The anthropologist Wade Davis who has stated that have live 30 years with the Chincheros reveals and explain cultures from Peru
Friday, June 20, 2008
A worldwide web of belief and ritual
The anthropologist Wade Davis who has stated that have live 30 years with the Chincheros reveals and explain cultures from Peru
Thursday, June 19, 2008
The Insecurity in the Systems Intelligence: A Very Brief Study of the Failures of Information Security Projects
What do IT projects fail so often? What are the impacts, if any; do these failures have on the confidentiality, integrity and availability [CIA] of our Information Systems? A fundamental and direct relationship between these two processes (security and failure) exists without a doubt; however, being that the impacts of project failure on security is a certainty, as it is obvious and dangerous, for the operational stability of our IT systems; and having in consideration that all along systems project failure is very expensive and has caused so much pain and sorrow: Why then, we are not more careful about developing and implementing these type of crucial projects? These were some of the questions that were explored during our last Xterior’s security team weekly meeting. On this paper, I am briefly documenting my conclusions based on the literature review that I had conducted about the failure of information systems security projects (Courses Material, 2007).
Insecurity Preambles
It is common knowledge what that old saying states: “The necessity is the mother of the invention.” I could not find a better word, with which I could epitomize more accurately the degree of civilization of any given society, and hence innovations are the best of our human manifestations that stems from our lack of having the adequate vital resources, or the insecurity to be free from our most basic physiological needs. The advances of any determined culture or historical period are represented precisely by its tools, as by its knowledge employed to solve their challenges, which typifies the distributed human intelligence expressed through the development of arts, sciences, architecture, engineering, weaponry, and industry and governmental institutions. Thus the history of invention describes and enumerates those technologies used from the Stone Age, throughout the contemporary and pervasive, as seemingly intrusive and insecure, Information age.
However as our inventions, i.e. the ability to create tools, objects and ideas for outreaching our overarching goals and objectives, and creativity have assisted us to become organized as nations with peculiar cultures and philosophies (the east and the west divide). Thus, we have survived and adapted to the inclemency of our environment and we have triumphed over all known beasts in nature with the exception of only one: The Man itself. “Homo Homini Lupus”, i.e., "Man is a wolf to man," is a famous Roman Proverb attributed to Plautus (184 BC) and used it as one of the main ingredients in the authoritarian social contract, in his “De Cive”, by Thomas Hobbes (1651). Thenceforth, it is the beginning of our tribulations, insecurities and project failures; it appears ingrained in our own needs, instincts, self-interested reasons and imperfect souls. It is not any different now that it was then, in the Stone Age, we need to survive. So, If the necessity were the mother of the invention, then the scarcity is the grandmother of all our insecurities and wrong doings. Therefore, information security deals not only with technology; it involves other factors that are more darker, deep-rooted and less understood than any form of attack because it has been, is and will be the source of all our human maladies.
System Project Failure
Failure is lack of success. To fail is to lose in a way, as not being able to provide. If a system were not working as expected, then we state, “the system has failed”, by the same token is a project fails, we can say “the project as the people who were involved in it, have fallen short in meeting the goals” or “they could not grow or develop fast enough to deliver successfully what is was expected or needed at this time.” (Scalability problem) At the end of the day, system project failures have significant costs, not only for the project team’s morale but in terms of dollars, time and other resources, as the loss of critical information, that have proven catastrophic for many business cases. Nowadays, that our lives spin around multiple projects, it will be a good idea to refresh our memories, and figure out what exactly is a project and why projects do fail. As I see it, a project is an organized and systematized activity that employs resources, i.e., people, technology, and processes or operations, within a well-defined start date, milestones or phases, and end date (duration and schedule) with the aim to achieve a relative unique service or product within an organization (Sommerville, 2000).
Learning from Failure
The study of failure could ensure the path to success. What did work some years ago to solve a problem, it might not work today. To investigate why systems projects usually fail, we need to understand how we plan, administer, monitor and evaluate them; in other words, we are asking what Project Management [PM] is. PM is a life cycle based discipline utilized to achieve desired and projected goals within a determined schedule and specific budgetary constrains (Why, 2007). Many experts agree that one of the main reasons why systems or Information Technology [IT] projects failed so often is the lack of knowledge, understanding or experience, of the IT Managers about System Engineering [SE] (Sommerville, 2000, p. 9); and on how to apply effectively the PM Body of Knowledge [PMBOK] for their specific situations. For instance, Wimmel & Wisspeintner (2003) showed the importance for security managers to be familiar with the application of the “Information Technology Security Evaluation Criteria” [ITSEC], AKA “the Orange book” and/or the Common Criteria [CC]; both standards that are usually utilized for designing and modeling trusted ecommerce systems. As it is the case of Plow of the Sea, Inc that now wants to translate its retailing business experience into the Internet.
