<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Network &#38; Information Technology Security</title>
	<atom:link href="http://suningbits3413.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://suningbits3413.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Fri, 30 Oct 2009 21:14:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='suningbits3413.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Network &#38; Information Technology Security</title>
		<link>http://suningbits3413.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://suningbits3413.wordpress.com/osd.xml" title="Network &#38; Information Technology Security" />
	<atom:link rel='hub' href='http://suningbits3413.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Lab Test</title>
		<link>http://suningbits3413.wordpress.com/2009/10/22/lab-test/</link>
		<comments>http://suningbits3413.wordpress.com/2009/10/22/lab-test/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 10:09:08 +0000</pubDate>
		<dc:creator>tansn</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://suningbits3413.wordpress.com/?p=94</guid>
		<description><![CDATA[22/10/09 LAB TEST Today is our lab test of this subject, there were 3 questions and we only have to answer 2 out of these 3 questions. I had no idea on how to answer question 2.  So, I had no choice.  I had to answer question 1 and question 3.  Question 3 is easier [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=94&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>22/10/09</strong></p>
<p><strong>LAB TEST</strong></p>
<p>Today is our lab test of this subject, there were 3 questions and we only have to answer 2 out of these 3 questions. I had no idea on how to answer question 2.  So, I had no choice.  I had to answer question 1 and question 3.  Question 3 is easier than Question 1. I couldnn&#8217;t answer question 1 well.  Hopefully my merciful lecturer can give me a good mark. Haha!!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/suningbits3413.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/suningbits3413.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/suningbits3413.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/suningbits3413.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/suningbits3413.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/suningbits3413.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/suningbits3413.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/suningbits3413.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/suningbits3413.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/suningbits3413.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/suningbits3413.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/suningbits3413.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/suningbits3413.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/suningbits3413.wordpress.com/94/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=94&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://suningbits3413.wordpress.com/2009/10/22/lab-test/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a5c7f9aa9108be188e125a3f0885a4b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tansn</media:title>
		</media:content>
	</item>
		<item>
		<title>Last Lecture</title>
		<link>http://suningbits3413.wordpress.com/2009/10/21/last-lecture/</link>
		<comments>http://suningbits3413.wordpress.com/2009/10/21/last-lecture/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 07:46:27 +0000</pubDate>
		<dc:creator>tansn</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://suningbits3413.wordpress.com/?p=92</guid>
		<description><![CDATA[21/10/09 INTRUSION DETECTION SYSTEM (IDS), LEGAL AND ETHICAL ISSUES IN COMPUTER SECURITY YES!!It&#8217;s the last lesson for the subject BITS3413.  But, I quite interested in this subject. Today, Mr Zaki taught us about IDS and Legal and Ethical Issues in Computer Security. The lecture begins with the topic &#8220;Intruders&#8221;.  So, who are the intruders??Me??Hope so&#8230;haha&#8230; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=92&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>21/10/09</strong></p>
<p><strong>INTRUSION DETECTION SYSTEM (IDS), LEGAL AND ETHICAL ISSUES IN COMPUTER SECURITY</strong></p>
<p>YES!!It&#8217;s the last lesson for the subject BITS3413.  But, I quite interested in this subject.</p>
<p>Today, Mr Zaki taught us about IDS and Legal and Ethical Issues in Computer Security.</p>
<p>The lecture begins with the topic &#8220;Intruders&#8221;.  So, who are the intruders??Me??Hope so&#8230;haha&#8230;</p>
<p><span style="color:#000080;"><em><strong>Examples of intruders:</strong></em></span></p>
<ul>
<li>significant issue hostile / unwanted trespass</li>
<li>user trespass</li>
<li>software trespass</li>
</ul>
<p><span style="color:#000080;"><em><strong>Examples of intrusion:</strong></em></span></p>
<ul>
<li>
<div>remote root compromise</div>
</li>
<li>
<div>web server defacement</div>
</li>
<li>
<div>guessing / cracking passwords</div>
</li>
<li>
<div>copying viewing sensitive data / databases</div>
</li>
<li>
<div>running a packet sniffer</div>
</li>
<li>
<div>distributing pirated software</div>
</li>
<li>
<div>using an unsecured modem to access net</div>
</li>
<li>
<div>impersonating a user to reset password</div>
</li>
<li>
<div>using an unattended workstation</div>
</li>
</ul>
<p>Intrusion Detection can be classified as <em><span style="color:#ff9900;">Host-based</span></em> and <span style="color:#ff9900;"><em>Network-based</em></span>. Host-based IDS is to monitor single host activity; whereas Network-based IDS is to monitor the network traffic.</p>
<p><span style="color:#000080;"><em><strong>Requirements of IDS: </strong></em></span></p>
<ul>
<li>
<div>run continually</div>
</li>
<li>
<div>be fault tolerant</div>
</li>
<li>
<div>resist subversion</div>
</li>
<li>
<div>impose a minimal overhead on system</div>
