Tuesday, October 15, 2019

PV system Assignment Example | Topics and Well Written Essays - 500 words

PV system - Assignment Example h. power storage: solar power can be put away in solar batteries and warm thermal solar frameworks for warming homes. At the point when there is light, the panels charge the batteries. Amid the night and climate conditions without the sun, the batteries are utilized to power the lightings (Conservative critic). (a) It is the design that expands the gathering of vitality from solar sources from a vast territory. It is attained by concentrating solar radiation from a vast region into a PV cell. It fundamentally lessens on the measure of the silicon wafer that is put into the generation of power. (b) Concentrating beams from the light is best accomplished by utilizing mirrors and lenses a procedure termed as optical force. Then again, a glass window built with luminescent substances in a methodology called luminescent concentration. (C) By guaranteeing that a lot of light from an unfathomable zone falls on a little PV cell, less measure of silicon is required to create and deliver high measures of energy subsequently lessening generation cost. For the luminescent concentration, the sheet of luminescent substance reradiates light, which wind up inside the glass. The reflection brought on falls on the PV cells to create power. The setup obliges that silicon wafer is just made utilization of on the edges. Productivity is a component considered from over edge as it prompts expanded proficiency (Ferowich). Ferowich, Grant. Solar Power: Cost and Reliability Make It the Perfect Energy Source. 31 MAY 2013. 4 OCT 2014

