My experience on my daily works... helping others ease each other

Sunday, December 4, 2011

Slide for IAS 2011 - Draft Completed

Completed my slide presentation which scheduled to be presented in IAS 2011 @ UTeM, Melaka on 6th December 2011. If you are nearby, please do stop by to see my presentation or we can have a chit-chat session after that. :)

By the way, this time around, I'm going there as UiTM student and will be presenting as UiTM student's since it is much related to my study rather than my work. I'll be sharing the slide and the papers link once I get the link ready :). Meanwhile, if you are interested to view my publications, just click on List of IPs and Publication tab or here.
Share:

Saturday, December 3, 2011

Bill Gates: Trustworthy Computing

This is the e-mail Bill Gates sent to every full-time employee at Microsoft, in which he describes the company's new strategy emphasizing security in its products.
From: Bill Gates
Sent: Tuesday, January 15, 2002 5:22 PM
To: Microsoft and Subsidiaries: All FTE
Subject: Trustworthy computing

Every few years I have sent out a memo talking about the highest priority for Microsoft. Two years ago, it was the kickoff of our .NET strategy. Before that, it was several memos about the importance of the Internet to our future and the ways we could make the Internet truly useful for people. Over the last year it has become clear that ensuring .NET is a platform for Trustworthy Computing is more important than any other part of our work. If we don't do this, people simply won't be willing -- or able -- to take advantage of all the other great work we do. Trustworthy Computing is the highest priority for all the work we are doing. We must lead the industry to a whole new level of Trustworthiness in computing.

When we started work on Microsoft .NET more than two years ago, we set a new direction for the company -- and articulated a new way to think about our software. Rather than developing standalone applications and Web sites, today we're moving towards smart clients with rich user interfaces interacting with Web services. We're driving the XML Web services standards so that systems from all vendors can share information, while working to make Windows the best client and server for this new era.

There is a lot of excitement about what this architecture makes possible. It allows the dreams about e-business that have been hyped over the last few years to become a reality. It enables people to collaborate in new ways, including how they read, communicate, share annotations, analyze information and meet.
However, even more important than any of these new capabilities is the fact that it is designed from the ground up to deliver Trustworthy Computing. What I mean by this is that customers will always be able to rely on these systems to be available and to secure their information. Trustworthy Computing is computing that is as available, reliable and secure as electricity, water services and telephony.

Today, in the developed world, we do not worry about electricity and water services being available. With telephony, we rely both on its availability and its security for conducting highly confidential business transactions without worrying that information about who we call or what we say will be compromised. Computing falls well short of this, ranging from the individual user who isn't willing to add a new application because it might destabilize their system, to a corporation that moves slowly to embrace e-business because today's platforms don't make the grade.

The events of last year -- from September's terrorist attacks to a number of malicious and highly publicized computer viruses -- reminded every one of us how important it is to ensure the integrity and security of our critical infrastructure, whether it's the airlines or computer systems.

Computing is already an important part of many people's lives. Within 10 years, it will be an integral and indispensable part of almost everything we do. Microsoft and the computer industry will only succeed in that world if CIOs, consumers and everyone else sees that Microsoft has created a platform for Trustworthy Computing.

Every week there are reports of newly discovered security problems in all kinds of software, from individual applications and services to Windows, Linux, Unix and other platforms. We have done a great job of having teams work around the clock to deliver security fixes for any problems that arise. Our responsiveness has been unmatched -- but as an industry leader we can and must do better. Our new design approaches need to dramatically reduce the number of such issues that come up in the software that Microsoft, its partners and its customers create. We need to make it automatic for customers to get the benefits of these fixes. Eventually, our software should be so fundamentally secure that customers never even worry about it.
No Trustworthy Computing platform exists today. It is only in the context of the basic redesign we have done around .NET that we can achieve this. The key design decisions we made around .NET include the advances we need to deliver on this vision. Visual Studio .NET is the first multi-language tool that is optimized for the creation of secure code, so it is a key foundation element.

