Friday, June 20, 2008

A worldwide web of belief and ritual

You can contact me directly by clicking in here

Original Cultures and the Environment could survive
The anthropologist Wade Davis who has stated that have live 30 years with the Chincheros reveals and explain cultures from Peru

AMAZING CLASH - THE GREAT INCA REBELLION


Incas Versus Conquistadors

Part One





Part Two




Part Three





Part four



Part Five



Part six

Thursday, June 19, 2008

The Insecurity in the Systems Intelligence: A Very Brief Study of the Failures of Information Security Projects

“Best is to know and know you know. Next best is to know that you don’t know. Third best is knowing, but not realizing it. Worst is not to know that you don’t know.”
Ancient Proverb (Business, 2002, P xxxi)
Introduction

What do IT projects fail so often? What are the impacts, if any; do these failures have on the confidentiality, integrity and availability [CIA] of our Information Systems? A fundamental and direct relationship between these two processes (security and failure) exists without a doubt; however, being that the impacts of project failure on security is a certainty, as it is obvious and dangerous, for the operational stability of our IT systems; and having in consideration that all along systems project failure is very expensive and has caused so much pain and sorrow: Why then, we are not more careful about developing and implementing these type of crucial projects? These were some of the questions that were explored during our last Xterior’s security team weekly meeting. On this paper, I am briefly documenting my conclusions based on the literature review that I had conducted about the failure of information systems security projects (Courses Material, 2007).

Insecurity Preambles

It is common knowledge what that old saying states: “The necessity is the mother of the invention.” I could not find a better word, with which I could epitomize more accurately the degree of civilization of any given society, and hence innovations are the best of our human manifestations that stems from our lack of having the adequate vital resources, or the insecurity to be free from our most basic physiological needs. The advances of any determined culture or historical period are represented precisely by its tools, as by its knowledge employed to solve their challenges, which typifies the distributed human intelligence expressed through the development of arts, sciences, architecture, engineering, weaponry, and industry and governmental institutions. Thus the history of invention describes and enumerates those technologies used from the Stone Age, throughout the contemporary and pervasive, as seemingly intrusive and insecure, Information age.

However as our inventions, i.e. the ability to create tools, objects and ideas for outreaching our overarching goals and objectives, and creativity have assisted us to become organized as nations with peculiar cultures and philosophies (the east and the west divide). Thus, we have survived and adapted to the inclemency of our environment and we have triumphed over all known beasts in nature with the exception of only one: The Man itself. “Homo Homini Lupus”, i.e., "Man is a wolf to man," is a famous Roman Proverb attributed to Plautus (184 BC) and used it as one of the main ingredients in the authoritarian social contract, in his “De Cive”, by Thomas Hobbes (1651). Thenceforth, it is the beginning of our tribulations, insecurities and project failures; it appears ingrained in our own needs, instincts, self-interested reasons and imperfect souls. It is not any different now that it was then, in the Stone Age, we need to survive. So, If the necessity were the mother of the invention, then the scarcity is the grandmother of all our insecurities and wrong doings. Therefore, information security deals not only with technology; it involves other factors that are more darker, deep-rooted and less understood than any form of attack because it has been, is and will be the source of all our human maladies.
System Project Failure

Failure is lack of success. To fail is to lose in a way, as not being able to provide. If a system were not working as expected, then we state, “the system has failed”, by the same token is a project fails, we can say “the project as the people who were involved in it, have fallen short in meeting the goals” or “they could not grow or develop fast enough to deliver successfully what is was expected or needed at this time.” (Scalability problem) At the end of the day, system project failures have significant costs, not only for the project team’s morale but in terms of dollars, time and other resources, as the loss of critical information, that have proven catastrophic for many business cases. Nowadays, that our lives spin around multiple projects, it will be a good idea to refresh our memories, and figure out what exactly is a project and why projects do fail. As I see it, a project is an organized and systematized activity that employs resources, i.e., people, technology, and processes or operations, within a well-defined start date, milestones or phases, and end date (duration and schedule) with the aim to achieve a relative unique service or product within an organization (Sommerville, 2000).
Learning from Failure

The study of failure could ensure the path to success. What did work some years ago to solve a problem, it might not work today. To investigate why systems projects usually fail, we need to understand how we plan, administer, monitor and evaluate them; in other words, we are asking what Project Management [PM] is. PM is a life cycle based discipline utilized to achieve desired and projected goals within a determined schedule and specific budgetary constrains (Why, 2007). Many experts agree that one of the main reasons why systems or Information Technology [IT] projects failed so often is the lack of knowledge, understanding or experience, of the IT Managers about System Engineering [SE] (Sommerville, 2000, p. 9); and on how to apply effectively the PM Body of Knowledge [PMBOK] for their specific situations. For instance, Wimmel & Wisspeintner (2003) showed the importance for security managers to be familiar with the application of the “Information Technology Security Evaluation Criteria” [ITSEC], AKA “the Orange book” and/or the Common Criteria [CC]; both standards that are usually utilized for designing and modeling trusted ecommerce systems. As it is the case of Plow of the Sea, Inc that now wants to translate its retailing business experience into the Internet.

Sten E. Vesterly (2004) based on surveys, reported that only one quarter of the System projects are almost completed as expected, as they meet just some of their specified deliverables according to schedule and budget. He added that two quarters of the IT projects deliver their final outputs with serious deficiencies in functionality and largely exceeding their price and time tags. In addition, that one quarter of the entire projects deliver anything but yes, they consumed all and evenly more of the money, time and resources that were assigned to them at their inception or during planning process (p. 1-7); No wonder, why IT Systems Project managers are fired with conspicuous frequency.

Vesterly (2004) explained that another cause, for the aforementioned negative and poor system project outcomes, is the overexciting or excessive enthusiasm created by the new features and rapid deployment of powerful emergent technologies. Most IT staff just cannot resist them and become too ambitious in including uncertain devices or software mechanisms; and so become part of what it has been called, the frontlines of the “bleeding edge”. As many new-released hardware, firmware and software off the shelf have not been properly tested or certified, using these products create tremendous stress in supporting their deployment and maintenance. IT Prudence is required in designing and developing system projects. On the other hand, Vesterly (idem), pointed out, that some IT managers usually offer the argument of, “If it works, don’t fix it”, pretending that legacy systems will work in the same way, facing the same attacks as they used to, within new and dangerous environments with threats that in no manner were known or evenly envisioned when they were firstly deployed. It suffices only to recalled the case of zero-day attacks, to understand that upgrading and patching systems is not only necessary, it should be continuous and compulsory goal to be enforced to all IT managers by the top security managers in any organization (p. 1-7). Ted Hendy (2000), the System Security Architect and Engineer at the Pentagon for the Office of the Secretary of Defense [OSD], stressed the importance of human analysis and the use of Security System Engineering Process and Techniques to prevent major problems in planning, implementing and managing IT systems, Hendy (idem) summarized very well why systems fail, “Though the technology exists to do great things in this field, without thoughtful analysis and preparation many of those attempts are doomed to fail.” (p. 1).

