<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>StacyChiam BITS 3413&#039;s Blog</title>
	<atom:link href="http://stacychiam.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://stacychiam.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Thu, 29 Oct 2009 20:50:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='stacychiam.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>StacyChiam BITS 3413&#039;s Blog</title>
		<link>http://stacychiam.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://stacychiam.wordpress.com/osd.xml" title="StacyChiam BITS 3413&#039;s Blog" />
	<atom:link rel='hub' href='http://stacychiam.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Lecture@21 Oct &amp; LabTest@22 Oct</title>
		<link>http://stacychiam.wordpress.com/2009/10/22/lecture21-oct-labtest22-oct/</link>
		<comments>http://stacychiam.wordpress.com/2009/10/22/lecture21-oct-labtest22-oct/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 20:48:51 +0000</pubDate>
		<dc:creator>stacychiam</dc:creator>
				<category><![CDATA[Network & IT Security]]></category>

		<guid isPermaLink="false">http://stacychiam.wordpress.com/?p=78</guid>
		<description><![CDATA[Lecture (21 Oct 09) Today is the last lecture of this subject, i wish this subject will never end because it is much more interesting than any other subjects. Sigh&#8230;.. :&#60; We have covered 2 topics today, which are Intrusion Detection System &#38; Legal And Ethical Issues In Computer Security. In IDS, the examples of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=78&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h2><span style="color:#000080;"><span style="text-decoration:underline;">Lecture (21 Oct 09)</span></span></h2>
<p style="text-align:justify;"><span style="color:#000000;">Today is the last lecture of this subject, i wish this subject will never end because it is much more interesting than any other subjects. Sigh&#8230;.. :&lt;</span><br />
We have covered 2 topics today, which are <span style="color:#993366;"><strong>Intrusion Detection System</strong></span> &amp; <span style="color:#3366ff;"><strong>Legal And Ethical Issues In Computer Security</strong></span>.</p>
<p style="text-align:justify;">In IDS, the examples of intruders are significant issue hostile / unwanted trespass, user trespass and software trespass. The examples of intrusion are:</p>
<ul style="text-align:justify;">
<li>
<div>remote root compromise</div>
</li>
<li>
<div>web server defacement</div>
</li>
<li>
<div>guessing / cracking passwords</div>
</li>
<li>
<div>copying viewing sensitive data / databases</div>
</li>
<li>
<div>running a packet sniffer</div>
</li>
<li>
<div>distributing pirated software</div>
</li>
<li>
<div>using an unsecured modem to access net</div>
</li>
<li>
<div>impersonating a user to reset password</div>
</li>
<li>
<div>using an unattended workstation</div>
</li>
</ul>
<p style="text-align:justify;">Intrusion Detection can be classified as Host-based and Network-based. Host-based IDS is to monitor single host activity; whereas Network-based IDS is to monitor the network traffic. The requirements of IDS are:</p>
<ul style="text-align:justify;">
<li>
<div>run continually</div>
</li>
<li>
<div>be fault tolerant</div>
</li>
<li>
<div>resist subversion</div>
</li>
<li>
<div>impose a minimal overhead on system</div>
</li>
<li>
<div>configured according to system security policies</div>
</li>
<li>
<div>adapt to changes in systems and users</div>
</li>
<li>
<div>scale to monitor large numbers of systems</div>
</li>
<li>
<div>provide graceful degradation of service</div>
</li>
<li>
<div>allow dynamic reconfiguration</div>
</li>
</ul>
<p style="text-align:justify;">There are three types of Intrusion Detection Techniques, they are signature detection, anomaly detection and when potential detected sensor sends an alert and logs information. Then, we know the SNORT is the lightweight IDS that is used for real time packet capture and rule analysis. Lastly is Honeypot which is the decoy system that emulates the entire networks.</p>
<p style="text-align:justify;">Next, we proceed to the last chapter: <strong>Legal and Ethical Issues in Computer Security. </strong>The differences of law and ethic are as below:</p>
<p style="text-align:justify;">1. Law</p>
<ul style="text-align:justify;">
<li>Formal, documented</li>
<li>Interpreted by courts</li>
<li>Established by legislature representing everyone</li>
<li>Applicable to everyone</li>
<li>Enforceable by police and courts</li>
</ul>
<p style="text-align:justify;">2. Ethic</p>
<ul style="text-align:justify;">
<li>Described by unwritten principles</li>
<li>Interpreted by individuals</li>
<li>Presented by philosophers, religions, professional group</li>
<li>Personal choice</li>
<li>Priority determined by individual if two principles conflict</li>
<li>Self-practice</li>
</ul>
<p style="text-align:justify;">Some examples for the ethics concept in Information Security are ethical differences across cultures, software license infringement, illicit use, misuse of corporate resources, ethics and education and deterrence to unethical and illegal behaviour (ignorance, accident and intent). The three ways protecting programs and data are trade secret, copyrights and patents. Although open-source software are free, they are protected by copyright protection also somehow. For example, one will be sued if he or she sells the copy of the open software.<br />
The issues related to Information are information commerce, electronic publishing and database. On the other hand, employee and employers should know their rights in order to avoid the law problems. Some of the rights are ownership of a patent, ownership of a copyright, work for hire, licenses, trade secret protection and employment contracts. To examine a case for ethical issues, we can use the following methods:</p>
<ul style="text-align:justify;">
<li>
<div>Understand the situation. Determine the issues involved.</div>
</li>
<li>
<div>Know several theories of ethical reasoning</div>
</li>
<li>
<div>List the ethical principles involved</div>
</li>
<li>
<div style="text-align:justify;">Determine which principles outweigh others.</div>
</li>
</ul>
<h2><span style="color:#000080;"><span style="text-decoration:underline;">Lab Test (22 Oct 09)</span></span></h2>
<p><span style="color:#000080;"><span style="color:#000000;">Today is our lab test of this subject, there are 3 questions and we have to answer 2 out of this 3 questions. The question 2 I totally no idea how to answer it. So, i have no choice, i must answer question 1 &amp; 3. Luckily all this i have learn during lab session, so it is not too difficult. Hopefully my kind lecturer can give me a good result. Hehehe&#8230;.^^</span><br />
