Monday, August 19, 2013

What is 3D Printing



3D printing is a lot in technology news nowadays. It’s essentially a way of constructing a 3-dimensional object by putting down thin layers of material. You can understand it best by looking at an example (see my video for the details).


Suppose you needed an object of a certain shape for a project. In the past, you'd have started with a block of material and removed the parts you don't need to arrive at the desired shape. That's "subtractive manufacturing" where you create a shape by removing material. If you think about it, you could also create that object by putting down the material a layer at a time, each layer with the needed shape. That, in essence, is 3D printing -- the method of creating a 3D object by laying down material a layer at a time. It's also called "additive manufacturing" because you add material rather than remove material. As you can see, this approach is less wasteful because you end up using exactly the amount of material you need.

3D printers are already available for people to buy and use. Here is an example -- the Makerbot Replicator -- that costs around two to three thousand dollars. The situation with 3D Printers is similar to when the PCs first became widely available in early to mid 1980s. If you are into it, you can now buy a 3D Printer and experiment with it, as many are already doing.
These printers use plastic filaments that are melted and laid down layer by layer to create a 3D object from a computer file that describes the object. The printer takes the 3D description and keeps putting down material layer by layer until the whole shape is created. You can create objects of any complexity with this approach. For example, using the old "subtractive" approach, it's quite difficult to create an object with some complex cavity inside of it, but something like that is simple to do with 3D printers.

Although most consumer 3D printers use plastic as the material, there are industrial 3D printers that can "print" objects using metals and other materials. General Electric, for example, is printing jet engine parts using 3D printers and whole cars have been printed using industrial 3D printers.



The example I used in the video showed an object created from paper and guess what, The Economist magazine had an article in its Aug 10th-016th, 2013 issue that talks about a 3D printer that creates 3D objects using paper!

That's 3D Printing in simple terms. Later I'll discuss why it's such a big deal.

Wednesday, August 14, 2013

Some defenses against Advanced Persistent Threats




Remember that Advanced Persistent Threats (APTs) take advantage of vulnerabilities in software such as the Web browser, Microsoft Office applications, or Adobe Acrobat to install malware (think of malware as bad software) -- usually a remote access tool (RAT) on your system that communicates with the attacker through command-and-control servers. As an individual, your best defense against these attacks is to make sure that you apply all available software updates. On Windows systems, you can set up automatic updates so that this happens routinely. If not, you should check manually by running Windows Update (or by looking for a "check for updates" option that's available in most software applications). The main point is that you need to make sure your system's software is up to date, so that at least the known vulnerabilities are patched up.

In addition to keeping up with software updates, you should also use some security software such as Microsoft Security Essential or any of the many commercial products. You need to deploy all currently available defenses even though it's impossible to fully defend against APTs because, in addition to known vulnerabilities, software often contains vulnerabilities that may have been discovered by the attackers, but not yet patched by the software vendor.

Additionally, you should use 2-factor authentication for sensitive transactions, including logging into social networking sites such as Google+, LinkedIn, and Facebook. For example, Google+ provides 2-factor authentication that works for logging into all services such as Gmail, Blogger, Google+, and others (see my previous video http://nbtmv.blogspot.com/2011/11/nbtmv-turn-on-2-step-verification-on.html for more information).

Organizations have more resources and can use more advanced defenses that are based on some key behavior of all APTs -- they install malware on the system, then periodically communicate to the command-control-server.

First, organizations should start with the existing defenses of firewall and usual patching and anti-virus regimen. Beyond that, there are security appliances (basically computers that inspect network traffic) available that can inspect email and web traffic to detect suspicious behavior and, potentially stop installation of malware. Third, organizations should collect event logs of various activities occurring in their systems and analyze those logs to detect any potential APT activities.

These are not perfect defenses, but they are a start. Unfortunately, it seems that APT attacks are bound to succeed, so organizations would just have to be prepared to deal with the aftermath.

As for individuals, I wish some low-cost security appliance were available to help us deal with the APT problem.

