Showing posts with label Internet. Show all posts
Showing posts with label Internet. Show all posts

Tuesday, August 23, 2016

Cyber Security: What is the Internet?

The internet is not a single entity with a single owner; instead it comprises a hierarchy of individual networks that have been connected to one another. These networks range from local area networks (LANs) that can be found in many businesses and universities to the telephone and data networks that link cities and countries by fibre optic cables and satellite links.

 Cisco Security and Virtual Private Network (VPN) courses   Implementing Cisco Threat Control Solutions (SITCS) v1.0 e-learning course   New Skills, New You: Transform your career in 2016 with Coursera

A definition often used is that the internet is a network of networks. Two key factors in the design of the internet were:
  • The network would not have a central controlling computer. Each computer on the network would be assumed to have the same authority as every other computer.
  • The network should be able to deliver information between any two computers on the network even if some of the machines in the network had failed (or given its Cold War origins, been blown to pieces). There would be a large number of alternative routes through the network, so it was not necessary for information to travel by the most direct route, instead it could travel in a roundabout route, avoiding the damaged parts of the network.
April2516-25off-sitewide640x480

Cyber Security: What is the Internet?

The internet is not a single entity with a single owner; instead it comprises a hierarchy of individual networks that have been connected to one another. These networks range from local area networks (LANs) that can be found in many businesses and universities to the telephone and data networks that link cities and countries by fibre optic cables and satellite links.

 Cisco Security and Virtual Private Network (VPN) courses   Implementing Cisco Threat Control Solutions (SITCS) v1.0 e-learning course   New Skills, New You: Transform your career in 2016 with Coursera

A definition often used is that the internet is a network of networks. Two key factors in the design of the internet were:
  • The network would not have a central controlling computer. Each computer on the network would be assumed to have the same authority as every other computer.
  • The network should be able to deliver information between any two computers on the network even if some of the machines in the network had failed (or given its Cold War origins, been blown to pieces). There would be a large number of alternative routes through the network, so it was not necessary for information to travel by the most direct route, instead it could travel in a roundabout route, avoiding the damaged parts of the network.

Wednesday, May 18, 2016

Cyber Conflicts: Internet Infrastructure

button
Greetings, so let us first understand what the Internet infrastructure looks like. The reason you need to understand this is because a lot of the issues of the Internet today are based on its basic architecture. Things like security, cyber crime, anonymity, censorship. Once we understand the infrastructure better, it will help you understand the basic cause and the origin of a lot of the issues that we have on the Internet and a lot of conflicts that we have.

Business Analytics from the Wharton School So what is Internet? The Internet really is a network of networks. We had a lot of networks before and all of them got connected into a gigantic network through backbones. And that is called the Internet today. So it is basically a collection of thousands of interconnected devices which allow for communication among millions of devices and people around the world.
Pimsleur All Languages Blue 125x125button The Internet is thus a collection of networks and means of communication for individual machines to send and receive data amongst each other.  And communication over the Internet happens by a process called packet-switching. Which is in contrast to something we called circuit-switching, which has been used for many, many, many years in telecommunications, such as with the telephones.

So what is the difference?
Testive
In circuit-switching the communication is happening through a dedicated connection between two points. Again, it could be any medium. It could be a wire, it could be wireless. It could be any medium at all. However, whatever bandwidth you have is dedicated.
ed2go Online Education Generic Bannerbutton
So you may have been familiar with the image of telephone operators managing switchboards and phone plugs. This was necessary because the connection was made by creating a dedicated connection between two devices of the communication.
Now let's contrast this with packet-switching. What happens in this case? You take a large message, you break it down into small pieces or packets, and you basically release them on the Internet. They basically hop from place to place of the sender and only the listed destination of the receiver. They can take any of different paths that come on their way.

The packet has the smallest unit or the amount of data that can be interpreted. The smallest sequence of zeroes and one that the Internet communication will understand.