Moreover, we know too well, that complexity creates havoc and it is very difficult to manage. The complexity of the Information Systems [IS], which is incremented by the rapid change in the technology available to use; as the level of sophistication, reached by the IS interoperability and components interactions, has created confusion and pressure on security and IT managers. Actually, the system complexity is one of the major causes of the other aforementioned factors. In reality, studying the causes that originate systems project failure is looking for answers as to why systems projects fail and how to do for implementing more trusted IS (Ivory & Alderman, 2005, p. 1-13).

Sommerville (2000) reminded that systems components are just not only about inert parts or soulless machines working as a whole with emergent own characteristics, properties and capabilities; systems also involved people and are built for support them and aid human activity (p. 3). Therefore, we need to zero-in on the users and operators too, and on the risks associated with how these users and operators are aware, trained and educated for perusing the systems infrastructure and access critical information. (Ivory & Alderman, 2005, p. 1-13) This factor is outlined by Beckley (2007) as inadequate training; he presents also other causes for the failure of system projects, such as: Radical and unconventional changes; the lack of enterprise level support and resources or budget; and communication failures (Slide 53). In addition, the figure 1, below, encapsulates the concepts behind the systems project failures and the difference between what the users want and what they finally get:




Conclusion

At the end of the day, some factors of failure appear at the beginning of the project, like the lack of communication among the team members of the project, or understanding over which ones are the system requirements or over roles or responsibilities. Some factors develop on the last phase of the project, like the lack of proper testing or evaluative practices. However, system projects fail at any phase during their development process, whereas for the lack of monitoring, contingency measures, or concurrency, interdependency and tasking issues, or event or people driven deadlocks. Systems project failure poises a great danger given its frequency. It has come to mean for us, as Xterior security managers, prevention, instead of contention; it means alertness instead of lamentations. It also means due-diligence and al lot of work and patience to estimate the process and to not sub estimates nothing; and so it security system projects need to adherence to system security engineering standards, such as SSE-CMM for reaching an adequate level of information assurance, and system reliability for Xterior’s customers.
A successful project not only meets its goals and objectives on time and within budget, but also implements and translates accurately the business model requirements into the security technology controls that squarely satisfy the security policy of the corporation.

Bibliography

Business - The Ultimate Resource. (2002) London, GBR: Bloomsbury Publishing Plc. Retrieved November 30, 2007, from http://http://wf2dnvr5.webfeat.org:80/dIEzI117/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10022156&ppg=1.
Hendy, T. (2000, May 9). The art of security engineering. US Army Information Systems Engineering Command. Retrieved November 30, 2007, from http://www.itoc.usma.edu/Workshop/2000/Abstracts/TM2_1.pdf.
Hobbes, T. (1651). De Cive. Retrieved December 1, 2007 from, http://socserv2.socsci.mcmaster.ca/~econ/ugcm/3ll3/hobbes/hobbes1.
Ivory, C. & Alderman N. (2005, September 28). Can Project Management Learn Anything From Studies Of Failure In Complex Systems? Project Management Journal, Vol. 36 Issue 3, p. 5-16, 12p. Retrieved November 30, 2007 from, http://search.ebscohost.com/login.aspx?direct=true&db=buh&jid=1NR&loginpage=Login.asp&site=ehost-live.
Mitchell, A. (2004, December 14). E-Commerce Missing Link: Software Requirement Specifications. E-Commerce Times. Retrieved December 2, 2007, from http://www.ecommercetimes.com/story/38919.html.
Sommerville, I. (2000). Critical Systems Engineering: Processes and techniques for developing critical systems. PowerPoint Presentation. Retrieved December 2, 2007 from, http://www.comp.lancs.ac.uk/computing/resources/IanS/Ian/Courses/CritSys-2004/PDF-notes/Introduction.pdf
Vesterli, S. E. (2004, October 19). Why IT Projects Fail − and how to avoid it. Retrieved on December 2, 2007, from http://vesterli.com/papers/why_it_projects_fail.pdf.
Wimmel, G. & Wisspeintner, A. (2003, June 17). Extended Description Techniques For Security Engineering. Institut für Informatik, Technische Universität: München, D-80290 München, Germany. Retrieved December 2, 2007 from, http://www4.in.tum.de/publ/papers/WW01.pdf.
Why do Projects Fail? (2007). JISC InfoNet. Retrieved December 2, 2007 from, http://www.jiscinfonet.ac.uk/InfoKits/project-management/pm-intro-1.2.

From The Chronicles of The Metasemantic Web III: Thus spoke Seattlle: Metasemantic Webs-Metacultures: Uncrashing the Past into our Future





There is much controversy over the environment nowadays. We do not know for sure what words really spoke, the Chief Seatle or Seattle, but this we know: he has and statue, and it seems that he compromised and survived until his natural death.

Also, he had a friend in Dr. Smith, who translated his words. It appears that the poems or letters attributed to him were embellished at later time, for making movies, money or for other reasons, rather than to try to improve the lives of the first Americans, or Pre-Americans, or Pre-Columbians. They are called Indians due to a mistake, really.

I called them humans, humans that were profoundly degraded, almost exterminated, ripped-off of their lands and brutally and largely dehumanized in the name of many things because they just lost the war. Yes, it is the Spencerian categorization, the survival of the fittest; with less and less animals, less plants and more energy demands, instead of green our planet is becoming gray. I would like to see from where we are going to take more money, or where we are going to look for new Indians or slaves. Oh yes... I am so sorry, there is water in Mars! and oil or something else elsewhere in the galaxies, go get continue with the autopsy...



    "Man did not weave the web of life - he is merely a strand in it.
    Whatever he does to the web, he does to himself."

    Chief Seattle, 1854.



Archaeologists, convinced that there is something more in the past, are looking really intensively in explaining to us how it was done in detail. National Geographic is graphical about one proven instance of the massacre, crash and war of two civilizations.