Note: There are some promising defenses based on running applications in a virtual environments where the activities of the malware could be contained before it causes damage, but this seems to be a cat-and-mouse game between the defenders and the attackers. Attackers are now designing malware that try to avoid being caught by looking for user activity such as mouse move or simply go to sleep for some time before initiating any contact with the remote command-and-control server.

Tuesday, August 13, 2013

What are Advanced Persistent Threats



Advanced Persistent Threat or APT is the latest buzzword for the newer cybersecurity attacks where some bad piece of code gets downloaded to your computer without your explicit knowledge and then it stays around to be used by a remote attacker to do whatever they want to do -- usually spread to other systems and to steal interesting information from your and your organization’s systems. Here’s how an APT typically work.



For a targeted attack, an attacker may gather information from public sources such as Facebook, Twitter, LinkedIn, etc and send you a targeted email, enticing you to open a document or perhaps click on a link. Once you do that, the malicious code embedded in the document or the web page will run (assuming your browser or the application such as Acrobat or Microsoft Word has the vulnerability that the malicious code can exploit). You won’t see anything unusual when this happens.

The malicious code would gather some basic information about your system and contact a command-and-control server to basically let the attacker know that it’s now in your system. The malicious code is usually a “remote access tool” or RAT through which the attacker can do various things on your system. Sometimes, the initial code may download the remote access tool and install it on your system in such a way that when you reboot your system, the RAT will run again. That’s how it’s “persistent.”

From this point on, the malicious remote access tool would periodically contact the command-and-control server and act on commands that it receives from the remote attacker. Some of these commands may be to scout your organization’s network and send out more emails to spread the remote access tool to other systems and also to get your data out to other servers from where the attacker can easily retrieve the information.

The existence of unknown vulnerabilities in software makes it hard to protect against such advanced persistent threat attacks, but they do have some common behavior that may help us detect and, perhaps, even stop an attack as it’s happening. More on that later.

Friday, June 8, 2012

Father of the Bride Speech at Daughter's Wedding

As the summer wedding season gets going, as the proud father of the bride, you may have to deliver a brief welcome speech at the reception. If so, here's my "father of the bride" speech for you to use as an example. This one is also an exception to the 3-minute rule for my NBTMV videos -- weighing in at almost 6 minutes, but you can't blame me for being long-winded; after all, this is my daughter's wedding and the first one at that!
Below is the speech as I had prepared it, but I spoke from memory, so the video does not match exactly, but it's always helpful to prepare (notice how short it is in print, yet it took almost 6 minutes to deliver the speech):

Good evening everyone. On behalf of my wife Leha and our family, we’d like to welcome friends and relatives of both families who are gathered here today to celebrate the marriage of Emily and Anran.
Thank you for taking time from your busy lives to join us on this evening, in some cases traveling quite a distance to be here. We hope you’ll enjoy the rest of the evening and remember this day fondly as we surely would.
I feel so proud today to be standing here as the father of the bride as she is looking beautiful with the man of her dream.
I remember as if it was only yesterday... when Emily was 4, she started to play children’s songs by ear on our piano and that’s when we decided to give her piano lessons when she turned 5.
The other thing I remember is how one day she announced that she wants to learn the violin when she was 9 and in elementary school. Despite discouragement from my wife who thinks the violin is much harder to learn than the piano, Emily’s progress was so impressive within 6 months of learning the violin that her mother was convinced that Emily would be able to play the violin after all. I remember her having violin lessons with Jody Gatwood and later taking her to Juilliard in NY city for violin lessons in her senior year. After year’s of chauffeuring to violin lessons and orchestra rehearsals, we were so happy when she got her driver’s license and could drive herself to her fellowship with the National Symphony Orchestra at the Kennedy Center. Emily is so good at everything -- from handicraft to cooking to math and science -- she got perfect score in math in both the SAT & GRE -- she could have been anything, but she chose music and the violin because she loves it.
You know, how some parents think no one is good enough for their daughter, it’s quite the opposite for us; we think Anran is great for Emily. He’s very considerate and thoughtful-- not to mention, extremely smart.

