Ginagawa mo dito? ^-^
Thursday, July 27, 2017
Learning Log for Information Systems Security: Week 7 and 8 (Defense Break)
In Week
7, we had discussed ethics. Concepts, cultural norms, ethical issues, etc.
Social media is I think the focus of this discussion and I think all is applied
for the cyber world. The Code of Ethics that I’ve learned from Sir JP is somewhat
similar to the Ethics of life that can be applied for real world scenario, like
protect society/commonwealth/infrastructure, act honorably/honestly/justly/responsibly/legally,
provide diligent/competent service to principals, advance/protect the
profession. The Six ethics of life is that before you speak - listen, similar
in protecting society; before you write – think, similar to act honorably;
before you quit – try, similar in providing diligent; and lastly, before you
die – live; similar in protect the profession in your limited given life. By
the way there were only five given, but the original is six. In this week,
ethics of hacking back was discussed and until now, I still don’t have a
concrete answer from the generated questions coming from the discussion of Sir
JP, maybe because understand it vividly. For me, hacking back is just a premade
trap just waiting for its prey and it is applicable for anyone whom who thinks
the same and I think that hacking back should be avoided. For the Week 8, we
had discussed the six arguments relating to the controversial of hacking back.
I wouldn’t explain these six arguments, but I’ll just provide a brief summary.
The argument must be under the law and it shouldn’t exceed its boundaries with
a purpose of replying a self-defense protocol without becoming one of the
hackers and making sure that you have the knowledge of who is attacking you.
Cyber attacks could happen abroad and this questions what kind of jurisdiction
do you have with a public health issue is in question like if it could help you
in your daily life and if your actions are practically effective. Also in this
week, we are preparing for a debate on Monday, Jul 31 wherein our topic is
Internet Censorship, that we are siding for the government. I really don’t know
if we would win the debate, but we will do our best to secure that this motion
would be positively implemented and also our machine project was given to us
for finals.
Thursday, July 13, 2017
Learning Log for Information Systems Security: Week 5 and 6 (Present Defense)
For
the week 5, I was surprised that we will be using Cisco Packet Tracer all over
again and my last use of this was last year. I and my group could not cope up
with the exercise given to us because all of us had really forgotten all about
this, but we didn’t just sit and wait, we asked for help and I mean all the
help we can get to finish this exercise. After 4 days, we had done the exercise
and sent it to our professor Sir JP and before finishing it, we struggled hard
mainly in the setup region because this is the part wherein all the connections
should be receiving packets from all the devices vice-versa. For the next week,
we had discussed all about the Legal Issues and the background of Privacy,
which for an instant was very shallow, but after an hour my perception had
changed. Let’s first start with Legal Issues, this discusses different kinds of
cyber crime and its law for both U.S. and Philippines. I enjoyed studying the
difference between the Civil Law and the Criminal Law, I thought first for
Civil Law because it rings a bell in my mind which is the Civil War in Captain
America’s movie that in the same concept, it needs two parties in the
discussion where both have their own perception about a subject. The Criminal
Law that I truly hate is that the bulleted point in the PDF file is “To convict
someone, the crime must be proven beyond any reasonable doubt” proof is really
highlighted in this sentence which I think is practiced with the same concept
in any judicial courts. For the Privacy discussion, I could not really explain
the way I remembered it explaining to us by Sir JP, but for my perception that
I’ve summarized is that Privacy is neither Good or Bad because for every
Privacy created, it will really create a rift(metaphorily speaking) in the
society and its up to us to see a side of it where would fit in our standard of
perception to that topic. I really don’t know the answer, but my guess is
Privacy is unfathomable. Today, our team would be focusing in the development
of our Midterm Presentation about Bitcoin and the reality is we are nearly
done.
Thursday, June 29, 2017
Learning Log for Information Systems Security: Week 3 and 4 (Organizational Security)
In the past 2 weeks, all we think about is the preparation
for midterm paper mainly the related literature connected to our topic which
is the Bitcoin. At first, I really don’t want to participate with my groups due
to other activities that I am attending but because of perseverance, I had done
my part when I found time for doing it. Sometimes the things you do might be
boring to you but, looking at the bright side lets you see the brighter side or
the positive side. Coincide with the preparation of the paper is our
discussion, which is the Organizational Security. For the Week 3, I have
learned that the security hierarchy are based on the organization’s priority,
policies and ethics. The Operational Model are planning, implementing,
monitoring, and evaluating which is a never ending cycle if maintenance for the
security will be conducted. We discussed much policies in an organization and
the thing that I am fascinated about is that there are some policies wherein
power in the company is not an option, meaning equality was established in this
policy for example, IUP or Internet Usage Policy, which is the connectivity of
all the members in the organization in the internet. We also discussed the 3
types of Model, Sir JP said that there are 30 Model, but we focused for 3
models only because this are most commonly used in the organization. Let us
start with Bell La Padula Model, with a misconception of Bella Padilla based on
first time encounter, that is a confidentiality model that has the rules of
simple security rule that doesn’t allow to read security higher or different
from your department; Star property that cannot write security if lower or
different from your department. Next is Biba Model which is the integrity model
that has a simple integrity rule that is the contrast of Bell La Padula and
also the star property. Last is the Clark-Wilson Model is an integrity model
and it uses a medium for its security. This discussions are all done for the
Week 3 because Week 4 was dismissed due to different kinds of events. For Week
4 first meeting, It is the end of Ramadan and Muslims had to celebrate it
despite of the war in Marawi City. Second meeting, Sir JP told has that his not
feeling well and unable to tutelage us for this period, so he cancelled that
session, this really broke my heart. Take Care and Get Well Soon Sir JP!
