Friday, September 6, 2019
Internal Building Security Proposal Essay Example for Free
Internal Building Security Proposal Essay Internal Building Security Proposal Access Control is an important part of any business. Anytime a business is under construction it will be more vulnerable to threats and attacks. Construction will need more protection because of the ability to gain easier access to a building because of the open areas within the building. Certain areas in a building are a target for attacks. Some areas are higher risk because of the information or high-value assets within the building. Access Control is the best way to wing out some threats and minimize other threats. Each individual at an access point will have several types of protection such as gates, lighting, cameras, detectors, sensors and other devices that can check individuals thoroughly and make sure each one is authorized to be in the building. Keeping individuals out that have no authorization can lower threats and minimizes chances of damage occurring externally. Access control will work from the outside in to protect a business. Technology is continuing to get better and there are a lot more devices available that can enhance security and help assist the personnel when concerning responsibilities. Access control still needs the support of security personnel to make sure all the devices are functioning properly. Technology has to be maintained to run properly and do what it is designed to do. Access Control was created to keep unwanted individuals from entering a location and to prevent from any employees or personnel from leaving with any valuable information unnoticed. There are so many ways to access a building that any vulnerable areas may be threatened at some point. Access control helps to minimize the vulnerabilities and lower threats against a business. Construction on a building will leave certain areas vulnerable and will be more difficult to secure because of all the individuals coming from outside of the business to do a job. More people can mean more threats, this will need more protection. Some of the types of technology that are becoming popular for protection are wireless access points, cameras, sensors,à detectors, wands, and computers. Security personnel are using these devices to detect and deter crime in the work environment (University of Phoenix, 2008). Wireless Access points and surveillance are becoming more common because of the portability. It is more difficult to carry around a big computer for monitoring purposes and access control. A wireless computer is much more compact and lighter to carry around while handling the responsibilities of monitoring employees at an access point. A building will also have a way for security personnel to monitor different areas of the building by using cameras. A wireless computer can make it easier to monitor these different areas all in one area. Cameras will not take the place of security but can make it easier for security to cover more ground successfully and still be able to perform other duties. One advantage that cameras have is that as long as maintenance is kept up that cameras will run non-stop even when security is unavailable or just in a different location. Crime can still occur with security on patrol. Areas more vulnerable can use cameras to help catch any activity that seems out of place. In most instances cameras are only viewed when something has already occurred and can validate an individualââ¬â¢s where physical where about during a certain time period. Sensors are a growing trend at access points. Many industrial buildings will have products that employees will have contact with during a work day. A business will use sensors on products to keep track of the location, while in the building. One product may be received and shipped from one location to the next until the process is complete and ready to be shipped to another building. Sensors can also be caught at access points if individuals attempt to leave the building with a product without authorization. One device that can find such sensors is the detector. At several access points for employeesââ¬â¢ detectors will be present and scanned over an individual to ensure that no sensors are found before leaving a building during lunch and after work hours. A wand is just one type of detector that will scan and have an alarm go off when it detects certain materials. Individuals will have to physically take anything out of their pockets and show that it is not a business product. Another type of detector is a full body detector that can detect different objects on a person without having to do a strip search. Computers is somet hing that is storing more data for a business and also it has the capability of doing other tasksà such as viewing camera feed during recording, and keeping track of authorization, cards, and keys for employees. At different access gates, a card will need scanning before entering. A computer can make sure that the card scanned at the gate is valid. A private intranet will hold information for a business about employees, customers, employers, and the business products and services. This type of device will have access points within the system. A computer will have a private server but is still running on the internet and can be hacked. Hackers will try and find ways to access the information and retrieve or damage it. A business can find ways to strengthen the access points into the private database and prevent hackers from accessing business information. A computer will have software, updates, passwords, and programs to protect intruders from hacking thedatabase without authorization. Computers need protection to prevent from damage. A system that has been hacked can corrupt the system and make it unusable. A way of protecting a system before it is damaged is having a back-up system. If the system is destroyed the back-up can make a business more prepared for any threats or damage to restore the system back to normal (University of Phoenix, 2011). A business will have certain areas that contain more vital information or equipment that can be threatened by construction. Areas that are more high-value need more layers of protection against any threats. Data of a business will contain information such as customer records which will have information, such as where they live, telephone numbers, full names, social security numbers and more which can be used to commit other crimes such as fraud. High-value areas are more vulnerable because the amount of damage that can be done will cost more than in other areas of the building. For instance, bathrooms of a facility will have little to no products and are less of a risk than an office. So the security will focus more on offices because of the amount of value. Some areas may only include security cameras for monitoring an area. A big high-value area could include the main power room. This area can cause damage to not only the building but also to the equipment. The main power room may have heavier walls, more cameras, passwords, security personnel, and other types of protection. There are several considerations that should be kept in mind such as who can access the room, who will be working in a room that is in the high-value areas? High-value rooms will be threatenedà normally both internally and externally. If a construction area is near anything high-value at a business, extra precautions may be taken to make sure the area is secure from both types of threats. Internal building security is important to have for every business to protect the business. A business has many assets that are unable to protect themselves. Security personnel are hired to protect the business, the people, and the environment. In a new building security will be less effective because of financial status and experience with threats. The type of threats will vary and the only way to avoid vulnerabilities is attempting to use other existing buildings methods when concerning access control, surveillance, and the protection of high-value areas. A business has to prepare for threats before they occur and then deal with new ones as they arise if there is no prior experience with the type of threat. For example, hackers are always finding ways to hack a system. No code or encryption that is created is identical and all the programs and software in the world can protect a business from all threats. A business needs constant management to evolve with society and the new changes. Taking advantage of new technologies will improve the chance of success for both the business and security. References University of Phoenix. (2008). Design and Evaluation of Physical Protection and Systems.
