Friday, November 29, 2019

Access Control - Security Administration free essay sample

In todays world we consider access control as something that grants or denies entry to our homes and businesses using a system or device such as a key, access cards, security pins or even physical guards. Modern day systems can do much more than just restrict access to a given space, but their basic function is to do just that, restrict access. The Decision making process Do we need access control and why. Think for a moment how many buildings or facilities that you know of that don’t have at least a lock on the door. In todays civilized society we unfortunately also have crime and lots of it. Because of this, we must have access control.The main reason for controlling access is to prevent someone from entering that may want to steal and damage property or cause harm to those on the property. Why there are also many social reasons for access control, many companies also employ access control to limit liability and improve productivity by allowing people to feel safer in their workplace knowing that not just anyone can come in. We will write a custom essay sample on Access Control Security Administration or any similar topic specifically for you Do Not WasteYour Time HIRE WRITER Only 13.90 / page The decision to have access control ultimately depends on the needs of the property or people being protected. Access Control Functions The basic function of all access control systems is to grant or deny access into a facility you are controlling. In order to be effective, an access control system must use certain processes, these processes are: Identification, Authentication, Authorization, and Accountability. The Identification process gathers information on the person requesting the access. Authentication is used to prove or disprove identification, this can be accomplished by several methods, but generally something like an access code along with a smart card works well (something you have and something you know) Authorization is determined by rules that determine who can enter and under what circumstances.The final process is accountability, the process of reporting and logging who has requested access and the results of those requests. Types of systems Starting with the basics, guards are a type of access control system that dates back to the medieval times. Even today, guards are still used to keep people out or at the least keep people under control. Locks and keys have also been around quite some time and are conside red to be a reasonably good access control system. However, over time, criminals have learned how to get past everyday locks and use tools of the trade to circumvent the key locking systems or simply cut padlocks.PINs (Personal Identification Numbers) are also a type of security system, but since pins are often lost and can easily be stolen, they are not widely used by themselves as a type of access control. Smart cards, which are still widely used today, offer a form of security that can require (something you have and something you know) the smart card being something you have and the pin for it something you know. Biometric access control systems are so far the best type of access control we have today. The reasoning for this is because it relies on identifying unique human characteristics such as fingerprints, retinas, hands, etc.Since these characteristics are unique to each person like DNA, biometric access control systems are considered far better than the other systems I have listed. When it comes to access control of comput er systems, many of the same types of control systems mentioned above are also used along with passwords and encryption. Uses of different systems There are many ways to use the systems I have already mentioned. Almost all buildings use keys to lock doors, but depending on the facility, they might also use smart card or proximity cards to control access into different parts of the building.By doing this they can enhance security and effectively control the access to different areas all through a computerized system. This allows them to easily grant or deny access in a very short period of time or only allow access during certain times of the day. Biometric access control systems can also be used in the same manner. Being able to control access in this manner also allows for good tracking and logging of who comes and goes. Components of an access control system Components of an access control system can be a door, turnstile, gate, elevator, or any other physical barrier where granting access can be electronically controlled. The most common access point is a door. An electronically controlled access door can contain several elements. The most basic might be just a stand-alone electric lock that is controlled by a security guard. The lock could also be automated by adding a reader that is controlled by a computer system that compares against an access list and determines who is allowed in by either entering a code, having a card or even biometrics. Most of the time due to fire regulations only the entry is controlled and the exit is uncontrolled. In cases where exit is also controlled a second card reader is simply added to the other side of the door.In cases where exit is not controlled, a device called a request-to-exit (RTE) is used. Request-to-exit devices can be as simple as a push-button or a motion detector. Access control topology Access control decisions are made by comparing the credential to an access control list. This can be accomplished by a server, an access control panel or reader. â€Å"The development of access control systems has seen a steady push of the lookup out from a central host to the edge of the system, or the reader. The predominant topology circa 2009 is hub and spoke with a control panel as the hub and the readers as the spokes.The lookup and control functions are by the control panel. The spokes communicate through a serial connection; usually RS485. Some manufactures are pushing the decision making to the edge by placing a controller at the door. The controllers are IP enabled and connect to a host and database using standard networks. † (Ref: http://en. wikipedia. org/wiki/Access_control) Security Risks What are the risks vs. benefits Unfortunately, there are many risks, the most common of which is called piggybacking. This is when someone simply follows someone with access through the access control point. This risk can be minimized through training of staff on security awareness. Another way to mitigate this risk is to add a mantrap or security guard to the access control point, but this can be costly and should only be done in higher security areas. Another common risk is from levering or prying the door open. This is very easy to do on most doors and can be done with something as small as a screwdriver. One way to mitigate this risk is to add door monitoring alarms that sound when a door has been opened by force or notify security personnel.Access cards, specifically proximity cards are vulnerable to sophisticated attacks. Portable readers are readily available that can capture the card number from a user’s proximity card. The attacker just has to get closer enough to the card holder to read the card and can then use that information to access the secure door. Lastly, most all electric locking systems still have keys as a backup to gain entry. Mechanical key locking systems are easily picked using a method called bumping. Some of the benefits of access control are reduction in fraud. If an access card is lost or stolen, it can quickly be de-activated.Another benefit is the ability to create an audit trail. Since electronic access control systems can record who is coming and going and when, it’s easy to limit control in a very short amount of time if not instantly. It also allows administrators to quickly address security breaches. Another great benefit is cost control. Being able to control access to many different access control points from a single control center reduces overall cost and manpower needed to control access to the facility. It also reduces costs associated with having to replace locks when keys are lost.And most importantly, the ability to secure your workplace with access control systems. Conclusion Going back hundreds of years, access control systems have always been a part of our society. Modern day systems are more high tech and usually consist of electronic locks, keypads, card readers, or biometric devices. But these systems do much more than keep the wrong people out, they protect people and property. Protecting people and property are main reasons for deploying an access control system, but they also help improve productivity and limit liability.Whether an access control system is big or small or whether it is protecting a handful of people or thousands of people they all employ the same processes, just on a different scale. In the end they all serve the same purpose and that is to let the right people through the right doors at the right time. References Finger key, hand key and hand reader Retrieved October 1st , 2012 from http://www. officesecuritypro. com/office-security-articles/access-control-security-system. php Access Control Retrieved October 1st , 2012 from

