.

Tuesday, August 6, 2019

Various Components Of Computer Network Structure Information Technology Essay

Various Components Of Computer Network Structure Information Technology Essay What are the various components of Computer Network structure. Explain in brief. Write down the differences between connection oriented and connectionless services. Explain in brief the topologies that are used for broadcasting type of communication. Television channels are 6MHz wide. How many bits/sec. can be sent if four levels digital signals are used? Assume a noiseless channel. Which of the OSI layer handles each of the following: Breaking the transmitted bit stream into frames. Determining which route through the subnet to use. Providing compatibility in data and text. Providing terminal compatibility. Providing facility for remote login. Sketch the Manchester and Differential Manchester encoding for the following bit stream: 0111000111001101 For differential Manchester encoding assume the line is initially in the low state. UPTU 2007-08 Attempt any two parts of the following: (102=20) What do you mean by a computer network? Explain in detail various goals and applications in real life of computer networks. Give different categorization of the computer networks. What are internetworks? How you will categorize internetworks using above categories of computer networks. Give a detail description of the functionality of different layer of OSI model. UPTU 2008-09 Attempt any two parts of the following: (102=20) (i) What do you mean by network topology? Explain in brief any three such network topologies. (ii) What is difference between TCP/IP and OSI model? What are channel types in ISDN to construct the transmission structure of any access link? Explain them. Which types of transmission media are used at physical layer transmission? Give a comparative study of different transmission media in guided media. When unguided media is suitable for transmission? UPTU 2009-10 Attempt any two parts of the following: (102=20) What are the reasons for using layered protocol? A system has an n-layer protocol Hierarchy. Applications generate messages of length M bytes. At each of the layers, an h-byte header is added. What fraction of the network bandwidth is filled with headers? (i) If a binary signal is sent over a 3-kHz channel whose signal-to-noise ratio is 20 dB, what is the maximum achievable data rate? (ii) What is the percent overhead on a T1 carrier; that is, what percent of the 1.544 Mbps are not delivered to the end user? Explain the advantages and disadvantages if any of the following topologies: (i) star (ii) ring (iii) bus (iv) mesh UNIT II UPTU 2006-07 Attempt any four parts of the following: (54=20) Suppose that the string 0101 is used as the bit string to indicate the end of a frame and the bit stuffing rule is to insert a 0 after each appearance of 010 in the original data; thus 010101 would be modified by stuffing to 01001001. In addition, if the frame proper ends in 01, 0 would be stuffed after the first 0 in the actual terminating string 0101. Show how the following would be modified by this rule? 11011010010101011101 Measurements of an infinite user slotted ALOHA channel show that 10% of the slots are idle: (i) What is the channel load, G? (ii) What is throughput? (iii) Is the channel underloaded or overloaded? Consider an error free 64-Kbps satellite channel used to send 512 byte data frames in one direction, with very short acknowledgement coming back the other way. What is the maximum throughput for window sizes of 01 and 07? A bit stream 10011101 is transmitted used the standard CRC method. The generator polynomial is x3 + 1. Show the actual bit string transmitted. Suppose the third bit from the left is inverted during transmission. Show that this error is detected at the receivers end. Explain Basic-Bit-Map (a collision free protocol) used at MAC sublayer. Sixteen stations, numbered 1 through 16, are contending for the use a shared channel by using the adaptive Free Walk Protocol. If all the station whose addresses are prime number suddenly becomes ready at once, how many bit slots are needed to resolve the contention? UPTU 2007-08 Attempt any two parts of the following: (102=20) What is Hamming code? For the following word pattern (message) find out the number of check bit and the bit at eleventh position. If any error is detected, show it. M = 1111 1010 0000 1110 What are medium access control (MAC) protocols? Discuss salient feature of CSMA/CD protocol. Describe the bit stuffing rule used the HDLC protocol. Consider a CSMA/CD network running at 200 Mbps over a 1 Km cable with no repeaters. The signal speed is 2 * 108 m/sec. Compute the minimum frame size. UPTU 2008-09 Attempt any two parts of the following: (102=20) What do you mean by ALOHA? How does slotted ALOHA improve efficiency? SEC(7,4) hamming code can be converted into a double error detecting and single error correcting code (8,4) by using an extra parity check. Construct the generator matrix for the code and show that the code is quasi perfect. Design a decoder for the code. Explain the IEEE 802.3 MAC sublayer frame format. What is the binary exponential back off algorithm? UPTU 2009-10 Attempt any two parts of the following: (102=20) A large population of ALOHA users manage to generate 50 requests/sec, including both originals and retransmissions. Time is slotted in units of 40 msec. What is the chance of success on the first attempt? What is the probability of exactly k collisions and then a success? Explain the working of CSMA/CD protocol. Why there is a minimum frame length restriction in CSMA/CD? Explain the working of GO-BACK N ARQ protocol. How it is different from selective repeat ARQ? UNIT III UPTU 2006-07 Attempt any two parts of the following: (102=20) Write and explain the kinds of shortest path routing Algorithm in brief. Find the shortest path in the following subnet using Dijsktra Algorithm, when the source is fixed but destination is not fixed. Describe the choke-packet method of congestion control. You are also required to explain the variation in the above mentioned algorithm. Explain the concept of Tunnelling in Internetworking. Write down the difference in IPv4 and IPv6. UPTU 2007-08 Attempt any two parts of the following: (102=20) Answer the following question: How is IPv6 different from IP protocol? Convert IP address whose hexadecimal representation is C22F1582 to dotted decimal notation. A class B class network on the internet has a subnet mask of 255.255.240.0. What is the maximum number of hosts per subnet? Explain the purpose of subnetting. What is Link Control Protocol? Give the format of LCP packet. Also how authentication is supported in PPP? Explain. (i) A computer on a 6-Mbps network is regulated by a token bucket. The token bucket is filled at a rate of 1 Mbps. It is initially filled to a capacity with 8 megabit. How long can the computer transmit at the full 6 Mbps? (ii) Discuss the token passing technique used in FDDI. UPTU 2008-09 Attempt any two parts of the following: (102=20) What is the congestion in network layer? Differentiate and explain Leaky-Bucket algorithm and Token Bucket algorithm? What is the role of routing algorithm? Explain the working of Distance Vector Routing algorithm with the help of a suitable example. (i) Explain various phases through which a PPP connection goes using transition state diagram. (ii) What is the significance of IP address classification? What problems of IPv4 are being addressed by IPv6? UPTU 2009-10 Attempt any two parts of the following: (102=20) A computer on a 6-Mbps network is regulated by a token bucket. The token bucket is filled at a rate of 1 Mbps. It is initially filled to capacity with 8 megabits. How long can the computer transmit at the full 6 Mbps? Give a classification of IP addresses used in the Internet. Suppose that instead of using 16 bits for the network part of a class B address originally, 20 bits had been used. How many class B networks would there have been? (i) The protocol field used in the IPv4 header is not present in the fived IPv6 header. Write your justification. (ii) IPv6 uses 16-byte addresses. If a block of 1 million addresses is allocated every picosecond, how long will the addresses last? UNIT IV UPTU 2006-07 Attempt any two parts of the following: (102=20) Describe Transmission Control Protocols (TCP) Transmission policy. Explain the Remote Procedure Call with suitable diagram. You are also required to explain the use of RPC in Transport layer. Imagine that a two-way handshake rather than a three-way handshake were used to set up connections. Are deadlocks now possible? Give an example or how what none exist. UPTU 2007-08 Attempt any two parts of the following: (102=20) Why does UDP exist? Would it not have been enough to just let user processes send raw IP packets? What are two army problem and a three way handshake? State the elements of transport protocol. Describe the feature of the following devices: Routers Bridges Gateway UPTU 2008-09 Attempt any two parts of the following: (102=20) A TCP connection is using a window size of 1000 B and the previous acknowledgement no was 22,001. It receives a segment with acknowledgement no 24,001. Draw a diagram to show the situation of the window after and before the acknowledgement is received. If the window size is change to 11000B and 9000B separately, than what will be the situation? Discuss the issue to be considered in designing different layers. (i) What is user datagram protocol? Give its datagram format. (ii) Would it not have been enough to just let user processes send raw IP packets? Give reason in support to your answer. UPTU 2009-10 Attempt any two parts of the following: (102=20) Draw the TCP header format and explain its various fields. A TCP machine is sending full windows of 65,535 bytes over a 1-Gbps channel that has a 10-msec one way delay. What is the maximum throughput achievable? What is the line capacity? Explain Connection Management at the transport layer in detail. UNIT V UPTU 2006-07 Attempt any two parts of the following: (102=20) Explain the architecture of Electronic Mail (i.e. E-mail). Describe the concept of Domain name System in brief. Explain the working of server side in the architectural overview of World-Wide-Web (WWW). UPTU 2007-08 Attempt any two parts of the following: (102=20) One secret key encryption method involves the permutation of bits. For example an 8 bit plain text is permuted, bit 8 becomes bit 3, bit 1 becomes bit 2 and so on. Draw a diagram to show the mapping of each bit to its new designation. Scramble the bits as you please. What is encryption and decryption algorithm? What do you mean by following : HTTP SNMP How MPEG file format is different from JPEG file format? Encode the following message using Huffman coding: INDIAN INNING Write short note on one of the following : Network security and cryptography Electronic mail and FTP. UPTU 2008-09 Attempt any two parts of the following: (102=20) One secret key encryption method involves the XOR operation. A bit patter (plaintext) of a fixed size in XORed with a block of bits of the same size to create to fixed sized cipher text. What is the encryption algorithm here? What is the decryption algorithm here? Remember that an XOR algorithm is a reversible algorithm. (i) Why do we need Domain name space when we can directly use an IP address? (ii) What is trivial file transfer protocol? How it is different from simple FTP? (i) What is the role of digital signature in cryptography? (ii) What is JPEG standard? How it is different from JPEG 2000? UPTU 2009-10 Attempt any four parts of the following: (54=20) Can a query message in DNS have one question section but the corresponding response message have several answer sections? Describe the addressing system used by SMTP. Describe the functions of the two FTP connection. What is anonymous FTP? Compare the way SMTP and HTTP transfer images. Which one do you think is more efficient? Why? The Diffie-Hellman key exchange is being used to establish a secret key between Alice and Bob. Alice sends Bob (719, 3, 191). Bob responds with (543). Alices secret number, x, is 16. What is the secret key? Can IPsec using AH be used in transport mode if one of the machines is behind a NAT box? Explain your answer.