Thursday, September 5, 2019
Feminism and the Body in Art
Feminism and the Body in Art Modernism is described usually as a movement and a tendency to provoke reflection and an individual character. During this period, art was seen to be set in its ways and people wanted to expand with new ideas and not stay in the lines of colour and structure. This movement was a representation of alternative modes for literature, art, photography and film. Its intention was to find new hidden meaning in human kind and use them to the best of their ability in experimentation. I feel therefore I exist. (Internet Archive Jean Jacques) The Oxford English Dictionary refers to postmodernism as a style and concept in the arts characterized by distrust of theories and ideologies and by the drawing of attention to conventions. (Internet Oxford Dictionary) Post Modernism didnt seem to have a theory, it was what it was, which meant it had smaller narratives and people gained the knowledge to do something with it. This is also portrayed in what was thought to be the start date of post modernism as no one really knows when modernism ends and postmodernism starts, what it does illustrate is cultural thinking and the way we live, what came with this is the reaction to what people thought modernism was. People rejected the thought of perfection but wanted design and purpose. Known for her conversation on bodies, sexuality and gender Carolee Schneemanns work is fundamentally characterized by research into visual convention. Schneemann focuses on the body as an individual and its relationship in general. Schneemanns family was largely supportive of her enjoyment of freeness with her body. As a child, her friends described her as a mad pantheist, due to her relationship and respect for nature'(Kate Haug p114) Schneemann cites her earliest connections between art and sexuality to her drawings from ages four and five, which she drew on her fathers prescription tablets (Linda Montano p135) Carolee Schneemann started her art career as a painter in the late 1950s. Neo-Dada was something that had because an accruing characteristic in her work, adopting box structures coupled with expressionist brushwork. These were shared with Robert Rauschberg using heavy textural characteristics. Schneemann described the atmosphere in the art community at this time as misogynistic and that female artists of the time were not aware of their bodies. These works integrated influence by artists such as Post-Impressionist painter Paul CÃ ©zanne and the issues in painting brought up by the abstract expressionists. (internet archive Jane Harris) Schneemann chose to focus on expressiveness in her art rather than accessibility or stylishness. Still describing herself as a formalist, unlike other feminist artists she didnt want to distance herself from male-oriented art history. Schneemann acknowledges that she is often labelled as a feminist icon and that she is an influential figure to female artists, but she also notes that she reaches out to male artists as well. Though she is noted for being a feminist figure, her works explore issues in art and rely heavily on her broad knowledge of art history. Though works such as Eye Body were meant to explore the processes of painting and assemblage, rather than to address feminist topics, they still possess a strong female presence. Revolving herself around sexual expression and liberation Schneemann decided not to revolve around victimization and repression of women. According to artist and lecturer Johannes Birringer, Schneemanns work resists the political correctness enforced by some branches of feminism as well as ideologies which feminists claim are misogynist, such as psychoanalysis. He also asserts that Schneemanns work is difficult to classify and analyze as it combines constructivist and painterly concepts with her physical body and energy.'(Kristine Stiles p3) In her 1976 book CÃ ©zanne, She Was a Great Painter, Schneemann wrote that she used nudity in her artwork to break taboos associated with the kinetic human body and to show that the life of the body is more variously expressive than a sex-negative society can admit. She also stated, In some sense I made a gift of my body to other women; giving our bodies back to ourselves. She preferred her term art historical (without the h), so as to reject th e his in history (Bonnie Marranca Review) While Jo Spence being a surliest and a feminist started her art life working on documentaries, which was very motivated by her political views. Spreading her working life across various camera projects, including being the founder of Hackney Flashers in 1974. After being diagnosed with cancer, Spence became particularly fascinated with the doctor patient relationship Passing through the hands of the medical profession can be terrifying when you have breast cancer.'(Jo Stanley article) Spence decided to document everything that was happening to her through photography, a piece taken while she had a mammograph done truly showed the brutality of her illness as she put her whole body under the scrutiny of one machine making her an active subject in her work. After a lumpectomy, Spence decided to undertake the holistic approach to cancer and underwent various Chinese medicine treatments, as she felt no need for chemotherapy or radioactive drugs. She also decided to use photography as a healing drug putting the emotion and passion into her work as she felt like cancer was able to take everything else. Through phototherapy she managed to capture the relationship between the doctor and the patient, her feelings towards cancer and the powerlessness as a patient. All of this was a need for Jo Spence to portray as not only a patient but a feminist. She was particularly interested in the perception of the breast as substance of desire, a medium for nourishing babies, and finally in her case of breast cancer, as a possession to be installed in the hands of the medical institution. This is what has really inspired me with her work, and her experience during her suffering of cancer. This is demonstrated in her photo of her breast, marked with pen t he property of Jo Spence? where she appears to question her rights over her own body, using the breast as a metaphor for womens struggle to become an active subject. (Bonnie Marranca Review) She puts no limits on her work and covers many social issues while her own pain. Jo Spence really makes me think about the body as a subject rather than an object. Thinking about the body and what it is used for, you never expect it to be destroyed by such an evil mass and