<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2956661363702348767</id><updated>2011-11-28T07:40:49.165+08:00</updated><category term='Week 5'/><category term='Week 4'/><category term='Week 10'/><category term='Week 1'/><category term='Week 6'/><category term='Week 3'/><category term='Week 8'/><category term='Week 7'/><category term='Week 2'/><category term='Week 9'/><title type='text'>B030710154</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>16</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-2999619497076842860</id><published>2009-10-23T23:57:00.000+08:00</published><updated>2009-10-30T04:58:44.883+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 10'/><title type='text'>Lecture 10: Cyberlaw</title><content type='html'>&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;&lt;span style="font-size:18.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Cyberlaw&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;Cyber law is rules in cyber world or internet. Cyber law created to prevent internet or cyber world from computer crime. &lt;span class="apple-style-span"&gt;Reason why computer crime hard to define are because cr&lt;/span&gt;eating and changing laws are slow processes, which is very much out of pace with a technology that is progressing as fast as computing. Then a computer can perform many roles in a crime, particular computer can be the subject, object or a medium of a crime. Which is means computer can act as an attacker, or as a victim, or as a medium use to attack the victim which means use to hack, phishing and so on. Based on this problem cyber law exists.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;

&lt;/span&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span style="font-size:12.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;Cyber Law in Malaysia&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:10.0pt;line-height:115%; font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;
&lt;span class="apple-style-span"&gt;DIGITAL SIGNATURE ACT 1997&lt;/span&gt;
&lt;span class="apple-style-span"&gt;it provides for the regulation of the public key infrastructure. The Act makes a digital signature as legally valid and enforceable as a traditional signature.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;span class="apple-style-span"&gt;&lt;/span&gt;

&lt;span class="apple-style-span"&gt;COPY RIGHT ACT 1997&lt;/span&gt;
&lt;span class="apple-style-span"&gt;Copyright serves to protect the expression of thoughts and ideas from unauthorized copying and/or alteration. With convergence of Information and Communication Technology (ICT), creative expression is now being captured and communicated in new forms (example: multimedia products, broadcast of movies over the Internet and cable TV). These new forms need protection. Copy right act rules the new and converged multimedia environment.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;span class="apple-style-span"&gt;&lt;/span&gt;

&lt;span class="apple-style-span"&gt;TELEMEDICINE ACT 1997&lt;/span&gt;
&lt;span class="apple-style-span"&gt;Healthcare systems and providers around the world are becoming interconnected. People and local healthcare providers can thus source quality healthcare advice and consultation from specialists from around the world, independent of geographical location. This act provide any registered doctor may practice telemedicine but healthcare providers must obtains the license to do so.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;span class="apple-style-span"&gt;&lt;/span&gt;

&lt;span class="apple-style-span"&gt;COMPUTERS CRIME ACT 1997&lt;/span&gt;
&lt;span class="apple-style-span"&gt;As computing becomes more central to people’s life and work, computers become both targets and tools of crime. This Act offense everything that would harm the computer system.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;span class="apple-style-span"&gt;&lt;/span&gt;

&lt;span class="apple-style-span"&gt;COMMUNICATION AND MULTIMEDIA ACT 1998&lt;/span&gt;
&lt;span class="apple-style-span"&gt;Convergence of technologies is driving convergence of telecommunications, broadcasting, computing and content.&lt;/span&gt;&lt;/span&gt;&lt;span class="apple-style-span"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family: Helvetica"&gt; This Act c&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height: 115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;reates a new system of licenses and defines the roles and responsibilities of those providing communication and multimedia services and provides for the existence of the Communication and Multimedia Commission, the new regulatory authority&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:18.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-2999619497076842860?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/2999619497076842860/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/10/lecture-10-cyberlaw_23.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/2999619497076842860'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/2999619497076842860'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/10/lecture-10-cyberlaw_23.html' title='Lecture 10: Cyberlaw'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-5535699664003036622</id><published>2009-10-16T23:20:00.000+08:00</published><updated>2009-10-30T04:22:44.548+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 9'/><title type='text'>Lecture 9: Legal and Ethical Issues in Computer Security</title><content type='html'>&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;&lt;span style="font-size:18.0pt;line-height:115%"&gt;Legal and Ethical Issues in Computer Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Law is a rule of conduct or action prescribed or formally recognized as binding or enforced by a controlling authority. Ethics is a set of moral principles or values or the principles of conduct governing an individual or a group.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Differences between law and ethic:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-weight:bold"&gt;LAW&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="margin-left:.75in;mso-add-space:auto; text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;Formal, documented&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;Interpreted by courts&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;Established by legislature representing everyone&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;Applicable to everyone&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;Priority determined by courts if two laws conflict&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:.75in;mso-add-space:auto; text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;Enforceable by police and courts&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-weight:bold"&gt;ETHIC&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="margin-left:.75in;mso-add-space:auto; text-indent:-.25in;mso-list:l2 level1 lfo2"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;Described by unwritten principles&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l2 level1 lfo2"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;Interpreted by individuals&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l2 level1 lfo2"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;Presented by philosophers, religions, professional group&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l2 level1 lfo2"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;Personal choice&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l2 level1 lfo2"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;Priority determined by individual if two principles conflict&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:.75in;mso-add-space:auto"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;The key difference between laws and ethics is that laws carry the sanction of a governing authority and ethics do not. Organizations formalize desired behaviors in documents called policies. Policies must be read and agreed to before they are binding. Civil law represents a wide variety of laws that are used to govern a nation or state. Criminal law addresses violations that harm society and are enforced by agents of the state or nation. Tort law is conducted by means of individual lawsuits rather than criminal prosecution by the state.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-bidi-font-weight:bold"&gt;Three&lt;/span&gt; general categories of unethical and illegal behavior:&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="margin-left:1.0in;mso-add-space:auto; text-indent:-.25in;mso-list:l1 level2 lfo3"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family:&amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea; mso-bidi-font-weight:bold"&gt;Ignorance&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level3 lfo3"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family: Wingdings"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;ignorance of the law is no excuse, however ignorance of policy and procedures is&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo3"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family:&amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea; mso-bidi-font-weight:bold"&gt;Accident&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level3 lfo3"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family: Wingdings"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;Individuals with authorization and privileges to manage information within the organization are most likely to cause harm or damage by accident&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo3"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family:&amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea; mso-bidi-font-weight:bold"&gt;Intent&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:1.5in;mso-add-space:auto; text-indent:-.25in;mso-list:l1 level3 lfo3"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family: Wingdings"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:+mn-ea"&gt;Intent is often the cornerstone of legal defense, when it becomes necessary to determine whether or not the offender acted out of ignorance, by accident, or with specific intent to cause harm or damage&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span style="font-size:14.0pt;line-height:115%"&gt;Ethic Concepts&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Deterrence is the best method for preventing an illegal or unethical activity. Deterrence can prevent an illegal or unethical activity from occurring. Deterrence requires significant penalties, a high probability of apprehension, and an expectation of enforcement of penalties. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-5535699664003036622?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/5535699664003036622/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/10/lecture-9-legal-and-ethical-issues-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/5535699664003036622'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/5535699664003036622'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/10/lecture-9-legal-and-ethical-issues-in.html' title='Lecture 9: Legal and Ethical Issues in Computer Security'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-1471625388800654942</id><published>2009-10-09T22:52:00.002+08:00</published><updated>2009-10-30T04:00:48.103+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 8'/><title type='text'>Lecture 8: Wireless LAN Security</title><content type='html'>&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;&lt;span style="line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;font-size:18.0pt;"&gt;Wireless Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Wireless LAN is a connection to network without using a cable.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Connection in wireless LAN usually at 1Mbps and 2 Mbps. Wireless LAN use radio frequency to transmit the data, and it can go through the building. Signals of wireless LAN weakened by wall, floor and interference. Wireless LAN 802.11 focus on physical layer and data link layer. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="margin-left:29.25pt;mso-add-space: auto;text-indent:-29.25pt;mso-list:l4 level2 lfo2"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-fareast-font-family:Georgia; mso-bidi-font-family:Georgia;"&gt;&lt;span style="mso-list:Ignore"&gt;802.11&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Physical layer&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt; &lt;/span&gt;&lt;/span&gt;Originally three alternative physical layers&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo1"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Two incompatible spread-spectrum radio in 2.4Ghz ISM band&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Frequency Hopping Spread Spectrum (FHSS)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:2.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level4 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;75 channels&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Direct Sequence Spread Spectrum (DSSS)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:2.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level4 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;14 channels (11 channels in US)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span"   style="font-family:Symbol;font-size:130%;"&gt;&lt;span class="Apple-style-span"  style="font-size:16px;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;One diffuse infrared layer&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"   style="font-family:Symbol;font-size:130%;"&gt;&lt;span class="Apple-style-span"  style="font-size:16px;"&gt;    &lt;/span&gt;&lt;/span&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;802.11 speed&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;    &lt;p class="MsoListParagraphCxSpLast" style="margin-left:1.0in;mso-add-space:auto; text-indent:-.25in;mso-list:l0 level2 lfo1"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;1 Mbps or 2 Mbps&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;802.11 Data link layer&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Layer 2 split into:&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l5 level2 lfo5"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Logical Link Control (LLC).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l5 level2 lfo5"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Media Access Control (MAC).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l5 level1 lfo5; tab-stops:list .5in"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;LLC - same 48-bit addresses as 802.3.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—  &lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;802.11 always slower than equivalent 802.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;MAC - CSMA/CD not possible.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;      &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l5 level2 lfo5"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Can’t listen for collision while transmitting.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l5 level1 lfo5; tab-stops:list .5in"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;CSMA/CA – Collision Avoidance.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l5 level2 lfo5"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Sender waits for clear air, waits random time, then sends data.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l5 level2 lfo5"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Receiver sends explicit ACK when data arrives intact.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l5 level2 lfo5"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Also handles interference.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:1.0in;mso-add-space:auto; text-indent:-.25in;mso-list:l5 level2 lfo5"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;But adds overhead.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Wireless 802.11 has two modes, instructure and ad-hoc mode. Instructure mode can have one access point or basic service set(BSS) and also can have two or more BSS perform as single subnet, most corporate LAN use in this mode. Ad-hoc or peer to peer is useful for easy and quick wireless network.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span class="Apple-style-span"  style="font-family:monospace;"&gt;&lt;span class="Apple-style-span" style="font-size: -webkit-xxx-large; white-space: pre-wrap;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px; "&gt;&lt;a href="http://www.uploadhouse.com/viewfile.php?id=4779991&amp;amp;showlnk=0" target="_blank"&gt;&lt;img alt="Image Hosted by UploadHouse.com" border="0" src="http://img1.uploadhouse.com/fileuploads/4779/4779991db0f3aee90fcf2d25f0d132ec7c5da1b.jpg" /&gt;&lt;/a&gt;&lt;a href="http://www.uploadhouse.com/viewfile.php?id=4779972&amp;amp;showlnk=0" target="_blank"&gt;&lt;img alt="Image Hosted by UploadHouse.com" border="0" src="http://img2.uploadhouse.com/fileuploads/4779/4779972ead3ce616ec0fdb53fad1bba2424653a.jpg" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span class="Apple-style-span"   style="  white-space: pre-wrap; font-family:monospace;font-size:13px;"&gt;&lt;/span&gt;802.11 can be divided into:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;1. 802.11a&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l2 level1 lfo4; tab-stops:list .5in"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;802.11a ratified in 2001&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt; &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Supports up to 54Mbps in 5 Ghz range.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;    &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l2 level2 lfo4"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Higher frequency limits the range&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l2 level2 lfo4"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Regulated frequency reduces interference from other devices&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l2 level1 lfo4; tab-stops:list .5in"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;12 non-overlapping channels&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Usable range of 30 metres&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt; &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Average throughput of 30 Mbps&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Not backwards compatible&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;        &lt;p class="MsoNormal"&gt;2. 802.11g&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l3 level1 lfo3; tab-stops:list .5in"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;802.11g ratified in 2002&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Supports up to 54Mbps in 2.4Ghz range.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;    &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l3 level2 lfo3"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Backwards compatible with 802.11b&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l3 level1 lfo3; tab-stops:list .5in"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;3 non-overlapping channels&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt; &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Range similar to 802.11b&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Average throughput of 30 Mbps&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;—&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;802.11n due for November 2006&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;        &lt;p class="MsoListParagraphCxSpLast" style="margin-left:1.0in;mso-add-space:auto; text-indent:-.25in;mso-list:l3 level2 lfo3"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Aiming for maximum 200Mbps with average 100Mbps&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-weight: boldfont-family:&amp;quot;;"&gt;Three basic security services&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;defined by IEEE for the WLAN environment&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="margin-left:1.0in;mso-add-space:auto; text-indent:-.25in;mso-list:l1 level2 lfo6"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Authentication&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level3 lfo6"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;provide a security service to verify the identity of communicating client stations&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo6"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Integrity&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level3 lfo6"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;to ensure that messages are not modified in transit between the wireless clients and the access point in an active attack&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo6"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;Confidentiality&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:1.5in;mso-add-space:auto; text-indent:-.25in;mso-list:l1 level3 lfo6"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;to provide “privacy achieved by a wired network”&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-1471625388800654942?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/1471625388800654942/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/10/lecture-8-wireless-lan-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/1471625388800654942'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/1471625388800654942'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/10/lecture-8-wireless-lan-security.html' title='Lecture 8: Wireless LAN Security'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-516857221318942876</id><published>2009-09-25T15:07:00.000+08:00</published><updated>2009-10-30T03:11:51.636+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 7'/><title type='text'>Lecture 7: Security in Application</title><content type='html'>&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;&lt;span style="font-size:18.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Security in Application&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Email is an electronic application, it’s a message made of string ASCII characters. Email has two part, header and body. Header part used to state the sender and email recipient. Body part is content of the message or email. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Security in email:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="margin-left:.75in;mso-add-space:auto; text-indent:-.25in;mso-list:l2 level1 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Confidentiality&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l2 level1 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Data origin authentication&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l2 level1 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Message integrity&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l2 level1 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Non-repudiation of origin&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:.75in;mso-add-space:auto; text-indent:-.25in;mso-list:l2 level1 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Key management&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span class="apple-style-span"&gt;&lt;span style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;MIME.&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt;

