Showing posts with label software. Show all posts
Showing posts with label software. Show all posts

Friday, March 7, 2014

DARPA MUSE: Deep program analysis, and big data analytics, create public database

DARPA's MUSE seeks to leverage deep program analysis and big data analytics to create a public database containing mined inferences about salient properties, behaviours and vulnerabilities of software drawn from the hundreds of billions of lines of open source code available today.

The program aims to make significant advances in the way software is built, debugged, verified, maintained and understood, and to enable the automated repair of existing programs and synthesis of new ones.

During the past decade information technologies have driven the productivity gains essential to U.S. economic competitiveness, and computing systems now control significant elements of critical national infrastructure.

As a result, tremendous resources are devoted to ensuring that programs are correct, especially at scale.

Unfortunately, in spite of developers' best efforts, software errors are at the root of most execution errors and security vulnerabilities.

To help improve this state, DARPA has created the Mining and Understanding Software Enclaves (MUSE) program.

MUSE seeks to make significant advances in the way software is built, debugged, verified, maintained and understood.

The collective knowledge gleaned from MUSE's efforts would facilitate new mechanisms for dramatically improving software correctness, and help develop radically different approaches for automatically constructing and repairing complex software.

Suresh Jagannathan
"Our goal is to apply the principles of big data analytics to identify and understand deep commonalities among the constantly evolving corpus of software drawn from the hundreds of billions of lines of open source code available today," said Suresh Jagannathan, DARPA program manager.

"We're aiming to treat programs—more precisely, facts about programs—as data, discovering new relationships (enclaves) among this 'big code' to build better, more robust software."

Central to MUSE's approach is the creation of a community infrastructure that would incorporate a continuously operational specification-mining engine.

This engine would leverage deep program analyses and foundational ideas underlying big data analytics to populate and refine a database containing inferences about salient properties, behaviours and vulnerabilities of the program components in the corpus.

If successful, MUSE could provide numerous capabilities that have so far remained elusive.

"Ideally, we could enable a paradigm shift in the way we think about software construction and maintenance, replacing the existing costly and laborious test/debug/validate cycle with 'always on' program analysis, mining, inspection and discovery," Jagannathan said.

"We could see scalable automated mechanisms to identify and repair program errors, as well as tools to efficiently create new, custom programs from existing components based only a description of desired properties."

Sunday, August 14, 2011

The First Study of Open Innovation in France

Click To View in larger format
The first ever study conducted in France ‘Open Innovation in France’ was presented during a Press Conference in Paris on May 31st 2011 and the English version was released online on June 7th 2011 at the Word Innovation Forum in New York.

An infography summary is available on this link : Open-Innovation-English-3
The detailed version is available in pdf format on this link:  Study 2011 by bluenove ‘OPEN INNOVATION IN FRANCE’ or on our blog.

The summary version is also available on slideshare.

The French version of the detailed study is available on this link.

Bluenove supports international companies to implement Open & Collaborative Innovation projects in France and Europe. For instance, we have helped a Brazilian leader in the Cosmetic industry to detect, assess and map potential innovative partners in Europe.

We also support change management projects to implement collaborative software solutions and dynamics within organizations.

We are also interested to identify consulting partners worldwide who may be interested to conduct a similar study in their own country in order to develop a benchmark approach or map such as our Open Innovation Map: http://www.openinnovationmap.org

Feel free to contact us for more information about the study or our services at contact@bluenove.com

Wednesday, June 2, 2010

Impossible figures brought to life in virtual worlds

Impossible figures brought to life in virtual worlds - New Scientist



Ever found a computer game truly impossible? If not, you soon might, thanks to Chinese computer scientists who have found a way to depict physically impossible figures in 3D virtual environments.

The endless staircases of the Dutch artist M. C. Escher appear impossible and possible at the same time, and able to go in all directions. Such visual trickery depends heavily on the observer's viewpoint – and that makes it difficult to animate Escher-type figures in games. If the viewpoint pans around a 3D computer depiction of such a staircase, "the impossibility is lost", says Tai-Pang Wu at the Chinese University of Hong Kong.

Now his team has found a way to make these images viewable from a useful array of angles. The trick is to take advantage of the image's strangeness; viewers scarcely notice if an Escher staircase becomes slightly distorted.

Saturday, May 8, 2010

Warning! How I’d Hack Your Weak Passwords - by Lifehacker

Note: This isn't intended as a guide to hacking *other people's* weak passwords. Instead, the aim is to help you better understand the security of your own passwords and how to bolster that security.

If you invited me to try and crack your password, you know the one that you use over and over for like every web page you visit, how many guesses would it take before I got it?

Let's see… here is my top 10 list. I can obtain most of this information much easier than you think, then I might just be able to get into your e-mail, computer, or online banking. After all, if I get into one I'll probably get into all of them.

