Tuesday, September 28, 2010

RFID Implementation.


RFID (Radio Frequency Identifier) is an interesting and booming technology in tracking, monitoring and administration in many industries. These RFID devices automatically transmit radio frequency which has a unique serial number for identification that particular devices uniquely. RFDI technology uses few main components in their architecture to provide complete and comprehensive system. Main components are RFID tag, Tag readers, RFID antennas, RFID controllers, RFID premises servers, and RFID integration servers.

RDIF architecture is shown in below diagram for better comprehension.

Implementation of RFID projects needs to be thoroughly planned and organized due to its nature of complexity, cost and needed expertise knowledge. First of all network administrator should have clearly identify the use case of RFID project. Planning, designing, and implementation of RFID project is based on the use case. Hence, meeting all the requirements of users is a great achievement but very difficult task for the implementer due to compatibility of hardware/software, environmental, budget, and organizational structural issues. When implementing RFID project minimum of below points needs to be adequately addressed.

Project objectives must be clearly defined and understood by the RFID team before hand doing anything. To understand clear objectives you need to identify why the organization is required to have RFID implementation, to serve what purpose. Whether it is trying to comply with some regulations or trying to improve productivity, efficiency or cost reduction in long run for their production environment or warehouse. This identification of reasons and setting objectives based on the facts you collected will help having smooth implementation process.

There should be a proper site survey to analyze the current infrastructure to identify places needs implementation of RFID. Selection of RFID product such as RFID tags, RFID readers, RFID antennas, etc need to be determined by the project team to suit the project budget. This is an area where there are lot of questions been rose. Your budget may not be enough to purchase required hardware devices such as RFID tags, RFID readers, etc with expected quality thus, this may leads to improper operation of devices when integrating, mismatch of your requirement or low quality of service. It is important to point out the disadvantages of having a fixed budget which cannot facilitate the organizational main purpose, thus get your budget approved for correct devices or else proceed with compromised budget, which is not recommended. On the other hand make sure your devices that are going to be purchased are well tested and have met quality and compliance standards in industry. There may be other RFID systems already in place in the organization or different system using radio frequency, in these conditions proper investigation should be carried out to identify the interferences that these existing systems may have on the RFID project you are going to implement.

Next step is to align your project to the organizational processes. Your organization’s business in the main concern, and this RFID implementation should benefit to the organization as a whole and improve the processes without adding burden. Due to new RFID implementation there may be a need to process/procedure realignments, adding new process/procedures, removing redundant processes/procedures, etc, which have to be well analyzed and adjusted to suit the business needs and implementation of RFID project.

Software configuration and integration of RFID devices play an important part in the RFID project. All the devices need to place in appropriate places as decided during the planning stage and configure software to connect all RFID devices and meet organization expectations. It is acceptable to start with the default configurations for general purposes applications. But fine tuning to get maximum accuracy and high performance needs well trained professional knowledge.

When all the things are in place monitor how interdependent components behave in the system. For instance all processes, equipments, software, and human aspect of the entire system needs to operate in collaboration to produce better result. Monitor all aspects to identify places where it needs adjustments to smooth the operation of RFID system to improve performance and efficiency.

One main aspect needs to address above all stages is education, awareness and training for users and manage the positive/negative resistance of users. People might have a misunderstanding of that implementation of RFID system will eliminate the human resources in the process which may results in loss of employment. If this situation cannot be managed diplomatically, this might result in a project failure with large amount of financial, and human resources wastage.

Applying RFID in real time or in line process just to serve the purpose of customer compliance is not going to give you a cost effective solution. But if the customer compliance is going to make huge difference in the market place than when it is not compliance, then the implementation is definitely going to give financial advantage. If the customer compliance is not going to add ad impact to your market place, then these are going to add some additional cost to the production due to its implementation of RFID tags. Thus, if the organization can find another a place where they can improve a production process, streamline warehouse operation, or improve logistic services, etc with the implementation of RFID system along with complying customer requirement, then the organization is reaping the true benefit of implementing RFID system.

Saturday, August 14, 2010

Perimeter defense strategies employed on various segments for an internal network.

One of the main aspects of security is to avoid, minimized or defend malicious activities as soon as it detects or take action before hand as appropriate. If this tasks can be achieved from the boarders of your premises and reduce the impact of the risk to the organization, it is the best method. Even though many of us have not considered perimeter defense in-depth, it is becoming very valuable defending strategy for any organization during incident breaches.

