Sunday, June 15, 2008

Network Security Software Risks & Vulnerabilities with Malware Prevention

By John M. Kennedy 
Introduction
Different people code different types of software. Therefore, software security issues stem from much of the same humans traits that code them in the first place. We can state that software is like people, you can find all kinds of them, in everywhere at anytime. In this era of hacktivism and cyberterrorism, it seems that crackers, cyberpunks or black-hat and grey-hat hackers have been able to translate the mightiest worst from humanity into computing. They use “deadly” routines or sets of attacking instructions to cause havoc or commit crimes for fun and profit and not necessarily done in that order. Therefore, I am telling you, the “Scarface’s tale” is nothing when comparing it to the nightmarish realities of the software security threats, risks and vulnerabilities, that I am presenting in the following pages. Notwithstanding, and for the last time, I am warning the reader, á la Jack Nicholson, especially when he characterized the Coronel Jessep, in the film, “A Few Good Men” (1992), perhaps “You can’t handle the truth!” Incidentally, for those who study software security, there should be a banner to warn them about it too, something like the inscription that Dante, in his “Divine Comedy”, told us that he found, when he was invited to enter the his mere self into hell, at the top of its doors: “Abandon hope all ye who enter here”. No wonder anymore why programmers have used, all along, names like Daemons (not precisely the Terminate and State Residents or TSRs or MS DOS environment.) and SATAN, to label their programs. Whatever, the danger might be or seem to be, as the “Man of Mancha” would have sang while crossing the borders of devilish domains, I shall encourage you to enter and while singing with me: “ …. to fight for the right without question or pause, to be willing to march into hell for a heavenly cause! … And this is exactly our jobs and the whole reason why the information systems security teams have been created. To do the right thing, to protect the most valuable asset therein in Plow of the Sea, Inc, i.e., its information. (Fitzgerald, M. 2001)
Network Security the level or Risk of Software
As a whole the level of risk that software represents is extremely high for GCI’s eCommerce venture. Azaris (2003) explains that network security software is vital for network users, information Technology [IT] professionals, and network security specialists (p. 1), hence the researcher implies its importance and ubiquity in our lives. Software is what makes hardware to process data in useful information; embeds the rules of communication or protocols; likely, it is used to commit all kind of malicious attacks, and software is what has made many people richer than the Sultans of Brunei. Therefore, let us immerse in the subject …
Bruce Scheneier (2007), the creator of Blowfish, an algorithm used for encryption, stated that information security is costing millions of dollars mainly because the software is insecure, due to bad design, poor feature implementation, security vulnerabilities and/or lack of adequate testing (p. 1). Well, as we know software permeates almost everything nowadays, what is software; it is so intangible and only is measurable perhaps by the amount of lines of code put together to do something. How exactly we put these lines of code logically together so the machine [CPU –Central Processor Unit and then the system] can work by following these commands determines the speed, utility and the versatility of the programs. Yes by all means, software are programs; as a program, software can be as small as one routine with a “laconic” set of instructions whose only purpose could be only to print one or more times the sentence “hello World” at the standard output stream device or screen or monitor. For instance, in C language the screen was called stdout and by default the stream was outputted to the terminal (you can redirect the output as well by the Shell’s Command Line Interface CLI ), and software can be very complex as an Operating Systems Like UNIX or Linux, whose kernels consists of several millions of lines of code or instructions. These lines of code are what programmers called the source code. For instance, the total number of the Source Lines of Code [SLOC], for the Linux kernel version 2.6, has been calculated as more than four million (exactly 4,287,449) (Wheeler, 2004) very complex software. It is a matter of fact, software can be so “effluvious” and “ethereal” that can be “loaded” in the most subtle and thinnest of devices, like the RFID, which in spite of many experts written about they have found flaws and vulnerabilities, people are using more and more to track almost everything, for instance, some of these transponders, are specified by the standards ISO-11785 and ISO-11784 for Radio-frequency identification, aka FDX-B. The code by itself is software “running” or “saving and responding” data in 128 bits devices, 64 bits of which it is utilized only for the Identification or ID information tracking system purpose.
Another subject is the firmware, its security poised other considerations of the sorts, for example, Booting, I personally, I don’t like to boot my systems at all (if you would click on “Booting” then you would understand why, and one more thing, remember the melody and reading it by following its rhythm, would you?). The Basic Input Output System [BIOS] is the software that is loaded before the OS does. It main purpose is to locate the bootstrap loader in the defaulted booting device of the system. This small program resides in the CMOS-Complementary Metal-Oxide Semiconductors, a Non-volatile Random Access memory chip that uses very little amount of energy from a battery and that is connecting to a quartz that oscillates evenly, called the RTC just to save some information like the date and time and the booting devices and the defaulted partitions when the computer is off. Well, the fact is that without or if the CMOS-BIOS hybrid device malfunctions, then the computer would be worthless.
Nowadays Firmware or BIOS vulnerabilities are also a new cause of preoccupation amount information security practitioners, BIOS chips have been the normal components of Motherboards, Network Interface Cards [NIC], video cards, but at the beginning, users were not able to updated these chips, that is why they were called Read Only Memory [ROM]; however, for some time now, users and operators can updated the BIOS or their machines, as to improve the system’s interoperability and compatibility with new and larger hard disk drives or other input/output [I/0] devices that offer more functionality. This process is called, “to flash the BIOS or CMOS”, the problem is that there is software, virus that could install itself and reside in these EPROMs (electrical programmable ROMs). Lately, as expected, the scenario seems to have been worsened by the apparition of the iWarp Ethernet NIC Cards, which can facilitate the detection of packet processing right out from the CPU, creating backchannels for bypassing completely the OS as serious threat for the security of the information (Jackson, 2007).
Mitigation against Malware
It is practically impossible to be fully protected and this means that what realistically networking security engineers and practitioners should be hopping for is for outreaching an acceptable level of security. Software security entitles the protection against malware from all its known and unknown forms, by perusing different tools, methods, network appliances and specialized combination of software, like: Firewalls, cryptography, network security administration and security programming development tools. However, all these software, controls and countermeasures to reduce the risks, will not work effectively without the addition of a well thought out security education, training and awareness program addressing the participation of all GCI’s stock holders (Pflegeer & Pfleeger, 2003).
Malware
Göran, Kaj & Peik, (2003) indicated that malware exploits vulnerabilities, and pointed to the 1992 Bowels and Pelaez’s simple taxonomy, which classified all malware in just two types: Programs Needing a Host, and self-reproducing malware (p.1 ). Let us see the following table below:
Bowels & Pelaez’s Malware Taxonomy
Programs Needing a Host
Self-reproducing
Trap Doors: Secret point of entrance to the system. This represents a serious threat.
Bacteria: self-replicating harmless program for only one detail that replicates so much that in the end could take all the capacity of the victim computer.
Logic Bomb: Waits for a date or and event to do their deeds. One of the earliest forms of Virus, very damaging in deed.
Trojan Horse: A “Goodie” with maladies.
Very serious threat.
Worm: Infects computers through network connections, can behave like virus and bacteria or could install Trojans too. Its effects are devastating.
Virus or Retrovirus: Infect other programs by copying its code to them and continuously infecting others. Serious Threat. Retrovirus behaves like a virus with the detriment-added attribute of being able to attack anti-virus; Even more serious.
Table 1. – The Malware Taxonomy (Göran, Kaj & Peik, 2003).
The rest of software can be a combination of all of the above mentioned like the infamous rootkits, which are very difficult to detect. Thus we have collection, prevention, detection and response mechanisms to deal with these malware maladies; a series of “anti-thesis” have been created for the purpose of responding to the imminence of viruses and retroviruses exploits: Therefore, we have antivirus in their many flavors and varieties, e.g. we are in the four generation of antivirus, being the latest mechanisms used by them Generic Decryption [GD], Digital Immune System technology [DIS] (Propose by IBM), GD is employed to protect polymorphic Viruses (Pflegeer & Pflegeer, 2003, Göran, Kaj & Peik, 2003, Panko, 2004). Recently antivirus programs are classified accordingly to what they are geared to protect, there are antivirus to protect gateways and firewalls, and files and database servers, and as always end users programs, operating systems and files. Figure 1 below show the classification according to the level of security that antivirus offer:
Figure 1 - Defense lines in antivirus protection (Göran, Kaj & Peik, 2003)
Firewalls protect the enterprise network at the perimeter, i.e. at the border, thus is a mechanism of defense that separates the network from the rest of the world, there are three common types of Firewalls: Packet-filtering router, application-level gateway or proxy server and circuit-level gateway external network-based security threats (Basta, 2007, Panko, 2004).
There are main two implementation of cryptography for networking security at the network layer level the IPSec and the Transport layer the TLS/SSL, proposed by the Internet Engineering Task Force, [IETF]. At the moment, IPSec is used mainly for Virtual Private Networks [VPN] but this could change as Secure Domain Name System or DNSSEC is earning acceptance (Göran, Kaj & Peik, 2003). The IETF standard Transport Layer Security [TLS] and Secure Socket layer [SSL] is used primarily for securing data communication carried on Hypertext Transfer Protocol [HTTP]. This Lead us to Web security and eCommerce security, were there are two main types of services to ponder transaction and access level security: thus we have the following mechanisms: HTTPS, the SSL Secured HTTP Protocol, the S-HTTP, Secure Hypertext Transfer Protocol, and the PCT, Private Communication Technology. Security administration counts with many programs for alerting, collecting, preventing and responding to incidents or events, like the so-called Intrusion Detection Systems [IDS] and the Intrusion Prevention Systems [IPS] (Panko, 2004).
Conclusion
Software, in their many manifestations, whereas in RFID, as Operating Systems or Network Protocols or like applications, is the means to produce information and for such to increase our knowledge and skills to solve our problems. As information is centric for our survival, so it is software as well.