</span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stacychiam.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stacychiam.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stacychiam.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stacychiam.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/stacychiam.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/stacychiam.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/stacychiam.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/stacychiam.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stacychiam.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stacychiam.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stacychiam.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stacychiam.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stacychiam.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stacychiam.wordpress.com/78/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=78&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://stacychiam.wordpress.com/2009/10/22/lecture21-oct-labtest22-oct/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a25f7b065464eb5f9209820e9ba7495c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stacychiam</media:title>
		</media:content>
	</item>
		<item>
		<title>Lecture@14Oct &amp; Lab@15 Oct</title>
		<link>http://stacychiam.wordpress.com/2009/10/15/lecture14oct-lab15-oct/</link>
		<comments>http://stacychiam.wordpress.com/2009/10/15/lecture14oct-lab15-oct/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 20:23:07 +0000</pubDate>
		<dc:creator>stacychiam</dc:creator>
				<category><![CDATA[Network & IT Security]]></category>

		<guid isPermaLink="false">http://stacychiam.wordpress.com/?p=75</guid>
		<description><![CDATA[Lecture session (14 Oct 09) Today is my coursemate + housemate + roomate = Wong Yen Ping&#8217;s birthday. Happy Birthday ya~^^ Ok, now we continue on our lecture&#8230;.hehe&#8230;.sounds like I&#8217;m the one giving lecture. Today&#8217;s topic is Wireless Security. The first part of the lecture was basically some sort of revision which we have studied [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=75&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h2 style="text-align:justify;"><span style="color:#333399;"><span style="text-decoration:underline;">Lecture session (14 Oct 09)</span></span></h2>
<p style="text-align:justify;"><span style="color:#000000;">Today is my coursemate + housemate + roomate = Wong Yen Ping&#8217;s birthday. Happy Birthday ya~^^</span></p>
<p style="text-align:justify;">Ok, now we continue on our lecture&#8230;.hehe&#8230;.sounds like I&#8217;m the one giving lecture. Today&#8217;s topic is Wireless Security. The first part of the lecture was basically some sort of revision which we have studied in networking subjects in the previous few semesters. There are two types of wireless mode; they are infrastructure mode and ad-hoc mode. There are two categories of infrastructure mode:</p>
<ol style="text-align:justify;">
<li>
<div>Basic Service Set (BSS) – All workstations are connected to one access point.</div>
</li>
<li>
<div>Extended Service Set – Two or more BSSs connect together to form a single subnet.</div>
</li>
</ol>
<p style="text-align:justify;">For ad-hoc mode or sometimes known as peer-to-peer, are independent BSS. It means that the wireless workstations are connected together without connecting to the access point first. And then we continue the lecture which is more to the security part of the wireless network. There are three basic security services defined by IEEE for WLAN:</p>
<ol style="text-align:justify;">
<li>
<div>Authentication – to provide a security service for verification the identity of communicating client stations.</div>
</li>
<li>
<div>Integrity – to ensure that messages are not modified in transit between the wireless clients and the access point in an active attack.</div>
</li>
<li>
<div>Confidentiality – to provide “privacy achieved by a wired network”</div>
</li>
</ol>
<p style="text-align:justify;">Wireless network can be categorised into four types, they are 802.11a, 802.11b, 802.11g and 802.11n. The two security services provided in 802.11b are Authentication (Shared Key Authentication) and Encryption (Wired Equivalence Privacy). Based on what I have understood, the encryption is done by a mechanism called RC4. It is a symmetric key encryption which applying RSA encryption algorithm. The three processes for WEP sending are:</p>
<ol style="text-align:justify;">
<li>
<div>Compute Integrity Check Vector (ICV)</div>
</li>
<li>
<div>Encrypt plaintext via RC4</div>
</li>
<li>
<div>Transmit the ciphertext</div>
</li>
</ol>
<p style="text-align:justify;">The processes are reversed when the ciphertext in order to get the plaintext. There are several WEP safeguards such as shared secret key required, messages are encrypted and messages have checksum. The passive attack happens when attacker collects all traffic or attacker collect two messages (Encrypted with same key and same IV and statistical attack to reveal plaintext). On the other hand, active attack could happen if attacker knows the pair of complement plaintext and ciphertext or through bitflipping method. Although some vendors limited WEP keys, it also can be brute forced in several minutes. The ways to do brute force key attack are:</p>
<ul style="text-align:justify;">
<li>
<div>Capture ciphertext.</div>
</li>
<li>
<div>Search all 240 possible secret keys.</div>
</li>
<li>
<div>Find which key decrypts ciphertext to plaintext.</div>
</li>
</ul>
<p style="text-align:justify;">The 802.11 safeguards are as follow:</p>
<ul style="text-align:justify;">
<li>
<div>Security Policy and Architecture Design</div>
</li>
<li>
<div>Treat it as untrusted LAN</div>
</li>
<li>
<div>Discover unauthorized use</div>
</li>
<li>
<div>Access point audits</div>
</li>
<li>
<div>Station protection</div>
</li>
<li>
<div>Access point location</div>
</li>
<li>
<div>Antenna design</div>
</li>
</ul>
<p style="text-align:justify;">The problem of WEP has been fixed with the replacement of Wi-Fi Protected Access (WPA). No matter how good it was fixed, it still has its weaknesses. The two practical attacks of WPA are dictionary attack on pre-shared key mode and denial of attack.<br />
The lecture then continued with a new chapter called firewall. The capabilities of firewall are:</p>
<ul style="text-align:justify;">
<li>
<div>defines a single choke point that keeps unauthorized users out of the protected network</div>
</li>
<li>