Monday, August 5, 2019

Technology for Network Security

Technology for Network Security 2.0 CHAPTER TWO 2.1 INTRODUCTION The ever increasing need for information technology as a result of globalisation has brought about the need for an application of a better network security system. It is without a doubt that the rate at which computer networks are expanding in this modern time to accommodate higher bandwidth, unique storage demand, and increase number of users can not be over emphasised. As this demand grows on daily bases, so also, are the threats associated with it. Some of which are, virus attacks, worm attacks, denial of services or distributed denial of service attack etc. Having this in mind then call for swift security measures to address these threats in order to protect data reliability, integrity, availability and other needed network resources across the network. Generally, network security can simply be described as a way of protecting the integrity of a network by making sure authorised access or threats of any form are restricted from accessing valuable information. As network architecture begins to expand, tackling the issue of security is becomes more and more complex to handle, therefore keeping network administrators on their toes to guard against any possible attacks that occurs on daily basis. Some of the malicious attacks are viruses and worm attacks, denial of service attacks, IP spoofing, cracking password, Domain Name Server (DNS) poisoning etc. As an effort to combat these threats, many security elements have been designed to tackle these attacks on the network. Some of which includes, firewall, Virtual Private Network (VPN), Encryption and Decryption, Cryptography, Internet Protocol Security (IPSec), Data Encryption Standard (3DES), Demilitarised Zone, (DMZ), Secure Shell Layer (SSL) etc. This chapter starts by briefly discussi ng Internet Protocol (IP), Transmission Control Protocol (TCP), User datagram Protocol (UDP), Internet Control Message Protocol (ICMP), then discussed the Open system interconnection (OSI) model and the protocols that operate at each layer of the model, network security elements, followed by the background of firewall, types and features of firewalls and lastly, network security tools. 2.2 A BRIEF DESCRIPTION OF TCP, IP, UDP AND ICMP 2.2.1 DEFINITION Going by the tremendous achievement of the World Wide Web (internet), a global communication standard with the aim of building interconnection of networks over heterogeneous network is known as the TCP/IP protocol suite was designed (Dunkels 2003; Global Knowledge 2007; Parziale et al 2006). The TCP/IP protocol suite is the core rule used for applications transfer such as File transfers, E-Mail traffics, web pages transfer between hosts across the heterogeneous networks (Dunkels 2003; Parziale et al 2006). Therefore, it becomes necessary for a network administrator to have a good understanding of TCP/IP when configuring firewalls, as most of the policies are set to protect the internal network from possible attacks that uses the TCP/IP protocols for communication (Noonan and Dobrawsky 2006). Many incidents of network attacks are as a result of improper configuration and poor implementation TCP/IP protocols, services and applications. TCP/IP make use of protocols such as TCP, UDP, IP, ICMP etc to define rules of how communication over the network takes place (Noonan and Dobrawsky 2006). Before these protocols are discussed, this thesis briefly looks into the theoretical Open Systems Interconnection (OSI) model (Simoneau 2006). 2.2.2 THE OSI MODEL The OSI model is a standardised layered model defined by International Organization for Standardization (ISO) for network communication which simplifies network communication to seven separate layers, with each individual layer having it own unique functions that support immediate layer above it and at same time offering services to its immediate layer below it (Parziale et al 2006; Simoneau 2006). The seven layers are Application, Presentation, Session Transport, Network, Data, Link and Physical layer. The first three lower layers (Network, Data, Link and Physical layer) are basically hardware implementations while the last four upper layers (Application, Presentation, Session and Transport) are software implementations. Application Layer This is the end user operating interface that support file transfer, web browsing, electronic mail etc. This layer allows user interaction with the system. Presentation Layer This layer is responsible for formatting the data to be sent across the network which enables the application to understand the message been sent and in addition it is responsible for message encryption and decryption for security purposes. Session Layer This layer is responsible for dialog and session control functions between systems. Transport layer This layer provides end-to-end communication which could be reliable or unreliable between end devices across the network. The two mostly used protocols in this layer are TCP and UDP. Network Layer This layer is also known as logical layer and is responsible for logical addressing for packet delivery services. The protocol used in this layer is the IP. Data Link Layer This layer is responsible for framing of units of information, error checking and physical addressing. Physical Layer This layer defines transmission medium requirements, connectors and responsible for the transmission of bits on the physical hardware (Parziale et al 2006; Simoneau 2006). 2.2.3 INTERNET PROTOCOL (IP) IP is a connectionless protocol designed to deliver data hosts across the network. IP data delivery is unreliable therefore depend on upper layer protocol such as TCP or lower layer protocols like IEEE 802.2 and IEEE802.3 for reliable data delivery between hosts on the network.(Noonan and Dobrawsky 2006) 2.2.4 TRANSMISSION CONTROL PROTOCOL (TCP) TCP is a standard protocol which is connection-oriented transport mechanism that operates at the transport layer of OSI model. It is described by the Request for Comment (RFC) 793. TCP solves the unreliability problem of the network layer protocol (IP) by making sure packets are reliably and accurately transmitted, errors are recovered and efficiently monitors flow control between hosts across the network. (Abie 2000; Noonan and Dobrawsky 2006; Simoneau 2006). The primary objective of TCP is to create session between hosts on the network and this process is carried out by what is called TCP three-way handshake. When using TCP for data transmission between hosts, the sending host will first of all send a synchronise (SYN) segment to the receiving host which is first step in the handshake. The receiving host on receiving the SYN segment reply with an acknowledgement (ACK) and with its own SYN segment and this form the second part of the handshake. The final step of the handshake is the n completed by the sending host responding with its own ACK segment to acknowledge the acceptance of the SYN/ACK. Once this process is completed, the hosts then established a virtual circuit between themselves through which the data will be transferred (Noonan and Dobrawsky 2006). As good as the three ways handshake of the TCP is, it also has its short comings. The most common one being the SYN flood attack. This form of attack occurs when the destination host such as the Server is flooded with a SYN session request without receiving any ACK reply from the source host (malicious host) that initiated a SYN session. The result of this action causes DOS attack as destination host buffer will get to a point it can no longer take any request from legitimate hosts but have no other choice than to drop such session request (Noonan and Dobrawsky 2006). 2.2.5 USER DATAGRAM PROTOCOL (UDP) UDP unlike the TCP is a standard connectionless transport mechanism that operates at the transport layer of OSI model. It is described by the Request for Comment (RFC) 768 (Noonan and Dobrawsky 2006; Simoneau 2006). When using UDP to transfer packets between hosts, session initiation, retransmission of lost or damaged packets and acknowledgement are omitted therefore, 100 percent packet delivery is not guaranteed (Sundararajan et al 2006; Postel 1980). UDP is designed with low over head as it does not involve initiation of session between hosts before data transmission starts. This protocol is best suite for small data transmission (Noonan and Dobrawsky 2006). 2.2.6 INTERNET CONTROL MESSAGE PROTOCOL (ICMP). ICMP is primarily designed to identify and report routing error, delivery failures and delays on the network. This protocol can only be used to report errors and can not be used to make any correction on the identified errors but depend on routing protocols or reliable protocols like the TCP to handle the error detected (Noonan and Dobrawsky 2006; Dunkels 2003). ICMP makes use of the echo mechanism called Ping command. This command is used to check if the host is replying to network traffic or not (Noonan and Dobrawsky 2006; Dunkels 2003). 2.3 OTHER NETWORK SECURITY ELEMENTS. 2.3.1 VIRTUAL PRIVATE NETWORK (VPN) VPN is one of the network security elements that make use of the public network infrastructure to securely maintain confidentiality of information transfer between hosts over the public network (Bou 2007). VPN provides this security features by making use of encryption and Tunneling technique to protect such information and it can be configured to support at least three models which are Remote- access connection. Site-to-site ( branch offices to the headquarters) Local area network internetworking (Extranet connection of companies with their business partners) (Bou 2007). 2.3.2 VPN TECHNOLOGY VPN make use of many standard protocols to implement the data authentication (identification of trusted parties) and encryption (scrambling of data) when making use of the public network to transfer data. These protocols include: Point-to-Point Tunneling Protocol PPTP [RFC2637] Secure Shell Layer Protocol (SSL) [RFC 2246] Internet Protocol Security (IPSec) [RFC 2401] Layer 2 Tunneling Protocol (L2TP) [RFC2661] 2.3.2.1 POINT-TO-POINT TUNNELING PROTOCOL [PPTP] The design of PPTP provides a secure means of transferring data over the public infrastructure with authentication and encryption support between hosts on the network. This protocol operates at the data link layer of the OSI model and it basically relies on user identification (ID) and password authentication for its security. PPTP did not eliminate Point-to-Point Protocol, but rather describes better way of Tunneling PPP traffic by using Generic Routing Encapsulation (GRE) (Bou 2007; Microsoft 1999; Schneier and Mudge 1998). 2.3.2.2 LAYER 2 TUNNELING PROTOCOL [L2TP] The L2TP is a connection-oriented protocol standard defined by the RFC 2661which merged the best features of PPTP and Layer 2 forwarding (L2F) protocol to create the new standard (L2TP) (Bou 2007; Townsley et al 1999). Just like the PPTP, the L2TP operates at the layer 2 of the OSI model. Tunneling in L2TP is achieved through series of data encapsulation of the different levels layer protocols. Examples are UDP, IPSec, IP, and Data-Link layer protocol but the data encryption for the tunnel is provided by the IPSec (Bou 2007; Townsley et al 1999). 2.3.2.3 INTERNET PROTOCOL SECURITY (IPSEC) [RFC 2401] IPSec is a standard protocol defined by the RFC 2401 which is designed to protect the payload of an IP packet and the paths between hosts, security gateways (routers and firewalls), or between security gateway and host over the unprotected network (Bou 2007; Kent and Atkinson 1998). IPSec operate at network layer of the OSI model. Some of the security services it provides are, authentication, connectionless integrity, encryption, access control, data origin, rejection of replayed packets, etc (Kent and Atkinson 1998). 2.3.3.4 SECURE SOCKET LAYER (SSL) [RFC 2246] SSL is a standard protocol defined by the RFC 2246 which is designed to provide secure communication tunnel between hosts by encrypting hosts communication over the network, to ensure packets confidentiality, integrity and proper hosts authentication, in order to eliminate eavesdropping attacks on the network (Homin et al 2007; Oppliger et al 2008). SSL makes use of security elements such as digital certificate, cryptography and certificates to enforce security measures over the network. SSL is a transport layer security protocol that runs on top of the TCP/IP which manage transport and routing of packets across the network. Also SSL is deployed at the application layer OSI model to ensure hosts authentication (Homin et al 2007; Oppliger et al 2008; Dierks and Allen 1999). 2.4 FIREWALL BACKGROUND The concept of network firewall is to prevent unauthorised packets from gaining entry into a network by filtering all packets that are coming into such network. The word firewall was not originally a computer security vocabulary, but was initially used to illustrate a wall which could be brick or mortar built to restrain fire from spreading from one part of a building to the other or to reduce the spread of the fire in the building giving some time for remedial actions to be taken (Komar et al 2003). 2.4.1BRIEF HISTORY OF FIREWALL Firewall as used in computing is dated as far back as the late 1980s, but the first set of firewalls came into light sometime in 1985, which was produced by a Ciscos Internet work Operating System (IOS) division called packet filter firewall (Cisco System 2004). In 1988, Jeff Mogul from DEC (Digital Equipment Corporation) published the first paper on firewall. Between 1989 and 1990, two workers of the ATT Bell laboratories Howard Trickey and Dave Persotto initiated the second generation firewall technology with their study in circuit relays called Circuit level firewall. Also, the two scientists implemented the first working model of the third generation firewall design called Application layer firewalls. Sadly enough, there was no published documents explaining their work and no product was released to support their work. Around the same year (1990-1991), different papers on the third generation firewalls were published by researchers. But among them, Marcus Ranums work received the most attention in 1991 and took the form of bastion hosts running proxy services. Ranums work quickly evolved into the first commercial product—Digital Equipment Corporations SEAL product (Cisco System 2004). About the same year, work started on the fourth generation firewall called Dynamic packet filtering and was not operational until 1994 when Check Point Software rolled out a complete working model of the fourth generation firewall architecture. In 1996, plans began on the fifth generation firewall design called the Kernel Proxy architecture and became reality in 1997 when Cisco released the Cisco Centri Firewall which was the first Proxy firewall produced for commercial use (Cisco System 2004). Since then many vendor have designed and implemented various forms of firewall both in hardware and software and till date, research works is on going in improving firewalls architecture to meet up with ever increasing challenges of network security. 