References
Azari, R. (2003). Current Security Management & Ethical Issues of Information Technology. Hershey, PA, USA: Idea Group Inc., 2003. Retrieved January 20, 2008, from, http://wf2dnvr5.webfeat.org:80/8i3HJ1828/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10032091&ppg=18.
Basta, A. & Halton, W. (2007 August). Computer Security and Penetration Testing. Boston, Massachusetts: Course Technology, Thomson Learning, Inc.
Bellovin, S.M. (1989). Security Problems in the TCP/IP Protocol Suite. Murray Hill, New Jersey: AT&T Bell Laboratories. Retrieved January 20, 2008, from http://www.cs.columbia.edu/~smb/papers/ipext.pdf.
Birkholz, E. P. (2003). Special Ops: Host and Network Security for Microsoft, UNIX, and Oracle. Rockland, MA, USA: Syngress Publishing Retrieved January 20, 2008, from http://wf2dnvr3.webfeat.org:80/nDEHJ1268/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10023441&ppg=27.
Cisco IOS Security Configuration Guide Release 12.4. (2006 July 29). Corporate Headquarters. San Jose, CA: Cisco System, Inc. Retrieved January 20, 2008, from http://www.cisco.com/application/pdf/en/us/guest/products/ps6350/c2001/ccmigration_09186a00804f229a.pdf.
Coakes, E. (Editor). (2003). Knowledge Management: Current Issues and Challenges. Hershey, PA, USA: Idea Group Inc. Retrieved on January 13, 2008 from, http://http://wf2dnvr3.webfeat.org:80/nDEHJ1151/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10032062&ppg=22.
Ciampa, M. (2005). Security + Guide to Network Security: Fundamentals, 2nd Edition. Boston, Massachusetts: Course Technology, Thomson Learning, Inc.
Course Materials. (2008). Network Security. Course: CS653-0801A-01. Colorado Technical University. Retrieved January 19, 2008, from https://campus.ctuonline.edu/classroom/MultimediaCourseMaterials.aspx?Class=92946&tid=44.
Current Malware Threats and Mitigation Strategies. (2005 May 16). Informational Whitepaper. Multi-State Information Sharing and Analysis Center & US-CERT - United States Computer Emergency Readiness Team. Retrieved January 20, 2008, from http://wf2dnvr3.webfeat.org:80/R2LHJ138/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10158249&ppg=27.
Fitzgerald, M. (2001). Building B2B Applications with XML: A Resource Guide. New York, NY, USA: John Wiley & Sons. Retrieved January 21, 2008, from http://wf2dnvr3.webfeat.org:80/nDEHJ1195/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10001744&ppg=32.
Göran P., Kaj J. G. , Peik Å, (2003). Network security software, Current security management & Ethical issues of information technology, Hershey, PA: Idea Group Publishing.
Hassing, K., Kent, A. K., & Johnson, G. (2003). CCNA 1 & 2 Companion Guide, 3rd Edition. Cisco Networking Academy Program Indianapolis, IN: 2003.
Jackson, J. (2007 March 3). Assessing firmware vulnerability. Tech Blog, Government Computers News [GCN]. Retrieved January 21, 2008, from http://www.gcn.com/blogs/tech/43212.html.
Khosrow-Pour, M. (Editor). (2004). Annals of Cases in Information Technology, Volume 6. Hershey, PA, USA: Idea Group Inc. Retrieved January 19, from, http://wf2dnvr3.webfeat.org:80/nDEHJ1158/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10051156&ppg=113.
Maiwald, E. (2002). Security Planning and Disaster Recovery. Blacklick, OH, USA: McGraw-Hill Professional, 2002. Retrieve January 21, 2008, from http://http://wf2dnvr3.webfeat.org:80/R2LHJ12/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10043872&ppg=30.
Nelson, B., Phillips, F. E., & Steuart, C. (2004). Guide to Computer Forensics and Investigations. Boston, Massachusetts: Course Technology, Thomson Learning, Inc.
Panko R. R. (2005). Business Data Networks and Telecommunications, 5th Edition. Upper Saddle River, NJ: Prentice Hall- Pearson Education, Inc.
Panko R. R. (2004). Corporate Computers and Network Security. Upper Saddle River, NJ: Prentice Hall- Pearson Education, Inc.
Pflegeer C. P., & Pflegeer, S. L. (2003). Security in Computing, 3rd Edition. Upper Saddle River, NJ: Prentice Hall Professional Technical Reference, Prentice Hall- Pearson Education, Inc.
Ratnasingam, P. (2003). Inter-Organizational Trust for Business To Business E-Commerce. Hershey, PA, USA: Idea Group Inc. Retrieved January 12, 2008, from http://wf2dnvr3.webfeat.org:80/nDEHJ1167/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10032067&ppg=13.
Reuvid, J. (2006). Secure Online Business Handbook: A Practical Guide to Risk Management and Business Continuity (4th Edition). London, GBR: Kogan Page, Limited. Retrieved January 19, 2008, from http://wf2dnvr3.webfeat.org:80/R2LHJ138/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10158249&ppg=27.
Russell, T. (2000). Telecommunications Pocket Reference. New York, NY: McGraw- Hill Companies.
SANS Top-20 2007 Security Risks (2007 November 28). Annual Update. SANS Institute. Retrieved January 20, 2008, from http://www.sans.org/top20/.