&lt;span class="apple-style-span"&gt;Short for Multipurpose Internet Mail Extensions, a specification for formatting non-ASCII messages so that they can be sent over the Internet. Many e-mail clients now support MIME, which enables them to send and receive graphics, audio, and video files via the Internet mail system. In addition, MIME supports messages in character sets other than ASCII.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span class="apple-style-span"&gt;&lt;span style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;Email Security Threads.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l1 level1 lfo2"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:Symbol;mso-fareast-font-family: Symbol;mso-bidi-font-family:Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span"   style="font-family:Symbol;font-size:100%;"&gt;&lt;span class="Apple-style-span" style="font-size: 13px; line-height: 14px;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;Two main group:&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;Threats to the security of e-mail itself&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;Threats to an organisation that are enabled by the use of e-mail.&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l1 level1 lfo2"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt; &lt;/span&gt;&lt;/span&gt;Loss of confidentiality.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;E-mails are sent in clear over open networks.&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;E-mails stored on potentially insecure clients and mail servers.&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;Ensuring confidentiality may be important for e-mails sent within an organisation.&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height: 115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l1 level1 lfo2"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt; &lt;/span&gt;&lt;/span&gt;Loss of integrity.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;No integrity protection on e-mails; body can be altered in transit or on mail server.&lt;/span&gt;&lt;span style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l1 level1 lfo2"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt; &lt;/span&gt;&lt;/span&gt;Lack of data origin authentication.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;Is this e-mail really from the person named in the From: field?&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;How many Kenny.Paterson’s are there? &lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;Recall SMTP directly over telnet allows forgery of all e-mail fields!&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;E-mail could also be altered in transit.&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;Even if the From: field looks fine, who was logged in as Kenny.Paterson when the e-mail was composed?&lt;/span&gt;&lt;span style="font-size: 10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family: Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;Sharing of e-mail passwords common.&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt; &lt;/span&gt;&lt;span style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l1 level1 lfo2"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt; &lt;/span&gt;&lt;/span&gt;Lack of non-repudiation.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;Can I rely and act on the content? (integrity)&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;If so, can the sender later deny having sent it? Who is liable if I have acted?&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height: 115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;Example of stock-trading via e-mail.&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l1 level1 lfo2"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt; &lt;/span&gt;&lt;/span&gt;Lack of notification of receipt.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;Has the intended recipient received my e-mail and acted on it?&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:1.0in;mso-add-space:auto; text-indent:-.25in;mso-list:l1 level2 lfo2"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;A message locally marked as ‘sent’ may not have been delivered.&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt;line-height:115%; font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt; &lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span lang="EN-GB" style="font-size:10.0pt;line-height:115%; font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica;mso-ansi-language: EN-GB"&gt;SSH or Secure Shell is initially designed to replace insecure rsh, telnet utilities, seecure remote administration (mostly of Unix systems), and Extended to support secure file transfer and e-mail.&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:20.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-fareast-font-family:+mn-ea;mso-bidi-font-family:+mn-cs;color:black; mso-font-kerning:12.0pt;mso-ansi-language:EN-GB"&gt; &lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica;mso-ansi-language:EN-GB"&gt;SSH provides security at Application layer, only covers traffic explicitly protected. Applications need modification, but port-forwarding eases some of this.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span lang="EN-GB" style="font-size:10.0pt;line-height:115%; font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica;mso-ansi-language: EN-GB"&gt;Application in SSH:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l0 level1 lfo3"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt; &lt;/span&gt;&lt;/span&gt;Anonymous ftp for software updates, patches...&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo3"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;No client authentication needed, but clients want to be sure of origin and integrity of software.&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt; &lt;/span&gt;&lt;span style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l0 level1 lfo3"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt; &lt;/span&gt;&lt;/span&gt;Secure ftp.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo3"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;E.g.upload of webpages to webserver using sftp.&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo3"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;Server now needs to authenticate clients. &lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo3"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;Username and password may be sufficient, transmitted over secure SSH transport layer protocol. &lt;/span&gt;&lt;span style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l0 level1 lfo3"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt; &lt;/span&gt;&lt;/span&gt;Secure remote administration.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo3"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;SysAdmin (client) sets up terminal on remote machine. &lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo3"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;SysAdmin password protected by SSH transport layer protocol.&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo3"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;SysAdmin commands protected by SSH connection protocol.&lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l0 level1 lfo3"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt; &lt;/span&gt;&lt;/span&gt;Guerilla Virtual Private Network.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:1.0in;mso-add-space:auto; text-indent:-.25in;mso-list:l0 level2 lfo3"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family: &amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica; mso-ansi-language:EN-GB"&gt;E.g. use SSH + port forwarding to secure e-mail communications.&lt;/span&gt;&lt;span lang="EN-GB" style="font-size:10.0pt;line-height: 115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt; &lt;/span&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10.0pt;line-height:115%;font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left:.75in"&gt;&lt;span style="font-size:10.0pt; line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-516857221318942876?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/516857221318942876/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/09/lecture-7-security-in-application.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/516857221318942876'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/516857221318942876'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/09/lecture-7-security-in-application.html' title='Lecture 7: Security in Application'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-5825382322905136313</id><published>2009-09-11T14:38:00.003+08:00</published><updated>2009-10-30T01:47:09.385+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 6'/><title type='text'>Lecture 6: Security in Network</title><content type='html'>&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;&lt;span style="line-height:115%;font-size:18.0pt;"&gt;Security in Network&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;A computing network is a computing environment with more than one independent processor and maybe multiple users per system and the distance between computers is not considered. Computers and user terminals which are connected to the network are known as network node. I n network user can send and receive message, executing program and obtaining status.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Basic terminology in network&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left:1.0in;text-indent:-.25in;mso-list:l3 level2 lfo1; tab-stops:list 1.0in"&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;É&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Node is single computing system in a network.&lt;b&gt; &lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left:1.0in;text-indent:-.25in;mso-list:l3 level2 lfo1; tab-stops:list 1.0in"&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;É&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Host is a single computing system's processor.&lt;b&gt; &lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left:1.0in;text-indent:-.25in;mso-list:l3 level2 lfo1; tab-stops:list 1.0in"&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;É&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Link is a connection between two hosts.&lt;b&gt; &lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left:1.0in;text-indent:-.25in;mso-list:l3 level2 lfo1; tab-stops:list 1.0in"&gt;&lt;span style="font-family:&amp;quot;Wingdings 2&amp;quot;; mso-fareast-font-family:&amp;quot;Wingdings 2&amp;quot;;mso-bidi-Wingdings 2&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;É&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Topology is the pattern of links in a network&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Network topologies &lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="margin-left:.75in;mso-add-space:auto; text-indent:-.25in;mso-list:l4 level1 lfo2"&gt;&lt;span style="mso-bidi-;font-family:Calibri;"&gt;&lt;span style="mso-list:Ignore"&gt;1.&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Bus Topology&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto"&gt;To provide a single communication network on which any node can place information and from which any code can retrieve information. One attachment in bus terminology not impacts the other nodes.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l4 level1 lfo2"&gt;&lt;span style="mso-bidi-;font-family:Calibri;"&gt;&lt;span style="mso-list:Ignore"&gt;2.&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Star topology&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto"&gt;Has switch as a central. The central switch receives all messages, identifies the addresses, selects the link appropriate for that addresses and forwards the messages.&lt;/p&gt;&lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto"&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: 13px; white-space: pre-wrap; "&gt;&lt;a href="http://www.uploadhouse.com/viewfile.php?id=4779572&amp;amp;showlnk=0" target="_blank"&gt;&lt;img alt="Image Hosted by UploadHouse.com" border="0" src="http://img2.uploadhouse.com/fileuploads/4779/477957283711a8f7c2880d12992870ec9247853.jpg" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l4 level1 lfo2"&gt;&lt;span style="mso-bidi-;font-family:Calibri;"&gt;&lt;span style="mso-list:Ignore"&gt;3.&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Ring Topology&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto"&gt;To connect a sequence of nodes in a loop or ring. Can be implemented with minimum cabling.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l4 level1 lfo2"&gt;&lt;span style="mso-bidi-;font-family:Calibri;"&gt;&lt;span style="mso-list:Ignore"&gt;4.&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Mesh Topology&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:1.0in;mso-add-space:auto"&gt;Each node can conceptually be connected directly to each other node and routing logic can be used to select the most efficient route through multiple nodes.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Advantages in network computing&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="margin-left:.75in;mso-add-space:auto; text-indent:-.25in;mso-list:l2 level1 lfo3"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Resource sharing is used to reduce maintenance and storage costs.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l2 level1 lfo3"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Increased reliability means if one system fails users can shift to another.&lt;b&gt; &lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l2 level1 lfo3"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Distributing the workload&lt;b&gt; &lt;/b&gt;&lt;span style="mso-bidi-font-weight:bold"&gt;means w&lt;/span&gt;orkload can be shifted from a heavily loaded system to an underutilized one.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:.75in;mso-add-space:auto; text-indent:-.25in;mso-list:l2 level1 lfo3"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Expandability&lt;b&gt; &lt;/b&gt;&lt;span style="mso-bidi-font-weight: bold"&gt;is s&lt;/span&gt;ystem is easily expanded by adding new nodes.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Disadvantages in network computing&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="margin-left:1.25in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level1 lfo4"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Sharing, access controls for a single system may be inadequate.&lt;b&gt; &lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.25in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level1 lfo4"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Complexity, a network may combine two or more systems with dissimilar operating systems with different mechanisms for interhost connection. Complexity of this nature makes the certification process extremely difficult.&lt;b&gt; &lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.25in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level1 lfo4"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Unknown perimeter is one host may be a node on two or more different networks.&lt;b&gt; &lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.25in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level1 lfo4"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Many points of attack, access controls on one machine preserves the secrecy of data on that processor. However, files stored in a remote network host may pass through many host machines to get to the user.&lt;b&gt; &lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.25in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level1 lfo4"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Unknown path may be many paths from one host to another and users generally do not have control of how their messages are routed.