Mostrando entradas con la etiqueta networks. Mostrar todas las entradas
Mostrando entradas con la etiqueta networks. Mostrar todas las entradas

jueves, 5 de julio de 2012

Busuu.com una red social para aprender idiomas


Siempre he pensado que las redes sociales pueden ser una herramienta complementaria perfecta en educación. Aunque muchos miren aún este recurso con recelo, tarde o temprano acabaremos utilizándolo para la enseñanza y el aprendizaje a lo largo de nuestra vida. Quizás, ahora, sobre todo a los docentes más mayores, les cueste hacerse con este tipo de herramientas, pero cuando la generación de “nativos digitales” sea la que pueble las aulas como profesores, no nos sorprenderá verlos tomar como apoyo redes como la que hoy os presentamos.
Se trata de Busuu y es una de las muchas redes sociales que nos ayudan a aprender idiomas gracias a la colaboración de los usuarios. Podemos ponernos metas para alcanzar el nivel de inglés que hayamos preconfigurado en nuestro perfil: ¿Y cómo lo conseguimos? Realizando los ejercicios y recibiendo las correcciones que otros usuarios nos harán. Para ello contaremos además con la ayuda de numerosos recursos que tenemos disponibles en la Red Social: alfabeto, unidades didácticas, guías gramaticales, etc.
La aplicación Web es muy fácil de usar gracias a su sencilla interface, así que si no mejoramos el idioma será por pereza o desidia; ya no podremos decir que no tenemos cientos de “amigos” dispuestos a ayudaros en el aprendizaje de las lenguas.

sábado, 28 de abril de 2012

Cómo utilizar Delicious

Gestiona tus páginas favoritas desde cualquier sitio a través de internet

Si eres de los que pierde un pedazo de vida digital cada vez que cambias de ordenador porque no encuentras tus páginas web preferidas en tu pestaña de favoritos, hay una herramienta pensada para ti. Delicious es un servicio gratuito que te permite categorizar, almacenar, gestionar y compartir tus páginas web a través de internet; y hacer uso de ellas cuando más te apetezca, siempre y cuando dispongas de conexión a internet.
  1. Registro.
    Para darte de alta tienes que acceder a www.delicious.com. En la portada haz clic en el cuadrado verde situado en la parte superior derecha en el que se puede leer "join now" y rellena los datos que te pide: first name (nombre), last name (apellido), email address (dirección de correo electrónico), user name (nombre de usuario o alias) y password (contraseña). A continuación, transcribe las letras que aparecen en la imagen, acepta las condiciones de uso y pulsa en registrar. En el siguiente paso puedes importar las páginas favoritas que ya tienes almacenadas en tu navegador. Para ello selecciona entre importar tus favoritos de manera automática o hacerlo de forma manual.
  2. Selección.
    Para añadir favoritos dispones de tres vías: desde el ícono de Delicious que suele aparecer en las páginas que te interesan, mediante un botón estático previamente instalado en tu navegador o copiando y pegando la dirección web de forma manual. Los favoritos aparecen acumulados en la pestaña "bookmarks" de tu página de Delicious por orden cronológico o alfabético según tus preferencias, y te muestra el número de personas que ha guardado la misma noticia que tú.
  3. Etiquetado.
    Cuando añades un sitio a tu página aparece una ventana de diálogo previa a su registro definitvo. Puedes clasificar tu sitio favorito utilizando tags (palabras clave que describen la información) o escribiendo una descripción. El sistema de etiquetado crea automáticamente una base de datos que agrupa todos tus favoritos en función de la categorización que hayas realizado. Por ejemplo, si quieres añadir una noticia sobre una exposición de arte sobre Picasso la puedes etiquetar empleando palabras como "arte", "pintura", "picasso", "exposición", "ocio", "noticias" etc.
    Las etiquetas no pueden incluir espacios ya que Delicious las descodifica como elementos independientes. Por ejemplo, si utilizas "pablo picasso" para etiquetar la noticia anterior creas dos etiquetas distintas:"pablo" y "picasso". Lo ideal es catalogarlo como "pablopicasso", "pablo-picasso", "pablo.picasso" o "picasso" a secas. Cuantas más etiquetas utilices para clasificar sitios, más fácil será su recuperación después.
  4. Comunidad.
    Delicious es una comunidad de usuarios y su valor añadido como marcador social reside en la posibilidad de encontrar a usuarios con los que puedas tener puntos de interés y suscribirte a sus lista de favoritos. De esta forma, cada vez que cliquees en la pestaña "network" del menú horizontal superior accederás a los favoritos de tu red personal de usuarios.
    Para añadir una persona a tu "network" lo puedes hacer de dos formas: seleccionar "add a user to network" en la parte superior derecha de la página "network" y escribir el nombre, o clicar la opción "add to my network" una vez dentro de su página de favoritos. Una vez que tengas amigos puedes recomendar o enviar noticias escribiendo la etiqueta "for:nombre del usuario de Delicious destinatario".

sábado, 19 de noviembre de 2011

Quieres saber como trabaja realmente Windows Live Messenger?

Aquí hay una buena representación visual de las pequeñas "Transmisiones de Messenger" sistema del que envía y recibe todos sus mensajes. Aqui hay una explicación clara de todo el proceso para aquellos que lo desconocen.
  1. El usuario inicia la sesión haciendo doble clic en un contacto.
  2. Las credenciales del usuario de Windows Live ID se envían a través del Servidor de Credenciales de Windows Live ID del para su posterior verificación.
  3. La información se transmite a través de un firewall entrantes en el servidor de envío. Este es el primer punto de conexión para el mensaje que se envía.
  4. Dependiendo de donde el usuario está en el mundo, se establecerá una conexión con el servidor de notificación local. Los principales estan en Singapur, Dublic, Redmond y Reading. Esto mantiene la conexión entre los dos usuarios, y mantiene las cosas actualizadas como la condición de usuario, peticiones de chat y las notificaciones de correo electrónico de Windows Live Mail / de Hotmail.
  5. El mensaje como tal no se acerca a los servidores de la notificación - sino que es pasado al servidor de distribución el cual intercambia todos los mensajes y archivos. El usuario que inicia la charla puede hablar con un usuario, mientras que usa otra sesión telefonica para hablar con otra persona, y otra sesión telefónica de otra persona aún - sin ni siquiera saberlo. Invitaciones, transferencias de archivos y video / chat de voz también se envían a través de aquí.
  6. La información entonces se retransmite de nuevo a través de un firewall de salida y los controles del usuario sigue estando en línea. Si el usuario está desconectado por el momento en que el mensaje está listo para ser recibido, entonces va a rebotar y se guarda en la sesión de panel de control hasta que el usuario inicia sesión de nuevo. Si están en línea, recibirán el mensaje.
Todo esto se hace en el espacio de alrededor de 2 segundos - la mayor parte del tiempo que su mensaje será enviado al menos dos veces en todo el mundo, en el espacio de 2 segundos. Nada mal eh?.