Pearson Education (InformIT)
If you're sending an email from one computer to somebody, received at the other computer, the email is broken down into several packets. Each packet has a piece of email. The packet travels through the network separately and then re-assembled at the other end and composed back into the email. So again, at the sender's side, they're broken into pieces and reassembled on the receiver's side.

And when the packets travel they don't have to go through any dedicated path. They go through different paths wherever they have the least resistance. Whatever the protocols tell them and they take a different journey and they may it to the same destination. And once they get to the final destination, then again they're the same message that appeared initially okay. The connection and communication through the Internet uses standard protocols.

Why does it use standard protocols? Because by standardizing the protocols they're able to manage the complexity.

And what is a protocol? It's just like a language, it establishes rules for the computers to understand and rules that device makers must follow for them to be compatible with the Internet.

So, as we strive to understand what these protocols mean, we need to make sure that we know that the standard protocols for the Internet is the TCP/IP. Which is basically implemented in all the devices that are connected to the Internet.

It can be any device, a desktop computer, a laptop, it could be a smartphone. And all of them have very similar processes and similar protocols which they are able to connect to the Internet.

Now, the connection to the Internet requires a particular kind of hardware that can support communication with the Internet Protocol. The Internet Protocol is a set of protocols suite called a TCP/IP suite. Which is again a set of instructions on how data is to be sent and interpreted by communicating devices in the Internet. And one of the main components of IPs in the addressing scheme.
The Heart of the Matter course
Why do we need the addressing scheme? Because each device that is connected to the Internet has a unique address for information to travel from one place to another. It goes from one address to another address, just like a postal address.

And if you're looking at the framework of the Internet, the format of each unique address is called the IP address. The IP address is simply a number, like a phone number and it is structured in a format which is called a dotted decimal notation which is like 169.226.221.9. Now again, this is a short form for a 32-bit binary number broken down into four 8-bit segments. Now since we are running out of addresses, a new version of hybrid addresses with a high number of possible addresses has been in deployment since 2006. It's called the IPv-6.

April2516-25off-sitewide468x60
Since IP addresses are difficult to remember, an alternate naming system, called the domain name system (DNS) has been developed. This system allows each device to have a unique mnemonic address such as amazon.com or dating.com instead of a number like 72.21.214.144. The domains name system allows for organizational computers to translate the dotted decimal number into the real domain name. So, the domain name system is essentially a database that stores the phone numbers, the IP address of each computer and the domain name and allows people to translate back and forth. For instance amazon.com is 72.21.214.144, the database also stores the hierarchy or how the levels of the naming system are organized. That makes it easy to navigate and easy to search and find.

