SlideShare ist ein Scribd-Unternehmen logo
1 von 20
The Security of National Network
of Public Administration
«SYZEFXIS»
Dr. Haris Stellakis
Program Portfolio Manager, Chief Security
Officer of “SYZEFXIS” Network
Information Society SA
March 4, 2015
2000 –2001–2002–2003–2004–2005–2006 2007– 2008 – 2009 – 2010 – 2011 – 2012 – 2013 2020
3rd
Community Support
Framework
4th
Community Support
Framework
5th
Community Support
Framework
Establishment of
Information
Society SA
2
A Life-long Partner
900M€ 1,300M€
Acquisition of
DIGITAL AID SA
Acquisition of
Observatory of Digital Greece SA
Dr. Haris Stellakis – 03/2015
The Role of Information Society SA
3
Public
Administration
CitizensBusinesses
Implements Facilitates
State AidsObserves
Informatics
•~ 180 M€
Public Reform
•~ 70 Μ€
Telecommunications
•Syzefxis
•MAN
•Rural Broadband
Dr. Haris Stellakis – 03/2015
SYZEFXIS ΙΙ
(600 Μ€)
RURAL
(160 Μ€)
Supplemental Actions for
SYZEFXIS II
(10 Μ€)
SYZEFXIS Ι
(45 Μ€)
ΜΑΝ
(5 Μ€)
Planning Tender Auctions Implementation Operations
Effort by Vendors
Effort by I.S. SA
Telecom Projects
Dr. Haris Stellakis – 03/2015
SYZEFXIS: The State’s Telecom
backbone
5
Interoperability and Apps G2B / G2C
 Ministries – General Secretaries
 Municipalities
 Citizen Service Centers
 Financial Agencies
 Health Agencies
 Citizen Protection Agencies (Police, etc)
 Armed Forces
 EU Agencies
 Justice Courts
 Independent Agencies
Dr. Haris Stellakis – 03/2015
SYZEFXIS: 2006-2013
6
Agency
Type Access Speed Agencies
ADSL 24/1 Μbps 1428
3G 2/1 Mbps 50
SMALL 2/2 Mbps 2488
MEDIUM 4-8/4-8 Mbps 434
LARGE 34/34 Mbps 85
TOTAL 4485
 Free broadband access (2 – 34 Mbps)
 Free onnet telephony services as well
as offnet at competitive prices
 Free webhosting or routing to
external ISPs
 Same for email services
 Connection to EU Netowork “S-Testa”
 Free teleconferencing services to
specific deployments
Dr. Haris Stellakis – 03/2015
SYZEFXIS Ι: 2013-14
7
PoP OTE
MAN Switch
Router
ΣΥΖΕΥΞΙΣ Ι
Router
ΣΥΖΕΥΞΙΣ Ι
MAN Switch
Router
ΣΥΖΕΥΞΙΣ Ι
SHDSL modem
πρόσβασης
Κόμβος Πρόσβασης
ΜΑΝ
ΜΑΝ
PBX
PBX
PBX
Kύριος κόμβος
ΜΑΝ (ΚΚ)
Κόμβος ΜΑΝ
πλησιέστερος στον ΟΤΕ
FE
FE
FE
PRA
PRA
PRA
GE
GE
GE
2Mbps
X.21
X.21
Router
ΣΥΖΕΥΞΙΣ Ι
PBX
PRA
Κόμβος Πρόσβασης
ΜΑΝ
FEGE ή FE
MAN Switch
FE
FE
FE
Metropolitan Area Fiber Optic Networks
Dr. Haris Stellakis – 03/2015
SYZEFXIS ΙΙ: 2015-2018
8
S
0
5000
10000
15000
20000
25000
30000
35000
2005 2006 2008 2009 2010 2014
1.800 3.000 3.250 4.450 6.000
34.000
SIZE SPEED (Μbps)
1 ADSL 24/1
2 SMALL 10/10
3 MEDIUM 100/100
4 LARGE 1000/1000
Secure broadband connection to 34.000 public
points and provision of telecom / multimedia
services
 50% reduction to annual OPEX
 Wireless access services 55.000 Government Agents
through the subsidization of smartphones
 Secure services to Public Sector
Dr. Haris Stellakis – 03/2015
SYZEFXIS ΙΙ: 5 Subprojects
9
SIX / DC
Wireless
Islet
Νησίδες
1-9
Telecom
Islets 1-8
Security /
Telephony /
Teleconferenci
ng / Cabling
ISP /
SLA
Dr. Haris Stellakis – 03/2015
10
Security in SYZEFXIS Ι (1/4)
Multi-stage Security Architecture:
 Provision of different VPNs per Agency and/or App
 Perimeter Security against the Internet
• Private ΙΡ addressing
• Connection through proxy
 Centrally managed Security devices
• Firewalls &Intrusion Detection Systems
• Antivirus & antispam mechanisms
• Multiple profile Web content filtering services
 Perimeter Security per Islet
• Intra-VPN communication for specific apps /
services, through the use of access lists
• Control of Intra-VPN traffic
Dr. Haris Stellakis – 03/2015
11
Security in SYZEFXIS Ι (2/4)
Security Policy:
 Within SYZEFXIS
• Intra-VPN traffic
• Inter-VPN traffic
 Outside of SYZEFXIS
• Internet
• Educational Network “EDET”
• EU Network s-Testa
 The perimeter security lifting is subjected to
approval by Information Society SA