&lt;b&gt; &lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.25in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level1 lfo4"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Label formats differences is a problem which may occur in multilevel systems is that the access labels may have different formats since there is no standard &lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:1.25in;mso-add-space:auto; text-indent:-.25in;mso-list:l1 level1 lfo4"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Anonymity is attack can passed through many other hosts in an effort to disguise from where the attack originated&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Network Security problem area:&lt;/p&gt;&lt;p class="MsoNormal"&gt;Authentication&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Deals with determining whom you are talking to before entering into a business deal or &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;before revealing sensitive information&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle"&gt;Secrecy&lt;/p&gt;&lt;p class="MsoListParagraphCxSpMiddle"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;What usually comes to mind when people think about network security&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle"&gt;Non-repudiation&lt;/p&gt;&lt;p class="MsoListParagraphCxSpMiddle"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Deals with signature&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle"&gt;Integrity control&lt;/p&gt;&lt;p class="MsoListParagraphCxSpMiddle"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Keeping information is not modified, add or delete by unauthorized user&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;                    &lt;p class="MsoListParagraphCxSpFirst" style="margin-left:.75in;mso-add-space:auto; text-indent:.25in"&gt;&lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:.75in;mso-add-space:auto"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-5825382322905136313?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/5825382322905136313/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/09/lecture-6-security-in-network.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/5825382322905136313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/5825382322905136313'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/09/lecture-6-security-in-network.html' title='Lecture 6: Security in Network'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-1058589110623305561</id><published>2009-09-04T23:40:00.000+08:00</published><updated>2009-10-30T05:43:15.995+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 5'/><title type='text'>Lab 5: Web Application Security</title><content type='html'>&lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;text-align: justify;line-height:normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:TTE1805540t00"&gt;Web Application&lt;span class="Apple-style-span" style="font-weight: normal; "&gt; &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;text-align: justify;line-height:normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1805540t00"&gt;Web application is an application that can be accessed using a web browser over a network. It is developed using browser-supported language such as HTML, JavaScript, PHP, ASP and etc. We also can use software such as dreamweaver to create a web application. The script produced is then rendered by common web browser. User can access web application anywhere and at any time, but user need to connect to a network connection and there is a web browser installed on the machine. This ease of usage makes web application popular among&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;text-align: justify;line-height:normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1805540t00"&gt;internet user. Moreover the ability to update and maintain web applications without distributing and installing software on potentially thousands of client computers contribute to the popularity of the webapp. Nowadays webapp is used for accessing mail, online banking, online shopping, online reservation, wikis and many other functions.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;text-align: justify;line-height:normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1805540t00"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1805540t00"&gt;The Open Web Application Security Project (OWASP) is an open community that focuses on improving the security of application software. Anyone can join this community and contribute an idea for developing secure software. OWASP provide free material such as article on secure programming, security testing guide and much more but all of the material is under free software license.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;text-align: justify;line-height:normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;strong&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Arial"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;text-align: justify;line-height:normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;strong&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Arial"&gt;&lt;o:p&gt;&lt;span class="Apple-style-span" style="font-weight: normal; "&gt;&lt;strong&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Arial"&gt;WebGoat&lt;/span&gt;&lt;/strong&gt;&lt;span class="apple-converted-space"&gt;&lt;b&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Arial"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family: Arial"&gt;WebGoat is simulation toolkit used to demonstrate how we can exploit the vulnerabilities of a poorly design web application.&lt;/span&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1805540t00"&gt; WebGoat provide hints and code to fexploit the vulnerabilities. WebGoat will keep track on the progress of the user on every lesson they completed, user can see their level of competence in trying to solve every problem given in the lesson.The primary goal of the WebGoat project is simple, to create a de-facto interactive teaching environment for web application security.&lt;/span&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Arial"&gt;
&lt;strong&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Arial"&gt;
&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Arial"&gt;&lt;strong&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Arial"&gt;WebScarab&lt;/span&gt;&lt;/strong&gt;&lt;span class="apple-converted-space"&gt;&lt;b&gt; &lt;/b&gt;&lt;/span&gt;&lt;b&gt;
&lt;/b&gt;
&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:Arial"&gt;WebScarab is another tool to expose the working of an HTTP(S) based application, whether to allow the developer to debug otherwise difficult problems, or to allow a security specialist to identify vulnerabilities in the way that application has been designed or implemented. WebScarab can use in any platform because it developed use JAVA programming language. WebScarab can intercept HTTP and HTTPS communication.&lt;/span&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:Helvetica"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-1058589110623305561?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/1058589110623305561/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/09/lab-5-web-application-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/1058589110623305561'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/1058589110623305561'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/09/lab-5-web-application-security.html' title='Lab 5: Web Application Security'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-6597549805611594153</id><published>2009-09-04T20:12:00.000+08:00</published><updated>2009-10-30T00:46:57.667+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 5'/><title type='text'>Lecture 5: Database Security</title><content type='html'>&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;&lt;span style="font-size:18.0pt;line-height:115%;font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Database Security&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Database security is a protection located in database to protect from unauthorized access. Database security become important because information is critical resource in enterprise, securing become billion dollar industry, and people want to protect their confidential information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Characteristic of good database security:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l1 level1 lfo1"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Data independence&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Shared access&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Minimal redundancy&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Data consistency&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Data integrity&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;      In database there are four levels of security:
&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Physical security (such as medium safekeeping and fire protection or fire wall)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Operating system security ( use of an access control matrix)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;DBMS security (protection and query mechanism)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Data encryption (standard data encryption and using RSA Method)&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;                    &lt;p class="MsoListParagraphCxSpLast" style="margin-left:0in;mso-add-space:auto"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;The first three levels in database security cannot provide a totally satisfactory solution because it’s hard to control disclosure of raw data and confidential data in distributed database, invalid to control sensitive data. To solve the problem, used encryption method, data is encrypted into cipher text and only be decrypted using decryption key.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Privacy mean unauthorized user cannot disclose data inside database.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Integrity mean unauthorized user cannot modify data inside database.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Availablelity mean authorized user can access database unfailingly.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Reliability and integrity:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l2 level1 lfo2"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Database integrity is concern to protect whole database from damage.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Element integrity is concern specific values of element only can be changed by authorized person.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;Element accuracy is concern correct values are written in database.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;      &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Sensitive data is data that should not be made public. There are many factor can make data become sensitive; data is inherently sensitive, declared sensitive, from sensitive source, or sensitive in relation to previously disclosed information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-6597549805611594153?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/6597549805611594153/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/09/lecture-5-database-security.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/6597549805611594153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/6597549805611594153'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/09/lecture-5-database-security.html' title='Lecture 5: Database Security'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-6835015716245010277</id><published>2009-08-28T23:54:00.001+08:00</published><updated>2009-10-30T00:04:32.086+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 4'/><title type='text'>Lab 4: Cryptography Extended</title><content type='html'>&lt;p class="MsoNormal"&gt;Cryptography Extended&lt;/p&gt;  &lt;p class="MsoNormal"&gt;In this lab we learn that cryptography algorithm can be classified into two categories, symmetric and asymmetric. Symmetric is using same key to encrypted and decrypted the plain text whereas asymmetric using different key to encrypted and decrypted plain text. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;Symmetric can divide to:&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="margin-left:.75in;mso-add-space:auto; text-indent:-.25in;mso-list:l1 level1 lfo1"&gt;&lt;span style="mso-bidi-font-family:Calibri"&gt;&lt;span style="mso-list:Ignore"&gt;1.&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Substitute encryption&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.25in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level1 lfo2"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;In substitute encryption, character in plain text being substitute with another character. Each character can be substitute with one character or multiple characters. &lt;b style="mso-bidi-font-weight:normal"&gt;Caesar cipher&lt;/b&gt; is example of substitute with one character and &lt;b style="mso-bidi-font-weight: normal"&gt;Vigenere cipher&lt;/b&gt; is example of substitute with multiple characters. Caesar cipher is easy to break by using brute force attack; an attacker can easily try every combinations of character to break the code as the numbers of possibility is 26. Vigenere cipher is an improvement from Caesar cipher.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:.75in;mso-add-space: auto;text-indent:-.25in;mso-list:l1 level1 lfo1"&gt;&lt;span style="mso-bidi-font-family:Calibri"&gt;&lt;span style="mso-list:Ignore"&gt;2.&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Transposition encryption&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:1.25in;mso-add-space:auto; text-indent:-.25in;mso-list:l0 level1 lfo2"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;This method is change the location of characters or reordering the character in plain text. The first character in plain text might be placed on fifth position and fifth character might be placed in another location in plain text.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Asymmetric encryption involves two key in encryption and decryption. &lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;The encryption key is called public key and decryption key called private or secret key.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;These algorithms allow the public key to be publicized, which means people with the public key can encrypt the plain text and the proper recipient with the private key can decrypt the plain text. To produce this to key used RSA algorithm. RSA is founded by Rivest, Shamir and Adleman of MIT in 1977.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-6835015716245010277?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/6835015716245010277/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/08/lab-4-cryptography-extended.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/6835015716245010277'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/6835015716245010277'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/08/lab-4-cryptography-extended.html' title='Lab 4: Cryptography Extended'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-4979602735439270612</id><published>2009-08-28T23:40:00.001+08:00</published><updated>2009-10-29T23:53:35.645+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 4'/><title type='text'>Lecture 4: Operating System</title><content type='html'>&lt;p class="MsoNormal" align="center" style="text-align:center"&gt;OPERATING SYSTEM&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Memory protection is preventing one process from corrupting the memory. There are methods for protecting memory:&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;/span&gt;&lt;span&gt;&lt;span class="Apple-style-span"   style="font-family:'Times New Roman';font-size:78%;"&gt;&lt;span class="Apple-style-span" style="font-size: 9px;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Fence is preventing faulty user program from destroying part of the resident portion of the operating system. There are two types of fence:&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo1"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Fixed fence( predefined memory access)&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;A method to confine user to one side of the boundary.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo1"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Register fence (used hardware register)&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Contain address of the end of the operating system.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;    &lt;/span&gt;Relocation is a process of changing all address to reflect actual address which the program is located.&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;    &lt;/span&gt;Base / Bound Register &lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;is useful in knowing how much space is available and checking overflows&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"   style="font-family:Symbol;font-size:130%;"&gt;&lt;span class="Apple-style-span" style="font-size: 16px;"&gt;   &lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Tagged Architecture is used to solve problem in contiguous nature and all or nothing situation for sharing.