Thematic CERN School of Computing on Security 2025
from
Sunday 6 April 2025 (11:00)
to
Saturday 12 April 2025 (12:00)
Sunday 6 April 2025
15:00
Registration
Registration
15:00 - 17:00
17:00
Welcome to the CERN School of Computing
Welcome to the CERN School of Computing
17:00 - 17:20
17:20
Self-presentation: 1 minute per person
Self-presentation: 1 minute per person
17:20 - 18:20
19:00
Dinner at the Nag's head pub
Dinner at the Nag's head pub
19:00 - 20:30
Monday 7 April 2025
09:00
Opening Session
-
Alberto Pace
(
CERN
)
Sebastian Lopienski
(
CERN
)
Opening Session
Alberto Pace
(
CERN
)
Sebastian Lopienski
(
CERN
)
09:00 - 09:45
09:45
Security in research and scientific computing
-
David Crooks
(
UKRI STFC
)
Security in research and scientific computing
David Crooks
(
UKRI STFC
)
09:45 - 10:45
* computer security: past, present and future * current risk landscape * most common threats and attack vectors * "why are we here?"
10:45
Announcements
Announcements
10:45 - 11:00
11:00
Coffee break
Coffee break
11:00 - 11:30
11:30
Risk Management - lecture 1
-
Sven Gabriel
Risk Management - lecture 1
Sven Gabriel
11:30 - 12:30
12:30
Lunch
Lunch
12:30 - 13:15
13:15
Study time and/or daily sports
Study time and/or daily sports
13:15 - 14:45
14:45
Risk management - lecture 2
-
Sven Gabriel
Risk management - lecture 2
Sven Gabriel
14:45 - 15:45
The files attached to Risk management - lecture 1 contain all the slides for both lectures
15:45
Coffee break
Coffee break
15:45 - 16:15
16:15
Security architecture fundamentals
-
Barbara Krašovec
(
IJS
)
Security architecture fundamentals
Barbara Krašovec
(
IJS
)
16:15 - 17:15
Security architecture fundamentals • fundamental security principles • develop skills to be a security architect • how to design and provide secure computing infrastructure • security standards and frameworks • physical security • network security: segmentation, firewalls, VPNs
17:15
Identity, authentication, authorisation
-
Tom Dack
Identity, authentication, authorisation
Tom Dack
17:15 - 18:15
• An introduction to the concepts of Identity, Authentication, and Authorization • Authentication and authorisation for distributed research • Methods for communicating authentication and authorization: Certificates, SAML, OAuth • How these technologies fit within research infrastructures
18:15
Identity Management & AAI - exercise
-
Tom Dack
Identity Management & AAI - exercise
Tom Dack
18:15 - 19:15
Resources: - Glitch: [https://glitch.com/~oauth-oidc-exercises][1] - IRIS IAM: [https://iris-iam.stfc.ac.uk/login][2] - IRIS IAM Documentation: [https://stfc.github.io/IAM-Docs/][3] [1]: https://glitch.com/~oauth-oidc-exercises [2]: https://iris-iam.stfc.ac.uk/login [3]: https://stfc.github.io/IAM-Docs/
19:15
Dinner at Cosener´s house
Dinner at Cosener´s house
19:15 - 20:00
Tuesday 8 April 2025
08:45
Defensible security architecture: how to implement security principles
-
Barbara Krašovec
(
IJS
)
Defensible security architecture: how to implement security principles
Barbara Krašovec
(
IJS
)
08:45 - 09:45
• data security • endpoint security: hardware, host, OS, BMC security, system hardening • application security • future security trends
09:45
Logging and traceability
-
David Crooks
(
UKRI STFC
)
Logging and traceability
David Crooks
(
UKRI STFC
)
09:45 - 10:45
* host-based logs (system and application level), network monitoring * the importance of central logging * tools and technologies * data privacy, dealing with personal and sensitive data, log retention * traceability challenges
10:45
Announcements
Announcements
10:45 - 11:00
11:00
School photo
School photo
11:00 - 11:05
11:05
Coffee break
Coffee break
11:05 - 11:30
11:30
Virtualisation and cloud security
-
Barbara Krašovec
(
IJS
)
Virtualisation and cloud security
Barbara Krašovec
(
IJS
)
11:30 - 12:30
Virtualisation and cloud security • virtualisation security fundamentals • cloud service models • authentication and key management • data security in the cloud • DevSecOps • security in private and public cloud • common threats in the cloud • security tools
12:30
Lunch
Lunch
12:30 - 13:15
13:15
Study time and/or daily sports
Study time and/or daily sports
13:15 - 14:45
14:45
Vulnerability management
-
Sven Gabriel
Vulnerability management
Sven Gabriel
14:45 - 15:45
* vulnerability lifecycle, monitoring, scanning * CVE, CVSS, CPE, CWE and related standards * special cases: vulnerable hardware, EOL systems etc.