Scheneier, B. (January 18, 2007). Information Security and Externalities. Retrieved January21, 2008, from http://www.schneier.com/blog/archives/2007/01/information_sec_1.html.

Tomasi, W. (2005). Introduction to Data communications and Networking, Upper Saddle River, NJ: Pearson Prentice Hall, Inc.

Wheeler, D. A. (2004 October 12). Linux Kernel 2.6: It's Worth More! Retrieved January 21, 2008, from http://www.dwheeler.com/essays/linux-kernel-cost.html


Saturday, June 14, 2008

Metasemantic Analysis


I am sharing with you this response....

Let me parse your message, since I always assume good faith from people and of course I do it with you, especially because I have a sense of spiritual intelligence behind your actions, and out of my believe in communication and education, I going to be a little granular with you in here, why? Because you have shown me respect with some of your feedback and I want to honor you as a colleague.

"I was rather impressed with what you did."

Thank you, as you might have seen I combined very fairly all of our contributions, as our interpretations, I was looking to balance up the gaps within each part, I did left some typos or minor mistakes though but due to my left eye that it was closing somehow on me, and it did not allow me to read well. It took me some hours of work and patience to put that together and I thrill that you have wrote me this line. Therefore, you make my day with this line "C."


"I am interested to know where you got some of those statistical slides from..."

The most brutal mistake for this presentation was to use MS-Project, I think; why? It is a cage difficult to get out of it. I have version 2003 and the graphics exporting and PERT analysis packages that offers are just not very helpful. Of course, the software has some things that are powerful, and helpful, but you need to battle with it. For instance, the ability to "extrapolate" quickly from the Gantt views to any other table, like the resources graph and matrix, or the PERT pessimistic table or resource use table. These things facilitates a great deal the allocation and determination of resources for tasks but once everything is Dandy and flashy inside one's Project file, it is not when it comes the time to show the world your work. Point in case, I expended a fruitful amount of hours to get the delicate information that I input in the WBS and GBS of this project in MS-project but if was not that smooth to export it to PowerPoint. I could have done it altogether in Excel, in which I can graph and calculated almost every thing, form the most ridiculous degrees of sigma or STDDEVs to the most demanding Riemann or Lévesque integration or other "areas under or over the curve" with it.

Therefore for statistics, I would say Excel but not for cartography though or mind mapping. Sometimes, I use Mathematica from Wolfram or Maple Software from a Canadian group, to do the calculations, when the models or simulations are arduous and intensive and require more powerful software functionality. Lately, I have been working out of my own interest, in a group collaborating in notions of graph theory, trees, connectivity, distance in graphs, Eulerian, Hamiltonian and planar graphs, and graph colorings. One of the results of it is the Gvedit or Graphvis, also it is the output of the AT&T labs’ credit. This program uses a DOT language to create the most complex graphs. The curious thing is that because this language utilizes the extension name .dot for saving its files, they open in MS-Word, and you can edit these files with that but it is better of use Emacs, vi or just notepad instead, It is terribly easy to grasp for making complex critical path graphs with it. Find it at http://www.graphviz.org/ for free and under the Common Public License. Hope you like it and give me your feedback about it.

In this particular case, I used MS-project, I detailed all the information out of my experience and research as I used some of your information as well at the input stage, as I was getting cranky with MS-Project I used many other programs, including Excel. Remember I used data and I manipulated that data from scratch just to make sure. For example, you budget was 13,000,000 or more in part because you figure out, that each workstation will cost around $1,7000.00 or so and then you calculate licenses for each user. I accepted the Exchange server, licenses part as in one slide I inputted your information as is in one slide’s note. However, the analysis and closer inspection with MS-Project and other tools showed other things as well that end with other results and I am sure with a little more time, we could change many things. Therefore, for the statistics I could use the formulas of Excel, or evenly calculated by hand as needed. So this is how I extracted the statistical slides, by figuring out the Phases or milestones and then typing and analyzing the whole WBS in MS-Project, followed by inputting many weights at the entry widget of the PERT analysis also I used Excel, for the PERT's Time Estimate or TE formula.

"Do you possess some type of software that creates that based upon the info you received from us?" [This question is loaded. I t is identified as the metasemantic root of the whole message, for such is the proto-intentional engine behind this question. This is to collapse many interpretations of the metasemantic world. (This is just for the author who is currently studying memetic worlds as metasemantic communications) as he engages with others, the reader please never mind]

Now, in terms of the graphics, all I made from the scratch myself except from one of two that were very generic and inconsequential because, they were from one of the public domain archives and illustrated some or other point. Most of the Graphs that I made are based on the combination of others or out of my research, some are entirely mine. In any case, I strive to give credit to all the sources that provides me with inspiration, knowledge base or ideas. I do this by releasing most of my educational work under Creative Commons Share Alike version 3.0, and under the GFDL too sometimes. The reason, why I do this with my documentation and with my graphics, is that some people have published some of my work, making money in the interim, but without even given credit. For example in one of the slides is depicted a complete workflow, I did that form scratch with one of my software tools based on the figure of Richman's book; and so he and his book, figure and page, it is clearly cited in that slide. I am very protective of people intellectual, private and freedom rights, I believe that these rights typify our western culture and societies.