<div>provides a location for monitoring security events</div>
</li>
<li>
<div>convenient platform for some Internet functions such as NAT, usage monitoring, IPSEC VPNs</div>
</li>
</ul>
<p style="text-align:justify;">Basically, there are four types of firewall; they are packet filtering firewall, stateful inspection firewall, application-level gateway (application proxy) and circuit-level gateway. Besides that, throughout the lecture I have learnt about the firewall basing. The three types of firewall basing are bastion host, host-based firewall and personal firewall. The last topic for today lecture was about firewall locations.</p>
<p style="text-align:justify;">
<h2 style="text-align:justify;"><span style="text-decoration:underline;"><span style="color:#333399;">Lab session (15 Oct 09)</span></span></h2>
<p>Title of this lab is the password cracking for WEP. The tools needed for this lab were one wireless router which was accessed by several workstations. The workstations should be installed with Backtrack2. Backtrack2 is a very useful OS for hacking use. It was developed from Linux. It needs a lot of times for the cracking process. The more workstations we use, the fastest the cracking time. As the number of packets sent are directly proportional to the number of workstations available for the WLAN. I have learn some commands from for example, “-airmon-ng”, “-airodunm-ng”, “-aireplay-ng” and so on to perform this cracking. But finally we still couldn&#8217;t get the result due to limited time. <span style="color:#000000;"> </span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stacychiam.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stacychiam.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stacychiam.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stacychiam.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/stacychiam.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/stacychiam.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/stacychiam.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/stacychiam.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stacychiam.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stacychiam.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stacychiam.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stacychiam.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stacychiam.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stacychiam.wordpress.com/75/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=75&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://stacychiam.wordpress.com/2009/10/15/lecture14oct-lab15-oct/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a25f7b065464eb5f9209820e9ba7495c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stacychiam</media:title>
		</media:content>
	</item>
		<item>
		<title>Lecture@7 Oct &amp; Lab@8 Oct</title>
		<link>http://stacychiam.wordpress.com/2009/10/08/lecture7-oct-lab8-oct/</link>
		<comments>http://stacychiam.wordpress.com/2009/10/08/lecture7-oct-lab8-oct/#comments</comments>
		<pubDate>Thu, 08 Oct 2009 20:05:01 +0000</pubDate>
		<dc:creator>stacychiam</dc:creator>
				<category><![CDATA[Network & IT Security]]></category>

		<guid isPermaLink="false">http://stacychiam.wordpress.com/?p=71</guid>
		<description><![CDATA[Lecture session (7 Oct 09) Topis: Security in Networks The summary of this topic as below: 1. Encryption - Link to link Cover layer 1 and layer 2 of OSI model Decryption occurs just as the communication arrives at and receiving computer - End to end Provide security from one end of a transmission to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=71&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h2><span style="color:#993366;"><span style="text-decoration:underline;">Lecture session (7 Oct 09)</span></span></h2>
<h3><span style="color:#000000;">Topis: Security in Networks</span></h3>
<p>The summary of this topic as below:</p>
<p>1. Encryption</p>
<p>- Link to link</p>
<ul>
<li>Cover layer 1 and layer 2 of OSI model</li>
<li>Decryption occurs just as the communication arrives at and receiving computer</li>
</ul>
<p>- End to end</p>
<ul>
<li>Provide security from one end of a transmission to the other layer 6 or 7</li>
<li>Protect data on every layer</li>
</ul>
<p>2. Strong authentication</p>
<p>- one entity proves its identity to another by demonstrating knowledge of a secret known to be associated with that entity<br />
- also called ‘challenge-response’ authentication<br />
- use cryptographic mechanisms to protect message in protocol like integrity mechanism and digital signature.</p>
<p>3. IPSec, SSH,SSL</p>
<p>- IpSec</p>
<ul>
<li>Optional for IPv4 but mandatory for IPv6</li>
<li>Implemented in IP layer so affect all layer above it.</li>
<li>Provide authentication(AH) and encryption (ESP)</li>
</ul>
<p>- SSH</p>
<ul>
<li>Secure remote login</li>
</ul>
<p>- SSL</p>
<ul>
<li>Encrypt data over the transport layer</li>
</ul>
<p>4. Kerberos<br />
- Based on the idea that a central server provides authentication tokens (tickets) to request application.<br />
- A ticket is an unforgeable and nonreplayable.</p>
<p>5. Firewall<br />
- A network security device designed to restrict access to resources (information) according to security policy.<br />
- Installed between organization’s network and the internet.<br />
- Can filter traffic.</p>
<p>6. Intrusion Detection System<br />
- A device or software tools or hardware tools that monitor activity to identify malicious or suspicious events.<br />
- Two types of IDS which are signature based and anamoly based.</p>
<p>7. Honeypot<br />
- Decoy systems that are designed to lure a potential attacker away from critical systems.</p>
<p>After that, Mr. Zaki continue taught us the new topic known as “Security in Applications”. To understand this chapter, we have to know the securities in Email and Web. The securities in Email are SMIME and PGP; while the securities in Web are SSL, SSH, SET, HTTPS and SFTP.</p>
<p>1. SSL<br />
- Widely used in e-commerce.<br />
- Provide secure channel for sending credit card information, personal information.</p>
<p>2. SSH<br />
- Secure remote administration<br />
- Provide security at application layer</p>
<p>3. SET<br />
- Open encryption and security specification designed to protect credit card transaction on the internet.<br />
- Use SSL to secure communication links</p>
<p>4. HTTPS<br />
- A communications protocol designed to transfer encrypted information between computers over the World Wide Web.<br />
- Used to enable online purchasing.</p>
<p>5. SFTP<br />
- Performs all operations over an encrypted SSH transport.</p>
