Quick Search Box

Tuesday, March 17, 2009

Data Retrieval

For meaningful data retrieval, availability of data that has been compiled from various sources and put together in a usable form is an essential prerequisite. On the Internet, a large number of databases exist. These have been put together by commercially run data providers as well as individuals or groups with special interest in particular areas. To retrieve such data, any user needs to know the address/s of such Internet servers. Then depending on the depth of information being sought, different databases have to be searched and required information compiled. The work involved is similar to a search process in a large library; except that this Internet "library" is immense, dynamic, because of regular updating, and entirely electronic. While some skill is required for searching, the user will be able to access, search and check a large collection of servers.

Communication

Communication on the Internet can be online or offline. When some users connect to a single server or an on-line service at the same time, they can communicate in an "online chat". This can be truly "many to many" as in a room full of people talking to each other on peer to peer basis. Alternatively, the users send e-mail to each other which can be read by the receiver whenever he/she finds the time. This is off-line communication, but "one to one" or "one to many". Similarly, it is possible for users to get together electronically with those sharing common interests in "usenet" groups. The users post messages to be read and answered by others at their convenience, in turn all of which can be read and replied to by others and so on.

Applications of Internet

Internet’s applications are many and depend on the innovation of the user. The common applications of the Internet can be classified into three primary types namely: Communication, Data retrieval and Data publishing.

Surfing on the Internet:

Many of the servers on the Internet provide information, specialising on a topic or subject. There is a large number of such servers on the Internet. When a user is
looking for some information, it may be necessary for him/her to look for such information from more than one server. WWW links the computers on the Internet, like a spider web, facilitating users to go from one computer to another directly. When a user keeps hopping from one computer to another, it is called "surfing".
The Internet facilitates "many to many" communication. Modern technology has, so far, made possible communication, "one to many" as in broadcasting; "one to one" as in telephony; "a few to a few" as in telephone conferencing; and "many to one" as in polling. In addition WWW works on "multi-media", and information can be accessed and transmitted in text, voice, sound and/or video. Graphics and interactive communication are two distinctive features of the Internet and WWW.

Uniform Resource Locators

The format of a URL is: protocol/Internet address/Web page address.
The protocol that the Web uses for HTML codes for Web page is HyperText Transport Protocol (HTTP) For example, consider the web page address: http://pages.prodigy.com/kdallas/index.htm.
The http:// specifies that HTTP will be used to process information to and from the Web server; pages.prodigy.com is the Web server’s Internet address; and kdallas/index.htm is the address of the page on the server. Index.htm could have been omitted, because this is the default for the main page within a directory (i.e., kdallas in this example) Within HTML, there is the capability to display information in list or tables and to create forms for users to send information to someone else. In addition, HTML provides the capability to specify graphic files to be displayed. These and other features let a user create complex Web pages.

Monday, March 16, 2009

World Wide Web

The World Wide Web or the Web is a component of the Internet that provides access to large amounts of information located on many different servers. The Web also provides access to many of the services available on the Internet.
The fundamental unit of the Web is the Web page. The Web page is a text document that contains links to other Web pages, graphic and audio files, and other Internet services such as file transfer protocol (FTP) and E-mail.
Web pages reside on servers that run special software that allow users to access Web pages and to activate links to other Web pages and to Internet services. Tens of thousands of Web servers are currently connected to the Internet. A user can directly access any Web page on one of these servers and then follow the links to other pages. This process creates a Web of links around the world and, thus, the name World Wide Web.

ARPANET Objectives

♦ The network would continue to function even if one or many of the computers or connections in the network failed.
♦ The network had to be useable by vastly different hardware and software platforms.
♦ The network had to be able to automatically reroute traffic around non-functioning parts of the network.
♦ The network had to be a network of networks, rather than a network of computers (Hoffman, 1995)
It rapidly became evident that people wanted to share information between networks, and as a result, commercial networks were developed to meet consumer demand. The Internet became the umbrella name for this combination of networks in the late 1980’s .Today’s Internet is somewhat difficult to describe. Essentially, the Internet is a network of computers that offers access to information and people.

History and Background

The history of the Internet is closely tied to the U.S. Department of Defense. The military was a leader in the use of computer technology in the 1960’s and saw the need to create a network that could survive a single network computer’s malfunction. In the 1970’s, the Advanced Research Projects Agency (ARPA) developed a network that has evolved into today’s Internet. The network was named ARPANET and had many objectives that are still relevant today.
Access controls are common form of controls encountered in the boundary subsystem by restricting the use of system resources to authorize users, limiting the actions authorized users can take with these resources and ensuring that the users obtain only authentic system resources.
Current systems are designed to allow users to share their resources. This is done by having a single system simulate the operations of several systems, where each of the simulated system works as virtual machine allowing more efficient use of resources by lowering the idle capacity of the real system. Here, a major design problem is to ensure that each virtual system operates as if it were totally unaware of the operations of the other virtual systems. Besides increased scope exists for unintentional or deliberate damage to system resources / user’s actions.