sábado, 29 de octubre de 2011

The Covered Bazaar on the Internet

Over the past decade, the Internet has evolved from an exotic “place” populated with academics and scientists to a common marketplace for the general populace. The global network of electronic infrastructure has played a significant role in this expansion but the technology itself is not the factor driving the business revolution. The changes are driven by the interaction of information technology and customer demand [1]. Gone are those days in the early 1990s when the Internet was populated mainly with research papers, scanned texts and some downloadable software from university research laboratories. The Internet has become the medium of what Vernadsky [2] calls “noosphere” - the next step in the evolution of the biosphere of the Earth. The developments in the latter half of the 1990s illustrate that the common information environment that supported the development of a common scientific approach to the world (the basis of the “noosphere”) has had an effect of homogenising the networked global population.
A contribution to the weakening of both economic and cultural diversity in the epoch of transition into the 21st century is the push towards globalisation at any cost. The latest advances in information and communication technologies (ICTs) have been touted by Internet
enthusiasts as the catalysts that lead to greater world democracy and prosperity. Little thought has been given to the possibility that the values and communication preferences inherent in these technologies may not be universal. In fact, the consequences of new communication
technologies could be a homogenous “McWorld” [3, 4]. The alternative to such global homogeneity is what Barber refers to as “Jihad” – the reaction that occurs when diverse cultures try to preserve their identity. However, the apparent dilemma between Jihad and McWorld may not be so intractable [5]. Indeed, there are examples that demonstrate points between Barber’s dichotomy. Thailand’s use of CMC technologies, for example, allows for
both global connectivity (but in a “thin” culture) and the preservation and enhancement of local cultural values and communicative preferences (a “thick” culture) [6].
Another contribution to the weakening of both economic and cultural diversity in the epoch of transition into the 21st century is the two processes of discontinuity and rapid change.
Even the most basic of human activities have lost much of their idiosyncratic individuality as these activities, of necessity, conform to standard protocols and operating procedures.
An example of such a basic human activity is the common task of shopping. The rapid expansion of e-commerce on the Internet, and the speed with which societies are adapting to the notion of doing business and shopping electronically, creates the perception that ecommerce is a natural evolution in this information age. Although scholars are cautious about
issues such as security [7-9], trust [10], health and lifestyle [11, 12], very little research has been carried out to evaluate the effect of global e-commerce on indigenous and local cultures.
The current environments, metaphors and processes of Internet commerce have perhaps the most potential to adversely impact on cultural identities. While new technologies are capable of creating and archiving user and product profiles, developers and researchers in the field are
only beginning to consider how cultural profiles can assist in the global marketplace.
In this paper, we describe the development of e-commerce in the context of the various metaphors currently used for online shopping. We explore the metaphor of a 3D marketplace and the implementation of such a model in e-commerce systems. Finally we discuss the efficacy of culturally diverse e-marketplaces for maintaining the integrity of languages and cultures along with global economic communities.









THE EVOLUTION OF E-COMMERCE

The evolution of the media and underlying technology for e-commerce on the Internet can be divided into several distinct phases. During the first phase, in the early 1990s, the Internet was used primarily for information dissemination via e-mail and static Web pages. The Internet was a complementary information channel to magazines, radio and TV for distributing product information. The transfer of information lacked security and integrity.
The second phase, from the mid to late 1990s, saw security and privacy protocols being added to a variety of transaction processing services. This addition opened the Internet to a variety of commercial and corporate uses. The development of dynamic Web pages and database-driven Web sites added a spin of interactivity. E-commerce also borrowed some ideas
from research in computer supported collaborative work (CSCW) [13, 14].
The current phase of e-commerce is connected with the development of intelligent technologies like data mining, online analytical processing (OLAP) and sophisticated search engines. These technologies are used for creating both product and user profiles, and for adapting the behaviour of the e-commerce system to individual combinations of these profiles.
They require the development of new interfaces and business models.
This dramatically changed computing universe – the networked microcomputer and advanced communication networks, deregulation of telephone services, expansion of Internet

BUSINESS TO CONSUMER (B2C) MODELS

Perhaps the most popular and visible B2C model on the Web is the web mart (or digital storefront). The model is a result of the creative merger of two shopping metaphors: the mailorder (catalogue) business6 and the shopping mall/supermarket.
The mail-order business has survived more than a century. The first catalogue sales began in the United States at the end of 19th century, when two major mail-order companies, Montgomery Ward and Sears Roebuck, were established. The obvious advantage of this model
was a decrease in the amount of time needed for shopping. The disadvantage was the
limitations of the media (paper) to represent the qualities of the goods.
The shopping mall model flourished with the growth in the popularity of automobiles and the expansion of road systems. The automobiles and road systems provided the underlying technology, and efficient large chain stores lured the customers. Customers were willing to travel relatively long distances to reach a large store that offered a variety of products at
relatively lower prices. The key factor for a chain to compete effectively and achieve profitability at low prices was purchasing in volume. Not surprisingly, the same principle worked for the customers – the volume at low prices compensated for travel time and expenses.
As customers were now purchasing in volume, families found it useful to have a shopping list (usually a cumulative list on which a household places it needs) as they negotiated massive supermarket isles with their shopping cart (in which the needed items are placed). The shopping cart is the vehicle for transporting needed items from the supermarket shelves to the cash register and subsequently to their automobile.
The combination of the catalogue and the supermarket metaphors formed the underlying metaphor of the popular Web-Marts. Figure 1 shows a typical example. Variations across Web-Marts are very small – where they do occur they are mainly in the layout. Consistent with its composite counterpart, Web-Marts feature a link to browse catalogue items and a link to
view the contents of the shopping cart as items are placed in. For full-scale shopping, a user generally enters the mall with a login name and a password.
Figure 1. The “front” Web view of a typical “Web-Mart”.


Figure 2 illustrates what a customer finds inside a “Web-Mart” – a typical catalogue page which is usually equipped with a search engine. To some extent, search engines change the shopping strategy from browsing (through the catalogue) to selective searching (for a specific product). However, the selective searching strategy will work if the customer not only knows
the language (English in most cases), but also the specific term used to label that product.
Figure 2. Inside the Web-Mart

Similar to the procedure in the physical supermarket, the virtual shopping cart metaphor allows customers to accumulate and store lists of items they wish to buy as they continue to shop. The underlying technology that supports the shopping cart metaphor is a database of catalogue information. Formalised in a database form and interfaced with web stylesheets, the product catalogue on the merchant server supplies the information that is displayed when the product is retrieved. The database that is used is a collection of product specifications, availability, shipping information, stock levels, on-order information and other data. Figure 3 illustrates an enhanced shopping cart metaphor. In this example, the shopping cart technology is enhanced with a facility for “chatting” (talking online) with a shop assistant.

Figure 3. Shopping cart technology enhanced with chat assistance.

The data model and the content of the database depends on the type of product. A music
CD store, for example, may include a downloadable sample file with a music segment from the CD, as illustrated in Figure 4.




Figure 4. Music Web-shop


Perhaps Amazon.com, with its range of products that include books, videos, music, CDs, DVDs, electronic cards, consumer electronics and toys, remains the most widely recognised example of a database-driven Web-Mart. The online catalogue handles millions of product offerings, providing sophisticated data analysis of sales histories, product reviews, in-depth
descriptions and cross-references, to guide customers according to some expectation about individual interests.
Personalisation is part of the strategy of Amazon.com. This feature suggests that the database keeps a record of all previous transactions, including items purchased, shipping and credit-card information. Combined with information from the customer database, it builds a user profile “on the fly”. Based on previous purchases and cross-referencing with customers
who bought similar products, it presents a list of recommended titles to the customer (Figure 5). This suggests that the site employs OLAP technologies which, by some criteria, identify similar products. By building and analysing customer profile data, such computing systems
provide a customised (but fairly uniform) service, driving sales of additional items without human participation.
For the purpose of this paper, we can state that the man-machine system has the property of symmetry, which perhaps is reflected in the structure of the database – a symmetry between the product and the human sections. This symmetry points to dehumanisation of the commercial environment.
It is difficult if almost impossible to establish a contact with a physical person behind the fabulous walls of the Web-Marts. Some modern sites, as illustrated in Figure 3, offer an access to a life channel, similar to the customer telephone lines. The attempt to connect on the live
chat, shown in Figure 6, demonstrates the analogy with a telephone scenario.


