Computer Security: Hot Review Summer, Cool Deployment Autumn
Written by:
Computer Security Office
—

This summer has seen a plethora of different assessments of the Organization’s security posture and stance. While an external vulnerability scan of CERN’s Internet presence and a red-teaming penetration test are still ongoing, the Computer Security Office, in collaboration with the IT Department, is continuing to mitigate the findings of the 2023 cybersecurity audit, the 2025 review of CERN’s active directory and the password cracking exercise of 2026. Let’s dive deep.
The external vulnerability scan is a repeated exercise to identify weaknesses, vulnerabilities and misconfigurations in CERN’s current total of 8689 public websites (and millions of webpages) and 2713 interactive servers. Given these vast numbers and the very frequent changes in this Internet presence, such a scan is contracted to a different company every year. And their results and the quality of the results vary a lot… In parallel, the CERN WhiteHat Challenge is still running. Here, cybersecurity and computer science students from partnering institutes poke around for problems in CERN’s websphere, for the benefit of their own education and training and for CERN’s benefit to further improve its security posture. Indeed, there are always areas for improvement, webpages with broken or vulnerable features, orphaned and outdated websites and configurations that are (security-wise) plainly wrong. If you are operating a website yourself, have a look at these Security Principles for Web Applications to see how best to proceed!
The red-teaming exercise goes beyond the vulnerability scans: it aims at infiltrating CERN with the goal of showing how to create damage. Seven objectives were set for the exercise in 2020 but are being executed only now, with the start of LS3. It has been assigned to the cybersecurity ministry of one of CERN’s Host States, whose specialists have been tasked with showing how to compromise CERN’s active directory, exfiltrate confidential documents, create fraudulent invoices, manipulate CERN’s domain name servers, deploy a malicious virtual machine on CERN’s OpenStack service, take over a CERN-specified control system and introduce malware into the software stack on the technical network. This exercise, of course, has been designed to be ethical in order to fully preserve CERN’s operations, data integrity and functioning. One lesson has already been learnt, and, as a result, the CERN Identity Management Team will deploy additional brute-force protections for CERN logins later this summer. Stay tuned for more about this!
While the red-teaming penetration test and the vulnerability scans continue, the IT Department and the Computer Security Office are preparing to deploy a series of additional computer security measures once all the accelerators have been stopped. The remaining eleven (of 95) work tasks, which are based on the recommendations of the 2023 cybersecurity audit, for example, will be implemented over the coming months. The recommendations of that audit included deployment of two-factor authentication to protect access to the technical network (TN) and the virtual machines used for TN development; a ban on the use of service accounts for remote CERN Single Sign-On log-ins and on the use of single-factor SSH-key access to LXTUNNEL from outside CERN; introduction of a new, encrypted wireless network using WPA3 protection; the launch and full configuration of the TN firewall before the restart of the injector complex in 2028; and the subsequent creation of another firewall separating the campus network from and protecting the Data Centre networks. In parallel, the findings related to last year’s review of CERN’s active directory will trigger a series of configuration improvements, such as the enforcement of LDAPS, as well as the termination of Kerberos delegation and use of DES encryption; enabling of UNC path protection, SMB password encryption and enhanced phishing protection; and disabling of “Custom Security Support Providers” on locally managed Windows PCs. Have a look whether this affects your services and systems if you haven’t already done so. In addition, as the AD has grown complex and vast, some clean up removing inactive devices has been scheduled. Finally, the password cracking exercise has pointed to several areas for improvement, and account owners will be informed if their password still adheres to the old password policy (eight characters minimum) rather than the new one (15 characters). For operational reasons, this was very much the case for service accounts, but LS3 has opened a window of opportunity to change this.
While the hot “review” summer comes to an end, autumn lies ahead of us, with the deployment of many additional cool and beneficial security measures. Have a look, reach out to us if you have any questions, and thanks a lot for helping to make the Organization secure!
__________
Do you want to learn more about computer security incidents and issues at CERN? Follow our Monthly Report. For further information, questions or help, check our website or contact us at Computer.Security@cern.ch.