Sunday, September 6, 2015

Cyber101x Cyberwar, Surveillance and Security - Week 1 - How Internet Works

How Internet Works

    MELISSA DE ZWART: Let's begin with what    makes the internet special, for it    is special-- possibly the most important invention    of modern times.    For the 42% of the world's population connected    to the internet in 2014, it has changed the way    in which they communicate, transact, access education    and information, and yet what is so unique and so radical    about this technology is that it belongs to and is controlled    by no-one-- at least in theory.    In theory, the internet relies upon voluntary adherence    to technical protocols and nothing more.    It is a network of volunteers passing along packets    of information, so when the time comes you will pass along    packets for them, but this utopian open internet    is being threatened by governments and corporations    worldwide who seek regulation, control, accountability,    and profits.    Key elements of the internet remain in the hands    of the US government.    For example, the domain name system    through its dominance over key internet bodies, ICANN--    Internet Corporation for Assigned Names and Numbers--    the body that allocates domain names    and controls approval of new domains;    and IANA-- Internet Assigned Numbers Authority-- the body    that allocates IP addresses and manages the data    maintained in the root servers at the heart of the domain name    system, enabling us to find one another on the internet.    ICANN is a non-profit incorporated body    under the laws of California.    This was a compromise reached in 1998    when the US-centric nature of domain name allocation    became the focus of dispute between Europe and the United    States at that time.    Other countries control the network connections    in and out of their jurisdiction in order    to monitor and to restrict content.    The internet evolved as an open-ended, collaborative    platform, despite the fact that much of the initial work    was undertaken using US Department of Defense funding.    Internet communication was made to operate    in a decentralised mode as distinct    from the traditional hub and spoke model of telephony.    This meant that if any part of the network was down,    the traffic could be re-routed via another route.    This model, of course, has meant that there    is an absence of centralised control, or a choke-point,    making the internet difficult-- although not    impossible-- to control from a central point.    See the Great Firewall of China.    Control over the backbone means control over access.    The beauty of this design means that the network is essentially    dumb, meaning the intelligence and applications are built    on at the endpoint, and this has created the innovative    and openness of the internet and distinguishes it from    proprietary and closed networks where the intelligence is    hosted and controlled in the centre of the network.    In the late 1960s, the US Advanced Research Projects    Agency funded research into an experimental computer network    designed to facilitate communication    between remote sites, even in the event    of parts of the line being destroyed in a nuclear attack.    This meant that the system was not the typical hub    and spoke model of telecommunications,    with all messages being routed through one central exchange,    but rather designed to send the message by whatever    means possible, re-routing messages through a series    of unpredictable links.    Although indirect, the system was    effective and hopefully robust.    This network, originally known as ARPANET was configured    to enable communication between different types of computers    --at this stage, all large mainframes    on university campuses or military bases--    to allow new modules to be added or deleted    and to continue to operate in the event    that any part of the line was damaged,    destroyed, or captured.    During the 1970s, the US government,    largely through military funding,    encouraged the expansion of academic users    on the internet to test its capabilities    and expand its uses.    It was used as a forum for the exchange of ideas, opinions,    and information, and particularly allowing    the collaboration of users at remote locations.    Over time, the military network was separated    from the general internet.    By the early 1990s, there was growing interest    in the commercial applications of the internet,    and commercial users were admitted    as paying users of the backbone lines established    by the National Science Foundation.    The National Science Foundation's acceptable use    policy prohibited commercial use of the internet until 1991.    It was anarchic, unstructured, and used largely    by enthusiasts with no need for guidelines, rules,    or regulations.    Private use of the internet was offered by commercial providers    in a walled garden model.    Internet service providers, such as CompuServe,    only connected mutual subscribers    and provided content managed by CompuServe, excluding access    to content offered by other service providers.    Three events which drastically altered    the nature of the internet occurred in 1991 and 1992.    First, the World Wide Web Protocol    was developed and publicly released    by Tim Berners-Lee from CERN.    Second, the Mosaic browser-- later    called Netscape Navigator-- facilitating search of the web    was developed.    And third, US Congress passed a bill    permitting commercial activity on the internet.    The development of the web effectively    destroyed the walled garden model,    although new models of walled gardens are now emerging.    From this point on, the US government policy,    and that of many governments worldwide,    was to enable the private sector to drive the development    of internet related technology.