&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"   style="font-family:Symbol;font-size:130%;"&gt;&lt;span class="Apple-style-span" style="font-size: 16px;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Segmentation is divide process into pieces with different rights.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;        &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo1"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Benefits of segmentation&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Each address reference checked for protection&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;User cannot access to unpermitted segment&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;User can share access with different rights.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo1"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Problem in segmentation&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Segments cause fragmentation of main memory because they are varying sizes.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;If swapping is used then additional memory management techniques must be employed &lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;The operating system’s lookup of the name in the table can be slow&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;    &lt;/span&gt;Paging is divide program into equal size; frame is divide memory into equal size.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo1"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Advantages of paging&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Each page is the same size thus fragmentation is reduced&lt;b&gt; &lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Addressing beyond a page is not a real problem since a carry just refers to the next page.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo1"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Disadvantages of paging&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Loss of individual access rights since there is not necessarily a relationship between lines of code in a page (unlike program segmentation) &lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;    &lt;/span&gt;Combine paging with segmentation used to break each segment into equal sized pages.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo1"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Advantages of combining segmentation with paging&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Retained the logical unity of the segment&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.5in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Permitted differentiated protection for the segments&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo1"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Disadvantage&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:1.5in;mso-add-space:auto; text-indent:-.25in;mso-list:l0 level3 lfo1"&gt;&lt;span style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"&gt;&lt;span style="mso-list:Ignore"&gt;§&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Added an additional layer of translation for each address&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Password is a character of string that used to authenticate identity of user.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Authentication is verification of someone identity who generated some data.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-4979602735439270612?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/4979602735439270612/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/08/lecture-4-operating-system.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/4979602735439270612'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/4979602735439270612'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/08/lecture-4-operating-system.html' title='Lecture 4: Operating System'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-8350478672064011549</id><published>2009-08-09T20:20:00.000+08:00</published><updated>2009-10-27T01:19:08.639+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 3'/><title type='text'>Lab 3: Authetication and Basic Cryptography</title><content type='html'>&lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi- font-family:TTE1E91888t00;color:black;"&gt;Authentication&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:TTE1E91888t00;color:black;"&gt; is a process to identify something or someone to prove that claims by the subject is true.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;Authentication principles:&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;- The claimant demonstrates knowledge of something,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in;margin-bottom: .0001pt;mso-add-space:auto;line-height:normal;mso-layout-grid-align:none; text-autospace:none"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;   e.g. password.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in;margin-bottom: .0001pt;mso-add-space:auto;line-height:normal;mso-layout-grid-align:none; text-autospace:none"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;- The claimant demonstrates possession of something,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in;margin-bottom: .0001pt;mso-add-space:auto;line-height:normal;mso-layout-grid-align:none; text-autospace:none"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;  e.g. a physical key or card.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in;margin-bottom: .0001pt;mso-add-space:auto;line-height:normal;mso-layout-grid-align:none; text-autospace:none"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;- The claimant exhibits some required immutable characteristics,&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in;margin-bottom: .0001pt;mso-add-space:auto;line-height:normal;mso-layout-grid-align:none; text-autospace:none"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;  e.g. a finger print.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in;margin-bottom: .0001pt;mso-add-space:auto;line-height:normal;mso-layout-grid-align:none; text-autospace:none"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;- Evidence is presented that the claimant is at some particular place or time.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoListParagraphCxSpMiddle" style="margin-bottom:0in;margin-bottom: .0001pt;mso-add-space:auto;line-height:normal;mso-layout-grid-align:none; text-autospace:none"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;- The verifier accepts that some other party, who is trusted, has already established authentication.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;b style="mso-bidi-font-weight: normal"&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi- font-family:TTE1E91888t00;color:black;"&gt;Cryptography&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-bidi-font-family:TTE1E91888t00;color:black;"&gt; is one of main tools for privacy which makes the information is unintelligible for unauthorized person. One of cryptography methods is &lt;b style="mso-bidi-font-weight:normal"&gt;encryption&lt;/b&gt;. Encryption not prevents access to the information or data, but it ensures unauthorized person cannot understand the content of the information. The original message is known as plain text and encrypted massage known as the chipper text. Encryption covers both encoding and enciphering, encoding is translating words into other words and enciphering is translating symbols or letters.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;Factors in security of encryption:&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;1. The algorithm must be very hard to decrypt on the basis of cipher text alone.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;2. Priority secrecy of the key, not secrecy of the algorithm.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;    &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height: normal;mso-layout-grid-align:none;text-autospace:none"&gt;&lt;span style="font-family: &amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-bidi-font-family:TTE1E91888t00;color:black;"&gt;There are two types of cryptography, symmetric and asymmetric. The difference between these two methods is only in number of key use to encrypt and decrypt. In symmetric method use same key to encrypt and decrypt data whereas asymmetric use for encrypt and decrypt is different.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-8350478672064011549?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/8350478672064011549/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/10/lab-2-authetication-and-basic.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/8350478672064011549'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/8350478672064011549'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/10/lab-2-authetication-and-basic.html' title='Lab 3: Authetication and Basic Cryptography'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-199669288554992321</id><published>2009-08-07T23:10:00.000+08:00</published><updated>2009-10-27T01:18:38.587+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 3'/><title type='text'>Lecture 3: Program Security</title><content type='html'>&lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" align="center" style="text-align:center"&gt;Program Security&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Secure program is preventing program from any vulnerability. There are two type of program error, no malicious and malicious.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Non malicious program error:&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l4 level1 lfo1"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;   &lt;/span&gt;Buffer over flows&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l4 level2 lfo1"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Array bound in the system is accidentally not checked.&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-indent:-.25in;mso-list:l4 level1 lfo1"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"   style="font-family:Symbol;font-size:130%;"&gt;&lt;span class="Apple-style-span"  style="font-size:16px;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Incomplete mediation&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left:1.0in;mso-add-space:auto; text-indent:-.25in;mso-list:l4 level2 lfo1"&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-Courier New&amp;quot;font-family:&amp;quot;;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Data being exposed or uncontrolled.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Malicious code is unanticipated effect in programs generated on intent of damage. Malicious program has two types, need host program and independent. Need host program mean the code need a host before it does harm into the system. Independent means malicious program can harm the system directly and does not need a host.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Need host program:&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l0 level1 lfo2"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;   &lt;/span&gt;Trapdoor is writing undocumented entry point into code for debugging can allow unwanted user.&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;   &lt;/span&gt;Logic boom is malicious code that activates on a event.&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;   &lt;/span&gt;Trojan is a program that performs useful function but sometime it performs an unexpected function.&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Virus is a code that copy itself to executable program to runs it functions (modify files or OS).&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;        &lt;p class="MsoNormal"&gt;Independent program:&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l5 level1 lfo3"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;   &lt;/span&gt;Worm is a code that can replicate itself through a network.&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Bacteria / rabbit is a code that will replicate itself until it exhausted the resource or until it fills all disk space.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;Difference of virus and worm&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Virus:&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l2 level1 lfo4"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"   style="font-family:Symbol;font-size:130%;"&gt;&lt;span class="Apple-style-span"  style="font-size:16px;"&gt;   &lt;/span&gt;&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Need host&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Activated by external action&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Replication limited to virtual system&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Only can attack single platform&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;        &lt;p class="MsoNormal"&gt;Worm:&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l1 level1 lfo5"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;   &lt;/span&gt;Self contained&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Activated by creating process&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;In network replication occurs across communication link.&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Can shut down entire network.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;        &lt;p class="MsoNormal"&gt;Virus has many types like listed below:&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l3 level1 lfo6"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Parasitic virus is a virus that attach itself into executable files and runs when host program run.&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Memory resident virus is virus that lodged in main memory as part of residual operating system.&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Boot sector virus is infects the boot sector and spread when the OS boots up.&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Stealth virus is a virus that designed to hide from virus scanning programs.&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family:Symbol;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Polymorphic virus mutates in new host to prevent from detection.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;          &lt;p class="MsoNormal" style="text-indent:.25in"&gt;We can prevent our system from infected by the virus by using detection tools, identification tools or removal tools. Scanner and disinfector are the most popular tools to protect our system from virus.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Do not open any attachment, downloaded files, and floppy disk unless they have been scanned. Other ways to prevent the system from virus are by using commercial software from established vendor and update the antivirus at least once a week. There is no real way to measure the amount of damage that malicious code can do, all one can do is estimate it. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-199669288554992321?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/199669288554992321/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/10/lecture-3-program-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/199669288554992321'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/199669288554992321'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/10/lecture-3-program-security.html' title='Lecture 3: Program Security'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-4714783478879303966</id><published>2009-07-30T20:20:00.003+08:00</published><updated>2009-10-27T01:09:08.329+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 2'/><title type='text'>Lab 2: Goal of Information Technology</title><content type='html'>&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Goal of Information Technology Security&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;text-indent: 0.5in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Information security provides a protection for the information, system, and hardware that use to store that information. Confidentiality,   integrity and availability are goals of information security.  Confidentiality provides privacy and protection to data in computer, which means only an authorized person can access the data. Integrity used to make only authorized person that can modify the data. To provide data integrity can use encryption. Availability make the data can be access any time without failure by an authorized person. These three elements must be balance, if not it will affect the functionality of the system. Combination of these three elements will provide a security for the data.