Figure 5. Sales history and cross-reference to customers with similar preferences are features of amazon.com’s site.



Figure 6. Chat service in a “Web-Mart”, simulating a telephone service.


The auction is another metaphor that provided a successful model for the e-business environment. With this model, information about the prices of a large number of potential buyers in the market for a particular product can be obtained at a relatively low cost. The auction model provides some assurance in effective matching of buyers and sellers. Vickrey [20] offered four models of simple auctions, assuming that buyers hold independent, private evaluation of the product value. Vickrey’s auction models established the de facto standard for the auctions of consumer goods in B2C e-commerce. eBay.com, the company which was a pioneer in Web-based auctions, attempted to bring in ideas from networked communities to ecommerce (note the “Community” section in Figure 7). There are also two additional operations compared with the Web-Mart: (i) announcing the product, and (ii) bidding for a product.
Figure 7. eBay.com - the entrance to the auction.


The attractiveness of e-auctions is that the customer is not only a buyer – the customer is able to offer his/her own goods for sale. Thus, the second generation e-commerce sites combine both models, as illustrated in Figure 8.

Although the models presented here have some variations on the Internet, the look, feel and functionality of the e-commerce sites are very similar. More importantly, the advantages of these types of e-commerce sites are convenience and lower prices. Consequently, there has been an expectation that online merchants will slowly overtake physical shopping malls.
However, even the most ardent fans of Cyberspace agree that present Web commerce cannot replace the variety of emotion, social and cultural experience of shopping in the hustle and bustle of the physical world. One of the reasons for the cultural flatness of e-commerce is “bandwidth colonialism” [21], or US dominance. The structure of the Internet and bandwidth costs give the US an overwhelming advantage for dominating global e-commerce. As Flynn [22]claims, “Julius Caesar conquered Gaul with Roman legions, but the US is doing it with Mickey Mouse, and the Internet”.

The dominant Western culture is certainly evident in the models discussed. These models have basically eliminated the notion of the “marketplace”. Westland and Clark [18] refer to this phenomenon as a “placeless marketplace that we call a marketspace – one that is nowhere yet everywhere”.

E-COMMERCE TODAY

The e-commerce landscape today, therefore, features three major trends away from the models of a decade ago.

  1. Products are changing from mass produced to custom made.
    As Amazon.com and other similar major B2C e-commerce sites have demonstrated, customisation has become the key to success on the Internet. The product is not just “for the consumer” but for a specific individual who has a name, a title, an address and a history as well as emotions such as hopes and fears. The product needs to be made available in a way more innovative and cost effective than a competitor company can offer.
  2. Production is changing from mass production to job specific.
    While automation enhanced mechanisation and the drive toward more mass production, knowledge engineering and data mining have increased flexibility and make customisation possible at an affordable cost.
  3. The market itself is changing from a mass market to a niche market.
    The shift to unique products for a specialised customer base is becoming the very essence of e-commerce.
However, current e-commerce models are still dominated by the shopping
mall/supermarket metaphor. This metaphor and its associated functionality correspond to Western lifestyle and shopping habits and thus continue to foster a homogenous McWorld. The success of such models in many countries, where shopping traditionally includes a social element along with bargaining and negotiations, is tenuous. The authors’ experiences in
Turkey, for example, demonstrated that the social element is an essential part of a commercial transaction. The pre-purchase activities vary from a few minutes talk over a cup of tea (çay) to a half-day excursion to show the cultural history of the product. To demonstrate how cultural integrity can be preserved in online shopping, we use the metaphor of a bazaar as an ecommerce model.
CULTURAL SENSITIVE E-COMMERCE

When engaging in commercial activities across cultures, one must be sensitive to the multidimensions of culture, which include language, religion and artifacts as well as values, cognitive style, and time and space orientations. Culture encompasses a set of norms that a group of people consciously or unconsciously agree to in order to facilitate a homogenous and harmonious coexistence.
Initially, the Internet was an open forum, an Internet “bazaar”, in which the diverse cultures could participate freely. However, with the commercialisation of the Internet generally, and the popular supermarket metaphor in particular, globalisation has resulted in homogenisation and a flattening of cultural diversity. An enormous export market exists in
addressing foreign markets – going global is no longer an alternative but a necessity for today’s business.
While the Web has helped to remove – or dilute – national borders, there are many issues that still need to be resolved. There are just seven countries where English is the primary language spoken and these seven countries represent 30% of the world’s economy and 8% of the world’s population [23]. Obviously there is a large potential market that is not catered for by parochially-minded businesses. Global e-commerce is most often limited by a narrow worldview that sees all countries at all times the same. Obviously cross-cultural e-commerce has its costs. Developing web sites specific to just the major national languages of the world
can be a barrier to embarking on an e-commerce venture. However, companies cannot hope to participate in a true global e-commerce environment without being concerned about cultural sensitivity.
We propose that a major step in embracing cultural diversity in e-commerce is the use of metaphors that have cultural and social meaning; metaphors to which customers can relate. The example we give here is the bazaar metaphor for online shopping. For Islamic countries, the most common mode of shopping is the bazaar, in which prices are negotiated and transactions
are accompanied by specific cultural experiences and emotions.
THE BAZAAR

One of the most notable ways in which a bazaar differs from a supermarket as a marketplace is price flexibility. The prices for each product in a bazaar depends on a variety of factors, including the season (peak or off-peak), the bargaining experience of the seller, the tenacity and culture of the buyer, and the manner in which the buyer handles the preliminary social etiquette. Most bazaars open early in the morning and continue until sunset.
The word bazaar, originating from the language of Uygur, means marketplace on the Silk Road. The word conjures up images of bustling and prosperous trading activities. In the marketplace, all types of fine items are carefully selected to cater for the need and taste of different customers. The markets of Islamic cities are one of the greatest achievements of the
Islamic peoples. Economy and religion are the two principal pillars of the Islamic bazaars, which symbolise their difference from other markets. Two famous bazaars illustrate the atmosphere and power that could be infused into an online metaphor.
The Kapalõ Çarşõ (‘Covered Market’ or Grand Bazaar) in Istanbul, Turkey, houses thousands of shops and stalls where merchants display a variety of goods. Starting from a small bedesten (warehouse) built in the time of Mehmet the Conqueror, the bazaar grew to cover a vast area. The foundations of the Covered Grand Bazaar were built after the conquest of
Istanbul by the Ottomans.
The bazaar grew in time with additional shops and halls. The arcades and halls were covered with arches (Figure 9) to form a series of covered streets leading to a central avenue.
Streets are named according to the trades, such as gold and silver sellers, carpet sellers, slipper sellers, bootsellers, booksellers, etc. Shoppers can buy colourful carpets, clothing, copperware, jewellery and many other items. Consisting of more than 4,000 shops, the Grand Bazaar is a maze of narrow streets where you can buy a bangle, a carpet, or just browse. This great covered bazaar is not simply a complex of buildings but a city covered by hemispheric domes with 18 entrances.
Figure 9. The arches of the Grand Bazaar, Istanbul, Turkey

The Souq al-Hamadiyyeh bazaar in Damascus, Syria (Figure 10), is the city’s main market. It features long streets covered with high canopies, lined with booths and shops and bustling crowds. The shops are narrow and shallow, filled with goods of every kind, and shopkeepers sit in front of the shop ready to haggle with with the passing crowds. It is noisy as
men bargain back and forth. Barbers invite passers-by to have their hair cut. Their shops are always full. A crowded as numerous as that in the galleries of the Palais-Royal throngs the bazaar all day long.