Sten E. Vesterly (2004) based on surveys, reported that only one quarter of the System projects are almost completed as expected, as they meet just some of their specified deliverables according to schedule and budget. He added that two quarters of the IT projects deliver their final outputs with serious deficiencies in functionality and largely exceeding their price and time tags. In addition, that one quarter of the entire projects deliver anything but yes, they consumed all and evenly more of the money, time and resources that were assigned to them at their inception or during planning process (p. 1-7); No wonder, why IT Systems Project managers are fired with conspicuous frequency.
Vesterly (2004) explained that another cause, for the aforementioned negative and poor system project outcomes, is the overexciting or excessive enthusiasm created by the new features and rapid deployment of powerful emergent technologies. Most IT staff just cannot resist them and become too ambitious in including uncertain devices or software mechanisms; and so become part of what it has been called, the frontlines of the “bleeding edge”. As many new-released hardware, firmware and software off the shelf have not been properly tested or certified, using these products create tremendous stress in supporting their deployment and maintenance. IT Prudence is required in designing and developing system projects. On the other hand, Vesterly (idem), pointed out, that some IT managers usually offer the argument of, “If it works, don’t fix it”, pretending that legacy systems will work in the same way, facing the same attacks as they used to, within new and dangerous environments with threats that in no manner were known or evenly envisioned when they were firstly deployed. It suffices only to recalled the case of zero-day attacks, to understand that upgrading and patching systems is not only necessary, it should be continuous and compulsory goal to be enforced to all IT managers by the top security managers in any organization (p. 1-7). Ted Hendy (2000), the System Security Architect and Engineer at the Pentagon for the Office of the Secretary of Defense [OSD], stressed the importance of human analysis and the use of Security System Engineering Process and Techniques to prevent major problems in planning, implementing and managing IT systems, Hendy (idem) summarized very well why systems fail, “Though the technology exists to do great things in this field, without thoughtful analysis and preparation many of those attempts are doomed to fail.” (p. 1).
Moreover, we know too well, that complexity creates havoc and it is very difficult to manage. The complexity of the Information Systems [IS], which is incremented by the rapid change in the technology available to use; as the level of sophistication, reached by the IS interoperability and components interactions, has created confusion and pressure on security and IT managers. Actually, the system complexity is one of the major causes of the other aforementioned factors. In reality, studying the causes that originate systems project failure is looking for answers as to why systems projects fail and how to do for implementing more trusted IS (Ivory & Alderman, 2005, p. 1-13).
Sommerville (2000) reminded that systems components are just not only about inert parts or soulless machines working as a whole with emergent own characteristics, properties and capabilities; systems also involved people and are built for support them and aid human activity (p. 3). Therefore, we need to zero-in on the users and operators too, and on the risks associated with how these users and operators are aware, trained and educated for perusing the systems infrastructure and access critical information. (Ivory & Alderman, 2005, p. 1-13) This factor is outlined by Beckley (2007) as inadequate training; he presents also other causes for the failure of system projects, such as: Radical and unconventional changes; the lack of enterprise level support and resources or budget; and communication failures (Slide 53). In addition, the figure 1, below, encapsulates the concepts behind the systems project failures and the difference between what the users want and what they finally get:

Conclusion
At the end of the day, some factors of failure appear at the beginning of the project, like the lack of communication among the team members of the project, or understanding over which ones are the system requirements or over roles or responsibilities. Some factors develop on the last phase of the project, like the lack of proper testing or evaluative practices. However, system projects fail at any phase during their development process, whereas for the lack of monitoring, contingency measures, or concurrency, interdependency and tasking issues, or event or people driven deadlocks. Systems project failure poises a great danger given its frequency. It has come to mean for us, as Xterior security managers, prevention, instead of contention; it means alertness instead of lamentations. It also means due-diligence and al lot of work and patience to estimate the process and to not sub estimates nothing; and so it security system projects need to adherence to system security engineering standards, such as SSE-CMM for reaching an adequate level of information assurance, and system reliability for Xterior’s customers.
A successful project not only meets its goals and objectives on time and within budget, but also implements and translates accurately the business model requirements into the security technology controls that squarely satisfy the security policy of the corporation.
Business - The Ultimate Resource. (2002) London, GBR: Bloomsbury Publishing Plc. Retrieved November 30, 2007, from http://http://wf2dnvr5.webfeat.org:80/dIEzI117/url=http://site.ebrary.com/lib/cecybrary/Doc?id=10022156&ppg=1.
Hendy, T. (2000, May 9). The art of security engineering. US Army Information Systems Engineering Command. Retrieved November 30, 2007, from http://www.itoc.usma.edu/Workshop/2000/Abstracts/TM2_1.pdf.
