My experience on my daily works... helping others ease each other

Saturday, October 29, 2011

A good blog to learn something

Take a look at http://drotspss.blogspot.com/

Although the way it is organize and writing seem too 'relax', but the value and knowledge inside it is very useful.
Share:

Energy efficient C code for ARM devices

An interesting articles by Chris Shore which appeared in ARM Tech. Conference. Check it out here

My thought:
I'm more interested on how you improve securities in ARM devices and at the same time maintain or did not causes any harm to the devices efficiencies especially current era where attacks can be directed or coming from a small devices such as wireless sensor.

There will always a debate on security versus performance and you can only have one to choose. However, I would love to see something that be able to work in parallel for both security and performance :)
Share:

Friday, October 28, 2011

Users don't understand public Wi-Fi risks

People accessing public Wi-Fi aware data theft and industrial espionage could happen with unsecured networks but see risks as "theoretical", say Astaro execs.[read more]

My 2 cents
There is nothing new in this. People especially in information security area know about this few years back and become greater concern when many restaurant, shops, etc are providing free WiFi access. It do come back to each individual. Their concern, purpose, and priority - which ones come first.
Share:

XML vulnerability leads to calls for standards change

German scientists say weakness in cipher block chaining mode for XML encryption means secured communications between Web services can now be decrypted, and call for change in encryption standard. [read more]

What do I think?
Current encryption method, or cryptography method is still strong. I believe that they can't simply break those and decrypt XML message. There must be specific scenario or parameters required in order for them to succeed.

Nevertheless, security community can't take that for granted. Hacking tools, methods, and others related to exploiting, cracking, etc are becoming easily accessible and easy to use or implemented. Computing powers is increasing but the cost is decreasing thus enable any decryption, hacking, brute-force kind of attack, etc to be completed faster or to be execute with more power.
Share:

Friday, October 21, 2011

Conference List - As of Oct 22, 2011


  • Finance Transformation for CFOs 24 October 2011 Toronto Canada
  • 2011 ANSYS Belgium Conference 25 October 2011 La Hulpe Belgium
  • 2011 ANSYS Netherlands Conference 28 October 2011 Eindhoven Netherlands
  • SWARM 10 November 2011 Sydney Australia
  • International Conference on Advancements in Information Technology 2011¨CICAIT 2011 17 December 2011 Chennai India
  • 2011 International Conference on Signal, Image Processing and Applications (ICSIA 2011) 17 December 2011 Chennai India
  • 1st International Workshop on Nanoparticles and their Applications in Medicine (NAM-2012) 03 January 2012 Kharagpur India
  • 2012 3rd International Conference on e-Education, e-Business, e-Management and E-Learning (IC4E 2012) 05 January 2012 Hong Kong China
  • International Conference on Intelligent Computational Systems (ICICS'2012) 07 January 2012 Dubai United Arab Emirates
  • 2012 International Conference on Innovation and Information Management(ICIIM 2012) 07 January 2012 Chengdu China
  • SCADA Asia 2012 11 January 2012 Hong Kong Hong Kong
  • 2012 International Conference on Communication and Electronics Information - ICCEI 2012 14 January 2012 Mumbai India
  • Network Enabled Operations Summit 23 January 2012 Washington DC
  • 2012 4th International Conference on Computer modeling and simulation (ICCMS 2012) 17 February 2012 Hong Kong China
  • 2012 International Conference on Information and Computer Applications(ICICA 2012) 17 February 2012 Hong Kong China
  • 2012 International Conference on System Modeling and Optimization(ICSMO 2012) 17 February 2012 Hong Kong China
  • 2012 International Conference on Digital Convergence (ICDC 2012) 18 February 2012 Coimbatore India
  • 2012 International Conference on Information and Computer Networks, ICICN 2012 26 February 2012 Singapore Singapore
  • The Early Education and Technology for Children (EETC) 14 March 2012 Salt Lake City Utah
  • The first International Conference on Informatics & Applications (ICIA2012) 03 June 2012 Kuala Terengganu Malaysia
  • SANS Forensics and Incident Response Summit 2012 21 June 2012 Austin Texas
  • InSITE 2012 22 June 2012 Montreal Canada
  • 3rd International ACM Sigsoft Symposium on Architecting Critical Systems (ISARCS 2012) 26 June 2012 Bertinoro Italy
  • 7th International Conference on Evaluation of Novel Approaches to Software Engineering 28 June 2012 Wroclaw Poland
  • LCBR European Marketing Conference 2012 09 August 2012 Munich Germany
  • Share:

    Codepad

    An online compiler/interpreter, and a simple collaboration tool 
    http://codepad.org/ created by Steven Hazel, one of the founders of Sauce Labs
    Share:

    Wednesday, October 19, 2011

    MyNOG-1 Conference

    A message to all members of ISOC MALAYSIA Chapter

    The MyNOG-1 Programme Committee are now seeking contributions for Presentations and Tutorials for MyNOG-1 that will be held on the 16 January – 17 January 2012 at Cyberjaya, Malaysia.

    We are looking for people and proposals that would:
    - Offer a technical tutorial on an appropriate topic; and/or
    - Participate in the technical conference sessions as a speaker; and/or
    - Convene and chair a Birds of a Feather (BoF) session.

    Please submit proposals online at:
    program@mynog.org

    CONFERENCE MILESTONES
    ———————
    o Call for Papers Opens: 14 October 2011
     o First Deadline for Submissions: 8 November 2011
    o First Draft Programme Published: 22 November 2011
    o Final Deadline for Submissions: 20 December 2011
    o Final Programme Published: 6 January 2012
    o  Final Slides Received: 10 January 2012
    o  Conference starts 16 January 2012
    ———————-

    The MyNOG-1 Programme is organised in two parts, including tutorials and the conference.
    Topics for tutorials and conferences would include amongst others relevant to Internet operations and technologies:
    - IPv4/IPv6 routing and operations.
    - IPv4 address run-out.
    - IPv6 deployments, transition technologies and experiences.
    - Network backbone operations.
    - ISP and network carrier services.
    - Network security issues (NSP-SEC, DDoS, Anti-Spam, Anti-Malware, Anti-Virus, e.t.c.).
    - Peering and Internet exchange points.
    - DNS/DNSSEC.
    - Internet policy (Security, Regulation, Content Management, Addressing, e.t.c.).
    - Access and transport technologies, e.g., xDSL, wireless, MPLS, Ethernet, FTTx, e.t.c.
    - Content and service delivery, e.g., Multicast, VoIP, video, TelePresence, IPTv, gaming, e.t.c.
    - Data Centre and Virtualization technologies.

    CfP SUBMISSION
    ————–
    Draft slides for both tutorial and conference sessions MUST be provided with CfP submissions otherwise the Programme Committee will be unable to review the submission.
    For work in progress, the most current information available at the time of submission is acceptable.
    Final slides are to be provided by the specified deadline for publication on the MyNOG website. While the majority of speaking slots will be filled by the first submission deadline, a limited number of slots may be available up to the final submission deadline for presentations that are exceptionally timely, important, or of critical operational
    importance.

    Please submit online at:
    program@mynog.org

    Any questions or concerns should be addressed to the Programme Committee by e-mail as below:
    program@mynog.org


    We look forward to receiving your presentation proposals.
    MyNOG Management Committee
    Visit ISOC MALAYSIA Chapter at: http://www.isoc.my/?xg_source=msg_mes_network
    Share:

    Tuesday, October 18, 2011

    Oracle Critical Patch Update October 2011

    October 18th, 2011

    The Critical Patch Update for October 2011 was released on October 18th, 2011. Oracle strongly recommends applying the patches as soon as possible. Please note that Sun products are included in this Critical Patch Update.

    The Critical Patch Update Advisory is the starting point for relevant information. It includes the list of products affected, pointers to obtain the patches, a summary of the security vulnerabilities for each product suite, and links to other important documents. Supported products that are not listed in the "Supported Products and Components Affected" section of the advisory do not require new patches to be applied.

    Also, it is essential to review the Critical Patch Update supporting documentation referenced in the Advisory before applying patches, as this is where you can find important pertinent information.