<p>At last, Mr.Zaki reminded us tomorrow is mid term exam&#8230;.T___T</p>
<h2><span style="color:#993366;"><span style="text-decoration:underline;">Lab Session (8 Oct 09)</span></span></h2>
<p>Today, we have our mid term exam during lab session. There are 4 question in this midterm exam and we are requested to answer 3 out of this 4 questions. Although this exam not really hard, but i knew i can do better if i spend more time to study&#8230;.haha!!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stacychiam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stacychiam.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stacychiam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stacychiam.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/stacychiam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/stacychiam.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/stacychiam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/stacychiam.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stacychiam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stacychiam.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stacychiam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stacychiam.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stacychiam.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stacychiam.wordpress.com/71/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=71&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://stacychiam.wordpress.com/2009/10/08/lecture7-oct-lab8-oct/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a25f7b065464eb5f9209820e9ba7495c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stacychiam</media:title>
		</media:content>
	</item>
		<item>
		<title>Lecture 30 Sept &amp; Lab 1 Oct</title>
		<link>http://stacychiam.wordpress.com/2009/10/01/lecture-30-sept-lab-1-oct/</link>
		<comments>http://stacychiam.wordpress.com/2009/10/01/lecture-30-sept-lab-1-oct/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 19:40:40 +0000</pubDate>
		<dc:creator>stacychiam</dc:creator>
				<category><![CDATA[Network & IT Security]]></category>

		<guid isPermaLink="false">http://stacychiam.wordpress.com/?p=67</guid>
		<description><![CDATA[Lecture (30 Sept 09) After came back from raya holiday, I&#8217;m so lazy to attend classes..haha! But at last i have to wake up and appear at BK 7 @ FTMK. Today&#8217;s topic is&#8230;&#8230;AUTHENTICATION &#38; ACCESS CONTROL. Authentication: Verification of identity of someone who generated some data and related to identity verification. Authentication divided to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=67&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h2 style="text-align:justify;"><span style="color:#800000;"><span style="text-decoration:underline;">Lecture (30 Sept 09)</span></span></h2>
<p style="text-align:justify;">After came back from raya holiday, I&#8217;m so lazy to attend classes..haha! But at last i have to wake up and appear at BK 7 @ FTMK. Today&#8217;s topic is&#8230;&#8230;AUTHENTICATION &amp; ACCESS CONTROL.</p>
<p style="text-align:justify;"><span style="color:#800080;"><strong><span style="text-decoration:underline;">Authentication</span></strong></span>: Verification of identity of someone who generated some data and related to identity verification. Authentication divided to 2 parts, i.e. <strong>password</strong> &amp; <strong>biometric</strong>.</p>
<p style="text-align:justify;">There are many ways to protect our password, such as don’t keep your password to anybody, don’t write or login your password at everywhere, Choose a good password and so on. Below are techniques for guessing passwords</p>
<ul>
<li>Try default passwords.</li>
<li>Try all short words, 1 to 3 characters long.</li>
<li>Try all the words in an electronic dictionary(60,000).</li>
<li>Collect information about the user’s hobbies, family names, birthday, etc.</li>
<li>Try user’s phone number, social security number, street address, etc.</li>
<li>Try all license plate numbers</li>
<li>Use a Trojan horse</li>
<li>Tap the line between a remote user and the host system.</li>
</ul>
<p style="text-align:justify;">Biometric is the measurement and statistical analysis of biological data. It identify by human&#8217;s <strong>Universality, Uniqueness, Stability, Collectability, Performance, Acceptability, Forge resistance. </strong>There are 2 types of biometric: Static and Dynamic.</p>
<p><strong><span style="color:#008000;">Static</span></strong></p>
<div>
<ul>
<li>Fingerprint recognition</li>
<li>Retinal scan</li>
<li>Iris scan</li>
<li>Hand geometry</li>
</ul>
</div>
<div><span style="color:#008000;"><strong>Dynamic</strong></span></div>
<ul>
<li>Signature recognition</li>
<li>Speaker recognition</li>
<li>Keystroke dynamics</li>
</ul>
<p style="text-align:justify;"><span style="text-decoration:underline;"><span style="color:#800080;"><strong>Access Control</strong></span></span>: The prevention of unauthorized use of a resource, including the prevention of use of a resource in an unauthorized manner. Access control have some requirement like reliable input, fine and coarse specification, least privilege etc. Access control can divide into three group which is access control matrix, access control list and Unix access control.  Access control list is a list of permission attached to an object. The list specifies who or what is allowed to access the object. Unix access control list is modern Unix support ACL. It can specify any number of additional users / groups and associated rwx permission.</p>
<p>At the end of lecture, En. Zaki told us next week will be our midterm exam during lab session&#8230;.T___T&#8230;</p>
<h2><span style="text-decoration:underline;"><span style="color:#800000;">Lab (1 Oct 09)<br />
</span></span></h2>
<p style="text-align:justify;"><span style="color:#800000;"><span style="color:#000000;">The topic of this lab is Security of Network. During lecture session, we knew that FTP and Telnet are not a secure way to remote or share files. The purpose of this lab is to prove that IPSec can protect our password, prevent to hack by hackers. </span></span></p>
<p style="text-align:justify;"><span style="color:#800000;"><span style="color:#000000;">At the beginning, I am still blurring and &#8220;facebooking&#8221;, and then i caught by Mr. Zaki, haha!! He recommended me to go through the lab manual. After that, i start doing the task. Firstly, i clone the Window server 2003 at VMWare to create 2 windows, one as server and another one as client. Next, i set the IP address so that both server and client are in the same LAN. Then, i start telnet to server and remote login by using FTP. Before that, i have start the WireShark to capture the packet have been sent while I&#8217;m telnet and doing FTP remote login. I can capture the username and password which i had enter to do telnet and FTP. The next task is to configure the IPSec at both sever and client. After the configuration, i couldn&#8217;t capture the username and password anymore. The protocol captured at Wireshark no longer is FTP, it became ESP.<br />