Exactly, what it has made ad hoc for this project? I made the theme of the presentation. How? Just with PowerPoint. Other graphic and the statistical information were made with a combination of tools.

I looked for prices in http://Pricewatch.com (I am sure you know this site) primary to make sure about the hardware. I just put some of my experience in building networks and internetworks, if you read the breakdown carefully you can find a down to the earth approach to solve the problems and with the mentality of going beyond into the scalability and Security areas of an email system. Therefore, the only thing I needed was to make sure the number of dollars since practically all the information I had it in my head but I always check and recheck. This is to say I believe in my memory but much more in my reason. Your approach was correct and in nature could work but was a little too expensive. Now, in order to manage files and information, I used different mapping tools too. I also use graphic tools mostly non-proprietary, like Graphvis. I like to code with [SVGs] Scalable Vector Graphic and XML whether using AJAX or Comet paradigms. I use sometimes Illustrator, or Photoshop, and Corel Paint with Blender and Rhino but and for video Edition I use Avis. There are plenty number of tools to develop good graphic, maps for GIS, that are essentially Open source, that I have used but you will be get tire if I continue, most people do, that is why, I am writing a book instead. Why open source? Well, you got the "bless" of the source code and you can them customize security from the kernel up, if it were an OS, for instance.

The other main thing is your hardware capabilities; I build my hardware but lately because price and quality I just buy it. Anyway, you cannot compiled nothing if you don't have the right engine, you need at least 4 gigs of RAM and double-core Quad [Whether be, AMD Xeon, or Intel Extreme] for say the least, and even though it could take you a long time to learn some sophisticated tools, like Rhino or Adobe CSPS3. That is why I prefer to use vectorized images rather than pixilated or bitmapped-rasterized pictures or graphs. However, this could take you to experience some grievances because not all browsers are created equal, they do not render equally the DOM [Document Object Model] objects the same. Firefox is "good", meaning, it is SVG compatible, as it is not the case with IE, it needs a plug-in, and this made the distribution of your image just a little sort of fuzzy and harsh for you.

In addition, If I would not have any computers I will do fine too, I still have my own hands, I studied Technical drafting and geometry descriptive since I was a 14 year-old, so I have plotted mechanical parts with my own hands all along and without any CAD software. If what we are talking were about Art, I teach myself to paint at the age of 10. Then, late on life and influence by the life of Gauguin and Van Gogh, I took formal art training in painting and sculpture not for one but for five years at the Art Students League of New York, exactly I paint oils, frescoes and pastels.

Painting from life and still life, it is marvelous, so I paint á la prima and with my hands, no with computers out of coping photographs or other's people work and without camera oscura. I paint with not other thing that my perception, perspective knowledge and skill in combining colors at once and at the spur of the moment, also I do it with passion and with the minimal regard for money. It was then as it is now, the art for the art sake. Finally, if my hands and my body, as it is somehow now, will refuse to aid me in my pursuit for beauty, I will use my mind and I will create substantial amount of images that if I would not be able to ever translate these to any media, I shall at least imagine them. I will, no matter what condition be free, because my freedom intrinsically rest in my principles and in my respect for the rights and believes of others as well.

I have dedicated my life to learning. Many things, I have learned then by myself, as most of us. I have partaken in formal academics, I attended classrooms and conferences, just to make sure I am in the right track, knowing that it is perhaps and overkill, since art and science are both learned by the determination and passion of the beholder. To understand what formally has been done and not because one could be recognized by a group, although this is good for surviving or for professional interests, all it is fine for me though.

You see there is something out there greater than men and ants, if you are truthful, really, it does not belong to our time, it transcends time boundaries and its entropic causation in which we currently live. It is like Keats' dictum "Beauty is Truth and truth is beauty", so as I don't understand many "social things" that are deeply rooted in the memes and spirits of the time in which people live, I don't mind them at all. Because, they seem to me just part of a culture and that it is very mutable in general. I am interested in the metasemantics of the things been learned or acquired, represented or understood, all images at last represent the same.

"At any rate it is exceptionally well done"

Now, this is another priceless statement for me it makes my life tremendously happy, but we, all of us, did exceptionally well for this project.

"I hope you feel better in the near future, I read some of what you and "P" spoke about regarding your health and I too am praying for your recovery."

Well, I have always to keep my difficulties to myself. I decided this time, that perhaps that was a terrible mistake and one of my main problems. Now, I am trying to share even my sufferings with others. I think I will be much better, as have always put this on my mind, but if I could not, I am doing my best to do my best in the mean time and until I could I would and must do just that.

"Take care"
Take care too "C", God provides to all men of good faith the ability to empathize with their neighbors. It is the Amazing Grace; we need to experience it, and eventually all of us we will have our “Coram Deo” moment. However, no matter what is our problem we have, we always can find beauty in everything that we do, all around us, because the beauty that we shall find in everything is simply God.

Wednesday, June 04, 2008

Other People's Network

The Ecommerce Architecture

Learning & Understanding Ecommerce Infrastructure

Cheswick/Burch Map of the Internet

Introduction


The main reason why Plow of the Sea, Inc [PotS], a small but prospering corporation has hired me, as a Networking Security Engineer [NSE], it is that the top management has recently decided to develop a competitive ecommerce or eBusiness presence. One of my main goals was to obtain the adequate executive level support for designing and implementing the networking security policy and conduct an enterprise wide security, education and awareness program. Even though, for the most part the network architecture has been already implemented, its security has not been properly developed, possibly because the lack of staff training or awareness about the importance that information systems security plays in the success of PotS, Inc’s ecommerce ventures. In this blog post, I am briefly identifying, describing and discussing the main topologies that are used to design and implement networks and internetworks that facilitate commercial online or web transactions and for such they can be considered as the network infrastructure and the bare bones of the ecommerce (Course, 2008).

Exploring Networks


At the very beginning of our journey into the realms of networking security, we need to understand the network topologies, that infrastructure whereby the exchange of information remotely or locally is carried on. However, firstly what really is a network? Especially nowadays, when it seems that everything is connected or networked somehow, as our personal information appears to be spinning around the globe many times within a gamut of disparate computing devices, cables and airwaves. Panko (2005); a consultant that has been working for the Whitehouse, gives us a very comprehensive definition of it, he states: “A network is a system of hardware, software, and transmission components that collectively allow two applications programs on two different stations connected to the network to communicate well.” (p. 3, chap 1), I also have another definition, a network is an interconnection of devices to form a pathway on which to exchange a signal, perhaps this concept is the reason why we call a small telephone network an “exchange”.