Hobbes, T. (1651). De Cive. Retrieved December 1, 2007 from, http://socserv2.socsci.mcmaster.ca/~econ/ugcm/3ll3/hobbes/hobbes1.
Ivory, C. & Alderman N. (2005, September 28). Can Project Management Learn Anything From Studies Of Failure In Complex Systems? Project Management Journal, Vol. 36 Issue 3, p. 5-16, 12p. Retrieved November 30, 2007 from, http://search.ebscohost.com/login.aspx?direct=true&db=buh&jid=1NR&loginpage=Login.asp&site=ehost-live.
Mitchell, A. (2004, December 14). E-Commerce Missing Link: Software Requirement Specifications. E-Commerce Times. Retrieved December 2, 2007, from http://www.ecommercetimes.com/story/38919.html.
Sommerville, I. (2000). Critical Systems Engineering: Processes and techniques for developing critical systems. PowerPoint Presentation. Retrieved December 2, 2007 from, http://www.comp.lancs.ac.uk/computing/resources/IanS/Ian/Courses/CritSys-2004/PDF-notes/Introduction.pdf
Vesterli, S. E. (2004, October 19). Why IT Projects Fail − and how to avoid it. Retrieved on December 2, 2007, from http://vesterli.com/papers/why_it_projects_fail.pdf.
Wimmel, G. & Wisspeintner, A. (2003, June 17). Extended Description Techniques For Security Engineering. Institut für Informatik, Technische Universität: München, D-80290 München, Germany. Retrieved December 2, 2007 from, http://www4.in.tum.de/publ/papers/WW01.pdf.
Why do Projects Fail? (2007). JISC InfoNet. Retrieved December 2, 2007 from, http://www.jiscinfonet.ac.uk/InfoKits/project-management/pm-intro-1.2.
From The Chronicles of The Metasemantic Web III: Thus spoke Seattlle: Metasemantic Webs-Metacultures: Uncrashing the Past into our Future

There is much controversy over the environment nowadays. We do not know for sure what words really spoke, the Chief Seatle or Seattle, but this we know: he has and statue, and it seems that he compromised and survived until his natural death.
Also, he had a friend in Dr. Smith, who translated his words. It appears that the poems or letters attributed to him were embellished at later time, for making movies, money or for other reasons, rather than to try to improve the lives of the first Americans, or Pre-Americans, or Pre-Columbians. They are called Indians due to a mistake, really.
I called them humans, humans that were profoundly degraded, almost exterminated, ripped-off of their lands and brutally and largely dehumanized in the name of many things because they just lost the war. Yes, it is the Spencerian categorization, the survival of the fittest; with less and less animals, less plants and more energy demands, instead of green our planet is becoming gray. I would like to see from where we are going to take more money, or where we are going to look for new Indians or slaves. Oh yes... I am so sorry, there is water in Mars! and oil or something else elsewhere in the galaxies, go get continue with the autopsy...
"Man did not weave the web of life - he is merely a strand in it.
Whatever he does to the web, he does to himself."
Chief Seattle, 1854.
Archaeologists, convinced that there is something more in the past, are looking really intensively in explaining to us how it was done in detail. National Geographic is graphical about one proven instance of the massacre, crash and war of two civilizations.
Again another mistake, it is called "conquista", ["Conquest"], and the winners are called using another euphemism, "Conquistadors", but in reality we all know what it was, don't we? While, we accept many things, we need to think of the consequences of these enterprises, for the whole world, including the world that we build for ourselves. Thousand of immigrants are coming
and continue coming, why is this occurring? We need to recognized that there are a lot of problems that are deeply rooted in another sort of cause that we cannot see, may be greedy, for survival and/or the thirst of put others down, I just do not know. A business is not a business while all what one is doing is taking goodies or labor from others by force, or by misleading contracts, agreements or licenses, and given it to your family or people. Yes, it was a war, but an unfair war, that for these people it would not have never an end. Rarely a war does, it never ends in a way, they stay somehow forever. So the fight continues and in the fighting we seem to be all embedded therein, as Willy Nelson will sing it, "After all these years".
Whether is was done thousand of years or just now. Look at what is happening in the middle east, unfortunately all the world is still kind of paying for something that was started some millenniums ago and far away from us.
Whatever the source of our problems is or would have been, as Polya, would tell us, we need to properly name it, define it that is, and make the necessary arrangements to improve this present for our future for the futures generations.
I do not think, we are doing this, so are we taking for granted the world peace that we have. It is very plausible that we are profiling another war, the third war world, WW version 3.0.
Whereby, we were having WWII.1 in the cold war, the WWII.5 the war for Kuwait and now we have the WWII.6, the holy war against the terrorism and lately we seem to be near to have a WWII.7, a world against our own environment. Some people say that is our nature, the brutish and evil nature of Man defined so well by Hobbes. The law of the Homo Homini Lupus.
