Tuesday, August 6, 2019
Project cost management
Project cost management Introduction The successful design, development and implementation of projects are very complex and at times daunting tasks for many project managers. The sum of growth in competition and globalization, institutionalization of innovation-based economics, rapid development of technologies, the uses of outer resources, increase in the significance of customers focus and the shortening of products and services cycles means that projects cost management has become a multifaceted issue for majority of businesses today. In essence, this has resulted in the need for the adoption and focus on project based on cost management of business activities. Indeed a lot of researchers emphasis the need for a multi-project environmental management of projects that pays cognizance to the key ingredients that will ensure for the success in projects. This paper will synthesis, analyze and dissect the key attributes that are seen to be inherently important for ensuring effective project cost management. Towards this, an insightful and succinct discussion of the following key factors for successful projects shall be done; appropriate senior management levels commitment to the project, adequate project funding, project requirements analysis and specifications, stakeholders involvement, risks management and presence of a contingent plan. While several dimensions could be pursued under each element only few will be highlighted Ensuring for effective project cost management Phillips (1) illustrates that From IT to construction, most projects have to purchase materials: routers and cables, shingles and cement, and so on; we must always buy some things to complete the project work. Without even underlining the scope or schedule of a given IT project, funds must be availed and properly managed and appropriated to achieve the goals of the project. In the cost management of IT projects, there are three major estimates cost techniques that project managers should make use to effectively manage their projects. These include the Ballpark estimate, the budget estimate and the definitive estimate. According to Barkley (68) Ballpark estimate is also known as the rough order of magnitude (ROM)which is based on high-level objectives, provides a birds-eye view of the project deliverables, and has lots of wiggle room in that most ROM estimates are dependent on the industry and have a range of variances from -25% all the way to +75%. The budget estimate that is also known as the top down estimate is more accurate than the Ballpark estimate and is always formulated at the beginning of the projects life. It includes a number of conditions just like the Ballpark estimate in that it takes into consideration a range of variances and assumptions that are characteristics of any projects estimation. The definitive estimate or bottom up estimate is the real opposite of the budget estimate (Haughey, 29). In effective cost management of an IT project, it is imperative that all the estimate methods are used to mitigate the effects of overhead costs on the project. Baldwin, Rose-Anderssen, Ridgway, Allen, Lopez, Strathern, and Varga (1), clearly demonstrates that The definitive estimate requires a work breakdown structure (WBS) and a WBS is not a list of activities, it is a detailed description of deliverables-oriented decomposition of the project scope. The attention to the creation of goods and services and technologies has significantly increased over the last few years that have prompted and preconditioned the need for better and more efficient projects cost management. This call for paying cognizance to the following key factors; Senior management support The success of projects will to a large extent rely on the interests, support and commitment of the senior management. This is in order to ensure that everybody in the project team and indeed the whole employees are focused and committed. Most projects in organization are sometimes conceived, funded and developed without appropriate senior management involvement or approval. Armstrong (25) has for example noted that some projects go forward without the management clearly conceptualizing what the project entails. A distinction between mere approval and commitment should be clearly discerned so that the projects run smoothly. According to Dennis (87) and Blair (13), most projects fail when the senior management lacks a clear understanding and a paucity of the projects perceived benefits, risks and difficulties. This is fundamental because the management plays a central role in costs appropriations and budget allocations for project activities. This means that while the projects approva l may actually have been acquired, in the euphoria of getting the projects approved; some of the risks may be ignored or glossed over. Efficient project cost management especially in the field of IT should however ensure that projects approvals are not based on hype and unrealistic calculations but on a framework that encapsulates a realistic assessment of the projects benefits, risks and costs. Adequate financing or funding for the project This forms the fundamental groundwork for the achievement any IT related projects objectives and goals. Most IT projects being initiated will require some substantial funding and resources deployment because they are always characterized by abnormally huge overhead costs. However, Kerzner (11) and Loosemore, Raftery and Reilly (161), have noted that ample project funding is not in itself a panacea to projects success. It has been advanced that inadequate project funding will most invariably result on delivery of less than promised. The realization of projects success has been positively correlated with efficient resources management and budget controls. According to Armstrong (32) effective resources management as well as its impact on the compatibility between the costs management and project value accumulation has been empirically proved in literature. Researchers show that in order to avoid the gap between the organizational strategies and the limited resources, it is purposive that available resources are reviewed and aligned to the budget in a seamless manner. This means that a lot needs to be arranged before and also during projects executions. A clear delineation of all the resources that are essential to the successful running of the project and a formulation of a budget that captures all the needs and requirements is therefore important. Armstrong (33), succinctly state that A project funding should be seen as a continuing and flexible process in that while a reasonable estimate of project expense must be made to obtain initial approval, this figure should not be considered as the final project cost. This point is further buttressed by Meyer (172) in illustrating that As the true scope of an IT project is revealed, the project manager can more accurately identify project expenses and recalculate the costs at several checkpoints in the project life cycle so that the new figures are communicated to senior management. Requirements analysis Requirements analysis should be carried out in order to develop the architectural design or frameworks of the specific IT project for the initiation and inception of the project. This calls for a thorough discussion between the clients and/or the stakeholders in order that all the salient issues are brought to the fore and the project is set off on a sound footing. According to Armstrong (27), client consultation at all the stages of an IT project development should always be done in order to avoid situations where repeated references to the project requirements are the case or projects are discontinued entirely. Requirements analysis should be detailed and the analysis or the project manager should visit, communicate and discuss