Safe-guarding organizational perimeter is an art and a science, which needs to identify all possible perimeter breaches in all the possible angles and applying best solution which balance the financial commitment of the organization and the amount of the risk that the organization can tolerate.

As a beginning of the defense strategy we must analyze the organization’s assets and their importance to the organization’s operation. Thereafter we should analyze and identify the risk factors involved and their impact to the business. When we are preparing the defense strategy consider above analyzed factors and find a balance between them. Deferent departments have different requirements as the defense strategy differ.

Reception area is the mostly frequently exposed area to the general public and there are limited numbers of measures that we can take to restrict access to this area. But in this scenario will look at the internal access to the area rather than the outside access. All internal work forces have basically given privilege of accessing the area since they are trusted by the organization than general public. This privilege can be misused by the employees with malicious intention. Reception area is equipped with important customer contact details, head of departments personal contact details, and access to whole contact detail of all major contacts. If an unwanted individual access these information they can exploit those detail and gain very valuable information. Even misuse of equipments like business telephone lines, international call facilities, can be dangerous and could tarnish the reputation of the organization. To prevent such occurrences taking place this area should be protected even from the internal staff by restricting access to only necessary people, placing the equipments in a secure manner by partitioning the area or separating access from visitors and internal staff.

Finance department should have a more restricted movement of internal staff as well. All organization information is stored in the place and manipulation, copying, or deleting this information has very drastic impact to the business. This could even take down the whole operation of the business and keep the organization out of operation for few days or forever. Free movement to this area by general public is generally restricted by any organizations, thus very marginal consideration is given by access from internal staff. This area’s access privileges can be controlled by company security policies for internal and external people. On the other hand restricting access by means of access controls like finger printing, facial recognition, proximity cards, ID cards, door access systems and monitoring cameras could be useful.

One of the main departments in any organization is the information technology department. This needs to have very strong security defense in place to protect the information. This target can be fulfilled by the implementation of properly planned and tested defense system. Apart from the general security measures placed in other areas in the organization such as security cameras, finger printing and ID cards below measures can be placed. Special security policy for IT department, formal sanction process to penalized the breach of security policies, limit very restrictive permission for IT department, properly laid and practiced backup procedures, maintenance procedures, SLA (Service Level Agreements), training and education for internal staff to understand, practice and obey the IT rules and regulation, man-traps, etc.

Wednesday, March 24, 2010

Why is it important to have disaster recovery and business continuity policy?

Business continuity plan (BCP) is the way in which an organization should recover and restore its organizational function within a predetermined time frame after a total or partial disturbance to its services during a disaster. These disasters can be earthquake, flood, natural disaster, terrorist attack, or any major event which cause a catastrophic event to the organization. In simple terms, BCP is a method of planning strategically to prevent or if possible manage the consequences of a disaster, as a result reduce the consequences to a limit that businesses can absorb.

BCP manual is a printed manual which is stored in a safe place (remote site) which contains names, contact numbers, crisis management staff and other staff details, venders, clients and details of offsite backup site to operate, other important legal documents and business documents, etc. Organizations should make sure their BCP manual is realistic and easy to follow in a crisis situation without adding another burden.

Disaster Recovery Plan is a map of how an organization gets recovered in the event of a major disaster and continues its business. This is a key component in an organizational business continuity planning. Business continuity plan has a broader scope than disaster recovering planning in an IT perspective.

We cannot predict what disaster will happen next and what impact that will have on our business or the patterns in which those disasters are occurring. Businesses have to continue with minimum interruption to survive in the industry. Suppose an organization is faced with a disaster, as a result its network and the communication went down. How can you operate the organization in a situation like this? This is where you see the practicality of investing for a BCP and DRP to backup plan to guide you how to operate in a disaster situation and how to get out of the disastrous situation. BCP guides you during this difficult situation how to find the resources and operate with business till you recover fully from the disaster. DRP is more towards the technology and how to build the normal operation after the disaster is over, while BCP helps to operate the business functions during the disaster’s period.

Project Processes which should be followed when implementing IT Security projects

IT security project require well defined processes because omission and errors can leads to huge security holes. There are quite a lot of processes should define to implement a IT security project. These processes are briefly discussed below.

Acceptance criteria - These is predefined results which can be expected during the security project. These results are agreed y discussing with key stakeholders of the IT security project.

Risk management - you conduct a thorough risk assessment and threat assessment to identify the risk associated with the security project and define in which way those risk can be avoided, mitigate or transfer during and after the project.