</span></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stacychiam.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stacychiam.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stacychiam.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stacychiam.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/stacychiam.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/stacychiam.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/stacychiam.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/stacychiam.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stacychiam.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stacychiam.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stacychiam.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stacychiam.wordpress.com/67/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stacychiam.wordpress.com/67/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stacychiam.wordpress.com/67/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=67&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://stacychiam.wordpress.com/2009/10/01/lecture-30-sept-lab-1-oct/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a25f7b065464eb5f9209820e9ba7495c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stacychiam</media:title>
		</media:content>
	</item>
		<item>
		<title>Lecture &amp; Lab @ 9 &amp; 10 Sept 2009</title>
		<link>http://stacychiam.wordpress.com/2009/09/10/lecture-lab-9-10-sept-2009/</link>
		<comments>http://stacychiam.wordpress.com/2009/09/10/lecture-lab-9-10-sept-2009/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 11:22:48 +0000</pubDate>
		<dc:creator>stacychiam</dc:creator>
				<category><![CDATA[Network & IT Security]]></category>

		<guid isPermaLink="false">http://stacychiam.wordpress.com/?p=50</guid>
		<description><![CDATA[Lecture (09-09-09) Lecture time again&#8230;. Finally we are in chapter 4 now&#8230;topic of this chapter is Program Security. It is about the vulnerability and VIRUSES&#8230;.haha!! Those want to know more about viruses please read my blog&#8230;wakakaka!! I know most of the computer users hate viruses!! So do i&#8230; From this chapter, we learn vulnerability, means [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=50&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3><span style="text-decoration:underline;">Lecture (09-09-09)</span></h3>
<p><span style="color:#808080;"><strong>Lecture time again&#8230;.</strong></span></p>
<p>Finally we are in chapter 4 now&#8230;topic of this chapter is Program Security. It is about the vulnerability and <span style="color:#ff0000;"><strong>VIRUSES</strong></span>&#8230;.haha!! Those want to know more about viruses please read my blog&#8230;wakakaka!! I know most of the computer users hate viruses!! So do i&#8230;</p>
<p>From this chapter, we learn vulnerability, means a software weakness that can be exploited by an attacker. Bugs and flows collectively form the basis of the most software vulnerability. most commonly known tracking faults from developers are requirements, design and code inspections. Vulnerability and flaws do not map to faults and failures.</p>
<p><em><strong><span style="color:#993300;">Types of flaws</span></strong></em></p>
<ul>
<li>validation error</li>
<li>domain error</li>
<li>serialization and aliasing</li>
<li>inadequate identification and authentication</li>
<li>boundary condition violation</li>
<li>other exploitable logic errors</li>
</ul>
<p><strong><em><span style="color:#993300;">Nonmalicious Program Errors</span></em></strong></p>
<ul>
<li>Buffer Overflows</li>
<li>Incomplete mediation – data exposed or uncontrolled</li>
<li>Time of check to Time of used</li>
</ul>
<p><span style="color:#993300;"><em><strong>Virus and other malicious code</strong></em></span></p>
<p>Malicious code can do harm.  The damage can be in the form of modification/destruction, stolen data, unauthorized access, damage on system or other forms not intended by users.  Malicious program has 2 types: need host program and independent. Examples of malicious codes are trojan horse, virus, worm, bacteria, logic bomb, spyware and trapdoor.</p>
<p>Next, we learn about the differences of viruses, worms and trapdoors &amp; salami attack.</p>
<p><em><strong><span style="color:#993300;">Pillar of software security</span></strong></em></p>
<ul>
<li>Risk management</li>
<li>touchpoints</li>
<li>knowledge.</li>
</ul>
<h3><span style="text-decoration:underline;">Lab (10-09-09)</span></h3>
<p>During this lab, we learned to use the OWASP.  The Open Web Application Security Project (OWASP) is an open community that focuses on improving the security of<br />
application software. At last, we failed to complete this lab exercise due to some unknown problem&#8230;hahaha&#8230;maybe is my own problem. Although we failed it, but it is still quite interesting lab ^o^</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stacychiam.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stacychiam.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stacychiam.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stacychiam.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/stacychiam.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/stacychiam.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/stacychiam.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/stacychiam.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stacychiam.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stacychiam.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stacychiam.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stacychiam.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stacychiam.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stacychiam.wordpress.com/50/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=50&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://stacychiam.wordpress.com/2009/09/10/lecture-lab-9-10-sept-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a25f7b065464eb5f9209820e9ba7495c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stacychiam</media:title>
		</media:content>
	</item>
		<item>
		<title>2 &amp; 3 Sept 2009</title>