Emily and Anran have been friends since middle school and became best friends in college. With their love and friendship Emily and Anran can face anything that life may throw at them.
Traditionally, at this point, I should offer some advice on marriage, but you two have known each other and been together now for quite some time, so you don’t really need much advice on that front. The only practical advice I can think of is -- cook for the entire week during the weekend, live like you’re still a graduate student, and take vacations each year. That should see you through a long and happy married life.
Before I close, may I propose a toast to the most important couple tonight... if you’d please join me...
Ladies and Gentlemen, Emily and Anran -- here’s to a long and happy marriage!


P.S. As for father-daughter dance, we danced the "foxy" to the tune of "Rufus Wainwright-Across The Universe." Here's a video:


Tuesday, April 3, 2012

Visiting Lisbon, Portugal


We visited Lisbon, Portugal for a week in late February 2012 and enjoyed it very much. We rented an apartment and explored the city on our own. As usual, I started by buying a copy of Lisbon travel guide to figure out the layout of the city and then searched for apartments on VRBO.com near Rossio, which is one of the main areas of the city.

We found an apartment called Casa Travessa that was located a short walk up the hill near Rossio, the busy central plaza. The apartment served as a very convenient base from which to explore the great city of Lisbon. When we arrived on Saturday, we were greeted by Maria, a friend of the owners, Jordan and Deb Kleber, who happened to be away in Italy that week. Maria gave us the key and  took us on a very helpful tour of the neighborhood --  how to get down to Rossio, the restaurant street, metro station, Rossio train station, and tram stops, etc. We found a welcome basket with bread, cheese, fruits, and vinho verde (green wine) to get us started. We shopped in Pingo Doce for milk, bread etc for breakfast and light meals and the apartment served as a great base for our daily excursions. Jordan and Deb had also sent us helpful information about the neighborhood and restaurants.

Before I forget, here’s some helpful advice -- get a €5 "7 Colinas" card from the Casa da Sorte store on Rossio that's good for 24 hours of unlimited tram and metro rides (and refill it every morning, the first time, you’ll pay €0.50 extra for the card itself). If possible, go to Belém and museums on Sunday when it's free. If you plan to go to Sintra, check the days when the Pena Palace and National Palace are open.

We did all the usual sightseeing in Lisbon  -- on Sunday morning, after buying the “7 Colinas” card, we took Tram 15E to Belém to see the Belém tower, National Coach Museum, San Jeronimo monastery), had lunch at Os Jeronimos restaurant and coffee plus the famous Pasteis de Belém (called Pasteis de Nata elsewhere), and then took the metro to see the Gulbenkian musueum in the afternoon. We rode the famous Tram 28E many times from Martim Moniz park nearby all the way through Alfama and Bairro Alto. We got off the Tram 28E to see Castelo San Jorge (the castle), Miradoro St Luzia, and Sé cathedral. We also took the Elevador Gloria funicular up to Chiado, to see the city from up there and also taste port wine at Solar do Vinho do Porto.  One day we took metro to the Oriente station and visited Parque das Naciones. We spent nearly each afternoon walking the plaza in Rossio, then down Rua Augusta pedestrian street to Praca Comercio and back. We had coffee and Pasteis de Nata each afternoon. We liked the area around Rossio a lot.

We took a day trip to Sintra by train from the Rossio train station and another half-day trip by train to Cascais (from the Cais do Sodré station) to enjoy the beach. In Sintra we saw the Pena palace and walked around the city. We also had a good lunch at the GSpot Gastronomia restaurant near Sintra train station.

There are lots of good restaurants in Lisbon. We ate meals at the Bom Jardim (slowly roasted chicken with piri piri sauce) and Cafe Tighelina nearby, and took the ferry across Rio Tejo to Cacilhas for a seafood lunch at Farol restaurant (shrimp in garlic sauce, Bacalhau à Farol platter -- bacalhau is salted cod, very popular in Portugal). We also ate at a small restaurant near the Castle called Claras em Castelo that was quite good.

