Showing posts with label example. Show all posts
Showing posts with label example. Show all posts

Tuesday, April 8, 2008

Network Probes

A network probe or sniffer is a very useful tool for troubleshooting network problems. You can find software and hardware network sniffers that collect data packets from the network and allow you to examine them to determine what is causing a problem on your network.

Because the purpose of a network probe is to intercept packets and examine them, you can easily see how this could be very damaging when used for purposes other than troubleshooting.

Remember that the less information known about your network by outsiders, the more difficult it is to infiltrate your network. However, when someone has broken in, it's a simple task to plant a program that does nothing except listen to the network and send information back to the person who planted the program in the first place. Using a network sniffer for this purpose enables an outsider to find out all sorts of useful information about your computers, users, and network configuration. For example, you already know it's a bad idea to use FTP, Telnet, and other utilities that use clear-text to send usernames and passwords. However, you might think it's safe to use these inside your network. Well, that's not so. If someone has planted a program in a server on your network and is "probing" the packets that pass around your network, they'll find it very easy to further infiltrate your network by obtaining more user account information, and thus be able to compromise one computer after another. Use safe utilities inside your network as well as for communications on the Internet. An example of this would be to use the Secure Shell utilities.

Internet 2010

Spoofing and Impersonation

Just as it's a simple matter to create a program that can construct a steady stream of SYN packets and send them rapidly to your server, it's also easy to create network packets that have false information in other fields of the IP header. For example, you might have a firewall set up to reject packets from known sources of trouble, based on the source IP address found in the header. However, there's nothing to stop the hacker, cracker, or attacker from simply putting in another source address so that your firewall lets the packet through.

IP address spoofing is very easy to do. It's also very hard to detect. One thing a firewall can do, however, is guard against packets that contain a spoofed address, making it appear that the packet originated inside your network. Think about it. If the source address of a network packet falls within the address range of your internal network, it shouldn't be coming in through a firewall interface that's connected to the Internet. It should be the other way around! All good firewalls can be configured to drop packets that arrive from the outside world with an address that makes it look like the packet came from your network.

If It's Too Good to Be True, It Isn't

One of the more prevalent scams that has proliferated on the Internet in the past two years is the claim that you can make a fortune by helping out a civil servant, or the wife of an ex-legislator of a foreign country, usually Nigeria. When you get these emails, don't even try to respond. The scam involves your helping the sender transfer his secret funds to another bank outside the originating country. For a small fee, you can receive a few million in return. Yet, after you get involved, the person encourages you to open an account at a bank he uses (which is simply a Web site, not a bank) and transfer funds to that bank. In this manner e can (1) keep your cash and (2) in some cases gain access to your real account information from y r own bank.

This is just one example. Again, if it appears too good to be true, it isn't (true)! The Internet can be a great place to learn about new ideas, to get involved in e-commerce, and so on. It can also be a great place to get fleeced.

Another similar scam is an email that appears to come from a reputable company. Recently, emails from a site that appeared to be Microsoft was passed through the Internet. When you receive a suspicious email, look closely at the address of the email. Check the properties page of the email to see where it was sent from. You shouldn't get emails, for example, from Microsoft. com, or Ebay. . corn, unless you have granted them the right to send you emails. Yet, if you get an email from, say, Microsoft - readnow.com, don't open it! Check those emails carefully.

Preventative Measures

There are many standard techniques typically used to keep a network up and running. One of these preventative measures is regular backups. If your system becomes infected with virus programs or if you find that data has been corrupted, you'll understand the importance of regular, frequent backups. In addition, it's a good idea to keep offline copies of important data files for an extended period. Simply doing a backup each night and overwriting the tape or tapes the next night will provide you with very little protection. Damage to your system might not become evident until weeks or, in some cases, months after the initial intrusion.

There are also commercial and noncommercial products you can use to help safeguard your system. These include intrusion-detection mechanisms, antivirus programs, and programs that can monitor changes on important servers.

So where should you start when defining the defensive mechanisms needed to protect your network? Let's start at the edge of the network—the router.

Protecting Routers

Routers typically can be configured in several ways. You can attach a serial cable and terminal directly to most routers and perform configuration tasks. Another method is Telnet. Most modern routers allow you to Telnet into the router to perform configuration tasks. Turn this functionality on only when it is needed, and then turn it back off. The same goes for unnecessary protocols and services. In a manner similar to deciding what services you want to allow through a firewall (and in what direction), you should turn off all unnecessary services on a router. You'll have to consult your documentation to find out the particular commands you'll need to use.