As we are exploring these concepts in some depth, with the aim to understand how network security is making our personal information and privacy safer, I would like to add that once upon a time and not too long ago, experts were talking about the phenomenon of convergence. During those times corporations needed to have two separate networks, one for voice and video, and other for data. Now with Voice over IP [VoIP], YouTube, Google, mobile wireless connections, Radio-Frequency Identification [RFID], Automatic Identification and Mobility (AIM) et al., convergence seems to be a done deal and corporations nowadays only need to implement one single enterprise network as a solution for all their telecommunications and data networking needs (Panko, 2003). Therefore, we should discuss networking topologies to increase our awareness over the network infrastructure and the challenges therein about its protection.

Network topologies

Barabási & Réka (1999) implied that the difficulties to describe, and for such to understand, complex networks rest in their topologies (p. 2-11), therefore is not a bad idea at all to become familiar with some of the nuances behind network topologies. Experts refer to network topologies when they are describing configurations of connected computers or information systems [IS]. This terminology can lead to confusions, for instance there are two types of networking topologies: [1] physical and [2] logical (or signal topology) logical topology describes the methods and algorithms used to pass information among computer and network components (Tomasi, chap. 17, p. 515). I usually differentiate these two topologies by thinking in the differences therein between hardware and software. Hardware is anything that can be touched, i.e., tangible; and software is those several sequences of instructions that it is used to process data for obtaining desired information, and for such is intangible (the spirit in the machine). It just flows from one point to other, in a stream of a bunch of zeros and ones, and so we are able to save it in many formats, within those various network components and storage devices, whether locally or remotely elsewhere.

Network design & Physical Topology

Once we have identified and evaluate our business concerns and opportunities in terms of desired data processing capacity, information transaction volume requirements and communications needs, we are in the position to design the information system that shall meet the demands imposed by those needs and requirements. The first step is to figure out what are the hardware and software elements that could substantiate the business model for putting the ecommerce site into ‘massive’ motion. Once we have identified and acquired the necessary resources, its time for assembling the network and so the need to arrange and organize these components so they can interoperate well.

Physical topology is the layout and configuration assigned by the system designers to connect two o more devices for sharing information over the network. The Physical topology involves the distribution of devices in a geometrically manner (segmentation) and within a determined geographically area; for example a network can consists of a minimum of two computers or nodes [although nowadays this is highly unlikeable] (Tomasi, 2005,). In fact, all devices or components that can be assigned an address in a Transfer Control Protocol [TCP]/Internet Protocol [IP] network are called nodes. Today connecting two computers is a task that is a piece of cake, but back in those “snickernet” times, two computers connected were considered a real deal, and it did not matter if just they were physically located next to each other.

Two computers, (Personal Computers) PC-to-PC can be connected via Network Interface Cards [NICs], transceivers (Homan, 1998), Universal Serial Bus [USB], serial or parallel ports. Today some people still using this type of connection throughout Universal Twisted-Pair [UTP] Crossover cables, USB cables, or wirelessly, using the ad-hoc mode or Bluetooth, because several different reasons propel them to do so (Russell, 2000, Chap. 4). In reality, the three main types of layouts and their combination thereof define the ABC of the configuration and wiring in networking the physical topology. Thus, we have the following main topologies: [A] Star, [B] Bus, and [C] Ring (Hassing, Kent, & Johnson, 2003).

The differences among Physical Topology


‘Addressing’ in a Local Area Network or LAN for short, changes according to the type of topology selected; LAN addressing could be unicast, one device; multicast, many devices; and broadcast, all devices. For example, the primary feature of the Star topology is that computers are linked to a central device; to either a hub or a switch (just the name of concentrators or electronic boxes use signal distribution), in a point-to-point direct connection. All transmissions enter this central device and are forwarded to all ongoing links. However, there are hubs that are more capable. The smart or managed hubs that allow the configuration of users’ access points for LAN connectivity, for instance, the Cisco’s 1500 Microhub series. Notwithstanding, the central device that is most often used today is the “switch”, this device could detect and save the Media Access Control address [MAC address] from the computers’ NIC cards connected to the network. A switch is able to forward the message, in this case, the frame, to a specific destination. Switches also can be managed, or unmanaged, it all depends of your budget and needs. The Cisco’s Catalyst family switches are managed via the proprietary operating systems [OS] developed by Cisco, called Internetwork OS [IOS]. Hubs are considered a layer 1 devices (by the International Organization for Standardization [ISO [not an acronym, but an Etymological denomination, from the Latin word “iso” meaning equal or standard as applied to all] Open Systems Interconnect [OSI] Reference Model [RM]); as switches are mostly considered Layer 2 (Data link) devices because they use and are able to build a MAC addresses table from the connected computers in the local network. The MAC address is a six hexadecimal number that is edged permanently in each NIC card. This number identifies physically each device in a network. By the way, the IP addresses are considered the logical addresses of the devices (an IP is temporally assigned to the node and can be reassigned). In contrast to the MAC addresses that are seen as the physical address and that cannot be reassigned or this we suppose, there are programs that can modify the MAC address by masking them in away.

Star topology seems to be ideal for troubleshooting since all traffic necessarily needs to flow into the central node, be either this facilitate by a switch or a hub, and thus appears to be very manageable for a small amount of devices and can be easily expanded or scaled as well. For instance, time-sharing systems, database management and word-processing systems are generally configured with a star topology.

The major inconvenience of the star topology is that the network is reliable as the central node or device. If the switch or hub fails then the network also fails, since the other computer would not have ways to contact one to other. Therefore, a central device is a critical resource, because a start network topology will be unable to function at all without it. A centralized network has the syndrome of the always avoided and feared “single point of failure”. This topology is capable of implementing Ethernet or LocalTalk. (Russell, 2005)

Bus topology is a multipoint or multidrop configuration whereby computers are interconnected to a single shared communication channel or transmission medium, thence its name of Bus. Its length is limited because certain attenuation problems; that is, the signals become weaker as they travel throughout the cables o more exactly, the wires. However, weaken signals can be enhanced and boosted by perusing repeaters and/or bridges. In this case the most critical resource is the ‘bus’ itself, because if it would get damaged and depending how and were, it could make the whole network inoperable as well. On the positive side, bus topology networks do not need routing information to be stored or retransmitted, as consequence, all that overhead is gone. However, as the traffic increases, collisions [crashes] among computers also will increase, thus a contention strategy has been ideated under the name of: Carrier Sense Multiple Access with collision Detection [CSMA/CD]. Scalability, is the main issue for the bus topology, it seems cumbersome, to find cables over the ceiling, on the wall or under the floor to connect another computer, this is why wireless networks seem to be such a blessing.

Developers have implemented other topologies to facilitate the expansion of bus network topology, called the Tree topology, consisting in adding more bus segments as a way of branching further the network. For Bus topology and Tree or Hierarchical topology, it is employed the Ethernet standard, this topology is suitable for the utilization of Ethernet and LocalTalk. (Russell, 2000).