I said, that incidentally, and definitely, there are some people that believe in supremacy, slavery, and war as the way of man. At any rage and for any reason under any social structure, epoch and within families, at the schools, at the job places, in the markets, these people appear somehow and evenly flourish as they are well-admired by people that think the same or like to think the same. They are very cohesive in nature, and so they organize.
As they seem to be very concreted up to the point to become binary thinkers at large, so for them is rather easy to make decisions, or it is war or it is peace, or they win or they loose, or you are white and you are not and so you are the rest. Fairness is not a principle for them, it is an issue, winning is all what it counts in the end, so they could utter: "Long live Machiavelli".
The second law of evolution: The survival of the fittest but based in mutual aid should be considered in here. Of course, once when we all are uploaded and saved into the "machine", then as Bill Joy stated and it would be perhaps easy to answer in here, "why the future does not need us"? It is rather obvious, isn't it?
Most likely, we are already an expendable number by now. Never mind, let us continue hunting and fishing and watching TV and playing golf though... Try to see the past ... then you see the
future, as above as below...
Wednesday, June 18, 2008
The Best Blog of the Web: The Blogger is a 96 year-old
Tuesday, June 17, 2008
Sunday, June 15, 2008
Network Security Software Risks & Vulnerabilities with Malware Prevention
Bowels & Pelaez’s Malware Taxonomy
| |
Programs Needing a Host
|
Self-reproducing
|
Trap Doors: Secret point of entrance to the system. This represents a serious threat.
|
Bacteria: self-replicating harmless program for only one detail that replicates so much that in the end could take all the capacity of the victim computer.
|
Logic Bomb: Waits for a date or and event to do their deeds. One of the earliest forms of Virus, very damaging in deed.
| |
Trojan Horse: A “Goodie” with maladies.
Very serious threat.
|
Worm: Infects computers through network connections, can behave like virus and bacteria or could install Trojans too. Its effects are devastating.
|
Virus or Retrovirus: Infect other programs by copying its code to them and continuously infecting others. Serious Threat. Retrovirus behaves like a virus with the detriment-added attribute of being able to attack anti-virus; Even more serious.
| |

Tomasi, W. (2005). Introduction to Data communications and Networking, Upper Saddle River, NJ: Pearson Prentice Hall, Inc.
Wheeler, D. A. (2004 October 12). Linux Kernel 2.6: It's Worth More! Retrieved January 21, 2008, from http://www.dwheeler.com/essays/linux-kernel-cost.html
Saturday, June 14, 2008
Metasemantic Analysis
"I was rather impressed with what you did."
Thank you, as you might have seen I combined very fairly all of our contributions, as our interpretations, I was looking to balance up the gaps within each part, I did left some typos or minor mistakes though but due to my left eye that it was closing somehow on me, and it did not allow me to read well. It took me some hours of work and patience to put that together and I thrill that you have wrote me this line. Therefore, you make my day with this line "C."
"I am interested to know where you got some of those statistical slides from..."
The most brutal mistake for this presentation was to use MS-Project, I think; why? It is a cage difficult to get out of it. I have version 2003 and the graphics exporting and PERT analysis packages that offers are just not very helpful. Of course, the software has some things that are powerful, and helpful, but you need to battle with it. For instance, the ability to "extrapolate" quickly from the Gantt views to any other table, like the resources graph and matrix, or the PERT pessimistic table or resource use table. These things facilitates a great deal the allocation and determination of resources for tasks but once everything is Dandy and flashy inside one's Project file, it is not when it comes the time to show the world your work. Point in case, I expended a fruitful amount of hours to get the delicate information that I input in the WBS and GBS of this project in MS-project but if was not that smooth to export it to PowerPoint. I could have done it altogether in Excel, in which I can graph and calculated almost every thing, form the most ridiculous degrees of sigma or STDDEVs to the most demanding Riemann or Lévesque integration or other "areas under or over the curve" with it.
Therefore for statistics, I would say Excel but not for cartography though or mind mapping. Sometimes, I use Mathematica from Wolfram or Maple Software from a Canadian group, to do the calculations, when the models or simulations are arduous and intensive and require more powerful software functionality. Lately, I have been working out of my own interest, in a group collaborating in notions of graph theory, trees, connectivity, distance in graphs, Eulerian, Hamiltonian and planar graphs, and graph colorings. One of the results of it is the Gvedit or Graphvis, also it is the output of the AT&T labs’ credit. This program uses a DOT language to create the most complex graphs. The curious thing is that because this language utilizes the extension name .dot for saving its files, they open in MS-Word, and you can edit these files with that but it is better of use Emacs, vi or just notepad instead, It is terribly easy to grasp for making complex critical path graphs with it. Find it at http://www.graphviz.org/ for free and under the Common Public License. Hope you like it and give me your feedback about it.