Monday, November 25, 2019

Biography of California Senator Kamala Harris

Biography of California Senator Kamala Harris Kamala Harris  was born October 20, 1964, to a black Stanford University professor and a Tamil Indian physician mother. Harris became the first California attorney general with African American or South Asian ancestry after defeating Republican rival Steve Cooley in the 2010 election for the position. Harris,  formerly San Franciscos district attorney, is also the first woman to serve in the role. Kamala Harris announced she was running for president in 2020 on Martin Luther King, Jr. Day, 2019. Fast Facts: Kamala Harris Name: Kamala Devi HarrisBorn: October 20, 1964, in Oakland, CAKnown For: Junior Senator from California; sits on Senate Budget, Homeland Security and Governmental Affairs, Judiciary, and Intelligence committees. First woman, African-American, and South Asian district attorney in San Francisco. First California Attorney General with African-American or South Asian ancestry.Education: Howard University, Hastings College of the LawDistinctions and Awards: Named one of Californias top 75 women litigators by the legal paper The Daily Journal and a Woman of Power by the National Urban League. Awarded Thurgood Marshall Award by National Black Prosecutors Association. Named Rodel Fellow by the Aspen Institute. On the board of the California District Attorneys Association. Early Life and Education Kamala Devi Harris was raised in San Franciscos East Bay, where she attended public schools, worshipped at black churches, and lived in predominantly African-American communities. Her immersion in African-American culture didnt prevent her from being exposed to Indian culture, however. Her mother took Harris to Hindu temples to worship. Moreover, Harris is no stranger to India, having visited the subcontinent on several occasions to see relatives. Her bicultural heritage and travels around the globe have inspired political insiders to compare her with President Barack Obama. While Obama sometimes struggled with identity issues,  as he describes in his memoir Dreams from My Father, Harris evidently didnt experience growing pains in this vein. Harris attended high school in Quebec, where she moved with her mother following her parents divorce. After graduation, Harris attended Howard University, a historically black academic institution. She earned a bachelors degree from Howard in 1986 and then returned to the bay area in northern California. Upon her return, she enrolled at Hastings College of the Law, where she earned a law degree. Following that accomplishment, Harris proceeded to leave her mark on the legal arena of San Francisco. Career Highlights Law degree in tow, Harris began prosecuting murder, robbery, and child rape cases as deputy district attorney for the Alameda County District Attorneys Office, serving as a prosecutor from 1990 to 1998. Then, as managing attorney of the Career Criminal Unit of the San Francisco District Attorneys Office, a position she filled from 1998 to 2000, Harris prosecuted cases involving serial felons. Later, she headed the San Francisco City Attorneys Division on Families and Children for three years. But it was in 2003 that Harris would make history. At the years end, she was elected as the San Francisco district attorney, becoming the first female, black, and South Asian person to achieve this feat. In November 2007, voters re-elected her to the office. During her 20 years as a prosecutor, Harris has shaped an identity for herself as being tough on crime. She prides herself on doubling trial conviction rates for gun felonies to 90 percent as San Franciscos top cop. Also, with Harris as head, the San Francisco District Attorneys office increased the percentage of dangerous criminals sentenced to prison by more than half. But serious crime wasnt Harris only focus. She also tripled the number of misdemeanor cases sent to trial  and