I've spent the past few months working with Craig Mundie's group and others across the company to define what achieving Trustworthy Computing will entail, and to focus our efforts on building trust into every one of our products and services. Key aspects include:
Availability: Our products should always be available when our customers need them. System outages should become a thing of the past because of a software architecture that supports redundancy and automatic recovery. Self-management should allow for service resumption without user intervention in almost every case.

Security: The data our software and services store on behalf of our customers should be protected from harm and used or modified only in appropriate ways. Security models should be easy for developers to understand and build into their applications.

Privacy: Users should be in control of how their data is used. Policies for information use should be clear to the user. Users should be in control of when and if they receive information to make best use of their time. It should be easy for users to specify appropriate use of their information including controlling the use of email they send.

Trustworthiness is a much broader concept than security, and winning our customers' trust involves more than just fixing bugs and achieving "five-nines" availability. It's a fundamental challenge that spans the entire computing ecosystem, from individual chips all the way to global Internet services. It's about smart software, services and industry-wide cooperation.

There are many changes Microsoft needs to make as a company to ensure and keep our customers' trust at every level -- from the way we develop software, to our support efforts, to our operational and business practices. As software has become ever more complex, interdependent and interconnected, our reputation as a company has in turn become more vulnerable. Flaws in a single Microsoft product, service or policy not only affect the quality of our platform and services overall, but also our customers' view of us as a company.
In recent months, we've stepped up programs and services that help us create better software and increase security for our customers. Last fall, we launched the Strategic Technology Protection Program, making software like IIS and Windows .NET Server secure by default, and educating our customers on how to get -- and stay -- secure. The error-reporting features built into Office XP and Windows XP are giving us a clear view of how to raise the level of reliability. The Office team is focused on training and processes that will anticipate and prevent security problems.

In December, the Visual Studio .NET team conducted a comprehensive review of every aspect of their product for potential security issues. We will be conducting similarly intensive reviews in the Windows division and throughout the company in the coming months.

At the same time, we're in the process of training all our developers in the latest secure coding techniques. We've also published books like Writing Secure Code, by Michael Howard and David LeBlanc, which gives all developers the tools they need to build secure software from the ground up. In addition, we must have even more highly trained sales, service and support people, along with offerings such as security assessments and broad security solutions. I encourage everyone at Microsoft to look at what we've done so far and think about how they can contribute.

But we need to go much further.

In the past, we've made our software and services more compelling for users by adding new features and functionality, and by making our platform richly extensible. We've done a terrific job at that, but all those great features won't matter unless customers trust our software.

So now, when we face a choice between adding features and resolving security issues, we need to choose security. Our products should emphasize security right out of the box, and we must constantly refine and improve that security as threats evolve. A good example of this is the changes we made in Outlook to avoid e-mail-borne viruses. If we discover a risk that a feature could compromise someone's privacy, that problem gets solved first. If there is any way we can better protect important data and minimize downtime, we should focus on this. These principles should apply at every stage of the development cycle of every kind of software we create, from operating systems and desktop applications to global Web services.

Going forward, we must develop technologies and policies that help businesses better manage ever larger networks of PCs, servers and other intelligent devices, knowing that their critical business systems are safe from harm. Systems will have to become self-managing and inherently resilient. We need to prepare now for the kind of software that will make this happen, and we must be the kind of company that people can rely on to deliver it.

This priority touches on all the software work we do. By delivering on Trustworthy Computing, customers will get dramatically more value out of our advances than they have in the past. The challenge here is one that Microsoft is uniquely suited to solve.

More discussion of our vision for Trustworthy Computing is in the internal white paper.

Bill

Copy from http://www.wired.com/techbiz/media/news/2002/01/49826
Share:

Friday, December 2, 2011

Effective and Easy Learning Method - 2


Click Register to start you registration process or fill up the form below and submit.

Share:

Effective and Easy Learning Method - 1


Click Register to start the registration process or fill up the form below and submit.