In this particular case, I used MS-project, I detailed all the information out of my experience and research as I used some of your information as well at the input stage, as I was getting cranky with MS-Project I used many other programs, including Excel. Remember I used data and I manipulated that data from scratch just to make sure. For example, you budget was 13,000,000 or more in part because you figure out, that each workstation will cost around $1,7000.00 or so and then you calculate licenses for each user. I accepted the Exchange server, licenses part as in one slide I inputted your information as is in one slide’s note. However, the analysis and closer inspection with MS-Project and other tools showed other things as well that end with other results and I am sure with a little more time, we could change many things. Therefore, for the statistics I could use the formulas of Excel, or evenly calculated by hand as needed. So this is how I extracted the statistical slides, by figuring out the Phases or milestones and then typing and analyzing the whole WBS in MS-Project, followed by inputting many weights at the entry widget of the PERT analysis also I used Excel, for the PERT's Time Estimate or TE formula.
"Do you possess some type of software that creates that based upon the info you received from us?" [This question is loaded. I t is identified as the metasemantic root of the whole message, for such is the proto-intentional engine behind this question. This is to collapse many interpretations of the metasemantic world. (This is just for the author who is currently studying memetic worlds as metasemantic communications) as he engages with others, the reader please never mind]
Now, in terms of the graphics, all I made from the scratch myself except from one of two that were very generic and inconsequential because, they were from one of the public domain archives and illustrated some or other point. Most of the Graphs that I made are based on the combination of others or out of my research, some are entirely mine. In any case, I strive to give credit to all the sources that provides me with inspiration, knowledge base or ideas. I do this by releasing most of my educational work under Creative Commons Share Alike version 3.0, and under the GFDL too sometimes. The reason, why I do this with my documentation and with my graphics, is that some people have published some of my work, making money in the interim, but without even given credit. For example in one of the slides is depicted a complete workflow, I did that form scratch with one of my software tools based on the figure of Richman's book; and so he and his book, figure and page, it is clearly cited in that slide. I am very protective of people intellectual, private and freedom rights, I believe that these rights typify our western culture and societies.
Exactly, what it has made ad hoc for this project? I made the theme of the presentation. How? Just with PowerPoint. Other graphic and the statistical information were made with a combination of tools.
I looked for prices in http://Pricewatch.com (I am sure you know this site) primary to make sure about the hardware. I just put some of my experience in building networks and internetworks, if you read the breakdown carefully you can find a down to the earth approach to solve the problems and with the mentality of going beyond into the scalability and Security areas of an email system. Therefore, the only thing I needed was to make sure the number of dollars since practically all the information I had it in my head but I always check and recheck. This is to say I believe in my memory but much more in my reason. Your approach was correct and in nature could work but was a little too expensive. Now, in order to manage files and information, I used different mapping tools too. I also use graphic tools mostly non-proprietary, like Graphvis. I like to code with [SVGs] Scalable Vector Graphic and XML whether using AJAX or Comet paradigms. I use sometimes Illustrator, or Photoshop, and Corel Paint with Blender and Rhino but and for video Edition I use Avis. There are plenty number of tools to develop good graphic, maps for GIS, that are essentially Open source, that I have used but you will be get tire if I continue, most people do, that is why, I am writing a book instead. Why open source? Well, you got the "bless" of the source code and you can them customize security from the kernel up, if it were an OS, for instance.
The other main thing is your hardware capabilities; I build my hardware but lately because price and quality I just buy it. Anyway, you cannot compiled nothing if you don't have the right engine, you need at least 4 gigs of RAM and double-core Quad [Whether be, AMD Xeon, or Intel Extreme] for say the least, and even though it could take you a long time to learn some sophisticated tools, like Rhino or Adobe CSPS3. That is why I prefer to use vectorized images rather than pixilated or bitmapped-rasterized pictures or graphs. However, this could take you to experience some grievances because not all browsers are created equal, they do not render equally the DOM [Document Object Model] objects the same. Firefox is "good", meaning, it is SVG compatible, as it is not the case with IE, it needs a plug-in, and this made the distribution of your image just a little sort of fuzzy and harsh for you.
In addition, If I would not have any computers I will do fine too, I still have my own hands, I studied Technical drafting and geometry descriptive since I was a 14 year-old, so I have plotted mechanical parts with my own hands all along and without any CAD software. If what we are talking were about Art, I teach myself to paint at the age of 10. Then, late on life and influence by the life of Gauguin and Van Gogh, I took formal art training in painting and sculpture not for one but for five years at the Art Students League of New York, exactly I paint oils, frescoes and pastels.