    Critical Patch Update Advisories are available at the following location:

    Oracle Technology Network:
    http://www.oracle.com/technetwork/topics/security/alerts-086861.html

    The Critical Patch Update Advisory - October 2011 is available at the following location:

    Oracle Technology Network:
    http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html

    The next four Critical Patch Update expected release dates are:
    • January 17, 2012
    • April 17, 2012
    • July 17,2012
    • October 16, 2012

    Share:

    Tuesday, September 27, 2011

    CWE: what developers of connected embedded systems need to know

    Tapp and Chandran (LRDA) wrote an articles published in EETimes (online). The articles starts with sharing information on vulnerabilities and cases related to exploitation. It then goes into CWE (Common Weaknesses Enumeration), purpose, people behind it, etc. They further explain on propose tool in CWE and end-up with why LRDA should be incorporated in SDLC.

    First, the title itself is totally conflicted with the contents of the articles which did not touch anything on developers related things especially in gaining knowledge on using CWE as part of their skills in securing their code. However, I tends to agree with them that there are indeed required to use multiple tools for security check.

    Their conclusion are more as promoting use of tools in part of SDLC to improve security testing which I believe it is more as marketing rather than technical.

    To be able a developer to use CWE, the developers must well equip with knowledge about vulnerabilities and how does it appear in codes. They can avoid it while writing the codes without waiting to use tools which it will be quite messy when dealing with millions LOC (Lines of Codes). Some of the tools even throw false alarm or too many warning as it depends on techniques implemented (PPT).

    On understanding vulnerabilities, there are few ways and one of those is to understanding on the behavior and code structures from coding perspective. A paper published in Springer shares on how a taxonomy can be used by developers to understand further thus improve their security skill and usage of tools. The papers can be read here.
    Share:

    List of Conferences as of Sep 25, 2011

    Share:

    Quantum Lecture Series 5

    Laboratory of Computational Sciences and Mathematical Physics, Institute for Mathematical Research in Universiti Putra Malaysia will be organizing Expository Quantum Lecture Series 5 on January 9-13, 2012. The theme for EQuaLS5 is "Geometry, Topology and Physics 2012" and the speakers are
    1. John Baez (NUS, Univ of California, Riverside)"Network Theory"
    2. Do Ngoc Diep (Inst of Math, Hanoi)
      "A Procedure for Quantization of Fields"
    3. Maurice de Gosson (Univ. of Vienna)
      "The Symplectic Camel and Quantum Mechanics"
    4. Fredrik Stroemberg (Technical Univ. of Darmstadt)
      "Arithmetic Quantum Chaos"
    5. S. Twareque Ali (Concordia University, Montreal)
      "Coherent States: Theory and Applications"
    On-line registration is now open at http://einspem.upm.edu.my/equals5/
    Share:

    Facebook Updates Could Give Nonprofits Better Visibility

    An interesting articles written by Derek Lieu and posted at Social Philantrophy.

    My thoughts:
    1. Lots of algorithm running behind facebook which one small mistake might affect lots of people
    2. Opportunity for researchers as there are lots of research can be done especially on algorithm, security, social etc.
    3. Facebook will be here for another decades
    Share:

    Friday, September 23, 2011

    User privacy concerns emerge over supercookies



    Difficult to remove new type of cookie which can track user history and preference, giving rise to privacy concerns, note experts, but add that supercookies aren't legal issue for now. [read more]






    Share:

    Tuesday, September 20, 2011

    Applying Static Analysis To Medical Device Software

    An interesting articles written back on 2008 by David N. Kleidermacher indicates the importance of having static analysis tool to improve reliability and sustainability of medical devices [read here]

    However, as complexity increases especially on mobile devices and mission-critical devices like medical and military, static analysis tool is still far away from achieving zero-tolerant or 99.99% secure. It depends on technique and tool use by the tool to statically analyze applications stored in those devices and at the moment, and as written in my paper title "Preventing Exploitation on Software Vulnerabilities: Why Static Analysis Failed?" in WEC 2010, there are more works need to be done to improve static analysis tool capability especially when the complexity and LOC is increase.
    Share:

    International Conference on Distributed Computing Engineering (ICDCE 2011)

    2011 International Conference on Distributed Computing Engineering (ICDCE 2011)
    28 to 30 December 2011
    Dubai, United Arab Emirates

    2011 International Conference on Distributed Computing Engineering (ICDCE 2011)
    will be held in Dubai, Chengdu, China during December 28-30, 2011.  The upcoming
    ICDCE 2011 will inherit the advantages of the previous conferences and develop
    the conference to a higher level.  The theme of the ICDCE is to discuss the new
    development of computer theory and engineering, and to promote its new
    application.  ICDCE 2011 will bring together leading engineers and scientists
    around the world, so as to present their research results and development
    activities in Distributed Computing Engineering. This conference provides
    opportunities for the delegates to exchange new ideas and application
    experiences
    face to face, to establish business or research relations and to find global
    partners for future collaboration.