 Software control mechanisms
 User’s information
Perimeter
Security lifting
Ticket submission
Evaluation by IS
SA
Reporting to
Vendor
Ticket
implementation
(upon approval)
Reporting to
Applicant Agency
Dr. Haris Stellakis – 03/2015
12
Security in SYZEFXIS Ι (3/4)
The role of Information Society SA:
 To monitor the project vendors
 To support the public Agencies
 To implement and improve the security policy
 To leverage the collected knowledge towards the
design of next G SYZEFXIS
0
10
20
30
40
50
60
Αιτήματα Φορέων
0 20 40 60 80 100 120 140 160 180
Περιφέρειες - Δήμοι
Νοσοκομεία
ΕΛΑΣ - Πυροσβεστική - Λιμενικό
Οικονομικές Υπηρεσίες
Υπουργεία - Γεν Γραμματείες
Υπηρεσίες Κοιν Αλλυλεγγύης - Ασφ. Ταμεία
Πολεοδομίες
ΕΥΔ Προγραμμάτων ΕΕ
Μουσεία
Λοιπές Δ.Υ.
Κατηγορίες Φορέων
39%
26%
20%
6%
3% 3%
2%
1%
Κατηγορίες Αιτημάτων
Άνοιγμα επιπλέον onnet
θυρών
Απόδοση πραγματικής δ/σης
ΙΡ
Άνοιγμα επιπλέον ofnet
θυρών
Πρόσβαση σε site
Ρυθμίσεις CPE
Παράκαμψη proxy
Επικοινωνία με άλλα δίκτυα
Ενημέρωση DNS
Dr. Haris Stellakis – 03/2015
13
Security in SYZEFXIS Ι (4/4)
State Elections through SYZEFXIS:
 Levaraging of telephone infrastructure
Municipalities Prefectures Ministry of Interiors
 Leveraging of internet infrastructure
 Creation of a VPN between MoI, SingularLogic and
Zappeio Megaro for the communication of results
 Full functionality was tested on a wide scale drill (5/2014)
2014 and 2015 Elections were
completed succesfully
Dr. Haris Stellakis – 03/2015
14
Security in SYZEFXIS ΙΙ (1/5)
Security/
Telephony /
Teleconferenci
ng / Cabling
Independent
Security Auditor
(1,3 Μ€)
Infrastructure
Services
A combination of Actions
Dr. Haris Stellakis – 03/2015
15
Security in SYZEFXIS ΙΙ (2/5)
Security Infrastructure and Services:
 Procurement of suitable security equipment
 Development of a security management
information system
 Operation services based on SLAs (Routing, QoS)
 Security Services
• IP Firewall, IPS, VPN, Email & Web Antivirus-
Antispam, Web Content Filtering
 User training
Dr. Haris Stellakis – 03/2015
16
Security in SYZEFXIS ΙΙ (3/5)
State-of-the-art Architecture:
 Leveraging IPSEC VPN technologies
 Ability to support multiple vendors in
contract framework
 Ability to support gradual deployment
 Ability to upgrade security level for
some sensitive Agencies, through the
use of special-purpose encrypting
devices
Κ.Υ.Α.
(Ανάδοχος 1)
Κ.Υ.Α.
(Ανάδοχος 2)
Κ.Υ.Α.
(Ανάδοχος Ν)
Κ.Σ.Α.
Περιφερειακές Συσκευές
Ασφάλειας
(Αναδόχου 1)
Περιφερειακές Συσκευές
Ασφάλειας
(Αναδόχου 2)
Περιφερειακές Συσκευές
Ασφάλειας
(Αναδόχου Ν)
Creation of VPNs
Φορείς
εκτός ΣΥΖΕΥΞΙΣ ΙΙ
Dr. Haris Stellakis – 03/2015
17
Security in SYZEFXIS ΙΙ (4/5)
Independent Security
Auditor:
 Development of an ISO 27001
based ISMS
 Network security auditing
 Development of a specialized
Information System for Security
Control and Management
 Consulting services / security
“think tank”
Dr. Haris Stellakis – 03/2015
18
Security in SYZEFXIS ΙΙ (5/5)
At the operational level:
 Creation of an independent Department for
Telecommunication projects
• Discrete group for SYZEFXIS
 Creation of a task force among all stakeholders
• Infomarmation Society SA
• Project vendors
• Public Agencies
• Ministry of Public Reform
• Other Agencies(ie, Greek FCC, etc)
ΚτΠ ΑΕ
ΥΕΔΑ
Δημόσιοι
Φορείς
Ανάδοχοι
Έργων
Ελεγκτής
Ασφάλειας
Λοιποί
Φορείς
Dr. Haris Stellakis – 03/2015
19
Epilogue
Information Society, in collaboration with:
 Ministry of Public Reform,
 The EU Managing Authorities, and
 The project vendors
Facilitate:
 The terms and specs,
 The framework and procedures,
 The tools and mechanisms, and
 The resources
That assure the security of SYZEFXIS network and
therefore the flawless operation of Greek Public
Sector.
Dr. Haris Stellakis – 03/2015
20
The End
We thank you for your attention!
Dr. Haris Stellakis – 03/2015