Thursday, June 15, 2017
Learning Log for Information Systems Security: Week 1 and 2 (Information Security)
Another
year another term, same professor same activity, but this professor is the BEST
in terms of Computer Networking and Security and I wouldn’t write his name here
due to the privacy of that professor, but we can call him Sir. JP. For our
first meeting, we were astonished that our past professor will be our current professor
for computer security, so in an instance, we clapped so hard and preached his
name like watching a live Fliptop battle, Sir JP!3x. After a few minutes of
idolization and homecoming, we began to study the scopes of information
security and I began to review my current knowledge about this topic and began
to cope up with the new knowledge that I am receiving. Sir JP has summarized
all his knowledge for just the title and just small amount was absorbed, and
the good thing is we are just in the title portion far from the real
integration of information security. Confidentiality, Integrity and
Availability are the first bulleted points that I have written in my notebook
and with these 3 items, I could feel the real vibe of information security. I
learned the Security Architecture is almost the same with the 7 levels in the
past networking lessons. Sir JP taught us the strong and the weaknesses of
information security if vivid knowledge was not apprehended and also the
offensive and defensive process in the system. The most interesting part of the
discussion is the authoritarian level of security wherein there are certain
levels that cannot be accessed by an ordinary person but a higher level can
access it. Sir JP had given us a case event wherein we will analyze the problem and
we must fill in the necessary requirements for the case. For the sake of the
shortness and the ending of this post in the case that was given to us stating
in the Recommendation section, in my personal opinion, if DDoS attack happen,
have a different kind of brand for your security device because not only do you
see the error but you also segregate the rotting security devices from others.
Thursday, December 15, 2016
Learning Log for Data Networks: Week 12 and 13 (Huling Paalam)
Sa huling pagkakataon ko sa paggawa ng "Learning Log for Data Networks" ay naisipan kong magsalita ng tagalog dahil alam ko na ito'y magiging mataimtim at ito'y tatagaos sa puso ng aking mambabasa. Hindi naman sa nagbibiro pero seryoso kong sinasabi na maraming akong natutunan sa aking guro. Para sa dalawang linggo kong pag-aaral ng Routing Information Protocol(RIP) ay natutunan ko na ito'y medyo madali kaysa sa natutunan ko noong nakaraang dalawang linggo na gumagamit ng "Static Routing" kung saan kailangan magkakaroon ng komunikasyon ang dalawang computer na konektado sa kani-kanilang router na nakonekta sa isang router na gagawa ng isang mahabang komunikasyon. Kung ihahalintulad mo sa pag-aaral ng database, ito'y tinatawag na isang bridge entity na tumatanggap at nangangasiwa ng komunikasyon sa bawat router na nakakonekta rito. Balik tayo sa RIP, sobrang taas ng ngiti ko sa pakikitungo ko rito dahil ang mga pangitain nito ay sobrang dali sa level na naiintindihan at mauunawaan ko. Nagustuhan ko ang "hop count" kung saan ay ito'y nagpapasa nang komunkinasyon sa ibang mga computer sa bilang ng labing-anim na kung saan ang pinaka-huling laktaw kung hindi pa napupuntahan ang pinaka-destinasyon ay ito'y tutukuyin bilang isang "dead packet" na sinasabing wala nang kwenta ang komunikasyon. Pinapansin rin nito ang ang iba't ibang oras sa pagdating ng komunikasyon; simula tayo sa "Hold down timer:" kung saan naghihintay ito ng tatlong minuto, pagkatapos noon at babasahin ang kumunikasyon. "Flash Timer:" kung saan ito ay nagdagdag ng isa pang minuto na kapareho ng hold down timer. "Invalid Timer:" kung saan ito ay nagbabasa ng anim na beses at kung walang nakita ay ito'y magiging mali. At ang huli, "Update Timer:" kung saan ito'y nagbabasa pagkatapos ng trenta minutos. Oo marami pa akong natutunan pero iigsian ko na dahil pag naglagay ako dito ay sinisigurado ko na tama at ito'y aking nasiyasat at napag-aralan ng husto, yung tipong nagresearch. Tatapusin ko na itong "Learning Log" pero bago iyon, mag-iiwan ako ng mensaheng galing sa puso na hindi pa nagtatanghalian upang pag-isipan ito. MARAMING SALAMAT PO SIR JUSTIN!!!! dahil sa inyong mga turo ay mas naunawaan ko ng mataimtim ang buong katauhan pag sinabi ang salitang "INTERNET", dati kasi hindi pag connected sa wifi yun na yun, pero dahil sayo sir ngayon ay alam ko na kung paano mag-ayos ng ip address, DNS, Default Gateway, etc. Salamat Sir! Mag-iingat ka lagi. ^_^
Friday, December 2, 2016
Learning Log for Data Networks: Week 10 and 11 (Capsa Free)
For the past 2 weeks, we had learned much information again
about data networks that our professor said that it would take a 1 term to