Again another mistake, it is called "conquista", ["Conquest"], and the winners are called using another euphemism, "Conquistadors", but in reality we all know what it was, don't we? While, we accept many things, we need to think of the consequences of these enterprises, for the whole world, including the world that we build for ourselves. Thousand of immigrants are coming

and continue coming, why is this occurring? We need to recognized that there are a lot of problems that are deeply rooted in another sort of cause that we cannot see, may be greedy, for survival and/or the thirst of put others down, I just do not know. A business is not a business while all what one is doing is taking goodies or labor from others by force, or by misleading contracts, agreements or licenses, and given it to your family or people. Yes, it was a war, but an unfair war, that for these people it would not have never an end. Rarely a war does, it never ends in a way, they stay somehow forever. So the fight continues and in the fighting we seem to be all embedded therein, as Willy Nelson will sing it, "After all these years".

Whether is was done thousand of years or just now. Look at what is happening in the middle east, unfortunately all the world is still kind of paying for something that was started some millenniums ago and far away from us.

Whatever the source of our problems is or would have been, as Polya, would tell us, we need to properly name it, define it that is, and make the necessary arrangements to improve this present for our future for the futures generations.

I do not think, we are doing this, so are we taking for granted the world peace that we have. It is very plausible that we are profiling another war, the third war world, WW version 3.0.
Whereby, we were having WWII.1 in the cold war, the WWII.5 the war for Kuwait and now we have the WWII.6, the holy war against the terrorism and lately we seem to be near to have a WWII.7, a world against our own environment. Some people say that is our nature, the brutish and evil nature of Man defined so well by Hobbes. The law of the Homo Homini Lupus.

I said, that incidentally, and definitely, there are some people that believe in supremacy, slavery, and war as the way of man. At any rage and for any reason under any social structure, epoch and within families, at the schools, at the job places, in the markets, these people appear somehow and evenly flourish as they are well-admired by people that think the same or like to think the same. They are very cohesive in nature, and so they organize.

As they seem to be very concreted up to the point to become binary thinkers at large, so for them is rather easy to make decisions, or it is war or it is peace, or they win or they loose, or you are white and you are not and so you are the rest. Fairness is not a principle for them, it is an issue, winning is all what it counts in the end, so they could utter: "Long live Machiavelli".

The second law of evolution: The survival of the fittest but based in mutual aid should be considered in here. Of course, once when we all are uploaded and saved into the "machine", then as Bill Joy stated and it would be perhaps easy to answer in here, "why the future does not need us"? It is rather obvious, isn't it?

Most likely, we are already an expendable number by now. Never mind, let us continue hunting and fishing and watching TV and playing golf though... Try to see the past ... then you see the
future, as above as below...

Wednesday, June 18, 2008

The Best Blog of the Web: The Blogger is a 96 year-old

It was selected in Germany and the BBC is going to interview the 96 year-old Blogger: OK you can read it by clicking in here. (It is in Spanish but there is a widget from which it can be read in many languages.)

Tuesday, June 17, 2008

As the value of Gasoline Increases let us look to "The Amish Way of life"

Einstein, Dirac, Godel, Selberg, and Harish-Chandra Together at Princeton

The Models of Making Decisions




If you will begin with certainties, you shall end in doubts, but if you will content to begin with doubts, you shall end in almost certainties.