15:45
Coffee break
Coffee break
15:45 - 16:15
16:15
Student lightning talks
-
Andrzej Nowicki
(
CERN
)
Gwen Dawes
(
University of Cambridge
)
Richard Bachmann
(
CERN
)
Subhashis Suara
(
CERN
)
Nowshaba Jeelani Wani
Student lightning talks
Andrzej Nowicki
(
CERN
)
Gwen Dawes
(
University of Cambridge
)
Richard Bachmann
(
CERN
)
Subhashis Suara
(
CERN
)
Nowshaba Jeelani Wani
16:15 - 16:55
16:55
Risk management - cont.
-
Sven Gabriel
Risk management - cont.
Sven Gabriel
16:55 - 17:10
17:15
Application security
-
Sebastian Lopienski
(
CERN
)
Application security
Sebastian Lopienski
(
CERN
)
17:15 - 18:15
* web application security, typical web vulnerabilities * ethical hacking * introduction to pentesting
18:15
Application Security - exercises
-
Sebastian Lopienski
(
CERN
)
Application Security - exercises
Sebastian Lopienski
(
CERN
)
18:15 - 19:15
19:15
Dinner at Cosener´s house
Dinner at Cosener´s house
19:15 - 20:00
Wednesday 9 April 2025
08:45
Container security
-
Daniel Kouřil
(
CESNET
)
Container security
Daniel Kouřil
(
CESNET
)
08:45 - 09:45
* key concepts of containers (namespaces, cgroups etc.) and Docker * container security, threat landscape * vulnerability and patch management
09:45
Container security - exercises
-
Daniel Kouřil
(
CESNET
)
Container security - exercises
Daniel Kouřil
(
CESNET
)
09:45 - 10:45
10:45
Announcements
Announcements
10:45 - 11:00
11:00
Coffee break
Coffee break
11:00 - 11:30
11:30
Intrusion detection with SOC: deployment and operation
-
David Crooks
(
UKRI STFC
)
Intrusion detection with SOC: deployment and operation
David Crooks
(
UKRI STFC
)
11:30 - 12:30
* indicators of compromise (IoCs), threat intelligence sharing, TLP protocol * tools and technologies: MISP, Zeek, OpenSearch etc. * deploying a Security Operation Center * security incidents: detecting and alerting* indicators of compromise (IoCs), threat intelligence sharing, TLP protocol * tools and technologies: MISP, Zeek, OpenSearch etc. * deploying a Security Operation Center * security incidents: detecting and alerting
12:30
Collect lunch bags
Collect lunch bags
12:30 - 12:45
13:00
Departure of bus to Oxford
Departure of bus to Oxford
13:00 - 14:00
14:00
Oxford visit, punting and dinner
Oxford visit, punting and dinner
14:00 - 21:30
21:30
Transport by bus to Cosener's house
Transport by bus to Cosener's house
21:30 - 22:30
Thursday 10 April 2025
08:45
Security Operations
-
Sven Gabriel
Security Operations
Sven Gabriel
08:45 - 09:45
additional material: - source code for communication challenges https://codeberg.org/dussa/CommsChallenge/
09:45
Incident response management
-
Barbara Krašovec
(
IJS
)
Incident response management
Barbara Krašovec
(
IJS
)
09:45 - 10:45
• incident management and coordination • incident analysis and investigation • communication with stakeholders • containment and eradiction • recovery • lessons learnt
10:45
Announcements
Announcements
10:45 - 11:00
11:00