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;text-indent: 0.5in; "&gt;&lt;span class="Apple-style-span" style="font-family: georgia; "&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: 13px; white-space: pre-wrap; "&gt;&lt;a href="http://www.uploadhouse.com/viewfile.php?id=4767683&amp;amp;showlnk=0" target="_blank"&gt;&lt;img alt="Image Hosted by UploadHouse.com" border="0" src="http://img3.uploadhouse.com/fileuploads/4767/4767683cf091c8a3dabbab0ae48d248dceb2b96.gif" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;text-indent: 0.5in; "&gt;&lt;span class="Apple-style-span" style="font-family: georgia; "&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: 13px; white-space: pre-wrap; "&gt;&lt;span class="Apple-style-span" style="font-family: georgia; font-size: 16px; white-space: normal; "&gt;1. Convert FAT32 to NTFS&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: left;text-indent: 0.5in; "&gt;  &lt;/p&gt;&lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;There are two type of partition in windows, FAT32 and NTFS.  Difference between these two types is FAT32 not offer local file security. You need to convert FAT32 to NTFS to get local file security. To convert FAT32 drive into NTFS, just follow this step:&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;a.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Open your winserv03 virtual machine and log on as Administrator (don’t forget to take a snapshot of your virtual machine before start the task)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;b.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Click &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Start&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;c.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Click &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Run&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt; and type &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;cmd&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt; to run command prompt.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;d.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Use command &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;chkntfs d: &lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;to check whether the drive use NTFS or not. You will see message “D: is not dirty”, it means no corruption in that drive.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;e.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;If drive is FAT32, use command &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;convert d: /fs:ntfs&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt; to convert your drive into NTFS.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;f.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;If the drive has volume label, enter it when prompted.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;g.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Use command &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;chkntfs d:&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt; to make sure the drive is NTFS&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;h.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Restart your computer.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; "&gt;&lt;o:p&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt; &lt;/span&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;2. Make Authorized folder&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Data confidentiality is making sure those people whom access the certain data actually have that access. NTFS can used to protect from intruders whom may have physical access to the data. In this task, we will need 2 user accounts.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;"&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Creating User Account&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;a.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Go to &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Start &gt; Administrative Tools &gt; Computer Management&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;b.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Choose &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Local User and Groups&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;, double click on &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;user&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt; folder.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;c.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Right click on the pane and choose &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;New user&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;, fill up the information.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align: justify;margin-left: 0.5in; "&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Creating data Confidentiality between 2 Accounts&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;a.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Log on to windows as Administrator.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;b.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Open drive D and create new folder name &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Confidentiality.&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;c.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Open Confidentiality folder and create folder name &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;User1folder.&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;d.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;To secure the folder, right click on the folder and click &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Properties&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;e.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Click &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Security &lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;tab ( only available in NTFS)&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;f.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Click on &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Advance&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt; button and uncheck the box “&lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Allow inheritable permission from parent to propagate to this object”&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;g.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;You will receive a message box, click &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Copy&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt; to retains the permissions.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;h.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Click &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Add&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;, and new window will pop up.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;i.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Type &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;User1 &lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;as object name and click &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Check Names&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;, then click &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Ok&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;j.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Click &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Allow full control&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt; in permission entry windows, and then click Ok.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;k.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Remove the others username except Administrator, System, and User1, and click Ok.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;l.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Close all windows and log off.&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="text-align: justify;margin-left: 1in; text-indent: -0.25in; "&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;m.&lt;/span&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;Log on as User2, can you open folder &lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;User1Folder&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"  style="font-family:georgia;"&gt;?&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-4714783478879303966?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/4714783478879303966/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/07/lab-2-goal-of-information-technology.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/4714783478879303966'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/4714783478879303966'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/07/lab-2-goal-of-information-technology.html' title='Lab 2: Goal of Information Technology'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-6021974697667963457</id><published>2009-07-28T22:07:00.000+08:00</published><updated>2009-10-27T01:19:32.424+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 2'/><title type='text'>Lecture 2: Athentication and Basic Cryptography</title><content type='html'>&lt;p class="MsoNormal"&gt;&lt;span style="line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;font-size:12.0pt;"&gt;In lecture 2 we learn about authentication and basic cryptography. Authentication is identity of someone who generates data being verified. Authentication used to protect information or data from active attack. There are many classification to verify identity of someone, we can use password, by identity card such as smart card or passport, using physical characteristic such as finger print and retina, and also by signature. Password is a character of string that used to authenticate identity. To make password hard to guessed we must combine number and letter, uppercase and lowercase, and also include symbol in the password. Even though we already combine all those things to create password, is not impossible the password being guessed by the hacker. To prevent that there is a method, cryptography method. Cryptography is convert plain text into cipher text. The idea of cryptography is to disguise the information and make it meaningless to unauthorized user. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;font-size:12.0pt;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;font-size:12.0pt;"&gt;Cryptography terminology:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-indent:-.25in;mso-list:l0 level1 lfo1"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="line-height:115%;font-family:Symbol;mso-fareast-font-family: Symbol;mso-bidi-font-family:Symbol;font-size:12.0pt;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span style="line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;font-size:12.0pt;"&gt;Plain text&lt;/span&gt;&lt;/b&gt;&lt;span style="line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;font-size:12.0pt;"&gt; is the original text.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span style=" line-height: 115%; font-size:12pt;"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;font-size:12.0pt;"&gt;Cipher text&lt;/span&gt;&lt;/b&gt;&lt;span style="line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;font-size:12.0pt;"&gt; is the coded text.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;span lang="EN-AU"  style=" line-height: 115%; font-size:12pt;"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-AU"   style=" line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt;Cipher&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-AU"   style="line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt; - algorithm for transforming plaintext to ciphertext&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="line-height:115%;font-family:Symbol;mso-fareast-font-family: Symbol;mso-bidi-font-family:Symbol;font-size:12.0pt;"&gt;&lt;span style="mso-list:Ignore"&gt;&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="Apple-style-span"   style="font-family:Symbol;font-size:130%;"&gt;&lt;span class="Apple-style-span"  style=" line-height: 18px;font-size:16px;"&gt;  &lt;/span&gt;&lt;/span&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span lang="EN-AU"   style=" line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt;Key&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-AU"   style="line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt; - info used in cipher known only to sender/receiver&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;span lang="EN-AU"  style=" line-height: 115%; font-size:12pt;"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-AU"   style=" line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt;Encipher (encrypt)&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-AU"   style="line-height:115%; Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt; - converting plaintext to ciphertext&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;span lang="EN-AU"  style=" line-height: 115%; font-size:12pt;"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-AU"   style=" line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt;Decipher (decrypt)&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-AU"   style="line-height:115%; Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt; - recovering ciphertext from plaintext&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;span lang="EN-AU"  style=" line-height: 115%; font-size:12pt;"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-AU"   style=" line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt;Cryptography&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-AU"   style="line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt; - study of encryption principles/methods&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;span lang="EN-AU"  style=" line-height: 115%; font-size:12pt;"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-AU"   style=" line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt;Cryptanalysis (codebreaking)&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-AU"   style="line-height: 115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt; - study of principles/ methods of deciphering ciphertext &lt;i&gt;without&lt;/i&gt; knowing key&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;span lang="EN-AU"  style=" line-height: 115%; font-size:12pt;"&gt;&lt;span class="Apple-style-span"  style="font-family:Symbol;"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-AU"   style=" line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt;Cryptology&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-AU"   style="line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;; mso-ansi-language:EN-AUfont-family:&amp;quot;;font-size:12.0pt;"&gt; - field of both cryptography and cryptanalysis&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;                  &lt;p class="MsoListParagraphCxSpLast"&gt;&lt;span style="line-height: 115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;font-size:12.0pt;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="line-height:115%;Georgia&amp;quot;,&amp;quot;serif&amp;quot;font-family:&amp;quot;;font-size:12.0pt;"&gt;Caesar cipher is letters A to W is encrypted by being represented by the letter that occurs three places after it in the alphabet. This cipher used by Julius Caesar in Gallic wars. Another way to protect the information is using digital signature. Digital signature is like hand written signature, its depend on the sender and same for all the message. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-6021974697667963457?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/6021974697667963457/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/07/lecture-2-athentication-and-basic.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/6021974697667963457'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/6021974697667963457'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/07/lecture-2-athentication-and-basic.html' title='Lecture 2: Athentication and Basic Cryptography'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-5936722805123829431</id><published>2009-07-19T13:43:00.006+08:00</published><updated>2009-10-26T22:11:23.687+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 1'/><title type='text'>Virtualization &amp; VMware</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(51, 51, 51);font-size:130%;"&gt;Virtualization&lt;/span&gt;&lt;span style="color: rgb(51, 51, 51);"&gt;