</li>
<li>
<div>configured according to system security policies</div>
</li>
<li>
<div>adapt to changes in systems and users</div>
</li>
<li>
<div>scale to monitor large numbers of systems</div>
</li>
<li>
<div>provide graceful degradation of service</div>
</li>
<li>
<div>allow dynamic reconfiguration</div>
</li>
</ul>
<p><strong><em><span style="color:#000080;">3 types of Intrusion Detection Techniques:</span></em></strong></p>
<ul>
<li>signature detection</li>
<li>anomaly detection</li>
<li>when potential detected sensor sends an alert and logs information</li>
</ul>
<p><strong><span style="color:#800080;">SNORT</span></strong> is the lightweight IDS that is used for real time packet capture and rule analysis.</p>
<p>The last chapter of this subject is Legal and Ethical Issues in Computer Security.  This chapter focuses on relevant legislation and regulation concerning the management of information in an organization. It presents ethical issues for information security as well as a summary of professional organizations with established ethical codes too.</p>
<p>The differences of law and ethic are as below:</p>
<p><span style="color:#339966;"><strong>1. Law</strong></span></p>
<ul>
<li>Formal, documented</li>
<li>Interpreted by courts</li>
<li>Established by legislature representing everyone</li>
<li>Applicable to everyone</li>
<li>Enforceable by police and courts</li>
</ul>
<p><strong><span style="color:#339966;">2. Ethic</span></strong></p>
<ul>
<li>Described by unwritten principles</li>
<li>Interpreted by individuals</li>
<li>Presented by philosophers, religions, professional group</li>
<li>Personal choice</li>
<li>Priority determined by individual if two principles conflict</li>
<li>Self-practice</li>
</ul>
<p>The three ways protecting programs and data are trade secret, copyrights and patents. Although open-source software are free, they are also protected by copyright protection.  The issues related to Information are information commerce, electronic publishing and database.</p>
<p><span style="color:#000080;"><em><strong>Methods for examining a case of ethical issues:</strong></em></span></p>
<ul>
<li>
<div>Understand the situation. Determine the issues involved.</div>
</li>
<li>
<div>Know several theories of ethical reasoning</div>
</li>
<li>
<div>List the ethical principles involved</div>
</li>
<li>
<div>Determine which principles outweigh others.</div>
</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/suningbits3413.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/suningbits3413.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/suningbits3413.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/suningbits3413.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/suningbits3413.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/suningbits3413.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/suningbits3413.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/suningbits3413.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/suningbits3413.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/suningbits3413.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/suningbits3413.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/suningbits3413.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/suningbits3413.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/suningbits3413.wordpress.com/92/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=92&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://suningbits3413.wordpress.com/2009/10/21/last-lecture/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a5c7f9aa9108be188e125a3f0885a4b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tansn</media:title>
		</media:content>
	</item>
		<item>
		<title>Lab 7</title>
		<link>http://suningbits3413.wordpress.com/2009/10/15/lab-7/</link>
		<comments>http://suningbits3413.wordpress.com/2009/10/15/lab-7/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 12:45:21 +0000</pubDate>
		<dc:creator>tansn</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://suningbits3413.wordpress.com/?p=89</guid>
		<description><![CDATA[15/10/09 WEP PASSWORD CRACKING During this lab session, we learn how to use Backtrack 2 to crack WEP.  To do this lab, 1 wireless router that is accessed by several workstations is needed.  Backtrack 2 is an OS that completed with cracking and hacking tools.  It was developed by Linux.  The more workstations accessed to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=89&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>15/10/09</strong></p>
<p><strong>WEP PASSWORD CRACKING</strong></p>
<p>During this lab session, we learn how to use Backtrack 2 to crack WEP.  To do this lab, 1 wireless router that is accessed by several workstations is needed.  Backtrack 2 is an OS that completed with cracking and hacking tools.  It was developed by Linux.  The more workstations accessed to wireless router, the time taken to crack the WEP will be shorter.  This is because the number of packets sent are directly proportional to the number of workstations available for the WLAN.</p>
<p>Several commands learned in this lab in order to crack WEP:</p>
<ul>
<li>
<div>iwconfig &#8211;&gt;to check wireless lan setting</div>
</li>
<li>
<div>ifconfig [name of device] up &#8211;&gt;to start the service</div>
</li>
<li>
<div>iwconfig [name] mode monitor</div>
</li>
<li>-airmon-ng</li>
<li>-airodunm-ng</li>
<li>-aireplay-ng</li>
</ul>