prosecuted the parents of truant children, which helped slash the truancy rate by 23 percent. Controversy The San Francisco District Attorneys Office found itself under fire in early 2010 when it came to light that Deborah Madden, a drug lab technician for the city police, confessed to removing cocaine from evidence samples. Her admission resulted in the police labs testing unit closing and pending drug cases being dismissed. The police department also had to investigate cases already prosecuted due to Maddens admission of evidence tampering. During the scandal, it was asserted that the District Attorneys Office knew of Maddens evidence tampering. However, it remains unclear what information the district attorney knew about Madden and when Harris learned of the techs improprieties. The San Francisco Examiner has alleged that the District Attorneys Office knew of the situation months before the public was told of the controversy and before the police chief himself learned of the news. Endorsements and Honors Harris won endorsements from Californias political elite while campaigning for Attorney General, including Senator Diane Feinstein, Congresswoman Maxine Waters, California  Lieutenant Governor Gavin Newsom, and former Los Angeles Mayor Antonio Villaraigosa. On the national stage, Harris had the backing of former U.S. Speaker of the House Nancy Pelosi. Leaders in law enforcement also endorsed Harris, including the then-police chiefs of San Diego and San Francisco. Harris has also won numerous honors, including being named one of Californias top 75 women litigators by the legal paper The Daily Journal and as a Woman of Power by the National Urban League. Additionally, the National Black Prosecutors Association gave Harris the Thurgood Marshall Award and the Aspen Institute chose her to serve as a Rodel Fellow. Lastly, the California District Attorneys Association elected her to its board. Senator Harris In January 2015, Kamala Harris announced her bid for the U.S. Senate. She defeated her opponent Loretta Sanchez to become the second woman of African or Asian descent to hold such a position. As a junior Senator from California, Harris sits on the Senate Budget, Homeland Security and Governmental Affairs, Judiciary, and Intelligence Committees. In 2017, she introduced 13 bills and resolutions, the majority dealing with public lands and natural resources, crime and law enforcement, and immigration. Member of the Resistance Harris is an outspoken advocate for immigrant and women’s rights, and a proud member of the resistance against Donald Trumps presidency. Speaking at the Women’s March in Washington, D.C., on January 21, 2017, the day after Trump was sworn into office, Harris called his inaugural address a â€Å"dark† message. Seven days later, she criticized his executive order barring citizens from terror-prone countries entry to the U.S. for 90 days, deeming it a â€Å"Muslim ban.† On June 7, 2017, during a Senate Intelligence Committee hearing, Harris put some tough questions to Rod Rosenstein, the Deputy Attorney General, over the role he played in the May 2017 firing of FBI director James Comey. As a result, Senators John McCain and Richard Burr admonished her for not being more respectful. Six days later, Harris was again taken to task by McCain and Burr for her hardline questioning of Jeff Sessions. Other Democratic members of the committee pointed out that their own questions had been similarly tough, yet Harris was the only member who received reprimands. The media got wind of the incidents and promptly leveled  accusations of sexism and racism against McCain and Burr. Sources Hafalia, Liz. Judge rips Harris office for hiding problems. San Francisco Chronicle, May 21, 2010. Herb, Jeremy. Senators try to quiet Harris, but she doesnt back down. CNN, June 7, 2017. Herndon, Astead W. Kamala Harris Declares Candidacy, Evoking King and Joining Diverse Field. The New York Times, January 21, 2019.