Painting from life and still life, it is marvelous, so I paint á la prima and with my hands, no with computers out of coping photographs or other's people work and without camera oscura. I paint with not other thing that my perception, perspective knowledge and skill in combining colors at once and at the spur of the moment, also I do it with passion and with the minimal regard for money. It was then as it is now, the art for the art sake. Finally, if my hands and my body, as it is somehow now, will refuse to aid me in my pursuit for beauty, I will use my mind and I will create substantial amount of images that if I would not be able to ever translate these to any media, I shall at least imagine them. I will, no matter what condition be free, because my freedom intrinsically rest in my principles and in my respect for the rights and believes of others as well.
I have dedicated my life to learning. Many things, I have learned then by myself, as most of us. I have partaken in formal academics, I attended classrooms and conferences, just to make sure I am in the right track, knowing that it is perhaps and overkill, since art and science are both learned by the determination and passion of the beholder. To understand what formally has been done and not because one could be recognized by a group, although this is good for surviving or for professional interests, all it is fine for me though.
You see there is something out there greater than men and ants, if you are truthful, really, it does not belong to our time, it transcends time boundaries and its entropic causation in which we currently live. It is like Keats' dictum "Beauty is Truth and truth is beauty", so as I don't understand many "social things" that are deeply rooted in the memes and spirits of the time in which people live, I don't mind them at all. Because, they seem to me just part of a culture and that it is very mutable in general. I am interested in the metasemantics of the things been learned or acquired, represented or understood, all images at last represent the same.
"At any rate it is exceptionally well done"
Now, this is another priceless statement for me it makes my life tremendously happy, but we, all of us, did exceptionally well for this project.
"I hope you feel better in the near future, I read some of what you and "P" spoke about regarding your health and I too am praying for your recovery."
Well, I have always to keep my difficulties to myself. I decided this time, that perhaps that was a terrible mistake and one of my main problems. Now, I am trying to share even my sufferings with others. I think I will be much better, as have always put this on my mind, but if I could not, I am doing my best to do my best in the mean time and until I could I would and must do just that.
"Take care"
Take care too "C", God provides to all men of good faith the ability to empathize with their neighbors. It is the Amazing Grace; we need to experience it, and eventually all of us we will have our “Coram Deo” moment. However, no matter what is our problem we have, we always can find beauty in everything that we do, all around us, because the beauty that we shall find in everything is simply God.
Friday, June 06, 2008
B2E Business to Everyone: Ecommerce Security - The Challenge of Protecting the Privacy of our Customers
For the whole script of this presentation contact John Manuel @ DiogenesRex@gmail.com
Wednesday, June 04, 2008
The Ecommerce Architecture
Learning & Understanding Ecommerce Infrastructure
Cheswick/Burch Map of the Internet
Introduction
The main reason why Plow of the Sea, Inc [PotS], a small but prospering corporation has hired me, as a Networking Security Engineer [NSE], it is that the top management has recently decided to develop a competitive ecommerce or eBusiness presence. One of my main goals was to obtain the adequate executive level support for designing and implementing the networking security policy and conduct an enterprise wide security, education and awareness program. Even though, for the most part the network architecture has been already implemented, its security has not been properly developed, possibly because the lack of staff training or awareness about the importance that information systems security plays in the success of PotS, Inc’s ecommerce ventures. In this blog post, I am briefly identifying, describing and discussing the main topologies that are used to design and implement networks and internetworks that facilitate commercial online or web transactions and for such they can be considered as the network infrastructure and the bare bones of the ecommerce (Course, 2008).
Exploring Networks
At the very beginning of our journey into the realms of networking security, we need to understand the network topologies, that infrastructure whereby the exchange of information remotely or locally is carried on. However, firstly what really is a network? Especially nowadays, when it seems that everything is connected or networked somehow, as our personal information appears to be spinning around the globe many times within a gamut of disparate computing devices, cables and airwaves. Panko (2005); a consultant that has been working for the Whitehouse, gives us a very comprehensive definition of it, he states: “A network is a system of hardware, software, and transmission components that collectively allow two applications programs on two different stations connected to the network to communicate well.” (p. 3, chap 1), I also have another definition, a network is an interconnection of devices to form a pathway on which to exchange a signal, perhaps this concept is the reason why we call a small telephone network an “exchange”.
As we are exploring these concepts in some depth, with the aim to understand how network security is making our personal information and privacy safer, I would like to add that once upon a time and not too long ago, experts were talking about the phenomenon of convergence. During those times corporations needed to have two separate networks, one for voice and video, and other for data. Now with Voice over IP [VoIP], YouTube, Google, mobile wireless connections, Radio-Frequency Identification [RFID], Automatic Identification and Mobility (AIM) et al., convergence seems to be a done deal and corporations nowadays only need to implement one single enterprise network as a solution for all their telecommunications and data networking needs (Panko, 2003). Therefore, we should discuss networking topologies to increase our awareness over the network infrastructure and the challenges therein about its protection.