Monday, October 14, 2019

Attack Tree Model Analysis of Security Breaches

Attack Tree Model Analysis of Security Breaches THE SUCCESS MISUSES of computer systems security breaches increased slightly in 2005, according to the FBI and the Computer Security Institute (CSI). Many security issues that apply to large enterprises definitely apply to SMBs, especially as SMBs become more technologically sophisticated, according to Andrew Kellett, senior research analyst with U.K.-based Butler Group. You dont have to be a particular large organization to have some pretty complex supporting systems in place, he says. (Fred Sandsmark, p11) The above-mentioned stated that there was slightly increase in computers attack in 2005. As technology evolving, companies willingly to spend more money on computer systems to do business activities with their associate and partners. This will increase more and more security breaches on the computer systems. The purpose of this analysis report is to examine the various possible attack methods to compromise the availability of the computers, information and associated resources of a small firm. Research for this report includes an attack tree diagram, showing how the hacker can compromise the availability of the systems services, associated resources and to access sensitive information through different attack techniques. Each technique is the subset of the different type of attack methods, with possible assumptions attach to each methods, the attack tree will be discussed in greater details. INTRODUCTION The manager of the Raylee Pte Ltd has recently heard through the media and newspaper publications that there are numerous threats which could compromise the availability of the computers, information and associated resources. Management of Raylee Pte Ltd has decided to hire the security consultant firm Red Alert Security Pte Ltd to undertake a details analysis of its current computer and network state in order to prevent the hackers to compromise the availability of the computers services, information and resources. The under-mentions are the network and desktop environments of the Raylee Pte Ltd. There are six computers and one internal server (for processing orders) within the firm. Each computer encompasses Microsoft Windows 7 and Microsoft 2007 Each workstation has been patched with all updates as of March 25th, 2010. The company shares an ADSL 2+ connection amongst all computers. Server backups are done fortnightly and stored on a DVD spindle name backup1 Workstation backups are done bi-monthly and stored on a DVD spindle name backup2 Employees have email addresses provided by the Internet Service Provider. Documents are shared amongst employees through a D-Link DNS-323 NAS The router is utilising a default settings and consists of a D-Link DSL G604t. Each workstation is utilising Microsoft Windows Malicious Software Removal Tool. SCOPE Security consultant of Red Alert Security Pte Ltd will analyse of the company current computer system, network state and desktop environment in order to prevent the hackers to compromise the availability of the computers services, information and resources. Then the consultant will submit a detail analysis report to the Management of Raylee Pte Ltd for recommendations METHODOGLY The security consultant uses a technique known as attack tree to identify the best possible options to compromise the availability of the system services, information and resource in the quickest time. Below is the attack tree he comes up with. Compromise The Availability Of Computers, Information And Associated Resources 1. Remote Access Router: D-Link DSL G604t 2. Access NAS: D-Link DNS-323 3. 3. Gain Access Internal Server (Processing Orders) Orders) 4. Steal Password: Workstations METHODOLOGY From the attack tree in the previous page, each of the sub attack tree will be discussed in more detail. Figure 1 1. Remote Access Router : D-Link DSL G604t 1.1 Determine the password 1.1.1 Learn password 1.1.2 Use widely know password 1.1.3 Dictionary attacks 1.1. Determine password Hacker and cyber criminal will try to determine the password of the router in order to access the network environment and do whatever they want. We will briefly explain the methods as follows 1.1.1 Learn password If the user has not set new password and is using the default which is normally blank. Hackers can easily search online for the manual of the particular wireless router and know the password. Hackers login the wireless router configuration page to change the setting and sabotage the network. For instance, hacker can surf this link http://www.routerpasswords.com/index.asp to get the default password for all the routers. 1.1.2 Use widely know password The common used passwords are admin, password, [emailprotected], 123456, 666666, qwerty, 00000000 and etc. These widely used passwords allow hackers to easily access the router. 1.1.3 Dictionary attacks As the word dictionary it implies that it is one of the attack techniques use by the hackers to determine its decryption key, password or passphrase by searching the all the words which are usually seven characters or lesser chosen by the user in the dictionary. METHODOLOGY Figure 2 2. Access NAS : D-Link DNS-323 2.1 FTP server 2.2 Folder File Permission 2.3 P2P distribution 2.1.1 Bounce Attack 2.1.2 Misconfigure 2.3.1 File poisoning 2.3.2 Sybil attack 2.1 FTP server Most of the Network Attach Storage device comes with the feature of the FTP server which allows user to download or upload file remotely anywhere. However, this service creates a loophole for attacker to retrieve sensitive information and data. The various attack methods on FTP server are discussed as follows 2.1.1 Bounce Attack FTP bounce attack is another attacking technique use by the hacker to exploit the ftp protocol so that he can use the PORT command to send request access to the ftp port indirectly to another victim machine which acts as third party for such request to access the ftp. 2.1.2 Misconfigure One of the common problems is to misconfigure the ftp server which allows users to download and upload the files in the same directory (global/tmp directory) for people to share data with each other. It will create an opportunity for attacker or theft to steal the data or upload virus program to the directory. Hence employee will accidentally install the virus program and infect to the computer systems and network. 2.2 Folder File Permission Proper folder and file permission must be set according to the employee roles and responsibilities. If there is no permission setting on the files and folder and gives everyone permission to read, write and execute it. Then it will be easily for attacker to retrieve information upon hacking into the company network. 2.3 P2P Distribution It is a peer-to-peer file transfer protocol to allow users each download different pieces of the broken file from the original uploader (seed). Users exchange the pieces with their peers to obtain the broken ones which are missing. IT savvy employees can make use of the P2P to download their favourite movies, videos, music and software. Hacker will make use of the P2P attacks to gain access into the network. There are two types of attacks which are file poisoning and Sybil attack. 2.3.1 File Poisoning File poisoning attacks operate on the data plane and have become extremely commonplace in P2P networks. The purpose of this attack is to replace a file in the network by a fake one and this file will be corrupted and no longer in use. 2.3.2 Sybil Attack The idea behind this attack is that a single malicious identity can present multiple identities, and thus gain control over part of the network. Once the attacker gains the control, he can abuse the protocol in any way he likes. METHODOLOGY Figure 3 3. Gain Access Internal Server (Processing Orders) 3.1 Steal sensitive information from the database 3.1.1 Gain access by internet 3.1.2 Physical access to the server 3.1.3 Access server from workstation OR OR 3.1.1.1 Monitor network traffic 3.1.1.2 Use remote exploit 3.1 Steal sensitive information from the database Sometimes hackers are hired by the competitor to create chaos in the company network and to steal confidential information such as customer data, vendor data, pricing information, new product launch information from the computer systems. There are various methods to steal information from the database and there are as follows: 3.1.1 Gain Access By Internet Attack corporate network by using internet is becoming more sophisticated as technologies evolving. There is an increase of internet attacks orchestrate by the hackers to strike highly protected targets, to coordinate waves of scripted exploits and/or to conceal the true origin of an attack. 3.1.1 .1 Monitor Network Traffic Cyber criminal use network monitor tools to monitor the local area networks or wide area networks. Some of the network monitoring tools such as Microsoft Network Monitor, Ettercap, TCP Dump and DSniff can be download freely from the internet. This program can intercept and log the traffic passing over the network or part of the network. Once the information is captured by the program, hacker will decodes and analyse its content according to the appropriate RFC or other specifications. 3.1.1 .2 Use Remote Exploit The server is connected to the internet and the operating system is not updated the latest patches, then the cyber attacker will use remote exploit the vulnerability of the system to infiltrated the system to steal the information and sabotage the server by destroy the database and hard disk. Since the server backups are done fortnightly, management will be facing difficulties in recover the data. 3.1.2 Physical Access To The Server Due to the space constraint, sometime the server share space with someones cubicle or office. This creates an opportunity for an attacker who able to access files and other data by removes the hard disk, and then attaches it to another computer. He can also use third-party operating system CD to start the computer and steal corporate data or insert USB drive to inject virus into the system. 3.1.3 Access Server From Workstation Cyber attacker is not limited to hack into the server. Workstation is the often the first target the hacker will try to access because from there, he can learn about the network environment and security loopholes to attack the server. He will use the workstation as the stepping-stone to server-level break-in by stealing administrator passwords. METHODOLOGY Figure 4 4. Steal Password: Workstations 4.1 Users Login password 4.1.2 Obtain password illegally 4.1.1 Social Engineering 4.1.1.1 Share password 4.1.1.2 Phishing 4.1.2.2 Find written password 4.1.2.1 Steal password 4.1.2.1.2 Install keyboard sniffer 4.1.2.1.1 Obtain sniffer output file AND 4.1 Users Login Password Companies must know that hackers not only interested in the corporate data, they are also interested in the employees personal data such as bank account, credit card, email address and others. To break into the workstation, hackers will need to know the users login password. 4.1.1 Social Engineering Social engineering is the method of non technical hacking into the system by manipulating people through social interaction via email or phone to reveal their password. 4.1.1.1 Shared Password It is very common for employees to share computer password with their colleagues. Sometimes in their absence in the office, they will usually call one another to help them login to the computer to retrieve some information. 4.1.1.2 Phishing Hacker can create an email or instant messaging with attach fake website link which looks almost the same as the real one to lure the user enters their personal details such as username, password, credit card details and banking credential. All these information will be sending to the hacker. 4.1.2 Obtain Password Illegally Weak password makes hacker to obtain password illegally and faster. Cyber attackers will steal the password by infect the workstation with trojan. Basically there are three types of trojan attackers can use to steal the password namely: keyboard sniffer, login spoofing and password stealer. When attacker install the keyboard sniffer program which will monitor each keystroke the user has entered and this program generate the sniffer output file which send to the attacker. Sometimes hacker can pose as companys guest to access the premises. Upon entering the office, he will look for password which the employee written on a piece of paper and paste it around the working cubicle. CONCLUSION Companies are constantly at risk of losing sensitive corporate data. In this report,  we have use the attack tree model to analyse various attacks method the attackers use to steal sensitive information on the server, network attach storage device, router and workstations. The most common and easier method is to obtain the users password by learn the password, use widely common password, dictionary attack, shared password, phishing, find written password and steal passwords. Cyber attackers and novice hackers are usual like to steal the passwords by downloading keyboard loggers, passwords cracking software, keyboard sniffers and others which are available on the website to test on their skill. Management should implement counter measures to prevent hackers to attack their system and security breaches. We recommend antivirus program to be installed on  the workstation and server as they are utilising Microsoft Windows Malicious Software Removal Tool which is not enough for the prevention of the cyber attacks. Local group policy of the password needs to enforce on the networking devices, workstation and server so that the password is not being easily crack by the hackers. Lastly, passwords should be set minimum 8 characters and contain alphanumeric and symbols for complexity. In conclusion, steal password is the easiest method for hackers to attack the computer system because local authorities might face difficulties in tracking them down if they are distant hackers. GLOSSARY Attack tree Attack trees provide a formal, methodical way of describing the security of systems, based on varying attacks. Basically, you represent attacks against a system in a tree structure, with the goal as the root node and different ways of achieving that goal as leaf nodes. (Source : http://www.schneier.com/paper-attacktrees-ddj-ft.html ) Social Engineering In computer security, social engineering is a term that describes a non-technical kind of intrusion that relies heavily on human interaction and often involves tricking other people to break normal security procedures. (Source : http://searchsecurity.techtarget.com/sDefinition/0,,sid14_gci531120,00.html ) 3. Phishing Phishing is a technique of fraudulently obtaining private information. (Source : http://en.wikipedia.org/wiki/Social_engineering_(security)#Pretexting ) 4. Keyboard Sniffer A program which reads the keystrokes made by a user and transmits them to someone else. Such programs are usually used by intruders into computer systems in order to capture important information such as passwords. (Source : http://www.encyclopedia.com/doc/1O12-keyboardsniffer.html ) 5. RFC Short for Request for Comments, a series of notes about the Internet, started in 1969 (when the Internet was the ARPANET). An Internet Document can be submitted to the IETF by anyone, but the IETF decides if the document becomes an RFC. Eventually, if it gains enough interest, it may evolve into an Internet standard. Each RFC is designated by an RFC number. Once published, an RFC never changes. Modifications to an original RFC are assigned a new RFC number. (Source : http://www.webopedia.com/TERM/R/RFC.html )