&lt;/span&gt;
&lt;span style="color: rgb(51, 51, 51);"&gt;Problem in developing new computer system is operating system for develop the system only compatible with the hardware from same vendor and cannot be implemented in another machines that have different architecture. For example, Windows application binaries will not directly execute on another processor. &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 51);"&gt;Virtualization &lt;/span&gt;&lt;span style="color: rgb(51, 51, 51);"&gt;used to eliminates these constraint and enables a much higher degree of portability and flexibility . Virtualization produced by adding software to an execution platform and give it appearance of different platform.&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 51);"&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(51, 51, 51);"&gt;



&lt;/span&gt;

&lt;span style="font-weight: bold; color: rgb(51, 51, 51);font-size:130%;"&gt;Virtual Machine&lt;/span&gt;&lt;span style="color: rgb(51, 51, 51);"&gt;



&lt;/span&gt;
&lt;span style="font-weight: bold; color: rgb(51, 51, 51);"&gt;Virtual machine&lt;/span&gt;&lt;span style="color: rgb(51, 51, 51);"&gt; is one of virtualization environment or duplicate of real machine. Virtual machine environment created by &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 51);"&gt;Virtual Machine Monitor (VMM)&lt;/span&gt;&lt;span style="color: rgb(51, 51, 51);"&gt;. VMM reproduces everything from the CPU instruction to the I/O devices in software of operating system which it run on. The underlying operating system is called host operating system, the operating system which runs on VMM is called guest operating system. Host operating system and guest operating system can be the same or different type of operating system. For example, Windows can runs as host operating system and Fedora as guest operating system and vice versa.