<p>This lab is really fun.  But, we can&#8217;t get the result yet because the time is not enough for us to do so.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/suningbits3413.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/suningbits3413.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/suningbits3413.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/suningbits3413.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/suningbits3413.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/suningbits3413.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/suningbits3413.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/suningbits3413.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/suningbits3413.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/suningbits3413.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/suningbits3413.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/suningbits3413.wordpress.com/89/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/suningbits3413.wordpress.com/89/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/suningbits3413.wordpress.com/89/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=89&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://suningbits3413.wordpress.com/2009/10/15/lab-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a5c7f9aa9108be188e125a3f0885a4b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tansn</media:title>
		</media:content>
	</item>
		<item>
		<title>Lecture 7</title>
		<link>http://suningbits3413.wordpress.com/2009/10/14/lecture-7/</link>
		<comments>http://suningbits3413.wordpress.com/2009/10/14/lecture-7/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 11:23:50 +0000</pubDate>
		<dc:creator>tansn</dc:creator>
				<category><![CDATA[Network and IT Sec]]></category>

		<guid isPermaLink="false">http://suningbits3413.wordpress.com/?p=87</guid>
		<description><![CDATA[14 Oct 09 WIRELESS SECURITY, FIREWALL Equipments: Wireless station &#8211; with a wireless NIC Access point &#8211; bridge between wireless and wired networks; composed of Radio,Wired network interface (usually 802.3),Bridging software Aggregates access for multiple wireless stations to wired network Wireless mode: Infrastructure mode / Basic Service Set (BSS): All workstations are connected to access [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=87&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>14 Oct 09</strong></p>
<p><strong>WIRELESS SECURITY, FIREWALL</strong></p>
<p><em><strong><span style="color:#000080;">Equipments</span></strong></em>:</p>
<ul>
<li>Wireless station &#8211; with a wireless NIC</li>
<li>Access point &#8211; bridge between wireless and wired networks; composed of Radio,Wired network interface (usually 802.3),Bridging software</li>
<li>Aggregates access for multiple wireless stations to wired network</li>
</ul>
<p><span style="color:#000080;"><em><strong>Wireless mode</strong></em></span>:</p>
<ul>
<li><em>Infrastructure mode / Basic Service Set (BSS)</em>: All workstations are connected to access point</li>
<li><em>Extended Service Set</em>: Two or more BSSs connect together to form a single subnet.</li>
<li><em>Ad hoc / peer-to-peer</em>: independent BSS, Set of 802.11 wireless stations that communicate directly without an access point.  It is useful for quick &amp; easy wireless networks.</li>
</ul>
<p><span style="color:#000080;"><em><strong>Basic security services defined by IEEE for WLAN:</strong></em></span></p>
<ul>
<li>
<div>Authentication – to provide a security service for verification the identity of communicating client stations.</div>
</li>
<li>
<div>Integrity – to ensure that messages are not modified in transit between the wireless clients and the access point in an active attack.</div>
</li>
<li>Confidentiality – to provide “privacy achieved by a wired network”</li>
</ul>
<p>Each wireless access point have their service set identifier (SSID) and AP broadcast their SSID. Wireless AP also have Access Control List that list the mac address of client to restric other pc connected to it. Wireless signal is weakened by walls, floors and interference.</p>
<p>Two security services provided by 802.11b are authentication(Shared Key Authentication) and encryption (Wired Equivalence Privacy). There are two encrytion method which are WEP and WPA. WEP use RC4 for encryption.  It is a symmetric key encryption which applying RSA encryption algorithm.</p>
<p><span style="color:#000080;"><em><strong>3 processes for WEP sending: </strong></em></span></p>
<ul>
<li>Compute Integrity Check Vector (ICV)</li>
<li>Encrypt plaintext via RC4</li>
<li>Transmit the ciphertext</li>
</ul>
<p><span style="color:#000080;"><em><strong>802.11 safeguards:</strong></em></span></p>
<ul>
<li>
<div>Security Policy and Architecture Design</div>
</li>
<li>
<div>Treat it as untrusted LAN</div>
</li>
<li>
<div>Discover unauthorized use</div>
</li>
<li>
<div>Access point audits</div>
</li>
<li>
<div>Station protection</div>
</li>
<li>
<div>Access point location</div>
</li>
<li>
<div>Antenna design</div>
</li>
</ul>
<p>Nowadays, WEP is not secure because there are many tools out there such as airsnort and wepcrack are used to attack WEP encryption. Wi-Fi Protected Access (WPA) is used to overcome the weakness of WEP.  But, there is no proper way to prevent the hackers out there.  The two practical attacks of WPA are dictionary attack on pre-shared key mode and denial of attack.</p>
<p>After chapter of WIRELESS SECURITY, we took a 5 minutes break.  After took 5, the lecture continue with the chapter entitled &#8220;FIREWALL&#8221;.</p>
<p><span style="color:#ff0000;"><em><strong>Firewall</strong></em></span> is use to protecting LAN, secure workstation and servers.</p>
<p><span style="color:#000080;"><em><strong>Capabilities of Firewall:</strong></em></span></p>
<ul>
<li>
<div>keep unauthorized user out of the protected network.</div>
</li>
<li>
<div>provide a location for monitoring security events.</div>
</li>
<li>
<div>convenient platform for some internet function like NAT.</div>
</li>
</ul>
<p><span style="color:#000080;"><em><strong>Limitations of Firewall:</strong></em></span></p>
<ul>
<li>
<div>cannot protect against attack by passing firewall.</div>
</li>
<li>
<div>may not protect fully against internal threats.</div>
</li>
<li>
<div>improperly secure wireless LAN may be accessed from outside the organization.</div>