the project requirements with the clients on a conclusive and comprehensive manner. A clear delineation of what will be delivered or not within projects scope should ideally be done. Project managers will attest to the fact that taking a thorough requirement analysis ahs the benefit of arriving at an accurate estimate on a project. This will reduce the effects of time wasted in search of more funds and convincing clients and other stake holders to increase funding after its initiation. In addition to the above, it comes with the added advantage of taking due care of crash programs and thus protects the projects from the effects external factors (Meyer, 171). Development of a comprehensive project plan and its cost components Basically, there are three main benefits to be realized through the development of a clear, comprehensive and elaborate project plan. One such benefit is that through adequate planning, the planners are able to present a clear and well documented or properly focused understanding of project. Secondly, adequate planning ensures that all issues are raised to help avoid instances of overlooking some issues that may later prove problematic. Finally, adequate planning reinforces and helps build confidence in the success of the project. Jiang and Gary (20) elucidates that project planning should never be viewed as a waste of time. This point has been buttressed by Armstrong (29) who has advanced that a very strong correlation between the lengths of time allocated to the project planning and the ultimate projects success abides. Stakeholders involvement The attainment of all the stakeholders involvement has been cited as an important ingredient in the success of IT projects in organizations. This means that every stakeholder in the organization is seen too own the project. This ensures that there are no complains about the project contents and performance when it is completed. This becomes more poignant when it is noted that projects warrants large investment of resources such as time, efforts and money. The involvement of the employees, internal customers and other important stakeholders should therefore be paid utmost cognize (Raz, Erez, 48). Frequent project status reporting should accompany the progress of the project and this should be done on as a regular interval in as far as is soundly possible. As early as the projects life, frequent reporting should help spot and identify adverse issues, as well as how these can be overcome. Jiang and Gary (31) have noted that it is not important that regular updates are provided but the accuracy of such reporting be the case so as to ensure that the status of the projects progress are accurate, realistic and timely. Risk assessment in an IT project It is important that a detailed risks assessment is carried in an IT project so as to ensure for the success of a project. Essentially, risks assessment may fall into two categories, i.e. the more usual and obvious risks and the risks that may be generated from the functions and requirements of a particular problem (Raz, Erez, 53). A businesslike approach to project management requires carefully considering and addressing these risks with internal customers and senior management as part of the projects approval process and if the risk analysis leads to a decision not to move forward, it is much better for everyone involved that the decision is made sooner, rather than later (Raz, Erez, 55). Armstrong (34) has advised that it is prudent to consider the possibility of some failures in the projects that would call for the development of contingent plans to overcome difficult situations should they arise and a project may have to incorporate items that were overlooked, or changes in the business needs associated with the project. This may result in delay of some projects that were dependent on this project or indeed some other business activities. Successfully and efficient project cost management will therefore entail the development of contingent plans to mitigate against such occurrences. In the course of an IT project development, a lot of issues and difficulties may arise. Thus, while some problems may have been anticipated, some occurrences, the need to clear to meet deadlines among others may create insurmountable pressures and tensions. These must be mitigated through the adoption of sound cost management approaches that ensures that issues and matters arising are addressed and mitigated. In some instances, continued top management support must be continually sought so that commitment to the project remains true, and un-anticipated funding requirements are met or delays in operations are understood. In obtaining senior management support, project managers must be willing to present an accurate picture of the potential difficulties inherent in the project in that insofar as is practical, senior management must be given a realistic assessment of the potential for difficulty and be willing to stay the course if things go wrong (Dennis, 95). Conclusion Effective project cost management is a multifaceted issue especially in an IT related project and difficulties abide in the identification and management of all potential difficulties and the ramifications that are associated with the successful development, budget appropriation and implementation of projects. This will depend to some extent on the size of the project where it is seen that the larger the size, the greater the probability of unseen contingencies. In large IT projects for example, the task can prove overwhelming and massive to coordinate. Organizations attempting to find and resolve all IT project difficulties and potential difficulties may not find the issues presented here as all inclusive as there are a lot more issues that must be paid cognizance for the efficient project cost management. However, while the draft does not strive for perfection, it can nonetheless be adjudged that paying attention to the issues raised, a project manager will be better prepared and k nowledgeable enough that undoubtedly greatly enhances the likelihood of a successful project and cost management strategies. WORKS CITED Armstrong, Mark. 2007. Simplified Risk Assessment. Engineering management journal.10, 1: 19-24. Baldwin, James, S., Rose-Anderssen, Chris., Ridgway, Keith., Allen, Peter, M., Lopez, Alvaro.,Strathern, Mark and Varga, Liz. (2006). Management Decision-Making: Risk Reduction Through Simulation. Website: http://www.palgrave-journals.com/rm/journal/v8/n4/pdf/8250020a.pdf Barkley, Bruce. 2004. Project risk management. McGraw-Hill Professional. Blair, Gerald, M. 2007. Planning a Project. http://www.see.ed.ac.uk/~gerard/Management/art8.html?http://www.ee.ed.ac.uk/~gerard/Management/art8.html Dennis, Lock. . 2007. Project management. 9th edition. London: Cooper Lybrand Haughey, Duncan. 2000. Planning a Project using a Work Breakdown Structure Logic Network. Website: http://www.projectsmart.co.uk/planning-a-project-using-a-work-breakdown-structure-and-logic-network.html Jiang, James, J. and Gary, Klein. Software project risks and development focus. Project management journal, 32, 1: 4-9. 2001. Kerzner, Harold. Project management: A Systems approach to planning, scheduling, and controlling. 9th edition. New York: John Willey Sons. 2006. Loosemore, Mark, Raftery, Justin and Reilly, Chris. Risk management in projects. Taylor Francis. 2006. Meyer, Brad, C. Project Costs and Crashing. 2002. Retrieved on February 22, 2010 from Website: http://www.cbpa.drake.edu/bmeyer/webm120/PPT_Crashing.pdf Phillips, Joseph. Project Cost Management. 2010. Retrieved March 15th, 2010 from Website: http://www.projectsmart.co.uk/project-cost-management.html Raz, Tzvi and Erez, Michael. Benchmarking the use of project risks management tools. Proceedings of the project management Institute Annual Seminars and Symposium.1999.