Weitere ähnliche Inhalte

Was ist angesagt?

Building the platform for 5G
Building the platform for 5GBuilding the platform for 5G
Building the platform for 5GEricsson
 
The march of the IoT - Charlie Sheridan, Intel Labs Europe
The march of the IoT - Charlie Sheridan, Intel Labs EuropeThe march of the IoT - Charlie Sheridan, Intel Labs Europe
The march of the IoT - Charlie Sheridan, Intel Labs EuropeSITA
 
5G – How to enable change-makers in the Networked Society
5G – How to enable change-makers in the Networked Society5G – How to enable change-makers in the Networked Society
5G – How to enable change-makers in the Networked SocietyEricsson Latin America
 
Agile 5G Deployment
Agile 5G DeploymentAgile 5G Deployment
Agile 5G DeploymentEricsson
 
Innovation Summit 2015 - 10 - linear dust
Innovation Summit 2015 - 10 - linear dustInnovation Summit 2015 - 10 - linear dust
Innovation Summit 2015 - 10 - linear dustThibault Cantegrel
 
Innovation Summit 2015 - 11 - morpho
Innovation Summit 2015 - 11 - morphoInnovation Summit 2015 - 11 - morpho
Innovation Summit 2015 - 11 - morphoThibault Cantegrel
 
Global Virtual Mobile Network for Car manufacturers
Global Virtual Mobile Network for Car manufacturersGlobal Virtual Mobile Network for Car manufacturers
Global Virtual Mobile Network for Car manufacturersITU
 
Meeting the Needs of the Global Community
Meeting the Needs of the Global CommunityMeeting the Needs of the Global Community
Meeting the Needs of the Global CommunityEricsson
 
Ericsson 5G plug-ins
Ericsson 5G plug-insEricsson 5G plug-ins
Ericsson 5G plug-insEricsson
 
Considerations for a secure enterprise wlan data connectors 2013
Considerations for a secure enterprise wlan   data connectors 2013Considerations for a secure enterprise wlan   data connectors 2013
Considerations for a secure enterprise wlan data connectors 2013AirTight Networks
 
IoT: A Global Perspective - Radcomms 2016
IoT: A Global Perspective - Radcomms 2016IoT: A Global Perspective - Radcomms 2016
IoT: A Global Perspective - Radcomms 2016Andres Torres
 
How operator core networks evolve towards 5G - Digital Futures 2025
How operator core networks evolve towards 5G - Digital Futures 2025How operator core networks evolve towards 5G - Digital Futures 2025
How operator core networks evolve towards 5G - Digital Futures 2025Ovum
 
5G: the context, use cases, privacy, security and rules. Attilio Somma, TIM
5G: the context, use cases, privacy, security and rules. Attilio Somma, TIM5G: the context, use cases, privacy, security and rules. Attilio Somma, TIM
5G: the context, use cases, privacy, security and rules. Attilio Somma, TIMData Driven Innovation
 
Evolving cellular IoT for industry digitalization
Evolving cellular IoT for industry digitalizationEvolving cellular IoT for industry digitalization
Evolving cellular IoT for industry digitalizationEricsson
 
Connected Cars & 5G
Connected Cars & 5GConnected Cars & 5G
Connected Cars & 5GITU
 
Multilayer Transport SDN - In the Broader Context of Service Provider SDN Tra...
Multilayer Transport SDN - In the Broader Context of Service Provider SDN Tra...Multilayer Transport SDN - In the Broader Context of Service Provider SDN Tra...
Multilayer Transport SDN - In the Broader Context of Service Provider SDN Tra...Ericsson
 
5G for Connected and Automated Driving
5G for Connected and Automated Driving5G for Connected and Automated Driving
5G for Connected and Automated DrivingITU
 
SAE 2014 - Cyber Security: Mission Critical for the Internet of Cars
SAE 2014 - Cyber Security: Mission Critical for the Internet of CarsSAE 2014 - Cyber Security: Mission Critical for the Internet of Cars
SAE 2014 - Cyber Security: Mission Critical for the Internet of CarsAndreas Mai
 
Ericsson NFVi solution
Ericsson NFVi solutionEricsson NFVi solution
Ericsson NFVi solutionEricsson
 
Scaling Internet of Things
Scaling Internet of ThingsScaling Internet of Things
Scaling Internet of ThingsEricsson
 

Was ist angesagt? (20)