</li>
</ul>
<p><span style="color:#000080;"><em><strong>Types of firewall:</strong></em></span></p>
<ul>
<li><span style="color:#ff9900;"><em>Packet Filtering Firewall:</em></span> Applies rules to packets in/out of firewall, easy to manage but less secure</li>
<li><em><span style="color:#ff9900;">Stateful Inspection Firewall:</span></em> Reviews packet header information but also keeps info on TCP connections,  stateful inspection packet firewall tightens rules for TCP traffic using a directory of TCP connections, only allow incoming traffic to high numbered ports for packets matching an entry in directory.</li>
<li><em><span style="color:#ff9900;">Application-level Gateway:</span></em> Act as a relay of application-level traffic, must have proxy code for each application, more secure than packet filters, have higher overheads</li>
<li><span style="color:#ff9900;"><em>Circuit- level Gateway:</em></span> Does not permit an end to end TCP connection, set up two connections which is between itself to internal network user and between itself to outside network host, determining which connections will be allowed</li>
</ul>
<p><span style="color:#000080;"><em><strong>Firewall bashing:</strong></em></span></p>
<ul>
<li>bastian host</li>
<li>host-based</li>
<li>personal</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/suningbits3413.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/suningbits3413.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/suningbits3413.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/suningbits3413.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/suningbits3413.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/suningbits3413.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/suningbits3413.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/suningbits3413.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/suningbits3413.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/suningbits3413.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/suningbits3413.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/suningbits3413.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/suningbits3413.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/suningbits3413.wordpress.com/87/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=87&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://suningbits3413.wordpress.com/2009/10/14/lecture-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a5c7f9aa9108be188e125a3f0885a4b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tansn</media:title>
		</media:content>
	</item>
		<item>
		<title>Mid Term Exam (Lab Session-08Oct09)</title>
		<link>http://suningbits3413.wordpress.com/2009/10/08/mid-term-exam-lab-session-08oct09/</link>
		<comments>http://suningbits3413.wordpress.com/2009/10/08/mid-term-exam-lab-session-08oct09/#comments</comments>
		<pubDate>Thu, 08 Oct 2009 09:00:33 +0000</pubDate>
		<dc:creator>tansn</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://suningbits3413.wordpress.com/?p=83</guid>
		<description><![CDATA[08/10/09 No lab today.  But, we were having BITS 3413 mid term exam during lab session. There are Part A and Part B.  1 question in Part A.  3 questions in Part B (Answer 2 questions only). The question in Part A is about cryptography.  I like this part more than Part B because Part [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=83&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>08/10/09</strong></p>
<p>No lab today.  But, we were having BITS 3413 mid term exam during lab session.</p>
<p>There are Part A and Part B.  1 question in Part A.  3 questions in Part B (Answer 2 questions only).</p>
<p>The question in Part A is about cryptography.  I like this part more than Part B because Part B questions are mainly theory questions.  The questions of the mid term exam are not so easy&#8230;T.T</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/suningbits3413.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/suningbits3413.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/suningbits3413.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/suningbits3413.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/suningbits3413.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/suningbits3413.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/suningbits3413.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/suningbits3413.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/suningbits3413.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/suningbits3413.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/suningbits3413.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/suningbits3413.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/suningbits3413.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/suningbits3413.wordpress.com/83/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=83&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://suningbits3413.wordpress.com/2009/10/08/mid-term-exam-lab-session-08oct09/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a5c7f9aa9108be188e125a3f0885a4b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tansn</media:title>
		</media:content>
	</item>
		<item>
		<title>Lecture 6</title>
		<link>http://suningbits3413.wordpress.com/2009/10/07/lecture-6/</link>
		<comments>http://suningbits3413.wordpress.com/2009/10/07/lecture-6/#comments</comments>
		<pubDate>Wed, 07 Oct 2009 06:51:37 +0000</pubDate>
		<dc:creator>tansn</dc:creator>
				<category><![CDATA[Network and IT Sec]]></category>

		<guid isPermaLink="false">http://suningbits3413.wordpress.com/?p=75</guid>