Coffee break
Coffee break
11:00 - 11:30
11:30
Digital forensics: essentials and data acquisition
-
Daniel Kouřil
(
CESNET
)
Digital forensics: essentials and data acquisition
Daniel Kouřil
(
CESNET
)
11:30 - 12:30
digital evidence handling data acquisition (live systems, storage etc.) data analysis (OS, file system, network, executables etc.) reporting
12:30
Lunch
Lunch
12:30 - 13:15
13:15
Study time and/or daily sports
Study time and/or daily sports
13:15 - 14:45
14:45
Digital forensics: data analysis
-
Daniel Kouřil
(
CESNET
)
Digital forensics: data analysis
Daniel Kouřil
(
CESNET
)
14:45 - 15:45
15:45
Coffee break
Coffee break
15:45 - 16:15
16:15
Intrusion detection with SOC - exercises
-
David Crooks
(
UKRI STFC
)
Intrusion detection with SOC - exercises
David Crooks
(
UKRI STFC
)
16:15 - 18:15
* indicators of compromise, threat intelligence sharing, TLP protocol * tools and technologies * deploying a Security Operation Center * detecting security incidents
19:15
Dinner at Cosener´s house
Dinner at Cosener´s house
19:15 - 20:00
Friday 11 April 2025
08:45
Digital forensics - exercises
-
Daniel Kouřil
(
CESNET
)
Digital forensics - exercises
Daniel Kouřil
(
CESNET
)
08:45 - 10:15
10:15
Coffee break
Coffee break
10:15 - 10:30
10:30
Introduction to forensics - exercises
-
Daniel Kouřil
Introduction to forensics - exercises
Daniel Kouřil
10:30 - 11:45
11:45
Announcements
Announcements
11:45 - 12:00
12:00
Penetration testing - exercise debriefing
-
Sebastian Lopienski
(
CERN
)
Penetration testing - exercise debriefing
Sebastian Lopienski
(
CERN
)
12:00 - 12:30
12:30
Lunch
Lunch
12:30 - 13:15
13:15
Study time
Study time
13:15 - 14:15
14:15
Exam
Exam
14:15 - 15:00
15:00
Short break
Short break
15:00 - 15:15
15:15
Incident response - exercise
-
David Crooks
(
UKRI STFC
)
Tom Dack
Sebastian Lopienski
(
CERN
)
Romain Wartel
(
CERN
)
Incident response - exercise
David Crooks
(
UKRI STFC
)
Tom Dack
Sebastian Lopienski
(
CERN
)
Romain Wartel
(
CERN
)
15:15 - 16:45
* incident management and coordination * Sirtfi and trust frameworks * communication with local users, external communities, and other stakeholders * working with law enforcement * privacy aspects
16:45
Coffee break
Coffee break
16:45 - 17:00
17:00
Incident response - exercise
-
David Crooks
(
UKRI STFC
)
Tom Dack
Romain Wartel
(
CERN
)
Sebastian Lopienski
(
CERN
)
Incident response - exercise
David Crooks
(
UKRI STFC
)
Tom Dack
Romain Wartel
(
CERN
)
Sebastian Lopienski
(
CERN
)
17:00 - 18:15
* incident management and coordination * Sirtfi and trust frameworks * communication with local users, external communities, and other stakeholders * working with law enforcement * privacy aspects
18:15
Closing Session
-
Alberto Pace
(
CERN
)
Closing Session
Alberto Pace
(
CERN
)
18:15 - 19:00
19:30
Outside Closing Dinner at Doriandos
Outside Closing Dinner at Doriandos
19:30 - 21:30
Saturday 12 April 2025
10:00
Departure
Departure
10:00 - 12:00