this is what Jo Spence looks at. I think Spence has a certain power over her work and having such a raw quality which she uses to her best advantage, this is something I can only hope to achieve in my future work. After looking at her work I can only appreciate her time going through her ordeal of cancer, as I have only been a witness to what cancer can do no one can fully understand it until you go through it. Spence using photography captures the story but what cant be told. Internet Archive The Confessions Of Jean Jacques Rousseau Now For The First Time Completely Translated Into English With Out Expurgation Volume II [internet] [accessed 15.11.2009] http://www.archive.org/stream/confessionsofjea012146mbp/confessionsofjea012146mbp_djvu.txt The Oxford Dictionary, Oxford University Press 2009 [internet] [accessed 15.11.2009] http://www.askoxford.com/concise_oed/postmodernism?view=uk Journal Haug, Kate (1998). An Interview with Carolee Schneemann (1) P 114 (accessed 20.11.2009) Montano, Linda (2001). Interview with Linda Montano. Imaging Her Erotics: Essays, Interviews, Projects (accessed 20.11.2009) Morgan, Robert C.1997. Carolee Schneemann: The Politics of Eroticism. Art Journal 56 (4): pp. 97-100 (accessed 20.11.2009) Harris, Jane (1996). Review / Carolee schneemann http://www.plexus.org/review/harris/schneemn.html (internet) (accessed 20.11.2009) The Art of Transgression. Jo Stanley, editor. Routledge.1995 (accessed 20.11.2009) Stiles, Kristine (2003). The Painter as an Instrument of Real Time. Imaging Her Erotics: Essays, Interviews, Project (accessed 22.11.09) Marranca, Bonnie (1999). Book Review: Bodies of Action, Bodies of Thought: Performance and Its Critics p20 (accessed 22.11.09) Bonnie (1999). Book Review: Bodies of Action, Bodies of Thought: Performance and Its Critics p41 (accessed 22.11.09)
Forensic Analysis of Personal Data Leakage on Android Phone
Forensic Analysis of Personal Data Leakage on Android Phone Sheriff Drammehà à RESEARCH STATEMENT The proposed research will explore personal data leakage on the android mobile application platform through forensic analysis of volatile and non-volatile memory. PROPOSAL SUMMARY The proposed research will employ both volatile memory forensic techniques and traditional disk forensic techniques to the android platform in order to identify privacy breaches primarily in android mobile applications [1]. The proposed research also aims to demonstrate that forensic artifacts can be found both in the disk drive (non-volatile) and memory (volatile). AIMS AND OBJECTIVES OF THE PROPOSED RESEARCH 1. Acquire non-volatile data from an android device using the traditional forensic approach and the memory dump, analyse the acquired data for any forensic artifacts and make a comparative analysis of both approaches. This will be achieve by conducting an experimental simulation of both approaches. 2. Develop an effective methodology to improve the detection of personal data leakages and sensitive information from android mobile applications. RESOURCES The major part of this proposed research will be conducting an experiment, hence few equipments are essential to be in place in order to carry out the experiment. The proposed research is mainly memory dumping and disk drive imaging for forensic analysis. Some open source tools will be highly utilize during the course of this proposed research, such as android studio SDK, Odin, ADB and mem. Additionally, books on android forensics, mobile forensics, journals and YouTube video tutorials will also be utilize. As the research progresses more resources might be needed. The following is a non-exhaustive list of resources currently available for use: à ¢-à Window 10 OS with processor Intel (R) Core(TM)i7, install memory of 16.0GB is the host operating system and forensic workstation for disk image analysis à ¢-à Linux Ubuntu 15.10 x32 with kernel v2.6 is our forensic workstation for memory analysis à ¢-à VMware Virtual Machine v11.1.2: Will be used to install guest operating system à ¢-à Physical android phone Samsung galaxy S3: Is the subject of the experiment à ¢-à Android SDK developer tool for Linux x32: Is a software development tool used for application development and analysis. à ¢-à mem is an open source tool for dumping running process on android phone à ¢-à Odin3.-v3.10 is open source tool that enable us to rooted android phone à ¢-à Samsung usb drive for mobile phone used to enable debugging bridge between android phone and forensic workstation à ¢-à CF-Auto-Root-2dcan-2dvl-sghi747m is used to update firmware during rooting process. à ¯Ã¢â¬Å¡Ã · AccessData Forensic tool kit version 3.4.2 ( Download FTK Imager 3.4.2) is forensic software tool used to analysis disk image file 3 | P a g e CONNECTION TO THE COURSES OF MISSM PROGRAM This proposed research is closely related to Digital forensic course (ISSM536), which is one of the course we had covered in our Information Systems and Security Management program. The proposed research used the techniques learned from this class and applied them in the android environment to reveal several types of personal information such as username, password, date of birth, postal addresses contact, photos, account number, messages etc. The comparative analysis method used covers the principles of digital evidence collection learned in Information Technology Security Laws and Ethics course (ISSM561). The proposed research has a beginning and ending, as a result it need to be managed in order to deliver the end result. Therefore, the knowledge learned from (ISSM545) System Development and Project Management. REVIEW OF RELATED RESEARCHS Fuchs, et al., [2] presented the first analysis tool for android called SCanDroid, a framework for Android to perform information flow analysis on applications in order to understand the flow of information from one component to another component. Consider a case where an application request permission to access multiple data stores i.e., public data store and private data store. The application requires permission for reading the data from the private store and writing data to the public store. SCanDriod analyzes the information flow of the application and reports whether the application will transfer the information in the private store to the public store or not. However, SCanDroid also suffers from the same limitation of security policy expressibility. In order to consider some information flow to be dangerous, the policy writers must define certain constraints prior to executing the policy. Similarly, if an information flow is not explicitly added to the set