		<description><![CDATA[7/10/09 LECTURE 6 &#8211; SECURITY IN NETWORKS, HACKING AND PREVENTION, SECURITY IN APPLICATIONS It&#8217;s another hectic week&#8230;All of us are busy with assignment, projects, and WORKSHOP 2.  Although we are busy, we still attend the lecture because attendance is very important. Summary of today lecture: Encryption &#62; Link to link Cover layer 1 and layer [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=75&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>7/10/09</strong></p>
<p><strong>LECTURE 6 &#8211; SECURITY IN NETWORKS, HACKING AND PREVENTION, SECURITY IN APPLICATIONS<br />
</strong></p>
<p>It&#8217;s another hectic week&#8230;All of us are busy with assignment, projects, and WORKSHOP 2.  Although we are busy, we still attend the lecture because attendance is very important.</p>
<p>Summary of today lecture:</p>
<p><em><strong><span style="color:#000080;">Encryption</span></strong></em></p>
<p>&gt; Link to link</p>
<ul>
<li>Cover layer 1 and layer 2 of OSI model</li>
<li>Decryption occurs just as the communication arrives at and receiving computer</li>
</ul>
<p>&gt; End to end</p>
<ul>
<li>Provide security from one end of a transmission to the other layer 6 or 7</li>
<li>Protect data on every layer</li>
</ul>
<p><em><strong><span style="color:#000080;">Strong Authentication</span></strong></em></p>
<p>&gt; one entity proves its identity to another by demonstrating knowledge of a secret known to be associated with that entity<br />
&gt; also called ‘challenge-response’ authentication<br />
&gt; use cryptographic mechanisms to protect message in protocol like integrity mechanism and digital signature.</p>
<p><span style="color:#000080;"><strong><em>IPSec, SSH, SSL</em></strong></span></p>
<p>&gt; IPSec</p>
<ul>
<li>Optional for IPv4 but mandatory for IPv6</li>
<li>Implemented in IP layer so affect all layer above it.</li>
<li>Provide authentication(AH) and encryption (ESP)</li>
</ul>
<p>&gt; SSH</p>
<ul>
<li>Secure remote login</li>
</ul>
<p>&gt; SSL</p>
<ul>
<li>Encrypt data over the transport layer</li>
</ul>
<p><em><strong><span style="color:#000080;">Kerberos</span></strong></em></p>
<p>&gt; Based on the idea that a central server provides authentication tokens (tickets) to request application.<br />
&gt; A ticket is an unforgeable and nonreplayable.</p>
<p><em><strong><span style="color:#000080;">Firewall</span></strong></em></p>
<p>&gt; A network security device designed to restrict access to resources (information) according to security policy.<br />
&gt; Installed between organization’s network and the internet.<br />
&gt; Can filter traffic.</p>
<p><span style="color:#000080;"><em><strong>Intrusion Detection System</strong></em></span></p>
<p>&gt; A device or software tools or hardware tools that monitor activity to identify malicious or suspicious events.<br />
&gt; Two types of IDS which are signature based and anamoly based.</p>
<p><em><strong><span style="color:#000080;"><br />
</span></strong></em></p>
<p><em><strong><span style="color:#000080;">Honeypot</span></strong></em><br />
&gt; Decoy systems that are designed to lure a potential attacker away from critical systems.</p>
<p>After that, Mr Zaki continued his lecture with the topic “<strong>HACKING AND PREVENTION</strong>”.</p>
<p>Examples of 5 <span style="color:#000080;">hacking phases</span>:</p>
<ul>
<li>reconaisance</li>
<li> scanning</li>
<li> gaining access</li>
<li>maintaining access</li>
<li>covering track</li>
</ul>
<p>The examples of <span style="color:#000080;">hacking behaviors</span> are:</p>
<ul>
<li>
<div>select target using IP lookup tools</div>
</li>
<li>
<div>map network for accessible services</div>
</li>
<li>
<div>identify potentially vulnerable services</div>
</li>
<li>
<div>brute force (guess) passwords</div>
</li>
<li>
<div>install remote administration tool</div>
</li>
<li>
<div>wait for admin to log on and capture password</div>
</li>
<li>
<div>use password to access remainder of network</div>
</li>
</ul>
<p>Another topic of the day is  “SECURITY IN APPLICATIONS”.  In this chapter, we had gained some knowledge about securities in Email and Web. The securities in Email are SMIME and PGP; while the securities in Web are SSL, SSH, SET, HTTPS and SFTP. The diagram below shows the way Email works:</p>
<p><img src="http://2.bp.blogspot.com/_cnV5qhPiM-E/StNcWUDbyVI/AAAAAAAAACw/0Ky8KJKhDws/s320/Untitled.jpg" border="0" alt="" /></p>
<p>At the end of the lecture, Mr. Zaki did not forget to remind us again about the mid term exam tomorrow.  Hope that we can get a good result&#8230;GOOD LUCK, EVERYONE!!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/suningbits3413.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/suningbits3413.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/suningbits3413.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/suningbits3413.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/suningbits3413.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/suningbits3413.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/suningbits3413.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/suningbits3413.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/suningbits3413.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/suningbits3413.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/suningbits3413.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/suningbits3413.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/suningbits3413.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/suningbits3413.wordpress.com/75/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=75&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://suningbits3413.wordpress.com/2009/10/07/lecture-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a5c7f9aa9108be188e125a3f0885a4b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tansn</media:title>
		</media:content>

		<media:content url="http://2.bp.blogspot.com/_cnV5qhPiM-E/StNcWUDbyVI/AAAAAAAAACw/0Ky8KJKhDws/s320/Untitled.jpg" medium="image" />
	</item>
		<item>
		<title>Lab 6</title>
		<link>http://suningbits3413.wordpress.com/2009/10/01/lab-6/</link>