Share:

Saturday, November 19, 2011

6 Sigma Belt tools

List of tools to be used for 6 Sigma Belt

http://6ixsigma.org/toolbox.aspx


Share:

Friday, November 18, 2011

Understanding the security framework behind RSA SecurID

An article published in EET which the author shares his view on weaknesses of RSA SecurID [read].

In this article, the author claims that there is vulnerability that can be used by attackers to gain access on system using RSA SecurID. I've yet to verified this but still I don't think that RSA SecurID or any of token-based security is secure enough. It shall be implemented with few security mechanism on top of that to tighten the security. Or else, someone might found a way to exploit it. :)
Share:

Cyber warfare - Is it myth or real?

Although involving mainly information theft, cyber warfare can endanger lives at many levels and is a reality that's here to stay, warn security observers [read more]

The topic had been discussed withing security community since many devices are inter-connected. Shared by experience renowned speaker it came to the question of it is true or it is just a myth created by security corporation to create interest within people.

From my perspective, it is true rather than a myth. We have seen attack on SCADA system by Stunet Virus (Symantec). There was also various reports such as by Mocana Corporation whom shares their analysis on attacks on mobile devices, Verizon whom analyzed on data breach in 2011, and lots more. All this indicates one things, CYBER WARFARE is TRUE.

In a keynote speech by a renowned speaker in information security at WEC 2010, he mentioned that as the real world are becoming overlapping with cyber world (with lots of devices are becoming an important interactive and interconnect mechanism), there is possibility of becoming are target for exploitation, hacking, attacks, etc and that my cost life.

From my own view :)
Share:

Monday, November 7, 2011

Samsung, Apple, Amazon, Perfect 10: Intellectual Property

An interesting articles by Victoria Slind-Flor about the on-going battle between Apple Inc and its rival (Samsung, HTC, etc...) and published in Bloomberg. (read it here).

This is something Microsoft have been fighting for the last few decades on its monopoly of OS. Should this be the same case or something else. In any case, as user, I do hope it will still benefit us the most :)
Share:

Friday, November 4, 2011

First recorded Virus - Brain

It was not developed by US or Europe guy, instead it was developed by brothers of Pakistani. It was released in 1986 with no intention to be virus (claimed by the brothers). However, it do cause havoc in software security world.

Nevertheless, it do triggers others to develop malware until today.... read the full story here.

But their virus was not as dangerous as Morris worm developed by Robert Morris Jr which become the first ever virus exploiting vulnerabilities and causing massive 'traffic-jam' on network.
Share:

List of IPs and Publications

IP
2013
  1. Nurul Haszeli Ahmad, Fazli Mat Nor, Nagendran Parumalai, System and Method to Secure Distribution and Execution Software Libraries, MyIPO (submitted), 2013
2012
  1. Nurul Haszeli Ahmad, Fazli Mat Nor, Nagendran Parumalai, Automatic Transformation of Non-Relational Database Into Relational Database, MyIPO, PI 2012005266, 2012
2011
  1. Arniyati Ahmad, Mohd Faizal Mubarak, Nurul Haszeli Ahmad, Secure External Storage System and Method Thereof, US patent, WO2012050421 A1, PCT/MY2011/000121, 2011

2010
  1. KPI Management System (14 Copyrights and Trade Secret)
  2. Project Q (6 Trade Secret)


2009
  1. Project Prihatin (6 Copyrights and Trademarks)