Figure 10. The Souq al-Hamadiyyeh bazaar in Damascus, Syria.

As in the Grand Bazaar in Istanbul, each type of product has a street or part of a street and is known by the product name. For example, there is the Street of the Saddlers, Street of the Slipper Merchants, Street of the Spice Men, and many others. The longest and busiest thoroughfare is the famous Street Which Is Called Straight.

THE BAZAAR METAPHOR FOR E-COMMERCE

We envisage that a bazaar universe (a “world” in Active Worlds) would appeal to cultures to whom the marketplace is a rich environment, such as the bazaars described in Section 6. Virtual worlds have the potential to provide commercial environments that transcend time and space. The development of virtual worlds has emerged from computer-mediated social spaces [24] that supported the needs of large, loosely-knit virtual communities. Unlike the 2D desktop interface, 3D interfaces can create an experience of immersion.
Under the right circumstances, users are able to mentally project themselves into a virtual space. One way this has been accomplished has been with 3D graphics. Another demonstration of immersion has been with MUDs, which are based purely on textual description. MUDs show that a rich, consistent presentation of a virtual space, even without sophisticated display technology, can be vividly experienced in the imagination of the user. The development of virtual worlds is inherently about creating places that mimic the physical world, but not necessarily restricted by 3D geometry [25]. This gives the person a feeling of being at some place, even though they have not physically moved from their home or office. An example of an environment that creates a sense of place is Active Worlds. Active Worlds is a 3D modelling environment that includes avatars of the people in the virtual world.
This environment provides a sense of place by presenting a 3D world in which the person can walk, talk, teleport, and look around. Although it is object-oriented, Active Worlds emphasises the 3D models of the contents of the world. It is used primarily for social interaction and as access to documents on the WWW. Because other users are present in these spaces, social interaction is facilitated.
The bazaar universe is, of course, developed in a local language. Within the bazaar universe, there are spaces for different types of goods – for example a “gold room”, a “carpet room”, a “slipper room”, and so forth. Waiting at the entrance of each space are animated avatars with whom potential customers can converse. The avatars are the counterparts of the
shop assistant in the shopping mall, as shown in Figure 3.
The avatars’ behaviours correspond to particular cultures. Non-verbal behaviour, in particular, is highly culturally specific and constitutes 60% of interactive messages. For example, an Indonesian would use the right thumb rather than an index finger when pointing to a person; a Japanese smile can mean appreciation but it can also mean feeling embarrassed or sorry for another person. Transactions are carried out by negotiating prices with avatars.
Using culturally specific shopping bots, customer profiling can be developed. Bots have a great potential in data mining, finding patterns in enormous amounts of data. A customer profile may include information about negotiation skills, level of risk taking, and the ratio between an initial offer and the settlement price.

A CULTURALLY-SPECIFIC E-COMMERCE MODEL

The bazaar e-commerce model (or any other metaphor for a specific culture) can be represented as in Figure 11.

Figure 11. A culturally-specific e-commerce model.

The four key components for developing and sustaining e-commerce in the global marketplace are consumers’ attitudes towards e-commerce as well as the cultural appeal, the economic appeal, and the usability of the site. These key components must be consistent with product integrity, a strong organisational culture, communication that facilitates frequent and
personalised seller-buyer interactions, and ongoing profiling of consumers.
It is not sufficient to have a multilingual or national e-commerce sites. E-commerce sites must provides “zones” for customers who are unified by a common culture. Culture zones are markets that share not only resource needs but also cultural mores.

REFERENCES
[1] F. Sudweeks and C. Romm, Doing Business on the Internet: Opportunities and Pitfalls.
London: Springer, 1999.
[2] V. I. Vernadsky, Scientific thought as a planetary phenomenon. Moscow: Science, 1991.
[3] B. Barber, "Jihad vs McWorld," The Atlantic Monthly, vol. March, pp. 53-63, 1992.
[4] B. Barber, Jihad versus McWorld. New York: Times Books, 1995.
[5] C. Ess, "We are the Borg: The Web as agent of assimilation or cultural Renaissance?," ePhilosopher, 2000.
[6] S. Hongladarom, "Global culture, local cultures, and the Internet: The Thai example," in
Cultural Attitudes towards Technology and Communication, C. Ess and F. Sudweeks, Eds.
Sydney: University of Sydney, 1998, pp. 187-201.
[7] B.-C. Lee, "Paying for goods and services in the information age," in Doing Business Electronically: A Global Perspective of Electronic Commerce, C. T. Romm and F. Sudweeks, Eds. London: Springer, 1998, pp. 163-173.
[8] N. Adam, A. Gangopadhyay, and R. Holowczak, "A survey on research on database protection," presented at Proceedings of the Conference on Statistical Data Protection, 1998.
[9] A. Gangopadhyay and M. Adya, "Protecting sensitive information in electronic commerce," in Doing Business on the Internet: Opportunities and Pitfalls, F. Sudweeks and C. Romm, Eds. London: Springer, 1999, pp. 77-86.
[10] T. F. Rebel and W. Koenig, "Ensuring security and trust in electronic commerce," in Doing Business on the Internet: Opportunities and Pitfalls, F. Sudweeks and C. T. Romm, Eds. London: Springer, 1999, pp. 101-112.
[11] K. Subrahmanyam, R. E. Kraut, P. M. Greenfield, and E. F. Gross, "The impact of home computer use on children's development," The Future of children: Children and Computer Technology, vol. 10, 2000.
[12] S. Kiesler, V. Lundmark, B. Zdaniuk, and R. E. Kraut, "Troubles with the Internet: The Dynamics of Help at Home," Human Computer Interaction, vol. 15, pp. 323-351, 2000.
[13] S. Viller, "The group facilitator: A CSCW perspective," in Readings in Groupware and Computer-Supported Cooperative Work: Assisting Human-Human Collaboration, R. M. Baecker, Ed. San Francisco: Morgan Kaufmann, 1993, pp. 145-152.
[14] H. Ishii, M. Kobayashi, and J. Grudin, "Integration of interpersonal space and shared workspace: Clearboard design and experiments," in Groupware for Real-Time Drawing: A Designer’s Guide, S. Greenberg, S. Hayne, and R. Rada, Eds. Berkshire, England: McGraw-Hill, 1995, pp. 96-125.
[15] AcivMedia, "Real Numbers Behind 'Net Profits 2000," ActivMedia June 2000.
[16] L. Leung, "Business-to-business ecommerce will explode, says Gartner,", vol. 2001: VNUNet.com, 2000.
[17] A. Swardson, "French groups sue to bar English-only Internet sites," Washington Post, pp. A01, 1996.
[18] J. C. Westland and T. H. K. Clark, Global Electronic Commerce: Theory and Case Studies. Cambridge, MA: MIT Press, 1999.
[19] L. Wise, "Internet Business Models,", vol. 2000, 1998.
[20] W. Vickrey, "Counterspeculation, auctions and competitive sealed tenders," Journal of Finance, vol. 16, pp. 8-37, 1961.
[21] K. N. Cuckier, "Bandwidth colonialism? The implications of Internet infrastructure on international e-commerce," presented at INET'99, San Jose, CA, 1999.
[22] M. K. Flynn, "Nations fear English language dominance on Net,", vol. 2001: CNN.com, 2000.
[23] B. Dunlap, "Reasons for Success in International E-Commerce: Speaking the Customer's Language,", vol. 2000: Euro-Marketing Associates, 1999.
[24] M. Abel, "Experiences in an exploratory distributed organisation," in Intellectual Teamwork: Social Foundations of Cooperative Work, J. Galegher, R. E. Kraut, and C. Edigo, Eds. Hillsdale, NJ: Lawrence Erlbaum Associates, 1990, pp. 489-510.
[25] S. J. Simoff and M. L. Maher, "Analysing participation in collaborative design environments," Design Studies, vol. 21, pp. 119-144, 2000. [This paper is to appear in P. Lowry, J. O. Cherrington and R. J. Watson (eds), (2001), Handbook of Electronic Commerce in Business and Society, CRC Press.]

