Monday, May 11, 2009

Exercise 16: Authentication and Encryption systems

1. Visit an e-commerce website and survey the mode of payment allowed. Would you trust the site with your business?

I have visited the eBay. In the eBay help page, it list the following payment methods:

a. PayPal
b. Credit cards and debit cards
c. Moneybookers
d. Paymate
e. ProPay
f. Pay upon pickup
g. Escrow

I would like to trust the eBay and PayPal for the business. It is because they are well known and famous company. The most important point is that they protect both merchant and buyer for business in its ecommerce website.

2. What measures should e-commerce provide to create trust among their potential customers? What measures can be verified by the customer?

a. Payment and its status should be traceable. (traceability)
b. Provide purchase protection
c. Prevent seller to obtain buyer's credit card number when using international wire payment such as PayPal (anonymous)
d. Provide encryption and authentication for information transfer.

3. Visit the Verisign web site - what solutions does it offer for e-commerce?

The versign provide SSL certification for authentication. The certification is used to certify the identity of the individuals and website. By using the PKI infrastructure, it is possible to authenticate the website and individual through the certificate and the three way handshare mechanism.

4. Visit the TRUSTe web site. Describe what services and solutions are offered.

The TRUSTe web site provides online privacy services to individual and businesses.
According to the factsheet from TRUSTe, they provide the following solutions for protecting privacy.

"Web Privacy Seal Marks companies that adhere to TRUSTe’s strict privacy principles and comply with the TRUSTe Watchdog Dispute Resolution System.

EUSafe Harbor Seal Certifies compliance with the EU Directive on Data Protection, specifically the Safe Harbor Framework, to avoid trade disruptions resulting from international privacy laws.

Email Privacy Seal Reinforces companies’ commitments to good email practices by certifying email disclosures, reputation, and unsubscribe policies.

Trusted Download Program Provides market incentives for adware and other software companies to clearly and unavoidably communicate key functionalities and obtain informed consumer consent prior to download.

Site Reputation Services Reduces the risk of attack by using technology to scan user-generated or third-party content for potential malicious content before it’s uploaded to a Web site"

5. Get the latest PGP software from http://web.mit.edu/network/pgp.html; install it on two machines and encrypt a message on one machine and decrypt it on the other. Report your findings.


Figure 1. PGP software is not found at URL provided



Figure 2. Install screen of PGP Desktop


Figure 3. Key Generation Assistant


Figure 4. Encryption settings for keys


Figure 5. Enter passphrase for private key


Figure 6. Generate the key and sub key


Figure 7. Secure a plain text file


Figure 8. Add key to secure file


Figure 9. Sign and Save the secured file


Figure 10. Compare plain text and encrypted file


Figure 11. Decrypt the encrypted file


Figure 12. Enter the key to decrypt


Figure 13. Decrypted file


I've download the trial version at www.pgp.com. When I install the PGP program, it generates two keys, one of them is private and one is for public. During the encryption of the plain text file I made, it asked to add a signature on to the encrypted file.

6. The use of digital certificates and passports are just two examples of many tools for validating legitimate users and avoiding consequences such as identity theft. What others exist?

Biometrics
It is used to identify the person by recognizing the physiological charactertics such as retina, fingerprint, face recognition.

Smart Card
It is a chip with integrated circuit with non-volatile and volatile storage components and microprocessor components. It is used to authenticate himself/herself to sign-on the company.

Friday, May 8, 2009

Not my week

During these weeks, my computer is down (the mainboard is dead) and need to be rebuilt.
At work, a special guess is going to visit the office. We are busying to prepare the things such as posters, computer labs for the visitor such that I actually do not have time to work on the blog.
All I can do is try to rebuild my computer as fast as I can and do some of the work during lunch time at office.

Just not my day and week!

Monday, April 27, 2009

Exercise 15: Protecting and archiving data

1. What makes a firewall a good security investment? Accessing the Internet, find two or three firewall vendors. Do they provide hardware, software or both?

Elias (2003) described that firewall acts as a sheild to prevent data and information inside the network to the public. Firewall is a hardware and software tool defines control and access of network and computers.

Firewall vendors:
Check Point Firewall
It is a security vendor, it sells hardware appliance and software firewall.

Kerio Technologies
It is a security vendor, it sells software firewall only.

Comodo
It is a security vendor, it sells software firewall and integrated security solutions.

2. Find out if your university or workplace has a backup policy in place. Is it followed and enforced?

In my workplace, there is a backup policy for the main servers. It is a enforced policy. In the policy, all files and data are backup daily to the backup server. As the backup server uses hard drives to store data, RAID-5 system is used and the backup server is located away from the main servers.

A tape backup system is also implemented to some of the servers. It backup data in a full backup manner. The tapes are rotated and changed every two weeks and the tape with the data is stored away from the server and tape backup system.


3. Most of the antivirus software perform an active scanning of the user activity on the Internet, detecting downloads and attachments in e-mails. Hackers have readily available resources to create new viruses. How easy is it to find a virus writing kit? Search the Internet and find such a tool. For example, see what you can find at http://vx.netlux.org/dat/vct.shtml.

In the http://vx.netlux.org, the virus can be easily generated with the generator.
Each of them generate different kind of virus.

As I searched with keyword "create computer virus", I found a blog from Bendib (Nov 22, 2008. 6:35 PM) posted a virus source code in his blog.