2.5 DEFINITION According to the British computer society (2008), Firewalls are defence mechanisms that can be implemented in either hardware or software, and serve to prevent unauthorized access to computers and networks. Similarly, Subrata, et al (2006) defined firewall as a combination of hardware and software used to implement a security policy governing the flow of network traffic between two or more networks. The concept of firewall in computer systems security is similar to firewall built within a building but differ in their functions. While the latter is purposely designed for only one task which is fire prevention in a building, computer system firewall is designed to prevent more than one threat (Komar et al 2003).This includes the following Denial Of Service Attacks (DoS) Virus attacks Worm attack. Hacking attacks etc 2.5.1 DENIAL OF SERVICE ATTACKS (DOS) â€Å"Countering DoS attacks on web servers has become a very challenging problem† (Srivatsa et al 2006). This is an attack that is aimed at denying legitimate packets to access network resources. The attacker achieved this by running a program that floods the network, making network resources such as main memory, network bandwidth, hard disk space, unavailable for legitimate packets. SYN attack is a good example of DOS attacks, but can be prevented by implementing good firewall polices for the secured network. A detailed firewall policy (iptables) is presented in chapter three of this thesis. 2.5.2 VIRUS AND WORM ATTACKS Viruses and worms attacks are big security problem which can become pandemic in a twinkle of an eye resulting to possible huge loss of information or system damage (Ford et al 2005; Cisco System 2004). These two forms of attacks can be programs designed to open up systems to allow information theft or programs that regenerate themselves once they gets into the system until they crashes the system and some could be programmed to generate programs that floods the network leading to DOS attacks. Therefore, security tools that can proactively detect possible attacks are required to secure the network. One of such tools is a firewall with good security policy configuration (Cisco System 2004). Generally speaking, any kind of firewall implementation will basically perform the following task. Manage and control network traffic. Authenticate access Act as an intermediary Make internal recourses available Record and report event 2.5.3 MANAGE AND CONTROL NETWORK TRAFFIC. The first process undertaken by firewalls is to secure a computer networks by checking all the traffic coming into and leaving the networks. This is achieved by stopping and analysing packet Source IP address, Source port, Destination IP address, Destination port, IP protocol Packet header information etc. in order decide on what action to take on such packets either to accept or reject the packet. This action is called packet filtering and it depends on the firewall configuration. Likewise the firewall can also make use of the connections between TCP/IP hosts to establish communication between them for identification and to state the way they will communicate with each other to decide which connection should be permitted or discarded. This is achieved by maintaining the state table used to check the state of all the packets passing through the firewall. This is called stateful inspection (Noonan and Dobrawsky 2006). 2.5.4 AUTHENTICATE ACCESS When firewalls inspects and analyses packets Source IP address, Source port, Destination IP address, Destination port, IP protocol Packet header information etc, and probably filters it based on the specified security procedure defined, it does not guarantee that the communication between the source host and destination host will be authorised in that, hackers can manage to spoof IP address and port action which defeats the inspection and analysis based on IP and port screening. To tackle this pit fall over the network, an authentication rule is implemented in firewall using a number of means such as, the use of username and password (xauth), certificate and public keys and pre-shared keys (PSKs).In using the xauth authentication method, the firewall will request for the source host that is trying to initiate a connection with the host on the protected network for its username and password before it will allow connection between the protected network and the source host to be establi shed. Once the connection is been confirmed and authorised by the security procedure defined, the source host need not to authenticate itself to make connection again (Noonan and Dobrawsky 2006). The second method is using certificates and public keys. The advantage of this method over xauth is that verification can take place without source host intervention having to supply its username and password for authentication. Implementation of Certificates and public keys requires proper hosts (protected network and the source host) configuration with certificates and firewall and making sure that protected network and the source host use a public key infrastructure that is properly configured. This security method is best for big network design (Noonan and Dobrawsky 2006). Another good way of dealing with authentication issues with firewalls is by using pre-shared keys (PSKs). The implementation of PSKs is easy compare to the certificates and public keys although, authentication still occur without the source host intervention its make use of an additional feature which is providing the host with a predetermined key that is used for the verification procedure (Noonan and Dobrawsky 2006). 2.5.5 ACT AS AN INTERMEDIARY When firewalls are configured to serve as an intermediary between a protected host and external host, they simply function as application proxy. The firewalls in this setup are configured to impersonate the protected host such that all packets destined for the protected host from the external host are delivered to the firewall which appears to the external host as the protected host. Once the firewalls receive the packets, they inspect the packet to determine if the packet is valid (e.g. genuine HTTT packet) or not before forwarding to the protected host. This firewall design totally blocks direct communication between the hosts. 2.5.6 RECORD AND REPORT EVENTS While it is good practise to put strong security policies in place to secure network, it is equally important to record firewalls events. Using firewalls to record and report events is a technique that can help to investigate what kind of attack took place in situations where firewalls are unable to stop malicious packets that violate the access control policy of the protected network. Recording this event gives the network administrator a clear understanding of the attack and at the same time, to make use of the recorded events to troubleshoot the problem that as taken place. To record these events, network administrators makes use of different methods but syslog or proprietary logging format are mostly used for firewalls. However, some malicious events need to be reported quickly so that immediate action can be taken before serious damage is done to the protected network. Therefore firewalls also need an alarming mechanism in addition to the syslog or proprietary logging format whe n ever access control policy of the protected network is violated. Some types of alarm supported by firewalls include Console notification, Simple Network Management Protocol (SNMP), Paging notification, E-mail notification etc (Noonan and Dobrawsky 2006). Console notification is a warning massage that is presented to the firewall console. The problem with this method of alarm is that, the console needs to be monitored by the network administrator at all times so that necessary action can be taken when an alarm is generated. Simple Network Management Protocol (SNMP) notification is implemented to create traps which are transferred to the network management system (NMS) monitoring the firewall. Paging notification is setup on the firewall to deliver a page to the network administrator whenever the firewall encounters any event. The message could be an alphanumeric or numeric depending on how the firewall is setup. E-mail notification is similar to paging notification, but in this case, the firewall send an email instead to proper address. 2.6 TYPES OF FIREWALLS Going by firewall definition, firewalls are expected to perform some key functions like, Application Proxy, Network Translation Address, and Packet filtering. 2.6.1 APPLICATION PROXY This is also known as Application Gateway, and it acts as a connection agent between protected network and the external network. Basically, the application proxy is a host on the protected network that is setup as proxy server. Just as the name implies, application proxy function at the application layer of the Open System Interconnection (OSI) model and makes sure that all application requests from the secured network is communicated to the external network through the proxy server and no packets passes through from to external network to the secured network until the proxy checks and confirms inbound packets. This firewall support different types of protocols such as a Hypertext Transfer Protocol (HTTP), File Transfer Protocol (FTP) and Simple Mail Transport Protocol (SMTP) (Noonan and Dobrawsky 2006; NetContinuum 2006). 2.6.2 NETWORK ADDRESS (NAT) NAT alter the IP addresses of hosts packets by hiding the genuine IP addresses of secured network hosts and dynamically replacing them with a different IP addresses (Cisco System 2008; Walberg 2007). When request packets are sent from the secured host through the gateway to an external host, the source host address is modified to a different IP address by NAT.  When the reply packets arrives at the gateway, the NAT then replaces the modified address with genuine host address before forwarding it to the host (Walberg 2007).The role played by NAT in a secured network system makes it uneasy for unauthorized access to know: The number of hosts available in the protected network The topology of the network The operating systems the host is running The type of host machine (Cisco System 2008). 2.6.3 PACKET FILTERING. â€Å"Firewalls and IPSec gateways have become major components in the current high speed Internet infrastructure to filter out undesired traffic and protect the integrity and confidentiality of critical traffic† (Hamed and Al-Shaer 2006). Packet filtering is based on the lay down security rule defined for any network or system. Filtering traffic over the network is big task that involves comprehensive understanding of the network on which it will be setup. This defined policy must always be updated in order to handle the possible network attacks (Hamed and Al-Shaer 2006). 2.6.4 INSTRUCTION DETECTION SYSTEMS. Network penetration attacks are now on the increase as valuable information is being stolen or damaged by the attacker. Many security products have been developed to combat these attacks. Two of such products are Intrusion Prevention systems (IPS) and Intrusion Detection Systems (IDS). IDS are software designed to purposely monitor and analysed all the activities (network traffic) on the network for any suspicious threats that may violate the defined network security policies (Scarfone and Mell 2007; Vignam et al 2003). There are varieties of methods IDS uses to detect threats on the network, two of them are, anomaly based IDS, and signature based IDS. 2.6.4.1 ANOMALY BASED IDS Anomaly based IDS is setup to monitor and compare network events against what is defined to be normal network activities which is represented by a profile, in order to detect any deviation from the defined normal events. Some of the events are, comparing the type of bandwidth used, the type of protocols etc and once the IDS identifies any deviation in any of this events, it notifies the network administrator who then take necessary action to stop the intended attack (Scarfone and Mell 2007). 2.6.4.2 SIGNATURE BASED IDS Signature based IDS are designed to monitor and compare packets on the network against the signature database of known malicious attacks or threats. This type of IDS is efficient at identifying already known threats but ineffective at identifying new threats which are not currently defined in the signature database, therefore giving way to network attacks (Scarfone and Mell 2007). 2.6.5 INTRUSION PREVENTION SYSTEMS (IPS). IPS are proactive security products which can be software or hardware used to identify malicious packets and also to prevent such packets from gaining entry in the networks (Ierace et al 2005, Botwicz et al 2006). IPS is another form of firewall which is basically designed to detect irregularity in regular network traffic and likewise to stop possible network attacks such as Denial of service attacks. They are capable of dropping malicious packets and disconnecting any connection suspected to be illegal before such traffic get to the protected host. Just like a typical firewall, IPS makes use of define rules in the system setup to determine the action to take on any traffic and this could be to allow or block the traffic. IPS makes use of stateful packet analysis to protect the network. Similarly, IPS is capable of performing signature matching, application protocol validation etc as a means of detecting attacks on the network (Ierace et al 2005). As good as IPS are, they also have t heir downsides as well. One of it is the problem of false positive and false negative. False positive is a situation where legitimate traffic is been identified to be malicious and thereby resulting to the IPS blocking such traffic on the network. False negative on the other hand is when malicious traffic is be identified by the IPS as legitimate traffic thereby allowing such traffic to pass through the IPS to the protected network (Ierace N et al 2005). 2.7 SOFTWARE AND HARDWARE FIREWALLS 2.7.1 SOFTWARE FIREWALLS Software-based firewalls are computers installed software for filtering packets (Permpootanalarp and Rujimethabhas 2001). These are programs setup either on personal computers or on network servers (Web servers and Email severs) operating system. Once the software is installed and proper security polices are defined, the systems (personal computers or servers) assume the role of a firewall. Software firewalls are second line of defence after hardware firewalls in situations where both are used for network security. Also software firewalls can be installed on different operating system such as, Windows Operating Systems, Mac operating system, Novel Netware, Linux Kernel, and UNIX Kernel etc. The function of these firewalls is, filtering distorted network traffic. There are several software firewall some of which include, Online Armor firewall, McAfee Personal Firewall, Zone Alarm, Norton Personal Firewall, Black Ice Defender, Sygate Personal Firewall, Panda Firewall, The DoorStop X Fi rewall etc (Lugo Parker 2005). When designing a software firewall two keys things are considered. These are, per-packet filtering and a per-process filtering. The pre-packet filter is design to search for distorted packets, port scan detection and checking if the packets are accepted into the protocol stack. In the same vein, pre-process filter is the designed to check if a process is allowed to begin a connection to the secured network or not (Lugo and Parker 2005). It should be noted that there are different implantations of all Firewalls. While some are built into the operating system others are add-ons. Examples of built-in firewalls are windows based firewall and Linux based. 