		<link>http://stacychiam.wordpress.com/2009/09/03/2-3-sept-2009/</link>
		<comments>http://stacychiam.wordpress.com/2009/09/03/2-3-sept-2009/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 11:22:02 +0000</pubDate>
		<dc:creator>stacychiam</dc:creator>
				<category><![CDATA[Network & IT Security]]></category>

		<guid isPermaLink="false">http://stacychiam.wordpress.com/?p=52</guid>
		<description><![CDATA[Lecture and lab of this week canceled again&#8230;.wahahahahaha!!! Are this good or bad news to me?? Hmm&#8230;only god knows&#8230;<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=52&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong><span style="color:#000080;">Lecture and lab of this week canceled again&#8230;.wahahahahaha!!! Are this good or bad news to me?? Hmm&#8230;only god knows&#8230;</span></strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stacychiam.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stacychiam.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stacychiam.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stacychiam.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/stacychiam.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/stacychiam.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/stacychiam.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/stacychiam.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stacychiam.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stacychiam.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stacychiam.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stacychiam.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stacychiam.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stacychiam.wordpress.com/52/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=52&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://stacychiam.wordpress.com/2009/09/03/2-3-sept-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a25f7b065464eb5f9209820e9ba7495c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stacychiam</media:title>
		</media:content>
	</item>
		<item>
		<title>- 26 Aug &amp; 27 Aug -</title>
		<link>http://stacychiam.wordpress.com/2009/08/27/6th-lecture-lab/</link>
		<comments>http://stacychiam.wordpress.com/2009/08/27/6th-lecture-lab/#comments</comments>
		<pubDate>Thu, 27 Aug 2009 10:33:41 +0000</pubDate>
		<dc:creator>stacychiam</dc:creator>
				<category><![CDATA[Network & IT Security]]></category>

		<guid isPermaLink="false">http://stacychiam.wordpress.com/?p=46</guid>
		<description><![CDATA[Lecture (26-8-09) Continue of chapter 3 modern Cryptography&#8230;.. After DES, AES and so on, this time we know about hash Functions, Digital Signature, Certificate Authority (CA), Public Key Infrastructure (PKI), RSA &#38; method of attack. Below are some details about each modern cryptography&#8230;.u can go through it only if u don&#8217;t feel sleepy&#8230;hehe ^o^ -Hash [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=46&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3><span style="text-decoration:underline;">Lecture (26-8-09)</span></h3>
<h4><span style="color:#666699;">Continue of chapter 3 modern Cryptography&#8230;..</span></h4>
<p>After DES, AES and so on, this time we know about hash Functions, Digital Signature, Certificate Authority (CA), Public Key Infrastructure (PKI), RSA &amp; method of attack.</p>
<p>Below are some details about each modern cryptography&#8230;.<span style="color:#c10000;">u can go through it only if u don&#8217;t feel sleepy&#8230;hehe ^o^</span></p>
<h4><span style="color:#800080;">-Hash Function-</span></h4>
<ul>
<li>a well-defined procedures or mathematical function that converts any size of data into a fixed-length output.</li>
<li><span style="color:#000080;"><strong>Simple Hash Function</strong></span>: It is used in message authentication and digital signatures.  All hash functions process input a block at a time in an iterative fashion.  One of the simplest Hash Functions is bit-by-bit exclusive-OR (XOR) of each block.</li>
<li><strong><span style="color:#000080;">MD5</span></strong>: produces 128-bit of output.  But, people discovered that there are weaknesses of using this algorithm.  So, SHA-1 was recommended.</li>
<li><strong><span style="color:#000080;">SHA-1</span></strong>: this algorithm was designed to be used with the Digital Signature Standard (DSS).  It produces a 160-bit MAC.</li>
<li>For SHA-1 and SHA-256, each message blocks has 512 bits, which are represented as a sequence of 16 32-bit words. SHA-256 uses 6 logical functions where each function operates on 32-bit words.</li>
</ul>
<h4><span style="color:#800080;">-Digital Signature-</span></h4>
<ul>
<li>It is the provision of a means of settling disputes between sender and receiver that distinguishes the digital signature mechanism from the MACing process.</li>
<li>A valid digital signature gives a recipient reason to believe that the message was created by a known sender, and that it was not altered in transit. Digital signatures are commonly used for software distribution, financial transactions, and in other cases where it is important to detect forgery and tampering.</li>
<li>Reasons of applying Digital Signature : authentication and integrity.</li>
</ul>
<h4><span style="color:#800080;">-Certificate Authority (CA)-</span></h4>
<ul>
<li>to guarantee the authenticity of public keys.</li>
<li>Method: signing a cert. containing user’s identity and public key with its secret keys.</li>
<li>Requirement: all users must have an authentic copy of the CA’s public key.</li>
<li>Example of CA in Malaysia: Digicert.</li>
</ul>
<h4><span style="color:#800080;">-Public Key Infrastructure (PKI)-</span></h4>
<ul>
<li>It is introduced to facilitate the public key cryptography.</li>
<li>Players in PKI system: certificate owner, CA, relying party, Registration Authority (RA), Validation Authority (VA)</li>
</ul>
<h4><span style="color:#800080;">-Methods of attack-</span></h4>
<ul>
<li><span style="color:#000080;"><strong>General attacks</strong></span> that can be performed against encrypted info: ciphertext-only attack, known plaintext, chosen-plaintext, chosen-ciphertext attack</li>
<li><span style="color:#000080;"><strong>Specific attacks</strong></span> against encryption systems: Brute-Force attack, Replay attacks, man-in-the-middle attacks, fault in cryptosystem.</li>
</ul>
<h3><span style="text-decoration:underline;">Lab (27-8-09)</span></h3>