You might want to check vendor Web sites for other router products that are in use on your network to look for similar advice. Additionally, be sure to stay informed of router firmware updates and operating-system updates and patches. As new threats are discovered, a responsible vendor will release information or code that can be used to help improve the security of the routers that stand guard at the edge of the network.

Tuesday, February 12, 2008

Defining Roles within the Project

Intranet project roles should be clearly defined at the outset of the project. This includes an understanding of job titles and of what each person adds to the project mix. It also includes an understanding of overlapping skills, and boundaries around their expectations of each other.

In Example A, two-thirds of the User-Centred Design group consisted of content writers and artists who were not familiar with the term UCD. The usability engineers were challenged to find their place within the group, to help clarify the difference between roles on the team, and to incorporate usability engineering techniques wherever possible.

To successfully integrate themselves with the rest of the team, the usability engineers worked to understand the value that each team member provided. Each person's role was considered equally valuable and respected, and each team member was encouraged to think outside of his or her role, even if his or her opinions were sometimes overruled. Focusing on the common goal helped promote a combined sense of ownership and teamwork that has extended throughout many different projects to this day. Still, the usability engineers should have gone one step further. Clarifying the role of each team member in writing would have formalized the plan, defining it clearly from the outset. For example:

Internet 2010

1. Usability Engineer. Conducts field studies and other observations, creates conceptual models, researches best practices, conducts heuristic evaluations of early design models and concepts, content (text, links, etc.), and navigation, provides the team with design feedback throughout the project.

2. Visual Designer. Creates intranet graphics, selects colours, fonts, and other graphical elements (buttons, links, etc.).

3. Content Provider. Writes all of the text that appears on the site, including text blocks, link names, button names, and banners, if included.

It is less important that the information be well written than that it be clear. In Example A, the usability engineers found that true working definitions were more appropriate than those you might find in a textbook. If the members of the project team feel that there is overlap in roles, for example, writing these issues down is a good way to ensure that they are dealt with. Doing so at the start of a project helps establish working relationships, expectations, and limits. A "roles" document can also help the project leader to understand who is responsible for what tasks.

People's familiarity with these roles is another critical factor. In our Example B, none of the consulting company's project team had worked together before. Although the roles of Project Manager, Technical Manager, and Developer were well established within the consulting company, all of the people filling these roles were new employees. To make matters worse, the concepts of usability engineering and information architecture were new to the consulting company as well, so no one quite knew how to integrate them into the process. The lack of clarity regarding roles within the consulting company was amplified when external clients became involved.

After the usability engineer created several page layouts, the visual designer created three concepts for the client to review. One of these concepts deviated drastically from the layouts — the navigation was on the right side of the screen. Although the usability engineer had made it clear to the visual designer that the right side navigation was not usable, she was on vacation when the concepts were presented. The client loved the uniqueness of the right side navigation model and selected it as the framework for the site. If the visual designer trusted the usability engineer and clearly understood the implications of an unusuable design, he might never have recommended the unorthodox design to the customer.

In addition, the usability engineer should have provided the team with extensive data supporting her page layouts. The team could have referred to this when the usability engineer was out of town.

Sunday, February 10, 2008

Identifying and Getting Access to Users

Successful intranet projects require access to users. In situations where this is discouraged, information may have to be gathered covertly. In situations where this is strictly forbidden, it is important to understand the limits and to find creative ways to work within them.

Identifying users of an intranet is as difficult as it is crucial. Getting access to them is more so. This proved to be a real challenge in Example A for several reasons. As is often the case, the project owners were concerned that employees would come to expect too much of the new portal. As a result, the usability engineers were told not to show associates prototypes or concepts that might "get their hopes up." Attempts at gathering information through field studies were repeatedly denied. The usability engineers were not to create any expectations at all, but to generate excitement whenever possible.

Internet 2010

What to do? The project leaders repeatedly described themselves and the developers as typical users, suggesting that the team observe them instead of going out to the stores. The usability engineers accepted the offer and treated the observations as sales opportunities. In one example, the usability engineers observed a project leader retrieving information from the newly designed intranet site. After conducting the observation, the usability engineers described the type of information that could be provided by actual (rather than representative) users, and how a fresh set of eyes might be useful. Eventually, the project leaders referred the usability engineers to customers who could be relied on to provide less biased feedback.

We took every possible opportunity to educate the business and technology sides of the project on the types of information that we could gather through field studies. One of the most difficult concepts for us to land was that users could provide us with useful information about their use of the intranet even if they had never used it. For example, users could have let us observe their current work areas, showing us their offices, allowing us to understand what systems they used and how an intranet site could make their lives easier. These educational opportunities challenged our ability to remain positive and resilient At times we spent more time complaining about our limited role than working to make the best of it. We should have visited the retail environment and gathered the information we needed any way we could.