Monday, August 5, 2019
Antivirus Research And Development Techniques
Antivirus Research And Development Techniques Antivirus software is the most booming product which has constant developments to be most up to date defensive detecting product competing with all other antivirus software products available in the commercial market. This thesis covers few techniques used by the antivirus products, a general background information about viruses and antivirus products, some research made on antivirus overheads which shows what overheads are introduced to the computer on using an antivirus products, a research made on one of the most important and common technique used by the antivirus software products to detect viruses which is signature based detection, also covers how antivirus software is updated and how new virus signatures are updated to the virus database. There is some research also on selected algorithms used by the techniques, here in this thesis it is explained how each selected algorithm works to detect the code or a file as an infected file or uninfected. In the experimentation, the expe riment is done to detect a virus using three selected popularly known antivirus software products, where reports shown by the three products are compared and concluded. Chapter 1: Introduction A life without computers cannot be imagined in the present life style where it plays a very important role though it might be any field one chooses from the millions. Computer is vulnerable to attacks which are most dangerous and hard to handle with. Just like humans even computers are attacked by viruses. A virus can be in a form of worm, malware or Trojan horses anything that infects the computer. The common source of these viruses is World Wide Web where a malicious person can spread the malware very easily. Many researchers found many methods or procedures to stop the attacks of virus that came up with many techniques or software to remove the viruses which are called Anti-Virus software. A computer virus spreads into the computer through emails, floppy disks, internet and many other sources. The spreading mechanism is usually from one computer to another where it corrupts data or deletes the data from the computer. The viruses mostly spread through internet or through emails which may have some hidden illicit software where the user unknowingly downloads the material into the computer. A virus can attack or cause damage to boot sector, system files, data files, software and also on system bios. There are many newer viruses which attack on many other parts of the computer. Viruses can spread by booting the computer using the infected file, executing or installing the infected file, or by opening the infected data or file. The main hardware sources can be floppy disks, compact disks, USB or external hard drives or a connection with other computer on an unsafe medium. This rapid growth of viruses is challenging the antivirus software in different fields like prevention of viruses, preparation, detection, recovery and control of viruses. Nowadays there are so many antivirus software tools that remove viruses from the PC and helps protect from future attacks. Antivirus raises privacy and security issues of our computers we work on which is a major issue. However, after taking so many safety measures the growth of viruses is rapidly increasing which are most dangerous and wider. In this thesis, a history on viruses and evolution of antivirus software is shown where I will explain about how viruses came into existence and what type of viruses evolved and antivirus software discovery. This general criteria of this thesis is mainly targeted on three selected techniques and is mostly concentrated one technique out of the selected three techniques and scanning methods of antivirus products and also gives a basic scenario of how an antivirus product adopts a framework to update the virus database and also gives some information about how a general computer gets an information to update the product to make it ready to defend against the zero-day viruses. A brief comparison of viruses based on types where the definitions and related threats of viruses will be explained and the working effects of each type of viruses are explained. The working of antivirus software on different types of viruses is explained. Analysis of the current antivirus techniques, showing both advantages and disadvantages. In chapter 2 gives you the general outline of the thesis in which you can know a general history of the viruses, evolution of the antivirus software. A definition to the virus, types of viruses, the most common methods or techniques used. In chapter 3 Literature Review, shows the research and review of some selected papers or literature that I found interesting about w antivirus software. In this chapter, there is research in which some antivirus products, techniques and algorithms compared according to the developments in the recent times. Chapter 4 Experimentation part of the thesis where the comparison of different commercial antivirus products based on their efficiency to detect a virus is shown and also the results are based on false positives, false negatives and hit ratios shown by each antivirus product. Chapter 5 Conclusion concludes the thesis summarizing research and experimentation done on antivirus products. Appendix holds relevant information about the undefined key words or frameworks used in this thesis. Chapter 2 Overview This chapter gives general information about the viruses and antivirus giving some basic information about the virus history and when the antivirus software evolved. There different types of viruses and are classified according to the attacking features. This chapter will lead to better understanding of the techniques used by the antivirus products and also gives you basic knowledge about different antivirus products. 2.1 History of Viruses The computer virus is a program that copies itself to the computer without user permission and infects the system (Vinod et al. 2009). Virus basically means an infection which can be of many types of malware which include worms, trojan horses, rootkits, spyware and adware. The first work on computer programs was done by John Von Neumann in 1949 (wiki 2010). In his work he suggested that a computer program (the term virus was still not invented) can self-reproduce. The first virus was discovered in early 1990s which is Creeper virus. Creeper copies itself to other computers over a network and shows messages on the infected machine: IM THE CREEPER: CATCH ME IF YOU CAN. It was harmless but to catch the Creeper and stop it the Reaper was released. In 1974 Rabbit a program that spreads and multiples itself quickly and crashes the infected system after it reaches a certain limit or number of copies. In 1980s the virus named Elk Cloner has infected many PCs. The Apple II computer which was released in 1977 loads its operating system from the floppy disks, using these characteristics the Elk Cloner installed itself to the boot sector of the floppy disk and was loaded already before the operating system. Ã ©Brain was the first stealth IBM-compatible virus. This stealth virus hides itself from being known and when detected it attempts to read the infected boot sector and displays the original, uninfected data. In 1987 the most dangerous virus got into news was Vienna virus which was first to infect the .COM files. Whenever the infected file was called it infects the other .COM files in the same directory. It was the first virus that was successfully neutralized by Bernd Fix and which leads to the idea of antivirus software. Then there were many viruses which were Cascade virus the first self-encrypting virus, Suriv Family virus which was a memory resident DOS file virus. Extremely dangerous virus was Datacrime virus which destructs FAT tables and cause loss of data. In 1990s there was Chameleon Virus, Concept virus and then CIH virus and in 2000s there were ILOVEYOU virus, My Doom Sasser. (Loebenberegr 2007) Vinod et al. 2009 defines computer virus as A program that infects other program by modifying them and their location such that a call to an infected program is a call to a possibly evolved, functional similar, copy of virus. To protect from the attacks, the antivirus software companies include many different methodologies for protecting against the virus attacks. 