<p>We practiced how complex of the DES during this lab session. DES works by encrypting groups of 64 message bits, which is the same as 16 hexadecimal numbers. To do the encryption, DES uses “keys” where are also 64 bits long. However, every 8th key bit is ignored in the DES algorithm, so that the effective key size is 56. The Plaintext and the Key will undergo 16 rounds of expansion, substitution, key mixing and permutation process.</p>
<p><strong>After all, we end this lab with spinning head&#8230;.-faint-</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stacychiam.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stacychiam.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stacychiam.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stacychiam.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/stacychiam.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/stacychiam.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/stacychiam.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/stacychiam.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stacychiam.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stacychiam.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stacychiam.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stacychiam.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stacychiam.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stacychiam.wordpress.com/46/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=46&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://stacychiam.wordpress.com/2009/08/27/6th-lecture-lab/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a25f7b065464eb5f9209820e9ba7495c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stacychiam</media:title>
		</media:content>
	</item>
		<item>
		<title>19 &amp; 20 Aug 2009</title>
		<link>http://stacychiam.wordpress.com/2009/08/20/the-5th-lecture-lab/</link>
		<comments>http://stacychiam.wordpress.com/2009/08/20/the-5th-lecture-lab/#comments</comments>
		<pubDate>Thu, 20 Aug 2009 08:43:52 +0000</pubDate>
		<dc:creator>stacychiam</dc:creator>
				<category><![CDATA[Network & IT Security]]></category>

		<guid isPermaLink="false">http://stacychiam.wordpress.com/?p=44</guid>
		<description><![CDATA[Lecture and lab of this week was canceled&#8230;i felt so sad&#8230; BUT&#8230; Huraay~~!!!!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=44&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Lecture and lab of this week was canceled&#8230;i felt so sad&#8230;</p>
<p>BUT&#8230;</p>
<p>Huraay~~!!!!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stacychiam.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stacychiam.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stacychiam.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stacychiam.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/stacychiam.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/stacychiam.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/stacychiam.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/stacychiam.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stacychiam.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stacychiam.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stacychiam.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stacychiam.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stacychiam.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stacychiam.wordpress.com/44/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=44&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://stacychiam.wordpress.com/2009/08/20/the-5th-lecture-lab/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a25f7b065464eb5f9209820e9ba7495c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stacychiam</media:title>
		</media:content>
	</item>
		<item>
		<title>* 4th Lecture &amp; Lab *</title>
		<link>http://stacychiam.wordpress.com/2009/08/13/4th-lecture-lab/</link>
		<comments>http://stacychiam.wordpress.com/2009/08/13/4th-lecture-lab/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 08:00:31 +0000</pubDate>
		<dc:creator>stacychiam</dc:creator>
				<category><![CDATA[Network & IT Security]]></category>

		<guid isPermaLink="false">http://stacychiam.wordpress.com/?p=40</guid>
		<description><![CDATA[Lecture session (12 Aug 2009) Here come the chapter 3 for this lecture time&#8230;that is Modern Cryptography. Sounds like very interesting right?? Ya, you&#8217;re right!! It&#8217;s really interesting and extremely difficult (for me)&#8230;haha!! i just hope that i could catch up all things that been teach by En. Zaki. First,we know that most of the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=40&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h3><span style="color:#800000;"><span style="text-decoration:underline;">Lecture session (12 Aug 2009)</span></span></h3>
<p style="text-align:justify;"><span style="color:#003366;">Here come the chapter 3 for this lecture time&#8230;that is Modern Cryptography. Sounds like very interesting right?? Ya, you&#8217;re right!! It&#8217;s really interesting and extremely difficult (for me)&#8230;haha!! i just hope that i could catch up all things that been teach by En. Zaki. </span></p>
<p style="text-align:justify;"><span style="color:#003366;">First,we know that most of the modern cipher use bits, i.e. 0s &amp; 1s, to represent the plain text which will be encrypted into cipher text (in bits). Commonly, modern cryptography algorithm can categorize to 2 types:</span></p>
<p style="text-align:justify;"><span style="color:#003366;">a) Stream cipher &#8211; convert 1 symbol of plain text immediately into a symbol of cipher text.</span></p>
<p style="text-align:justify;"><span style="color:#003366;">b) Block cipher &#8211; encrypt a group of plain text as a block.</span></p>
<p style="text-align:justify;"><span style="color:#003366;">After that, we learn about Data Encryption Standard (DES) which is super duper complicated processes. Yet, with today&#8217;s high technology, this DES was break by Brute Force Attack. Therefore, an improvement was introduced, that is triple DES. </span></p>
<p style="text-align:justify;"><span style="color:#003366;">At this time, we all are spinning with the DES super hard processes. Then En. Zaki show us the PDF file of DES, it made all of us felt like our brains are going to explode. Luckily En.Zaki could understand our feeling and explain the Advanced Encryption Standard (AES) by using flash. This made us easier to understand AES. Maybe we can ask BITM students to make some flash for us&#8230;wahahaha!!</span></p>
<p style="text-align:justify;">
<h3 style="text-align:justify;"><span style="color:#800000;"><span style="text-decoration:underline;">Lab session (13 Aug 2009)</span></span></h3>