In Example B, the usability engineer had access to the current site's webmaster and the supervisor of the employees who were most likely to use the site. Both of these people were invaluable resources. Although the client's Project Manager had forbidden the usability engineer from asking these experts what the site would be used for, the usability engineer was able to gather this information by asking good, carefully framed questions about the underlying technology. The usability engineer initially asked what type of files were being accessed on the site and then followed up with a questions about how the users would use the files and what the userstneeds were for the files. The subject matter experts didn't share the project managers' ideas that all the analysis was already complete and were therefore willing to discuss the users' need with the usability engineer. This data, covertly gathered and analysed, was used to build a solid information architecture, which was critical to the success of the site.

Thursday, January 31, 2008

Online Marketing Legal Developments

Although this chapter is divided into one section dealing with 'legal' and another with 'ethical' issues, it should become clear as you read through that the two areas are very much interrelated.

A comprehensive international legislation system that applies to global online trading does not exist at present and is not expected in the foreseeable future. Even within the USA, which is comparatively advanced in its use of the Internet, legal issues such as the validity of digital signatures have caused significant disagreements. While waiting for federal legislation, many states have set up their own laws, which have differed widely from state to state. Organizations such as the United Nations or bodies dealing with international trade law have been actively calling for global co-ordination of appropriate legal structures.

Copyright protection

Because the copyright legislation on the Internet is complex and vague, many Web site operators are reusing information from other sites. Comparison-shopping sites such as www.moneysupermarket.com, for example, rely heavily on aggregating information existing on other sites and presenting it in a comparative format. While this is acceptable in the USA, which allows data to be extracted and compiled in this way, there are indications that Europe may impose certain restrictions on what one site can do with another's information.

Internet 2010

Another contentious issue concerns domain name conflict. There have been a number of cases whereby individuals (known as `cybersquatters') have registered domain names that resemble established brands or generic terminology and thenattempted to sell the right to use that name to the company concerned. For example, Chen (2001) notes that the address `business.com' was sold for $7.5 million and `wine.com' for $3 million. The author goes on to describe the case of Marks and Spencer v. One in a Million Limited and Others, in which Marks and Spencer sued for infringement of its trademark after the defendant registered the domain name marksandspencer.com and demanded money in exchange for handing it over. The courts found in favour of Marks and Spencer, and One in a Million was prevented from using the name or trying to sell it to anyone else. Chen also describes the problem of character string conflicts that arise when there is more than one legitimate user of a certain combination of letters. Finally, remember the case of www.untied.com that was described in Chapter 6? This site was set up by an online 'vigilante' to publicize the customer service failings of www.ual.corn (United Airlines), and accurately mimics the logo, style and layout of the original site.

This example also illustrates that copying anything from a Web site is very easy — merely a matter of cutting and pasting the code — so that protection of any intellectual property is very difficult. A famous example concerns the ongoing dispute over the piracy of music on MP3 sites, which are file compression formats allowing songs to be freely transmitted over the Web and downloaded to an individual's computer. Peer-to-peer (P2P) sites such as www.napster.com allow

users to share the content of their computers, hard drives, and this technological innovation makes the worldwide sharing of music files even easier.

While legislation continues to lag behind technological developments, one of the few protections currently available to businesses is to patent innovative techniques that they have devised. In the case of Amazon v. Barnes and Noble in 1999, Amazon won a lawsuit against Barnes and Noble, which had tried to copy the famous 'one-click' ordering system pioneered by Amazon.

Contractual agreements

Electronic contractual agreements are part and parcel of e-Commerce. The registration procedure is part of the purchasing process and requests the buyer to scroll through a set of contract terms. The purchase sequence is completed only when the buyer has clicked his or her agreement to the terms and conditions presented. The validity of such an electronic contract has been tested already through the US courts, but it is not certain that it is globally acceptable. Consumer protection laws vary from country to country and the global operator must be aware of differing obligations that could impact on the validity of the transaction performed.

The importance of keeping track of changes in legislation that will affect e-Business cannot be underestimated. Certain legislation such as the law passed recently by the European Union regarding email marketing could have far reaching consequences. Effective from 1 March 2001, this law states that if a dispute occurs between a consumer and an online retailer in any of the fifteen countries of the EU, the consumer may file a suit in his or her own country. Small firms that have thrived from the freedom the Internet is offering may well find it harder now to maintain control over their direct email marketing campaigns in this increasingly legislative environment.

Internet Blogosphere