Sunday, October 13, 2019

Hamlet: Character Analysis :: essays research papers

Over the centuries many people have complained that William Shakespeare did an inadequate job of steering the readers of Hamlet to a specific interpretation of each character. Each reader is left to decide the true extent of Hamlet’s evil and insane ways or to realize that he clearly is a victim of circumstances beyond his control, therefore declaring him innocent. Because of William Shakespeare’s writing style, the reader receives little help in discovering who is truly innocent and who is as guilty as Claudius. Many scholars agree that Hamlet may be the most complex character presented by any playwrite. Over the centuries critics have offered many theories and explanations for Hamlet’s actions, but none have sufficiently explained him. Many people view Hamlet as a deeply troubled youth who caused many unnecessary deaths, such as those of Polonius and Laertes. Critics who support this theory point out the cruel actions carried out by Hamlet, one example being the indifferent and boastful way Hamlet describes the ingenious way he had his two good friend, Rosencrantz and Guildentsern killed. But wilt thou hear now how I did proceed?†¦I sat down, devised a new commission, wrote it fair. I once did hold it, as our satists do, a baseness to write fair, labored much how to forget that learning, but, sir, now it did me a yeoman’s service. Wilt thou know th’ effect of what I wrote?†¦An earnest conjuration from the King, as England was his faithful tributary†¦that on the view and knowing of the contents, without debatement further more or less, he should those bearers put to sudden death. (Shakespeare 5:228-45) The way Hamlet treats Ophelia, the woman he supposedly loved, also supports the portrayal of him being a barbarian. If thou dost marry ,I’ll give thee this plague for thy dowry: be thou as chaste as ice, as pure as snow, thou shalt not escape calumny. Get thee to a nunnery[referring to a brothel], go and quickly, too.(Shakespeare 3:1 136-141) Another offered interpretation suggests that using the information given by the ghost of King Hamlet, Hamlet seized the opportunity to regain what was rightfully his-the throne of Denmark. One less popular belief that has been expressed states that Hamlet was actually a girl, raised as a man, so there would be an heir to the throne. Critics who support this view say that this theory explains Hamlet’s reluctance and hesitation to commit murder(which is most often viewed as a masculine act).

Saturday, October 12, 2019

Computers in the Classroom :: Education Teaching

Computers in the Classroom Technology is increasingly becoming part of our everyday life. We can think back to a time when we did not even know what a computer was and all we had was the telephone, radio, and television. Now, we cannot go a day without using my computer and the internet to do something that we need to get done. When did it all change? Everything is happening so fast. We remember going to school and all that we were allowed to use was paper and pencil and we are only twenty and twenty-two years old. When we think about how quickly things have changed, we can only image what it’s going to be like for the next generation. Everyday there is something new coming out into the technology market whether it be, an upgrade to a software package or a new model for a computer. We have come to the realization that as soon as we buy a product, such as a new computer or printer that within a month or less, it is essentially out dated. The reason for that is that as soon as the companies such as Hewett Packard put a new product out on the market, they have already begun work on a new model to improve the one that they just put out. Not only have computers become part of everyday life; they have also become an essential part of instruction in the classroom for both teachers and students. Throughout this paper, we will be discussing several different aspects of why computers are important tool in the classroom. The job of a teacher is to engage students in learning. Computers are engaging learning tools because they reinforce the concepts which are being taught in the classroom. In the past ten years from Kindergarten through college, teachers and students have embraced information technology. Eight-five percent of children know more about computers and the Internet then both their parents (http://www.davidpearcesnyder.com/computers_and_classrooms.htm, n.d). When computers are used in an interactive mode it enhances the average young person’s ability to learn. Some examples of inactive mode include video games, educational games, and chat rooms. In addition, CD-ROMs allow students to learn to read faster and retain more information. In high school, three fourths of students prefer researching school assignments on the Internet (http://www.

