• No results found

Secure Access To Telemetry Data

N/A
N/A
Protected

Academic year: 2021

Share "Secure Access To Telemetry Data"

Copied!
24
0
0

Loading.... (view fulltext now)

Full text

(1)

1

Secure Access To Telemetry

Secure Access To Telemetry

Data

Data

Arthur T McClinton Jr

Arthur T McClinton Jr

Mitretek Systems

Mitretek Systems

1 March 2005 1 March 2005
(2)

Overview

Overview

„

„

Introductions

Introductions

„

„

Background & Objectives

Background & Objectives

„

„

SRAS Overall Architecture

SRAS Overall Architecture

„
(3)

3

Overview of Issues

Overview of Issues

„

„

Distributed processing requirements are making

Distributed processing requirements are making

closed networks more difficult

closed networks more difficult

„

„

NOAA Satellite Operations has found need to

NOAA Satellite Operations has found need to

export three different types of data

export three different types of data

„

„

Processed H&S telemetry for anomaly analysis

Processed H&S telemetry for anomaly analysis

„

„

Exporting large files for various on

Exporting large files for various on

-

-

site external

site external

analysis using other tools

analysis using other tools

„

„

Exporting streams of raw data to other processing

Exporting streams of raw data to other processing

systems

(4)

Background

Background

„

„ Anomaly investigations need to have key people Anomaly investigations need to have key people

gaining quick access to the data

gaining quick access to the data

„

„ The SOCC is a closed system and requires the The SOCC is a closed system and requires the

people to come to the SOCC to receive the data

people to come to the SOCC to receive the data

„

„ NOAA/NESDIS has the responsibilities to NOAA/NESDIS has the responsibilities to

correctly operate the nations weather satellite fleet

correctly operate the nations weather satellite fleet

„

„ SRAS is primarily a means of providing telemetry SRAS is primarily a means of providing telemetry

data to remote analysts so that spacecraft health

data to remote analysts so that spacecraft health

and safety can be remotely monitored

(5)

5

Background (Continued)

Background (Continued)

„

„

The External Analysis Transfer System uses the

The External Analysis Transfer System uses the

same one

same one

-

-

way fiber technology as SRAS to allow

way fiber technology as SRAS to allow

automated transfer of files from the operations

automated transfer of files from the operations

network to the administrative network.

network to the administrative network.

„

„

The streaming of data from the operations

The streaming of data from the operations

network to external processing networks is

network to external processing networks is

performed using UDP packets through a one

performed using UDP packets through a one

-

-way fiber link.

(6)

SRAS Objectives

SRAS Objectives

„

„

Increase effectiveness of communication

Increase effectiveness of communication

between off

between off

-

-

site engineers and on

site engineers and on

-

-

line

line

operations crews during after hours anomaly

operations crews during after hours anomaly

identification

identification

„

„

Improve response time to identify spacecraft

Improve response time to identify spacecraft

anomalies and begin corrective action

anomalies and begin corrective action

„

„

Reduce number of instances where

Reduce number of instances where

engineers must travel to SOCC during non

engineers must travel to SOCC during non

-

-work hours

(7)

7

SRAS Objectives

SRAS Objectives

„

„

Increase the pool of experts who have rapid

Increase the pool of experts who have rapid

access to health and safety data

access to health and safety data

„

„

Evaluate the utility of remote access to

Evaluate the utility of remote access to

health and safety data to determine if this

health and safety data to determine if this

function should be included in future

function should be included in future

ground system architectures

ground system architectures

„

„

Evaluate the utility of PKI based security as

Evaluate the utility of PKI based security as

an authentication mechanism for remote

an authentication mechanism for remote

access systems

(8)

SRAS Overview

SRAS Overview

„

„ Telemetry archive files are flowed through a oneTelemetry archive files are flowed through a one-

-way fiber link appliance to the SRAS network.

way fiber link appliance to the SRAS network.

„

„ Files are processed and stored in a database.Files are processed and stored in a database. „

„ UserUser’’s are paged when user specified conditions s are paged when user specified conditions

exist in the inbound data.

exist in the inbound data.