Francis Bacon

Sunday, June 15, 2008

Network Security Software Risks & Vulnerabilities with Malware Prevention

By John M. Kennedy 
Introduction
Different people code different types of software. Therefore, software security issues stem from much of the same humans traits that code them in the first place. We can state that software is like people, you can find all kinds of them, in everywhere at anytime. In this era of hacktivism and cyberterrorism, it seems that crackers, cyberpunks or black-hat and grey-hat hackers have been able to translate the mightiest worst from humanity into computing. They use “deadly” routines or sets of attacking instructions to cause havoc or commit crimes for fun and profit and not necessarily done in that order. Therefore, I am telling you, the “Scarface’s tale” is nothing when comparing it to the nightmarish realities of the software security threats, risks and vulnerabilities, that I am presenting in the following pages. Notwithstanding, and for the last time, I am warning the reader, á la Jack Nicholson, especially when he characterized the Coronel Jessep, in the film, “A Few Good Men” (1992), perhaps “You can’t handle the truth!” Incidentally, for those who study software security, there should be a banner to warn them about it too, something like the inscription that Dante, in his “Divine Comedy”, told us that he found, when he was invited to enter the his mere self into hell, at the top of its doors: “Abandon hope all ye who enter here”. No wonder anymore why programmers have used, all along, names like Daemons (not precisely the Terminate and State Residents or TSRs or MS DOS environment.) and SATAN, to label their programs. Whatever, the danger might be or seem to be, as the “Man of Mancha” would have sang while crossing the borders of devilish domains, I shall encourage you to enter and while singing with me: “ …. to fight for the right without question or pause, to be willing to march into hell for a heavenly cause! … And this is exactly our jobs and the whole reason why the information systems security teams have been created. To do the right thing, to protect the most valuable asset therein in Plow of the Sea, Inc, i.e., its information. (Fitzgerald, M. 2001)
Network Security the level or Risk of Software
As a whole the level of risk that software represents is extremely high for GCI’s eCommerce venture. Azaris (2003) explains that network security software is vital for network users, information Technology [IT] professionals, and network security specialists (p. 1), hence the researcher implies its importance and ubiquity in our lives. Software is what makes hardware to process data in useful information; embeds the rules of communication or protocols; likely, it is used to commit all kind of malicious attacks, and software is what has made many people richer than the Sultans of Brunei. Therefore, let us immerse in the subject …
Bruce Scheneier (2007), the creator of Blowfish, an algorithm used for encryption, stated that information security is costing millions of dollars mainly because the software is insecure, due to bad design, poor feature implementation, security vulnerabilities and/or lack of adequate testing (p. 1). Well, as we know software permeates almost everything nowadays, what is software; it is so intangible and only is measurable perhaps by the amount of lines of code put together to do something. How exactly we put these lines of code logically together so the machine [CPU –Central Processor Unit and then the system] can work by following these commands determines the speed, utility and the versatility of the programs. Yes by all means, software are programs; as a program, software can be as small as one routine with a “laconic” set of instructions whose only purpose could be only to print one or more times the sentence “hello World” at the standard output stream device or screen or monitor. For instance, in C language the screen was called stdout and by default the stream was outputted to the terminal (you can redirect the output as well by the Shell’s Command Line Interface CLI ), and software can be very complex as an Operating Systems Like UNIX or Linux, whose kernels consists of several millions of lines of code or instructions. These lines of code are what programmers called the source code. For instance, the total number of the Source Lines of Code [SLOC], for the Linux kernel version 2.6, has been calculated as more than four million (exactly 4,287,449) (Wheeler, 2004) very complex software. It is a matter of fact, software can be so “effluvious” and “ethereal” that can be “loaded” in the most subtle and thinnest of devices, like the RFID, which in spite of many experts written about they have found flaws and vulnerabilities, people are using more and more to track almost everything, for instance, some of these transponders, are specified by the standards ISO-11785 and ISO-11784 for Radio-frequency identification, aka FDX-B. The code by itself is software “running” or “saving and responding” data in 128 bits devices, 64 bits of which it is utilized only for the Identification or ID information tracking system purpose.
Another subject is the firmware, its security poised other considerations of the sorts, for example, Booting, I personally, I don’t like to boot my systems at all (if you would click on “Booting” then you would understand why, and one more thing, remember the melody and reading it by following its rhythm, would you?). The Basic Input Output System [BIOS] is the software that is loaded before the OS does. It main purpose is to locate the bootstrap loader in the defaulted booting device of the system. This small program resides in the CMOS-Complementary Metal-Oxide Semiconductors, a Non-volatile Random Access memory chip that uses very little amount of energy from a battery and that is connecting to a quartz that oscillates evenly, called the RTC just to save some information like the date and time and the booting devices and the defaulted partitions when the computer is off. Well, the fact is that without or if the CMOS-BIOS hybrid device malfunctions, then the computer would be worthless.
Nowadays Firmware or BIOS vulnerabilities are also a new cause of preoccupation amount information security practitioners, BIOS chips have been the normal components of Motherboards, Network Interface Cards [NIC], video cards, but at the beginning, users were not able to updated these chips, that is why they were called Read Only Memory [ROM]; however, for some time now, users and operators can updated the BIOS or their machines, as to improve the system’s interoperability and compatibility with new and larger hard disk drives or other input/output [I/0] devices that offer more functionality. This process is called, “to flash the BIOS or CMOS”, the problem is that there is software, virus that could install itself and reside in these EPROMs (electrical programmable ROMs). Lately, as expected, the scenario seems to have been worsened by the apparition of the iWarp Ethernet NIC Cards, which can facilitate the detection of packet processing right out from the CPU, creating backchannels for bypassing completely the OS as serious threat for the security of the information (Jackson, 2007).
Mitigation against Malware
It is practically impossible to be fully protected and this means that what realistically networking security engineers and practitioners should be hopping for is for outreaching an acceptable level of security. Software security entitles the protection against malware from all its known and unknown forms, by perusing different tools, methods, network appliances and specialized combination of software, like: Firewalls, cryptography, network security administration and security programming development tools. However, all these software, controls and countermeasures to reduce the risks, will not work effectively without the addition of a well thought out security education, training and awareness program addressing the participation of all GCI’s stock holders (Pflegeer & Pfleeger, 2003).
Malware
Göran, Kaj & Peik, (2003) indicated that malware exploits vulnerabilities, and pointed to the 1992 Bowels and Pelaez’s simple taxonomy, which classified all malware in just two types: Programs Needing a Host, and self-reproducing malware (p.1 ). Let us see the following table below:
Bowels & Pelaez’s Malware Taxonomy
Programs Needing a Host
Self-reproducing
Trap Doors: Secret point of entrance to the system. This represents a serious threat.
Bacteria: self-replicating harmless program for only one detail that replicates so much that in the end could take all the capacity of the victim computer.
Logic Bomb: Waits for a date or and event to do their deeds. One of the earliest forms of Virus, very damaging in deed.
Trojan Horse: A “Goodie” with maladies.
Very serious threat.
Worm: Infects computers through network connections, can behave like virus and bacteria or could install Trojans too. Its effects are devastating.
Virus or Retrovirus: Infect other programs by copying its code to them and continuously infecting others. Serious Threat. Retrovirus behaves like a virus with the detriment-added attribute of being able to attack anti-virus; Even more serious.
Table 1. – The Malware Taxonomy (Göran, Kaj & Peik, 2003).
The rest of software can be a combination of all of the above mentioned like the infamous rootkits, which are very difficult to detect. Thus we have collection, prevention, detection and response mechanisms to deal with these malware maladies; a series of “anti-thesis” have been created for the purpose of responding to the imminence of viruses and retroviruses exploits: Therefore, we have antivirus in their many flavors and varieties, e.g. we are in the four generation of antivirus, being the latest mechanisms used by them Generic Decryption [GD], Digital Immune System technology [DIS] (Propose by IBM), GD is employed to protect polymorphic Viruses (Pflegeer & Pflegeer, 2003, Göran, Kaj & Peik, 2003, Panko, 2004). Recently antivirus programs are classified accordingly to what they are geared to protect, there are antivirus to protect gateways and firewalls, and files and database servers, and as always end users programs, operating systems and files. Figure 1 below show the classification according to the level of security that antivirus offer:
Figure 1 - Defense lines in antivirus protection (Göran, Kaj & Peik, 2003)
Firewalls protect the enterprise network at the perimeter, i.e. at the border, thus is a mechanism of defense that separates the network from the rest of the world, there are three common types of Firewalls: Packet-filtering router, application-level gateway or proxy server and circuit-level gateway external network-based security threats (Basta, 2007, Panko, 2004).
There are main two implementation of cryptography for networking security at the network layer level the IPSec and the Transport layer the TLS/SSL, proposed by the Internet Engineering Task Force, [IETF]. At the moment, IPSec is used mainly for Virtual Private Networks [VPN] but this could change as Secure Domain Name System or DNSSEC is earning acceptance (Göran, Kaj & Peik, 2003). The IETF standard Transport Layer Security [TLS] and Secure Socket layer [SSL] is used primarily for securing data communication carried on Hypertext Transfer Protocol [HTTP]. This Lead us to Web security and eCommerce security, were there are two main types of services to ponder transaction and access level security: thus we have the following mechanisms: HTTPS, the SSL Secured HTTP Protocol, the S-HTTP, Secure Hypertext Transfer Protocol, and the PCT, Private Communication Technology. Security administration counts with many programs for alerting, collecting, preventing and responding to incidents or events, like the so-called Intrusion Detection Systems [IDS] and the Intrusion Prevention Systems [IPS] (Panko, 2004).
Conclusion
Software, in their many manifestations, whereas in RFID, as Operating Systems or Network Protocols or like applications, is the means to produce information and for such to increase our knowledge and skills to solve our problems. As information is centric for our survival, so it is software as well.

