21Feb Perform integrity checks on all new employees
o Perform integrity checks on all new employees to make sure that theyhaven’t lied about their background, experience or qualifications.o Give all new employees a simple introduction to information security, andmake sure that they read and understand your information security policy.Make sure they know where to find details of the information securitystandards and procedures relevant […]
30Jan Securing your p2p network
The routing primitives implemented by current structured p2p overlays provide a besteffortservice to deliver a message to a replica root associated with a given key. Asdiscussed above, a malicious overlay node has ample opportunities to corrupt overlaylevelcommunication. Therefore, these primitives are not sufficient to construct secureapplications. For example, when inserting an object, an application cannot […]
29Jan Extranet
An extranet is a private network that uses Internet technology and the public telecommunication system to securely share part of a business’s information or operations with suppliers, vendors, partners, customers, or other businesses. An extranet can be viewed as part of a company’s intranet that is extended to users outside the company. It has also […]
26Jan Dynamic Host Configuration Protocol (DHCP) Server
DHCP is used to lease out individual IP addresses to anyone who configures their system to request one. Other vital information such as subnet mask, default gateway, and name server are also given to the client at this time. The WFG uses a beta DHCPv3 open-source server from the Internet Software Consortium with the additional […]
12Jan Network security concern
Every day, students send dozens of electronic messages or store personal files in their accounts thinking that their messages will remain private and their files secure. This, however, might not be the case.
According to one computing assistant (CA) who asked to remain unidentified, break-ins into personal accounts are not uncommon. “People [on the Internet] have […]
05Dec Heartbeat method to detect networking failure
The best solution for the `client waits forever` problem is the heartbeat pattern, as it was know it from Wiley Java Design Patterns Vol 3. That implementation is RMI, but the idea is that the server sends a message to the client, which is listening for `still alive`
messages. So you might be able to have […]
04Dec how the security team should review the networking security changes
There is a security paper in cisco networking. It explain how the security team should review the networking security changes. It recommend that the security team review the following types of changes:
Any change to the firewall configuration.
Any change to access control lists (ACL).
Any change to Simple Network Management Protocol (SNMP) configuration.
Any change or update […]
03Dec Layers in networking security
Layered defense has been proven as a concept that works. Instead of having one layer of protection that leaves networks susceptible to a single point of failure, layered security offers additional protection. The security approach slows down the attack, collects more information about its actions and supports the network in effectively stopping it before an […]
02Dec Protecting Distributed Networks
Many corporate intranets are deployed to connect branch office networks, where security can often be perceived as less effective than at corporate headquarters. For example, postal service headquarters will have strong network security policies, but local post offices might not have as stringent procedures due to lack of IT personnel expertise. This kind of situation […]
02Dec Conducting a risk analysis in networking
A risk analysis should identify the risks to your network, network resources, and data. This doesn’t mean you should identify every possible entry point to the network, nor every possible means of attack. The intent of a risk analysis is to identify portions of your network, assign a threat rating to […]
22Oct WEP is wide open in security
The 802.11b standard includes a provision for encryption called WEP (Wired Equivalent Privacy). Depending on the manufacturer and the model of the NIC card and access point, there are two levels of WEP commonly available - one based on a 40-bit encryption key and 24-bit Initialization Vector (also called 64-bit encryption and generally considered insecure) […]
25Jun P2p programs are dangerous for your system
If you have installed file-sharing software, files on your computer may be available to other P2P users on the Internet without your knowledge. Many file-sharing applications also receive a continuous stream of advertisements whenever they are open, degrading your computer’s performance and using additional network bandwidth. In addition to the drain they place on network […]