Monday, March 19, 2012

Cybersecurity is hard, we need some assist


Cybersecurity is so much harder than physical security! In physical security, you have a well-defined physical perimeter -- your doors, windows, gates etc -- to watch and protect, but in cybersecurity the perimeter is not well-defined. Think of cybersecurity for a typical home or business -- you usually have a box -- the “router,” perhaps a wireless one -- that lets you connect your network of PCs and other devices to the Internet via your Internet Service Provider. Although there is a single physical connection to the Internet, the software applications in your PCs and devices are making lots of network connections. If you think of each of these as a door, it’s like trying to watch over and protect thousands of doors at once and, on top of that, you need to check the packets of information that are coming in and going out of these “doors” -- like checking each visitor to a building, only the number of visitors is in the billions! To make matters worse, the software applications -- think of Web browsers, Office suite, PDF reader, etc have their own weaknesses and could serve as gateways through which bad guys get access to your information... so that’s even more “doors” to protect. Anyway, you get the idea -- compared to physical security, cybersecurity is too difficult for us to tackle in a routine manner.

Does that mean we do nothing about cybersecurity? Of course not! We already try to do our best with antivirus and firewalls etc, but to keep up with the ever-changing number and types of “doors” that we have to watch over, we need some assist from the information security companies.

First, we need a way to monitor the status of cybersecurity, similar to the way we have guards monitoring doors, fences, and gates through video cameras etc. Only in cybersecurity, someone needs to build a simple dashboard to show us how well our defenses are working against the torrent of potential malicious packets coming through the cyber “doors” to our network.

Second, someone needs to build a consumer “cybersecurity appliance” -- I envision a box that sits between that router and the rest of your network, a box that watches over all the network connections and does whatever is needed to keep our internal network safe. Come to think of it, the cybersecurity appliance can both monitor cybersecurity and provide protection.

I hope someone takes up the challenge and builds us a “cybersecurity appliance” someday soon.


Here's some more information to help you...
You may find the following books useful:




Here's an old GAO report that's still quite relevant: 

Cybersecurity for Critical Infrastructure Protection

GAO-04-321, May 28, 2004

Here's a presentation on Cybrsecurity research an development (R&D) based on this report:

Tuesday, February 28, 2012

Assessing impact of using facial recognition technology



In a previous video I talked about the importance of assessing the impact of technology before adopting it. Today I want to talk to you about the impact of increased use of facial recognition technology. You may have already heard about the use of facial recognition technology to detect the mix of male and female customers at bars. Facial recognition technology is also used to identify people on the street or in a crowd.

Facial recognition is what is known as biometrics, which is identification of people from some features of their body such as fingerprint, iris pattern, or facial characteristics. No matter what biometrics we pick, if you stop and think about it for a moment, you would realize that your fingerprint or facial image does not come with your name stamped on it. Rather, somewhere in a computer system your facial image and your name are linked together. That linkage between your name and your facial image must be correct to begin with and the information must be stored securely.
Additionally, facial recognition systems are not error-free and there is a potential for misidentification.
So, as much as facial recognition is useful, it is not error-free. Therefore, you need some protection when the facial recognition technology misidentifies you as someone else. You need some way of correcting the mistake.
There is also the potential of someone trying to fool a facial recognition system by presenting, for example, a photograph or a video of you as your face. Something has to be done to detect such misuse and not accept a photograph as substitute for a face. It’s not easy to overcome this problem because facial recognition system identifies people from photographs or videos.
This means that if you are using facial recognition technology to identify customers or perhaps suspected criminals, you have to make sure that appropriate security precautions are in place to protect the linkage between a person’s facial image and their identity information and that the information is correct in the first place. You must also provide some sort of recourse when someone is misidentified.

Here's some more information to help you...
You may find my previous videos on technology impact assessment and biometric technology helpful:


NBTMV - On the need to assess impact of technology...

NBTMV on using biometric technologies to identify ...