2.7.2 WINDOWS OPERATING SYSTEM BASED FIREWALL. In operating system design, security features is one important aspect that is greatly considered. This is a challenge the software giant (Microsoft) as always made sure they implement is their products. In the software industry, Mi Technology for Network Security Technology for Network Security 2.0 CHAPTER TWO 2.1 INTRODUCTION The ever increasing need for information technology as a result of globalisation has brought about the need for an application of a better network security system. It is without a doubt that the rate at which computer networks are expanding in this modern time to accommodate higher bandwidth, unique storage demand, and increase number of users can not be over emphasised. As this demand grows on daily bases, so also, are the threats associated with it. Some of which are, virus attacks, worm attacks, denial of services or distributed denial of service attack etc. Having this in mind then call for swift security measures to address these threats in order to protect data reliability, integrity, availability and other needed network resources across the network. Generally, network security can simply be described as a way of protecting the integrity of a network by making sure authorised access or threats of any form are restricted from accessing valuable information. As network architecture begins to expand, tackling the issue of security is becomes more and more complex to handle, therefore keeping network administrators on their toes to guard against any possible attacks that occurs on daily basis. Some of the malicious attacks are viruses and worm attacks, denial of service attacks, IP spoofing, cracking password, Domain Name Server (DNS) poisoning etc. As an effort to combat these threats, many security elements have been designed to tackle these attacks on the network. Some of which includes, firewall, Virtual Private Network (VPN), Encryption and Decryption, Cryptography, Internet Protocol Security (IPSec), Data Encryption Standard (3DES), Demilitarised Zone, (DMZ), Secure Shell Layer (SSL) etc. This chapter starts by briefly discussi ng Internet Protocol (IP), Transmission Control Protocol (TCP), User datagram Protocol (UDP), Internet Control Message Protocol (ICMP), then discussed the Open system interconnection (OSI) model and the protocols that operate at each layer of the model, network security elements, followed by the background of firewall, types and features of firewalls and lastly, network security tools. 2.2 A BRIEF DESCRIPTION OF TCP, IP, UDP AND ICMP 2.2.1 DEFINITION Going by the tremendous achievement of the World Wide Web (internet), a global communication standard with the aim of building interconnection of networks over heterogeneous network is known as the TCP/IP protocol suite was designed (Dunkels 2003; Global Knowledge 2007; Parziale et al 2006). The TCP/IP protocol suite is the core rule used for applications transfer such as File transfers, E-Mail traffics, web pages transfer between hosts across the heterogeneous networks (Dunkels 2003; Parziale et al 2006). Therefore, it becomes necessary for a network administrator to have a good understanding of TCP/IP when configuring firewalls, as most of the policies are set to protect the internal network from possible attacks that uses the TCP/IP protocols for communication (Noonan and Dobrawsky 2006). Many incidents of network attacks are as a result of improper configuration and poor implementation TCP/IP protocols, services and applications. TCP/IP make use of protocols such as TCP, UDP, IP, ICMP etc to define rules of how communication over the network takes place (Noonan and Dobrawsky 2006). Before these protocols are discussed, this thesis briefly looks into the theoretical Open Systems Interconnection (OSI) model (Simoneau 2006). 2.2.2 THE OSI MODEL The OSI model is a standardised layered model defined by International Organization for Standardization (ISO) for network communication which simplifies network communication to seven separate layers, with each individual layer having it own unique functions that support immediate layer above it and at same time offering services to its immediate layer below it (Parziale et al 2006; Simoneau 2006). The seven layers are Application, Presentation, Session Transport, Network, Data, Link and Physical layer. The first three lower layers (Network, Data, Link and Physical layer) are basically hardware implementations while the last four upper layers (Application, Presentation, Session and Transport) are software implementations. Application Layer This is the end user operating interface that support file transfer, web browsing, electronic mail etc. This layer allows user interaction with the system. Presentation Layer This layer is responsible for formatting the data to be sent across the network which enables the application to understand the message been sent and in addition it is responsible for message encryption and decryption for security purposes. Session Layer This layer is responsible for dialog and session control functions between systems. Transport layer This layer provides end-to-end communication which could be reliable or unreliable between end devices across the network. The two mostly used protocols in this layer are TCP and UDP. Network Layer This layer is also known as logical layer and is responsible for logical addressing for packet delivery services. The protocol used in this layer is the IP. Data Link Layer This layer is responsible for framing of units of information, error checking and physical addressing. Physical Layer This layer defines transmission medium requirements, connectors and responsible for the transmission of bits on the physical hardware (Parziale et al 2006; Simoneau 2006). 2.2.3 INTERNET PROTOCOL (IP) IP is a connectionless protocol designed to deliver data hosts across the network. IP data delivery is unreliable therefore depend on upper layer protocol such as TCP or lower layer protocols like IEEE 802.2 and IEEE802.3 for reliable data delivery between hosts on the network.(Noonan and Dobrawsky 2006) 2.2.4 TRANSMISSION CONTROL PROTOCOL (TCP) TCP is a standard protocol which is connection-oriented transport mechanism that operates at the transport layer of OSI model. It is described by the Request for Comment (RFC) 793. TCP solves the unreliability problem of the network layer protocol (IP) by making sure packets are reliably and accurately transmitted, errors are recovered and efficiently monitors flow control between hosts across the network. (Abie 2000; Noonan and Dobrawsky 2006; Simoneau 2006). The primary objective of TCP is to create session between hosts on the network and this process is carried out by what is called TCP three-way handshake. When using TCP for data transmission between hosts, the sending host will first of all send a synchronise (SYN) segment to the receiving host which is first step in the handshake. The receiving host on receiving the SYN segment reply with an acknowledgement (ACK) and with its own SYN segment and this form the second part of the handshake. The final step of the handshake is the n completed by the sending host responding with its own ACK segment to acknowledge the acceptance of the SYN/ACK. Once this process is completed, the hosts then established a virtual circuit between themselves through which the data will be transferred (Noonan and Dobrawsky 2006). As good as the three ways handshake of the TCP is, it also has its short comings. The most common one being the SYN flood attack. This form of attack occurs when the destination host such as the Server is flooded with a SYN session request without receiving any ACK reply from the source host (malicious host) that initiated a SYN session. The result of this action causes DOS attack as destination host buffer will get to a point it can no longer take any request from legitimate hosts but have no other choice than to drop such session request (Noonan and Dobrawsky 2006). 2.2.5 USER DATAGRAM PROTOCOL (UDP) UDP unlike the TCP is a standard connectionless transport mechanism that operates at the transport layer of OSI model. It is described by the Request for Comment (RFC) 768 (Noonan and Dobrawsky 2006; Simoneau 2006). When using UDP to transfer packets between hosts, session initiation, retransmission of lost or damaged packets and acknowledgement are omitted therefore, 100 percent packet delivery is not guaranteed (Sundararajan et al 2006; Postel 1980). UDP is designed with low over head as it does not involve initiation of session between hosts before data transmission starts. This protocol is best suite for small data transmission (Noonan and Dobrawsky 2006). 2.2.6 INTERNET CONTROL MESSAGE PROTOCOL (ICMP). ICMP is primarily designed to identify and report routing error, delivery failures and delays on the network. This protocol can only be used to report errors and can not be used to make any correction on the identified errors but depend on routing protocols or reliable protocols like the TCP to handle the error detected (Noonan and Dobrawsky 2006; Dunkels 2003). ICMP makes use of the echo mechanism called Ping command. This command is used to check if the host is replying to network traffic or not (Noonan and Dobrawsky 2006; Dunkels 2003). 2.3 OTHER NETWORK SECURITY ELEMENTS. 2.3.1 VIRTUAL PRIVATE NETWORK (VPN) VPN is one of the network security elements that make use of the public network infrastructure to securely maintain confidentiality of information transfer between hosts over the public network (Bou 2007). VPN provides this security features by making use of encryption and Tunneling technique to protect such information and it can be configured to support at least three models which are Remote- access connection. Site-to-site ( branch offices to the headquarters) Local area network internetworking (Extranet connection of companies with their business partners) (Bou 2007). 2.3.2 VPN TECHNOLOGY VPN make use of many standard protocols to implement the data authentication (identification of trusted parties) and encryption (scrambling of data) when making use of the public network to transfer data. These protocols include: Point-to-Point Tunneling Protocol PPTP [RFC2637] Secure Shell Layer Protocol (SSL) [RFC 2246] Internet Protocol Security (IPSec) [RFC 2401] Layer 2 Tunneling Protocol (L2TP) [RFC2661] 2.3.2.1 POINT-TO-POINT TUNNELING PROTOCOL [PPTP] The design of PPTP provides a secure means of transferring data over the public infrastructure with authentication and encryption support between hosts on the network. This protocol operates at the data link layer of the OSI model and it basically relies on user identification (ID) and password authentication for its security. PPTP did not eliminate Point-to-Point Protocol, but rather describes better way of Tunneling PPP traffic by using Generic Routing Encapsulation (GRE) (Bou 2007; Microsoft 1999; Schneier and Mudge 1998). 2.3.2.2 LAYER 2 TUNNELING PROTOCOL [L2TP] The L2TP is a connection-oriented protocol standard defined by the RFC 2661which merged the best features of PPTP and Layer 2 forwarding (L2F) protocol to create the new standard (L2TP) (Bou 2007; Townsley et al 1999). Just like the PPTP, the L2TP operates at the layer 2 of the OSI model. Tunneling in L2TP is achieved through series of data encapsulation of the different levels layer protocols. Examples are UDP, IPSec, IP, and Data-Link layer protocol but the data encryption for the tunnel is provided by the IPSec (Bou 2007; Townsley et al 1999). 2.3.2.3 INTERNET PROTOCOL SECURITY (IPSEC) [RFC 2401] IPSec is a standard protocol defined by the RFC 2401 which is designed to protect the payload of an IP packet and the paths between hosts, security gateways (routers and firewalls), or between security gateway and host over the unprotected network (Bou 2007; Kent and Atkinson 1998). IPSec operate at network layer of the OSI model. Some of the security services it provides are, authentication, connectionless integrity, encryption, access control, data origin, rejection of replayed packets, etc (Kent and Atkinson 1998). 2.3.3.4 SECURE SOCKET LAYER (SSL) [RFC 2246] SSL is a standard protocol defined by the RFC 2246 which is designed to provide secure communication tunnel between hosts by encrypting hosts communication over the network, to ensure packets confidentiality, integrity and proper hosts authentication, in order to eliminate eavesdropping attacks on the network (Homin et al 2007; Oppliger et al 2008). SSL makes use of security elements such as digital certificate, cryptography and certificates to enforce security measures over the network. SSL is a transport layer security protocol that runs on top of the TCP/IP which manage transport and routing of packets across the network. Also SSL is deployed at the application layer OSI model to ensure hosts authentication (Homin et al 2007; Oppliger et al 2008; Dierks and Allen 1999). 2.4 FIREWALL BACKGROUND The concept of network firewall is to prevent unauthorised packets from gaining entry into a network by filtering all packets that are coming into such network. The word firewall was not originally a computer security vocabulary, but was initially used to illustrate a wall which could be brick or mortar built to restrain fire from spreading from one part of a building to the other or to reduce the spread of the fire in the building giving some time for remedial actions to be taken (Komar et al 2003). 2.4.1BRIEF HISTORY OF FIREWALL Firewall as used in computing is dated as far back as the late 1980s, but the first set of firewalls came into light sometime in 1985, which was produced by a Ciscos Internet work Operating System (IOS) division called packet filter firewall (Cisco System 2004). In 1988, Jeff Mogul from DEC (Digital Equipment Corporation) published the first paper on firewall. Between 1989 and 1990, two workers of the ATT Bell laboratories Howard Trickey and Dave Persotto initiated the second generation firewall technology with their study in circuit relays called Circuit level firewall. Also, the two scientists implemented the first working model of the third generation firewall design called Application layer firewalls. Sadly enough, there was no published documents explaining their work and no product was released to support their work. Around the same year (1990-1991), different papers on the third generation firewalls were published by researchers. But among them, Marcus Ranums work received the most attention in 1991 and took the form of bastion hosts running proxy services. Ranums work quickly evolved into the first commercial product—Digital Equipment Corporations SEAL product (Cisco System 2004). About the same year, work started on the fourth generation firewall called Dynamic packet filtering and was not operational until 1994 when Check Point Software rolled out a complete working model of the fourth generation firewall architecture. In 1996, plans began on the fifth generation firewall design called the Kernel Proxy architecture and became reality in 1997 when Cisco released the Cisco Centri Firewall which was the first Proxy firewall produced for commercial use (Cisco System 2004). Since then many vendor have designed and implemented various forms of firewall both in hardware and software and till date, research works is on going in improving firewalls architecture to meet up with ever increasing challenges of network security. 