2.2 Virus Detectors The virus detector scans the file or a program to check whether file/program is malicious or benign. In this research there will be usage of some technical terms and detection methods which are defined below. The main goal for testing the file/program is to find for false positives, false negatives and hit ratio.(Vinod et. al. 2009) False Positive: This takes place when the scanner detects a non-infected file as a virus by error. They can be a waste of time and resources. False Negatives: This occurs when the scanners fail to detect the virus in an infected files. Hit Ratio: This happens when the virus scanner scans the virus. Detections are based on 3 types of malware which are: Basic In basic type the malware attacks the program at the entry point as shown in the figure 2.2.1. The control is transferred to virus payload as the entry point itself is infected. Infected Code Main Code Entry Infected by virus Figure 2.2.1 Attacking system by basic malware. (Vinod et al 2009) Polymorphic Polymorphic viruses are viruses which mutates by hiding the original code the virus consists of encrypted malware code along with decrypted unit. They create new mutants very time it is executed. The figure 2.2.2 shows how the main code or original code is encrypted by infected file to produce a decrypted virus code. Virus Code Decrypted Code Main Code Entry Encrypted by infected file Figure 2.2.2 Attacking system by polymorphic viruses. (Vinod et al 2009) Metamorphic Metamorphic viruses can reprogram themselves using some obfuscation techniques so that the new variants are not same as the original. It sees that the signatures of the subsets are not same as the main set. Form B Virus A Form A S1 S2 S3 Figure 2.2.3 Attacking system by metamorphic viruses. (Vinod et al 2009) The above figure 2.2.3 shows that the original virus and form of that virus have different signatures where s1, s2 s3 are different signatures. 2.3 Detection Methods 2.3.1 Signature based detection Here the scanners search for signatures which are sequence of bytes within the virus code and shows that the programs scanned are malicious. The signatures are developed easy if the network behavior is identified. Signature based detection is based on pattern matching. The pattern matching techniques evolved from times when the operating system was DOS. The viruses then were parasitic in nature and used to attack the host files and most common executable files. (Daniel, Sanok 2005) 2.3.2 Heuristic based detection Heuristics describe a method of scanning a virus by evaluating the patterns of behaviors. It takes the possibility of the file or program being a virus by testing the uniqueness and behavior matching them to the database of the antivirus heuristic which contains number of indicators. It is helpful to discover those viruses which does not have signatures or hides their signatures. It is also helpful to detect the metamorphic viruses (Daniel, Sanok 2005) 2.3.3 Obfuscation Technique This technique is used by the viruses to transform an original program into virus program using some transformation functions which makes the virus program irreversible, performs comparably with original program and has the functions of the original program. This technique is used mainly by metamorphic and polymorphic viruses. (Daniel, Sanok 2005) Antivirus Products There are many antivirus products available in the commercial market. Some of the most commonly used antivirus products are: McAfee G Data Symantec Avast Kaspersky Trend Micro AVG Bit Defender Norton ESET Nod32 Chapter 3: Literature Review 3.1 Antivirus workload characterization A research done by (Derek, Mischa, David 2005) shows an antivirus software package takes many ranges of techniques to check whether the file is infected or not. But from the observations of (Derek, Mischa, David 2005) to best difference between some antivirus software packages compare the overheads introduced by the respective antivirus software during on-access execution. When running antivirus software there is usage of two main models which are: on-demand. on-access. On-demand involves the scanning of the user specified files where as on-access can be a process that checks the system-level and the user-level operations and scans when an event occurs. The paper discusses the behavior of four different anti-virus software packages which run on a Intel Pentium IV being installed with Windows XP Professional. Considering three different test scenarios: A small executable file is copied from the CDROM to the hard disk. Executing a calc.exe And also executing wordpad.exe. All these executable files are running on the Windows XP Professional operating system. The antivirus packages used in this experiment were Cillin, F-Port, McAfee and Norton. The execution of the files are done using the before mentioned antivirus packages. Figure 3.1.1 shows the usage of these packages introduces some overheads during the execution which increases the time of execution. Fig 3.1.1 Performance degradation of antivirus packages (Derek, Mischa, David 2005) Then a test was made to know about the extra instructions executed when the file system operations is performed and also when loading and executing a binary. Taking the both scenarios a small binary of very less size is involved. It is found that the execution is dominated by some hot basic blocks in each antivirus package. A basic block is considered hot if it is visited more than fifty thousand times. To detect the behavior of antivirus software packages the (Derek, Mischa, David 2005) used the platform which was majorly targeted by the virus attacks and also must have the existence of some of the commercial antivirus software. A framework of simulator is introduced here called Virustech Simics this has architectural structure as shown in table 3.1.1. Virustech Simics is a simulator that includes a cycle-accurate micro-architectural model and used to get cycle-accurate performance numbers. Table 3.1.1 Virustech Simics architectural structures (Derek, Mischa, David 2005) Processor Model Processor Operating Frequency L1 Trace Cache L1 Data Cache L2 Cache Main Memory Intel Pentium 4 2.0A 2GHz 12K entry 8KB 512KB 256MB The goal behind the model is to confine the execution of antivirus software on a system. To achieve metrics the stream executed is passed to the simulator. To simulate the micro-processor, simics are configured. The host (simulator) executes the operating system loaded via simulated hard drive. On top of the operating system the researchers have installed and run the antivirus software and also the test scenarios are taken (see figure 3.1.2). After this the comparison is done between the baseline configuration execution (without the antivirus software installed) and the systems that are installed with four different antivirus packages. L2 Cache Copy/execute process Antivirus Process L1 Inst Cache L1 data Cache Operating System (Windows XP) Inst Stream Simulate micro-architecture Simulated Architecture HOST Fig 3.1.2 Multi Level architectural Micro Architectural simulation environment (Derek, Mischa, and David 2005) The table 3.1.2 shows the summary of five configurations. For each experiment an image file is created and loaded as a CDROM in the machine. The execution of the utility (contains special instructions) at the start and end of each collection was done in order to assist accurate profile collection. Table 3.1.2: Five environments evaluated: Base has no antivirus software running (Derek, Mischa, David 2005) Configuration Anti-Virus edition Version Base NAV PC-Cillin McAfee F-Port Norton Anti-Virus Professional 2004 Trend Micro Internet Security McAfee Virus scan professional F-Port Antivirus for windows 10.0.0.109 11.0.0.1253 8.0.20 3.14b The three different operations invoke anti-virus scanning. In first, a file from the CDROM to the hard drive was copied, and then the operating system accessories: calculator and wordpad are run accessing through a shortcut. After experimentation it is found that there is less than one percent difference in the work load parameters throughout the profile runs. Then on doing the antivirus characterization it is seen that there is a gradual increase in the cache activity which shows that the overheads released is smallest for F-Port and highest for Norton. The impact on memory while running the antivirus software shows that Norton and McAfee have larger footprints that the Base case, F-Port Cillin. 