jueves, 19 de mayo de 2011

Networking Ebooks 2008

computer network is a collection of computers and devices connected to each other. The network allows computers to communicate with each other and share resources and information. The Advanced Research Projects Agency (ARPA) designed “Advanced Research Projects Agency Network” (ARPANET) for the United States Department of Defense. It was the first computer network in the world in late 1960s and early 1970s.[1]
Computer networks can also be classified according to the hardware and software technology that is used to interconnect the individual devices in the network, such as Optical fiber, Ethernet, Wireless LAN, HomePNA, Power line communication or G.hn.

Ethernet uses physical wiring to connect devices. Frequently deployed devices include hubs, switches, bridges and/or routers.

Wireless LAN technology is designed to connect devices without wiring. These devices use radio waves or infrared signals as a transmission medium

ITU-T G.hn technology uses existing home wiring (coaxial cable, phone lines and power lines) to create a high-speed (up to 1 Gigabit/s) local area network.
Networks are often classified as Local Area Network (LAN), Wide Area Network (WAN), Metropolitan Area Network (MAN), Personal Area Network (PAN), Virtual Private Network (VPN), Campus Area Network (CAN), Storage Area Network (SAN), etc. depending on their scale, scope and purpose. Usage, trust levels and access rights often differ between these types of network - for example, LANs tend to be designed for internal use by an organization’s internal systems and employees in individual physical locations (such as a building), while WANs may connect physically separate parts of an organization to each other and may include connections to third parties.

Download
http://www.uploading.com/files/AWTMZR99/ebook_Administering_Windows_Server_2008_…rar.html
http://www.uploading.com/files/NGVXFONI/ebook_Administering_Windows_Vista_Securi…rar.html
http://www.uploading.com/files/5H7840NR/ebook_Alfresco_Enterprise_Content_Manage…rar.html
http://www.uploading.com/files/C956C57R/ebook_Building_Websites_with_VB_NET_and_…rar.html
http://www.uploading.com/files/AEHV5C5T/ebook_Building_websites_with_Xoops.rar.html
http://www.uploading.com/files/8JMX77CQ/ebook_CCNA-Day2.rar.html
http://www.uploading.com/files/Q2BZMZ8K/ebook_CCNA-Day3.rar.html
http://www.uploading.com/files/0SHTD5IZ/ebook_CCNA-Day1.rar.html
http://www.uploading.com/files/VSH6TP0M/ebook_Apache_JMeter.rar.html
http://www.uploading.com/files/841PZ2DY/ebook_Building_and_Maintaining_Linux_Clu…rar.html
http://www.uploading.com/files/RLA70Z7U/ebook_CCNA-Day4.rar.html
http://www.uploading.com/files/AFNUPLZ3/ebook_Essential_Windows_Communication_Fo…rar.html
http://www.uploading.com/files/975RXM87/ebook_Dangerous_Google_-_Searching_For_S…rar.html
http://www.uploading.com/files/HXKCIMYO/ebook_Data_and_Databases_-_Concepts_in_P…pdf.html
http://www.uploading.com/files/74U122BF/ebook_Hacking_Vim.rar.html
http://www.uploading.com/files/GKS2TC4L/ebook_Introducing_Windows_Server_2008.rar.html
http://www.uploading.com/files/X9TMJOOJ/ebook_IP_Network_Design_Guide.rar.html
http://www.uploading.com/files/W8LQLC1J/ebook_Learning.the.Yahoo.User.Interface….rar.html
http://www.uploading.com/files/3VA7BQUT/ebook_Distributed_Applications_-_Integra…rar.html
http://www.uploading.com/files/O77GEO8D/ebook_Mastering_OpenLDAP_-_Configuring__…rar.html
http://www.uploading.com/files/0PBXBFMK/ebook_MediaWiki_Administrators_s_Tutoria…rar.html
http://www.uploading.com/files/IS0PR8TO/ebook_Microsoft_Windows_Server_2008_Admi…rar.html
http://www.uploading.com/files/DYOU5YOH/ebook_Object_Oriented_JavaScript_Jul_2008.rar.html
http://www.uploading.com/files/7QJUTUK9/ebook_Mobile_Web_Development.rar.html
http://www.uploading.com/files/4QKE5XOB/ebook_OSWorkflow_A_Guide_for_Java_Develo…rar.html
http://www.uploading.com/files/I3PFDAB3/ebook_Professional_CSS_Cascading_Style_S…rar.html
http://www.uploading.com/files/KBSXADXQ/ebook_Web_Content_Management_With_Docume…rar.html
http://www.uploading.com/files/05CUUUEL/ebook_Web_Host_Manager_Administration_Gu…rar.html
http://www.uploading.com/files/1SDKO460/ebook_Windows_Server_2008_Active_Directo…rar.html
http://www.uploading.com/files/DHP1O8TR/ebook_Windows_Server_2008_For_Dummies.rar.html
http://www.uploading.com/files/V8XC2KZ7/ebook_Windows_Server_2008_Networking_and…rar.html
http://www.uploading.com/files/3TR1T7IM/ebook_Windows_Server_2008_TCP_IP_Protoco…rar.html
http://uploading.com/files/4QKE5XOB/ebook_OSWorkflow_A_Guide_for_Java_Developers_and_Architects.rar.html

domingo, 24 de abril de 2011

Web Application Scanners: Definitions and Functions

Abstract
There are many commercial software security assurance tools that claim to detect and prevent vulnerabilities in application software. However, a closer look at the tools often leaves one wondering which tools find what vulnerabilities. This paper identifies a taxonomy of software security assurance tools and defines one type of tool: web application scanner, i.e., an automated program that examines web applications for security vulnerabilities. We describe the types of functions that are generally found in a web application scanner and how to test it.
 
1. Introduction and motivation
New security vulnerabilities are discovered every day in commonly used applications. In the recent years, web applications have become primary targets of attacks. The National Vulnerability Database (NVD) [14] maintained by the National Institute of Standards and Technology (NIST) has over 18,500 vulnerabilities (as of August 18, 2006). These include 2,757 buffer overflow, 2,147 cross-site scripting (XSS), and 1,600 SQL injection vulnerabilities. XSS and SQL injection vulnerabilities occur mostly in web-based applications. 

Figure 1 shows the percentages of the total vulnerabilities reported in the NVD represented by cross-site scripting and SQL injection vulnerabilities. The NVD contains no reports for XSS and SQL
injection vulnerabilities prior to year 2000. The share of these vulnerabilities is large and rapidly growing. On the other hand, the share of the buffer overflows, a widely studied security weakness, has not increased in the last several years.