2.5 DEFINITION According to the British computer society (2008), Firewalls are defence mechanisms that can be implemented in either hardware or software, and serve to prevent unauthorized access to computers and networks. Similarly, Subrata, et al (2006) defined firewall as a combination of hardware and software used to implement a security policy governing the flow of network traffic between two or more networks. The concept of firewall in computer systems security is similar to firewall built within a building but differ in their functions. While the latter is purposely designed for only one task which is fire prevention in a building, computer system firewall is designed to prevent more than one threat (Komar et al 2003).This includes the following Denial Of Service Attacks (DoS) Virus attacks Worm attack. Hacking attacks etc 2.5.1 DENIAL OF SERVICE ATTACKS (DOS) â€Å"Countering DoS attacks on web servers has become a very challenging problem† (Srivatsa et al 2006). This is an attack that is aimed at denying legitimate packets to access network resources. The attacker achieved this by running a program that floods the network, making network resources such as main memory, network bandwidth, hard disk space, unavailable for legitimate packets. SYN attack is a good example of DOS attacks, but can be prevented by implementing good firewall polices for the secured network. A detailed firewall policy (iptables) is presented in chapter three of this thesis. 2.5.2 VIRUS AND WORM ATTACKS Viruses and worms attacks are big security problem which can become pandemic in a twinkle of an eye resulting to possible huge loss of information or system damage (Ford et al 2005; Cisco System 2004). These two forms of attacks can be programs designed to open up systems to allow information theft or programs that regenerate themselves once they gets into the system until they crashes the system and some could be programmed to generate programs that floods the network leading to DOS attacks. Therefore, security tools that can proactively detect possible attacks are required to secure the network. One of such tools is a firewall with good security policy configuration (Cisco System 2004). Generally speaking, any kind of firewall implementation will basically perform the following task. Manage and control network traffic. Authenticate access Act as an intermediary Make internal recourses available Record and report event 2.5.3 MANAGE AND CONTROL NETWORK TRAFFIC. The first process undertaken by firewalls is to secure a computer networks by checking all the traffic coming into and leaving the networks. This is achieved by stopping and analysing packet Source IP address, Source port, Destination IP address, Destination port, IP protocol Packet header information etc. in order decide on what action to take on such packets either to accept or reject the packet. This action is called packet filtering and it depends on the firewall configuration. Likewise the firewall can also make use of the connections between TCP/IP hosts to establish communication between them for identification and to state the way they will communicate with each other to decide which connection should be permitted or discarded. This is achieved by maintaining the state table used to check the state of all the packets passing through the firewall. This is called stateful inspection (Noonan and Dobrawsky 2006). 2.5.4 AUTHENTICATE ACCESS When firewalls inspects and analyses packets Source IP address, Source port, Destination IP address, Destination port, IP protocol Packet header information etc, and probably filters it based on the specified security procedure defined, it does not guarantee that the communication between the source host and destination host will be authorised in that, hackers can manage to spoof IP address and port action which defeats the inspection and analysis based on IP and port screening. To tackle this pit fall over the network, an authentication rule is implemented in firewall using a number of means such as, the use of username and password (xauth), certificate and public keys and pre-shared keys (PSKs).In using the xauth authentication method, the firewall will request for the source host that is trying to initiate a connection with the host on the protected network for its username and password before it will allow connection between the protected network and the source host to be establi shed. Once the connection is been confirmed and authorised by the security procedure defined, the source host need not to authenticate itself to make connection again (Noonan and Dobrawsky 2006). The second method is using certificates and public keys. The advantage of this method over xauth is that verification can take place without source host intervention having to supply its username and password for authentication. Implementation of Certificates and public keys requires proper hosts (protected network and the source host) configuration with certificates and firewall and making sure that protected network and the source host use a public key infrastructure that is properly configured. This security method is best for big network design (Noonan and Dobrawsky 2006). Another good way of dealing with authentication issues with firewalls is by using pre-shared keys (PSKs). The implementation of PSKs is easy compare to the certificates and public keys although, authentication still occur without the source host intervention its make use of an additional feature which is providing the host with a predetermined key that is used for the verification procedure (Noonan and Dobrawsky 2006). 2.5.5 ACT AS AN INTERMEDIARY When firewalls are configured to serve as an intermediary between a protected host and external host, they simply function as application proxy. The firewalls in this setup are configured to impersonate the protected host such that all packets destined for the protected host from the external host are delivered to the firewall which appears to the external host as the protected host. Once the firewalls receive the packets, they inspect the packet to determine if the packet is valid (e.g. genuine HTTT packet) or not before forwarding to the protected host. This firewall design totally blocks direct communication between the hosts. 2.5.6 RECORD AND REPORT EVENTS While it is good practise to put strong security policies in place to secure network, it is equally important to record firewalls events. Using firewalls to record and report events is a technique that can help to investigate what kind of attack took place in situations where firewalls are unable to stop malicious packets that violate the access control policy of the protected network. Recording this event gives the network administrator a clear understanding of the attack and at the same time, to make use of the recorded events to troubleshoot the problem that as taken place. To record these events, network administrators makes use of different methods but syslog or proprietary logging format are mostly used for firewalls. However, some malicious events need to be reported quickly so that immediate action can be taken before serious damage is done to the protected network. Therefore firewalls also need an alarming mechanism in addition to the syslog or proprietary logging format whe n ever access control policy of the protected network is violated. Some types of alarm supported by firewalls include Console notification, Simple Network Management Protocol (SNMP), Paging notification, E-mail notification etc (Noonan and Dobrawsky 2006). Console notification is a warning massage that is presented to the firewall console. The problem with this method of alarm is that, the console needs to be monitored by the network administrator at all times so that necessary action can be taken when an alarm is generated. Simple Network Management Protocol (SNMP) notification is implemented to create traps which are transferred to the network management system (NMS) monitoring the firewall. Paging notification is setup on the firewall to deliver a page to the network administrator whenever the firewall encounters any event. The message could be an alphanumeric or numeric depending on how the firewall is setup. E-mail notification is similar to paging notification, but in this case, the firewall send an email instead to proper address. 2.6 TYPES OF FIREWALLS Going by firewall definition, firewalls are expected to perform some key functions like, Application Proxy, Network Translation Address, and Packet filtering. 2.6.1 APPLICATION PROXY This is also known as Application Gateway, and it acts as a connection agent between protected network and the external network. Basically, the application proxy is a host on the protected network that is setup as proxy server. Just as the name implies, application proxy function at the application layer of the Open System Interconnection (OSI) model and makes sure that all application requests from the secured network is communicated to the external network through the proxy server and no packets passes through from to external network to the secured network until the proxy checks and confirms inbound packets. This firewall support different types of protocols such as a Hypertext Transfer Protocol (HTTP), File Transfer Protocol (FTP) and Simple Mail Transport Protocol (SMTP) (Noonan and Dobrawsky 2006; NetContinuum 2006). 2.6.2 NETWORK ADDRESS (NAT) NAT alter the IP addresses of hosts packets by hiding the genuine IP addresses of secured network hosts and dynamically replacing them with a different IP addresses (Cisco System 2008; Walberg 2007). When request packets are sent from the secured host through the gateway to an external host, the source host address is modified to a different IP address by NAT.  When the reply packets arrives at the gateway, the NAT then replaces the modified address with genuine host address before forwarding it to the host (Walberg 2007).The role played by NAT in a secured network system makes it uneasy for unauthorized access to know: The number of hosts available in the protected network The topology of the network The operating systems the host is running The type of host machine (Cisco System 2008). 2.6.3 PACKET FILTERING. â€Å"Firewalls and IPSec gateways have become major components in the current high speed Internet infrastructure to filter out undesired traffic and protect the integrity and confidentiality of critical traffic† (Hamed and Al-Shaer 2006). Packet filtering is based on the lay down security rule defined for any network or system. Filtering traffic over the network is big task that involves comprehensive understanding of the network on which it will be setup. This defined policy must always be updated in order to handle the possible network attacks (Hamed and Al-Shaer 2006). 2.6.4 INSTRUCTION DETECTION SYSTEMS. Network penetration attacks are now on the increase as valuable information is being stolen or damaged by the attacker. Many security products have been developed to combat these attacks. Two of such products are Intrusion Prevention systems (IPS) and Intrusion Detection Systems (IDS). IDS are software designed to purposely monitor and analysed all the activities (network traffic) on the network for any suspicious threats that may violate the defined network security policies (Scarfone and Mell 2007; Vignam et al 2003). There are varieties of methods IDS uses to detect threats on the network, two of them are, anomaly based IDS, and signature based IDS. 2.6.4.1 ANOMALY BASED IDS Anomaly based IDS is setup to monitor and compare network events against what is defined to be normal network activities which is represented by a profile, in order to detect any deviation from the defined normal events. Some of the events are, comparing the type of bandwidth used, the type of protocols etc and once the IDS identifies any deviation in any of this events, it notifies the network administrator who then take necessary action to stop the intended attack (Scarfone and Mell 2007). 2.6.4.2 SIGNATURE BASED IDS Signature based IDS are designed to monitor and compare packets on the network against the signature database of known malicious attacks or threats. This type of IDS is efficient at identifying already known threats but ineffective at identifying new threats which are not currently defined in the signature database, therefore giving way to network attacks (Scarfone and Mell 2007). 2.6.5 INTRUSION PREVENTION SYSTEMS (IPS). IPS are proactive security products which can be software or hardware used to identify malicious packets and also to prevent such packets from gaining entry in the networks (Ierace et al 2005, Botwicz et al 2006). IPS is another form of firewall which is basically designed to detect irregularity in regular network traffic and likewise to stop possible network attacks such as Denial of service attacks. They are capable of dropping malicious packets and disconnecting any connection suspected to be illegal before such traffic get to the protected host. Just like a typical firewall, IPS makes use of define rules in the system setup to determine the action to take on any traffic and this could be to allow or block the traffic. IPS makes use of stateful packet analysis to protect the network. Similarly, IPS is capable of performing signature matching, application protocol validation etc as a means of detecting attacks on the network (Ierace et al 2005). As good as IPS are, they also have t heir downsides as well. One of it is the problem of false positive and false negative. False positive is a situation where legitimate traffic is been identified to be malicious and thereby resulting to the IPS blocking such traffic on the network. False negative on the other hand is when malicious traffic is be identified by the IPS as legitimate traffic thereby allowing such traffic to pass through the IPS to the protected network (Ierace N et al 2005). 2.7 SOFTWARE AND HARDWARE FIREWALLS 2.7.1 SOFTWARE FIREWALLS Software-based firewalls are computers installed software for filtering packets (Permpootanalarp and Rujimethabhas 2001). These are programs setup either on personal computers or on network servers (Web servers and Email severs) operating system. Once the software is installed and proper security polices are defined, the systems (personal computers or servers) assume the role of a firewall. Software firewalls are second line of defence after hardware firewalls in situations where both are used for network security. Also software firewalls can be installed on different operating system such as, Windows Operating Systems, Mac operating system, Novel Netware, Linux Kernel, and UNIX Kernel etc. The function of these firewalls is, filtering distorted network traffic. There are several software firewall some of which include, Online Armor firewall, McAfee Personal Firewall, Zone Alarm, Norton Personal Firewall, Black Ice Defender, Sygate Personal Firewall, Panda Firewall, The DoorStop X Fi rewall etc (Lugo Parker 2005). When designing a software firewall two keys things are considered. These are, per-packet filtering and a per-process filtering. The pre-packet filter is design to search for distorted packets, port scan detection and checking if the packets are accepted into the protocol stack. In the same vein, pre-process filter is the designed to check if a process is allowed to begin a connection to the secured network or not (Lugo and Parker 2005). It should be noted that there are different implantations of all Firewalls. While some are built into the operating system others are add-ons. Examples of built-in firewalls are windows based firewall and Linux based. 2.7.2 WINDOWS OPERATING SYSTEM BASED FIREWALL. In operating system design, security features is one important aspect that is greatly considered. This is a challenge the software giant (Microsoft) as always made sure they implement is their products. In the software industry, Mi