3.2 Development techniques a framework showing malware detection using combination of techniques There are several developments in techniques used by antivirus software. These techniques must be able to detect viruses which were not detected by previous techniques and this is what we say a development in technique. Antivirus software not only does detect a virus but also worms, Trojan horses, spyware and other malicious codes which constitute malware. Malware is a code or a program which intents to damage the computer with its malicious code. We can filter malware by use of specific antivirus software that installs detection techniques and algorithms. Several commercial antivirus programs uses a common technique called signature-based matching; this technique must be often updated to store new malware signatures in virus dictionary. As the technology advances plenty of malware writers aim to employ better hiding techniques, importantly rootkits became a security issue because of its higher hiding ability. There is a development of many new detection methods which are used to detect malware, machine learning technique and data mining technique. In this research Zolkipli, M.F.; Jantan, A.,2010 have proposed a new framework to detect malware for which there is a combination of two techniques signature based technique and machine learning technique. This framework has three main sections which are signature-based detection, genetic algorithm based detection signature generator. Zolkipli, M.F.; Jantan, A., 2010 defines malware as the software that performs actions intended by an attacker without consent of the owner when executed. Every malware has precise individuality, goal attack and transmission method. According to Zolkipli, M.F.; Jantan, A., 2010 virus is that malware, which when executed tries to replicate itself into other executable code within a host. What so ever, as technology advances creating malware became sophisticated and extensively improved since early days. Signature-based matching technique is most common approach to detect malware, this technique works by contrasting file content with the signature by using an approach called string scan that search for pre-defined bit patterns. There are some limitations which needs to be solved to this technique though it is popular and very reliable for host-based security tool. The problem with signature-based matching technique I it fails to detect zero-day virus attack or zero-day malware attack. Zero-day malware attack are also called new launch malware. To store and capture a new virus pattern for upcoming use, some number of computers needs to be infected. Figure 3.2.1 shows an automatic malware removal and system repair was developed by F.Hsu et al. 2006 which has three important parts such as monitor, a logger, and a recovery agent. The framework solves two problems: Determines the un-trusted program that breaks the system integrity. Removal of un-trusted program Untrusted Process Trusted Process Logger Recovery agent Monitor Operating System Figure 3.2.1: Framework for monitoring, logging recovery by F.Hsu et al. 2006 The framework is used to monitor and enter logs of the un-trusted program. This framework is capable of defending known and unknown malware, though it does not need any prior information of the un-trusted programs. And from the user side there is no need of modifying any current programs and need not observe that the program is running in the framework as the framework is invisible to both known and unknown malware. A sample of this framework was used on the windows environment and shows that all the malware changes can be detected compared to the commercial tools which use the signature based technique. Machine learning algorithm was tested and applied on the malware detection technique. In order to classify the signature-based technique limitations that particular technique was using an adaptive data compression. The two restrictions of signature-based technique according to Zolkipli, M.F.; Jantan, A., 2010 are: It is not compulsory that all malicious programs have bit patterns which are proof of their malicious nature and are also not recorded in virus dictionaries. Many forms of bit patterns are taken by obfuscated malware that will not work on signature-based technique. Genetic Algorithm (GA) takes the full advantage of system limitations that are used to detect zero day malware or the day malware was launched. The algorithm was used to develop a detection technique called IMAD that analyzes the new malware. To oppose the restrictions of signature-based detection technique this technique has been developed. Data mining is another technique which was applied on malware detection much before. The standard data mining algorithm classifies every block file content as normal or used to categorize potentially the malware. To defeat the limitations of signature-based antivirus programs an Intelligent Malware Detection System known as IMDS was developed. This system used Object Oriented Association which adapts OOA_Fast_FPGrowth algorithm. A complete experimentation on windows API file sequence was done which re called PE files. The huge gathering of PE files was taken from the King Soft Corporation antivirus laboratory which is used to compare many malware detection approaches. The results show that IMDS system shows the best results than Norton and McAfee. The proposed framework has two techniques combined which are signature-based technique and GA technique. It was designed to resolve two challenges of malware detections. How to detect newly launched malware (Zolkipli, M.F.; Jantan, A., 2010) How to generate signature from infected file (Zolkipli, M.F.; Jantan, A., 2010) Signature Generator S-Based Detection GA Detection Figure 3.2.2: Framework for malware detection technique (Zolkipli, M.F.; Jantan, A., 2010) The main components are s-based detection, s-based generator and GA detection(see figure 3.2.2). The s-based detection acts first in defending the malware, then GA detection is the second layer which is another defense layer that is used to detect newly launched malware. After creating the new signature from zero-day malware these signatures are used by signature based detection technique. Signature based detection is a fixed examining method used on every antivirus product. This is also called a static analysis method. This decides whether the code is malicious or not by using its malware characterization. This technique is sometimes also called scan strings. In general every malware has one or more patterns of signature which has unique characters. Antivirus software searches through data stream bytes, when a program is executed. Database of antivirus software has thousands of signatures it scans through each signature comparing it with the program code which is executed. For comparing purposes searching algorithm is used, the comparison is usually between program code content with the signature database. The Zolkipli, M.F.; Jantan, A., 2010 chooses this technique at the beginning of the framework because of its effective detection of well known viruses. This technique was used in this framework in order to develop the competence of computer operation. G.A detection technique is one of the most popular technique that is used to detect newly launched malware. This is used to learn approaches to resolve algebraic or statistical research problems. This is a machine learning technique which applies genetic programming that learns a evolving population. Chromosomes are used for data representation which is used in this algorithm, chromosomes are bit string values, new chromosomes are developed from a bit string combinations from existing chromosomes. Basing the nature of the problem the solution for the problem is given. Crossover and mutation are 2 types of basic operations in GA, to solve the issues concerned with polymorphic viruses and new types of malware this technique was introduced in this framework. By using this technique codes of malware using hidden technique can also be detected which only because of its learning and filtering aspects of virus behavior.