of constraints the f ramework will consider it to be safe. In 2012, C. Gibler, et al., presented AndroidLeaks, a static analysis framework for automatically finding potential leaks of sensitive information in Android applications on a massive scale[4]. It informed the user if applications are leaking their personal information. AndroidLeaks drastically reduces the number of applications and the number of traces that a security auditor has to verify manually. To secure privacy information, they set up a mappings between Android API methods and the required permissions as the sources and sinks of private data for data flow analysis. However, AndroidLeaks does not yet analyze Android-specific control and data flows. This includes Intents, which are used for communication between Android and application components, and content providers, which provide access to database-like structures managed by other components. Sasa Mrdovic et al., [3] proposed a combination of static and live analysis for memory image, which is obtained by hibernation mode (power management feature that exists in most portable computers). After they obtained the physical memory image, they used it to boot the investigated system in the virtual machine (live view) to resume the system to the same state before it went into hibernation mode. Their proposal of using hibernating feature was to obtain the memory contents without violating the evidence integrity, but during their analysis they found out that they lost all the information about network connections because hibernation mode terminates the network connections before it starts in Windows environment. As one of best well-known analysis approaches, Taint Droid detects privacy leaks using dynamic taint tracking [5]. Enck et al. built a modified Android operating system to add taint tracking information to data from privacy-sensitive sources. They track private data as it propagates through applications during execution. If private data is leaked from the phone, the taint tracker records the event in a log which can be audited by the user. In 2015,Young ho Kim et al., proposed a methodology and an architecture for measuring user awareness of sensitive data leakage, which features runtime application analysis over timing distance between the user input event and actual privacy data leak[6]. 4 | P a g e Nai-Wei Lo, Kuo-Hui Yeh, and Chuan-Yen Fan present a user privacy analysis framework called LRPdroid[7]. LRPdroid has been proposed for an Android platform to offer a user privacy management model. In the LRPdroid framework, they defined required models to achieve user privacy management: App execution data flow, user perception, leakage awareness, information leakage detection, privacy disclosure evaluation, and privacy risk assessment. To support the proposed privacy analysis model, two information capture modules for LRPdroid were designed to acquire incoming data inputted by a mobile user and outgoing data transmitted from a targeted App. A system prototype based on the LRPdroid framework was developed to evaluate the feasibility and practicability of LRPdroid. Two general App usage scenarios were adopted during the usage of Line App to evaluate the effectiveness of LRPdroid on user privacy disclosure by social engineering attack, user information leakage from normal operations o f a running App, and privacy risk assessment of targeted running App. In 2015[10], Pasquale Stirparo, Igor Nai Fovino, and Ioannis Kounelis developed a novel methodology called MobiLeak, for analysis of security and privacy level of mobile applications, which focuses more on user data instead of application code and its architecture. Their research work addressed and solved the problems related to the following three research questions for mobile environment and applications: (1)what are data and where can such data exist? (2) How is personal data handled? (3)How can one properly assess the security and privacy of mobile applications? They start their research work with a fundamental prerequisite in order to be able to properly treat them, which is studying and identifying every possibility state at which data can exist. After this step, they analyzed how real life mobile applications and operating systems handle users personal data for each of the states previously identified. Based on these steps they developed MobiLeak, which also combined concepts and principles from the digital forensics discipline. DESCRIPTION OF PROPOSED RESEARCH THE FOCUS OF THE RESEARCH The aim of this proposed research is to examine user data storage mechanism on a mobile application in a context of android platform. Analyzing mobile application for personal data leakage require extensive analysis and in-depth understanding of both the OS and application architecture. The analysis is expected to be conduct to data at rest and data in motion. The result of this proposed research will help to create awareness to both application developers and the android community that users personal data information such as username, password and other sensitive information are at risk both in volatile and non-volatile memory. Finding user sensitive data on android smart phone could be in three (3) locations: disk drive, memory and app server. Our research is limited to two out of the three application data store which is disk drive and memory, both storage areas could prove strategic locations for finding vital information for android smart phone users. The motive of this research is to examine whether applications encrypt user sensitive information both in the memory and the disk drive. This pose the following questions: 1. Does user credentials are encrypted on a memory ? 2. Among the two method which one is more forensically sound? 3. What information could be found in disk drive and not in memory? During the experimental phase of the proposed research certain applications will be examining, such as VOIP applications, social media applications, financial applications and telecom applications. I chose this samples of android application from various categories. Because these applications are fairly popular and are used by millions of people around the globe. For each application I will look at how user sensitive data, such as user name, password, date of birth and account number are store both in the disk drive and the memory. 