Sunday, August 4, 2019

Elements of The Lord of the Rings in Final Fantasy VIII Essay -- Lord

Elements of The Lord of the Rings in Final Fantasy VIII      Ã‚  Ã‚   J.R.R. Tolkien's The Lord of the Rings trilogy is arguably the most influential work of fantasy literature in modern times. Its epic tale of good against evil and its surreal world of magical and unusual characters and places have captured and enchanted readers since its publication half a century ago. The story of the struggle to destroy the One Ring still influences numerous tales of adventure in literature, film, and role-playing games. Since the advent of role-playing video games, the Final Fantasy series has endured in a genre where many other games seem to blend together. It marks a standard in the world of role-playing games in much the same way The Lord of the Rings marks a standard in fantasy literature. This essay shall examine these two epic adventures and show some of the ways in which Final Fantasy VIII draws upon elements from The Lord of the Rings.    At the center of Tolkien's The Lord of the Rings is the basic struggle between good and evil, manifested through the battle over the One Ring. The story draws upon traditional Christian theology and ideas about good and evil, right and wrong. Goodness in The Lord of the Rings is represented by selflessness and an interest in the good of all, with a willingness to give of oneself for the good of the whole. However, the border between good and evil is not always clear, and characters are not necessarily completely good or completely evil. Selfishness, greed, and hunger for individual power are destructive forces for evil within individual characters, and characters must use their own moral compass to choose whether to strive for good or give in to the temptation of evil. Even... ...Merry and Pippin or Zell Dincht. Perhaps it is the vulnerability in characters like Frodo Baggins or Squall Leonheart; seemingly 'regular guys' who are thrust into extraordinary situations and who persevere for the forces of good in the world. Regardless, both The Lord of the Rings and the Final Fantasy series are works that have managed to grow beyond the narrow bounds of their genre, and both will likely remain influential standards by which other works are judged.    WORKS CITED Final Fantasy VIII. SquareSoft/Electronic Arts. 1999. Final Fantasy: Worlds Apart. Final Fantasy VIII home page. Tolkein, J.R.R. The Fellowship of the Ring. New York: Ballantine Books, 1954. ---. The Return of the King. New York: Ballantine Books, 1955. ---. The Two Towers. New York: Ballantine Books, 1954.   