References
Azari, R. (2003). Current Security Management & Ethical Issues of Information Technology. Hershey, PA, USA: Idea Group Inc., 2003. Retrieved January 20, 2008, from, http://wf2dnvr5.webfeat.org:80/8i3HJ1828/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10032091&ppg=18.
Basta, A. & Halton, W. (2007 August). Computer Security and Penetration Testing. Boston, Massachusetts: Course Technology, Thomson Learning, Inc.
Bellovin, S.M. (1989). Security Problems in the TCP/IP Protocol Suite. Murray Hill, New Jersey: AT&T Bell Laboratories. Retrieved January 20, 2008, from http://www.cs.columbia.edu/~smb/papers/ipext.pdf.
Birkholz, E. P. (2003). Special Ops: Host and Network Security for Microsoft, UNIX, and Oracle. Rockland, MA, USA: Syngress Publishing Retrieved January 20, 2008, from http://wf2dnvr3.webfeat.org:80/nDEHJ1268/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10023441&ppg=27.
Cisco IOS Security Configuration Guide Release 12.4. (2006 July 29). Corporate Headquarters. San Jose, CA: Cisco System, Inc. Retrieved January 20, 2008, from http://www.cisco.com/application/pdf/en/us/guest/products/ps6350/c2001/ccmigration_09186a00804f229a.pdf.
Coakes, E. (Editor). (2003). Knowledge Management: Current Issues and Challenges. Hershey, PA, USA: Idea Group Inc. Retrieved on January 13, 2008 from, http://http://wf2dnvr3.webfeat.org:80/nDEHJ1151/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10032062&ppg=22.
Ciampa, M. (2005). Security + Guide to Network Security: Fundamentals, 2nd Edition. Boston, Massachusetts: Course Technology, Thomson Learning, Inc.
Course Materials. (2008). Network Security. Course: CS653-0801A-01. Colorado Technical University. Retrieved January 19, 2008, from https://campus.ctuonline.edu/classroom/MultimediaCourseMaterials.aspx?Class=92946&tid=44.
Current Malware Threats and Mitigation Strategies. (2005 May 16). Informational Whitepaper. Multi-State Information Sharing and Analysis Center & US-CERT - United States Computer Emergency Readiness Team. Retrieved January 20, 2008, from http://wf2dnvr3.webfeat.org:80/R2LHJ138/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10158249&ppg=27.
Fitzgerald, M. (2001). Building B2B Applications with XML: A Resource Guide. New York, NY, USA: John Wiley & Sons. Retrieved January 21, 2008, from http://wf2dnvr3.webfeat.org:80/nDEHJ1195/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10001744&ppg=32.
Göran P., Kaj J. G. , Peik Å, (2003). Network security software, Current security management & Ethical issues of information technology, Hershey, PA: Idea Group Publishing.
Hassing, K., Kent, A. K., & Johnson, G. (2003). CCNA 1 & 2 Companion Guide, 3rd Edition. Cisco Networking Academy Program Indianapolis, IN: 2003.
Jackson, J. (2007 March 3). Assessing firmware vulnerability. Tech Blog, Government Computers News [GCN]. Retrieved January 21, 2008, from http://www.gcn.com/blogs/tech/43212.html.
Khosrow-Pour, M. (Editor). (2004). Annals of Cases in Information Technology, Volume 6. Hershey, PA, USA: Idea Group Inc. Retrieved January 19, from, http://wf2dnvr3.webfeat.org:80/nDEHJ1158/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10051156&ppg=113.
Maiwald, E. (2002). Security Planning and Disaster Recovery. Blacklick, OH, USA: McGraw-Hill Professional, 2002. Retrieve January 21, 2008, from http://http://wf2dnvr3.webfeat.org:80/R2LHJ12/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10043872&ppg=30.
Nelson, B., Phillips, F. E., & Steuart, C. (2004). Guide to Computer Forensics and Investigations. Boston, Massachusetts: Course Technology, Thomson Learning, Inc.
Panko R. R. (2005). Business Data Networks and Telecommunications, 5th Edition. Upper Saddle River, NJ: Prentice Hall- Pearson Education, Inc.
Panko R. R. (2004). Corporate Computers and Network Security. Upper Saddle River, NJ: Prentice Hall- Pearson Education, Inc.
Pflegeer C. P., & Pflegeer, S. L. (2003). Security in Computing, 3rd Edition. Upper Saddle River, NJ: Prentice Hall Professional Technical Reference, Prentice Hall- Pearson Education, Inc.
Ratnasingam, P. (2003). Inter-Organizational Trust for Business To Business E-Commerce. Hershey, PA, USA: Idea Group Inc. Retrieved January 12, 2008, from http://wf2dnvr3.webfeat.org:80/nDEHJ1167/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10032067&ppg=13.
Reuvid, J. (2006). Secure Online Business Handbook: A Practical Guide to Risk Management and Business Continuity (4th Edition). London, GBR: Kogan Page, Limited. Retrieved January 19, 2008, from http://wf2dnvr3.webfeat.org:80/R2LHJ138/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10158249&ppg=27.
Russell, T. (2000). Telecommunications Pocket Reference. New York, NY: McGraw- Hill Companies.
SANS Top-20 2007 Security Risks (2007 November 28). Annual Update. SANS Institute. Retrieved January 20, 2008, from http://www.sans.org/top20/.

Scheneier, B. (January 18, 2007). Information Security and Externalities. Retrieved January21, 2008, from http://www.schneier.com/blog/archives/2007/01/information_sec_1.html.

Tomasi, W. (2005). Introduction to Data communications and Networking, Upper Saddle River, NJ: Pearson Prentice Hall, Inc.

Wheeler, D. A. (2004 October 12). Linux Kernel 2.6: It's Worth More! Retrieved January 21, 2008, from http://www.dwheeler.com/essays/linux-kernel-cost.html


Saturday, June 14, 2008

Metasemantic Analysis


I am sharing with you this response....

Let me parse your message, since I always assume good faith from people and of course I do it with you, especially because I have a sense of spiritual intelligence behind your actions, and out of my believe in communication and education, I going to be a little granular with you in here, why? Because you have shown me respect with some of your feedback and I want to honor you as a colleague.

"I was rather impressed with what you did."

Thank you, as you might have seen I combined very fairly all of our contributions, as our interpretations, I was looking to balance up the gaps within each part, I did left some typos or minor mistakes though but due to my left eye that it was closing somehow on me, and it did not allow me to read well. It took me some hours of work and patience to put that together and I thrill that you have wrote me this line. Therefore, you make my day with this line "C."


"I am interested to know where you got some of those statistical slides from..."

The most brutal mistake for this presentation was to use MS-Project, I think; why? It is a cage difficult to get out of it. I have version 2003 and the graphics exporting and PERT analysis packages that offers are just not very helpful. Of course, the software has some things that are powerful, and helpful, but you need to battle with it. For instance, the ability to "extrapolate" quickly from the Gantt views to any other table, like the resources graph and matrix, or the PERT pessimistic table or resource use table. These things facilitates a great deal the allocation and determination of resources for tasks but once everything is Dandy and flashy inside one's Project file, it is not when it comes the time to show the world your work. Point in case, I expended a fruitful amount of hours to get the delicate information that I input in the WBS and GBS of this project in MS-project but if was not that smooth to export it to PowerPoint. I could have done it altogether in Excel, in which I can graph and calculated almost every thing, form the most ridiculous degrees of sigma or STDDEVs to the most demanding Riemann or Lévesque integration or other "areas under or over the curve" with it.