		<comments>http://suningbits3413.wordpress.com/2009/10/01/lab-6/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 10:47:42 +0000</pubDate>
		<dc:creator>tansn</dc:creator>
				<category><![CDATA[Network and IT Sec]]></category>

		<guid isPermaLink="false">http://suningbits3413.wordpress.com/?p=68</guid>
		<description><![CDATA[17/09/09 LAB 6 &#8211; SECURITY IN NETWORK Network security can been said as a prevention from nosy people from getting data they are not authorized or worse yet, modify messages intended for other recipients. It is concerned with people trying to access remote services that are not authorized to use. Most problems are intentionally caused [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=68&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>17/09/09</strong></p>
<p><strong>LAB 6 &#8211; SECURITY IN NETWORK<br />
</strong></p>
<p>Network security can been said as a prevention from nosy people from getting data they are not authorized or worse yet, modify messages intended for other recipients. It is concerned with people trying to access remote services that are not authorized to use. Most problems are intentionally caused by malicious people trying to gain some benefit or bring harm to someone else.</p>
<p>Firewall, Intrusion detection system (IDS), Intrusion Prevention system (IPS), Kerberos and Honeypot is among the<br />
application introduce to protect Network services on the network from being attack by malicious people we called hackers.</p>
<p>IPSec is available in IPv4, yet it is not mandatory to use it, user can choose to enable IPSec or not. This protocol suite is not only <span style="color:#ff6600;"><em>providing authentication and encryption</em></span> on each IP packet of a data stream but also <span style="color:#ff6600;"><em>providing an establishment of mutual authentication</em></span> between the parties involves at the beginning of the session and negotiation of cryptographic keys to be used during the session. As it is implemented at the IP layer, IPsec provide protection for all the layer above it, in particular TCP and UDP.</p>
<p>IPSec protocol suites contain various protocols for performing various functions:-</p>
<ul>
<li><span style="color:#ff0000;"><em>Internet key exchange (IKE and IKEv2)</em></span> to set up a security association (SA) by handling negotiation of protocols and algorithms and to generate the encryption and authentication keys to be used by IPsec.</li>
</ul>
<ul>
<li><em><span style="color:#ff0000;">Authentication Header (AH)</span></em> to provide connectionless integrity and data origin authentication for IP datagrams and to provide protection against replay attacks.</li>
</ul>
<ul>
<li><span style="color:#ff0000;"><em>Encapsulating Security Payload (ESP)</em></span> to provide confidentiality, data origin authentication, connectionless integrity, an anti-replay service (a form of partial sequence integrity), and limited traffic flow confidentiality.</li>
</ul>
<p>Task 1:</p>
<p>In task one, we need to configure FTP service.  Then, capture the packets using Wireshark.</p>
<p>Task 2:</p>
<p>In task two, we configure IPSec.  Then, transfer file using FTP we had configured in task 1.  Capture the packets using Wireshark as well.</p>
<p>Differences between Task 1 and Task 2 from the result get from Wireshark:</p>
<ul>
<li><span style="color:#3366ff;"><em>Task 1</em></span>: One of the protocols captured by Wireshark is FTP protocol.  From the packets captured, we can easily get the password of username and password of FTP server.</li>
<li><em><span style="color:#3366ff;">Task 2</span></em>: No FTP protocol being captured by Wireshark but ESP protocol was captured.  The username and password of FTP server have been encrypted.  Thus, we can&#8217;t get to know about the username and password of the FTP server.</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/suningbits3413.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/suningbits3413.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/suningbits3413.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/suningbits3413.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/suningbits3413.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/suningbits3413.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/suningbits3413.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/suningbits3413.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/suningbits3413.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/suningbits3413.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/suningbits3413.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/suningbits3413.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/suningbits3413.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/suningbits3413.wordpress.com/68/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=68&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://suningbits3413.wordpress.com/2009/10/01/lab-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a5c7f9aa9108be188e125a3f0885a4b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tansn</media:title>
		</media:content>
	</item>
		<item>
		<title>Lecture 5</title>
		<link>http://suningbits3413.wordpress.com/2009/09/30/lecture-5/</link>
		<comments>http://suningbits3413.wordpress.com/2009/09/30/lecture-5/#comments</comments>
		<pubDate>Wed, 30 Sep 2009 12:32:31 +0000</pubDate>
		<dc:creator>tansn</dc:creator>
				<category><![CDATA[Network and IT Sec]]></category>

		<guid isPermaLink="false">http://suningbits3413.wordpress.com/?p=64</guid>
		<description><![CDATA[16/09/09 LECTURE 5 &#8211; AUTHENTICATION AND ACCESS CONTROL Authentication Authentication is related to identity verification. Classifications of identity verification: by something known such as password by something possessed such as smart card, passport by physical characteristics (biometrics) signature Password Protection of password Don&#8217;t keep your password to anybody Don&#8217;t ever write the password everywhere etc [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=64&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>16/09/09</strong></p>