„

„ Remote user access using laptop or home pc:Remote user access using laptop or home pc:

„

„ Smart card authentication,Smart card authentication,

„

„ Dialup or internet,Dialup or internet,

„

„ Web access ,Web access ,

„

(9)

SRAS Overview

SRAS Overview

NOAA Operations Engineer Workstation SmartCard PTSN E-Business E-Gap BACKOFFICE NOAA Operations Engineer Workstation SmartCard PTSN E-Business E-Gap (Future?) 16 Port FastEthernet Switch DC2 DC2 iPlanet CleaTrust(BU) Directory E-mail Pager OWL GOES Gateway PAS SDCI OWLs IAS HP OpenviewHP Openview IDS Director ADM1 Ace Server DC1 Child DC ClearTrust iPlanet (BU) DC1 SRAS Web Appl Web App Server Dell PE 1550 APP1 RSA ClearTrust SRAS Web Appl Web App Server Dell PE 1550 APP1 RSA ClearTrust ClearTrust EDB (BU) Ace Server (BU)

Root2 Root DC KEON CA SRAS Console Root2 APP4 APP5 APP2 SFP MS SQL Database SRAS DB Dell PE 2550 Cisco Pix 515 Firewall Cisco Pix 515 Firewall 16 Port FastEthernet Hub 16 Port FastEthernet Hub Cisco 4210 Intrusion Detection System Cisco 4210 Intrusion Detection System

NOAA Network Access (future?)

NOAA Network Access

Dell PE 350 Mail Server Dell PE 350 Mail Server Dial-Up Access Cisco 3620 24 Port v.90 Dial-Up Access Cisco 3620 24 Port v.90 Domain Controller Root1 Root DC Root1 DDNS Tape Library DLT 9 Tape capacity ARCServe Enterprise TapeBackup Software channels ISDN PRI 20 Voice E-mail NTP Timeserver APP3 IRIG-B one way Fibre

(10)

External Analysis Transfer System

External Analysis Transfer System

Objectives and Overview

Objectives and Overview

„

„

Transfer data to administrative LAN

Transfer data to administrative LAN

„

„

One

One

-

-

way fiber optic link allowing:

way fiber optic link allowing:

„

„ Users to push a file to a directory on the OPS Users to push a file to a directory on the OPS

LAN machine

LAN machine

„

„ Automatic transfer to the Admin LAN Automatic transfer to the Admin LAN

machine

machine

„

„ Users can retrieve the fileUsers can retrieve the file

„

(11)

11

Data Streaming Overview

Data Streaming Overview

„

„ Need to get real time telemetry streams to several Need to get real time telemetry streams to several

external processing systems.

external processing systems.

„

„ Implemented using two different systems but they Implemented using two different systems but they

have very similar capabilities

have very similar capabilities

„

„ TCP/IP socket set up to machine on OPS LANTCP/IP socket set up to machine on OPS LAN

„

„ UDP or proprietary packet pushed through oneUDP or proprietary packet pushed through one--way way fiber link to machine on foreign network

fiber link to machine on foreign network

„

„ TCP/IP TCP/IP socket(ssocket(s) set up from machine on foreign ) set up from machine on foreign network to other

network to other machine(smachine(s) on that network.) on that network.

„

„ One solution was a certified commercial system One solution was a certified commercial system

the other was a home brew using a media

the other was a home brew using a media

converter and two Linux systems.

(12)

Conclusions

Conclusions

„

„

The use of one

The use of one

-

-

way fiber links provides an

way fiber links provides an

attractive way to export data without running

attractive way to export data without running

the risks associated with Firewalls.

(13)

13

SRAS Demonstration

SRAS Demonstration

„

„

Log in using smart card over Verizon EVDO

Log in using smart card over Verizon EVDO

link

link

„

„

Extract data from current operational SC

Extract data from current operational SC

„

„

Following slides show capabilities for those not

Following slides show capabilities for those not

present to see live demo

(14)
(15)
(16)
(17)
(18)
(19)
(20)
(21)
(22)
(23)
(24)

References

Related documents

O transmedia storytelling afigura-se, desta forma, como um promissor futuro para a indústria de média e para a produção de conteúdos audiovisuais, permitindo a introdução

Since index.php has the rights to connect to a file like contacts.php, it's possible that the administrator has forgottten to restrict its access to other files, including the

Of course, unobserved differences in firm characteristics and performance between acquired and non-acquired firms in the years before acquisition could bias the estimates of the

Agaricus martineziensis , previously reported from Argentina and Mexico, is described from Brazil, and its phylogenetic affinities evaluated by nLSU rDNA sequence data showed a close

Written by a distinguished roster of philosophers, this volume includes chapters on truth and meaning; the philosophy of action; radical interpretation; philosophical psychology;

Objective—This study sought to determine the correlation between baseline cardiac medications and cardiovascular outcomes in patients with obstructive coronary artery disease

Overall, the literature concludes that insecure attachment is related to higher levels of both anxiety and depression than secure attachments from childhood to early adulthood