How we use the Internet
    MELISSA DE ZWART: When most people    think about using an online service,        they tend to generalise it as navigating or surfing    the World Wide Web.    While a lot of the content we consume is found on web pages    that we access through web browsers,    the World Wide Web is just one available service    on the internet.    The internet, as the name suggests,    is a series of interconnected computer networks that    carry a large amount of information    for a number of network services,    including email, internet, phone, audio, video, games,    file transfers, and most notably, the World Wide Web.    The web is a collection of interconnected documents,    or web pages, and other web resources    linked by hyperlinks and URLs.    Hypertext Transfer Protocol, or HTTP,    is the language used on the web for information transfer,    yet it is just one of many languages or protocols    that can be used for communication on the internet.    Protocols could be described as languages, or alternatively,    sets of rules for computers.    If two computers obey these rules,    they will be able to understand each other and communicate.    The two primary protocols by which    communication is effected between computers    on the internet are the Internet Protocol, IP,    and the Transmission Control Protocol, TCP.    Other common protocols, or languages,    include SMTP (email), FTP (file transfer), VOIP (voice),    and BitTorrent (peer to peer file sharing).    Data that is sent by Internet Protocol    is packetised, that is, broken up in to small packets    and then sent by means of the IP.    Each packet contains a header-- akin to an envelope--    containing information identifying the address    or location from which the packet is sent    and to which the packet is to be sent.    The packet itself contains the data,    which is akin to the letter within an envelope.    The Internet Protocol communicates information    between computers by means of allocating IP addresses    to the sending and receiving computers, and then sending    the packets of data from one address to another.    In most situations, packets of data    are not sent directly from one location to another.    Largely because each computer on the internet    is not connected directly to every other computer    on the internet.    Rather, each computer is linked to other computers,    which are then in turn connected to other computers and so on.    This fundamental exchange of information    has enabled and increased human interactions    through the availability or instant    messaging, internet forums, and social networking.    Online shopping has exploded as a result of convenience    and ability to carry out financial transactions online,    and mobile technology continues to advance    at a staggering pace.    The internet has become such a large part of our lives    that we tend to expect our everyday items to be smarter    as a result.    Whilst this offers further convenience,    we often don't consider that all smart products    are part of the internet.    This has given rise to the internet of things, which    extends to anything that can communicate or receive    information.    Devices we use every day, like our smart phones,    cars that send data to their manufacturers, security    devices, smart TVs, refrigerators,    and even implanted heart monitoring devices    send and receive information constantly.    Used in the right way, this information    can reveal a great deal about who we are, what we do,    say, think, and feel, but we aren't the only ones    with access to this information, and in this course    we will be considering the implications of who else    might have access to your data.    

Cyber101x Cyberwar, Surveillance and Security - Week 1 - The New Internet

CONCEALING YOUR IDENTITY ON THE INTERNET
 

 BRUCE SCHNEIER: The old saying is that on the internet, nobody knows you're a dog. And these days, it's more like, on the internet, everyone knows exactly what kind of dog you are. It is becoming harder to change your identity. And if you're a woman, to have a male name and maybe be taken more seriously. Or if you're a member of a minority to use a more common name and be treated differently. That's incredibly valuable. Even taking an alias to explore a different aspect of yourself. If you're joining a support group at some time, you might not want to use your real name. This is becoming harder. It's incredibly important. We know that being able to shed the baggage of your identity, especially if you are from a minority class, is incredibly empowering. And that's something we shouldn't give up lightly.

HOW WE GIVE UP METADATA

  BRUCE SCHNEIER: I mean, certainly, we give up metadata continuously willingly on our computers, on our phones. And every device we use these days is producing data and metadata sitting as the cloud. And in some ways, yes, we do it willingly. We accept Facebook, which is collecting enormous data and metadata about us, for free in exchange for that. Now you can argue that we're doing that as consumers willingly, but I'm not sure we're really doing it informed. I'm not convinced that we think in the morning, you know, I'm really happy my phone company is tracking my location 24/7 and maybe sharing that data with the government, because I love getting cell phone calls. We just think, I need my cell phone. So a lot of this data and metadata collection is hidden. It's not salient. We're not really thinking about it as it happens. So even though we're doing it willingly, I'm not convinced there's informed consent going on. I think that most of us believe, at some level, that we're maintaining our privacy. That if I go off and sneak around the corner, I'm thinking I'm sneaking around the corner. I don't think, well, the jig is up, because Apple knows where I am.

SOCIAL NORMS AND KIDS MAINTAINING PRIVACY

 BRUCE SCHNEIER: It's interesting to see how social norms change. We are seeing changes that for now for kids, it's public by default private by effort. Kids still value privacy enormously. And if you're a teenager or know a teenager, you know that's true. Privacy from their peers, their teachers, their parents, they don't think about the government, but they certainly think about privacy. And kids spend a lot of effort trying to maintain their privacy. Whether it's using apps like Snapchat that delete things, or scraping their Facebook wall or using aliases, kids take a lot of pains to keep their privacy. They may not be sophisticated. They might not be able to maintain privacy against the government or foreign governments, but they are trying to maintain privacy. Even though it's harder, even though public is more of a default, privacy is an inherent human need. So I think we are in the middle of some profound social changes, but we're not going to move to a world where kids say oh I never had any privacy.