    ICDCE is sponsored by Singapore International Association of Computer Science
    and Information Technology (IACSIT), and technical co-sponsored by many
    universities and institutes.

    This year, all ICDCE 2011 conference papers will be included in the ICACTE 2011
    proceedings, which is published by ASME Press, and will be included in the ASME
    Digital Library, and indexed by the Ei Compendex, ISI Proceeding and other major
    indexing services.

    The deadline for abstracts/proposals is
    30 October 2011

    Enquiries: icdce@iacsit.org
    Web address: http://www.icdce.org/
    Sponsored by: IACSIT
    Share:

    Implement CRUD operations using RESTful WCF Service and javascript

    Found a good articles to start playing with WCF and Javascript (for Java developers) written by Shahriar Iqbal Chowdhury. Check it out @ Code Project
    Share:

    Friday, September 16, 2011

    Using static code analysis to support DO-178b certification

    Paul Anderson, GrammaTech   
    9/6/2011 6:29 PM EDT

    In this Product How-To, Paul Anderson of GrammaTech takes you step by step through the DO-178B and how use his company’s static analysis tools to support the safety-critical software requirements of the specification [read more].

    As one of my interest in software security, I keen to evaluate the effectiveness and efficiencies of GrammaTech CodeSonar on its static analysis capability using taxonomy of C Overflow Vulnerabilities Attack which I constructed for the purpose of identifying overflow vulnerabilities in C. However, due to fact (based on my email conversation between one of the company's employee), I can't evaluate theirs thus I'm not sure how their tools could help supporting the safety-critical software requirements.

    And I can says one things for sure here that all tools including CodeSonar is yet to successfully help in reducing vulnerabilities in software. This can been seen by looking at various vulnerability database and advisories released by Symantec, Karspesky, Microsoft, NIST, etc. The numbers are still large and yet to see it is tremendously reduce.
    Share:

    Thursday, September 15, 2011

    Google add new artilery in fight with the other giant (Facebook, Yahoo, Microsoft, Apple, etc)

    Recently, I heard many IT giant acquiring patents from various company such as Nortel, HTC, IBM, etc and we will definitely keep on reading news of patent infringement case as the fight continues. Latest news was acquisition of some IBM patents related to Java language (JDJ: Google Buys Some Java Patents). And this was continuation from the last battle between Google and the other IT giant. (list of Java related patent).

    This fight is hope to bring better future for the consumer and shall not affect or increase in cost of having better technology.
    Share:

    Vulnerabilities is known and yet it is still there

    Reported by Symantec, vulnerabilities still there and will always be there unless we do something to eliminate or reduce it to lower state. This is numbers of vulnerabilities captured/monitored by Symantec. It does not includes or cross-checking between other vulnerability databases such as NIST, CVE, Karspesky, Microsoft, etc.

    Check it out the reports at Symantec Vulnerabilities Trend Report.
    Share:

    Oracle Critical Patch Update - September 2011

    Critical Patch Update - September 2011
    Dear Oracle Security Alert Customer,

    Oracle Security Alert for CVE-2011-3192 was released on September 15th, 2011.

    Oracle strongly recommends applying Security Alert fixes as soon as possible.

    The Security Alert Advisory is the starting point for relevant information. It includes the list of products affected, a summary of the security vulnerability, and a pointer to obtain the latest patches. Supported products that are not listed in the "Affected Products and Versions" section of the advisory do not require new patches to be applied.

    Also, it is essential to review the Security Alert supporting documentation referenced in the Advisory before applying patches, as this is where you can find important pertinent information.

    The Advisory is available at the following location:

    Oracle Critical Patch Updates and Security Alerts
    http://www.oracle.com/technology/deploy/security/alerts.html


    Oracle Security Alert CVE-2011-3192
    http://www.oracle.com/technetwork/topics/security/alert-cve-2011-3192-485304.html



    From Oracle Security Alerts team
    Share:

    About Me

    Somewhere, Selangor, Malaysia
    An IT by profession, a beginner in photography

    Labels

    Blog Archive

    Blogger templates