Web application security is difficult because these applications are, by definition, exposed to the general public, including malicious users. Additionally, input to web applications comes from within HTTP requests. Correctly processing this input is difficult. The incorrect or missing input validation causes most vulnerabilities in web applications.

Network firewalls, network vulnerability scanners, and the use of Secure Socket Layer (SSL) do not make a web site secure[7]. The Gartner Group estimates that over 70% of attacks against a company's web site or web application come at the application layer, not the network or system layer[22].
 
Web application scanners help reduce the number of vulnerabilities in web applications. Briefly, web application scanners crawl through a web application’s pages and search the application for vulnerabilities by simulating attacks on it.
While web application scanners can find many vulnerabilities, they alone cannot provide evidence that an application is secure. Web application scanners are applied late in the software development life cycle. Security must be designed and built in. Different types of tools and best practices must be applied throughout the development life cycle[11].

Currently, there is no agreement about what a web application scanner is. To enable objective comparison of different tools, the required functionality of web application scanner must be clearly identified.
We define “web application scanner” and present some vulnerabilities that this tool class should detect. This work is a part of the NIST SAMATE project.
1.1. The SAMATE project  
The Software Assurance Metrics and Tool Evaluation (SAMATE) [23] project intends to provide a measure of confidence in the software tools used for software assurance. Part of the SAMATE project is the identification and measurement of software security assurance tools, including web application scanners.
When we have chosen a particular class of tools to work on, we begin by writing a specification. The specification typically consists of an informal list of features, and then more formally worded requirements for features, both mandatory and optional. For each tool class, we recruit a focus group to review and advise on specifications. We also develop a test plan and test sets to check that the tool is indeed capable of satisfying a set of mandatory requirements.
Currently, we are developing a specification and test plan for source code analyzers. We also plan to develop a specification for web application scanners.
1.2. Definitions   Often, different terms are used to refer to the same concept in security literature. Different authors may use the same term to refer to different concepts. For clarity we give our definitions.
Software assurance is the planned and systematic set of activities that ensures that software processes and products conform to requirements, standards and procedures in order to help achieve:
  • Trustworthiness – no exploitable vulnerabilities exist either of malicious or unintended origin, and
  • Predictable execution – justifiable confidence that software, when executed, functions as intended.
In general, a software security assurance (SSA) tool is an automated piece of software that detects or prevents security weaknesses and vulnerabilities.

Weaknesses in requirements, design, implementation, or operation may have either direct or indirect impact on security. In what follows, we use the terms “weakness” and “security weakness” interchangeably.
A weakness may result in a vulnerability, that is, a possibility of harming the system. A weakness may be the lack of program instructions, for example, lack of a check for buffer size. Since a weakness may or may not result in a vulnerability, we use the term "weakness" instead of "flaw" or "defect". Often, vulnerability is caused by a combination of weaknesses.

A false positive is a situation where a tool reports correct behavior as vulnerability.

To accurately determine how well a tool checks for weaknesses, one must begin with a taxonomy of weaknesses. Several security weakness classification schemes have been proposed. The latest attempt at unifying the schemes is the Common Weakness Enumeration (CWE). 

1.3. A taxonomy of SSA tool classes

As the first step in identification of SSA tools, we need a taxonomy, or classification, of SSA tools and techniques in order to prioritize our effort.

We started by asking what classes of tools are currently used to identify potential vulnerabilities in software. We then asked what capabilities a tool should have to be placed into a particular class of tools. A taxonomy, is organized around four facets: software development life cycle phase (from requirements to operation), automation level (from manual to fully automated), approach (preclude, detect, mitigate, react), and viewpoint (external vs. internal).

2. What is a web application? The Web Application Security Consortium (WASC) defines a web application as "a software application, executed by a web server, which responds to dynamic web page requests over HTTP."

A web application is comprised of a collection of scripts, which reside on a web server and interact with databases or other sources of dynamic content. Using the infrastructure of the Internet, web applications allow service providers and clients to share and manipulate information in a platform-independent manner. For a good introduction to web application from the penetration tester’s perspective.
The technologies used to build web applications include PHP, Active Server Pages (ASP), Perl, Common Gateway Interface (CGI), Java Server Pages (JSP), JavaScript, VBScript, etc. Some of the broad categories of web application technologies are communication protocols, formats, server-side and client-side scripting languages, browser plug-ins, and web server API.
A web application has a distributed n-tiered architecture. Typically, there is a client (web browser), a web server, an application server (or several application servers), and a persistence (database) server. Figure 2 presents a simplified view of a web application. There may be a firewall between web client and web server.
 
2.1. Sources of vulnerabilities in web applications
Web applications typically interact with the user via FORM (buttons, text boxes, etc.) elements and GET or POST variables. The incorrect processing of data elements within the HTTP requests causes most critical vulnerabilities in the web applications. While SSL ensures secure data transfer, it does not prevent these vulnerabilities because it transmits HTTP requests without scrutiny.

Web applications are a gateway to databases that hold critical application data and assets. Some of the main threats to the database server tier include SQL injection, unauthorized server access and password cracking. Most SQL injection vulnerabilities result from poor input validation.

Most web applications store sensitive information in databases or on a file system. Developers often make mistakes in the use of cryptographic techniques to protect this information.

Since HTTP is a stateless protocol, web applications use separate mechanisms to maintain session state. A session is a series of interactions between user and web application during a single visit to the web site. Typically, session management is done through the use of a pseudo-unique string called Session ID, which gets transmitted to the web server with every request. Most web scripting languages support sessions via GET variables and/or cookies. If an attacker can guess or steal a session ID, he can manipulate another user’s session.
We provide a list of vulnerabilities in Section 4.1.

3. What is a web application scanner?
A web application scanner is an automated program that examines web applications for security vulnerabilities. In addition to searching for web application specific vulnerabilities, the tools also look for software coding errors, such as illegal input strings and buffer overflows.
Web application scanner explores an application by crawling through its web pages and performs penetration testing - an active analysis of a web application by simulating attacks on it. This involves generation of malicious inputs and subsequent evaluation of application’s response. Web application scanner performs different types of attack. A generally useful attack, called fuzzing, is submitting random inputs of various sizes to the application.
Penetration testing is a black-box testing approach. The limitation of this approach is its inability to examine source code, thus it is unlikely to detect such vulnerabilities as back doors. However, it is well suited for detecting input validation problems. Additionally, client-side code (JavaScript, etc.) is available to the penetration tester and can provide important information about the inner workings of a Web application.
Some instances of commercial web application scanners are listed below. This list is obtained from references [5,25,6] and web sites.
  • AppScan [29]
  • WebKing [20]
  • WebInspect [26]
  • NTOspider [16]
3.1. Other web application security tool types