( Zolkipli, M.F.; Jantan, A., 2010) S-based generator generate string patterns are used by signatures which are used to characterize and identify the viruses. Forensic experts started creating signatures once a new virus sample is found, based on the virus behavior these signatures are created. All the antivirus products creates their own signatures and accessing records they are encrypted in case there are more than one antivirus software installed on the computer. As soon as a signature is created the signature database is updated with it. Every computer user requires updating the antivirus product with the database in order to defense against the new viruses. Signature pattern is 16 bytes and to detect 16 bit virus 16 bytes is more than enough.( Zolkipli, M.F.; Jantan, A., 2010) This generator takes the behavior of virus which identified by the GA detection. The signature pattern of the virus is generated and is added to virus database as a new signature for the signature based detection. To replace the forensic experts task this framework was proposed. This creation of framework was lot useful in detecting the new virus signature, and to improve the efficiency and performance of the computer. 3.3 Improving speed of signature scanners using BMH algorithm. This paper discusses about the problem of detecting viruses using signature scanning method that relies on fast pattern matching algorithm So basically in this technique the pattern is a virus signature which is searched for anywhere in the file. This algorithm is an expensive task which affects the performance frequently. Many users may find it impatient if the pattern matching algorithm does not work fast and consumes lot of time. So to avoid this faster pattern matching algorithm is used to the scanner which is Boyer-Moore Horspool algorithm when compare d to Boyer-Moore algorithm and Turbo Boyer Moore algorithm proved to be the fastest pattern matching algorithm. In technical terms, a virus has three parts which are trigger, infection mechanism and payload. The main mechanism which is infection mechanism part actually looks for fatalities and frequently avoids multiple infections. After looking for fatalities it might overwrite the fatalities or can attach itself at the beginning of the file or at the end of the fle. Trigger is actually a event which specifies when the payload has to be executed. The payload is the foundation of malicious behavior which actually can be corruption of boot sector or manipulating files. To detect a virus and to disinfect the infected file are two most important tasks of algorithms used by antivirus software. So defense system code of the algorithm must have a part that is able to detect any type of virus code. There are four types of basic detection techniques. Integrity Checking Signature Scanning Activity Monitoring Heuristic Method. Integrity checking technique: This program gives checker codes that can be checksums, CRCs or hashes of files that are used to check viruses. Regularly the checksum are re-computed and is compared against the previous checksums. In case the two checksums does not match it is indicated that the file is infected since the file is modified. This technique detects the virus presence by detecting the change in files and also is capable to detect new or unknown viruses. But this technique has several drawbacks. Firstly, the primary checksum calculation has to be performed on a virus less clean system so the technique can never detect viruses if system is infected. Secondly there are lots of false positives if the system is modified during execution. (Sunitha Kanaujiya, et., al 2010) Signature scanning technique: This technique is used on large scale to detect virus. This reads data from a system and to that it applies pattern matching algorithm to list of existing virus patterns in case it matches with the existing patterns it is a virus. This scanning technique is effective but the pattern database needs frequent updating which is very easy. There are several advantages of this scanner one of it is the scanning speed for this technique can be increased, it can also be used to detect other types of malicious programs like Trojan horses, worms, logic bombs, etc. So mainly for the virus it is only signature of the virus which is needed and update it to the database. This technique is used on many viruses due to this reason. Activity monitoring technique: This technique is used to monitor the behavior of programs executed by some other programs these monitoring programs are known as behavior monitor and they stay in main memory. The behavior monitors alarms or do some action to prevent the program when it tries to do some unusual activities like interrupting tables, partition tables or boot sectors. The database maintains every virus behavior that is supposed to be. The main disadvantage is when the new virus uses another infecting method that is not in the database and in this scenario finding virus is helpless. Secondly viruses avoid defense by activating earlier in the boot sequence prior to the behavior monitors. And also viruses modify the monitors
Sunday, August 4, 2019
Dealing with Transformation in The Metamorphosis Essay -- Papers
Dealing with Transformation in The Metamorphosis In The Metamorphosis Gregor Samsa is forced to deal with his transformation from a human being into an insect. After his transformation Gregor is no longer able to do everyday ordinary things. He now has to depend on someone to do these things for him. His younger sister, Grete, makes herself responsible for Gregor. She takes it upon herself to make sure that Gregor is fed and his room is cleaned. This leads to the question; why does she place such a huge responsibility on herself? An optimist like Gregor who only sees the good side of people would say it is because she is a loving and caring person. That her brotherââ¬â¢s current condition makes her feel sorry for him and she wants to help him in any way possible. However a pessimist would see an ulterior motive to his sistersââ¬â¢ actions. Since the narrator of the story is Gregor the reader is introduced to Grete through the optimistââ¬â¢s point of view. Gregor portrays Grete as a nurturing and caring person who se actions are solely based on what is best for Gregor. However, what if the narrator was not Gregor but a neutral person who had no prior relationship to Grete? Would Greteââ¬â¢s motives for helping Gregor appear to be purely unselfish? There are many points in the story that the reader is left with the feeling that Grete might have ulterior motives. If the narrator were an impartial character Greteââ¬â¢s intentions would not appear to be so pure. Greteââ¬â¢s motives from the beginning of the story are questionable. Why does she make herself responsible for Gregor? Gregor believes that she ââ¬Å"had perhaps taken on so difficult a task merely out of childish thoughtlessnessâ⬠(100). However there is another .. ...ghout the novel. Gregor throughout the book constantly misreads his sisterââ¬â¢s actions and misinterprets her motives. Since the story is told through Gregorââ¬â¢s point of view we perceive Grete through most of the novel as someone who is unselfish and helpful. However at the end we find ourselves wondering if Greteââ¬â¢s intentions are really as pure as Gregor thinks. Did Grete plan from the beginning to get rid of Gregor? The truth is once Gregor was out of the picture Grete became the needed and helpful child. Grete had a lot to gain and nothing to lose by getting rid of Gregor. Gregor is not impartial when it comes to his sister and he is unable to perceive her bad intentions because he thinks so highly of her. Therefore it can be said that if the narrator of the story was a detached character Grete would not appear to be so harmless and innocent.