Thursday, November 21, 2019

DIVIDEND POLICY Essay Example | Topics and Well Written Essays - 750 words

DIVIDEND POLICY - Essay Example The management increased both the interim and final dividend throughout the four-year period. In 2007 the company paid an interim dividend of 6.5p which increased to 6.75p in 2008, 6.9p in 2009,7.6p in 2010 and finally 7.9p in 2011. For the case of the final dividend, the amount paid in 2008 was 13.5p, which was increased to 14.1p, 16.2p, 16.85p in 2009,200 and 2011 respectively (Associated British food, 2011). This is attributed to the increasing performance and profitability together with the increase in the performance of the general economy. Since the economy recovered from the recession and the inflation rates reduced, the company realized a reduction in the cost that made it post positive performance. The improving global economic performance also resulted in the increase in the sales turnover and improvement in ABF cash flows (Associated British food, 2011). Since the payments of dividends depends on the availability of cash flows, an increase in the cash inflows would result into an increase in the dividend that can be distributed to the company. Several theories have been developed o elucidate the relevance or irrelevance of dividends decision on the value of a firm (Lease, 2000). Modigliani and Millar dividend irrelevance theory asserts that dividends have no effect on the firms value in a perfect market because dividends are paid out of earnings and therefore whether distributed or not, it does not affect the firms earnings. Dividends have no effect on both equity and cost of equity (Baker, Powell & Veit, 2002). The bird in hand theory was also developed. According to this theory, dividend payments affect the value of a firm since investors are sure about the dividend earnings than the expected capital gains, which they consider as a bird in the bush (Miller & Kevin, 1985). The tax preference theory on the contrary claims that investors will prefer capital gains to the dividend because of the tax advantage associated with the capital gain. Since divi dends attract higher taxes, investors will prefer capital gain. The signaling theory further argues that dividend payment is significant in a firm’s investment decisions because it acts as a signal to the performance of the company. A company with high dividends is said to have better future prospects hence this will attract investors; the theory is based on the assumption that capital markets are imperfect and investors have different levels of knowledge (Benartzi, Roni & Thaler,1997). Before selecting a dividend policy, company managements must take into consideration the likely impact of their dividend decisions. Dividend decisions of a firm are important, as it can be use in influencing the value to the shareholders. In paying dividend, firms will considerer several factors. First, the dividend policy can be determined by the financial requirements of a firm. A firm that has several positive investment projects may decide to increase the proportion that is retained to inv est in the positive projects (Baker, Powell & Veit, 2002). Retention in this case provides the capital required to undertake the positive projects. Secondly, the dividend policy can also be determined by the nature of the company’s earnings. A company that realizes stable income in the financial performance can decide to increase the amount of dividends paid because of stability in the earnings whereas those with fluctuating incomes may reduce the amount of dividend distributed to the shareholders (Clayman, 2012). Moreover, firms’ liquidity also affects its dividend policy. A firm with better cash flows and which is liquid has the ability to make large dividend payments than that is not liquid. This is because dividends are always distributed out of cash and is therefore determined by the