Building the platform for 5G
Building the platform for 5GBuilding the platform for 5G
Building the platform for 5G
 
The march of the IoT - Charlie Sheridan, Intel Labs Europe
The march of the IoT - Charlie Sheridan, Intel Labs EuropeThe march of the IoT - Charlie Sheridan, Intel Labs Europe
The march of the IoT - Charlie Sheridan, Intel Labs Europe
 
5G – How to enable change-makers in the Networked Society
5G – How to enable change-makers in the Networked Society5G – How to enable change-makers in the Networked Society
5G – How to enable change-makers in the Networked Society
 
Agile 5G Deployment
Agile 5G DeploymentAgile 5G Deployment
Agile 5G Deployment
 
Innovation Summit 2015 - 10 - linear dust
Innovation Summit 2015 - 10 - linear dustInnovation Summit 2015 - 10 - linear dust
Innovation Summit 2015 - 10 - linear dust
 
Innovation Summit 2015 - 11 - morpho
Innovation Summit 2015 - 11 - morphoInnovation Summit 2015 - 11 - morpho
Innovation Summit 2015 - 11 - morpho
 
Global Virtual Mobile Network for Car manufacturers
Global Virtual Mobile Network for Car manufacturersGlobal Virtual Mobile Network for Car manufacturers
Global Virtual Mobile Network for Car manufacturers
 
Meeting the Needs of the Global Community
Meeting the Needs of the Global CommunityMeeting the Needs of the Global Community
Meeting the Needs of the Global Community
 
Ericsson 5G plug-ins
Ericsson 5G plug-insEricsson 5G plug-ins
Ericsson 5G plug-ins
 
Considerations for a secure enterprise wlan data connectors 2013
Considerations for a secure enterprise wlan   data connectors 2013Considerations for a secure enterprise wlan   data connectors 2013
Considerations for a secure enterprise wlan data connectors 2013
 
IoT: A Global Perspective - Radcomms 2016
IoT: A Global Perspective - Radcomms 2016IoT: A Global Perspective - Radcomms 2016
IoT: A Global Perspective - Radcomms 2016
 
How operator core networks evolve towards 5G - Digital Futures 2025
How operator core networks evolve towards 5G - Digital Futures 2025How operator core networks evolve towards 5G - Digital Futures 2025
How operator core networks evolve towards 5G - Digital Futures 2025
 
5G: the context, use cases, privacy, security and rules. Attilio Somma, TIM
5G: the context, use cases, privacy, security and rules. Attilio Somma, TIM5G: the context, use cases, privacy, security and rules. Attilio Somma, TIM
5G: the context, use cases, privacy, security and rules. Attilio Somma, TIM
 
Evolving cellular IoT for industry digitalization
Evolving cellular IoT for industry digitalizationEvolving cellular IoT for industry digitalization
Evolving cellular IoT for industry digitalization
 
Connected Cars & 5G
Connected Cars & 5GConnected Cars & 5G
Connected Cars & 5G
 
Multilayer Transport SDN - In the Broader Context of Service Provider SDN Tra...
Multilayer Transport SDN - In the Broader Context of Service Provider SDN Tra...Multilayer Transport SDN - In the Broader Context of Service Provider SDN Tra...
Multilayer Transport SDN - In the Broader Context of Service Provider SDN Tra...
 
5G for Connected and Automated Driving
5G for Connected and Automated Driving5G for Connected and Automated Driving
5G for Connected and Automated Driving
 
SAE 2014 - Cyber Security: Mission Critical for the Internet of Cars
SAE 2014 - Cyber Security: Mission Critical for the Internet of CarsSAE 2014 - Cyber Security: Mission Critical for the Internet of Cars
SAE 2014 - Cyber Security: Mission Critical for the Internet of Cars
 
Ericsson NFVi solution
Ericsson NFVi solutionEricsson NFVi solution
Ericsson NFVi solution
 
Scaling Internet of Things
Scaling Internet of ThingsScaling Internet of Things
Scaling Internet of Things
 

Andere mochten auch

Andere mochten auch (10)

IPv6 addressing in National Network of Public Administration "SYZEFXIS"
IPv6 addressing in National Network of Public Administration "SYZEFXIS"IPv6 addressing in National Network of Public Administration "SYZEFXIS"
IPv6 addressing in National Network of Public Administration "SYZEFXIS"
 
El paradigma de la pedagogia dialogante
El paradigma de la pedagogia dialoganteEl paradigma de la pedagogia dialogante
El paradigma de la pedagogia dialogante
 
Historia de la educación
Historia de la educaciónHistoria de la educación
Historia de la educación
 
Del triunfo del cristianismo a la crisis
Del triunfo del cristianismo a la crisis Del triunfo del cristianismo a la crisis
Del triunfo del cristianismo a la crisis
 
Historia de la educación
Historia de la educaciónHistoria de la educación
Historia de la educación
 
La guerra del peloponeso
La guerra del peloponeso La guerra del peloponeso
La guerra del peloponeso
 