Friday, October 11, 2019

Foreign Direct investment policies Essay

Recently Egypt has made some impressive reforms in reforming its foreign direct investment policies but there are still some significant barriers. Currently the FDI stands at 12. 2 Billion up from one billion in 2001. Barriers to entry have been eased for foreign investors; the country has dedicated a ministry to propel the number of foreign investors. Egypt streamlined its tax system with a reduction in corporate income tax rate from between thirty two percent and forty percent to a uniform of twenty percent. In manufacturing, foreign investment has been fully liberalized other than in industries related to defense activities. Foreign equity is allowed to participate in privately owned communication and financial services up to one hundred percent. It has become cheaper and quicker for foreigners to register new companies (Ikram et al 1980) In some sectors such as transport, electricity and construction, foreign investment is restricted. For example in construction foreign companies have to set up a joint venture, in which the equity of foreigner is only limited to forty nine percent. Economic Structure and performance The economy of Egypt is undergoing a steady growth in the last quarter of 2008. Egypt’s annual growth domestic product had risen from 7. 3 in 2006 to 8. 6 in 2008. The rate of inflation has also dropped from 18. 3% in 2003 to 3. 21% in 2008. However with the current economic downturn inflation rate in Egypt stand at 10. 87%. With the economic reforms that the government has undertaken, private sector commands over eighty percent of Egypt’s economy. As economic reforms take root, the annual growth domestic percent is likely to accelerate. It has been predicted that it will hit 13. 5 % by 2010. Economist agrees that the economic climate that currently exists in Egypt is the best one for investing. The Egyptian economy as it is now is able to create more opportunity for domestic growth of wealth and also has enormous potential over long term because of the following reasons: strong economic growth of 8. 6% in 2007, incentives and reforms given to foreign investors, low cost of living and availability of cheap labor. Since 2001, Egypt consumer price index, has registered a significant growth from 12. 68% in 2004 to 3. 6% a fact that is attributed to the rise in the value of the Egyptian Pound. The current account of Egypt has also grown from a deficit of 1. 8% of the annual gross domestic product to an estimated 6. 1% in 2007. (CIAO/EIU Partnership 2008) With the high population in Egypt, the county has a wider market of both skilled labor and unskilled labor. The ministry of education has always ensured that the courses offered in both private and public learning institutions are at par with the requirements in the job market. With the assistance of IMF and World, Egypt has embarked on a program that will see the private sector takes a big role in the county. Egyptian government entrenched Law 203, which was to speed privatization of the public sector. Currently the degree of privatization in Egypt is high (72 percent). By 2007, the government had privatized over eighty percent of the 314 public enterprises which it had earmarked for privatization. The ministry of public enterprise in Egypt predicts that by 2010, all the public enterprises that were earmarked for privatization will have been privatized. With privatization of these public enterprises, the benefits accrued to the Egypt economy is an additional savings to the country. The total gain which has so far been realized by privatization is that GDP has grown by 2. 8 %. With the growth in GDP, the country’s infrastructure has also noticed some improvement, because most of the savings that the government is making as a result of privatization is currently being used for development (Sayed et al 2007 pp12-29) The Egyptian’s road network is somehow underdeveloped. It is currently being serviced by a network of over sixty eighty thousand kilometers of both secondary and primary roads. Despite modernizations of roads in Egypt in mid 1980s, most of them are either under construction or are in poor condition. The level of congestion of automobiles has continued to rise due to the increase in the number of licensed automobiles. According to a report released by EIU (2006) country profile, Egypt reported the highest incidences of automobile fatalities in the entire world: it was 44. 8 deaths per one hundred thousand kilometers. In terms of energy Egypt has adequate supply of electricity from Egyptian Electricity Authority which produces over fifteen thousand megawatts of power. Plans are already underway for EAA to increase its power production by more than two thousands five hundred by 2010. Power consumption has reported a constant growth of 6. 1% per year. Telecommunication services are cheaper and modern. According to reports by EIU country profile for 2006/2007, Egypt had more than seven million lines. The lines are increasing at a rate of one million per year. The country has seventy nine internet providers (Economic intelligence unit country profile) Natural and Cultural factors Egypt has a diverse cultural mix which is good for investors. 80 percent of the Egyptian population is Muslims, while Christians and Hindu makes up the remaining percentage. The country observes religious practices like during the holy month of Ramadhan the country is always in a prayer mood. Egypt also has an average temperature of between 13 and 29 degree centigrade. For entry to Egypt, Visa is usually required. EU and U. S nationalities that are traveling or want to invest in Dahab, Taba, Sharm EL Shik and Hurghada are given a free visa stamp upon arriving at the airport Social and political stability Egypt is a democratic country with many political parties. The country has a semi presidential system, where power has been split between the prime minister and the president. In 2005, Egypt changed its constitution to allow for more presidential candidates to take part in the elections. The county also has a good political temperature that is favorable for investors. The country was the first Arab country to embraces political relationship with Israel. It also plays in mediating conflict between different countries in the Middle East. The political life in Egypt is good for investors. Hence U. S businessmen who are currently doing their business there or who want to start doing their business should do so. Recommendation and Conclusion From the analysis carried, the writer of this paper is of the opinion that Egypt is a good country for any American companies who are thinking of investing there or who have already invested there to continue. The writer is of the opinion that Egypt has an attractive and stable market for property investors. The country has an emerging property market in tourist destinations and it is also offering a return that is excellent on property investment. Despite the fact that foreign equity in construction industry is standing at forty nine percent Americans companies should ventures into it because of the high rate of return that this industry commands in Egypt. Reference: Abd al –Salam, Abou Khaf M & Abu Qahf (2005) Foreign direct investment in developing countries, a comprehensive analysis of the determinants, policies, organization & impacts a case study of Egypt. Buckley P (2003) the changing global context of Egypt international Trade CIAO/EIU Partnership (2007) Economic structure of Egypt retrieved from www. ciaonet. org on March 26 2009 Egypt trade summary PDF retrieved from www. ustr. gov/assets/Document_Library on March, 26 2009 Economic intelligence unit country profile 2006/2007 report retrieved from www. eiu. com/index. asp March, 26 2009 Galal A & Lawrence (1998) An Egypt US free trade Brookings Institution Press pp 23 -56 Ikram K & World Bank (1980) Egypt, Economic management during transition period – A mission report sent to Egypt by the World Bank pp 12 -42 Kaudhar- Luis F (2006) Investing in Construction Industry in Egypt Alexandra University Press pp 9 – 30 Marks S & Ken K 2001 a comparative study of foreign direct investment in Egypt Published by USAID pp 9 -14 Olarreaga M & Madani D (2002) Politically Optimal Tariffs- an application of Egypt pp 6 – 29 Sayed S, Idarat A. & Dawliyah (2007) international business in Egypt & Middle East Jordan Publisher 12 -65 Weigel D, Wagle D & Gregory W (1997) foreign direct investment World Bank Publications pp 1 -22

