242

        Twitter:  http://twitter.com/Fiware

        LinkedIn: http://www.linkedin.com/groups/FIWARE-4239932




El 24/09/2013, a las 12:15, Fernando Lopez Aguilar <fla at tid.es<mailto:fla at tid.es>> escribió:


Hi Daniel, Pascal,

The first questions is about which environment we have to provide that information. I assume
that you refer only to the FI-LAB.

In the excel file, Network topology, you talk about CPE (Common Platform Enumeration),
which information have we show there and how can we obtain it?

In the same way, regarding the information about the software, you talk again CPE, how
we can obtain that information?

Finally, like yesterday, you mention that in order to obtain the vulnerability identifier (CAVE)
it is needed to execute a program, correct me if I am wrong, this program is CAVE? How
we can use it in order to provide the identifier (e.g. CVE-2012-4558)

Regarding the values of the scoring, honestly I do not know which value we can put there if
we are a open source project. The same in the "business application that have constraint on IT"
and "cost parameters" in the Remediation part.

Best regards,

Fernando López Aguilar
Cloud Computing
fla at tid dot es
+34 914 832 729
Telefónica I+D (R&D)
Ronda de la Comunicación s/n
Distrito C, Edificio Oeste 1, Planta 9
28043 Madrid, Spain

<PastedGraphic-1.tiff>



Follow FI-WARE on the net



        Website:  http://www.fi-ware.eu<http://www.fi-ware.eu/>

        Facebook: http://www.facebook.com/pages/FI-WARE/251366491587242

        Twitter:  http://twitter.com/Fiware

        LinkedIn: http://www.linkedin.com/groups/FIWARE-4239932






________________________________

Este mensaje se dirige exclusivamente a su destinatario. Puede consultar nuestra política de envío y recepción de correo electrónico en el enlace situado más abajo.
This message is intended exclusively for its addressee. We only send and receive email on the basis of the terms set out at:
http://www.tid.es/ES/PAGINAS/disclaimer.aspx


________________________________

Este mensaje se dirige exclusivamente a su destinatario. Puede consultar nuestra política de envío y recepción de correo electrónico en el enlace situado más abajo.
This message is intended exclusively for its addressee. We only send and receive email on the basis of the terms set out at:
http://www.tid.es/ES/PAGINAS/disclaimer.aspx


________________________________

Este mensaje se dirige exclusivamente a su destinatario. Puede consultar nuestra política de envío y recepción de correo electrónico en el enlace situado más abajo.
This message is intended exclusively for its addressee. We only send and receive email on the basis of the terms set out at:
http://www.tid.es/ES/PAGINAS/disclaimer.aspx
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.fiware.org/private/fiware-secure-cloud/attachments/20131126/3a579603/attachment.html>


More information about the Fiware-secure-cloud mailing list

You can get more information about our cookies and privacy policies clicking on the following links: Privacy policy   Cookies policy