Publications
2013
  1. Nurul Haszeli Ahmad, Syed Ahmad Aljunid, Jamalul-lail Ab Manan, “Vulnerabilities and Exploitation in Computer System - Past, Present and Future”, SiSKOM 2013 (ISBN 978-967-12088-0-9), Universiti Teknologi Mara, Shah Alam, Selangor, Malaysia, 3rd - 4th Sep 2013
2011
  1. Noor Nashriq Ramly, Nurul Haszeli Ahmad, Mohd Haris Aziz, “Comparative Analysis on Data Visualization for Operations Dashboard”, International Journal of Information and Education Technology. IJIET 2012 Vol.2(4): 287-290 ISSN 2010-3689. Published by IEEE
2011
  1. Nurul Haszeli Ahmad, Syed Ahmad Aljunid, Jamalul-lail Ab Manan, “Understanding Vulnerabilities by Refining Taxonomy”, IEEE, 7th International Conference on Information Assurance and Security (IAS 2011), ISBN 978-1-4577-2154-0, page 25 – 29, Melaka, 5th – 8th December 2011 
  2. Nurul Haszeli Ahmad, Syed Ahmad Aljunid, Jamalul-lail Ab Manan, “Classifications and Measurement on C Overflow Vulnerabilities Attack”, International Journal of New Computer Architectures and their Applications (IJNCAA), Vol. 3, No 1, 2011 
  3. Noor Nashriq Ramly, Ahmad Zuhairi Ismail, Mohd Haris Aziz, Nurul Haszeli Ahmad, “Operations Dashboard: Comparative Study”, SPIE Digital Library, Proceeding SPIE 8285, International Conference on Graphic and Image Processing (ICGIP 2011), Volume 82853, DOI:10.1117/12.914400, October 01, 2011, Cairo, Egypt 
  4. Nurul Haszeli Ahmad, Syed Ahmad Aljunid, Jamalul-lail Ab Manan, “Taxonomy of C Overflow Vulnerabilities Attack”, Journal of Software Engineering and Computer Systems, Communications in Computer and Information Science Series, Vol 180, Springer Berlin Heidelberg, Proceedings of Second International Conference ICSECS 2011, pp 376-390, ISBN 978-3-642-22190-3, Kuantan, Pahang, Malaysia, June 27-29, 2011
2010
  1. Nurul Haszeli Ahmad, Syed Ahmad Aljunid, Jamalul-lail Ab Manan, “Preventing Exploitation on Software Vulnerabilities – Why Static Analysis Failed?”, Proceeding of World Engineering Conference (WEC 2010), Kuching, Sarawak, 2010
  2. The Taxonomy, Exploitation Techniques, and Preventive Measurement on Classical Exploitation of Software Vulnerabilities (abstract submitted to WEC 2010)
  3. Implementation of Trustworthiness in Hardening the Protection of Highly Confidential Information (abstract submitted to WEC 2010)

2009
  1. Fazli Mat Noor, Nurul Haszeli Ahmad, Mohd Haris Aziz, Arniyati Ahmad, “Simplified Cairngorm – Towards A Better Approach of Cairngorm”, Proceeding of MIMOS Symposium, 2009
  2. Nurul Haszeli Ahmad, Fazli Mat Nor, Mohd Haris Aziz, Arniyati Ahmad, “Towards Choosing A Suitable Flex Framework - A Comparative Study”, Proceeding of MIMOS Symposium, 2009
2008 

  1. Arniyati Ahmad, Nurul Haszeli Ahmad, Fazli Mat Nor, Mohd Haris Aziz, “Securing Project Management Dashboard Application”, Malaysia Educational Security Convention and Seminars (MyEduSec 2008), 17 – 18 August 2008, Grand Continental, Terengganu

Share:

Making your application code multicore ready

In this product how-to article, Vector Fabrics’ Paul Stavers describes a more efficient way to parallelize code for embedded multicore designs illustrating the process using the company’s online tool to parallelize Google’s VP8 video decoder... [read more]
Share:

Saturday, October 29, 2011

A good blog to learn something

Take a look at http://drotspss.blogspot.com/

Although the way it is organize and writing seem too 'relax', but the value and knowledge inside it is very useful.
Share:

Energy efficient C code for ARM devices

An interesting articles by Chris Shore which appeared in ARM Tech. Conference. Check it out here

My thought:
I'm more interested on how you improve securities in ARM devices and at the same time maintain or did not causes any harm to the devices efficiencies especially current era where attacks can be directed or coming from a small devices such as wireless sensor.