1.Your partner, child, or pet's name, possibly followed by a 0 or 1 (because they're always making you use a number, aren't they?)
2.The last 4 digits of your social security number.
3.123 or 1234 or 123456.
4."password"
5.Your city, or college, football team name.
6.Date of birth – yours, your partner's or your child's.
7."god"
8."letmein"
9."money"
10."love"
Statistically speaking that should probably cover about 20% of you. But don't worry. If I didn't get it yet it will probably only take a few more minutes before I do…

Black Hats
Hackers, and I'm not talking about the ethical kind, have developed a whole range of tools to get at your personal data. And the main impediment standing between your information remaining safe, or leaking out, is the password you choose. (Ironically, the best protection people have is usually the one they take least seriously.)

Brute Force
One of the simplest ways to gain access to your information is through the use of a Brute Force Attack. This is accomplished when a hacker uses a specially written piece of software to attempt to log into a site using your credentials.


Insecure.org
has a list of the Top 10 FREE Password Crackers. Please use this information in a responsible manner. If you do use them, do so to improve your system security.

Security Breach
So, how would one use this process to actually breach your personal security? Simple. Follow my logic:

You probably use the same password for lots of stuff right?
Some sites you access such as your Bank or work VPN probably have pretty decent security, so I'm not going to attack them.

However, other sites like the Hallmark e-mail greeting cards site, an online forum you frequent, or an e-commerce site you've shopped at might not be as well prepared. So those are the ones I'd work on.

Software aids
So, all we have to do now is unleash Brutus, wwwhack, or THC Hydra on their server with instructions to try say 10,000 (or 100,000 – whatever makes you happy) different usernames and passwords as fast as possible.

Once we've got several login+password pairings we can then go back and test them on targeted sites.

Interrogating cookies
But wait… How do I know which bank you use and what your login ID is for the sites you frequent? All those cookies are simply stored, unencrypted and nicely named, in your Web browser's cache. Use cleaning software to remedy that problem.

Speed is relative
How fast can all this be done? Well, that depends on three main things, the length and complexity of your password, the speed of the hacker's computer, and the speed of the hacker's Internet connection.

Assuming the hacker has a reasonably fast connection and PC here is an estimate of the amount of time it would take to generate every possible combination of passwords for a given number of characters. After generating the list it's just a matter of time before the computer runs through all the possibilities – or gets shut down trying.

Lowercase and Uppercase
Pay particular attention to the difference between using only lowercase characters and using all possible characters (uppercase, lowercase, and special characters – like @#$%^&*). Adding just one capital letter and one asterisk would change the processing time for an 8 character password from 2.4 days to 2.1 centuries.

Remember, these are just for an average computer, and these assume you aren't using any word in the dictionary. If Google put their computer to work on it they'd finish about 1,000 times faster.

Now, I could go on for hours and hours more about all sorts of ways to compromise your security and generally make your life miserable – but 95% of those methods begin with compromising your weak password. So, why not just protect yourself from the start and we can all sleep better at night?

Believe me, I understand the need to choose passwords that are memorable. But if you're going to do that how about using something that no one is ever going to guess AND doesn't contain any common word or phrase in it.

Here are some strong password tips:
  • 1.Randomly substitute numbers for letters that look similar. The letter ‘o' becomes the number ‘0′, or even better an ‘@' or ‘*'. (i.e. – m0d3ltf0rd… like modelTford)
  • 2.Randomly throw in capital letters (i.e. – Mod3lTF0rd)
  • 3.Think of something you were attached to when you were younger, but DON'T CHOOSE A PERSON'S NAME! Every name plus every word in the dictionary will fail under a simple brute force attack.
  • 4.Maybe a place you loved, or a specific car, an attraction from a vacation, or a favorite restaurant?
  • 5.You really need to have different username / password combinations for everything. Remember, the technique is to break into anything you access just to figure out your standard password, then compromise everything else. This doesn't work if you don't use the same password everywhere.
  • 6.Since it can be difficult to remember a ton of passwords, I recommend using Roboform for Windows users. It will store all of your passwords in an encrypted format and allow you to use just one master password to access all of them. It will also automatically fill in forms on Web pages, and you can even get versions that allow you to take your password list with you on your PDA, phone or a USB key. If you'd like to download it without having to navigate their web site here is the direct download link. (Ed. note: Lifehacker readers love the free, open-source KeePass for this duty, while others swear by the cross-platform, browser-based LastPass.)
  • 7.Mac users can use 1Password. It is essentially the same thing as Roboform, except for Mac, and they even have an iPhone application so you can take them with you too.
  • 8.Once you've thought of a password, try Microsoft's password strength tester to find out how secure it is.
Guard email passwords
Another thing to keep in mind is that some of the passwords you think matter least actually matter most. For example, some people think that the password to their e-mail box isn't important because "I don't get anything sensitive there."