La escuela moderna francesa
La escuela moderna francesaLa escuela moderna francesa
La escuela moderna francesa
 
La guerra del Peloponeso
La guerra del Peloponeso La guerra del Peloponeso
La guerra del Peloponeso
 
La escuela moderna francesa
La escuela moderna francesaLa escuela moderna francesa
La escuela moderna francesa
 
El paradigma de la pedagogia dialogante
El paradigma de la pedagogia dialoganteEl paradigma de la pedagogia dialogante
El paradigma de la pedagogia dialogante
 

Ähnlich wie Syzefxis security stellakis

Connected roadways external launch feb26 revised_final.ptx
Connected roadways external launch feb26 revised_final.ptxConnected roadways external launch feb26 revised_final.ptx
Connected roadways external launch feb26 revised_final.ptxbrigel529
 
Business Development, Industry Solutions, Internet of Everything Cisco India ...
Business Development, Industry Solutions, Internet of Everything Cisco India ...Business Development, Industry Solutions, Internet of Everything Cisco India ...
Business Development, Industry Solutions, Internet of Everything Cisco India ...IPPAI
 
telebriefing-150415-ericssons-security-solutions
telebriefing-150415-ericssons-security-solutionstelebriefing-150415-ericssons-security-solutions
telebriefing-150415-ericssons-security-solutionsFakher Oueslati
 
Internet of everything #IoE
Internet of everything #IoEInternet of everything #IoE
Internet of everything #IoEMatteo Masi
 
Policy Cloud Data Driven - Policies against Radicalisation
Policy Cloud Data Driven - Policies against RadicalisationPolicy Cloud Data Driven - Policies against Radicalisation
Policy Cloud Data Driven - Policies against RadicalisationBig Data Value Association
 
Policy Cloud Data Driven Policies against Radicalisation
Policy Cloud Data Driven Policies against RadicalisationPolicy Cloud Data Driven Policies against Radicalisation
Policy Cloud Data Driven Policies against RadicalisationBig Data Value Association
 
Cisco mwc2013 barcelona
Cisco mwc2013 barcelonaCisco mwc2013 barcelona
Cisco mwc2013 barcelonaIT Tech
 
Cloud Asia Day 1 11.20 -11.40 Toru Nakamura
Cloud Asia Day 1 11.20 -11.40 Toru NakamuraCloud Asia Day 1 11.20 -11.40 Toru Nakamura
Cloud Asia Day 1 11.20 -11.40 Toru NakamuraCloudExpoAsia
 
Chris Swan's presentation from the London Tech Entrepreneurs' Meetup
Chris Swan's presentation from the London Tech Entrepreneurs' MeetupChris Swan's presentation from the London Tech Entrepreneurs' Meetup
Chris Swan's presentation from the London Tech Entrepreneurs' MeetupCohesive Networks
 
Cloud computing_LKYSPP GSP 2019
Cloud computing_LKYSPP GSP 2019Cloud computing_LKYSPP GSP 2019
Cloud computing_LKYSPP GSP 2019Jenny Jenish kyzy
 
Internet of Cars, Andreas Mai, Cisco Systems
Internet of Cars, Andreas Mai, Cisco SystemsInternet of Cars, Andreas Mai, Cisco Systems
Internet of Cars, Andreas Mai, Cisco SystemsAndreas Mai
 
Internet of Everything. El Reto de la Innovación
Internet of Everything. El Reto de la InnovaciónInternet of Everything. El Reto de la Innovación
Internet of Everything. El Reto de la InnovaciónAMETIC
 
Ericsson Technology Review - Issue1 2015
Ericsson Technology Review - Issue1 2015Ericsson Technology Review - Issue1 2015
Ericsson Technology Review - Issue1 2015Ericsson
 
BigDataPilotDemoDays - I BiDaaS Application to the Manufacturing Sector Webinar
BigDataPilotDemoDays - I BiDaaS Application to the Manufacturing Sector WebinarBigDataPilotDemoDays - I BiDaaS Application to the Manufacturing Sector Webinar
BigDataPilotDemoDays - I BiDaaS Application to the Manufacturing Sector WebinarBig Data Value Association
 
Cómo usar la tecnología para generar más Seguridad y desarrollo local
Cómo usar la tecnología para generar más Seguridad y desarrollo localCómo usar la tecnología para generar más Seguridad y desarrollo local
Cómo usar la tecnología para generar más Seguridad y desarrollo localAdrian Mikeliunas
 
El IoT y la gestión de las empresas del futuro, IGNASI ERRANDO, CISCO
El IoT y la gestión de las empresas del futuro, IGNASI ERRANDO, CISCOEl IoT y la gestión de las empresas del futuro, IGNASI ERRANDO, CISCO
El IoT y la gestión de las empresas del futuro, IGNASI ERRANDO, CISCODomotys
 
Big Data Expo 2015 - Cisco Connected Analytics
Big Data Expo 2015 - Cisco Connected AnalyticsBig Data Expo 2015 - Cisco Connected Analytics
Big Data Expo 2015 - Cisco Connected AnalyticsBigDataExpo
 