Cyber101x Cyberwar, Surveillance and Security - Week 1 - Structure and Governance

THE FUTURE OF THE INTERNET
 

  JONATHAN ZITTRAIN: It can be hard to talk about what we stand to lose if the internet and its surrounding technologies get a lot more rational, get a lot more cash-and-carry -- the way that so many other sectors of our economy that are thriving are -- but nonetheless, I think we have great risks at stake. And one of the best ways to understand it is to look back at some of the technologies that have been the most successful and ask how successful they might have been if there hadn't been an absence of gate-keeping that allowed them to thrive. So one example that may be a cautionary tale is something like Napster or peer-to-peer networking. That's the kind of thing that when a college undergraduate in Boston invented Napster and started sending the code around-- and the code was not that much rocket science. It was just, here's a way of putting files in a directory in your computer that you're willing to share with others. You are making them available for people to copy. It's like the essence of the internet from way back-- share some files, share some data. This of course focused on data that was music, files ending in MP3, and it completely undermined the prevailing business model of the music industry. You can see the music executives at the time were like, we don't get it. How is this allowed? Why isn't this being banned, it is surely illegal. And years of litigation still didn't substantially alter the fact that that kind of networking was greatly desired by a lot of people. They were willing to engage in it. Now again, this might be a cautionary tale. In a corporatised net that would never have gotten out of the gate. It also means that the kinds of pressures that brought about Spotify and other elements of the music industry, well they now see music as a service and something that you might pay a modest amount per month to have, or to get out of the kind of 15 US dollars per DVD or for a CD kind of land. Peer-to-peer networking just descriptively pushed things in that direction and in fact became popular because of the divide between what it really costs to move the music around and what the companies producing it wanted to try to gain. Other examples include things like Wikipedia. Wikipedia is one of the craziest ideas ever. Let's start with, I don't know, six articles that had been produced by academics getting paid by Jimbo Wales, the founder of Wikipedia, originally as something called Nupedia, and dissatisfied with the pace at which the academics were going, he and others experimented with having a wiki-- having the articles be in a form that people could come in and edit and make suggestions on. That was originally going to be the back room, but it turned out to be the live site where now anything can be edited at any time, more or less, run by volunteer editors who are themselves Wikipedians. This is the kind of thing that has been a smashing success-- hard to replicate. It's just so singularly successful. It's the kind of thing that I can guarantee you it would have made no sense if you presented it to Microsoft to say hey, instead of Encarta, what if everybody just edited everything? It's nuts. Or presenting it to CompuServe-- hey, why don't you create an area on your service where people can just edit stuff together and create an encyclopaedia -- it would never have flown. Here Wikipedia could gestate in a quiet corner of the internet with some devoted nerds writing articles about Star Trek, editing them, and then having the topics expand, having the number of participants expand, having the number of languages expand, and you now end up with the fourth or fifth most popular website in the world being this not-for-profit, collective hallucination set of information that is by no means perfect, but represents such an unusual way of using the technology to produce something that people find precious and valuable. That's thanks to the generative internet that we got that. Are there other examples? Sure. Anytime you see a business that got started as the proverbial two people in a garage, you're looking at something that they could go from conception to some kind of running site, up and live with people able to access it and then iterate it into new versions without having to negotiate to get access to those audiences. And many configurations -- partly driven by security, partly driven by other considerations -- of a future internet are ones in which that is not nearly as easy to do. And as soon as those barriers go up, you end up with ideas then that might get the way you shop a good idea for a television show to one of a handful of channels or producers, if they like it then maybe great they'll take it, because they are your gateway to that audience, and that greatly changes the nature of innovation.