Wednesday, November 20, 2019

Tab M Essay Example | Topics and Well Written Essays - 750 words

Tab M - Essay Example The present duty of the Missouri Secretary of State includes overseeing different crucial areas, which are generally election related, business related and other government related operations. In the election related operations, the Secretary of State often play the role of the main election official during the state elections. Secretary of State also regulates the office where registration of candidate takes place. In business duties, the Secretary of State is responsible for the registration of all the profit and non-profit based organizations within the state. Additionally, the Secretary of State does have to keep an eye over the libraries and archives of the state along with handling of other operations such as issuing of automobile registrations among others (sos.mo.gov, â€Å"Publications & Forms†). The ‘Streamlined Sales and the Use of Tax Agreement (SSUTA)’ is generally a kind of agreement implemented by the government of the United States, so as to carry out the sales process and the tax administration system within the member states in a simplified and transparent manner (mobudget.org, â€Å"Streamlined Sales And 2 Use Tax Agreement†). Currently, SSUTA is implemented with the prime intention of making Missouri capable enough to adopt the definition along with the procedures of the sales tax that has been agreed upon by all the 22 member states (Blouin, â€Å"Missouri House Committee Substitute Streamlined Sales Tax Bill Contains Significant Negative Policy Consequences†). The Streamline Sales tax Project (SSTP) is highly effective in simplifying the tax regulations and the sales process. The guidelines of the SSTP have subsequently helped multiple states within US in terms of upgrading their sales and tax systems (Streamlined Sales tax Project, â€Å"Welcome to the Streamlined Sales Tax Registration System†). The archives of the Missouri

Monday, November 18, 2019

MGT506 - Strategic Leadership, Mod 1 Case Assignment Essay

MGT506 - Strategic Leadership, Mod 1 Case Assignment - Essay Example Davis (2013) explained that business analytics is instrument to achieve objectives which transformed information as data to leverage in business competition. Admittedly, they have spent tremendous amount of obtaining invaluable assets and in developing storage or database to save essential uncovered insights as knowledge-base that can be useful, for instance, in social network analysis and in behavioural studies at multiple levels (Davis, 2013). This may include concerns on retail pricing, portfolio analysis, risks positions, banking or finance management, and the empirical demand of the market based on considered demography and customer needs (Davis, 2013). This expertise on business analytics is also provided as consultancy service to pharmaceuticals, industries, companies and institutions seeking expert consultancy on organizational capacity management (Davis, 2013). In a cursory look into the organization’s performance, it is driven to empower clients using advanced analyt ics for organizations to make use of its internal database to improve its competence, performance, financials, and its quest for meaningful innovative information (Davis, 2013). Through this, clients are inspired to make fact-based decision-making to generate great impact (SAS Inc., 2012). The company also partner with clients in all development process to ensure that they are able to generate maximum satisfaction of relevant services (SAS Inc., 2012). Such commitment target at getting shared outcome. The organization used creative capital for high performance analytics and client empowerment. This process is undertaken by optimizing technology in resolving problems on financial services, pharmaceutical market development, nurturing retail business opportunities, valuing customer relations, business risk management, optimizing information technology networks with cross-functional solutions via information management, analytics and business intelligence (SAS Inc., 2012). SAS services are rendered to 60,000 sites over 135 countries which include 90 of top companies of on the 2011 Fortune Global 500Â ® list (SAS Inc., 2012). The company has been an avid service provider on customer intelligence, improving governance, IT performance management, retail and supply chain in the manufacturing industry, product marketing, pricing and packaging, banking, insurance, risk management, Saas, business analytics, business intelligence, performance management, communications, health and life sciences, data integration, information management, alliances and channels, and relations (SAS.com. 2013). As of these days, it has developed 903 companies in partnerships and alliances based on its online directory (SAS.com, 2013). The success of this organization is obviously attained because they have clear vision, mission, goals, and sustained good relationship with its clienteles. They see tangible results of the SAS’s software and services (SAS.com, 2013). Their systems are m atched with mixture of transformational and transactional leadership that are applied in managing in its operation, in relating to customers, and in managing its human resources. CNNMoney (2012)

