Showing posts with label system automation. Show all posts
Showing posts with label system automation. Show all posts

Sunday, March 16, 2014

Hackers & Stuxnet: Education & Best Practices can Change Perspectives

Speaking of hackers in general, the video "Creating panic in Estonia" was well done.  It speaks to aspects of cyber security I have touched on personally with peers and users who are generally unaware of how dangerous the Internet can be, and do not understand how they should be protecting themselves and in turn the rest of the user community at large.  The global dependency on the Internet as a necessary aspect of daily life can, and may, eventually lead to its demise.  It used to be seen as a tool, something that made research easier or necessitated more efficient processing of goods and services to customers.  The global Internet is far more interconnected than most people can comprehend.  We, as IT pros and field experts, find ourselves at a unique crossroads when it comes to the cyber realm.  On one hand, we are users who find entertainment and conduct business transactions through the Internet.  We keep in touch with friends, relatives, and associates.  Pay bills and send gifts to people, through the Internet.  We curiously investigate other perspectives on anything we can think of, reachable with a simple search string.  On another hand we develop and/or service information systems and are responsible for ensuring that the users are not their own worst enemy, and the executive stakeholders understand why expenses are necessary to ensure seamless operations while maintaining data security and integrity through digital interactions across the company or across the Internet.  Yet another proverbial fork is that of a hacker.  Not necessarily one that breaks into systems with malicious intent, which are primarily the hackers (criminals) most people hear about, but the white hat hacker who, like the man who works for Kaspersky in Russia, looks to improve the quality and safety of the Internet.  In order to beat a hacker, one must be able to think like a hacker, and have the intimately specific knowledge of software and systems, how they interconnect, and how users interact with them.  This whole-view perspective on digital communications is necessary in order to properly safeguard oneself, and also the global user community.  Education and repetitive reinforcement have been the successful combination for me in getting users at all levels to start to invest in cyber security and take a different view on what they share on the web.  People contact me regularly to clean infections from their systems and networks.  Unfortunately, most of these users are of the mindset that "it should just work, and never give me problems, regardless of what I do" which has no substantive basis in reality.  In reality, it takes the combination of dozens, if not hundreds, of software applications to make a system function the way it does today.  Since no user situation is ever the lab-tested "ideal" situation, users must be educated on not only how to use their system, but a basic level understanding of how their use affects everyone connected to their system, and the subsequent systems the collective interacts with.  As experiences and exposure to different interactive scenarios manifest, continued education is the key which not only makes a better user but a better system as a whole.

The Stuxnet event could have been avoided with the right engineer designing security protocols, establishing policies, and integrating hardware solutions designed specifically at denying access to unauthorized devices on a network.  Granted, Estonia may not have had access to the technology necessary to affect such a system, but those types of systems do exist.  It is this reason why companies like SymantecMcAfee, and Kaspersky have integrated a feature into their anti-everything software packages to instantly scan any removable device attached to a protected system.  Granted, the Stuxnet did not yet have a known signature and thus could not be specifically scanned for, but those packages also have zero-day detection capabilities, meaning they have an algorithm designed into the software to detect virus-like patterns and flag them as suspicious - which is how Stuxnet was ultimately found, through a zero-day detection algorithm.  While they are highly effective, they can only be detected on a system with this type of software installed.  Unfortunately, there is a large number of users who do not have protective software, let alone hardware solutions, installed in their systems and/or networks which leaves them, and anyone they connect to, highly vulnerable.  Here again, education is the key - once the people can be made to understand the risks involved, they will be willing to learn how to best safeguard themselves, which protects everyone else they interact with digitally.  It is like getting an immunization for a disease - if everyone gets the shot, then no one can transfer it or get it from someone who is infected or has not had their immunization.  The shot cures any carriers of the disease, prevents spreading of the disease to others, and does not allow the inoculated to become carriers again.  That is the same philosophy of security software, and important for the same reasons.

~Geek

Reference: Video On Demand - http://digital.films.com/PortalPlaylists.aspx?aid=7967&xtid=50121&loid=182367

Sunday, March 9, 2014

A discussion about RFID


My class is talking about the viability of using RFID technology to subnet networks as an alternative to moving away from IPv4 because IPv6 is so complex, so I did some research.

The Internet is running out of public IP addresses to assign to websites and devices publicly connected to the Internet.  The current standard in use, IPv4, supports about 4.3 billion addresses (2^32), with more than 588 million of those assigned to the private address range which is not routable on the public Internet (you see those ranges in your office or home LAN). The next version of the IP protocol is IPv6, which supports 3.4 x 10^38 (340 undecillion) (2^128) unique addresses in total, but only 42 undecillion (2^41) have been made available at the moment by ICANN...that is enough for about 4,096 unique IP's per person in the world, assuming 8 billion souls and /48 allocations by ISPs.