&lt;/span&gt;
&lt;span style="font-weight: bold; color: rgb(51, 51, 51);font-size:130%;"&gt;VMware Workstation&lt;/span&gt;&lt;span style="color: rgb(51, 51, 51);"&gt;



&lt;/span&gt;
&lt;span style="color: rgb(51, 51, 51);"&gt;VMware is example of a more recent VMM that has been developed. Another close environment which also provides virtualization is called emulator. Difference between emulator and VMM is VMM only let one guest operating system that run on the host system. VMware makes it possible for PC user to use multiple operating system in same PC. User can run multiple OS side by side and by just clicking mouse you can switch to different OS and share files by just drag and drop. VMware also have ability to preserves the state by taking a "snapshot", so user can do testing on virtual machine without worying the system will corrupt.





&lt;/span&gt;
&lt;span style="font-weight: bold; color: rgb(51, 51, 51);font-size:130%;"&gt;VMware Installation&lt;/span&gt;&lt;span style="color: rgb(51, 51, 51);"&gt;



&lt;/span&gt;
&lt;span style="color: rgb(51, 51, 51);"&gt;VMware can be downloaded from &lt;/span&gt;&lt;a style="color: rgb(51, 51, 51);" href="http://www.vmware.com/download/ws/"&gt;http://www.vmware.com/download/ws/&lt;/a&gt;

&lt;span style="font-weight: bold; color: rgb(51, 51, 51);"&gt;Installation&lt;/span&gt;

&lt;ol style="color: rgb(51, 51, 51);"&gt;&lt;li&gt;Double click VMware launcher to start the installation wizard.
&lt;/li&gt;&lt;li&gt;Click Next.&lt;/li&gt;&lt;li&gt;Choose Typical set up (if you already familiar with VMware you can choose Custom to choose features that you want to instal).                                         
&lt;/li&gt;&lt;li&gt;Choose the location for VMware installation.                                                                              
&lt;/li&gt;&lt;li&gt;Configure the sortcut and then click Next.&lt;/li&gt;&lt;li&gt;Click Install to start the installation, this will take several minutes to finish.&lt;/li&gt;&lt;li&gt;Enter the Serial Number for VMware (you can get the serial number inside your VMware folder).&lt;/li&gt;&lt;li&gt;Click Finish to finish the installation.&lt;/li&gt;&lt;/ol&gt;
&lt;span style="color: rgb(51, 51, 51);font-size:130%;"&gt;Creating Disk Image&lt;/span&gt;
&lt;ol style="color: rgb(51, 51, 51);"&gt;&lt;li&gt;RunVMware, from Home tab click New Virtual Machine, to open the virtual machine wizard.                                                                                                                                               &lt;a href="http://www.uploadhouse.com/viewfile.php?id=4347364&amp;amp;showlnk=0" target="_blank"&gt;&lt;img src="http://img4.uploadhouse.com/fileuploads/4347/4347364-holder-6c721cbb4731da3b3c358df122383695.jpg" alt="Image Hosted by UploadHouse.com" border="0" /&gt;&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Click Next to continue.&lt;/li&gt;&lt;li&gt;Choose Typical configuration, then click Next.&lt;/li&gt;&lt;li&gt;Choose the type of OS to be installed on virtual machine.&lt;/li&gt;&lt;li&gt;Name the virtual machine and specify where the disk image for virtual machine will be stored in hard disk.&lt;/li&gt;&lt;li&gt;For the Network Type select Use host-only Networking.&lt;/li&gt;&lt;li&gt;Specify disk capacity for virtual machine. Initially the size of disk image you created is small and as you installed virtual machine with OS and software, the will increase up to the storage capacity set in this configuration. Select Allocate disk space now and click Finish, this will take several.
&lt;/li&gt;&lt;li&gt; Click Close to end the installation wizard.&lt;/li&gt;&lt;/ol&gt;

&lt;span style="color: rgb(51, 51, 51);font-size:130%;"&gt;Installing Windows Server 2003 in virtual machine&lt;/span&gt;
&lt;ol style="color: rgb(51, 51, 51);"&gt;&lt;li&gt;Place Windows Server 2003 installer CD in cdroom drive.&lt;/li&gt;&lt;li&gt;From command menu click start the virtual machine or you can click start button on toolbar.&lt;/li&gt;&lt;li&gt;Once virtual machine start booting, you will see windows server 2003 installation page, just follow windows server 2003 installation steps.&lt;/li&gt;&lt;li&gt;After installation finish, you will see windows server 2003 login page.&lt;/li&gt;&lt;li&gt;Click on the console to start using windows server 2003, to get mouse pointer back to host desktop use CTRL + ALT.&lt;/li&gt;&lt;li&gt;To take a snapshot of your OS, just clicking button snapshot on toolbar, use button Revert if anything happened to your OS and choose your previous state.&lt;/li&gt;&lt;li&gt;To manage size of your console, you can click on Quick switch or select Full screen from View on the toolbar.&lt;/li&gt;&lt;/ol&gt;


&lt;span style="color: rgb(51, 51, 51);"&gt;Regards ^^&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-5936722805123829431?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/5936722805123829431/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/07/virtualization-vmware.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/5936722805123829431'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/5936722805123829431'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/07/virtualization-vmware.html' title='Virtualization &amp; VMware'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-6568977349278114383</id><published>2009-07-18T12:25:00.013+08:00</published><updated>2009-10-26T22:12:21.308+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Week 1'/><title type='text'>Introduction to Information Security</title><content type='html'>&lt;span style=";font-family:georgia;font-size:100%;"&gt;Information security&lt;/span&gt;&lt;span style="font-size:100%;"&gt;
&lt;/span&gt;&lt;span style=";font-family:georgia;font-size:100%;"&gt;

&lt;/span&gt;&lt;span style="font-size:100%;"&gt;
&lt;/span&gt;&lt;div  style="text-align: center;font-family:courier new;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.uploadhouse.com/viewfile.php?id=4340610&amp;amp;showlnk=0" target="_blank"&gt;&lt;img src="http://img0.uploadhouse.com/fileuploads/4340/4340610-holder-5dc5512c248e1d84dda816d675cae8fe.jpg" alt="Image Hosted by UploadHouse.com" border="0" /&gt;&lt;/a&gt;
&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size:100%;"&gt;

&lt;/span&gt;&lt;span style=";font-family:georgia;font-size:100%;"&gt;What is security??&lt;/span&gt;


&lt;span style="font-weight: bold;font-family:georgia;font-size:100%;"&gt;Security&lt;/span&gt;&lt;span style=";font-family:georgia;font-size:100%;"&gt; is state of being secure from any danger and protected from those whom would do harm.&lt;/span&gt;


&lt;span style="font-weight: bold;font-family:georgia;font-size:100%;"&gt;Information security&lt;/span&gt;&lt;span style=";font-family:georgia;font-size:100%;"&gt; mean that information is being protected and also the system and hardware for transmit the information being protected.&lt;/span&gt;



&lt;span style="font-size:100%;"&gt;

&lt;/span&gt;&lt;span style=";font-family:georgia;font-size:100%;"&gt;There are 3 step for being secure:&lt;/span&gt;


&lt;span style=";font-family:georgia;font-size:100%;"&gt;1. &lt;/span&gt;&lt;span style="font-weight: bold;font-family:georgia;font-size:100%;"&gt;Detection
&lt;/span&gt;&lt;span style=";font-family:georgia;font-size:100%;"&gt;Detect any danger that may harm your system by using scanner such as virus scanner, internet scanner, and Web server scanner.&lt;/span&gt;