Saturday, November 16, 2019

User Level Rootkit: Computer Security Systems

User Level Rootkit: Computer Security Systems Hamid Tarmazdi Sohaib Irshad 1 Introduction Let us have a look at the definition of the word. The word has two components, root and kit. Root is usually a UNIX/Linux term that is used for administrators just like we do in Windows. The word kit is used to denote the programs that allow someone to gain illegal access to root/admin level of the computer by executing some programs in the kit. All of this is done without the consent or knowledge of the end-user. This document is the final report on the user level rootkit developed by our team. It contains new and updated information from previous documents. The general aspects are discussed to provide a overview on rootkits in general and specifically user level rootkits. Different features have been described with code snippets or pseudocode depending on complexity and length of the code. The aim has been to make this document as self sufficient as possible, so the reader can gain information on rootkits and user level rootkits and then proceed to details of implementing one. 2 Usage There are two primary functions for rootkit. Backdoor remote command or control of the computer Software eavesdropping. Rootkits are used to administratively control a computer, either through legitimate means or otherwise. This means that one can execute files, access logs, monitor the user activity and even able to change the computer configuration. If we consider the strict definition of rootkit, even some versions of VNC are rootkits. One example of the rootkit use was by Sony BMG’s attempt to install a software on user machines to prevent copyright violations. 3 Propagation Rootkits do not propagate by themselves. They are one single part of three part component which we call as Blended Threat. A blended threat has three snippets of code that are dropper, loader and rootkit itself. Dropper initializes the installation of the rootkit. Dropper is usually activated through human intervention (read: error) for example clicking a malicious link. After it initiates, it executes loader program and then deletes itself to avoid any detection. After the loader has been activated, it causes a buffer overflow which then loads the rootkit into the memory. One of the recent examples of such an attack are through propagation of malicious links through social media sites (Facebook and Twitter). After clicking a malicious link, the rootkit takes control of the client and then sends out messages to every contact on the list. Other example is through Rich content such as PDF files. Just opening such files will execute dropper code and the rootkit is subsequently installed, infecting the computer. 4 Types of Rootkits There are several types of rootkits that we can discuss. 4.1 User-mode rootkits Such rootkits usually run on a computer with administrative rights. This allows the usermode rootkits to change security options and hide system processes, files, system drivers, block network ports and system services. These rootkits remain on the infected computer through copying of required files on target computer’s hard drive and launch automatically with every system reboot. 4.2 Kernel-mode rootkits Because the user-mode rootkits can be found by rootkit detection software’s running in kernel mode, malware developers developed kernel mode rootkits. They placed the rootkit in the same level as operating system and rootkit detection software. In other words, the Operating system could not find the rootkit. 4.3 User-mode/kernel-mode hybrid rootkit Some malware developers designed the hybrid of both the rootkits, user-mode for higher stability and kernel mode for greater stealth ability. It is the most successful and most popular rootkit at this moment. 4.4 Firmware rootkit The next sophisticated form of rootkit is firmware rootkit. It is a very complex and harder to detect rootkit. It hides itself into the firmware of the computer and reinstall every time the PC gets rebooted. It can be installed with any firmware such as microprocessor code to PCI expansion card firmware. 4.5 Virtual rootkit These are the most new kind of rootkit in the industry and the most difficult to detect. It acts like a software implementation of a hardware set in a manner similar to used by VMware. Such rootkits are almost invisible. One of the examples of such rootkits is Blue Pill. 5 Polymorphism and Detection of Rootkits Polymorphism is one of the techniques that make us difficult to find and remove malwares such as rootkits. It is defined as the ability by the rootkit to rewrite the core assembly  code that makes antivirus pr antispyware signature based defenses useless. 6 History The term rootkit or root kit originally is attributed to maliciously modified set of admin- istrative tools in a Unix OS that is granted a †root† access. If an intruder substitutes the standard administrative tools on a system with a program such as rootkit, the intruder could gain root access over the system whilst at the same time obscuring these activities from the legitimate system administrator. These rootkits known as first generation rootkits were easy to detect using the tools such as Tripwire. First documented computer virus was discovered in 1986. It used cloaking techniques to hide itself. The Brain virus intercepted many attempts to read the boot sector and then made sure these attacks are redirected to elsewhere on the disk. These disks contained confidential data and also a copy of the original boot sector. Over time, DOS-virus cloaking methods have become more sophisti- cated, with the usage of advanced techniques including the hooking of low-level disk INT 13H BIOS interrupt calls to hide unauthorized modifications to files. 7 Features This section contains information on general functionalities of the rootkit developed by our team. Feature set is divided into small tasks and these tasks are individually completed and integrated. 7.1 Achieved functionality Following is a detailed breakdown of the feature set including implementation details. The rootkit shall be installed through modifying LD PRELOAD to pre-load our dynamic library with our functions to replace their original counterparts in standard C library. The rootkit shall hide LD PRELOAD environment variable. The rootkit shall start automatically on user login. The mechanism of the rootkit must be hidden. 