One of my classmates proposed that we use RFID chips embedded in a person to enable subnetting of devices they use; such as computers, tablets, smartphones, game systems, appliances, along with NFC (Near Field Communication) tags that use the RFID tag for systems access, even opening your front door and paying for groceries, etc. - using the RFID tag in the person as the host with the public IPv4 address, and the private IPv4 range for anything that connects through the tag.  All device communications go through the RFID chip embedded in the person to some access point or NAT device.

While in concept the idea seems logical and relevant to the future of interactivity through a relatively cheap tech to work with (averaging between $0.05-$0.17 per RFID tag) that has a broad range of possibilities, I do not think this is a viable alternative to avoid moving to IPv6.  Two primary reasons stick out in my mind as to why: 1) That I know of our can find, RFID technology does not contain the logic processing, nor the physical hardware capacity, to negotiate the infrastructure methods necessary to make this plausible, especially when implanted in a human (biochemical considerations), and 2) a highly sensitive consideration of a person's privacy as these RFID tags can store contact details, bank account information, and, with NFC sensors/readers installed, your activities.  Most would be fine with this level of invasiveness because it would simplify life interactions across personal and professional spaces (and it in all honesty could), a lot more would not because literally everything you do would be tracked and cataloged for whomever is linked to the system to extract and use for whatever they need the data for.

Assuming security is properly implemented, specific privacy issues resolved, and technological evolution to allow RFID tags to work like this - a hypothetical win-win for all sides - it would only delay the inevitable.  We would still run out of IPv4 addresses sooner than later.  Implanting tags in every person adds nearly 8 billion more unique addresses, which is more than the total capacity of IPv4.  Trying to update a system that embedded (surgically inserted into a person) would cost everyone so much money it would defeat its entire purpose.

Because we only have a couple billion IPv4 addresses left available world-wide, the move to IPv6 is already well under way.  While I like certain aspects of RFID use - retail sales tracking like Wal-Mart uses for automated restock orders, or vehicle tracking used by trucking lines and manufacturers, processing payment through the RFID chip in a credit/debit car, etc., making processes more efficient and effective for their respective purposes -  it scares the crap out of me with the direction a lot of authorities want to take the technology.  I won't go into the conspiracy theory side of RFID (that is a lengthy conversation), but the implication that it will one day be used to track us and all our activities (yes, all of them) is real.  Here's the real question - given the expected future of RFID, would you get chipped, even if only for the purpose of instant access to your medical records and payment for goods and services?

~Geek

References
http://electronics.howstuffworks.com/gadgets/high-tech-gadgets/rfid.htm
http://rednectar.net/2012/05/24/just-how-many-ipv6-addresses-are-there-really/
http://spectrum.ieee.org/semiconductors/processors/the-plastic-processor
http://itknowledgeexchange.techtarget.com/whatis/ipv6-addresses-how-many-is-that-in-numbers/

This blog is only to express the opinions of the creator.  Inline tags above link to external sites to further your understanding of current methods and/or technologies in use, or to clarify meaning of certain technical terms.  Any copyrighted or trademarked terms or abbreviations are used for educational purposes and remain the sole property of their respective owners.


Sunday, October 7, 2012

Integrating Information System Knowledge

Integrating Informations Systems Knowledge within an Organization

The first discussion question for my last class went something like this:

"What is the best approach to integrating IS knowledge domain-specific and professional core competency needs with your organization? Why is this approach better than others?"

After reading my fellow classmates responses, and pondering my own perspectives on the question, here is what I came up with as my response:

The theme I see in my classmates responses mirror my own opinions on this topic - the best approach is to evaluate the IS resource to determine its usefulness, or kind of knowledge, and apply the resource based on the needs and goals of the organization.  As information systems have evolved into the complex and interconnected platforms of the modern era, more domain specific competencies have emerged, resulting in a need for more specialization from IT professionals.  My families business has been scaled down over the past two years due to the economic downturn  however we continue to thrive because of my unique understanding of information systems and how they can help us be more efficient with less knowledge workers for our type of business.  The reason why we remain successful is because of information systems.  Having grown up watching my father and grandfather build the business to what it was after over 60 years (dozens of workers, four locations around the globe, representing more than 100 major brand names for all aspects of construction and hospitality supply), being a part of the downsize effort was sobering.  Before the downsize, our core competencies were spread among departments, much like found at any corporation, based on the level of skill and domain specific knowledge.  Since I am the systems engineer it is my responsibility to connect the dissimilar and unconnected workers to each other   Understanding the core competencies for each position, and its importance to the whole of the company, coupled with my IT experience and system prowess, I was able to create a cohesive environment of wares and solutions that not only integrated all domain-specific workers to the larger whole, but also helped refine our core competencies to what they have evolved into today.  A mostly interchangeable workforce that can be effective and efficient across all knowledge bases.  As another classmate noted, it would be unconventional to have an IT tech move into the accounting role especially within a larger organization, but in small businesses workers need to have a mix of knowledge because more is required by less.  Integrating information systems is the only way to accomplish this with any level of organization and efficiency.  Without properly planned and implemented information systems, and skilled workers to use them, most companies would fail before they get going because they could not remain competitive in the market.  Staying "lean and mean" in modern business is the only way most companies are still around after the harsh economic downturn  and the low cost of technology has enabled them to stay open, as well as pave the way for start-ups to reach a profitable state faster than ever.  The trick is to plan, plan, and plan.  Going into a information system migration/integration takes careful planning, testing, redesigning, retesting, and finally implementation and maintenance.  Trying to integrate the same without a plan almost always results in catastrophic failures.

...damn I love this shit...

Do you have any thoughts on the subject?  Or any questions on my contribution?  Post a comment, let's discuss.


~Geek

Monday, September 27, 2010

Automated Systems: Will Human Interaction go the way of the Dodo?

Recently, a classmate of mine posed the following statement;
"Do you see automated systems advancing in the near future to save developers more money? I understand that most times there needs to be human to human contact, but there has to be some way to take this to the next level. Software applications are replacing ATM's for crying out loud! I see this as another threat to humans' jobs though. I guess you just have to work in the right field." ~Jermaine Edwards


Here's some of my thoughts on the subject - what do you think?
----------------------------------------------------------------------------
Eventually intuitive systems will replace most human to human interaction in the short term, making developers wallets fatter and our lives simpler. Programs will continue to get more complex as the demands of users change and technology advances.  The drawback is reduction in jobs, as was experienced during the first industrial revolution when mass production changed the way everything was done, and who was no longer needed on the manufacturing floor.  As you mentioned, ATM's are being replaced with iPhone apps.  Eventually, I think bank branches will be replaced by full-service, online, interactive banking.  We have robots that build our vehicles - one robot can do the work of 100 men in far less time; robots that perpetually clean our floors and recharge themselves when necessary; planes that can fly themselves around the world without pilot interference, etc..  I think beyond our lifetimes is when true artificial intelligence will be born, like we see in movies today.  Only then do I think will human interaction become obsolete because it will not longer be necessary - an intelligent machine in our life will perform many, if not all, of the functions we perform today, leaving little left for the human to do except system maintenance and maintain physical relationships as desired.  That may be an extreme example, but one that I think has a real chance of eventually becoming reality with the way technology is advancing.  It is a trickle down effect - a new advancement causes a common product to become obsolete which leaves manufacturers without a product to make, distributors without a product to sell, and service providers without a means to an end.  The consumer enjoys the benefit of a great product delivered quicker than ever, but the supply chain dwindles to a computer server and a delivery truck.  This is a profitable arrangement for the manufacturers but leaves everyone that was in the middle stuck to reinvent themselves or close their doors.

There is also another side to this - the green effect, meaning that the reduction in effect on the environment and the effect that has on job availability. As technology advances, so too do the materials they are manufactured from.  Most machines and consumables can be recycled today, or are biodegradable and non-toxic.  Also, the increase in use of Internet based storage and collaboration has significantly reduced the amount of paper output, as well as reduced the quantity of laser toner/ink cartridges used, which further reduces the environmental impact.  This affects the job market as well, automation has a long history of leaving people/industries jobless, such as when mass production was introduced in the early 20th Century and a lot of factory workers were replaced with machines.  As technology advances we invent or refine machines to help us in our endeavors, initially as tools to enhance an experience or quicken a solution.  Now, machines are seen as a necessity of life - for many to keep up with an ever evolving world, for others just to keep track of their daily lives.  Whatever it is used for, humans are more dependant on machines and technology now than we every have been.  Unfortunately, I think a dose of laziness is driving a lot of today's innovations, leaving consumers to sit on their couches, at their desks, or in their cars doing whatever they want, whenever they want. 

As far as working in the right field, IT seems to be a big fit now and in the future.  We must be mindful not to loose control though, what if god forbid every electronic system on the planet went dead and we all had to go back to doing it manually.  Since business has married to technology for a while now, how many companies, and individuals for that matter, do you think could really survive in an old-fashioned world?  My guess, a lot less than any of us think.



Tell me what you think, post a comment below.


-Geek