5 | P a g e The rest of the proposed research section is divided into 4 parts: First I am going talk about my methodology, next I will present the series of preliminary result both in the memory analysis and disk analysis, third I give the highlight of the expected result and finally, I will discuss about certain obstacles that may arise. METHODOLOGY The method used in carrying out the experiment of the proposed research consist of four phases. Phase One: Gather the require tool both in term of hardware and software As the proposed research required memory dump and disk drive imaging analysis a physical android phone is needed to conduct our experiment. 1. Window Host OS and Ubuntu Guest OS as our forensic workstation 2. Android phone Samsung Galaxy S3 3. Installing Odin3.-v3 which will allow us to root our android phone 4. Install android SDK tool for using ADB(Android Debug Bridge) to get shell access on our android Phone 5. Mem application software loaded into our android phone through ADB which allow us to dump the running process from the Phone Phase Two: Installation and configuration of experimental environment At this phase all the required tools, such as the hardware and software are installed and configured. Pre-experiment of memory dump and disk imaging is performed, and tools are verified. Phase Three: Acquisition of disk image and memory dump At this phase the disk image drive is acquired using dd command tool from the internal memory to internal SDcard of the phone and ADB pull is utilize to pull/copy the disk partitions to our forensic work station. Mem program software is utilize, this allow us to dump the running process. We used ADB to install mem application into our phone in order to dump the desired running application process. Phase Four: Preservation and analysis of acquired data The purpose of this phase is to examine acquired application data both in the memory and disk drive. For example, we will check if the application is encrypting users credential both data at rest and data in transit? MEMORY DUMPING ANALYSIS This section provide detail steps taken to analysis the dumped memory of certain applications selected for this proposed research. The result shows that users credential are not properly handle by the application, which can result in personal data leakage. A program called mem was used to facilities the process dump, ABD was also used to install mem program into our android phone. List the running process and dump them into the internal SDcard and finally pull it to our forensic workstation for further analysis. Strings and sqlite3 command were utilized to look for ASCII text format from the dumped memory to understand the output result. Interestingly, the result showed that users credential are not encrypted at all. The applications analyse in this proposed research are as follows: A) Africallshop App Africallshop is a VOIP application which allows customers to buy credit online to make national and international calls and send text message worldwide to friends and family at a cheap rate. The application is 6 | P a g e rated about 4.4 in the android play store and was downloaded by five thousand (5000) customers during the time of this proposed research. The prominent outcome of this application are as follow: The username, password, caller id and user account balance are not encrypted. We ran the sqlite3 and string command on the dumped memory, which produce the result below: sip.africallshop.com XXXXXXX 0017802986780 CANADA 12590 xxxxxxxxx yes CAD proxy.africallshop.com:443 574b690276bc5 [emailprotected] 0,434 B) EHarmony App EHarmony is an online dating site for singles. Those using this app can communicate freely, share picture, video and text. During the time of this proposed research the application was downloaded by five million people and rated 3.1 in the app store. The prominent outcome of this application analysis are as follow: The user credential, such as username, password and device information are all in plaintext. The result below: POST /singles/servlet/login/mobile HTTP/1.1 j_username=sdramme1%40student.concordia.ab.caj_password=123qazplatform=androidj0r1D7fg4ArJ2uSVPgSti5zcEnltO919mHUV88E%2FKUWcan9NEMgT820MygiKsWf0Sg1147vdZbXIo tLS HTTP/1.1 User-Agent: eHarmony-Android/3.1 (SGH-I747M; Android OS 4.4.2; en_CA; id f9d8a2acfec7b901) X-eharmony-device-id: f9d8a2acfec7b901 X-eharmony-device-os: Android X-eharmony-device-os-version: 19 X-eharmony-device-type: 1 X-eharmony-client: eHarmony X-eharmony-client-version: 3.1 Accept: application/json lBxp c_te j_username=sdramme1%40student.concordia.ab.caj_password=123qazplatform=android 8KTB stevedocwra on 7 | P a g e C) Virgin Mobile My account App Virgin mobile is GSM mobile application that allow user to manage their account features and usage. Users can make payment and add a buddy to their list. This application was downloaded by five hundred thousand (500,000) people during the time of this proposed research and was rated 3.4 in the app store. The prominent outcome of this application are as follow: Sim sequence number, cell phone number, UMTS number, activation date, user data of birth, subscribe date, user e-mail address, initial password, pin unlock code and account number. all this information are not encrypted. [emailprotected]:~/android-sdk-linux/platform-tools$ strings virginmobile | grep [emailprotected] We run the ps and string command on the dumped memory, which produced the result below: imeioriginal:null,simsequenceNumber:174392323,esnequipmentType:null,imeiequipmentType:{value:LTEDevice,code:T},simequipmentType:{value:USimVal,code:U}},telephoneNumber:7802356780,networkType:{value:UMTS,code:85},language:{value:EN,code:E},isBillSixty:false,isTab:false,commitmentStartDate:null,commitmentEndDate:null,commitmentTerm:0,contractType:{value:OFF_COMMITMENT,code:O},paccPinStatus:{value:NOT_ENROLLED,code:78},padPinStatus:{value:NOT_ENROLLED,code:78},initialActivationDate:1463112000000,accountCommPref:{value:BILL_INSERTS,code:66},isAccountSMSPerm:true,birthDate:512197200000,lastUpdateDate:1464062400000,lastUpdateStamp:9863,lastHardwareUpgradeDate:null,daysSinceLastHWUpgrade:null,subscriberEstablishDate:1463112000000,daysSinceActivation:16,nextTopupDate:1465704000000,cancelledSubStatusDate:1463371200000,initialPassword:5069,isCallDisplayAllowed:false,pricePlan:VHV226,portInidicator:null,primeMateInidicator:{value:UNKNOWN,code:R},primeSubNumber:null,subMarket:{value:UAC,code:UAC },telcoId:MOBL,pinUnlockKey:[36761817,63094923],manitobaIndicator:O,thunderBayIndicator:O,portabilityIndicator:O,serviceArea:N,hasOrderInProgress:false,isWCoCSubscriber:true,hasDomesticDataServices:false,hasRoamingDataServices:false,domesticDSBlockedUntil:null,roamingDSBlockedUntil:null,isAccessible:false,promotionGroupCode:null,emailAddress:[emailprotected],wcoCDate:1463112000000}]},emailAddress:[emailprotected],arbalance:{name:{http://bside.int.bell.ca/customer/profile/types}ARBalance,declaredType:java.lang.Double,scope:ca.bell._int.bside.customer.profile.types.MobilityAccountType,value:0,nil:false,globalScope:false,typeSubstituted:false},ebillInfo:{isEBillEnrolled:true,isEBillNotifyEnabled:true,ebillStartDate:1463112000000,ebillEndDate:null},siowner:{value:BELL_MOBILITY,code:MOBL},arpuamount:19.13}]},wirelineAccounts:null,internetAccounts:null,tvaccounts:null},activeHouseholdOrders:null,emailAddress:[emailprotected]},username:7802986780,guid:SCP9O0ELLDDUN2J,profileType:BUP,savedT imeStamp:2016-05-29T01:30:38.458-04:00,profilebanNumbers:[{accountType:Legacy,ban:527566075,profileSaveTime:1463945744000}],accountType:,paymentData:[[{paymentInfoList:{billAvailable:true,lastPaymentAmount:40.18,totalAmountDue:40.18,lastPaymentDate:2016-05-22T00:00:00.000-04:00,paymentDueDate:2016-06-06T00:00:00.000-04:00,billEnddate:2016-05-14T00:00:00.000-04:00,balanceForward:0,bankAccountNumber:null,creditCardNum:null,customerId:null,ban:527566075,mdn:52756607UAV580,eligibilityInd:Y}}]]}` DISK IMAGING ANALYSIS This section provided detail steps taken to conduct traditional forensic technique for non-volatile memory acquisition and analysis. During this phase the acquired memory will be examine and the primary concern will be user data stored, in particular share_pref folder. Share_pref folder is a storage location for key-value in side application database. Android application store user data within /dev/block[8]. With the use of common forensic command, such as dd, will be utilize to image disk drive partition. For this proposed research the following partitions are imaged for analysis: System file Cache file 8 | P a g e User data Persist But our proposed research experiment will be focus on user data folder, as it is consider to be the storage location for application data. To image disk drive, shell access is need through android SDK, we then look for mount file on the disk drive before executing dd commands to copy the partition from the internal memory to internal SDcard and finally pulling it to our forensic work station using adb pull command. 1. Checking the mounted file on the disk drive mount /dev/block/platform/msm_sdcc.1/by-name/userdata /dev/block/platform/msm_sdcc.1/by-name/cache /dev/block/platform/msm_sdcc.1/by-name/system /dev/block/platform/msm_sdcc.1/by-name/persist 2. Copying the user date partition and pull it to forensic work station dd if=/dev/block/platform/msm_sdcc.1/by-name/userdata of=/mnt/sdcard/test1 17399538+0 records in 17399537+0 records out 8908562944 bytes transferred in 1934.464 secs (4605184 bytes/sec) adb pull /mnt/sdcard/test1 3. Imaging the cache partition to internal SDcard dd if=/dev/block/platform/msm_sdcc.1/by-name/cache of=/mnt/sdcard/cachefile1.img 1720320+0 records in 1720320+0 records out 880803840 bytes transferred in 118.669 secs (7422358 bytes/sec) 4. Copying the system partition dd if=/dev/block/platform/msm_sdcc.1/by-name/system of=/mnt/sdcard/systemfile.img 3072000+0 records in 3072000+0 records out 1572864000 bytes transferred in 255.874 secs (6147025 bytes/sec) [emailprotected]:/ # 5. Copying the persist partition dd if=/dev/block/platform/msm_sdcc.1/by-name/persist of=/mnt/sdcard/persist.img 16384+0 records in 16384+0 records out 8388608 bytes transferred in 0.865 secs (9697812 bytes/sec) The above command will image each partition of the mounted file of dev/block with the default block size of 512 byte during bit-by-bit copy of the file and direct the output file to internal SDcard. Finally, copy it to our forensic workstation, Which can be analysis using forensic tool called AccessData FTK imager version 3.4.2. FTK is recommended forensic tool for disk image analysis by both forensic and legal community for its powerful carving capability, stability and ease of use. AccessData FTK ANALYSIS 1. PayPal App PayPal is an online payment system that allows its member to transfer funds locally and globally. Members can receive, send money and buy or pay for goods and services online. The application was downloaded by 10 million people at the time of this research and rated as a good app in the app store. We added evidence item to 9 | P a g e FTK navigate to data and com.paypal.android.p2pmobile then share_pref folder. The folder share_pref/PresentationAccount.RememberedUsersta../ reveal user data information such as user first and last name, cell phone number, and email address. 2. AfricallShop App Africallshop is a VOIP application that allow the users to make cheap international call worldwide, user can purchase credit online to communicate with peer by text message and voice call. After adding user data partition to FTK imager, navigate to com.v2.africallshop folder, expand the folder view share_pref folder. In sher_pref folder an xml file called com.v2.africallshop-prefrences.xml was view and contain user sensitive data such as app domain name, caller ID, country, ID, user password, username and account balance all in plain text. 10 | P a g e 3. Keku App Keku is a VOIP application which facilitate call or text through Wi-Fi or mobile data. User buy credit online to make local and internationally calls. The package of the application contain probative information about the user. App database store was reveal through FTK analysis and the share_pref folder contain sensitive information about the user. In share_pref folder a file called Org.keku_preferences.xml, this file contain users sensitive data and device information such as, password, username, device-mac address and user phone number. 11 | P a g e EXPECTED RESULTS During the experimental phase of the proposed research, aim and objective of the experiment is to demonstrate or show that users personnel data information are at risk during application data process in transit and at rest. The research has observe the dumped process and disk drive imaged to reveal personal data leakage and has successfully uncover vital information about App users, such as username, password, date of birth etc. OBSTACLE The obstacles encountered during the experimental phase of the proposed research as follow: 1) Lack of enough material regarding android forensic as the field is immature 2) Unable to image the whole memory of the actual phone, as the system configuration file is missing and couldnt be found to compile it with LiMe in order to acquire the whole memory. 