Ring topology is a daisy-chained group of connected computers, in which one computer is connected to the other forming a circle or loop. Ring topology facilitates the transmission of messages in one way, one computer to the next, either in counterclockwise or clockwise direction, until the message reaches its final destination. Ring topology devices have to states: Listen or transmitting mode (aided by a signal, i.e., the token). The downside of the Ring topology is that almost every computer needs to retransmit the message (Hassing, Kent, & Johnson, 2003).

From these basic types of network topologies, other types of topologies are generated, such as partial and full mesh, double ring and a combination of two or more topologies, i.e., hybrid topologies. When a router, a layer 3 (of the ISO-OSI-RM) device is used, the network is able to forward packets to other networks, thus in how you are connect to the Internet [the global network made out of networks and for such the host of all the webs]. These types of topologies can then be joined over large geographical areas, constituting internetworks or networks of networks, call accordingly, Wide Area Networks [WAN], Metropolitan Area Networks [MAN], Campus Area Network [CANs] Global Area Networks [GAN] and finally, there we are, the Internet.

Conclusion

One of the main goals of networking security engineering is to bring the highest level possible of information assurance, ciphered in three main areas of information security confidentiality, availability, & integrity. By setting correctly the aforementioned topologies, the designers are being able to understand how to improve the security of the system and reduce the risks therein (Tomasi, 2005; Panko 2005).

For example, ideally, from the very beginning of the network design, and as a networking security engineer [NSE], I recommend the identification of security controls, constrains, requirements and features that would have matched the business requirements. Thus, I am increasing the likelihood that the PotS’s Local Area Networks [LANs] and Wide Area Network [WAN] would be able to operate as intended in the first place. Now, the challenges that we face ahead for initiating the PotS eBusiness venture, are issues associated with risk management, i.e., system’s reliability [downtimes], network management, scalability and performance, and how to offer a level of security for customers so they would be able to feel comfortable to buy products and/or order services from the PotS’s e-catalogue via online services.

References

Barabási, A. & Réka, A. (1999 October 21). Emergence of Scaling in Random Networks. Department of Physics, Notre-Dame, IN: University of Notre-Dame. Retrieved, January 8, 2008, from http://arxiv.org/PS_cache/cond-mat/pdf/9910/9910332v1.pdf.

Hassing, K., Kent, A. K., & Johnson, G. (2003). CCNA 1 & 2 Companion Guide, 3rd Edition. Cisco Networking Academy Program Indianapolis, IN: 2003.

Homan, C. (1998 October 19). NICs and Transceivers: Overview. UCDavis Network 21. Retrieved, January 8, 2008, from http://net21.ucdavis.edu/nic21rec.htm.

Panko R. R. (2005). Business Data Networks and Telecommunications, 5th Edition. Upper Saddle River, NJ: Prentice Hall- Pearson Education, Inc.

Russell, T. (2000). Telecommunications Pocket Reference. New York, NY: McGraw- Hill Companies.

Tomasi, W. (2005). Introduction to Data communications and Networking, Upper Saddle River, NJ: Pearson Prentice Hall, Inc.

Teilhard de Chardin - Visions from a Pre-Metasemantic Web Era





The Wholly World Wide [Metasemantic] Web


(Please, Click on the image to see the details)



Monday, June 02, 2008

Listen to the Joy of Freedom

One of the most beautiful rhythms in the world: The Lando (Afro-Peruvian)

Nicomedes Santa Cruz died in Madrid in 1992, but he was in all his ways Peruvian and much more than that he was an internationalist who fought with his poems, and Afroperuvian dances and rhythms against the racism and discrimination.

Nicomedes opposed and faced the injustices with art, with beauty and with his deep and well articulated voice. He shared the humanism of a culture that was extracted from one continent, Africa, and inserted into a supposed "new world"; both worlds suffered the same common societal maladies: Exploitation, discrimination, "homo homini lupus". They, the Africans with Americans so called Indians, (a pejorative term) were victims of one of the most cruel of all type of colonialisms: Slavery, despite Nicomedes was able to gather and collect for us, for the rest of the world, the music, the dances, i.e, those mechanisms whereby afroperuvians were able to remain humans, whereas in captivity, they remain somehow free, no matter the abuse, whatever their pain or inhuman condition, they have experienced therein.

Here is just one proof of it, a very rare but exquisite production in the Voice of the mere poet, folklorist, and intellectual Afroperuvian, Don Nicomedes Santa Cruz Gamarra, (another thing is the history of the "Ceviche" and the taste of the afroperuvian food, next in this blog, I will tell you were to go in Peru to enjoy real Peruvian gastronomy while we will continue distilling what is going on at the Metasemantic Web at this site):

Lando


... And the Music grew on us with Cecilia Barraza... "Toro Mata"



Thus the Afroperuvian music was recognized internationally in the voice of Celia Cruz

Enjoy it... Because it means that you are listen to the joy of Freedom as well.

Plausible Effective Change Models for Yahoo & Microsoft Merge

Effective Change Models for Managing Merging Organizations with seemed Conflicting Cultures

By John Manuel K.

This study surveys different change models & how to understand and managing change facing two conflicting cultures in the verge to be merged. For effecting the abstraction, I have named these two corporations with seemingly opposite & conflicting cultures as: "AAA" & "OOO"

Change alone is Unchanging

Heraclites AKA Heraclitus (c. 535- c.475 BC.)

As a result of the identification of many potential conflicting cultural factors between the AAA and the OOO Corporations, and enacting the role as the AAA Director of the Fulfillment Applications of the information department, I became aware of the need to study effective change models not only to manage the merging process between the AAA and the OOO corps., but also to create and strategic plan that it will use to optimize the whole merging process. As a major milestone for creating such a strategic plan, this study starts by exploring three organizational change models, by identifying situations in which their application will be most effective, and finally, by analyzing advantages and/or disadvantages in following these models.

Opposition brings concord.

Out of discord comes the fairest harmony.

Heraclites AKA Heraclitus (c. 535- c.475 BC.)

The Meaning of Change

I understand change as a “flux”, or a process and not as a final product or as a specific result that is manifested before our consciousness as a result of our instantiation of this process under our observation, with the purpose to study a determined object(s), as in here the purpose of study is about organizational Change models. It is a cyclical, episodic or periodic study indeed.

In the first chapter, “the purpose”, of his book [by the way the young Hillary Clinton (our next President), would have had written her thesis about this author]: “Rules for Radicals,” Saul D. Alinsky (1971) wrote: “Change means movement. Movement means friction. Only in the frictionless vacuum of a nonexistent abstract world can movement or change occur without that abrasive friction of conflict.” I assume this quote personifies well what is about to happen between two cultures which seem to have some many ways of doing things differently, as the AAA and OOO corporations: but we are conducting this research to be better equipped to managing an effective change.