Thursday, October 10, 2019

HBC From Fur to Fendi Essay

1. Three competitive strategies that the company HBC used prior to its sale to Zucker and NRDC are the differentiation strategy, the growth strategy and an e-business strategy. HBC used the differentiation strategy by reinventing itself with a more fashionable image through designer depot/Style depot. HBC used the growth strategy by expansion of the corporation to strengthen its share of the market with the acquisition of other retailers such as K-Mart Canada. They also opened the HBC Rewards Program to entice costumers back to its stores. HBC also used the e-business strategy by opening their online shopping program, allowing customers to have the option to shop online instead of having to go to the store. 2. Three strategies HBC adopted since the sale would be the renewal strategy, the focus differentiation strategy and the diversification strategy. Under the NRDC leadership, The Bay’s main focus was reattracting customers. They did this by dropping over 60 percent of its previous brands and relaunching the â€Å"Room†, which was located at one of its Toronto locations. â€Å"The Room† is a VIP suite containing high end designers. HBC also used the focus differentiation strategy by becoming an official sponsor for the 2010 Olympics in Vancouver. By selling Olympic branded merchandise this allowed the Bay to be open to a whole new market. Selling Olympic merchandise allows Olympic fans to have the option to buy that merchandise at The Bay. HBC uses the diversification strategy by launching â€Å"The Room† which allowed The Bay to then sell designer merchandise to customers, which broadened their variety to a whole new market of customers. 3. The competitive strategies mentioned before can be categorized into two categories, business or corporate level strategies. The business level strategies included, the differentiation strategy and the focus differentiation strategy. The corporate strategies included the growth strategy, e-business strategy, renewal strategy, and the diversification strategy.