Network topologies
Barabási & Réka (1999) implied that the difficulties to describe, and for such to understand, complex networks rest in their topologies (p. 2-11), therefore is not a bad idea at all to become familiar with some of the nuances behind network topologies. Experts refer to network topologies when they are describing configurations of connected computers or information systems [IS]. This terminology can lead to confusions, for instance there are two types of networking topologies: [1] physical and [2] logical (or signal topology) logical topology describes the methods and algorithms used to pass information among computer and network components (Tomasi, chap. 17, p. 515). I usually differentiate these two topologies by thinking in the differences therein between hardware and software. Hardware is anything that can be touched, i.e., tangible; and software is those several sequences of instructions that it is used to process data for obtaining desired information, and for such is intangible (the spirit in the machine). It just flows from one point to other, in a stream of a bunch of zeros and ones, and so we are able to save it in many formats, within those various network components and storage devices, whether locally or remotely elsewhere.
Network design & Physical Topology
Once we have identified and evaluate our business concerns and opportunities in terms of desired data processing capacity, information transaction volume requirements and communications needs, we are in the position to design the information system that shall meet the demands imposed by those needs and requirements. The first step is to figure out what are the hardware and software elements that could substantiate the business model for putting the ecommerce site into ‘massive’ motion. Once we have identified and acquired the necessary resources, its time for assembling the network and so the need to arrange and organize these components so they can interoperate well.
Physical topology is the layout and configuration assigned by the system designers to connect two o more devices for sharing information over the network. The Physical topology involves the distribution of devices in a geometrically manner (segmentation) and within a determined geographically area; for example a network can consists of a minimum of two computers or nodes [although nowadays this is highly unlikeable] (Tomasi, 2005,). In fact, all devices or components that can be assigned an address in a Transfer Control Protocol [TCP]/Internet Protocol [IP] network are called nodes. Today connecting two computers is a task that is a piece of cake, but back in those “snickernet” times, two computers connected were considered a real deal, and it did not matter if just they were physically located next to each other.
Two computers, (Personal Computers) PC-to-PC can be connected via Network Interface Cards [NICs], transceivers (Homan, 1998), Universal Serial Bus [USB], serial or parallel ports. Today some people still using this type of connection throughout Universal Twisted-Pair [UTP] Crossover cables, USB cables, or wirelessly, using the ad-hoc mode or Bluetooth, because several different reasons propel them to do so (Russell, 2000, Chap. 4). In reality, the three main types of layouts and their combination thereof define the ABC of the configuration and wiring in networking the physical topology. Thus, we have the following main topologies: [A] Star, [B] Bus, and [C] Ring (Hassing, Kent, & Johnson, 2003).
The differences among Physical Topology
‘Addressing’ in a Local Area Network or LAN for short, changes according to the type of topology selected; LAN addressing could be unicast, one device; multicast, many devices; and broadcast, all devices. For example, the primary feature of the Star topology is that computers are linked to a central device; to either a hub or a switch (just the name of concentrators or electronic boxes use signal distribution), in a point-to-point direct connection. All transmissions enter this central device and are forwarded to all ongoing links. However, there are hubs that are more capable. The smart or managed hubs that allow the configuration of users’ access points for LAN connectivity, for instance, the Cisco’s 1500 Microhub series. Notwithstanding, the central device that is most often used today is the “switch”, this device could detect and save the Media Access Control address [MAC address] from the computers’ NIC cards connected to the network. A switch is able to forward the message, in this case, the frame, to a specific destination. Switches also can be managed, or unmanaged, it all depends of your budget and needs. The Cisco’s Catalyst family switches are managed via the proprietary operating systems [OS] developed by Cisco, called Internetwork OS [IOS]. Hubs are considered a layer 1 devices (by the International Organization for Standardization [ISO [not an acronym, but an Etymological denomination, from the Latin word “iso” meaning equal or standard as applied to all] Open Systems Interconnect [OSI] Reference Model [RM]); as switches are mostly considered Layer 2 (Data link) devices because they use and are able to build a MAC addresses table from the connected computers in the local network. The MAC address is a six hexadecimal number that is edged permanently in each NIC card. This number identifies physically each device in a network. By the way, the IP addresses are considered the logical addresses of the devices (an IP is temporally assigned to the node and can be reassigned). In contrast to the MAC addresses that are seen as the physical address and that cannot be reassigned or this we suppose, there are programs that can modify the MAC address by masking them in away.