study but in our case, we would study it for maybe 3 weeks or so. In this minimal
time, we had to gain much knowledge that we could because the finals is coming
and I could feel that our final examination would be hard because I could see a
bright smile in our professors face. Before I would go for the gained
knowledge, I would tell you all about what happen in the late week 9, what
happened is we are about to do the final project of our professor, which tells
about a sniffing software given to each group. Our software was very simple and
the user interface are very unique however, we are using the free version and
the given free interfaces are very few. For me, I would want to know more about
the software and sniff different kinds of module in that software. The free
version really underlines the word free because it restricts us for every move
we take and sometimes limits are action while using the software, but thank God
we had finished the project and also I remember that +20 for the groups who
would present in that week and the succeeding weeks will decrease by 5, and we
had presented early and got a +15. With the use of the YouTube videos tackling
our software, I have learned different kinds of the uses for the module that
are enterprise based and could not be used in the free version and it made me
understand deeper what am I doing with the software. Now let’s go back to the
discussion, we had studied the Chapter 10 that our professor prepared and it
tackles a review for connecting a router to a PC, the introduction to network
layer, and some knowledge about internet data connectivity. I learned about
Static Routing which uses a so called an ISP for a big connection, Dynamic
Routing which contains many protocols that I don’t want to mention it all and
many more. The most enjoyable topic that I can’t really much understand is the
Static Routing wherein the connection is router to router which has the same
time connectivity and same type of connection, we had some exercises about this
using the Cisco packet tracer and thank you to my listening skills, I have
learned this topic just after 2 meetings of our data networks subject. This
kind of connection is really new to me because all I use when using the packet
tracer is just cross and straight connection, and I don’t really this kind of
connection that needs configurations for both routers.
Thursday, November 17, 2016
Learning Log for Data Networks: Week 8 and 9 (WireShark)
A week has passed and the ache had been encountered and moved on, but there are still such ache that still remains in my mind like when I think about how I delivered my role in the defense and how I made some choking sensation during that Thursday morning, November 10, 2016. And even after that, we still had to make some revisions with our final paper, but we are able to revised it in time and attained all the expectations of our professor towards our proposed Quality of Service proposition. Also in that day, our professor has taught us about a software that can sniff packets in the internet and this software is called "WireShark". At first I could not really apprehend all the inputs in that software because I really don't know the meaning in all those numbers. In my case, I know what we have to look in that software when sniffing and that the words "syn, syn-ack, syn" in a chronological order and knowing that may help you understand what you are sniffing, but for me this are just words that are yet to be discovered. After a while of trying, asking tons of questions to our professor, sniffing different kinds of websites, making sure that our professor doesn't leave my side for him to help me all the way, and showing me the right algorithm. Finally, I have found the what I was looking for, the "syn, syn-ack, syn" in the monitor and I am happy to say that I have done something right not knowing that this was right all along before our professor had taught me the right way. If I remembered it correctly, the right way of using the software is first, open the WireShark and then click the Ethernet interface because we are using a cabled internet. Then, we run the WireShark to sniff then open the prescribed website for the activity. After that, we open the Command Prompt to ping the ip address of the prescribed website then and there we had learned the ip address. Then, we open again the WireShark and inputed in the search bar "ip. addr == (insert ip address) click enter then we click the Time header then the answer was there, Used snippet tool to crop the image of the "3 way handshake" then put it in the powerpoint presentation, but it is not yet completed and we have to fill in the theoretical part. In the day of November 14, 2016, we redone our Exercise 6 and answer the theoretical part and fill in the remaining errors, then that wraps it all up.
Subscribe to:
Posts (Atom)