Ähnlich wie Syzefxis security stellakis (20)

Connected roadways external launch feb26 revised_final.ptx
Connected roadways external launch feb26 revised_final.ptxConnected roadways external launch feb26 revised_final.ptx
Connected roadways external launch feb26 revised_final.ptx
 
Business Development, Industry Solutions, Internet of Everything Cisco India ...
Business Development, Industry Solutions, Internet of Everything Cisco India ...Business Development, Industry Solutions, Internet of Everything Cisco India ...
Business Development, Industry Solutions, Internet of Everything Cisco India ...
 
telebriefing-150415-ericssons-security-solutions
telebriefing-150415-ericssons-security-solutionstelebriefing-150415-ericssons-security-solutions
telebriefing-150415-ericssons-security-solutions
 
Internet of everything #IoE
Internet of everything #IoEInternet of everything #IoE
Internet of everything #IoE
 
Policy Cloud Data Driven - Policies against Radicalisation
Policy Cloud Data Driven - Policies against RadicalisationPolicy Cloud Data Driven - Policies against Radicalisation
Policy Cloud Data Driven - Policies against Radicalisation
 
Policy Cloud Data Driven Policies against Radicalisation
Policy Cloud Data Driven Policies against RadicalisationPolicy Cloud Data Driven Policies against Radicalisation
Policy Cloud Data Driven Policies against Radicalisation
 
Cisco mwc2013 barcelona
Cisco mwc2013 barcelonaCisco mwc2013 barcelona
Cisco mwc2013 barcelona
 
Cloud Asia Day 1 11.20 -11.40 Toru Nakamura
Cloud Asia Day 1 11.20 -11.40 Toru NakamuraCloud Asia Day 1 11.20 -11.40 Toru Nakamura
Cloud Asia Day 1 11.20 -11.40 Toru Nakamura
 
Fortinet k
Fortinet kFortinet k
Fortinet k
 
Chris Swan's presentation from the London Tech Entrepreneurs' Meetup
Chris Swan's presentation from the London Tech Entrepreneurs' MeetupChris Swan's presentation from the London Tech Entrepreneurs' Meetup
Chris Swan's presentation from the London Tech Entrepreneurs' Meetup
 
Cloud computing_LKYSPP GSP 2019
Cloud computing_LKYSPP GSP 2019Cloud computing_LKYSPP GSP 2019
Cloud computing_LKYSPP GSP 2019
 
Internet of Cars, Andreas Mai, Cisco Systems
Internet of Cars, Andreas Mai, Cisco SystemsInternet of Cars, Andreas Mai, Cisco Systems
Internet of Cars, Andreas Mai, Cisco Systems
 
Big Data Pilot Days
Big Data Pilot DaysBig Data Pilot Days
Big Data Pilot Days
 
Internet of Everything. El Reto de la Innovación
Internet of Everything. El Reto de la InnovaciónInternet of Everything. El Reto de la Innovación
Internet of Everything. El Reto de la Innovación
 
Ericsson Technology Review - Issue1 2015
Ericsson Technology Review - Issue1 2015Ericsson Technology Review - Issue1 2015
Ericsson Technology Review - Issue1 2015
 
BigDataPilotDemoDays - I BiDaaS Application to the Manufacturing Sector Webinar
BigDataPilotDemoDays - I BiDaaS Application to the Manufacturing Sector WebinarBigDataPilotDemoDays - I BiDaaS Application to the Manufacturing Sector Webinar
BigDataPilotDemoDays - I BiDaaS Application to the Manufacturing Sector Webinar
 
WCIT 2016 Jan Ming Ho
WCIT 2016 Jan Ming HoWCIT 2016 Jan Ming Ho
WCIT 2016 Jan Ming Ho
 
Cómo usar la tecnología para generar más Seguridad y desarrollo local
Cómo usar la tecnología para generar más Seguridad y desarrollo localCómo usar la tecnología para generar más Seguridad y desarrollo local
Cómo usar la tecnología para generar más Seguridad y desarrollo local
 
El IoT y la gestión de las empresas del futuro, IGNASI ERRANDO, CISCO
El IoT y la gestión de las empresas del futuro, IGNASI ERRANDO, CISCOEl IoT y la gestión de las empresas del futuro, IGNASI ERRANDO, CISCO
El IoT y la gestión de las empresas del futuro, IGNASI ERRANDO, CISCO
 
Big Data Expo 2015 - Cisco Connected Analytics
Big Data Expo 2015 - Cisco Connected AnalyticsBig Data Expo 2015 - Cisco Connected Analytics
Big Data Expo 2015 - Cisco Connected Analytics
 

Kürzlich hochgeladen

Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningLars Bell
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 

Kürzlich hochgeladen (20)

Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine Tuning
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 