Well, that e-mail box is probably connected to your online banking account. If I can compromise it then I can log into the Bank's Web site and tell it I've forgotten my password to have it e-mailed to me. Now, what were you saying about it not being important?

Drive-by Hacking
Often times people also reason that all of their passwords and logins are stored on their computer at home, which is safe behind a router or firewall device. Of course, they've never bothered to change the default password on that device, so someone could drive up and park near the house, use a laptop to breach the wireless network and then try passwords from this list until they gain control of your network — after which time they will own you!

Pay attention
Now I realise that every day we encounter people who make a lot of noise and over-exaggerate points, to move us to action or for their own benefit, but trust me this is not one of those times. There are 50 other ways you can be compromised and punished for using weak passwords that haven't been mentioned.

I also realise that most people just don't care about all this until it's too late and they've learned a very hard lesson. But why don't you do yourself a big favour and take a little action to greatly strengthen your passwords. You know it makes good sense.

Wednesday, January 6, 2010

The Future of IT Project Management Software - Business Technology Leadership

The Future of IT Project Management Software - Business Technology Leadership

Today's information technology organisations are responding to the most treacherous recession in memory. Their actions range from classic belt-tightening to innovating and improving value-added services in their organisations. A primary value-adding strategy for the most effective organisations is to further improve project management.

In view of this strategy, the project management software industry's future looks especially promising. During the global recession, industrial countries around the world devoted billions in economic stimulus funds for infrastructure and other projects. This has created considerable demand for project management software.

Cybersitter is suing the Chinese government for piracy and breach of copyright

A US software maker is suing the Chinese authorities and seven major computer maker, including; Sony, Toshiba, Lenovo, etc. Cybersitter is accusing China of openly pirating its Cybersitter content filtering software and using it for their own purposes.

The federal lawsuit has been filed in Los Angeles by Cybersitter and the compensation demanded is $2.2 billion (£1.37 billion).

The company alleges that the Chinese authorities have blatantly copied its codes and incorporated them into their 'citizen security' software. This software is used to monitor and block Chinese citizens' ability to access sites deemed politically undesirable by the government.

Cybersitter software was originally designed to help parents monitor and filter content seen by children.

The seven computer manufacturers, including Sony, Lenovo, and Toshiba, that are also being cited in this lawsuitsued, have been distributing the Chinese 'citizen security' software program with PCs sold in the country.

This was forced on PC manufacturers who wanted to distribute their products in China. It was done to comply with a mandate from the Chinese authorities to ensure that no computers were sold in China without the 'security' software bundle on it. This mandate was later amended.

Thursday, August 13, 2009

Chinese Government Backdown on Censorship Software

In a previous blog we reported on the Chinese Government IT ministry's order to compulsory install censorship software on every computer in China.

Thankfully, this order has now been withdraw and the Chinese Government has climbed down and put the legislation on hold.

Advocates of free-speech and human rights said that the program was a clear attempt by the Chinese government to extend its control and censorship of political opinions, from public places into people’s living rooms.


The contentious order was first issued last May 19, and had stirred an outcry from Chinese Internet users and foreign computer manufacturers alike, arguing that the software ran counter to China’s proclaimed goal of creating an information-based society.


Although the government insists that the program is meant to shield children from online pornography and paedophiles, its filter is automatically updated by the government and targeted many topics with political overtones.

From a comercial viewpoint, the United States also warned China that the installation requirement would be seen as a violation of world trade regulations.

Green Dam Software
The information ministry previously had suspended the Green Dam pre-installation mandate on June 30, one day before it was to take effect, saying that computer makers needed more time to accommodate it as a pre-installed package in their manufacturing process.

Pre-installed on new computers
The statement by Mr. Li appeared to make that initial suspension, more permanent. Mr. Li said the government would neither require the program to come pre-installed on new computers or force computer makers to include the program on a CD with other optional software.

Lenovo, Acer and Sony
A few Asian computer manufacturers, led by China-based Lenovo, Taiwan’s Acer, and Japan's Sony, nevertheless, include the software on computers sold in China for fear of being barred from a lucrative market.

Filtering remains Mandatory for Public Internet Users
Although Mr. Li’s concession is a step backward for the Green Dam program, the software remains mandatory in schools, Internet cafes and other sites used by scores of millions of people.

The government already takes extraordinary steps to monitor computer use in Internet cafes, which remain common in a nation where owning a computer remains a comparative luxury.

Only 25% of Chinese people have access to a computer and the Internet. This number is equal to the entire population of the US and is growing.

Tuesday, August 4, 2009

The Unwritten Laws of Luddite Technology

What are the Basic Luddite PC Tech Laws?