We contrast web application scanner with some other approaches and point out their differences.
A web application firewall, sometimes called wrapper, is a tool that examines HTTP requests and responses for application specific vulnerabilities. It is used primarily during system operation phase, whereas web application scanners are used primarily during testing phase. Also, web application scanner performs active detection by simulating attacks, whereas web application firewall mitigates vulnerabilities.
Although web application firewall can be used to detect vulnerabilities by examining saved attack information, the detection is passive. That is, nothing is detected until and unless an attack triggers a response indicating a vulnerability.
Source code analysis is a white-box testing approach that scans the application source code for security weaknesses. Source code scanners are primarily used during the implementation phase of the software development life cycle. Some source code scanners can detect web application specific vulnerabilities.
Using a framework is another approach. Frameworks assist coders and security analysts in the process of testing their Web applications, either by providing an interface that exposes the internals of the HTTP traffic, or by helping create automated tests for custom Web applications.
No single approach is sufficient to make web applications secure: different types of tools must be used at different stages of the development life cycle, starting with the early phases. Below are some instances of web security tools which are not web application scanners.
  • NC2000 [15] is an application gateway. It is a physical box that is placed in front of a web server and examines the traffic to/from the web application. 
  • Nessus [27] is an open source scanner that supports a plugin architecture allowing users to develop security checks with the NASL (Nessus Attack Scripting Language). 
  • WebScarab [19] is a framework for analyzing applications that communicate using the HTTP and HTTPS protocols. It observes the conversations (requests and responses) and allows the operator to review them. It provides a number of plugins, mainly aimed at security functionality. Plugins perform one of two tasks: generate requests or analyze conversations.
3.2. Other types of information security tools
SANS Institute [25] classifies the information security tools into the following five categories:
  1. Blocking attacks: Network based (includes secure web filtering)
  2. Blocking attacks: Host based
  3. Eliminating security vulnerabilities (includes penetration testing and application security testing)
  4. Safely supporting authorized users
  5. Tools to minimize business losses and maximize effectiveness
Web application scanners are in category 3. The class of web application scanners consists of tools that detect potential vulnerabilities in the web applications only, and not on the network. In addition to web application scanners, the overall security defense should include tools for web services, database scanners, network firewalls, anti-virus gateways, routers, intrusion detection/protection systems, and other tools.

4. Functional requirements for web application scanner
To develop a specification for web application scanners, we must clearly define a set of functions that a tool must successfully perform. A web application scanner must:

  • Identify a selected set of software security vulnerabilities in a web application. 
  • Generate a text report indicating an action (or a sequence of actions) that leads to vulnerability. 
  • Generate an acceptably low ratio of false positives.
4.1. Some web application vulnerabilities
In this section, we identify a list of vulnerabilities that a web application scanner should detect. This list will form the basis for a formally worded requirement for mandatory features for a web application scanner. An extensive classification of web security threats can be found in [30]. The Open Web Application Security Project (OWASP) publishes the list of the most critical web application vulnerabilities [17]. These and other efforts are being incorporated into CWE [4].
Input validation weaknesses cause most web application vulnerabilities. Other types of weaknesses include use of poor authentication mechanisms, logic weaknesses, unintentional disclosure of content and environment information, and low-level coding weaknesses (such as buffer overflows). Often, vulnerability is caused by a combination of weaknesses. Some common vulnerabilities and attacks are:
  • Cross-site scripting (XSS) vulnerabilities. The vulnerability occurs when an attacker submits malicious data to a web application. Examples of such data are client-side scripts and hyperlinks to an attacker’s site. If the application gathers the data without proper validation and dynamically displays it within its generated web pages, it will display the malicious data in a legitimate user’s browser. As a result, the attacker can manipulate or steal the credentials of the legitimate user, impersonate the user, or execute malicious scripts on the user’s machine.
  • Injection vulnerabilities. This includes data injection, command injection, resource injection, and SQL injection. SQL Injection occurs when a web application does not properly filter user input and places it directly into a SQL statement. This can allow disclosure and/or modification of data in the database. Another possible object of injection is executable scripts, which can be coerced into doing things that their authors did not anticipate.
  • Cookie poisoning is a technique mainly for achieving impersonation and breach of privacy through manipulation of session cookies, which maintain the identity of the client. By forging these cookies, an attacker can impersonate a valid client, and thus gain information and perform actions on behalf of the victim.
  • Unvalidated input. XSS, SQL Injection, and cookie poisoning vulnerabilities are some of the specific instances of this problem. In addition, it includes tainted data and forms, improper use of hidden fields, use of unvalidated data in array index, in function call, in a format string, in loop condition, in memory allocation and array allocation.
  • Authentication, authorization and access control vulnerabilities could allow malicious user to gain control of the application or backend servers. This includes weak password management, use of poor encryption methods, use of privilege elevation, use of insecure macro for dangerous functions, use of unintended copy, authentication errors, and cryptographic errors.
  • Incorrect error handling and reporting may reveal information thus opening doors for malicious users to guess sensitive information. This includes catch NullPointerException, empty catch block, overly-broad catch block and overly-broad “throws” declaration. 
Some other vulnerabilities are:
  • Denial of service
  • Path manipulation
  • Broken session management
  • Synchronization timing problems
More work is needed to refine the list of vulnerabilities that the web application scanners must support. 

5. Issues in testing web application scanners
In addition to a functional specification, we need a test plan and a suite (or several suites) of test cases to check that a web application scanner satisfies the specification.

A test plan details how a tool is tested, how to interpret test results, and how to summarize or report tests. Currently, tools produce reports in a variety of formats. A common reporting format would make it easier to automate comparison of different tools.

We measure conformance of a tool to the specification by running it against a variety of test cases. In choosing test cases, it is important to understand the ways in which an attacker exploits vulnerabilities.

In normal operation, a user submits a request to the web application and gets a response back. An attacker submits an unexpected request to an application in hopes of exploiting an existing vulnerability. The goal of an attacker is to violate application’s security policy. The attacker recognizes the existence of vulnerability either by examining application’s response or indirectly, by noticing changes in application’s behavior (this may include probing different parts of the application). Web application scanner works by simulating attacker’s action.

To test web application scanners, we need web applications with vulnerabilities. For each vulnerability class, there must be at least one test application that exhibits it. Small test cases with a single vulnerability can be used to precisely test tools’ ability to detect specific vulnerabilities. Large applications with a variety of vulnerabilities, such as WebGoat [18], will test scalability of a tool for real life applications. It is also important to test tools’ ability to detect vulnerabilities in web applications built using different web technologies.

A basic test suite may contain only applications with easily exploitable vulnerabilities. For instance, if an application does no input validation at all, there are many ways to exploit the vulnerability and most tools can find it. However, to thoroughly test a scanner, we need programs with subtle vulnerabilities.

Different types of SQL injection represent another example. An attacker typically sends a request to cause the application to generate a SQL query that can induce unexpected behavior. Then the attacker examines the error message returned to the web client. A typical mitigation approach is to prevent the application from displaying any database error messages. The vulnerability, though harder to detect, still exists – it is called “blind SQL injection”.

In order to check for false positives, we need test cases that are free of vulnerabilities but have some features that cause difficulty for web application scanners. Generation of such test cases is an interesting research problem that requires understanding the way the tools work.

While developing test suites, we collect much larger numbers of candidate test cases. This collection, the SAMATE Reference Dataset (SRD) [23], is freely accessible on-line. We intend the database to support empirical research of software assurance. It contains over 1,600 test cases for source code analysis tools (as of August 18, 2006). We intend to add many test cases for web application scanners. We welcome participation from researchers and companies.

6. Summary
We defined web application scanners and presented some vulnerabilities that this class of tools should detect. We plan to develop a specification for web application scanners. The specification will give a precise definition of functions that the tools in this class must perform. We will develop suites of test cases to measure conformance of tools to the specification. This will enable more objective comparison of web application scanners and stimulate their improvement.

7. Acknowledgments
We thank Jeffrey Meister, Paul E. Black, and Eric Dalci for improving our understanding of web application scanners and many helpful suggestions on this paper. We also thank the anonymous reviewers for their insightful comments.