Syzefxis security stellakis

  • 1. The Security of National Network of Public Administration «SYZEFXIS» Dr. Haris Stellakis Program Portfolio Manager, Chief Security Officer of “SYZEFXIS” Network Information Society SA March 4, 2015
  • 2. 2000 –2001–2002–2003–2004–2005–2006 2007– 2008 – 2009 – 2010 – 2011 – 2012 – 2013 2020 3rd Community Support Framework 4th Community Support Framework 5th Community Support Framework Establishment of Information Society SA 2 A Life-long Partner 900M€ 1,300M€ Acquisition of DIGITAL AID SA Acquisition of Observatory of Digital Greece SA Dr. Haris Stellakis – 03/2015
  • 3. The Role of Information Society SA 3 Public Administration CitizensBusinesses Implements Facilitates State AidsObserves Informatics •~ 180 M€ Public Reform •~ 70 Μ€ Telecommunications •Syzefxis •MAN •Rural Broadband Dr. Haris Stellakis – 03/2015
  • 4. SYZEFXIS ΙΙ (600 Μ€) RURAL (160 Μ€) Supplemental Actions for SYZEFXIS II (10 Μ€) SYZEFXIS Ι (45 Μ€) ΜΑΝ (5 Μ€) Planning Tender Auctions Implementation Operations Effort by Vendors Effort by I.S. SA Telecom Projects Dr. Haris Stellakis – 03/2015
  • 5. SYZEFXIS: The State’s Telecom backbone 5 Interoperability and Apps G2B / G2C  Ministries – General Secretaries  Municipalities  Citizen Service Centers  Financial Agencies  Health Agencies  Citizen Protection Agencies (Police, etc)  Armed Forces  EU Agencies  Justice Courts  Independent Agencies Dr. Haris Stellakis – 03/2015
  • 6. SYZEFXIS: 2006-2013 6 Agency Type Access Speed Agencies ADSL 24/1 Μbps 1428 3G 2/1 Mbps 50 SMALL 2/2 Mbps 2488 MEDIUM 4-8/4-8 Mbps 434 LARGE 34/34 Mbps 85 TOTAL 4485  Free broadband access (2 – 34 Mbps)  Free onnet telephony services as well as offnet at competitive prices  Free webhosting or routing to external ISPs  Same for email services  Connection to EU Netowork “S-Testa”  Free teleconferencing services to specific deployments Dr. Haris Stellakis – 03/2015
  • 7. SYZEFXIS Ι: 2013-14 7 PoP OTE MAN Switch Router ΣΥΖΕΥΞΙΣ Ι Router ΣΥΖΕΥΞΙΣ Ι MAN Switch Router ΣΥΖΕΥΞΙΣ Ι SHDSL modem πρόσβασης Κόμβος Πρόσβασης ΜΑΝ ΜΑΝ PBX PBX PBX Kύριος κόμβος ΜΑΝ (ΚΚ) Κόμβος ΜΑΝ πλησιέστερος στον ΟΤΕ FE FE FE PRA PRA PRA GE GE GE 2Mbps X.21 X.21 Router ΣΥΖΕΥΞΙΣ Ι PBX PRA Κόμβος Πρόσβασης ΜΑΝ FEGE ή FE MAN Switch FE FE FE Metropolitan Area Fiber Optic Networks Dr. Haris Stellakis – 03/2015
  • 8. SYZEFXIS ΙΙ: 2015-2018 8 S 0 5000 10000 15000 20000 25000 30000 35000 2005 2006 2008 2009 2010 2014 1.800 3.000 3.250 4.450 6.000 34.000 SIZE SPEED (Μbps) 1 ADSL 24/1 2 SMALL 10/10 3 MEDIUM 100/100 4 LARGE 1000/1000 Secure broadband connection to 34.000 public points and provision of telecom / multimedia services  50% reduction to annual OPEX  Wireless access services 55.000 Government Agents through the subsidization of smartphones  Secure services to Public Sector Dr. Haris Stellakis – 03/2015
  • 9. SYZEFXIS ΙΙ: 5 Subprojects 9 SIX / DC Wireless Islet Νησίδες 1-9 Telecom Islets 1-8 Security / Telephony / Teleconferenci ng / Cabling ISP / SLA Dr. Haris Stellakis – 03/2015
  • 10. 10 Security in SYZEFXIS Ι (1/4) Multi-stage Security Architecture:  Provision of different VPNs per Agency and/or App  Perimeter Security against the Internet • Private ΙΡ addressing • Connection through proxy  Centrally managed Security devices • Firewalls &Intrusion Detection Systems • Antivirus & antispam mechanisms • Multiple profile Web content filtering services  Perimeter Security per Islet • Intra-VPN communication for specific apps / services, through the use of access lists • Control of Intra-VPN traffic Dr. Haris Stellakis – 03/2015
  • 11. 11 Security in SYZEFXIS Ι (2/4) Security Policy:  Within SYZEFXIS • Intra-VPN traffic • Inter-VPN traffic  Outside of SYZEFXIS • Internet • Educational Network “EDET” • EU Network s-Testa  The perimeter security lifting is subjected to approval by Information Society SA  Software control mechanisms  User’s information Perimeter Security lifting Ticket submission Evaluation by IS SA Reporting to Vendor Ticket implementation (upon approval) Reporting to Applicant Agency Dr. Haris Stellakis – 03/2015