THE GENERATIVITY OF THE INTERNET

 JONATHAN ZITTRAIN: If you were to rewind time and play it back again, it's not clear you'd end up with the internet. I'm not sure you'd say the same thing about E equals MC squared, or truss bridges, or other pieces of technology that really are suited to what they do and are such the best solution, whether in theory or in practice, that you figure humanity would've gotten there one way or another eventually. With the internet, it reflects so many idiosyncratic choices about how to build a global network that it's important to remember they didn't have to be made that way. We could have ended up with a global network, or set of networks, that were a lot like the legacy telephone systems that prevailed from the early 20th century through into the early 21st. They might have been like CompuServe, AOL, Prodigy, The Source, MCI Mail. If you took a snapshot in 1982, '83, '85, everybody figured that the future of global networking was going to be something resembling those competing services, and one of them would just out-compete the others. Instead, out of left field came this unusual creature that we call the internet, and there's several things that made it unusual. The first of which is the folks who put its protocols together were not well-funded and had no particular expectation of making money from it. So in that sense, whatever you might know about Silicon Valley, the fundamentals of the internet were not as a dot com start up. They were instead as -- here are a number of ways that you could take existing networks and have them interoperate with one another, and that way you'd have a global network with no main menu, no CEO, no business plan, no particular committee even that runs it. A handful of functions, mostly what we call ministerial, merely administrative, are centralised, but the rest is pretty much what I'd call a collective hallucination. There's a commons that exists, in part through modest government subsidies to do this kind of research to produce the internet, but the rest is left up to the users to figure out what they want to use a network for. So in that sense, the essence of the internet is a set of protocols that allow any given points of presence that are connected to communicate with one another, and not have to worry so much about how the bits will work their way from point A to point Z. I have tended to call such technologies "generative technologies", and the core feature of a generative technology is that it tends to welcome contribution from nearly any quarter, and applied to the internet that means that in order to become a point of presence on the internet, to start exchanging bits with one other entity-- or perhaps if you think of yourself as a server, with hundreds of thousands or millions of other entities, if they are wanting to beat a path to your doorstep and get the bits that you have to offer -- that there's no gate-keeping to that. Anybody can set up on a kind of virtual hilltop a server-- maybe it's a web server, maybe it's some other kind of server-- and you're off to the races. That's very different from the CompuServe configuration of having to cut a deal with that company in order to be exposed to its subscribers. It's different from cable television. It's different from pay television or free television where there's a broadcast tower and a government will issue a licence or itself will be the broadcaster on unlimited bandwidth to an audience. And there's an interesting parallel kind of generative technology that really made the internet come into its own, and that is the typical end point. The thing that you would use to get onto the internet ended up being what we call the PC-- the personal computer. The PC's origins were less corporate and more hobbyist. Originally created by hobbyists for other hobbyists, and then by companies, but companies that in America would be called Heath or Heathkit-- kind of build your own clock rather than buy one. Not thought of as a big, broad market product, but rather a niche. That was the origins of the personal computer, and in 1977 when the Apple II was unveiled by Steve Jobs, 21 years old at the time, that was a computer that when it left the factory was not itself useful. You would plug it into a television set, turn it on, and you would be treated to a blinking cursor. That was all it was doing. It was waiting for you to write software, or to put in software written by somebody else that you've either purchased or been given or loaned, and that is another example then of a generative technology. Unlike say a smart information appliance, at the time -- late '70s, early '80s -- it might have been a word processor or something. You buy it, you turn it on, you get a word processor rather than a blinking cursor. You've got a document that you're ready to draft and then you could print it out. These PCs were