<p><strong>LECTURE 5 &#8211; AUTHENTICATION AND ACCESS CONTROL</strong></p>
<p><span style="color:#000080;"><em><strong>Authentication</strong></em></span></p>
<p>Authentication is related to identity verification.</p>
<p>Classifications of identity verification:</p>
<ul>
<li>by something known such as password</li>
<li>by something possessed such as smart card, passport</li>
<li>by physical characteristics (biometrics)</li>
<li>signature</li>
</ul>
<p><span style="color:#000080;"><strong><em>Password</em></strong></span></p>
<p>Protection of password</p>
<ul>
<li>Don&#8217;t keep your password to anybody</li>
<li>Don&#8217;t ever write the password everywhere</li>
<li>etc</li>
</ul>
<p>Good password characteristics</p>
<ul>
<li>more than 6 characters</li>
<li>Not patterns from the keyboard</li>
<li>etc</li>
</ul>
<p>Calculations on password</p>
<ul>
<li>password population, N = r^s</li>
<li>Probability of guessing a password = 1/N</li>
<li>Probability of success, P = (nt)/N</li>
</ul>
<p>Mr. Zaki did show us some examples about the calculations on passwords.</p>
<p>Techniques of guessing passwords</p>
<ul>
<li>try default passwords</li>
<li>try all short words, 1 &#8211; 3 characters long</li>
<li>collect user&#8217;s information</li>
<li>try all license plate numbers</li>
<li>use trojan horse and etc.</li>
</ul>
<p>Password selecting strategies</p>
<ul>
<li>user education</li>
<li>computer-generated passwords</li>
<li>reactive password checking</li>
<li>proactive password checking</li>
</ul>
<p><span style="color:#000080;"><em><strong>Biometrics</strong></em></span></p>
<p>Biometrics &#8211; the measurement and statistical analysis of biological data.</p>
<p>In IT, biometrics refer to technologies for measuring and analyzing human body characteristics for authentication purposes.</p>
<p>Biometrics identifiers</p>
<ul>
<li>universality</li>
<li>uniqueness</li>
<li>stability</li>
<li>collectability</li>
<li>performance</li>
<li>acceptability</li>
<li>forge resistance</li>
</ul>
<p>Static biometric methods (Physiological)</p>
<ul>
<li>Authentication based on a feature that is always present</li>
<li>Classifications: fingerprint recognition, retinal scan, iris scan, hand geometry</li>
</ul>
<p>Dynamic biometric methods (Behavioral)</p>
<ul>
<li>Authentication based on a certain behavior pattern</li>
<li>Classifications: signature recognition, speaker recognition, keystrokes dynamics</li>
</ul>
<p>Major components of biometric system</p>
<ul>
<li>data collection</li>
<li>signal processing</li>
<li>matching</li>
<li>decision</li>
<li>storage</li>
<li>transmission</li>
</ul>
<p><em><strong><span style="color:#000080;">Access Control</span></strong></em></p>
<p>The prevention of unauthorized use of a resource, including the prevention of use of a resource in an unauthorized manner.</p>
<p>Requirements:</p>
<ul>
<li>reliable input</li>
<li>fine and coarse specifications</li>
<li>least privilege</li>
<li>separation of duty</li>
<li>open and closed policies</li>
<li>policy combination, conflict resolution</li>
<li>administrative policies</li>
</ul>
<p>Elements: subject, object and access right</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/suningbits3413.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/suningbits3413.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/suningbits3413.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/suningbits3413.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/suningbits3413.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/suningbits3413.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/suningbits3413.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/suningbits3413.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/suningbits3413.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/suningbits3413.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/suningbits3413.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/suningbits3413.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/suningbits3413.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/suningbits3413.wordpress.com/64/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=64&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://suningbits3413.wordpress.com/2009/09/30/lecture-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a5c7f9aa9108be188e125a3f0885a4b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tansn</media:title>
		</media:content>
	</item>
		<item>
		<title>Lecture 4 and Lab 5</title>
		<link>http://suningbits3413.wordpress.com/2009/09/10/lecture-4-and-lab-5/</link>
		<comments>http://suningbits3413.wordpress.com/2009/09/10/lecture-4-and-lab-5/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 12:50:53 +0000</pubDate>
		<dc:creator>tansn</dc:creator>
				<category><![CDATA[Network and IT Sec]]></category>

		<guid isPermaLink="false">http://suningbits3413.wordpress.com/?p=49</guid>
		<description><![CDATA[09/09/09 LECTURE 4 &#8211; PROGRAM SECURITY The date of the day (9/9/9) was very wonderful.  ^^ Actually, Mr Zaki wanna give us the message and key of our assignment.  But, he formatted his laptop without back-up his documents. What a good news to us!!haha&#8230; Lecture 4 is all about program security.  Vulnerability is a software [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=49&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>09/09/09</strong></p>
<p><strong>LECTURE 4 &#8211; PROGRAM SECURITY</strong></p>
<p>The date of the day (9/9/9) was very wonderful.  ^^<br />
Actually, Mr Zaki wanna give us the message and key of our assignment.  But, he formatted his laptop without back-up his documents. What a good news to us!!haha&#8230;</p>