Saturday, August 3, 2019

Disney: To be a Young Woman Essay -- disney princess, unrealistic beau

To be a Young Woman (according to Disney) Since Disney first introduced Snow White from the film Snow White and the Seven Dwarves back in 1937, the definition of what it means to be a young woman has been hugely influenced by Walt Disney Studios princesses. From the hair and the dresses to the demeanor and poise, Disney princesses have been showing girls of all ages how a woman should look and act, if she wants to have a happy life and find the perfect husband. Being constantly fed the seemingly ‘ideal’ image of beauty since their youth; most girls feel a need to strive to that level of beauty in order for them to feel accepted in society, and confident in themselves. According to researcher Dawn England, â€Å"The princesses in the first three Disney Princess movies were frequently affectionate, helpful, troublesome, fearful, tentative, and described as pretty† (England).Focusing in on the three original Disney princesses, Snow White, Cinderella, and Aurora from Sleeping Beauty, according to those thre e princesses what it means to be a young woman is to have unrealistic physical beauty, be dependent on a man, and be submissive and obedient. The Disney princesses’ unrealistic level of beauty can be seen in the artist portrayal of each princess. In the article, "The Mixed Blessings Of Disney's Classic Fairy Tales" Asma Ayob talks about how the princesses’ are created, â€Å"Snow White and Cinderella are presented as beautiful archetypal princesses who are ideally perfect. With the advent of the ï ¬ lm, and the animators’ ability to create ï ¬â€šawless bodies, this type of female attractiveness, which can be compared to â€Å"air-brushing† models on the covers of popular magazines, is a hard act to follow† (Ayob). The ‘hard act to follow’, has been t... ...llier-Meek. "Gender Role Portrayal And The Disney Princesses." Sex Roles 64.7/8 (2011): 555-567. OmniFile Full Text Select (H.W. Wilson). Web. 14 Apr. 2014. "Marry The Prince Or Stay With Family—That Is The Question: A Perspective Of Young Korean Immigrant Girls On Disney Marriages In The United States." Australasian Journal Of Early Childhood 34.2 (2009): 39-46. OmniFile Full Text Select (H.W. Wilson). Web. 14 Apr. 2014. Rozario, Rebecca-Anne C. Do. "The Princess And The Magic Kingdom: Beyond Nostalgia, The Function Of The Disney Princess." Women's Studies In Communication 27.1 (2004): 34-59. OmniFile Full Text Select (H.W. Wilson). Web. 28 Apr. 2014. Whelan, Bridget1. "Power To The Princess: Disney And The Creation Of The 20Th Century Princess Narrative." Interdisciplinary Humanities 29.1 (2012): 21-34. OmniFile Full Text Select (H.W. Wilson). Web. 14 Apr. 2014. Disney: To be a Young Woman Essay -- disney princess, unrealistic beau To be a Young Woman (according to Disney) Since Disney first introduced Snow White from the film Snow White and the Seven Dwarves back in 1937, the definition of what it means to be a young woman has been hugely influenced by Walt Disney Studios princesses. From the hair and the dresses to the demeanor and poise, Disney princesses have been showing girls of all ages how a woman should look and act, if she wants to have a happy life and find the perfect husband. Being constantly fed the seemingly ‘ideal’ image of beauty since their youth; most girls feel a need to strive to that level of beauty in order for them to feel accepted in society, and confident in themselves. According to researcher Dawn England, â€Å"The princesses in the first three Disney Princess movies were frequently affectionate, helpful, troublesome, fearful, tentative, and described as pretty† (England).Focusing in on the three original Disney princesses, Snow White, Cinderella, and Aurora from Sleeping Beauty, according to those thre e princesses what it means to be a young woman is to have unrealistic physical beauty, be dependent on a man, and be submissive and obedient. The Disney princesses’ unrealistic level of beauty can be seen in the artist portrayal of each princess. In the article, "The Mixed Blessings Of Disney's Classic Fairy Tales" Asma Ayob talks about how the princesses’ are created, â€Å"Snow White and Cinderella are presented as beautiful archetypal princesses who are ideally perfect. With the advent of the ï ¬ lm, and the animators’ ability to create ï ¬â€šawless bodies, this type of female attractiveness, which can be compared to â€Å"air-brushing† models on the covers of popular magazines, is a hard act to follow† (Ayob). The ‘hard act to follow’, has been t... ...llier-Meek. "Gender Role Portrayal And The Disney Princesses." Sex Roles 64.7/8 (2011): 555-567. OmniFile Full Text Select (H.W. Wilson). Web. 14 Apr. 2014. "Marry The Prince Or Stay With Family—That Is The Question: A Perspective Of Young Korean Immigrant Girls On Disney Marriages In The United States." Australasian Journal Of Early Childhood 34.2 (2009): 39-46. OmniFile Full Text Select (H.W. Wilson). Web. 14 Apr. 2014. Rozario, Rebecca-Anne C. Do. "The Princess And The Magic Kingdom: Beyond Nostalgia, The Function Of The Disney Princess." Women's Studies In Communication 27.1 (2004): 34-59. OmniFile Full Text Select (H.W. Wilson). Web. 28 Apr. 2014. Whelan, Bridget1. "Power To The Princess: Disney And The Creation Of The 20Th Century Princess Narrative." Interdisciplinary Humanities 29.1 (2012): 21-34. OmniFile Full Text Select (H.W. Wilson). Web. 14 Apr. 2014.

Friday, August 2, 2019

Irony in Sophocles Oedipus the King Essays -- Oedipus Rex Essays

Irony in Sophocles' Oedipus In the play "Oedipus," irony is used frequently as and as eloquently by Sophocles to the reveal theme of seeking knowledge. Not knowing the King of Thebes, Oedipus, gives speeches on finding the murderer of the King of Laias and how wretched the poor soil will be when the truth is revealed. " Then once more I must bring what is dark to light†¦, whoever killed King Laios might- who knows?-might decide at any moment to kill me as well. By avenging the murder of the King, I protect myself, (Sophocles 1109). The speech shows how dedicated Oedipus in the pursuit of the murderer and not only the avenge of the King but to save himself. He will not be saving but adding down to his life. Oedipus doesn't realize he is in pursuit of himself. He continues his speech "Moreover: If anyone knows the murderer to be foreign, Let him not keep silent: he shall have his reward from him," ( 1112). With his own words he asks for the truth. But he can't handle the truth, for he has no idea what he is asking for or for whom he is searching for. He also states that he wants t...