general purpose, but originally to no purpose, and there was an understanding that anybody in the world could write code for it and circulate that code, and others, whether or not they were coders, could run the code. Two years after the introduction of the Apple II we saw Bob Frankston and Dan Bricklin of Boston Massachusetts produce VisiCalc, the first digital spreadsheet ever, and suddenly business around the world is noticing the personal computer. Now, it's what we would call an enterprise computer, because it's very useful in businesses to have spreadsheets. If you wanted to run VisiCalc you needed an Apple II. Apple IIs are flying off the shelves. Apple has no idea why -- they have to do market research to figure out what made their hobbyist computer so popular, and the answer was the generative nature meant people could code for it, didn't have to make a deal with Apple in order to get the code in front of people, you just needed your audience to have Apple computers, and sure enough they went out and got them so they could run something like VisiCalc. That generative technology meant that somebody actually from the southern cone, Robert Tattam, a researcher at the University of Tasmania in the psychology department could write something in 1995 called Trumpet Winsock (because he liked to play the trumpet), and that was kind of the keystone in the arch, the golden spike that allowed for the first time windows PCs to speak internet. So if you had a Windows PC and you ran Trumpet Winsock you could find yourself an internet service provider and get yourself online. And I think it's quite fitting that it was this gentleman's piece of freeware that actually was the gateway, rather than even that Microsoft had foreseen the importance to its own customers of the internet and had built internet connectivity into Windows, rather than building a paper clip that would tell you that it looked like you were trying to write a Word document, do you need help with that ... So thanks to PCs that could be repurposed and a network that was not a source of content, but merely a facilitator of its movement, we ended up by say, the year 2000, with this incredibly, doubly generative system that allowed anybody, anywhere to write code, to use this neutral network, to ship the code to others, to do it under any number of business models for money, not for money, for glory, not for glory, and that's how we saw the smart appliances fall by the wayside, and we saw the proprietary networks fall by the wayside. Now that's a snapshot as of 2000. In the intervening decade and a half we've seen a lot of growing pains. We've seen security threats to the internet. If anybody can write code, and it can easily work its way onto your machine how do you know the code is any good? And the answer is, you don't always know that. Microsoft, part of its way of talking about the importance of getting your code from accredited sources like Microsoft, likens it to a sandwich. If you found a sandwich on the street, would you pick it up and eat it? Probably not. So why would you do the same with your code? Now, the fact that you don't literally eat code is probably one of the answers. You can run it, and if there's a problem you could reboot the machine rather than have to go to the physician -- but that quirk has meant that as business models have come about to make it worth somebody's while to compromise your machine, to make it so that it answers to them far away rather than to you, the owner of the machine, we have seen great security problems arise. And my concern starting in around 2006, 2007, as I saw those problems on the horizon was that the cures for the problems might be as bad as the problems themselves in different ways. But we are unfortunately I think too often thinking that we are in a dilemma where we either have to suffer the vulnerability of arbitrary code running on our machine, scooping up our data, even worse, disturbing its integrity ... I don't know if it's worse to lose your spreadsheet or simply have cells within it transposed and you don't know until six months later that none of your numbers in your payroll make any sense, but that on the one hand-- to suffer those kinds of depredations-- either on your own machine or magnified to a merchant that has a server in which it keeps customer data that's off and running a PC operating system -- equally vulnerable. So that's on the one hand. On the other hand is locking stuff down so much that the wonderfully chaotic environment that gave rise to so much cool code out of odd and unusual corners could be stymied, that we could get back de facto to the worlds of CompuServe, Prodigy and AOL, because we will only trust code from a limited number of sources. Figuring out how to balance between those two undesirable end points to me is one of the fundamental questions about the future of the internet.