3) Lack of enough analysis tool to cross examine or evaluate both the dumped and disk drive memory, Ubuntu Linux tool was used to do our analysis. CONTRIBUTION TO KNOWLEDGE The proposed research show that application developers are far less careful with user sensitive data when it being stored both in the disk drive and memory in running applications. Using very simple forensic investigation techniques running strings and sqlite3 on dumped memory and disk drive imaging analysis on FTK show quite a lot of private information. OUTLINE OF FINAL RESEARCH PAPER ISSM 580/581 The final research document will be structure as follows [9]: Section 1, will be the abstract then the Introduction to the paper. Section 2, will discuss memory analysis technique. Section 3, will discuss disk imaging analysis 12 | P a g e technique. Section 4, will discusses the forensic artifacts unveil during the analysis . Section 5, related work. Section 6, the result summary. Section 7; conclusion and future work. . RESEARCH DELIVERABLES This research will be conduct in Fall Semester 2016, from September 2016 to December 2016. Nevertheless, some major preliminary steps have already being taken. Most of the required tools both hardware and software for the proposed research have already being obtained and implemented. Spring 2016 April Researching the Topic of Interest Week 1 2 Finalize the Topic with Primary Advisor Week 3 4 Read the Area/Topic of Interest May Week 1 2 Read relevant Journal or Article related to the topic of interest Week 3 4 Gathering and installation of test Environment, Conducting and Experiment. June Week 1 Writing First Draft proposal and submit Week 2 -3 Edit and Improve proposal based on advisor guidance, Further Experiment and literature review read. Week 4 Final Proposal and Submit.
Wednesday, September 4, 2019
Research Paper :: essays papers
Research Paper ââ¬Å"As a child, I loved athletics and physical activities. I was talented, but my talent was not appreciated or approved of by most. I watched my brothers compete on school teams. It didn't matter that in the neighborhood pick-up games, I was selected before my brothers. Society dictated that I should watch, and that they should compete. So at home in the backyard, I would catch as my brother worked on his curve ball, I would shag flies as he developed his batting prowess and, as I recall, I frequently served as his tackling dummy. The brother I caught and shagged for, and for whom I served as a tackling dummy, went on to Georgetown University on a full athletic grant. He later became vice president of a large banking firm. So, while I rode in the back seat on the bus of opportunity during my lifetime, I want my daughter's daughter and her peers to be able to select a seat based on their abilities and their willingness to work. Don't deny them the things that I dreamed of."-- Exce rpts of a letter sent to OCR in spring 1995 by Joan Martin, Senior Associate Director of Athletics, Monmouth University, New Jersey In April of 1993 the film The Sandlot premiered. The movie took place in 1963 when a group of 12-year-old boys spent their summer playing baseball at the local sandlot. In one particular scene in the movie, the boys got in a verbal dispute with a team of 12 year olds from the privileged side of town. The argument was over who was the more skilled baseball players. The camera switched back and forth from one kid to another as they exchanged insults. Then the camera stopped dramatically. One of the boys said the most heinous thing any young male can say to another, ââ¬Å"You play ball like a girl!â⬠It was like the other boy had just been hit with a bullet. The eyes of all the other boys involved in the argument widened and their jaws dropped. All that was heard were gasps from the rest of the kids in the movie. In 1963 that was the feeling of many people. The insult, ââ¬Å"You play ball like a girlâ⬠, was one of the biggest insults a male could ever give anyone. Ho wever, since 1972 the Title IX law has changed many peopleââ¬â¢s opinions on females in the athletic world.
Tuesday, September 3, 2019
The American Diet and Its Effects Essay -- Nutrition
The American Diet and Its Effects Today, we have many people suffering from various diseases, most of which are diet related. Basically, these complications are either as a result of increased intake of specific foods, or due to deficiency of some major nutritional components. What this means is that the health of human beings can only be assured by making sure the right foods and dietary compositions have been consumed (Swinburn & Waters, 2010). This approach can therefore make sure majority of diet-related diseases and complications will be addressed. This is because good diet is the beginning of good life. The American diet is a dietary habit that is highly associated with the high consumption of red meat, sugary desserts, foods high in fat content, as well as refined grains. A distinct characteristic of this diet is the fact that these foods are consumed as fast foods and they are characterized by ingredients that are either preheated or pre - cooked. Most of the American diet consists of products with high cholesterol levels associated with obesity and diabetes, secondly the sodium salts and sugars in the diets have negative effects on health where they progress blood pressure, heart diseases and stroke. Since our bodies factually depend on sugars, moderate glucose content is effective for normal functioning, but unlike glucose, fructose found in most American diet is metabolized differently from glucose. High Fructose levels in the liver increases uric acid which inhibits normal functions of nitric oxide cycle, a process that keeps blood vessels open or vasodilated.High sugar levels are also characterized with hyperinsulinemia and production of VLD Lipoproteins which elevates risks of heart diseases. American diet... ...case, I totally believe that obesity has become a major problem in our country (Swinburn & Waters, 2010). An obese person is at a higher risk of developing threatening health conditions such as stroke and other cardiovascular risks. Most obese children suffer from eating and sleeping disorders which interfere with the developmental stages of the child. Because of the poor diet compositions in our nation, obesity has thus remained a major problem. This calls for new approaches to deal with the situation before it gets out of hand. Works Cited Farber, L. & Blustein, J. (2007). Handbook of health care ethics. Oxford: Oxford University Press. Hills, J. (2005). Childhood obesity: prevention and treatment. Oxford: Oxford University Press. Swinburn, B. & Waters, E. (2010). Preventing childhood obesity: evidence policy and practice. New York: John Wiley and Sons.