7.2 Subtasks 7.2.1 req.1 To achieve req.1 we have finished following sub tasks : A sample C program which makes a call to a method from standard C library. A sample dynamic library which redefines the function called in our program. Modifying LD PRELOAD to preload our custom library. Update the modified function to also run the original function in addition to the modified code to avoid breaking functionality. Acceptance criteria req.1: After successfully executing sub-task #4 running the program created in sub-task #1 would result in execution of the modified function in our library created in sub-task #2 in addition to running the original function from standard C libraries. This gives the capability to spy on user program, modify its input/output,etc. Achieving req.1 allows us to run our code within a user program. 7.2.2 req.2 Following subtasks are finished for req.2. Identify the functions used to retrieve LD PRELOAD by programs Hook the functions to hide LD PRELOAD Acceptance criteria req.2: The function to return environment variables is â€Å"getenv†, when hooked it should not return the value for LD PRELOAD. 7.2.3 req.3 To achieve req.3 following tasks have been perused: Create a script for initiating the rootkit. We have created a pseudocode for our script which puts our preload library into â€Å"/lib†. Modify /etc/ld.so.preload to include an entry for hooking the dynamic library we have placed in â€Å"/lib†. Acceptance criteria req.3: A script which successfully copies the library and applies the changes to preload when executed. 7.2.4 req.4 To hide the rootkit, the rootkit file and entry must be hidden. For more detail on hiding please refer to Section 9. Identify the functions involved in listing files: The functions are identified in Listing 6. Hook these functions to hide our mechanism. Modified version of 6 out of 8 functions are coded. Acceptance criteria req.4: In order to hide the rootkit, the folder containing the rootkit or the rootkit files and any script must be hidden in addition to hiding LD PRELOAD(req.2). The files and folder of the rootkit shall not be visible. 8 Implementation Following we have details on implementation of the different features. 8.1 req.1 Sub-task 1: Following C program is used as a sample program to demonstrate the mechanism. Listing 1: Sample C Program #include main() { printf(This is a valid program.); } Sub-task 2: We have used printf function as an example for demonstration of this feature, modified version is compiled into a shared dynamic library using the following commands: gcc -fPIC -c -o fakeprintf.o fakeprintf.c gcc -shared -o libfakeprintf.so fakeprintf.o Argument -fPIC is for position independent code to used in dynamic linking. Listing 2: fakeprintf.c #define GNU SOURCE #include int printf(const char âˆâ€"format, ) { } Sub-task 3: To modify LD PRELOAD we can run the following command: export LD PRELOAD=$PWD/libfakeprintf.so Now when we run our sample C program there will be no output as the printf function in the modified library will get executed instead of the original printf. Sub-task 4: To run the original function in addition to the modified function, we need to obtain a pointer to the original function using â€Å"dlsym† [2] with the argument RTLD NEXT. Code in Listing 3 shows how â€Å"rmdir† has been hooked to prevent from removing the rootkit files while keeping the functionality of the said function intact everywhere else. Listing 3: fakermdir.c #define GNU SOURCE #include int rmdir(const char âˆâ€"pathname) { typeof(rmdir) âˆâ€"clean rmdir; clean rmdir = dlsym(RTLD NEXT, rmdir); /* return if pathname contains rootkit files */ return clean rmdir(pathname); } 8.2 req.2 Sub-task 1: The function to retrieve environment variables is â€Å"getenv† [1]. Sub-task 2: The modified version in Listing 4 prevents from retrieving LD PRELOAD. However this method has not been successful in hiding the environment variable. Listing 4: fakegetenv.c #define GNU SOURCE #include char âˆâ€"getenv(const char âˆâ€"name) { typeof(getenv) âˆâ€"clean getenv; clean getenv = dlsym(RTLD NEXT, getenv); /* return zero if name contains LD_PRELOAD */ return clean getenv(name); } 8.3 req.3 The script to install the rootkit follows the pseudocode 5. Listing 5: install.sh compile and copy rootkit.so to /lib remove source modify /etc/ld.so.preload to hook rootkit.so export LD PRELOAD=$PWD/rootkit.so 8.4 req.4 Sub-task 1: List of functions that need to be hooked are in Listing 6. More detail on hiding is provided in Section 9. Listing 6: functions stat, fstat, lstat Information about a file, Filter the rootkit files rmdir Prevent removal opendir, fdopendir Filter the rootkit directory readdir, readdir r Prevent reading the rootkit directory Sub-task 2: We have coded the hooked functions for stat, fstat, lstat, rmdir, readdir, readdir r. More detail on how to hide the rootkit by hooking this functions in next section. 9 Hiding Due to their importance the hiding techniques are discussed in more detail in this section. To hide the files/folders the functions which are used to access or get information on these must be hooked. To have a bash which does not show the rootkit files the LD PRELOAD for running the bash have to be hooked: LD PRELOAD=/lib/libselinux.so bash -l The list of functions to be hooked for this purpose is listed in Listing 6, the method on hiding the file/folder is similar so one example is given in Listing 7. All the functions in Listing 6 must be hooked according to the example in Listing 7. Listing 7: Hiding the rootkit #define GNU SOURCE #include int lstat(const char âˆâ€"file, struct stat âˆâ€"buffer) { if(to be hidden(file)) { errno = ENOENT; return −1; } return clean lstat(file,buffer); } The function â€Å"to be hidden† returns true for each of the files(example:rootkit.so or ld.so.preload) or folders containing files related to the rootkit. Applying this hook to functions in Listing 6 will cause them to skip any file related to the rootkit. References [1] Linux man page getenv. http://linux.die.net/man/3/getenv [2] Linux man page dlsym. http://linux.die.net/man/3/dlsym