There will always a debate on security versus performance and you can only have one to choose. However, I would love to see something that be able to work in parallel for both security and performance :)
Share:

Friday, October 28, 2011

Users don't understand public Wi-Fi risks

People accessing public Wi-Fi aware data theft and industrial espionage could happen with unsecured networks but see risks as "theoretical", say Astaro execs.[read more]

My 2 cents
There is nothing new in this. People especially in information security area know about this few years back and become greater concern when many restaurant, shops, etc are providing free WiFi access. It do come back to each individual. Their concern, purpose, and priority - which ones come first.
Share:

XML vulnerability leads to calls for standards change

German scientists say weakness in cipher block chaining mode for XML encryption means secured communications between Web services can now be decrypted, and call for change in encryption standard. [read more]

What do I think?
Current encryption method, or cryptography method is still strong. I believe that they can't simply break those and decrypt XML message. There must be specific scenario or parameters required in order for them to succeed.

Nevertheless, security community can't take that for granted. Hacking tools, methods, and others related to exploiting, cracking, etc are becoming easily accessible and easy to use or implemented. Computing powers is increasing but the cost is decreasing thus enable any decryption, hacking, brute-force kind of attack, etc to be completed faster or to be execute with more power.
Share:

Friday, October 21, 2011

Conference List - As of Oct 22, 2011


  • Finance Transformation for CFOs 24 October 2011 Toronto Canada
  • 2011 ANSYS Belgium Conference 25 October 2011 La Hulpe Belgium
  • 2011 ANSYS Netherlands Conference 28 October 2011 Eindhoven Netherlands
  • SWARM 10 November 2011 Sydney Australia
  • International Conference on Advancements in Information Technology 2011¨CICAIT 2011 17 December 2011 Chennai India
  • 2011 International Conference on Signal, Image Processing and Applications (ICSIA 2011) 17 December 2011 Chennai India
  • 1st International Workshop on Nanoparticles and their Applications in Medicine (NAM-2012) 03 January 2012 Kharagpur India
  • 2012 3rd International Conference on e-Education, e-Business, e-Management and E-Learning (IC4E 2012) 05 January 2012 Hong Kong China
  • International Conference on Intelligent Computational Systems (ICICS'2012) 07 January 2012 Dubai United Arab Emirates
  • 2012 International Conference on Innovation and Information Management(ICIIM 2012) 07 January 2012 Chengdu China
  • SCADA Asia 2012 11 January 2012 Hong Kong Hong Kong
  • 2012 International Conference on Communication and Electronics Information - ICCEI 2012 14 January 2012 Mumbai India
  • Network Enabled Operations Summit 23 January 2012 Washington DC
  • 2012 4th International Conference on Computer modeling and simulation (ICCMS 2012) 17 February 2012 Hong Kong China
  • 2012 International Conference on Information and Computer Applications(ICICA 2012) 17 February 2012 Hong Kong China
  • 2012 International Conference on System Modeling and Optimization(ICSMO 2012) 17 February 2012 Hong Kong China
  • 2012 International Conference on Digital Convergence (ICDC 2012) 18 February 2012 Coimbatore India
  • 2012 International Conference on Information and Computer Networks, ICICN 2012 26 February 2012 Singapore Singapore
  • The Early Education and Technology for Children (EETC) 14 March 2012 Salt Lake City Utah
  • The first International Conference on Informatics & Applications (ICIA2012) 03 June 2012 Kuala Terengganu Malaysia
  • SANS Forensics and Incident Response Summit 2012 21 June 2012 Austin Texas
  • InSITE 2012 22 June 2012 Montreal Canada
  • 3rd International ACM Sigsoft Symposium on Architecting Critical Systems (ISARCS 2012) 26 June 2012 Bertinoro Italy
  • 7th International Conference on Evaluation of Novel Approaches to Software Engineering 28 June 2012 Wroclaw Poland
  • LCBR European Marketing Conference 2012 09 August 2012 Munich Germany
  • Share:

    Codepad

    An online compiler/interpreter, and a simple collaboration tool 
    http://codepad.org/ created by Steven Hazel, one of the founders of Sauce Labs
    Share:

    Wednesday, October 19, 2011

    MyNOG-1 Conference

    A message to all members of ISOC MALAYSIA Chapter

    The MyNOG-1 Programme Committee are now seeking contributions for Presentations and Tutorials for MyNOG-1 that will be held on the 16 January – 17 January 2012 at Cyberjaya, Malaysia.