Therefore for statistics, I would say Excel but not for cartography though or mind mapping. Sometimes, I use Mathematica from Wolfram or Maple Software from a Canadian group, to do the calculations, when the models or simulations are arduous and intensive and require more powerful software functionality. Lately, I have been working out of my own interest, in a group collaborating in notions of graph theory, trees, connectivity, distance in graphs, Eulerian, Hamiltonian and planar graphs, and graph colorings. One of the results of it is the Gvedit or Graphvis, also it is the output of the AT&T labs’ credit. This program uses a DOT language to create the most complex graphs. The curious thing is that because this language utilizes the extension name .dot for saving its files, they open in MS-Word, and you can edit these files with that but it is better of use Emacs, vi or just notepad instead, It is terribly easy to grasp for making complex critical path graphs with it. Find it at http://www.graphviz.org/ for free and under the Common Public License. Hope you like it and give me your feedback about it.

In this particular case, I used MS-project, I detailed all the information out of my experience and research as I used some of your information as well at the input stage, as I was getting cranky with MS-Project I used many other programs, including Excel. Remember I used data and I manipulated that data from scratch just to make sure. For example, you budget was 13,000,000 or more in part because you figure out, that each workstation will cost around $1,7000.00 or so and then you calculate licenses for each user. I accepted the Exchange server, licenses part as in one slide I inputted your information as is in one slide’s note. However, the analysis and closer inspection with MS-Project and other tools showed other things as well that end with other results and I am sure with a little more time, we could change many things. Therefore, for the statistics I could use the formulas of Excel, or evenly calculated by hand as needed. So this is how I extracted the statistical slides, by figuring out the Phases or milestones and then typing and analyzing the whole WBS in MS-Project, followed by inputting many weights at the entry widget of the PERT analysis also I used Excel, for the PERT's Time Estimate or TE formula.

"Do you possess some type of software that creates that based upon the info you received from us?" [This question is loaded. I t is identified as the metasemantic root of the whole message, for such is the proto-intentional engine behind this question. This is to collapse many interpretations of the metasemantic world. (This is just for the author who is currently studying memetic worlds as metasemantic communications) as he engages with others, the reader please never mind]

Now, in terms of the graphics, all I made from the scratch myself except from one of two that were very generic and inconsequential because, they were from one of the public domain archives and illustrated some or other point. Most of the Graphs that I made are based on the combination of others or out of my research, some are entirely mine. In any case, I strive to give credit to all the sources that provides me with inspiration, knowledge base or ideas. I do this by releasing most of my educational work under Creative Commons Share Alike version 3.0, and under the GFDL too sometimes. The reason, why I do this with my documentation and with my graphics, is that some people have published some of my work, making money in the interim, but without even given credit. For example in one of the slides is depicted a complete workflow, I did that form scratch with one of my software tools based on the figure of Richman's book; and so he and his book, figure and page, it is clearly cited in that slide. I am very protective of people intellectual, private and freedom rights, I believe that these rights typify our western culture and societies.

Exactly, what it has made ad hoc for this project? I made the theme of the presentation. How? Just with PowerPoint. Other graphic and the statistical information were made with a combination of tools.

I looked for prices in http://Pricewatch.com (I am sure you know this site) primary to make sure about the hardware. I just put some of my experience in building networks and internetworks, if you read the breakdown carefully you can find a down to the earth approach to solve the problems and with the mentality of going beyond into the scalability and Security areas of an email system. Therefore, the only thing I needed was to make sure the number of dollars since practically all the information I had it in my head but I always check and recheck. This is to say I believe in my memory but much more in my reason. Your approach was correct and in nature could work but was a little too expensive. Now, in order to manage files and information, I used different mapping tools too. I also use graphic tools mostly non-proprietary, like Graphvis. I like to code with [SVGs] Scalable Vector Graphic and XML whether using AJAX or Comet paradigms. I use sometimes Illustrator, or Photoshop, and Corel Paint with Blender and Rhino but and for video Edition I use Avis. There are plenty number of tools to develop good graphic, maps for GIS, that are essentially Open source, that I have used but you will be get tire if I continue, most people do, that is why, I am writing a book instead. Why open source? Well, you got the "bless" of the source code and you can them customize security from the kernel up, if it were an OS, for instance.

The other main thing is your hardware capabilities; I build my hardware but lately because price and quality I just buy it. Anyway, you cannot compiled nothing if you don't have the right engine, you need at least 4 gigs of RAM and double-core Quad [Whether be, AMD Xeon, or Intel Extreme] for say the least, and even though it could take you a long time to learn some sophisticated tools, like Rhino or Adobe CSPS3. That is why I prefer to use vectorized images rather than pixilated or bitmapped-rasterized pictures or graphs. However, this could take you to experience some grievances because not all browsers are created equal, they do not render equally the DOM [Document Object Model] objects the same. Firefox is "good", meaning, it is SVG compatible, as it is not the case with IE, it needs a plug-in, and this made the distribution of your image just a little sort of fuzzy and harsh for you.

In addition, If I would not have any computers I will do fine too, I still have my own hands, I studied Technical drafting and geometry descriptive since I was a 14 year-old, so I have plotted mechanical parts with my own hands all along and without any CAD software. If what we are talking were about Art, I teach myself to paint at the age of 10. Then, late on life and influence by the life of Gauguin and Van Gogh, I took formal art training in painting and sculpture not for one but for five years at the Art Students League of New York, exactly I paint oils, frescoes and pastels.

Painting from life and still life, it is marvelous, so I paint á la prima and with my hands, no with computers out of coping photographs or other's people work and without camera oscura. I paint with not other thing that my perception, perspective knowledge and skill in combining colors at once and at the spur of the moment, also I do it with passion and with the minimal regard for money. It was then as it is now, the art for the art sake. Finally, if my hands and my body, as it is somehow now, will refuse to aid me in my pursuit for beauty, I will use my mind and I will create substantial amount of images that if I would not be able to ever translate these to any media, I shall at least imagine them. I will, no matter what condition be free, because my freedom intrinsically rest in my principles and in my respect for the rights and believes of others as well.