Change management - Errors and omissions in security project is hard to avoid but keeping proper track of what went wrong, when, where, how and what measures you take should be properly documented to avoid countering or solve the risk and problems that could occur in future.

Communication procedure - Most importantly the communication has to be managing properly. Project’s key stakeholders and sponsors have to keep informed about the milestones of the project throughout the security project. The process of when, how, who to keep update and at what frequency should to known when starting the security project. Otherwise project manager and team will have a tough time what, when and whom to inform when the security project underway.

Quality management - Quality measured through testing and this should be clearly defined in your quality management procedure. What test methodologies to use, what modules to test, when to test, etc have to be defined in advance. Level of testing required for IT security projects is solely depend on the type of the security project and the severity of the impact to the organization.

Status reporting - Status of the project should be updated to project sponsors and key stakeholders when needed. This frequency of reporting can be agreed during the project requirement phase, where you can discuss the report type required and what frequency they needed.

Escalation procedure - If the issues cannot solved through the normal channels, you need to pass the issue to the next level in the escalation hierarchy to reach a solution. These escalation paths have to be identified accurately and defined clearly in case of an emergency to follow without causing any delay for the project.

Documentation - Every aspect of the project should be clearly documented. This documentation will greatly help in future when managing, monitoring and troubleshooting some errors in the project.

Approval procedures - Approval procedure should include who has the authority to approve for changes in the project. Mostly this will be the project sponsor who makes the decision about the security project. You cannot run here and there to see who should approve the changes in urgent situation. If these procedures are clearly defined, the unwanted delays could be avoided.

Deployment - Deployment procedure should include when and how the deployment should happen. Before the deployment all the affected parties must be informed in advance to avoid unwanted systems problems, this can be address in the communication plan.

Operational procedures - How the security system is monitored during the day to day activities and who is responsible for the maintenance and monitoring of the implemented system is mentioned in the operations procedure. It includes how to manage the security system and to whom to contact in case of any emergency, etc.

Training procedure - Users of the security system should be adequately trained to get the maximum use of the implemented security system. Through training you increase the awareness level of the users and make them responsible for the system, where they can report any suspicious activity.

Sunday, August 16, 2009

Capturing Nature - Sky

These pictures were captured during 2006-2007 using Nokia 6230i.









Data Compression Algorithm - Lampel Ziv

This is a universal lossless data compression algorithm designed by A. Lampel, Jacab Ziv, and Terry Welch, which was published by T. Welch in 1984 as an enhanced version of LZ78 algorithm. Lempel Ziv algorithm is mostly used in compression like gzip, GIF, and V.42 modem standard. There are two algorithms derived from Lempel Ziv algorithms , they are LZ77 and LZ78.

Most data carry a pattern, for instance in an article some letters appear more often than others, data compression techniques uses this method to compress data by replacing repeated letters by adding different short value to it and get a small size than the original data. Reproducing the original data is possible in this lossless data compression method. Lempel Ziv uses an adaptive dictionary; this is created in while the data being encoded. On the other hand it is not required to transmit or store the dictionary since decoder is capable of building the dictionary. The dictionary size can increase infinitely large in theory, although it practice it increased to certain extend and stop. Recommended size of a dictionary is 4096.

Friday, August 07, 2009

What is Data Hiding Analysis ?

Data hiding analysis is the method or the process of searching for the hidden data in the system or the hard disk. Cybercriminals hide the information in the system by thinking that it would not be detected by searching queries or advance forensic data analyzing tools used by forensic investigators. They will use different methods to hide the information or the application that they infect, intend to damage or trying to steal in hidden format inside the hard disk using many varieties of data hiding methods such as using tools like Invisible software or simple method of adding the hidden flag in Windows file system or by adding the hidden attribute (-h) in DOS prompt. In some other cases cybercriminals change the file format of the data so that it appears different to other users. For instance a cybercriminal who is trying to pass out a confidential business data file (MS excel file) might rename it as a picture file and nobody would suspect since this is a totally different file than it looks. Later the cybercriminal will rename the file extension back to the excel format and use it.
On the other hand cybercriminals use steganography techniques to hide data from the authorized users. For example in MS PowerPoint slide add a picture of a “duck” and insert a confidential document and minimize it as much as possible then change the font colour of the words to white and group with the “duck” picture and save and send via e-mail. Everyone will think that sender is transferring a picture of a duck to a friend, but the actual scenario is the cybercriminal is transferring confidential data without anyone noticing any difference.