Wednesday, November 13, 2019

Free Speech, Censorship, and Self Determination Issues in Protests against the Chinese Government :: China Government Research Politics Papers

Free Speech, Censorship, and Self Determination Issues in Protests against the Chinese Government Introduction As a Chinese American, I have long admired the African American culture that spawned the civil rights movement. Here was a people buffeted by a history of discrimination that asserted its equal rights as men and women. Whether advocating nonviolence and integration or separation and violence if necessary, these men and women used and asserted their freedom of speech on the streets, in writings, and on the airwaves. Today we see China growing rapidly in economic power yet shaken by protests by workers displaced by the closings of state owned enterprises and migrant workers treated as second class citizens. We see organizations, from the Chinese Democratic Foundation to the Falun Gong, advocating and asserting human rights. The Chinese government has been relentless in "nip(ing) those factors that undermine social stability in the bud, no matter where they come from."(7) Many human rights organizations and dissident organizations have turned to the Internet to protest these government actions and to communicate, inform, and advocate their message to both the Chinese people and to the rest of the world. As a believer in protests and freedom of speech and someone who wants Chinese culture to grow, I should be a staunch supporter of these organizations and their actions. Yet, I am torn. What's Happening In China China is undergoing rapid and violent change. China has the fastest growing economy in the world, growing at 9.1% clip in 2003. SFGate recently reported on Shanghai novelist Mian Mian whose tale exposing an underground of rock, drugs, and promiscuity is reminiscent of America in the 60's. The number of Chinese Internet users is estimated at close to 80 million. A new generation of artists have appeared on the scene, wryly commenting on China's rapid change. China, nominally communist, seems freer than ever before and its future looks bright. Yet, you also hear reports of corruption, of large and growing underclass, and renewed repression. It seems that partly fueling China's engine of growth is a near inexhaustible supply of cheap and desperate labor spawned by the closing of state owned enterprises (S.O.E.s) and an impoverished rural population. These hardships have spawned a migrant labor population, estimated to swell to 100 million this year, that has flooded urban centers looking for work. These workers are denied education, medical care, pensions, are locked out of most jobs, and are vulnerable to labor abuses.