<p>Lecture 4 is all about program security.  Vulnerability is a software weakness that can be exploited by an attacker. Bugs and flaws collectively form the basis of most software vulnerabilities.  Most commonly known tracking faults from developers are requirements, design and code inspections.  Vulnerability and flaws do not map to faults and failures.</p>
<p>&#8220;Bugs&#8221; means different things, depending on context.</p>
<blockquote><p>Bugs are software problems that exist only in code.  A bug that exists in code may or may not ever be executed or exploitable.  Therefore, a bug may or may not represent a vulnerability in the underlying software.  Bugs are used to describe minor implementation errors that are typically easy to fix.</p></blockquote>
<p><strong>Types of flaws:</strong></p>
<ul>
<li>validation error</li>
<li>domain error</li>
<li>serialization and aliasing</li>
<li>inadequate identification and authentication</li>
<li>boundary condition violation</li>
<li>other exploitable logic errors</li>
</ul>
<p><strong>Nonmalicious Program Errors:</strong></p>
<ul>
<li>Buffer Overflows</li>
<li>Incomplete mediation &#8211; data exposed or uncontrolled</li>
<li>Time of check to Time of used</li>
</ul>
<p><strong>Virus and other malicious code:</strong></p>
<p>I think this is an interesting part of this lecture.  Malicious code can do harm.  The damage can be in the form of modification /  destruction, stolen data, unauthorized access, damage on system or other forms not intended by users.  Examples of malicious codes are trojan horse, virus, worm, bacteria, logic bomb, spyware and trapdoor.</p>
<p>Mr. Zaki explained to us about viruses, worms and trapdoors and salami attack.</p>
<p>Besides, ways to prevent virus infection and web application attack also being taught in this lecture.  To prevent virus infection, there are several tools need to be used.</p>
<p>Pillar of software security: Risk management, touchpoints and knowledge.</p>
<p><strong>10/09/09</strong></p>
<p><strong>LAB 5</strong></p>
<p>Another interesting lab of this course.  In this lab, Mr. Zaki told us that there are 2 kinds of hackers &#8211; black hackers and white hackers.  Can I be grey hacker??haha&#8230;</p>
<p>We learned to use the OWASP.  The Open Web Application Security Project (OWASP) is an open community that focuses on improving the security of<br />
application software.  We try the lab but we failed to finish it because we don&#8217;t know how to do&#8230;^^</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/suningbits3413.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/suningbits3413.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/suningbits3413.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/suningbits3413.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/suningbits3413.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/suningbits3413.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/suningbits3413.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/suningbits3413.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/suningbits3413.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/suningbits3413.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/suningbits3413.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/suningbits3413.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/suningbits3413.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/suningbits3413.wordpress.com/49/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=49&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://suningbits3413.wordpress.com/2009/09/10/lecture-4-and-lab-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a5c7f9aa9108be188e125a3f0885a4b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tansn</media:title>
		</media:content>
	</item>
		<item>
		<title>02Sept09 and 03Sept09</title>
		<link>http://suningbits3413.wordpress.com/2009/09/02/02sept09-and-03sept09/</link>
		<comments>http://suningbits3413.wordpress.com/2009/09/02/02sept09-and-03sept09/#comments</comments>
		<pubDate>Wed, 02 Sep 2009 06:14:38 +0000</pubDate>
		<dc:creator>tansn</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://suningbits3413.wordpress.com/?p=46</guid>
		<description><![CDATA[Lecture and lab of Network and IT Sec this week cancel!!!YES!!HOORAY!!!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=46&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Lecture and lab of Network and IT Sec this week cancel!!!YES!!HOORAY!!!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/suningbits3413.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/suningbits3413.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/suningbits3413.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/suningbits3413.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/suningbits3413.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/suningbits3413.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/suningbits3413.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/suningbits3413.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/suningbits3413.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/suningbits3413.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/suningbits3413.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/suningbits3413.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/suningbits3413.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/suningbits3413.wordpress.com/46/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=suningbits3413.wordpress.com&amp;blog=8601558&amp;post=46&amp;subd=suningbits3413&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://suningbits3413.wordpress.com/2009/09/02/02sept09-and-03sept09/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0a5c7f9aa9108be188e125a3f0885a4b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">tansn</media:title>
		</media:content>
	</item>
	</channel>
</rss>