Star topology seems to be ideal for troubleshooting since all traffic necessarily needs to flow into the central node, be either this facilitate by a switch or a hub, and thus appears to be very manageable for a small amount of devices and can be easily expanded or scaled as well. For instance, time-sharing systems, database management and word-processing systems are generally configured with a star topology.
The major inconvenience of the star topology is that the network is reliable as the central node or device. If the switch or hub fails then the network also fails, since the other computer would not have ways to contact one to other. Therefore, a central device is a critical resource, because a start network topology will be unable to function at all without it. A centralized network has the syndrome of the always avoided and feared “single point of failure”. This topology is capable of implementing Ethernet or LocalTalk. (Russell, 2005)
Bus topology is a multipoint or multidrop configuration whereby computers are interconnected to a single shared communication channel or transmission medium, thence its name of Bus. Its length is limited because certain attenuation problems; that is, the signals become weaker as they travel throughout the cables o more exactly, the wires. However, weaken signals can be enhanced and boosted by perusing repeaters and/or bridges. In this case the most critical resource is the ‘bus’ itself, because if it would get damaged and depending how and were, it could make the whole network inoperable as well. On the positive side, bus topology networks do not need routing information to be stored or retransmitted, as consequence, all that overhead is gone. However, as the traffic increases, collisions [crashes] among computers also will increase, thus a contention strategy has been ideated under the name of: Carrier Sense Multiple Access with collision Detection [CSMA/CD]. Scalability, is the main issue for the bus topology, it seems cumbersome, to find cables over the ceiling, on the wall or under the floor to connect another computer, this is why wireless networks seem to be such a blessing.
Developers have implemented other topologies to facilitate the expansion of bus network topology, called the Tree topology, consisting in adding more bus segments as a way of branching further the network. For Bus topology and Tree or Hierarchical topology, it is employed the Ethernet standard, this topology is suitable for the utilization of Ethernet and LocalTalk. (Russell, 2000).
Ring topology is a daisy-chained group of connected computers, in which one computer is connected to the other forming a circle or loop. Ring topology facilitates the transmission of messages in one way, one computer to the next, either in counterclockwise or clockwise direction, until the message reaches its final destination. Ring topology devices have to states: Listen or transmitting mode (aided by a signal, i.e., the token). The downside of the Ring topology is that almost every computer needs to retransmit the message (Hassing, Kent, & Johnson, 2003).
From these basic types of network topologies, other types of topologies are generated, such as partial and full mesh, double ring and a combination of two or more topologies, i.e., hybrid topologies. When a router, a layer 3 (of the ISO-OSI-RM) device is used, the network is able to forward packets to other networks, thus in how you are connect to the Internet [the global network made out of networks and for such the host of all the webs]. These types of topologies can then be joined over large geographical areas, constituting internetworks or networks of networks, call accordingly, Wide Area Networks [WAN], Metropolitan Area Networks [MAN], Campus Area Network [CANs] Global Area Networks [GAN] and finally, there we are, the Internet.
Conclusion
One of the main goals of networking security engineering is to bring the highest level possible of information assurance, ciphered in three main areas of information security confidentiality, availability, & integrity. By setting correctly the aforementioned topologies, the designers are being able to understand how to improve the security of the system and reduce the risks therein (Tomasi, 2005; Panko 2005).
For example, ideally, from the very beginning of the network design, and as a networking security engineer [NSE], I recommend the identification of security controls, constrains, requirements and features that would have matched the business requirements. Thus, I am increasing the likelihood that the PotS’s Local Area Networks [LANs] and Wide Area Network [WAN] would be able to operate as intended in the first place. Now, the challenges that we face ahead for initiating the PotS eBusiness venture, are issues associated with risk management, i.e., system’s reliability [downtimes], network management, scalability and performance, and how to offer a level of security for customers so they would be able to feel comfortable to buy products and/or order services from the PotS’s e-catalogue via online services.
References
Barabási, A. & Réka, A. (1999 October 21). Emergence of Scaling in Random Networks. Department of Physics, Notre-Dame, IN: University of Notre-Dame. Retrieved, January 8, 2008, from http://arxiv.org/PS_cache/cond-mat/pdf/9910/9910332v1.pdf.
Hassing, K., Kent, A. K., & Johnson, G. (2003). CCNA 1 & 2 Companion Guide, 3rd Edition.
Homan, C. (1998 October 19). NICs and Transceivers: Overview. UCDavis Network 21. Retrieved, January 8, 2008, from http://net21.ucdavis.edu/nic21rec.htm.
Panko R. R. (2005). Business Data Networks and Telecommunications, 5th Edition.
Russell, T. (2000). Telecommunications Pocket Reference.
Tomasi, W. (2005). Introduction to Data communications and Networking,