&lt;span style=";font-family:georgia;font-size:100%;"&gt;2. &lt;/span&gt;&lt;span style="font-weight: bold;font-family:georgia;font-size:100%;"&gt;Prevention
&lt;span style="font-weight: bold;"&gt;    &lt;/span&gt;&lt;/span&gt;&lt;span style=";font-family:georgia;font-size:100%;"&gt;By setting your proxy and turn on your firewall, you already prevent your system from any danger such as virus.&lt;/span&gt;


&lt;span style=";font-family:georgia;font-size:100%;"&gt;3. &lt;/span&gt;&lt;span style="font-weight: bold;font-family:georgia;font-size:100%;"&gt;Recovery&lt;/span&gt;&lt;span style="font-size:100%;"&gt;
&lt;/span&gt;&lt;span style=";font-family:georgia;font-size:100%;"&gt;    Recover your system when it being infected by virus or anything that would damage your system. you can use cryptography technique.&lt;/span&gt;





&lt;span style=";font-family:courier new;font-size:100%;"&gt;Security principles :&lt;/span&gt;


&lt;span style="font-weight: bold;font-family:georgia;font-size:100%;"&gt;Confidentiality&lt;/span&gt;&lt;span style=";font-family:georgia;font-size:100%;"&gt; is prevention of unauthorized disclosure of information&lt;/span&gt;&lt;span style=";font-family:georgia;font-size:100%;color:black;"&gt;.&lt;/span&gt;


&lt;span style=";font-family:georgia;font-size:100%;color:black;"&gt;&lt;span style="font-weight: bold;"&gt;Integrity&lt;/span&gt; is prevention of unauthorized modification of information.&lt;/span&gt;


&lt;span style=";font-family:georgia;font-size:100%;color:black;"&gt;&lt;span style="font-weight: bold;"&gt;Availability&lt;/span&gt; is prevention of unauthorized withholding of information.&lt;/span&gt;





&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Security attack is classified into 2 types, &lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;font-size:100%;"&gt;passive attack&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt; and &lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;font-size:100%;"&gt;active attack&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;.&lt;/span&gt;&lt;/span&gt;



&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;Passive attacks is&lt;/span&gt;&lt;/span&gt;&lt;span style=";font-family:georgia;font-size:100%;color:black;"&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;monitoring the transmission. Usually used to obtain the information that is being transmitted. Passive attacks divide into 2 types, &lt;span style="font-weight: bold;"&gt;release of message content&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;traffic analysis&lt;/span&gt;.&lt;/span&gt;



&lt;span style=";font-family:georgia;font-size:100%;color:black;"&gt;Active attacks is involve some modification of data stream or creation of false stream to obtain an authorization of the data. Types of active attacks are &lt;span style="font-weight: bold;"&gt;masquerade&lt;/span&gt;, &lt;span style="font-weight: bold;"&gt;replay&lt;/span&gt;, &lt;span style="font-weight: bold;"&gt;modification of messages&lt;/span&gt;, and &lt;span style="font-weight: bold;"&gt;denial of services&lt;/span&gt;.
&lt;/span&gt;



&lt;div  style="text-align: center;font-family:courier new;"&gt;&lt;span style=";font-size:100%;color:black;"&gt;&lt;span style="font-weight: bold;"&gt;Passive attacks vs. Active attacks&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;
&lt;/span&gt;&lt;div style="text-align: left;"&gt;
&lt;div style="text-align: left;"&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=""&gt;Passive attacks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;o&lt;span style="font-size:7;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style=""&gt;Very difficult to detect&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;o&lt;span style="font-size:7;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style=""&gt;Feasible to prevent the success of this attack&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;o&lt;span style="font-size:7;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style=""&gt;Prevention rather than detection&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;·&lt;span style="font-size:7;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style=""&gt;Active attacks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;   &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;o&lt;span style="font-size:7;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style=""&gt;Difficult to prevent&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;o&lt;span style="font-size:7;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style=""&gt;Instead, the goal is to &lt;span style=""&gt;detect&lt;b&gt; &lt;/b&gt;&lt;/span&gt;active attacks and to &lt;span style=""&gt;recover&lt;b&gt; &lt;/b&gt;&lt;/span&gt;from any disruption or delays caused by them&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;&lt;span style=""&gt;o&lt;span style="font-size:7;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span style=""&gt;If the detection has a &lt;span style=""&gt;deterrent effect&lt;/span&gt;, it may also contribute to &lt;span style=""&gt;prevention&lt;/span&gt;.&lt;/span&gt;&lt;/p&gt;There are several ways to deal with harm that occurs when a threat is realized against a vulnerability.
&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Prevent it&lt;/span&gt;, by blocking the attack or closing the vulnerability.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Deter it&lt;/span&gt;, by making the attack harder, but not impossible.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Detect it&lt;/span&gt;, either as it happens or some time after the fact.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Deflect it&lt;/span&gt;, by making another target more attractive.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Recover&lt;/span&gt; from its effect.&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Encryption&lt;/span&gt; is making the interpretation is meaningless by scrambling the data without the intruder's knowing how the scrambling was done. Encryption enable us to provide security while accomplishing an important system or network task.

Security services:
&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Authentication&lt;/span&gt; is assurance that the communicating entity is the one claimed or assurance that the source of received data is as claimed.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Access control&lt;/span&gt; is prevention of unauthorized use of resource.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Data confidentiality&lt;/span&gt; is protect data from unauthorized disclosure.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Data integrity&lt;/span&gt; is assurance that the data received is as sent by authorized entity.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Non repudiation &lt;/span&gt;is to proof that the data sent by specified party and received by specified party.&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Security mechanism&lt;/span&gt; is any process that is designed to detect, prevent, or recover from any security attack. Security mechanism divided into 2 classes,  and &lt;span style="font-weight: bold;"&gt;Specific Security Mechanisms&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;Pervasive Security Mechanisms&lt;/span&gt;.





&lt;div style="text-align: center;"&gt;&lt;a href="http://www.uploadhouse.com/viewfile.php?id=4340612&amp;amp;showlnk=0" target="_blank"&gt;&lt;img src="http://img2.uploadhouse.com/fileuploads/4340/4340612-holder-ad7704a85094b5e3709daf58723c0d7f.jpg" alt="Image Hosted by UploadHouse.com" border="0" /&gt;&lt;/a&gt;  &lt;a href="http://www.uploadhouse.com/viewfile.php?id=4340625&amp;amp;showlnk=0" target="_blank"&gt;&lt;img src="http://img5.uploadhouse.com/fileuploads/4340/4340625-holder-dbf9d109dbe830b0d12fe03914bc953b.jpg" alt="Image Hosted by UploadHouse.com" border="0" /&gt;&lt;/a&gt;
&lt;/div&gt;&lt;span style="font-weight: bold;"&gt;
&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="font-weight: bold;font-family:georgia;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-6568977349278114383?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/6568977349278114383/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/07/introduction-to-information-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/6568977349278114383'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/6568977349278114383'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/07/introduction-to-information-security.html' title='Introduction to Information Security'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2956661363702348767.post-5758949088854740832</id><published>2009-07-18T10:14:00.003+08:00</published><updated>2009-07-18T10:33:04.809+08:00</updated><title type='text'>Prologue to my blog</title><content type='html'>&lt;span style="font-family:courier new;"&gt;Hi, wellcome to my blog.&lt;/span&gt;
&lt;br /&gt;&lt;/br&gt;
&lt;span style="font-family:courier new;"&gt;Here's my little oasis to share thoughts about anythings, especially about information technology security which i have learn at my campus.
&lt;/span&gt;&lt;br /&gt;&lt;/br&gt;
&lt;span style="font-family:courier new;"&gt;Please leave your comments as you please, but keep it clean from any vulgar word.  &lt;/span&gt;
&lt;br /&gt;&lt;/br&gt;
&lt;br /&gt;&lt;/br&gt;
&lt;span style="font-family:courier new;"&gt;Regards ^^&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2956661363702348767-5758949088854740832?l=ardidudidam.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ardidudidam.blogspot.com/feeds/5758949088854740832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://ardidudidam.blogspot.com/2009/07/prologue-to-my-blog.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/5758949088854740832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2956661363702348767/posts/default/5758949088854740832'/><link rel='alternate' type='text/html' href='http://ardidudidam.blogspot.com/2009/07/prologue-to-my-blog.html' title='Prologue to my blog'/><author><name>ardidudidam</name><uri>http://www.blogger.com/profile/09652997801275372309</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/_Rtotf9vjBxM/Sl3wlThmjxI/AAAAAAAAAAM/Jmvaom74OUA/S220/02122008728.jpg'/></author><thr:total>0</thr:total></entry></feed>