8. References
[1] A. Avizienis, J-C. Laprie, B. Randell, and C. Landwehr, “Basic Concepts and Taxonomy of Dependable and Secure Computing,” IEEE Trans. on Dependable and Secure Computing, 1(1):11-33, Jan-Mar 2004.

[2] M. Bishop and D. Bailey, “A Critical Analysis of Vulnerability Taxonomies,” Technical Report 96-11, Department of Computer Science, University of California at Davis, Sep. 1996.


[3] Black, Paul E. and Fong, Elizabeth, “Proceedings of Defining the State of the Art in Software Security Tool Workshop,” NIST Special Publication 500-264, September 2005.

[4] Common Weakness Enumeration (CWE), MITRE, http://cve.mitre.org/cwe/

[5] DISA, Application Security Tool Assessment Survey, V3.0, July 29, 2004. (To be published as STIG)

[6] Arian J. Evans, “Software Security Quality: Testing Taxonomy and Testing Tools Classification,” Presentation viewgraph for OWASP APPSec DC, October 2005.

[7] Jeremiah Grossman, The Five Myths of Web Application Security, WhiteHat Security, Inc, 2005.

[8] Michael Howard, David LeBlanc, and John Viega, 19 Deadly Sins of Software Security. McGraw-Hill Osborne Media, July 2005.

[9] Andrew J. Kornecki and Janusz Zalewski, The Qualification of Software Development Tools From the DO-178B Certification Perspective, CrossTalk, pages 19-23, April 2006

[10] C. E. Landwehr, A. R. Bull, J. P. McDermott, and W. S. Choi, “A Taxonomy of Computer Program Security Flaws,” Information Technology Division, Naval Research Laboratory, Washington, D. C., September 1994.

[11] G. McGraw, Software Security: Building Security In, Addison-Wesley Software Security Series, 2006.

[12] Jody Melbourne and David Jorm, Penetration Testing for Web Applications, in SecurityFocus, 2003.

[13] NASA Software Assurance Guidebook and Standard, http://satc.gsfc.nasa.gov/assure/assurepage.html

[14] National Vulnerability Database (NVD), http://nvd.nist.gov/

[15] Netcontinuum, NC2000, http://netcontinuum.com/products/

[16] NT Objectives, NTOSpider, http://www.ntobjectives.com/products/ntospider.php

[17] OWASP, “The Ten Most Critical Web Application Security Vulnerabilities,” http://www.owasp.org/index.php/OWASP_Top_Ten_Project

[18] OWASP, WebGoat Project, http://www.owasp.org/software/webgoat.html.
 
[19] OWASP, WebScarab http://www.owasp.org/software/webscarab/
 
[20] Parasoft, WebKing, http://www.parasoft.com/webking

[21] F. Piessens. “A taxonomy (with examples) of software vulnerabilities in Internet software,” Report CW 346, Katholieke University Leuven, 2002.

[22] Prescatore, John, Gartner, quoted in Computerworld, Feb. 25, 2005, http://www.computerworld.com/printthis/2005/0,4814,99981,00.html

[23] SAMATE project, http://samate.nist.gov/

[24] SAMATE Tool Taxonomy, http://samate.nist.gov/index.php/Tool_Taxonomy

[25] SANS Institute, http://www.sans.org/whatworks

[26] SPI Dynamics, WebInspect, http://www.spidynamics.com/products/webinspect/

[27] Tenable Network Security, Nessus, http://www.nessus.org/about/

[28] K. Tsipenyuk, B. Chess, and G. McGraw, “Seven Pernicious Kingdoms: A Taxonomy of Software Security Errors,” Proc. NIST Workshop on Software Security Assurance Tools, Techniques, and Metrics (SSATTM), US National Institute of Standards and Technology, 2005.

[29] Watchfire, AppScan, http://www.watchfire.com/products/appscan/

[30] Web Application Security Consortium, “Threat Classification,” http://www.webappsec.org/projects/threat/

[31] Web Application Security Consortium Glossary, http://www.webappsec.org/projects/glossary/ 

miércoles, 13 de abril de 2011

Social networks in transnational and virtual communities

Question
  • Why do some communities survive and some disintegrate? 
or more importantly …
  • How are today’s communities created and maintained?

 

Social Networks

  • Social networks can explain how communities are created and maintained.  
  • Individuals create interpersonal bonds with others within their social network that are interwoven with the social institutions of their society.
  • These interwoven patterns and matrices can facilitate the success or failure of societies and organisations that depend on these networks.
  • Social ties are not fixed. Networks are constantly being socially constructed and altered by their members. 
  • Interpersonal relations within social networks cut across traditional boundaries such as neighbourhood, workplace, kinship and class.
  • Sociologist in the 1950s anticipated disconnectedness, loss of community and weakly supportive relationships due to “rapid modernisation”.  
  • Yet the realisation of the Internet and modern technologies have provided for community creation well beyond expectation.
  • How have social networks facilitated communities?
  • A proposed framework helps to explain how social networks facilitate the creation and maintenance of communities regardless of size and communication medium.
  • In particular we look at transnational communities and virtual communities. Transnational Communities
  • “Migration is a process that both depends on and creates social networks” (Portes, 1995) 
    • Transnational communities are characterised by perpetual back and forth border crossing movements among migrants. 
    • Communities whose mobility is celebrated as being “neither here nor there” (Portes) 
    • Communities whose mobility is a drama of displacement, destitution, and ultimate homelessness (Torres-Saillant)

 

 

Virtual Communities

  • “The online social network provided a venue for storytelling, showcasing, projects and best practices that could be leveraged to create new knowledge resources” (Kimball & Rheingold, 2000) 
    • People who are geographically separated or “on the road” need a way of maintaining contact, whether they are part of a large community or an organisational project team. 
    • Virtual settlements.

 

 

Social Spaces

  • Social spaces are: 
  • place-centered (embedded in particular location)  
  • trans-territorial (geographically disparate but intensely connected) 
  • and social spaces: 
  • are where individuals first meet and develop contacts 
  • provide the initial medium to form and maintain basic connections which enable individuals to create relationships 
  • create the identity or belongingness of the community (e.g. campus, shopping mall, town squares).
 

 

 

Social Formation

  • Relationships exist between individuals or between groups which are mostly dynamic but strengthen a sense of identity and belonging in groups and teams.  
    • Notion of community consciousness 
  • These groups are often in different social arenas, but are identifiable in any community.  
  • The key members of these groups are those who are stakeholders within their community.
  • Key members use communication and social spaces to maintain their networks. 
  • Community members are embedded in the community in two ways:
    • how they relate personally to each other (relational embeddedness) 
    • how social relationships affect social structures (structural embeddedness) 

 

 

Social Capital

  • Social capital is defined as a player’s level of cooperativeness within a social network.  
  • A social network is a set of players and a pattern of exchange of information and/or goods among these players. 
  • Social capital is developed and maintained over time through regular communication, participation in events and membership of associations
  • Participation alone is not capital building – reciprocation is required

 

Transnational Communities

  • Not only individual people migrate, but their social networks migrate also. 
    • Social networks are crucial for finding jobs, accommodation, psychological support, social and economic information. 
    • Migration is a process of network building, which reinforces social relationships across space.
  • Virtual community members bring offline values and interactions in their online communities. 
    • Many believe that virtual communities are sociologically the same as their “brick and mortar” counterparts.

Conclusions
  • Social networks do not depend on one relationship or on any particular social space in which people meet. 
  • Social networks depend on the process of creating relationships, embedding oneself into the social structure – whether the structure be trans-territorial or virtually co-located – and the ability to mobilise social capital.