Monday, September 2, 2019
Answer pastpaper
Answer all the questions. Give non-exact numerical answers correct to 3 significant figures, or 1 decimal place in the case of angles in degrees, unless a different level of accuracy is specified in the question. Where a numerical value for the acceleration due to gravity is needed, use 10 m s-2. The use of an electronic calculator is expected, where appropriate. You are reminded of the need for clear presentation in your answers. At the end of the examination, fasten all your work securely together. The number of marks is given in brackets [ ] at the end of each question or part question.The total number of marks for this paper is 50. Questions carrying smaller numbers of marks are printed earlier in the paper, and questions carrying larger numbers of marks later in the paper. This document consists of 3 printed pages and 1 blank page. UCLES 2011 [Turn over 2 A car of mass 700 kg is travelling along a straight horizontal road. The resistance to motion is constant and equal to 600 N. (i) Find the driving force of the car's engine at an instant when the acceleration is 2 m s-2. Given that the car's speed at this instant is 15 m s-l , car's engine is working. find the rate at which theA load of mass 1250 kg is raised by a crane from rest on horizontal ground, to rest at a height of 1. 54 m above the ground. The work done against the resistance to motion is 5750 J. (i) Find the work done by the crane. (it) Assuming the power output of the crane is constant and equal to 1. 25 kW, find the time taken to raise the load. 3 q 15. 5 N A small smooth ring R of weight 8. 5 N is threaded on a light inextensible string. The ends of the string are attached to fixed points A and B, with A vertically above B. A horizontal force of magnitude 15. 5 N acts on R so that the ring is in equilibrium with ngle ARB = 900 .The part AR of the string makes an angle B with the horizontal and the part BR makes an angle B with the vertical (see diagram). The tension in the string is T N. Sho w that T sin 12 and T cos B = 3. 5 and hence find B . [6] 4 A block of mass 11 kg is at rest on a rough plane inclined at 300 to the horizontal. A force acts on the block in a direction up the plane parallel to a line of greatest slope. When the magnitude of the force is 2X N the block is on the point of sliding down the plane, and when the magnitude of the force is 9X N the block is on the point of liding up the plane.
Sunday, September 1, 2019
Develop Productive Working Relationships with Colleagues Essay
D1. Develop productive working relationships with colleagues 4) How to identify conflicts of interest with colleagues and the measurements that can be used to manage or remove them A conflict of interest occurs when an individual or organisation is involved in multiple interests, one of which could possibly corrupt the motivation for an act in the other. An example of this between colleagues could be the staff wants to have training to gain more knowledge, but the manager wants them delivering sales therefore being on the phones so not to loose out on any business. These are two conflicts of interest, i. e. revenue the business makes vs. new learning skills the agents gain. The way to manage this is to ensure both interest of colleagues are satisfied or a compromise is allowed. For example the compromise could be that if the agents receive the learning sessions and are off the phones, that they have a shorter break to ensure the company is still getting money. This would resolve the issue and both parties would be satisfied. Assessing both sides when there are conflicts of interest is important, as it puts into perspective what affects each individual. This should be discussed possibly in a group meeting, and a solution put together to make sure everyone is happy with the final outcome. ) How to take account of diversity issues when developing working relationships with colleagues Diversity in a business means that the company has a diverse work force this can consist of a range of different cultures, men and women, people of many generations, people from ethnically and racially diverse backgrounds. A company that supports the diversity of its workforce can also improve employee satisfaction. Diversity is beneficial to both the business and the employees an d brings potential benefits such as better decision making and improved problem solving due to the different types of staff. Greater creativity and innovation, which leads to enhanced product development, and more successful marketing to different types of customers as each employee would have something different to Diverse businesses will be successful as long as there is a sufficient amount of communication within them, this is because people from different cultures perceive messages in different ways, communication is vital to the performance of the business But if there is miscommunication within a diverse workplace this will lead to a great deal of challenges, as the employees are going to be unclear on their goals/duties. When there is diversity in the business you need to make note that different people will have varied learning styles or preferred ways of management, it is good to take this into thought and find out more about the individual employee. This will ensure training and management is effective. 6) The importance of exchanging information and resources with colleagues It is vital to keep team members informed and up to date with any changes because they need to be aware of new information that may come into the business. When giving feedback it is always good to give a balance of both strengths and areas to improve on, this way it is not a negative occasions but the staff can also feel as if they are being praised for their performance at work, also known as ââ¬Å"the positive/negative sandwichâ⬠. When giving feedback you must give the team an area to improve on, this way they can stretch themselves to achieve new targets and overachieve from the previous months. Giving the colleagues feedback allows them to realise their hard work is being noticed; also any negative points can be addressed and put back on track for improvement.
Subscribe to:
Posts (Atom)