How the JPL works to secure its missions from adversaries
techcrunch.com
techcrunch.com
What's abnormal about that statement is that it is now considered normal.
We as people used to call these 'projects'.. I fail to see how a funded mission within a gov't organization which will never sell anything is anything at all like a small company bootstrapping a commercial product..
But man, talking about "the JPL" reads awkwardly.
This is a fairly standard infosec method already in use for a long time (defense in depth, enclave-based security architectures, etc).
Not knocking them - JPL are wonderful people. If I had to guess they did not have funding for this prior, got caught (embarrassed) and now are correctly allocating resources to deal with the issue. Good news!
You can see what they’re looking for here https://jpl.jobs/
Here’s Arun Viswanathan’s google scholar page: https://scholar.google.com/citations?user=jdotmygAAAAJ&hl=en
In order words, I think what they're trying to work from is that their existing systems don't present a unified or homogeneous set of interfaces or design or control. What they're trying to solve is how to fit a homogeneous interface onto their existing mess.
I think that this is probably the main purpose of the system. The is-ought problem can become very tricky to manage with a complex network, especially if the team is on the larger size or geographically distributed.
Access in any of cafeterias (there’s more than 1) over WiFi is limited to common systems and the internet. There was no Cat5/6 in the cafeterias. There was also a further limited Guest WiFi network for media, guests and the like with bandwidth limited access to the internet only.
Some of the specific accomplishments in OP (network inventory, network topology) seem related to this intrusion: https://www.drizgroup.com/driz_group_blog/nasas-jet-propulsi...
When someone is granted access to a new resource, do you have to move them to a different network segment? What if there's not already a segment with the right combination of resources? Provision a new one on the fly? Or maybe grant more access than needed at the same time? We just have nginx check if you have the required LDAP group for the URL before forwarding into production. Typically one group per tool.
What about temporary access? There are tools at my workplace where manager approval gets you access for 24 hours. As I understand it, there's just a cron job purging people every so often at which point nginx will start bouncing you again. Can you do something similar with VLANs? Is that sane?
These are nation-level assets. You're going to protect them much more heavily & securely than a corporate website. You can't allow a hostile attacker in for even a fraction of a second, so guest access will be strongly vetted, and networks will be protected by physical isolation.