It feels lacerating, but as the record shows, if we do not consider the human factors and culture the merging process will be erratically implemented with serious repercussion not only in the morale of the staff but also in our performance and lost of market value, instead to have positive outcome. It would probably defeat the merger’s purpose.

In this regard, I prize the inputs of Jerry (Gerald) Weinberg who has written many books combining seemed equidistant subjects as technical software development and human factors in improving productivity, this is a sort of software anthropology.

In an interview Weinberg explained how he realized the importance of people transformation in the Software Development of Technical organizations, and how this perception lead him to study the work of Virginia Satir, who, Weinberg, indicated that she is often referred as “The Columbus of Family therapy” and how her Satir’s work forms the basis of Neurolinguistic Programming (NLP), basically Weinberg state during this interview what it was his main “discovery”: “…The Software team works together to produce software; the family works to make new people …” (Dorset House Publishing, 2006). Thus, as implausible as it may sound, Weinberg also ‘confessed’ in this interview that he learned more about effective programming from Satir that from any other person in his life (Dorset House Publishing, 2006). Weinberg’s research supports our newly gained understanding that human factors are of primary importance for technical organizations, especially when they are facing an eminent cultural clash as again it seems to be the case with AAA and OOO.

Change Models

Organizations are made by people, thus Virginia Satir estates, “Change happens one person at a time” (Smith, 2006). Weinberg further states that the Satir Change model implies, “… one day at a time, one choice at a time …” (AYE conference, 2006). The whole point is that the organizational change occurs in the individuals, theretofore, in every choice, in every day, in every transaction and the integration of all his “micro-changes”, I will dare to state, quantum changes, will effect and affect a systemic change in the organizations.

Some outcomes will and can be anticipated properly but others that should/could be anticipated, perhaps might be ignored, or not addressed accordingly and thus chaos could and will be the unexpected guest of an otherwise avoided situation. Returning once more to Weinberg writes: “Change is a long-term process, but a living organization lives in the immediate present. Thus, without careful management, long-term change is invariably sacrificed to short-term expedience(Research Triangular Park, 2006). In this regard, I would rather be effective than efficient.

Thus we can see that organizational changes start at the level of each individual, each transaction, each choice, at everyday, as matter of fact multiple of these changes happens simultaneously, some are perceptible and some are not. As a company in its way to be merged with a company like OOO with antagonistic culture we at AAA must understand some main organizational change models to assist us to put our upcoming merger at easy. There are three main types of organization change models: top-down; transformational leadership; and strategic approaches (Kinsman & Laporte, 2006).

The Satir Merger Model

Figure 1 Satir Change Model

As we can see, the Satir Change Model above (Figure 1), is centered on the tenet that improvement is always possible. Virginia Satir developed this model to assist people to improve their lives by transforming the way they see and express themselves. In this way this change model is transformational in nature. It is a five-phase change model (see Figure 1) displaying the effects each phase has on emotions, cognitive, behaviors and physiology. According to Satir using the principles of this model facilitate how organizations or group process change and how to assist other organization or groups in processing change as well.

This model could be applied in any situation: Before, during and after the completion of the merger. For instance, the phase 1, called the “Late Status Quo” represents AAA culture as is right now, a people-oriented, family like environment whereby there is a sense of belonging, staff knows what to expect, how to react, and how to behave. There are policies and these policies are known and well accepted within the organization (Satir, 1991).

In the second phase, known as “resistance” in this model, the OOO culture is depicted as the “foreign element”, this is the conflict for AAA staff and a probable source of uncertainty, doubt, and discomfort. The Satir Change model allows the understanding of how the situation would appear for the staff since their stability is going to be compromised by the OOO and its conflicting culture. Restless behavior and some another resistance tactics can be developed among the staff as a mechanism of defense. Is in this phase that this model prescribes to assist employees to become aware of their reaction of denial, avoidance or blaming by opening up to others staff members.

I the third phase, in this model: the chaos, the merge eventually has happened and this phase discovers the unknown, because for more plans that management could make always there are many details that remain unknown to us, and for such “obscure.” There will be employees that could feel nervous after the loss of some of their counterparts because the merger and they probably will develop symptoms of anxiety and other characteristic of the sorts. This phase should be expected by managers as erratic periods and also as an opportunity for assisting staff to search for beneficial relationships with the “foreign element” the new staff and culture from OOO. This is the stage where under Satir Change model transformation happens (Weinberg, 1997).

In Phase four, i.e. the integration, the staff of AAA will encounter at least some positive attributes in OOO and in consequence new projects and relationships will be implemented rapidly and with positive energy, and thus we arrive at Phase five: New Status Quo, whereby change have been assimilated, the Merger have been completed and a new environment has emerged and a new sense of accomplishment and enhancing possibilities are permeating this new organization that has been derived from the Merger of AAA and OOO (Satir, 1991).

The advantage of this model is that provides to us proven ways to deal with the entire process of the merger, The Satir Change Model simplifies the scenario of how people react when face change, as in this case a merger, and what management needs to do about in each phase or stage of the process. I hardly see any disadvantage, only that requires a lot planning and support from management since is very granular and its focused in many dimensions, including the physiological reactions of the individuals. I would gladly use this model because it seems to be centered on transforming cultures by assistant each staff member to adapt to the pressing demands of doing so.

Nadler-Tushman Change Model: Key Variables

This model observes how change is managed or face, according to the extent in which change(s) can be anticipated, thus there are two types of changes: Anticipatory changes are planned changes based on expected situations. Example: Insurance needed for Paintings in the Exhibition and reactive changes: Changes made in response to unexpected situations. What decisions you make when you were alone at home and suddenly you fractured your femur and fibula by accident? (Kritner, 2004).

The Nadler and Tushamn model provides the following steps:

1) Identify the problems and Situational analysis - Get support of key power groups

2) Demonstrate leadership support of the change

3) Use symbols / Create identification w/ the change and appearance of a critical mass of support

4) Build in stability

5) Surface/create dissatisfaction w/ the current state

6) Obtain the appropriate levels of participation in planning/implementing change

7) Reward desired behavior in transition to future state

8) Provide time and opportunity to disengage from current state

9) Develop and communicate a clear image of the future state

10) Use multiple and consistent leverage points

11) Use transition devices

12) Obtain feedback about the transition state and evaluate success

This case Model primary advantage is that considers also what we could do when facing unexpected changes, as we know for this merger we need a flexible yet a structure model that guide us in the process, this modes does just that by providing opportunities for disengagement and also using multiple leverage points. One of the best situation to use this model is during the implementation phase when new rules or policies are going to be applied to newly created groups and projects has been formed within perhaps same or new departments. The disadvantage is the amount of time that will take to analyze, and for planning the strategic plan to facilitate this merger.