    We are looking for people and proposals that would:
    - Offer a technical tutorial on an appropriate topic; and/or
    - Participate in the technical conference sessions as a speaker; and/or
    - Convene and chair a Birds of a Feather (BoF) session.

    Please submit proposals online at:
    program@mynog.org

    CONFERENCE MILESTONES
    ———————
    o Call for Papers Opens: 14 October 2011
     o First Deadline for Submissions: 8 November 2011
    o First Draft Programme Published: 22 November 2011
    o Final Deadline for Submissions: 20 December 2011
    o Final Programme Published: 6 January 2012
    o  Final Slides Received: 10 January 2012
    o  Conference starts 16 January 2012
    ———————-

    The MyNOG-1 Programme is organised in two parts, including tutorials and the conference.
    Topics for tutorials and conferences would include amongst others relevant to Internet operations and technologies:
    - IPv4/IPv6 routing and operations.
    - IPv4 address run-out.
    - IPv6 deployments, transition technologies and experiences.
    - Network backbone operations.
    - ISP and network carrier services.
    - Network security issues (NSP-SEC, DDoS, Anti-Spam, Anti-Malware, Anti-Virus, e.t.c.).
    - Peering and Internet exchange points.
    - DNS/DNSSEC.
    - Internet policy (Security, Regulation, Content Management, Addressing, e.t.c.).
    - Access and transport technologies, e.g., xDSL, wireless, MPLS, Ethernet, FTTx, e.t.c.
    - Content and service delivery, e.g., Multicast, VoIP, video, TelePresence, IPTv, gaming, e.t.c.
    - Data Centre and Virtualization technologies.

    CfP SUBMISSION
    ————–
    Draft slides for both tutorial and conference sessions MUST be provided with CfP submissions otherwise the Programme Committee will be unable to review the submission.
    For work in progress, the most current information available at the time of submission is acceptable.
    Final slides are to be provided by the specified deadline for publication on the MyNOG website. While the majority of speaking slots will be filled by the first submission deadline, a limited number of slots may be available up to the final submission deadline for presentations that are exceptionally timely, important, or of critical operational
    importance.

    Please submit online at:
    program@mynog.org

    Any questions or concerns should be addressed to the Programme Committee by e-mail as below:
    program@mynog.org


    We look forward to receiving your presentation proposals.
    MyNOG Management Committee
    Visit ISOC MALAYSIA Chapter at: http://www.isoc.my/?xg_source=msg_mes_network
    Share:

    Tuesday, October 18, 2011

    Oracle Critical Patch Update October 2011

    October 18th, 2011

    The Critical Patch Update for October 2011 was released on October 18th, 2011. Oracle strongly recommends applying the patches as soon as possible. Please note that Sun products are included in this Critical Patch Update.

    The Critical Patch Update Advisory is the starting point for relevant information. It includes the list of products affected, pointers to obtain the patches, a summary of the security vulnerabilities for each product suite, and links to other important documents. Supported products that are not listed in the "Supported Products and Components Affected" section of the advisory do not require new patches to be applied.

    Also, it is essential to review the Critical Patch Update supporting documentation referenced in the Advisory before applying patches, as this is where you can find important pertinent information.

    Critical Patch Update Advisories are available at the following location:

    Oracle Technology Network:
    http://www.oracle.com/technetwork/topics/security/alerts-086861.html

    The Critical Patch Update Advisory - October 2011 is available at the following location:

    Oracle Technology Network:
    http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html

    The next four Critical Patch Update expected release dates are:
    • January 17, 2012
    • April 17, 2012
    • July 17,2012
    • October 16, 2012

    Share:

    About Me

    Somewhere, Selangor, Malaysia
    An IT by profession, a beginner in photography

    Labels

    Blog Archive

    Blogger templates