As I search again in Google with keyword "computer virus generator", one of the computer security website shows the name of the generator. I then search again with the name listed in the security website. It is easy to find the generator with the search engines.

Exercise 14: Electronic payments and security II

1. What are cookies and how are they used to improve security?

As the web pages from the web servers are stateless, cookies is developed to store the information in users' computer for maintaining the interaction between the web page changes within a website and revisit of the web site by user. (W3.org)

According to W3.org, there is a attribute in cookies. The attribute validates the information send and through from the users' browser to the originating server/website but not others, this mechanism prevents the information in cookies not to be collected by others.

2. Can the use of cookies be a security risk?

The common information contained in cookies are:
a. the session ID or authorization information
b. issue time and date of the cookie
c. time of expiration
d. the IP address of the browser the cookie was issued to
e. a message authenticity check (MAC) code

Although the mechanism prevents the information send to other servers, there is still security risk when browsing the websites. The adverising agent in the internet promote the website holder to post advertisement in their website. As a result, when a user browse the website which subscribe the agent, the information will be logged in their cookies. The collected information in the cookies with the IP address contained can be used to analyze for the user habbits and interests. The privacy of the user is affected.

Reference:
Lincoln D. S., John N. S. (2003), The World Wide Web Security FAQ, Retrieved 27 April 2009 from http://www.w3.org/Security/Faq/wwwsf2.html

Exercise 13: Electronic payments and security I

1. List and describe your experiences with a secure Web site. Some examples may be:
• University enrolment;
• online banking, auctions, real estate;
• booking a cheap air ticket or concert ticket;
• shopping online for a book, software or a CD.

I have tried to apply jobs with the secure website. The website is established by the Hong Kong government with Hong Kong University. The sys tem is named Government Vacancies Enquiry System .

When I enter the application form at the site, a lock liked symbol is located on the status bar of the browser. The system does not allow to use the forward and backward button on the browser to go back or forth. Changes can be made by selecting the page before the end of entering information.

Finally, a agreement is to be signed by selecting the check box and press SUBMIT button to send the form.


2. What is SET and how does it compare to SSL as a platform for secure electronic
transaction? Is SET in common use?

Based on the Bernstein, Bhimani, Schultz, Siegel (1996), In term of protocol the SSL is a general purpose protocol between browser and server while SET is a special protocol to link up between customer, merchant, card issuing bank and merchant’s bank.

Interm of keys and signatures, SSL uses a pair of keys for encryption and digital signature but SET uses two pairs of keys for separating encryption and digital signature.

The SET is not a common use protocol becsue it only works with credit/debit card.

Reference:
Bernstein T., Bhimani A. B., Schultz E., Siegel C. A. (1996), Internet Security for Business, Wiley, p.332-351

Exercise 12: Designing for a secure framework

1. Find out about SET and the use of RSA 128-bit encryption for e-commerce.

SET stands for Secure Electronic Transaction. It is a protocol designed for secure credit and debit card transaction between customers and merchants. With this protocol, all messages including ordering and payment information are encrypted. As both parties using SET requires digital certificate, any modification of the data and information can be altered. As the merchants complete the transaction with the bank but not the customer directly, the privacy of customer is retained.

RSA 128-bit encryption is a encryption method for symmertic keys for the certificate issued to merchants and clients who uses SET for transactions.

RSA recommended that the 128-bits as a minimum symmetric security level till 2013 and beyond. This level requires the minimum RSA key size to be at 3072bits.


2. What can you find out about network and host-based intrusion detection systems?

Wikipedia (2009) stated that "A network intrusion detection system (NIDS) is an independent platform which identifies intrusions by examining network traffic and monitors multiple hosts. Network Intrusion Detection Systems gain access to network traffic by connecting to a hub, network switch configured for port mirroring, or network tap. An example of a NIDS is Snort."
It is found to be a packet level analyzer for intrusion.

Wikipedia (2009) stated that "A host-based intrusion detection system (HIDS) consists of an agent on a host which identifies intrusions by analyzing system calls, application logs, file-system modifications (binaries, password files, capability/acl databases) and other host activities and state. An example of a HIDS is OSSEC."
It is found to be a application level analyzer for intrusion.

3. What is ‘phishing’?
Phishing is a kind of technique to collect victim's user name and password for criminal activities.

It always uses emails that pretent itself as an enterprise or organization and send to the users. The email mostly used to acknowledge the user to change his/her password with a specified web address that similar to the real address.

When user click on the web address provided by that email, it leads the user to a fake website, which look and feel as the real website to collect the personal information such as user name and password of a bank account. It usually lead financial loss on victim user. (webopedia, Wikipedia)


Reference:
Wikipedia (2009), Intrusion detection system, Retrieved 24 May 2009 from http://en.wikipedia.org/wiki/Intrusion-detection_system

Wikipedia (n.d.), Phishing, Retrieved 28 April 2009 from http://en.wikipedia.org/wiki/Intrusion-detection_system

webopedia (n.d.), All About Phishing, Retrieved 28 April 2009 from http://www.webopedia.com/DidYouKnow/Internet/2005/phishing.asp

Secure Electronic Transaction (SET), Retrieved 4 May 2009 from http://lyle.smu.edu/~nair/courses/7349/SET.ppt

Wednesday, April 15, 2009

About Elevator pitch

I just wanna to know if we need to put the script into our blog?