Saturday, August 3, 2019
ft.lauderdale high AP bio project :: essays research papers
2) LEVEL 1 - Cells Are the basic unit of structure and function in living things.May serve a specific function within the organism Examples- blood cells, nerve cells, bone cells, etc. tissue LEVEL 2 - Tissues Made up of cells that are similar in structure and function and which work together to perform a specific activity Examples - blood, nervous, bone, etc. Humans have 4 basic tissues: connective, epithelial, muscle, and nerve. LEVEL 3 - Organs Made up of tissues that work together to perform a specific activity Examples - heart, brain, skin, etc. LEVEL4 - Organ Systems Groups of two or more tissues that work together to perform a specific function for the organism. Examples - circulatory system, nervous system, skeletal system, etc. LEVEL 5 - Organisms Entire living things that can carry out all basic life processes. Meaning they can take in materials, release energy from food, release wastes, grow, respond to the environment, and reproduce. Usually made up of organ systems, but an organism may be made up of only one cell such as bacteria or protist. Examples - bacteria, amoeba, mushroom, sunflower, human 4) 1)Atom: The smallest unit of matter that retains the properties of an element. 2) Ion: An atom that has gained or lost electrons thus acquiring a charge. 3) Electronegativity: The attraction of an atom for the electrons of a covalent bond. 4) Hydrogen Bond: A type of weak chemical bond formed when the slightly positive hydrogen atom of a polar covalent bond in one molecule is attracted to the slightly negative atom a polar covalent bond in another molecule. 5) Hydrophilic: Having an affinity for water. 6) Cohesion: The binding together of like molecules, often by hydrogen bonds. 7) Capillary action: Physical effect caused by the interactions of a liquid with the walls of a thin tube. The capillary effect is a function of the ability of the liquid to wet a particular material. 8) Organic Compound: Ccontains carbon chemically bound to hydrogen. Organic compounds often contain other elements (particularly O, N, halogens, or S). 9) Polar Covalent Compound: A type of covalent bond between atoms that differ in electronegativity. The shared electrons are pulled closer to the more electronegative atom, making it slightly negative and the other atom slightly positive. 10) Molecule: Two or more atoms held together by covalent bonds. 11) Isotope: One of several atomic forms of an element, each containing a different number of neutrons and thus differing in atomic mass. 12) Ionic bonding: A chemical bond resulting from the attraction between oppositely charged ions. 13) Nonpolar covalent bond: A type of covalent bond in which electrons are shared equally between two atoms of similar electronegativitiy.
Friday, August 2, 2019
Epic of Beowulf Essay - Beowulf as Anglo-Saxon Hero :: Epic Beowulf herobeo
Beowulf - An Anglo-Saxon Hero A hero is a person of distinguished courage who has outstanding qualities and abilities, who is admired for these having these aspects of their character and also admired for brave and noble acts. An Anglo-Saxon hero is a person who has good leadership qualities, is able and willing to provide people with a sense of security, and is willing to go into danger despite possible harm to themselves. These Anglo-Saxon heroes usually were kings or thanes because they distinguished themselves above others by doing a good for the greater of everyone. This person has to be willing to put their own lives on the line for the benefit of others. There are several heroic characteristics, all of which Beowulf possesses. First of these characteristics is honor. Honor is showing a sense of integrity in oneââ¬â¢s actions. When Beowulf went to the land of the Danes to kill Grendel, he did it not because he wanted money, but because he wanted to help out the Geats. Beowulf felt as if it was the right thing to do since he had been successful in past deeds which he proudly says in lines 321-322, where he says ââ¬Å"They had in remembrance my courage and might. Many had seen me come safe from the conflict,â⬠. Beowulf expected no reward for his action, but rather just being able to ââ¬Å"put another notch in his belt.â⬠Another heroic characteristic, which Beowulf possesses, is bravery. Bravery is being able to go against the odds and possibly risk your life in the process. An example of Beowulf showing bravery is when he goes to slay the dragon even though all his men abandon him. He realizes that the dragon is more powerful than he is, but he will still not back down. In line 1493, he says ââ¬Å"Not one footââ¬â¢s space will I flee from the monster,â⬠thus showing his true bravery by not giving up to the more powerful foe. One more heroic characteristic of Beowulf is his strong sense of duty. This means that he is always devoted to his people, his king, and their security. An example of this is again when he goes to slay the dragon. He has no help, he realizes that the dragon is more powerful, and most importantly, he realizes that he will probably not be returning victorious from this battle.
Thursday, August 1, 2019
Bharat Sanchar Nigam Limited
Bharat Sanchar Nigam Limited (known as BSNL, India Communications Corporation Limited) is a public sector communications company in India. It is the India's largest telecommunication company with 25.14% market share as on December 31, 2007. Its headquarters are at Bharat Sanchar Bhawan, Harish Chandra Mathur Lane, Janpath, New Delhi. It has the status of Mini-ratna ââ¬â a status assigned to reputed Public Sector companies in India. BSNL is India's oldest and largest Communication Service Provider (CSP). Currently BSNL has a customer base of 68.5 million (Basic & Mobile telephony). It has footprints throughout India except for the metropolitan cities of Mumbai and New Delhi which are managed by MTNL. As on December 31, 2007 BSNL commanded a customer base of 31.7 million Wireline, 4.1 million CDMA-WLL and 32.7 million GSM Mobile subscribers. BSNL's earnings for the Financial Year ending March 31, 2007 stood at INR 397.15b (US$ 9.67 b) with net profit of INR 78.06b (US$ 1.90 billion). Today, BSNL is India's largest Telco and one of the largest Public Sector Undertaking with estimated market value of $ 100 Billion. The company is planning an IPO with in 6 months to offload 10 % to public. Bharat Sanchar Nigam Ltd. formed in October, 2000, is World's 7th largest Telecommunications Company providing comprehensive range of telecom services in India: Wireline, CDMA mobile, GSM Mobile, Internet, Broadband, Carrier service, MPLS-VPN, VSAT, VoIP services, IN Services etc. Within a span of five years it has become one of the largest public sector unit in India. BSNL has installed Quality Telecom Network in the country and now focusing on improving it, expanding the network, introducing new telecom services with ICT applications in villages and wining customer's confidence. Today, it has about 47.3 million line basic telephone capacity, 4 million WLL capacity, 20.1 Million GSM Capacity, more than 37382 fixed exchanges, 18000 BTS, 287 Satellite Stations, 480196 Rkm of OFC Cable, 63730 Rkm of Microwave Network connecting 602 Districts, 7330 cities/towns and 5.5 Lakhs villages. BSNL is the only service provider, making focused efforts and planned initiatives to bridge the Rural-Urban Digital Divide ICT sector. In fact there is no telecom operator in the country to beat its reach with its wide network giving services in every nook & corner of country and operates across India except Delhi & Mumbai. Whether it is inaccessible areas of Siachen glacier and North-eastern region of the country. BSNL serves its customers with its wide bouquet