Models of Action Research: Cummings & Worley Model et al

The majority of research is aimed to create knowledge; action research is a way to conduct studies which engages in both: taking action and creating knowledge constituting a theory of action (Coghlan & Brannick, 2001, p.xi). Organizations use action research models to learn how to change significant aspect of its system by involving their members to actively study their own behaviors, from here action research shows the new knowledge emanated from the self-reflection of the participants on the whole research process.

Many actions action research models exist, all of them includes in their definition as iterative, collaborative, and change effort that involve needs analysis, plan of action based on the needs analysis, implementation of the plan of action and finally evaluation of the process. I identified four of this models Cummings and Worley Model, Burke’s Adaptation of W. L. French classic 11–step Model, Frohman, Sashkin and Kavanagh’s Seven-Phase Model and Pearce and Robinsons Six-Step Model. The entire aforementioned models are very similar but the most notable or the one that is more referred, in my literature review, is the Cummings and Worley Model (Cummings & Worley, 1991, p. 155) here is the well delineated stages:

1) Motivating Change creating readiness for change and overcoming resistance to change

2) Creating a Vision - Describing the Core Ideology and Constructing the Envisioned Future

3) Development political support -- Assessing Change Agent Power and Identifying Key stakeholders and Influencing stakeholders.

4) Managing the Transition - Activity Planning and commitment planning and management structure.

5) Sustaining Momentum - Providing Resources for Change and Building a Support System for Change Agents and Developing New Competencies and Skills and Reinforcing New Behaviors

The Cummings and Worley model takes in account the anxiety and other emotional factors introducing in its first “prescription”: Motivating change by creating readiness for change, very interesting concept, it includes leadership because it compel to create a vision a core ideology, in this sense is also a transformational change mode. And takes in account the power by identifying key people, I think that this model also is applicable for the merger, especially in the planning and commitment for facilitate the merger by creating appropriate structures of management to sustain development into a new culture.

There are many advantages, in using this model principally; it is straight forward, as it appears to be easy to follow, and on the other hand, few disadvantages can be noticed about this model, perhaps is too compact and lack of specificity to anticipate unknowns.

In closing we have idenfied tree change models: The Satir Change, Nadler & Tushman, and the Cummings & Worley Change model. We have explored situations in which they can be utilized and finally, we analyze each model, according to their advantage or disadvantages in following these models.

References

Alinsky, S. D. (1971). Rules for Radicals. New York: Random House.

Anderson, P. & Tushman, M. L. (eds.) (2004). Managing Strategic Innovation and Change - a Collection of Readings - Second Edition. New York: Oxford University

AYE (Amplifying Your Effectiveness) Conference. NoMoreResolutions. Retrieved January 25, 2006, from http://www.ayeconference.com/wiki/scribble.cgi?read=NoMoreResolutions.

Burke, W. W. (1982). Organization development: Principles and practices. Glenview, IL: Scott, Foresman.

Coghlan, D., & Brannick, T. (2000). Doing action research in your own organization. Thousand Oaks, CA: Sage Publications.

Cummings, T. G. & Worley C. G. (2001). Organization Development and Change - Seventh Edition.Mason, OH: South-Western College Publishing - Thomson Learning.


Thursday, May 29, 2008

The Best Guitar Song Ever: The persistence of a Meme

RollingStone has nominated the 100 greatest guitar songs of all the times The Chuck Berry's "Johnny B. Goode ": What do you think? Anyways, it has passed a little more than 50 years since January 1958 when this song was introduced in the market of music, so let us hear the song again and again and ...





Jimi Hendrix playing the song is his own style




Judas Priest couldn't left this song alone and here is the sound



An the song survives still, here is Green Day's interpretation



Go Johnny go .... hundred of years more

Human 2.0: The Opportunities and the Risks of Creating Powerful Tecnologies


Memory at the Molecular level






Wednesday, May 28, 2008

The Death of Death: The Picture of Aubrey de Grey



"With Reason, Without Reason or Against Reason, I don't want to die!"

Don Miguel de Unamuno

The man of flesh and bone; the man who is born, suffers, and dies—above all, who dies; the man who eats and drinks and plays and sleeps and thinks and wills; the man who is seen and heard; the brother, the real brother."

From Chap 1, Tragic Sense Of Life

The Methuselah Foundation Chairman wants you to live 1,000 years or even more...

Is immortality possible?
Aubrey de Grey believes it is..

Part 1

Part 2


Part 3 - With Marvin Minsky

Part 4

Tuesday, May 27, 2008

Metasemantic II - Understanding the Clash of the Wikis and all the Pedias

As Thomas Friedman has told us the world is flat, but not really, we know that it is not, perhaps there are many worlds, and many maps made out of the same planet and there may be many encyclopedias. Now, we are facing the battle for knowledge as new domains are starting to emerge under the same sun and moon... So lets us compare the opposing views in here, later we will continue elucidating the origins of these memes and the foundations of Metasemantics....

Conservepedia



Some Comments Published by the mere "Conservators"

"Broad and Alien is the World"






The Peruvian Ciro Alegría's novel "Broad and alien is the World has been recently published by Merlin Press in the United Kingdom. [ISBN 0850362822]

Monday, May 26, 2008

Rocking at the Red Rocks

Learn Hiragana & Katakana & make it better

Learn in Here or Here and enjoy...

The talent of the net



So Remember... Then you begin to make it better

Saturday, May 24, 2008

Ecology - Ernst Haeckel

Web Mud Time searching: In the semantics of Robert Frost



My Object in living is to unite

My avocation is my vocation

As my two eyes make one sight.

Only where love and need are one.

And the work is play for mortal stakes,

Is the deed ever really done

For heavens and Future sakes.

Robert Frost, "Two Tramps in Mud Time"

""The Poetry of Robert Frost" by Edvard Connery, ed. New York, NY: Henry Holle Co. 1968

Thursday, May 22, 2008

The Oldest City of America

Sechin Bajo has been confirmed as 5,500 years old city by German and Peruvian Archeologists. The Archeological Institute of America has published in his magazine "Archeology," that Sechin Bajo is "the oldest monument of America," and points that the city presents a circular structure of 46 feet (14 meters), while the Peruvian "National Institute of Culture" in the voice of César Pérez stated "It's an impressive find; the scientific and archeology communities are very happy." Sechin Bajo is 500 years older than the city "Caral" (5,000 years old ) and it is located in "Casma" a 370 kilometers (circa 230 miles) away from the capital of Peru, Lima. Sechin Bajo places the American ancient culture as one of the only six places in which people started to live in cities some 5,000 years ago, together with, China, India, Mesopotamia, Mesoamerica, and Egypt.

Sechin Bajo Modeling by Dr. Peter R. Fuchs & Prof. Dr. Eng. Perter Mesenburg

Plowed Results | Resultados Arados