Let's start with the so-called 'Brains of the Outfit', the 'Nerve Centre' - The PC, Laptop, Mac or 'computer'

  • Law 1: For every fix that a Windows Update patch fixes, the update will break two other things on your PC
  • Law 2: The risk that Windows will need to automatically install time-sucking critical updates on your PC, is directly proportional to your need to get your PC started
  • Law 3: The hard drive always fails just before you were going to back it up.
  • Law 4: Your data will get corrupted just before you plug in your new backup external drive or will be corrupted when plugging in your backup device..
  • Law 5: Your backup plan is only as good as your last successful restore.
  • Law 6: The number of USB ports on your PC or Mac will always be one less than you need at any given time.
  • Law 7: Feeling the time pressure on you to fix a computer quickly, will cause you to take longer.
  • Law 8: If you close the PC case and tighten all the screws before testing it, it won't work; If you test it before closing the case, it will be OK.
What are The Luddite Tech Support Rules?
Now that you've mastered the basic technology traps, you think you're ready to move on to Tech Support.
  • Law 1: If you fix a computer for a friend or family member, you'll be their tech support for life.
  • Law 2: If you Build a computer for someone else, then he/she also owns you for life!
  • Law 3: Recommend a product that you've used with no problems, and the friend/family member who buys it will immediately descend into some sort of product return hellhole of retribution.
  • Law 4: Show any smart or handy IT skills at work, and your company's IT department will start referring all their difficult coworkers to you, the Mr Fixit Guru Guy!
  • Law 5: If it's broken and you call tech support, it will immediately fix itself while you're on hold or are still trying to press the correct buttons to get through the responding call centre's phone system.
What are The Luddite Internet Ordinances?
You can find a world of trouble online.
  • Law 1: Within a month of agreeing to be "friends" with your boss on Facebook you will regret it, big time.
  • Law 2: The crappier the Web site, the sleazier and sketchier the ads.
  • Law 3: When entering "Captcha" verification codes on a Web site, you'll always type in the numeral 1 when the site wants a lowercase L, and a capital O when the site wants the number 0.
  • Law 4: Just before taking out the boss in a WoW raid, your Internet connection will die.
  • Law 5: The difficulty involved in redeeming a rebate is directly proportional to the monetary value of the rebate.
  • Law 6: The safe draft of a nasty e-mail, will always somehow find its way to the (unintended) recipient.
What are The Luddite Precepts of Mobile Tech?
Desktop technology isn't the only source of inevitable woe in your life. All those shiny mobile devices can cause pain, too, since the freedom of untethered technology doesn't extend to immunity from rank on rank of frustrating unalterable laws.

We report 10 master Luddite Mobile Laws here.
  • Law 1: The charger for your current cell phone will not work with the next cell phone you buy.
  • Law 2: Your laptop's charger weighs half of what your laptop weighs and doesn't fit easily into the laptop carry bag.
  • Law 3: A laptop battery will drain at twice its normal rate whenever you leave home without your power cord.
  • Corollary: Your laptop's battery life is inversely proportional to the amount of work you need to get done on a single charge.
  • Law 4: Your iPod or iPhone will be on its last burst of power just as the plane door shuts.
  • Law 5: A replacement battery charger will cost 70 percent of the original purchase price of the whole device, including the laptop bag. For phones, the figure is 140 percent!
  • Law 6: Your cell phone will inevitably break before your two-year contract is up, forcing you to overpay for a new, less-cool model.
  • Law 7: The proprietary charging plug (cost to produce: 50 cents) for your device will disappear within two weeks and will cost you $40 to replace.
  • Law 8: On any vacation, a) the memory card for your digital camera will be safely lodged in the card reader on your desk at home. b) The camera's proprietary re-chargeable battery will be dead, with the charger sitting next to the card reader.
  • Law 9: A cup of coffee or fizzing drink on your desk, is guaranteed to render your laptop utterly useless.
  • Law 10: Your MagSafe adapter will always come unplugged precisely when you need to charge your Mac laptop's battery.
What are The Luddite Software Statutes?
Finally, if entanglements with hardware principles don't leave you bound and gagged, there are always software standards to render you helpless.
  • Law 1: Your software provider's online support pages contain explicit instructions for troubleshooting every conceivable problem, except yours.
  • Law 2: Nine times out of ten, tinkering with your Registry to fix a system issue will create a new and more severe problem. Did you back it up before you started? Unlikely!
  • Law 3: Ten times out of ten, downloading a spyware product will create hidden processes/services more insidious than the original malware/adware encroachment you set out to stop.
  • Law 4: The performance increase you can expect from running a Registry cleaner can be calculated as z(n + y), where n is the number of Registry entries cleaned, y is your system CPU's clock speed in gigahertz, and z = 0, or near to it.
  • Law 5: The larger the number of people who want your attractive iPhone app, the likelier Apple is to reject it.
  • Law 6: iTunes will crash. That's it. No, really.