of telecom services. BSNL is numero uno operator of India in all services in its license area. The company offers vide ranging & most transparent tariff schemes designed to suite every customer. BSNL cellular service, CellOne, has more than 17.8 million cellular customers, garnering 24 percent of all mobile users as its subscribers. That means that almost every fourth mobile user in the country has a BSNL connection. In basic services, BSNL is miles ahead of its rivals, with 35.1 million Basic Phone subscribers i.e. 85 per cent share of the subscriber base and 92 percent share in revenue terms. BSNL has more than 2.5 million WLL subscribers and 2.5 million Internet Customers who access Internet through various modes viz. Dial-up, Leased Line, DIAS, Account Less Internet(CLI). BSNL has been adjudged as the NUMBER ONE ISP in the country. BSNL has set up a world class multi-gigabit, multi-protocol convergent IP infrastructure that provides convergent services like voice, data and video through the same Backbone and Broadband Access Network. At present there are 0.6 million DataOne broadband customers. The company has vast experience in Planning, Installation, network integration and Maintenance of Switching & Transmission Networks and also has a world class ISO 9000 certified Telecom Training Institute. Scaling new heights of success, the present turnover of BSNL is more than Rs.351,820 million (US $ 8 billion) with net profit to the tune of Rs.99,390 million (US $ 2.26 billion) for last financial year. The infrastructure asset on telephone alone is worth about Rs.630,000 million (US $ 14.37 billion). BSNL plans to expand its customer base from present 47 millions lines to 125 million lines by December 2007 and infrastructure investment plan to the tune of Rs. 733 crores (US$ 16.67 million) in the next three years. The turnover, nationwide coverage, reach, comprehensive range of telecom services and the desire to excel has made BSNL the No. 1 Telecom Company of India. History The foundation of Telecom Network in India was laid by the British sometime in 19th century. The history of BSNL is linked with the beginning of Telecom in India. In 19th century and for almost entire 20th century, the Telecom in India was operated as a Government of India wing. Earlier it was part of erstwhile Post & Telegraph Department (P&T). In 1975 the Department of Telecom (DoT) was separated from P&T. DoT was responsible for running of Telecom services in entire country until 1985 when Mahanagar Telephone Nigam Limited (MTNL) was carved out of DoT to run the telecom services of Delhi and Mumbai. It is a well known fact that BSNL was carved out of Department of Telecom to provide level playing field to private telecoms. Subsequently in 1990s the telecom sector was opened up by the Government for Private investment, therefore it became necessary to separate the Government's policy wing from Operations wing. The Government of India corporatised the operations wing of DoT on October 01, 2000 and named it as Bharat Sanchar Nigam Limited (BSNL).BSNL operates as a public sector.
Arthur Millerââ¬â¢s Commentary Essay
Arthur Millerââ¬â¢s commentary helps our understanding of the play very much. Through more character detail he has made it possible for us to understand exactly how the different characters are feeling, and why they behave the way they do, as in the case of Abigail using the whole situation to her advantage, and being very manipulative and sly, all of which are characteristics that we donââ¬â¢t like in ourselves. For example, Abigail was using the whole situation to get back at John Proctor, she wanted him but he didnââ¬â¢t want her, and in trying to gain his affections, she involved all of the people of Salem. During the play Abigail had one goal (to get John Proctor) and she didnââ¬â¢t care how she achieved this. Throughout the play the contrast between light and dark is a prominent feature. In the footnote at the begging of act one Miller has used the image of light ââ¬Å"There is a narrow window at the left. Through itââ¬â¢s leaded pains the morning sunlight streams. A candle still burns near the bedâ⬠¦ The room gives of an air of clean spareness.â⬠This symbolises that everything is OK, there are no bad things happening. Light throughout the play is use to represent good. As the story line continues the mood and even the scenes themselves become darker and more evil, even the weather becomes more negative and depressing. Dark is used throughout the play to symbolise bad. For example, the courtroom is always dark; there are no open windows and no candles. In some cases certain characters bring light into a scene that was dark, like John Proctor. But when he is accused of witchcraft the light that accompanies him became a lot dimmer. I also think Arthur Miller makes it very easy for us to pick out good and bad characters at the beginning of the play. But some of the characters switch sides as the play goes on, at the beginning of the play I found Reverend Hale was very annoying. However as the play developed he was one of the people who could see sense in the situation. Towards the end of the play you could tell which characters were good, and which were bad. Arthur Miller also puts the audience in a very annoying position because we can see how wrong and how stupid the characters are being. The audience would get very angry at the fact that only John Proctor and Mr Hale can see sense, even though it takes two acts for them to see it. An example of this would be John Proctorââ¬â¢s reaction to Abigail stumbling in with a needle in her stomach, claiming that John Proctorââ¬â¢s wife is a voodoo witch. ââ¬Å"Why she done it herself I hope you arenââ¬â¢t takin it for proof, Misterâ⬠. Abigail claims this to get back at John Proctor; the audience however are led to believe that she did it to herself, even though it is not actually said in the text. All of this would make the audience very angry, and would make us start to think why the characters arenââ¬â¢t doing anything about it. In this case Iââ¬â¢m going to point out Judge Danforth because he is so wrapped up in his own little world and doing what he thinks is ââ¬Å"rightâ⬠. At first Danforth only frustrated me with his ignorance, but as the story line developed I found my frustration turning to anger and my anger into hate. Abby also frustrated me because she twisted the situation for her own benefit and to get at John Proctorà At the end of each act Miller leaves the play in a state of climax. At the end of act one Miller draws the curtain on the girlââ¬â¢s firing frantic and false accusations of witchcraft against many women in Salem, act three ends with the dramatic exit of Mr Hale ââ¬Å"I denounce these proceedings, I quit this court!â⬠Through this approach it always keeps the audience on the edge of their seats. It keeps the audience swept up in the story line, almost like a soap opera today, where each episode ends with a dramatic last scene (cliff hanger), and ensuring they watch the next episode because they want to know what happens, I find it very frustrating. In fact, The Crucible is very similar to a modern day soap opera, in that its success as a whole depends on how involved the viewers, or audience, become with the characters and the story line. I also think that because it is based on history, the story might not be true to word, which adds fascination. The play was not only written to record historical events in Salem but was also written to warn people of modern day witch hunts, such as the McCarthy ââ¬Å"witchâ⬠hunt (1950ââ¬â¢s) in which people were asked to turn in anyone who was a Communist at the time. The naming and shaming followed a similar pattern of that in Salem.
Subscribe to:
Posts (Atom)