Status Updates of work items (FOD/SecEventProcessing/CT)
F2F-Meeting-Planning
AOB
Discussion items
Time
Item
Who
Notes
Status of FOD
No changes yet
Evangelos will sent FOD reqs (full list) sheet to task mailing list
Evangelos will particpate in FOD development
FOD pilot installation at Surfnet starting: Albert will send his recommendation for needed/nice features also depending on Surfnets particular use case/user story of FOD (different to GEANT)
DDoS in general
Evangelos attended workshop by ATEN:
DDOS intelligence solution (combination of FlowMon and ATENs own parts) with Scrubbing capability up to 150 Gbps
config: cli/web: very nice
e.g. possibility to have different operation levels (having different rules active), level change depending on conditions,
filter particular protocols
very granular
Further workshop with ATEN at Cambridge planned (about >= mid of Aug):
about potential deployment scenarios for ATEN solution in GEANT
-> idea to other attend (at least DS),
-> maybe if it makes sense combine with T6 F2F meeting
GEANT (Evangelos): plans to conduct a survery for NRENs
about FOD + potential use of ATEN (or similar) for DDoS Mitigation tool
find out out whether using ATEN in GEANT can be of use for NRENs
-> coordinate/combine this survey with T6 for finding out further stakeholders and their particular requirements regarding T6
Status of Warden/RepShield
RepShield: can now in real-time receive all current events from warden
Status of SecTestBed
Info from T5: Nemea will not be used as one of the first candidates for NMaaS
But instead T5 is currently investigating flow tools (e.g. nfdump):
And CESNET has much experience with this
especially also implemented a library for efficient parsing of NFdump files
-> liase with T5 to ask whether they want help
Status of CT
DS will contact Linus/Magnus separately about this
F2F-meeting
As not all members are present, talk about next meeting;
Maybe combine with ATEN workshop (compare above)
Action items
Evangelos: send full list of planned/missing features excel list to mailing list
Albert: send infos aboute SURFNET FOD user story and recommended new features
DS: ask T5 about help with software investigation concerning nfdump by CESNET
all: next regular task VC: Wed, 27.07.2016, 14:00-14:30 CEST