I have dedicated my life to learning. Many things, I have learned then by myself, as most of us. I have partaken in formal academics, I attended classrooms and conferences, just to make sure I am in the right track, knowing that it is perhaps and overkill, since art and science are both learned by the determination and passion of the beholder. To understand what formally has been done and not because one could be recognized by a group, although this is good for surviving or for professional interests, all it is fine for me though.

You see there is something out there greater than men and ants, if you are truthful, really, it does not belong to our time, it transcends time boundaries and its entropic causation in which we currently live. It is like Keats' dictum "Beauty is Truth and truth is beauty", so as I don't understand many "social things" that are deeply rooted in the memes and spirits of the time in which people live, I don't mind them at all. Because, they seem to me just part of a culture and that it is very mutable in general. I am interested in the metasemantics of the things been learned or acquired, represented or understood, all images at last represent the same.

"At any rate it is exceptionally well done"

Now, this is another priceless statement for me it makes my life tremendously happy, but we, all of us, did exceptionally well for this project.

"I hope you feel better in the near future, I read some of what you and "P" spoke about regarding your health and I too am praying for your recovery."

Well, I have always to keep my difficulties to myself. I decided this time, that perhaps that was a terrible mistake and one of my main problems. Now, I am trying to share even my sufferings with others. I think I will be much better, as have always put this on my mind, but if I could not, I am doing my best to do my best in the mean time and until I could I would and must do just that.

"Take care"
Take care too "C", God provides to all men of good faith the ability to empathize with their neighbors. It is the Amazing Grace; we need to experience it, and eventually all of us we will have our “Coram Deo” moment. However, no matter what is our problem we have, we always can find beauty in everything that we do, all around us, because the beauty that we shall find in everything is simply God.

Wednesday, June 04, 2008

Other People's Network

The Ecommerce Architecture

Learning & Understanding Ecommerce Infrastructure

Cheswick/Burch Map of the Internet

Introduction


The main reason why Plow of the Sea, Inc [PotS], a small but prospering corporation has hired me, as a Networking Security Engineer [NSE], it is that the top management has recently decided to develop a competitive ecommerce or eBusiness presence. One of my main goals was to obtain the adequate executive level support for designing and implementing the networking security policy and conduct an enterprise wide security, education and awareness program. Even though, for the most part the network architecture has been already implemented, its security has not been properly developed, possibly because the lack of staff training or awareness about the importance that information systems security plays in the success of PotS, Inc’s ecommerce ventures. In this blog post, I am briefly identifying, describing and discussing the main topologies that are used to design and implement networks and internetworks that facilitate commercial online or web transactions and for such they can be considered as the network infrastructure and the bare bones of the ecommerce (Course, 2008).

Exploring Networks


At the very beginning of our journey into the realms of networking security, we need to understand the network topologies, that infrastructure whereby the exchange of information remotely or locally is carried on. However, firstly what really is a network? Especially nowadays, when it seems that everything is connected or networked somehow, as our personal information appears to be spinning around the globe many times within a gamut of disparate computing devices, cables and airwaves. Panko (2005); a consultant that has been working for the Whitehouse, gives us a very comprehensive definition of it, he states: “A network is a system of hardware, software, and transmission components that collectively allow two applications programs on two different stations connected to the network to communicate well.” (p. 3, chap 1), I also have another definition, a network is an interconnection of devices to form a pathway on which to exchange a signal, perhaps this concept is the reason why we call a small telephone network an “exchange”.

As we are exploring these concepts in some depth, with the aim to understand how network security is making our personal information and privacy safer, I would like to add that once upon a time and not too long ago, experts were talking about the phenomenon of convergence. During those times corporations needed to have two separate networks, one for voice and video, and other for data. Now with Voice over IP [VoIP], YouTube, Google, mobile wireless connections, Radio-Frequency Identification [RFID], Automatic Identification and Mobility (AIM) et al., convergence seems to be a done deal and corporations nowadays only need to implement one single enterprise network as a solution for all their telecommunications and data networking needs (Panko, 2003). Therefore, we should discuss networking topologies to increase our awareness over the network infrastructure and the challenges therein about its protection.

Network topologies

Barabási & Réka (1999) implied that the difficulties to describe, and for such to understand, complex networks rest in their topologies (p. 2-11), therefore is not a bad idea at all to become familiar with some of the nuances behind network topologies. Experts refer to network topologies when they are describing configurations of connected computers or information systems [IS]. This terminology can lead to confusions, for instance there are two types of networking topologies: [1] physical and [2] logical (or signal topology) logical topology describes the methods and algorithms used to pass information among computer and network components (Tomasi, chap. 17, p. 515). I usually differentiate these two topologies by thinking in the differences therein between hardware and software. Hardware is anything that can be touched, i.e., tangible; and software is those several sequences of instructions that it is used to process data for obtaining desired information, and for such is intangible (the spirit in the machine). It just flows from one point to other, in a stream of a bunch of zeros and ones, and so we are able to save it in many formats, within those various network components and storage devices, whether locally or remotely elsewhere.

Network design & Physical Topology

Once we have identified and evaluate our business concerns and opportunities in terms of desired data processing capacity, information transaction volume requirements and communications needs, we are in the position to design the information system that shall meet the demands imposed by those needs and requirements. The first step is to figure out what are the hardware and software elements that could substantiate the business model for putting the ecommerce site into ‘massive’ motion. Once we have identified and acquired the necessary resources, its time for assembling the network and so the need to arrange and organize these components so they can interoperate well.

Physical topology is the layout and configuration assigned by the system designers to connect two o more devices for sharing information over the network. The Physical topology involves the distribution of devices in a geometrically manner (segmentation) and within a determined geographically area; for example a network can consists of a minimum of two computers or nodes [although nowadays this is highly unlikeable] (Tomasi, 2005,). In fact, all devices or components that can be assigned an address in a Transfer Control Protocol [TCP]/Internet Protocol [IP] network are called nodes. Today connecting two computers is a task that is a piece of cake, but back in those “snickernet” times, two computers connected were considered a real deal, and it did not matter if just they were physically located next to each other.

Two computers, (Personal Computers) PC-to-PC can be connected via Network Interface Cards [NICs], transceivers (Homan, 1998), Universal Serial Bus [USB], serial or parallel ports. Today some people still using this type of connection throughout Universal Twisted-Pair [UTP] Crossover cables, USB cables, or wirelessly, using the ad-hoc mode or Bluetooth, because several different reasons propel them to do so (Russell, 2000, Chap. 4). In reality, the three main types of layouts and their combination thereof define the ABC of the configuration and wiring in networking the physical topology. Thus, we have the following main topologies: [A] Star, [B] Bus, and [C] Ring (Hassing, Kent, & Johnson, 2003).