Thursday, August 1, 2019

Jean Rhys Wide Sargasso Sea

WIDE SARGASSO SEA Spoiled Rose A child is a reflection of their parents becoming a product of their environment. Childhood is the most crucial stage in life, for this is when a child is most impressionable. What is experienced, felt, and taught is what shapes a child into who they will become upon entering adulthood. Antoinette (Bertha) Mason from Jean Rhy’s Wide Sargasso Sea, is victim to mental injury, forced to grow up on her own, feeling out of place without the love and care of her mother.The loneliness and hurt she felt at a young age imprisoned her to a life of unhappiness. Eventually madness took over her which mushroomed furthermore in her arranged marriage to Mr. Rochester, who unravels her already precarious mental state. He drives her to the point where Bertha decides to take her life, believing in a deluded state it is her destiny. Her tragic life reveals the importance of growing up in a stable home environment, especially in her day, and location, given her soci al status and race, growing up stable was not a basket of roses considering her circumstances.Early on, we learn of Antoinette’s family life, with the absence of her father all she has is her mother and younger brother who suffers from a learning disabled state which prevents her from bonding with him. Then there is Christophine who is their servant, a black obeah woman who becomes of great influence to her, as well as Tia her brief and only childhood friend who is of African descent. Her mother is very distant with her, only paying attention to her sick brother.Although she was not physically abused, Antoinette suffered severe emotional abuse due to un-acceptance of others as well as neglect and lack of love from her Mother, which in some cases is more harmful because it goes unnoticed until it becomes too late. According to an article exploring the nature of victim and victimizer emotional abuse is a silent attacker. â€Å"Emotional abuse (psychological abuse, verbal abuse , and mental injury) includes acts or omissions that have caused, or could cause, serious behavioral, cognitive, emotional, or mental disorders†Ã‚  (Banks).At a young age we can see Antoinette is susceptible to these symptoms. For example her mother would shove her away when shed try to get close, â€Å"calmly, coldly, without a word† as Antoinette was â€Å"useless† (Rhys 11). This lack of being loved can affect her judgment of what love truly is, because she never properly received it. According to a file in the National library of Health- NHS Evidence, Children may experience a number of different emotional disorders. Behavioral issues such as avoidance of feared activities as well as clinginess or reluctance to separate from trusted adults may arise (NHS).At a young age we can see Antoinette is susceptible to these symptoms. As she wakes up early one morning she finds her mother’s horse dead â€Å"I ran away and did not speak of it for I thought if I told no one it might not be true. †(Rhys 10) When faced with troubled situations, she runs away and in a cognitive state, she reasons with herself denying a current situation is not real. Burying her reality is a defense mechanism she has built and constantly uses into adulthood in order cope when faced with unsettling realities, distorting her perception, memory and judgment.Antoinette also grows very fond of Christophine, as she is the only one who seems to genuinely care for her, Antoinette grows attached to her, feeling a security when she has christophine around because she is the only one who respects and protects the Cosways. Additionally growing up in Jamaica just after the emancipation act of 1833 during a harsh time combating slavery and rights, Antoinette found it difficult to fit in and find some sense of identity. She was a beautiful young white skinned Creole girl, daughter to ex-slave and plantation owners, surrounded by mainly blacks and few rich whites.Althoug h she came from a wealthy background, as she grew up her mother was not financially doing well and was fairly close to losing their plantation. Evidently her and her family was despised. She was not accepted by the black community surrounding her and underwent racism having to constantly be called a â€Å"white cockroach† (Rhys 13) by the black community. The few whites in the area also frowned upon her and her family for not being of true English descent.So although she lived in a Calibri estate surrounded by beautiful nature and ocean sun filled days, on the inside she felt out of place, fearful and lonely. Her only childhood friend Tia betrayed her leaving her further damaged by stealing her clothes and pennies, while out one day swimming unsupervised. A child needs friends and interaction with others in order to communicate and be socially inclined. Things seem to turn around for Antoinette, when her mother marries Mr. Mason, a wealthy English man, who decides to stay and renovate Coulibri.Unfortunately racial tensions arose among recent freed black slaves, escalading to a protest that ends in catastrophe. Their home gets burned down with torches; her brother injured fatally passes away, leading her mother to fully manifest insanity due to the event. At this point Antoinette’s life drastically changes she is injured and sick for several weeks. She is faced with death once more by the passing of her brother and loses her mother as she becomes mentally unstable and dies; Mr. Mason abandons them leaving Jamaica while traveling.Antoinette is sent to live in a catholic convent ran by nuns. As you can imagine this was very hard for Antoinette, although she was surrounded by others she was left their isolated. In the convent she grows a fascination with death, since it is something she is used to she begins to like the dark ominous part of religion and death. I believe Antoinette suppresses all the calamities she has had to deal with till that point . Life has not been kind to her and despite of it she still manages to keep it together although she becomes a docile human being.When she finally reaches the age of seventeen Mr. Mason visits her more and finally removes her from the convent and introduces her to his English friends. Upon this happening an arranged marriage is what is in store for Antoinette. She is married to Mr. Rochester; their marriage is more like a business pact because they do not marry on the base of love. It is apparent Mr. Rochester marries Antoinette merely for her riches. She is not in love with him but do to her docile way she becomes intoxicated with the idea of Love and having a male companion.At first Mr. Rochester is amorous with Antoinette, upon finding out about her past, which he was not aware of his attitude and view towards Antoinette changes. His indifference towards her, affects her deeply as she becomes distressed. She looks to Christophine for help, who unknowingly makes the situation with herself and husband worse. Gradually Antoinette begins to drink more, making her act out violently. Alcohol distorts the mind and suppressed feelings she has kept hidden arise.The fact that her husband had no real love or apathy for her austerely depressed her and made her sick, she became emotionally unstable. Due to the era they were in, divorce was not easy to achieve. Upon marrying Mr. Rochester She basically became his property along with all of her wealth. She was trapped and depended on her husband. She had no control of her life and she was going the same route her mother went. Mr. Rochester constantly called Antoinette Bertha, which affected her because it was not what she went by, this Bertha finally manifested herself in Antoinette. Mr.Rochester’s disdain and abandonment was the climax to Antoinette’s insanity, as she was isolated and locked in an attic. Throughout her life Antoinette suffered multiple losses, her mental health got worse as she transitioned into an adult. Her mood was low and depressing, she barely ate, and she became delusional by believing in her dreams as a true reality. I think anyone in her position would go insane and prefer to die than live in such a horrible reality. As a child she had not one positive role model to look up to, primarily her mother is at fault with how Antoinette’s life came to be.She could have been a real mother and been loving and supportive towards her daughter who always needed her. Childhood is the most vital part of life; this is when a child needs to be in a positive loving environment. Otherwise a child becomes a dysfunctional part of society as an adult, causing harm to oneself or others. Due to the treatment she received as a child, she had very low self esteem and no self worth; always accepting situations when all along she could have changed her destiny, if only she was not so weak.Ironically she turned out weak just like her mother, unknowingly becoming mentally ill, lead ing to the loss of her life. The beautiful rose she was turned black as death, never fully blooming. Works cited Banks, Ron. Focus Adolescent Services. â€Å"Bullying What Parents and Teachers Should Know. † EECE Publications, Digest EDO-PS-97-17 www. focusas. com NHS, National Electronic Library for Health. â€Å"Isolation and Mental Health† http://www. library. nhs. uk/mentalhealth/ Jean Rhys, Wide Sargasso Sea (Penguin Books Ltd: Middlesex, England, 1966).

Constitution Laws Essay

People Alexander Hamilton- saved convention in Maryland from failure by engineering the adoption of his report; called upon congress to summon a convention in Philadelphia next year not to deal with commerce; His speech on his plan= 1 delegate convinced; Joined John Jay & Madison in writing The Federalist George Washington- elected chairman by demand; said, â€Å"We have probably had too good an opinion of human nature in forming our Confederation† Ben Franklin- added the urbanity of an elder statesman though he was inclined to be indiscreetly talkative in his decline years; the convention assigned chaperones to Franklin to make sure he held his tongue James Madison- made contributions so notable = â€Å"The father of the constitution† ; wrote federalist #1 and refuted that it is impossible to extend republican form of government over large territory Thomas Jefferson, John Adams and Thomas Paine- absent in convention because they were in Europe Sam Adams and John Hancock- were absent because not elected by Mass. Patrick Henry- not at convention because he was chosen by Virginia but declined to serve; professed to fee in fearsome doc. the death warrant of liberty Dey of Algiers- drove delegates to their work to their work; was a founding father Daniel Shays- frightened the conservative minded delegates; the specter of the recent outburst in Mass was alarming & now another founding father Lord Sheffield- British mercantilists spurred constitution framers to their task; Also a founding father Events Annapolis Convention – nine states appointed delegates but only five appointed – fix issue on commerce by Alexander Hamilton Congress calls another Convention- reluctant but called then called to revise the Articles of Confederation; most Revolutionary leaders of 1776 absent Philadelphia Convention May 25-September 17,1787- only 42 of original 55 members remained to sign Constitution (3 refused & returned to resist ratification) Large State Plan- pushed as the framework of the constitution; its essence was that representation in both houses of a bicameral congress should be based on population (large states have advantage) Small State Plan- included VA & NJ; provided equal representation in a unicameral congress by states, regardless of size & population under the AOC Great Compromise- hammered out & agreed upon; large states represented by population in HOR; each state no matter how big or small had 2 senators End of 1807- slave trade turned off but only Georgia allowed Elections held to for members in states to of the ratifying convention- feds or antis were elected on a basis of their pledge for/against the Constitution; Penn first state to accept constitution; Mass provided acid test- if failed the constitution would be bogged down Boston Ratifying Convention- the absence of the bill of rights feared anti- federalist but federalists assured them that the 1st congress would add such a safeguard by amendment Constitution adopted June 21, 1788- 9 states expect VA,NY,NC & Ohio ratified the constitution Virginia ratified Constitution- Virginia ratified Constitution—provided fierce anti-federalist opposition; George Washington, James Madison, and John Marshall (federalists) lent influential support; could not continue as an independent state because the new Union was going to be formed anyway New York Ratified the Constitution- realized it cannot be an independent state & prosper away from the union; approved 32 proposed amendments; issued a call for another convention to modify the Constitution Convention met in North Carolina—adjourned without taking a vote Rhode Island rejected the Constitution—did not summon a ratifying convention; rejected by popular referendum Documents The Federalist- John Jay, Madison, and Hamilton write series of articles for New York news; designed as propaganda but remained most penetrating commentary ever written in Constitution Laws Constitution – provided for a strong, independent executive in presidency (president= military chief, have wide powers of appointment to domestic offices, & have veto power over leg.); plenty of compromises ( electing president by indirect by electoral college); would become the supreme law of the land in the states ratifying; adopted on June 21, 1788; reconcild principles of liberty & order 3/5s Compromise- the consituttion questioned if slaves counted as a person in direct taxes; decided slaves counted as 3/5 of a person Articles of Confederation- delegates decided to rid of the old confederation, despite explicit instruction from Congress to revise ; these spirits were determined to overthrow the government in the US by peaceful means Ideas Strengthen Republic (republicanism) – delegates hoped to crystallize idealism into a stable political structure; wanted a firm, strong, & respected government; determined to preserve the union, forestall anarchy, and ensure security of life and property against dangerous uprisings; sought to curb the unrestrained democracy rampant in the states Conservatism- safeguards= erected against mob- rule excesses while republican gains of Revolution= conserved Rid of AOC- determined to overthrow the government of US by peaceful means (see events) Manhood suffrage democracy- convention was unanimous in believing in this; government by democratic babblers (feared & fought) Presidency (president) – a president should be a military chief and have wide of power of appointment to domestic offices;& have veto power over legislation Groups State Legislatures – chose leaders whose members had been elected by voters who could qualify as property holders for the convention that revised the AOC Demigods- the caliber of the participants= extradinary high elected GW as chairman 55 delegates at the convention- 95% owned slaves; young but experienced statesmen; nationalists interesting in preserving/ strengthening the young republic; preserved the union, forestall anarchy, & ensure security of life & property Travel-stained delegates- reached Philadelphia and decided to scrap the old AOC House of Representative- represented the larger states by population; every tax bill and revenue must originate in the house; were citizens permitted to choose officials by direct vote Senate – made smaller states have equal representation; each had to senators Members of the constitutional convention- saw eye-to-eye; they demanded money & protection of private property; favored a stronger government with 3 branches Conservative minded delegates – erected safeguards against the excesses of the mob & made strong barriers Anti- Federalists- opposed stronger federal government; were arrayed against the the feds.; wanted to steal back power; leaders: Sam Adams, Patrick Henry, & Richard Henry Lee; believed sovereignty of people resided in the legislative Federalists- favored the new Constitution; had power & influence; support of George Washington and Franklin; wealthier/ more educated and organized then antifederalists; controlled the press; contender every branch, executive, judiciary, & legislative; thought by settling the drifting ship of state on steady course, they could restore economic & political stability Militant minority of conservatives- Engineered the peaceful revolution that overthrow the inadequate constitution= AOC