Threats and Vulnerabilities:

The threats to the security of systems assets can be broadly divided into nine categories:
(i) Fire,
(ii) Water,
(iii) Energy variations like voltage fluctuations, circuit breakage, etc.,
(iv) Structural damages,
(v) Pollution,
(vi) Intrusion like physical intrusion and eavesdropping which can be eliminated / minimized by physical access controls, prevention of electromagnetic emission and providing the facilities with their proper locations / sites,
(vii) Viruses and Worms (being discussed in detail later on),
(viii) Misuse of software, data and services which can be avoided by preparing an employees’ code of conduct and
(ix) Hackers, the expected loss from whose activities can be mitigated only by robust logical access controls.

Sunday, March 15, 2009

Level of Security:

The task of a Security Administration in an organization is to conduct a security program which is a series of ongoing, regular and periodic review of controls exercised to ensure safeguarding of assets and maintenance of data integrity. Security programs involve following eight steps –
(i) Preparing project plan for enforcing security,
(ii) Assets identification,
(iii) Assets valuation,
(iv) Threats identification,
(v) Threats probability of occurrence assessment,
(vi) Exposure analysis,
(vii) Controls adjustment,
(viii) Report generation outlining the levels of security to be provided for individual systems, end user, etc.

Need for security:

The basic objective for providing network security is two fold:
(i) to safeguard assets and (ii) to ensure and maintain the data integrity.
The boundary subsystem is an interface between the potential users of a system and the system itself controls in the boundary subsystem have the following purposes like
(i) to establish the system resources that the users desire to employ and (ii) to restrict the actions undertaken by the users who obtain the system resource to an authorized set.
There are two types of systems security. A physical security is implemented to protect the physical systems assets of an organization like the personnel, hardware, facilities, supplies and documentation. A logical security is intended to control (i) malicious and non-malicious threats to physical security and (ii) malicious threats to logical security itself.

Business Continuity Planning (BCP)

Disaster events: -
(i) There is a potential for significantly interrupt normal business processing,
(ii) Business is associated with natural disasters like earthquake, flood, tornadoes, thunderstorms, fire, etc.
(iii) It is not a fact that all the disruptions are disasters,
(iv) Disasters are disruptions causing the entire facility to be inoperative for a lengthy period of time (usually more than a day)
(v) Catastrophes are disruptions resulting from disruption of processing facility.
A Business Continuity Plan (BCP) is a documented description of action, resources, and procedures to be followed before, during and after an event, functions vital to continue business operations are recovered, operational in an acceptable time frame.

Hot site:

An alternative facility that has the equipment and resources to recover business functions that are affected by a disaster. Hot sites may vary in the type of facilities offered (such as data processing, communications, or any other critical business functions needing duplication) The location and size of the hog site must be proportional to the equipment and resources needed.

Warm site:

An alternate processing site that is only partially equipped, as compared to a hot site, which is fully equipped. It can be shared (sharing servers equipment) or dedicated (own servers) .

Saturday, March 14, 2009

Cold site:

An alternative facility that is devoid of any resources or equipment, except air conditioning and raised flooring. Equipment and resources must be installed in such a facility to duplicate the critical business functions of an organisation. Cold sites have many variations depending on their communication facilities.

Disaster recovery sites

Data centers need to be equipped with the appropriate disaster recovery systems that minimize downtime for its customers. This means that every data center needs to invest in solutions, such as power backup and remote management. Downtime can be eliminated by having proper disaster recovery (DR) plans for mission-critical types of organisations, so as to be prepared when disaster strikes. Some of the larger IT organizations, which cannot tolerate too much downtime, tend to set up their DR site as a hot site, where both the primary and DR sites are kept in real-time synchronization , all the time.

Challenges faced by the management

(i) Maintaining a skilled staff and the high infrastructure needed for daily data center operations:. A company needs to have staff which is expert at network management and has software / OS skills and hardware skills. The company has to employ a large number of such people, as they have to work on rotational shifts. The company would also used additional cover in case a person leaves
(ii) Maximising uptime and performance : While establishing sufficient redundancy and maintaining watertight security, data centers have to maintain maximum uptime and system performance.
(iii) Technology selection : The other challenges that enterprise data centers face is technology selection, which is crucial to the operations of the facility keeping business objectives in mind. Another problem is compensating for obsolescence.

Leveraging the best

In both enterprise/captive and public data centers, the systems and infrastructure need to be leveraged fully to maximize ROI. For companies that host their online applications with public data centers, in addition to the primary benefit of cost savings, perhaps the biggest advantage is the value-added services available. Enterprises usually prefer to select a service provider,
which can function as a one-stop solution provider and give them an end-to-end outsourcing experience.
Data centers need to strike a careful balance between utilization and spare infrastructure capacity. They need to be able to provide additional infrastructure to their customers who wish to scale their existing contracts with little or no advance notice. Thus it is necessary that there be additional infrastructure at all times. This infrastructure could include bandwidth and connectivity, storage, server or security infrastructure (firewalls, etc.)

Constituents of a Data Centre

To keep equipment running reliably, even under the worst circumstances, the data center is built with following carefully engineered support infrastructures:
• Network connectivity with various levels of physical (optical fibre and copper) and service (both last mile and international bandwidth) provider redundancy
• Dual DG sets and dual UPS
• HVAC systems for temperature control
• Fire extinguishing systems
• Physical security systems: swipe card/ biometric entry systems, CCTV, guards and so on.
• Raised flooring
• Network equipment
• Network management software
• Multiple optical fibre connectivity
• Network security: segregating the public and private network, installing firewalls and intrusion detection systems (IDS)