The differences among Physical Topology


‘Addressing’ in a Local Area Network or LAN for short, changes according to the type of topology selected; LAN addressing could be unicast, one device; multicast, many devices; and broadcast, all devices. For example, the primary feature of the Star topology is that computers are linked to a central device; to either a hub or a switch (just the name of concentrators or electronic boxes use signal distribution), in a point-to-point direct connection. All transmissions enter this central device and are forwarded to all ongoing links. However, there are hubs that are more capable. The smart or managed hubs that allow the configuration of users’ access points for LAN connectivity, for instance, the Cisco’s 1500 Microhub series. Notwithstanding, the central device that is most often used today is the “switch”, this device could detect and save the Media Access Control address [MAC address] from the computers’ NIC cards connected to the network. A switch is able to forward the message, in this case, the frame, to a specific destination. Switches also can be managed, or unmanaged, it all depends of your budget and needs. The Cisco’s Catalyst family switches are managed via the proprietary operating systems [OS] developed by Cisco, called Internetwork OS [IOS]. Hubs are considered a layer 1 devices (by the International Organization for Standardization [ISO [not an acronym, but an Etymological denomination, from the Latin word “iso” meaning equal or standard as applied to all] Open Systems Interconnect [OSI] Reference Model [RM]); as switches are mostly considered Layer 2 (Data link) devices because they use and are able to build a MAC addresses table from the connected computers in the local network. The MAC address is a six hexadecimal number that is edged permanently in each NIC card. This number identifies physically each device in a network. By the way, the IP addresses are considered the logical addresses of the devices (an IP is temporally assigned to the node and can be reassigned). In contrast to the MAC addresses that are seen as the physical address and that cannot be reassigned or this we suppose, there are programs that can modify the MAC address by masking them in away.

Star topology seems to be ideal for troubleshooting since all traffic necessarily needs to flow into the central node, be either this facilitate by a switch or a hub, and thus appears to be very manageable for a small amount of devices and can be easily expanded or scaled as well. For instance, time-sharing systems, database management and word-processing systems are generally configured with a star topology.

The major inconvenience of the star topology is that the network is reliable as the central node or device. If the switch or hub fails then the network also fails, since the other computer would not have ways to contact one to other. Therefore, a central device is a critical resource, because a start network topology will be unable to function at all without it. A centralized network has the syndrome of the always avoided and feared “single point of failure”. This topology is capable of implementing Ethernet or LocalTalk. (Russell, 2005)

Bus topology is a multipoint or multidrop configuration whereby computers are interconnected to a single shared communication channel or transmission medium, thence its name of Bus. Its length is limited because certain attenuation problems; that is, the signals become weaker as they travel throughout the cables o more exactly, the wires. However, weaken signals can be enhanced and boosted by perusing repeaters and/or bridges. In this case the most critical resource is the ‘bus’ itself, because if it would get damaged and depending how and were, it could make the whole network inoperable as well. On the positive side, bus topology networks do not need routing information to be stored or retransmitted, as consequence, all that overhead is gone. However, as the traffic increases, collisions [crashes] among computers also will increase, thus a contention strategy has been ideated under the name of: Carrier Sense Multiple Access with collision Detection [CSMA/CD]. Scalability, is the main issue for the bus topology, it seems cumbersome, to find cables over the ceiling, on the wall or under the floor to connect another computer, this is why wireless networks seem to be such a blessing.

Developers have implemented other topologies to facilitate the expansion of bus network topology, called the Tree topology, consisting in adding more bus segments as a way of branching further the network. For Bus topology and Tree or Hierarchical topology, it is employed the Ethernet standard, this topology is suitable for the utilization of Ethernet and LocalTalk. (Russell, 2000).

Ring topology is a daisy-chained group of connected computers, in which one computer is connected to the other forming a circle or loop. Ring topology facilitates the transmission of messages in one way, one computer to the next, either in counterclockwise or clockwise direction, until the message reaches its final destination. Ring topology devices have to states: Listen or transmitting mode (aided by a signal, i.e., the token). The downside of the Ring topology is that almost every computer needs to retransmit the message (Hassing, Kent, & Johnson, 2003).

From these basic types of network topologies, other types of topologies are generated, such as partial and full mesh, double ring and a combination of two or more topologies, i.e., hybrid topologies. When a router, a layer 3 (of the ISO-OSI-RM) device is used, the network is able to forward packets to other networks, thus in how you are connect to the Internet [the global network made out of networks and for such the host of all the webs]. These types of topologies can then be joined over large geographical areas, constituting internetworks or networks of networks, call accordingly, Wide Area Networks [WAN], Metropolitan Area Networks [MAN], Campus Area Network [CANs] Global Area Networks [GAN] and finally, there we are, the Internet.

Conclusion

One of the main goals of networking security engineering is to bring the highest level possible of information assurance, ciphered in three main areas of information security confidentiality, availability, & integrity. By setting correctly the aforementioned topologies, the designers are being able to understand how to improve the security of the system and reduce the risks therein (Tomasi, 2005; Panko 2005).

For example, ideally, from the very beginning of the network design, and as a networking security engineer [NSE], I recommend the identification of security controls, constrains, requirements and features that would have matched the business requirements. Thus, I am increasing the likelihood that the PotS’s Local Area Networks [LANs] and Wide Area Network [WAN] would be able to operate as intended in the first place. Now, the challenges that we face ahead for initiating the PotS eBusiness venture, are issues associated with risk management, i.e., system’s reliability [downtimes], network management, scalability and performance, and how to offer a level of security for customers so they would be able to feel comfortable to buy products and/or order services from the PotS’s e-catalogue via online services.

References

Barabási, A. & Réka, A. (1999 October 21). Emergence of Scaling in Random Networks. Department of Physics, Notre-Dame, IN: University of Notre-Dame. Retrieved, January 8, 2008, from http://arxiv.org/PS_cache/cond-mat/pdf/9910/9910332v1.pdf.

Hassing, K., Kent, A. K., & Johnson, G. (2003). CCNA 1 & 2 Companion Guide, 3rd Edition. Cisco Networking Academy Program Indianapolis, IN: 2003.

Homan, C. (1998 October 19). NICs and Transceivers: Overview. UCDavis Network 21. Retrieved, January 8, 2008, from http://net21.ucdavis.edu/nic21rec.htm.

Panko R. R. (2005). Business Data Networks and Telecommunications, 5th Edition. Upper Saddle River, NJ: Prentice Hall- Pearson Education, Inc.

Russell, T. (2000). Telecommunications Pocket Reference. New York, NY: McGraw- Hill Companies.

Tomasi, W. (2005). Introduction to Data communications and Networking, Upper Saddle River, NJ: Pearson Prentice Hall, Inc.

Plowed Results | Resultados Arados