<p style="text-align:justify;"><span style="color:#003366;">During this lab, En. Zaki teach us about Digital Signature, Hash Function and RSA.  Then, we do some exercises about RSA algorithm.  RSA algorithm can be used to implement private and public key.</span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stacychiam.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stacychiam.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stacychiam.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stacychiam.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/stacychiam.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/stacychiam.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/stacychiam.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/stacychiam.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stacychiam.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stacychiam.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stacychiam.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stacychiam.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stacychiam.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stacychiam.wordpress.com/40/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=40&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://stacychiam.wordpress.com/2009/08/13/4th-lecture-lab/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a25f7b065464eb5f9209820e9ba7495c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stacychiam</media:title>
		</media:content>
	</item>
		<item>
		<title>The 3rd lecture &amp; lab&#8230;</title>
		<link>http://stacychiam.wordpress.com/2009/07/30/the-3rd-lecture-lab/</link>
		<comments>http://stacychiam.wordpress.com/2009/07/30/the-3rd-lecture-lab/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 09:03:53 +0000</pubDate>
		<dc:creator>stacychiam</dc:creator>
				<category><![CDATA[Network & IT Security]]></category>

		<guid isPermaLink="false">http://stacychiam.wordpress.com/?p=31</guid>
		<description><![CDATA[Today, we learn more about the Caesar cipher&#8230;more secure Caesar cipher. Lecture (29 July 2009) Instead of shift the alphabet, shuffle the alphabet arbitrarily is more secure. It means each plain text letter maps to a different random cipher text letter.For a Simple Substitution Ciphers (Monoalphabetic ciphers), we write alphabet in a randomly chosen order [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=31&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:justify;">Today, we learn more about the Caesar cipher&#8230;more secure Caesar cipher.</p>
<h3 style="text-align:justify;"><span style="text-decoration:underline;">Lecture (29 July 2009)</span></h3>
<p style="text-align:justify;">Instead of shift the alphabet, shuffle the alphabet arbitrarily is more secure. It means each plain text letter maps to a different random cipher text letter.For a Simple Substitution Ciphers (Monoalphabetic ciphers), we write alphabet in a randomly chosen order underneath the alphabet written in strict alphabetic order. The number keys for a Simple Substitution Cipher is equal to the number of ways in which the 26 letters of alphabet can be arranged, i.e. 26 factorial (26!). Having large number of keys is certainly <strong>no guarantee</strong> that the cipher system is strong enough.</p>
<p style="text-align:justify;">
<p style="text-align:justify;">Human language are <strong>REDUNDANT</strong>. The letters are not equally used. In English, <strong>E </strong>is the most common letter then followed by <strong>T, R, N, I, O, A, S. </strong></p>
<p style="text-align:justify;"><strong> </strong></p>
<div id="attachment_36" class="wp-caption aligncenter" style="width: 509px"><strong><strong><img class="size-full wp-image-36" title="English Letter Frequencies" src="http://stacychiam.files.wordpress.com/2009/08/11.jpg?w=495" alt="English Letter Frequencies"   /></strong></strong><p class="wp-caption-text">English Letter Frequencies</p></div>
<p><strong> </strong></p>
<p style="text-align:justify;"><strong> </strong></p>
<p style="text-align:justify;"><strong> </strong>The <strong>Vigenère Cipher</strong> (the best known of the manual polyalphabetic cipher) uses a Vigenère Square to perform encryption. This cipher was secure from about 1553 till 1854. The primary weakness of the Vigenère Cipher is the repeating if its key.</p>
<p style="text-align:justify;">
<div class="mceTemp mceIEcenter" style="text-align:justify;">
<dl class="wp-caption aligncenter">
<dt class="wp-caption-dt"><img class="size-full wp-image-33" title="Vigenere Tableau" src="http://stacychiam.files.wordpress.com/2009/08/2.jpg?w=495" alt="Vigenere Tableau"   /></dt>
<dd class="wp-caption-dd">Vigenere Tableau</dd>
</dl>
</div>
<h3 style="text-align:justify;"><span style="text-decoration:underline;">Lab (30 july 2009)</span></h3>
<p style="text-align:justify;">During lab session, we practiced how to encrypt and decrypt Caesar cipher &amp; Vigenère cipher.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/stacychiam.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/stacychiam.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/stacychiam.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/stacychiam.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/stacychiam.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/stacychiam.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/stacychiam.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/stacychiam.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/stacychiam.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/stacychiam.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/stacychiam.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/stacychiam.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/stacychiam.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/stacychiam.wordpress.com/31/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=stacychiam.wordpress.com&amp;blog=8601746&amp;post=31&amp;subd=stacychiam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://stacychiam.wordpress.com/2009/07/30/the-3rd-lecture-lab/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a25f7b065464eb5f9209820e9ba7495c?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">stacychiam</media:title>
		</media:content>

		<media:content url="http://stacychiam.files.wordpress.com/2009/08/11.jpg" medium="image">
			<media:title type="html">English Letter Frequencies</media:title>
		</media:content>

		<media:content url="http://stacychiam.files.wordpress.com/2009/08/2.jpg" medium="image">
			<media:title type="html">Vigenere Tableau</media:title>
		</media:content>
	</item>
	</channel>
</rss>