  • 12. 12 Security in SYZEFXIS Ι (3/4) The role of Information Society SA:  To monitor the project vendors  To support the public Agencies  To implement and improve the security policy  To leverage the collected knowledge towards the design of next G SYZEFXIS 0 10 20 30 40 50 60 Αιτήματα Φορέων 0 20 40 60 80 100 120 140 160 180 Περιφέρειες - Δήμοι Νοσοκομεία ΕΛΑΣ - Πυροσβεστική - Λιμενικό Οικονομικές Υπηρεσίες Υπουργεία - Γεν Γραμματείες Υπηρεσίες Κοιν Αλλυλεγγύης - Ασφ. Ταμεία Πολεοδομίες ΕΥΔ Προγραμμάτων ΕΕ Μουσεία Λοιπές Δ.Υ. Κατηγορίες Φορέων 39% 26% 20% 6% 3% 3% 2% 1% Κατηγορίες Αιτημάτων Άνοιγμα επιπλέον onnet θυρών Απόδοση πραγματικής δ/σης ΙΡ Άνοιγμα επιπλέον ofnet θυρών Πρόσβαση σε site Ρυθμίσεις CPE Παράκαμψη proxy Επικοινωνία με άλλα δίκτυα Ενημέρωση DNS Dr. Haris Stellakis – 03/2015
  • 13. 13 Security in SYZEFXIS Ι (4/4) State Elections through SYZEFXIS:  Levaraging of telephone infrastructure Municipalities Prefectures Ministry of Interiors  Leveraging of internet infrastructure  Creation of a VPN between MoI, SingularLogic and Zappeio Megaro for the communication of results  Full functionality was tested on a wide scale drill (5/2014) 2014 and 2015 Elections were completed succesfully Dr. Haris Stellakis – 03/2015
  • 14. 14 Security in SYZEFXIS ΙΙ (1/5) Security/ Telephony / Teleconferenci ng / Cabling Independent Security Auditor (1,3 Μ€) Infrastructure Services A combination of Actions Dr. Haris Stellakis – 03/2015
  • 15. 15 Security in SYZEFXIS ΙΙ (2/5) Security Infrastructure and Services:  Procurement of suitable security equipment  Development of a security management information system  Operation services based on SLAs (Routing, QoS)  Security Services • IP Firewall, IPS, VPN, Email & Web Antivirus- Antispam, Web Content Filtering  User training Dr. Haris Stellakis – 03/2015
  • 16. 16 Security in SYZEFXIS ΙΙ (3/5) State-of-the-art Architecture:  Leveraging IPSEC VPN technologies  Ability to support multiple vendors in contract framework  Ability to support gradual deployment  Ability to upgrade security level for some sensitive Agencies, through the use of special-purpose encrypting devices Κ.Υ.Α. (Ανάδοχος 1) Κ.Υ.Α. (Ανάδοχος 2) Κ.Υ.Α. (Ανάδοχος Ν) Κ.Σ.Α. Περιφερειακές Συσκευές Ασφάλειας (Αναδόχου 1) Περιφερειακές Συσκευές Ασφάλειας (Αναδόχου 2) Περιφερειακές Συσκευές Ασφάλειας (Αναδόχου Ν) Creation of VPNs Φορείς εκτός ΣΥΖΕΥΞΙΣ ΙΙ Dr. Haris Stellakis – 03/2015
  • 17. 17 Security in SYZEFXIS ΙΙ (4/5) Independent Security Auditor:  Development of an ISO 27001 based ISMS  Network security auditing  Development of a specialized Information System for Security Control and Management  Consulting services / security “think tank” Dr. Haris Stellakis – 03/2015
  • 18. 18 Security in SYZEFXIS ΙΙ (5/5) At the operational level:  Creation of an independent Department for Telecommunication projects • Discrete group for SYZEFXIS  Creation of a task force among all stakeholders • Infomarmation Society SA • Project vendors • Public Agencies • Ministry of Public Reform • Other Agencies(ie, Greek FCC, etc) ΚτΠ ΑΕ ΥΕΔΑ Δημόσιοι Φορείς Ανάδοχοι Έργων Ελεγκτής Ασφάλειας Λοιποί Φορείς Dr. Haris Stellakis – 03/2015
  • 19. 19 Epilogue Information Society, in collaboration with:  Ministry of Public Reform,  The EU Managing Authorities, and  The project vendors Facilitate:  The terms and specs,  The framework and procedures,  The tools and mechanisms, and  The resources That assure the security of SYZEFXIS network and therefore the flawless operation of Greek Public Sector. Dr. Haris Stellakis – 03/2015
  • 20. 20 The End We thank you for your attention! Dr. Haris Stellakis – 03/2015