Wednesday, October 9, 2019

Is3440 Project Part 1 Essay

First World Savings and Loan is a financial institution that processes credit card transactions and loan applications online. We are currently considering implementing an open source infrastructure. This could potentially save us over $4,000,000 per year in licensing fees for the software we are currently using. However, due to our business needs; we must still comply with the Sarbanes-Oxley Act (SOX), Payment Card Industry – Data Security Standard (PCI-DSS), and the Gramm-Leach-Bliley Act (GLBA). We must comply with SOX, because we are a publicly-traded financial institution; PCI-DSS, because we process online credit card transactions; and GLBA, because we are a financial institution. All of the regulations of these three compliancy laws must be met, while still maintaining the Confidentiality, Integrity, and Availability (CIA) triad. All security requirements for SOX, PCI-DSS, and GLBA can be achieved using Linux and open source infrastructure. Some examples of open source software that we might use are: Web Server – Apache Web Filtering – DansGuardian Network Firewall – Turtle Firewall VPN – Endian Firewall Community IDS/IPS – Suricata Database – MySQL File Server – Samba SMTP Server – hMailServer I would recommend that we use a â€Å"Defense in Depth† strategy, having multiple layers of access protection. We need to have an IDS/IPS on both sides of our edge firewall. The inside IDS/IPS will be used as additional protection for our network and the outside IDS/IPS will serve as an early warning system from attacks. We will also use the outside IDS/IPS for additional protection and to monitor what types of attacks are occurring. Our web server and mail server should be completely separated from the rest of our network in a de-militarized zone (DMZ). We need to have a network firewall between our DMZ and our internal network, between the outside world and our internal network, and between our DMZ and the outside world. There should also be a local firewall enabled on each local machine. Also, since our physical servers will be hosted at a third party location, we must have VPN access to these servers to manage them. All private data will need to be encrypted, as well as all data transitions. To go along with the previously mentioned physical and software based security measures, we will also apply multiple policies to maintain this security. Acceptable Use  Policy – This policy will describe how the companies IT assets should and can be used. As well as what is not acceptable to do on company assets. Password Policy – This policy will explain what parameters a password must meet to be accepted. For example; a password must be at least 15 characters long have at least on capital letter, have at least one lower case letter, have at least one number, and have at least on symbol. Privacy Policy – This policy describes what information must remain confidential. Training employees on the proper way to use (and how NOT to use) company assets is a major key to ensuring the CIA triad remains intact and our network secure. In this part of the executive summary, I am going to be explaining, and making recommendations on what the best options are for the open source software that is needed for the management of the First World Savings and Loan financial institute’s various web and application servers. F or each of the servers, I recommend using the Red Hat Enterprise Linux operating system for a number of reasons. The main ones being that it is one of the most secure, It’s backed by years of technical support, It’s supported by a vast number of different hardware, and It is one of the most, if not the most, popular and used server OSs that one can get today. I would rather go with software that has been vigorously tested to its breaking point and still remains at the top tier of server software options that’s readily available today, than one that has just come out with all of the bells and whistles. So on that note, let’s get started on what I recommend to be the best of the best in terms of specific software and service needs. There are numerous great open source software solutions for database servers, like, H2, HyperSQL, MySQL, mysql, Oracle, and PostgreSQL, just to name a few. They all offer topnotch functionality, performance, scalability, and security. As far as which one is the best, I recommend PostgreSQL. PostgreSQL is an object-relational Database softwar e solution that offers some of the most feature rich options as compared to the bigger commercial manufacturers like Oracle, IBM, Sybase and Informix, and the best part of it, it’s free. It’s also one of the first database software that was released, and it has a proven track record with over 23 years of active development. It was created back in 1989. The only other DB software that came out before it is Oracle, which was created back in 1979. Now PostgreSQL might not be the fastest, but It more than makes up for it with its functionality. It allows the use of two  different types of interfaces, a GUI (for those who like the point-click style) and a SQL. It works on most OSs like windows, Linux, Mac, Unix, etc. It has a vast array of services and tools that is included to streamline the administration of the Database. Here are just some examples; Full ACID (Atomicity, Consistency, Isolation, & Durability) compliancy, commercial & noncommercial support, triggers support, user defined data type support, stored procedure support, online backup, multiple index type input support, embedded access controls, encryption, etc. Here is a comparison of the top DB software available I got from the unbiased, data-driven comparison website; www.findthebest.com/database-management-sytems: —————— Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€- Specifications Product | MySQL | Oracle | PostgreSQL | Architecture | Relational Model | Relational Model | Object-relational Model | Software License | * GPL * PostgreSQL * Proprietary | * GPL * PostgreSQL * Proprietary | * GPL * PostgreSQL * Proprietary | Operating System | * Windows * Mac OS X * Linux * UNIX * z/OS * BSD * Symbian * AmigaOS | * Windows * Mac OS X * Linux * UNIX * z/OS * BSD * Symbian * AmigaOS | * Windows * Mac OS X * Linux * UNIX * z/OS * BSD * Symbian * AmigaOS | Demo? | | – | | Interface | * GUI * SQL | * GUI * SQL | * GUI * SQL | Website | MySQL (mysql.com) | Oracle (oracle.com) | PostgreSQL (postgresql.org) | First Public Release Year | 1995 | 1979 | 1989 | Lastest Stable Version | 5.5.19 | 11g Release 2 | 9.1.3 | ————————————————- -Price Price | $0 | $180 | $0 | Purchase Page | MySQL (https) | Oracle (https) | – | ————————————————- -General Features Features | * ACID * Backup * Custom Functions * Database Imports * Export Data * Extensibility * High Availability * Highly Scalable * Import Data * Java Support * Multi-Core Support * See more†º | * ACID * Backup * Custom Functions * Database Imports * Export Data * Extensibility * High Availability * Highly Scalable * Import Data * Java Support * Multi-Core Support * See more†º | * ACID * Backup * Custom Functions * Database Imports * Export Data * Extensibility * High Availability * Highly Scalable * Import Data * Java Support * Multi-Core Support * See more†º | Indexes | * Bitmap * Expression * Full-text * GIN * GiST * Hash * Partial * R-/R+ Tree * Reverse | * Bitmap * Expression * Full-text * GIN * GiST * Hash * Partial * R-/R+ Tree * Reverse | * Bitmap * Expression * Full-text * GIN * GiST * Hash * Partial * R-/R+ Tree * Reverse | Database Capabilities | * Blobs and Clobs * Common Table Expressions * Except * Inner Joins * Inner Selects * Intersect * Merge Joins * Outer Joins * Parallel Query * Union * Windowing Functions | * Blobs and Clobs * Common Table Expressions * Except * Inner Joins * Inner Selects * Intersect * Merge Joins * Outer Joins * Parallel Query * Union * Windowing Functions | * Blobs and Clobs * Common Table Expressions * Except * Inner Joins * Inner Selects * Intersect * Merge Joins * Outer Joins * Parallel Query * Union * Windowing Functions | Partitioning | * Composite (Range + Hash) * Hash * List * Native Replication API * Range * Shadow | * Composite (Range + Hash) * Hash * List * Native Replication API * Range * Shadow | * Composite (Range + Hash) * Hash * List * Native Replication API * Range * Shadow | Access Control | * Audit * Brute-force Protection * Enterprise Directory Compatibility * Native Network Encryption * Password Complexity Rules * Patch Access * Resource Limit * Run Unprivileged * Security Certification | * Audit * Brute-force Protection * Enterprise Directory Compatibility * Native Network Encryption * Password Complexity Rules * Patch Access * Resource Limit * Run Unprivileged * Security Certification | * Audit * Brute-force Protection * Enterpr ise Directory Compatibility * Native Network Encryption * Password Complexity Rules * Patch Access * Resource Limit * Run Unprivileged * Security Certification | Tables and Views | * Materialized Views * Temporary Table | * Materialized Views * Temporary Table | * Materialized Views * Temporary Table | Other Objects | * Cursor * Data Domain * External Routine * Function * Procedure * Trigger | * Cursor * Data Domain * External Routine * Function * Procedure * Trigger | * Cursor * Data Domain * External Routine * Function * Procedure * Trigger | Support Features | * Email * FAQ * Forums * Live chat * Mailing List * On-site * Phone * Tips and hints * White papers | * Email * FAQ * Forums * Live chat * Mailing List * On-site * Phone * Tips and hints * White papers | * Email * FAQ * Forums * Live chat * Mailing List * On-site * Phone * Tips and hints * White papers | ————————————————- -Product Description Product Description | MySQL is a relational database management system (RDBMS) that runs as a server providing multi-user access to a number of databases. MySQL is officially pronounced /maÉ ªÃ‹Å'É›skjuË Ã‹Ë†Ã‰â€ºl/ (â€Å"My S-Q-L†), but is often also pronounced /maÉ ªÃ‹Ë†siË kwÉ™l/ (â€Å"My Sequel†). It is named for original developer Michael Widenius’s daughter My. | Oracle Database 11g Release 2 provides the foundation for IT to successfully deliver more information with higher quality of service, reduce the risk of change within IT, and make more efficient use of their IT budgets. By deploying Oracle Database 11g Release 2 as their data management foundation, organizations can utilize the full power of the world’s leading database to:ï‚ · Reduce server costs by a factor of 5ï‚ · Reduce storage requirements by a factor of 12ï‚ · Improve mission critical systems performance by a factor of 10ï‚ · Increase DBA productivity by a fa ctor of 2ï‚ · Eliminate idle redundancy in the data center, andï‚ · Simplify their overall IT software portfolio. | PostgreSQL is a powerful, open source object-relational database system. It has more than 15 years of active development and a proven architecture that has earned it a strong reputation for reliability, data integrity, and correctness. It runs on all major operating systems, including Linux, UNIX (AIX, BSD, HP-UX, SGI IRIX, Mac OS X, Solaris, Tru64), and Windows. It is fully ACID compliant, has full support for foreign keys, joins, views, triggers, and stored procedures (in multiple languages). It includes most SQL:2008 data types, including INTEGER, NUMERIC, BOOLEAN, CHAR, VARCHAR, DATE, INTERVAL, and TIMESTAMP. It also supports storage of binary large objects, including pictures, sounds, or video. It has native programming interfaces for C/C++, Java, .Net, Perl, Python, Ruby, Tcl, ODBC, among others, and exceptional documentation. | ———â₠¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€Ã¢â‚¬â€- -Contact Information Contact Link | MySQL (mysql.com) | Oracle (oracle.com) | PostgreSQL (postgresql.org) | Phone | 1 (866) 221-0634 | 1 (800) 392-2999 | – | ————————————————- -Limits Max Blob/Clob Size | 4 GB | Unlimited | 1 GB (text, bytea) – stored inline or 2 GB (stored in pg_largeobject) | Max CHAR Size | 64 KB (text) | 4000 B | 1 GB | Max Column Name Size | 64 | 30 | 63 | Max Columns per Row | 4096 | 1000 | 250-1600 depending on type | Max DATE Value | 9999 | 9999 | 5874897 | Max DB Size | Unlimited | Unlimited | Unlimited | Max NUMBER Size | 64 bits | 126 bits | Unlimited | Max Row Size | 64 KB | 8KB | 1.6 TB | Max Table Size | MyISAM storage limits: 256TB; Innodb storage limits: 64TB | 4 GB | 32 TB | Min DATE Value | 1000 | -4712 | -4713 | ————————————————- -Data Types Type System | * Dynamic * Static | * Dynamic * Static | * Dynamic * Static | Integer | * BIGINT (64-bit) * INTEGER (32-bit) * MEDIUMINT (24-bit) * NUMBER * SMALLINT * SMALLINT (16-bit) * TINYINT (8-bit) | * BIGINT (64-bit) * INTEGER (32-bit) * MEDIUMINT (24-bit) * NUMBER * SMALLINT * SMALLINT (16-bit) * TINYINT (8-bit) | * BIGINT (64-bit) * INTEGER (32-bit) * MEDIUMINT (24-bit) * NUMBER * SMALLINT * SMALLINT (16-bit) * TINYINT (8-bit) | Floating Point | * BINARY_DOUBLE * BINARY_FLOAT * DOUBLE (64-bit) * DOUBLE PRECISION * FLOAT * REAL | * BINARY_DOUBLE * BINARY_FLOAT * DOUBLE (64-bit) * DOUBLE PRECISION * FLOAT * REAL | * BINARY_DOUBLE * BINARY_FLOAT * DOUBLE (64-bit) * DOUBLE PRECISION * FLOAT * REAL | Decimal | * DECIMAL * NUMERIC | * DECIMAL * NUMERIC | * DECIMAL * NUMERIC | String | * CHAR * NCHAR * NVARCHAR * TEXT * VARCHAR | * CHAR * NCHAR * NVARCHAR * TEXT * VARCHAR | * CHAR * NCHAR * NVARCHAR * TEXT * VARCHAR | Binary | * BFILE * BINARY * BINARY LARGE OBJECT * BYTEA * LONGBLO B * LONGRAW * MEDIUMBLOB * RAW * TINYBLOB * VARBINARY | * BFILE * BINARY * BINARY LARGE OBJECT * BYTEA * LONGBLOB * LONGRAW * MEDIUMBLOB * RAW * TINYBLOB * VARBINARY | * BFILE * BINARY * BINARY LARGE OBJECT * BYTEA * LONGBLOB * LONGRAW * MEDIUMBLOB * RAW * TINYBLOB * VARBINARY | Date/Time | * DATE * DATETIME * TIME * TIMESTAMP * YEAR | * DATE * DATETIME * TIME * TIMESTAMP * YEAR | * DATE * DATETIME * TIME * TIMESTAMP * YEAR | Boolean | * BOOLEAN * Unknown | * BOOLEAN * Unknown | * BOOLEAN * Unknown | Other | * ARRAYS * AUDIO * BIT * CIDR * CIRCLE * DICOM * ENUM * GIS data types * IMAGE * INET * MACCADDR * See more†º | * ARRAYS * AUDIO * BIT * CIDR * CIRCLE * DICOM * ENUM * GIS data types * IMAGE * INET * MACCADDR * See more†º | * ARRAYS * AUDIO * BIT * CIDR * CIRCLE * DICOM * ENUM * GIS data types * IMAGE * INET * MACCADDR * See more†º | I think it’s pretty obvious that the data speaks for itself. You can’t get any better option unless you want to pay big money for these specific services. When it comes to deciding on which open source web server software to utilize, there are a lot of different options, such as, Apache, LightTPD, NGiNX, Boa, Cherokee, etc. The one that stands out the most is Apache. Apache is the most popular web server to date. It is the leading web server that is used most over all others including open source and non-open source options, such as, Microsoft’s IIS, Google’s proprietary custom servers, NGiNX, AOL, IBM, etc. according to the website www.makeuseof.com. Here is a graph table I found (it’s a little dated) to give you an idea: Apache is the leader because of its functionality, performance, price (it’s free), stability, and security. It has top notch cross-plat forming capabilities so it can be used on numerous operating systems like, Microsoft’s Windows platform, Linux and UNIX based platforms, Macintosh platforms, BSD platforms, IBM platforms, HP platforms, etc. It can basically run on just about all OS platforms. This is ideal in today’s ever evolving business needs and requirements. Some of the best features that an Apache web server offers are as follows: Basic access authentication & digest access authentication, SSL/TLS HTTPS, virtual hosting, CGI, FCGI, SCGI, Java, SSI, ISAPI, runs in user space versus kernel space, Administration console, and IPv4 & IPv6 addressing. Now these are just some of the feature sets that Apache uses. It helps that most, if not all, of these features are security based; which is most important when dealing with IT in any aspect of today’s business world and society itself. There are a lot of different options when it comes to file servers. Some examples are, FileZilla, Samba,  HFS, TurnKey, Cerberus, VSFTPD, etc. As far as what’s the best file server software options it boils down to the company’s needs. I recommend using Samba or FileZilla for a number of reasons. Samba has over 20 years of development and FileZilla has over 10 years of development, They both offer amazing cross-plat forming capabilities on several different operating systems, They are both pretty easy to setup and administer, they both offer great security, and best of all they are free. This is extremely important for a modern business. Also the fact that they are free helps in cutting down company costs and drives up financial gains throughout the entire company. Plus, Samba speaks natively with Microsoft Windows machines and these are typically what most end users use for their operating systems. Now for the open source SMTP server software I recommend using iRedMail. iRedMail offers two different options, iRedMail (which is free) & iRedMailPro (which is a paid version for $299 per server per year) with amazing fully fledged features. The feature include: blazing fast deployment (less than 1 minute), easy to use, security and stability, mind-blowing productivity (uses a very little resources to run), top notch support, absolute control over data (all personal data is stored on company’s hard disk versus some third party storage medium), supports virtualization and non-virtualization software (VMware, Xen, VirtualBox, KVM, OpenVZ, etc. with i386 and x86/x64/ amd64 compatibility), low maintenance, unlimited accounts, stores mail in openLDAP, MySQL, and PostgreSQL, Service and access restrictions, throttling, Anti-Spam & Anti-Virus by de fault, Webmail, backup support, and security (forced password change policy for every 90 days, uses SSL/TLS connections for sending and receiving mail, etc.). The support offered for iRedMail is among the best and in the business world, this is a must. The LDAP server I recommend is Red Hat Directory Server because it offers some of the best features to date. It’s also has some of the best support in the business. It has an amazing reputation as well. Here is a list of the features that it offers: cost-savings, tremendous scalability (Allows 4-way multimaster replication of data across the entire enterprise while providing centralized, consistent data, and allows extranet applications), enhanced security (provides centralized, fine-grained access controls, and utilizes strong certificate-based authentication & encryption.), and amazing productivity (centralizes user identity and  applications for ease of access for administration), you can’t go wrong with using softw are from a nationally known and reputable company like Red Hat Linux. Each user will be put into groups; this will be done to control access to the file system. Each user on the network will have to meet the standards below. Having each user in groups will help manage them, and what they have access and are allowed to do on the server. Each user will have their own partitioned /home directory to reduce impact of the file system. No user should be without a group, any users without groups will only have access to only their home directory. The following is the password policy they will be using: User account Standard users: Restrict reuse of passwords to once per 18 months Set min day for password expire Set max day for password expire every 30 days Set password complexity to require 1 capital letter, 1 lower case letter, 1 number, 1 symbol and must be at least 15 characters long Enforce password policies Ensure all users do not have access to sudo, or su rights  Create groups for all users, and give them allow sups or admins to maintain rights to those groups, and allow them specific path use on sudo (only if needed). This will allow users to access the data they need to complete their jobs. Also with this password system in place, it will ensure they do not use simple passwords or recycle passwords too often. Super users: Rights to manage groups Specific path use of sudo Restrict reuse of passwords Set min day for password expire Set max day for password expire Set password complexity Enforce password policies These will help super users to manage groups and have access to the tools that they need. This also prevents the users from having too much access to the systems. This helps the admin manage groups by allowing them to move users into the correct group or give them access to specific files that they may need access to. Su will only be used by top level admins, and only if something is truly not working. Lower level admins will have sudo access to files they need to have access to. Users will only have read/write access to the files they need access to; the rest will be read only access. Kernel will be locked down and will need admin permission to access. Passwd file will not be accessible by anyone other than top level admins Firewall and iptables will only be accessible by top level admins and super users. Configuring our network in this manner and applying these user access control permissions will cost less money and add a greater level of security. Using this â€Å"Defense in Depth† strategy, we will have multiple layers of security that an attacker will have to penetrate to break the CIA triad.