Thursday, July 30, 2015

Internet History, Technology, and Security - Final

Final Exam

1. How did the top-secret computing technologies developed at Bletchley Park during World-War II impact computing technology after the war:
  • The computer scientists used their knowledge of electronic computers to build the first generation of general purpose computers
2. What did Alan Turing contribute to Computer Science?
  • He founded the field of Artificial Intelligence

3. What was the primary reason the Colossus computer was faster than the BOMBE computer?
  • The Colossus computer used vacuum tubes instead or gears and relays
  • banner
4. Which of the following was the greatest weakness of store-and-forward networks like BITNET?
  • If your message was behind a large message it would have to wait until the large message was completed before it was sent.


5. Which of the following is most like a “packet” on the Internet?
  • A postcard
6. What was the original “stated” intention of the National Science Foundation Network (NSFNet)?
  • To connect scientists to supercomputers
7. Given the original five-year and 15 million dollar budget of the National Science Foundation Network (NSFNet), what was the expected speed of the national NSFNet backbone?
  • 56 thousand bits per second
8. Which of the following is the best explanation as to why the web was invented at CERN?
  • Well-funded smart people in a culture that was open and fun
9. Which of the following is something that Robert Cailliau and Tim Berners-Lee did not do?
  • Invented the first object-oriented language (WWW++)
10. Where was the first web server in America in production on December 12, 1991?
  • Stanford Linear Accelerator (SLAC)
11. What protocol was commonly used during 1990-1993 to organize and find information on the Internet that did not use the world-wide-web protocols?
  • Gopher
12. Which of the following products could be thought of as the “early ancestor of the Mozilla Firefox browser”?
  • NCSA Mosaic
13. Where was JavaScript developed at?
  • Netscape
14. What is the purpose of the World-Wide-Web Consortium?
  • Define standards for the web and avoid proprietary balkanization of the web
15. Why was the first product sold by Amazon books?
  • Because there are over 3 million books in print
16. Which of the following is most similar to an Internet router?
  • A train station
17. About how many separate physical connections (i.e. hops) will a packet cross on the Internet as it goes from University of Michigan to Stanford University?
  • 15


18. What is the value of a layered network model?
  • It allows a complex design problem to be broken into smaller manageable parts
19. What is the IETF?
  • It is a coordinating body where the standards that define the inner workings of the Internet are developed and published
20. Which is the lowest layer in the TCP/IP network model?
  • Link
21. Which of the following is a Link Layer address?
  • 00:1f:5b:81:62:e7
22. Which of the following is *not* an attribute of the Internet (IP) Layer?
  • It is designed to recover lost packets
23. What is the purpose of the TTL value in an IP packet?
  • It ensures that a packet does not get stuck in an infinite loop in the Internet
24. Which of the following is a domain name?
  • www.coursera.org
25. What problem did Van Jacobson solve in TCP?
  • He invented the slow-start algorithm to keep systems from overloading a slow link
  • banner
26. When we talk of the protocols that move data over the Internet, we talk of TCP/IP. Which of the following is FALSE about TCP/IP?
  • IP makes use of TCP as its underlying transport mechanism
27. Secure TCP (TLS) is between which two layers?
28. When you are using secure http and sending data between your computer and your bank’s computer, where is the data encrypted and decrypted?
  • Encrypted in your computer and decrypted in the bank’s computer
29. Which of the following is a TCP port (such as port 80 for HTTP) most like?
  • A telephone extension
30. Which of the following commands is part of the Hypertext Transport Protocol (HTTP)?
  • GET
  • Find Enroll Learnbanner
31. What is the problem with secret key distribution via the internet?
  • We cannot all physically visit every web site and physically pick up a key book to work securely with that site
32. What does a cryptographic hash function do?
  • It takes a block of data and computes a fixed-size bit string called the hash value
33. Which of the following is credited as one of the inventors of Public Key Cryptograhy in the 1970’s
  • Whitfield Diffie
34. Which historical figure is credited with encrypting military messages using a simple “shifted alphabet”?
  • Caesar
35. Which of the following are the steps to sign and send a message to insure that the message came from the sender and was not modified in transit?
  • Append the shared secret to the message, compute the cryptographic hash of the message + secret, send the message + cryptographic hash across the internet
36. Which of the following statements is false
  • Public key encryption cannot be broken
  • Testive
37. What is the mathematical underpinnings of public key encryption?
  • Prime numbers
38. Considering the four-layer TCP/IP model, which two layers does Secure Sockets Layer (SSL) fit between?
  • Application and TCP
39. If you are sending credit card information from a coffee shop WiFi to an Internet web site and later you find your credit card information has been stolen, which is the most likely scenario as to how your information was stolen?
  • You did not use secure HTTP (https) at a coffee shop with an open WiFi
  • Symantec Corp.
40. Which of the following would be major a warning sign that indicates lax security practices when dealing with a site where you have an ID and Pasword?
  • They can send you a mail message with the password you previously used to log in if you forget it