星期六, 3月 24, 2012

Change the displayed name of CIS webmail

 問:How to change the name of user in CIS Webmail?
         如何更改 CIS Webmail 的使用者姓名?


答:
  1. Use Internet Explorer to login the account via http://wmaila.scig.gov.hk
    使用 Internet Explorer 在 http://wmaila.scig.gov.hk 登入帳戶
  2. Click Preferences
    點擊 Preferences
  3. Click Mail
    點擊 Mail
  4. Select "DefaultMailAccount[IMAP]"
    選擇 "DefaultMailAccount[IMAP]"
  5. Click Edit
    點擊 Edit
  6. Change the Name
    更改名稱
  7. Click OK
    點擊 OK

星期日, 2月 05, 2012

Mission of HKTA

Hong Kong Tennis Association
Missions
To promote tennis to all through the HKTA and collaborations with other tennis and government bodies
To set and maintain the standards of the game to an international level and to nurture talented local players to compete in regional and international tournaments
To raise the standards of tennis by organizing local, regional and international competitions
Objectives
Hong Kong Tennis Association has never deviated from its objective to promote tennis to all, to nurture talented players, and to raise the standard of the game in Hong Kong.

Programs
The HKTA organizes a number of local and international tennis events as well as junior and elite development programs, for example, star of the future, talent group, and youth athlete. Etc, a corporate training scheme, coaching certification courses, a Tennis-For-All open enrollment program, and a mini-tennis initiative for young children.

Organization Structure
The HKTA is a non-profit organization and recognized by both the Asian Tennis Federation (ATF) and the International Tennis Federation (ITF). The Association is guided by a Council whose members are elected for a two-year term. There are currently 39 member clubs affiliated with the HKTA and approximately 4000 individual members. Also, there are a nine specialized Committees that oversee particular aspects of the work of the Association, each Committee is chaired by a Councilor and supported by other council members or those knowledgeable tennis enthusiasts from the general public that are invited to participate by the respective Committees. The first is the Coaches Development Committee which includes a chairman, a vice Chairman, 8 members, 2 ex-officio members, and 5 HKTA staffs .The second is the Development Committee which includes a chairman, 4 members, 2 ex-officio Members, and 4 HKTA staffs .The third is the Education and Qualification Committee which includes a Chairlady, 7 members, 2 ex-officio Members, and 4 HKTA staffs .The forth is the Elite Committee which includes a chairman, 3 members, 2 ex-officio members, and 5 HKTA staffs . The fifth is the Executive Committee which includes a president, 3 vice presidents, Honorary Secretary, and Honorary TreasurerThe sixth is the League Management Committee which includes chairman, immediate past chairman, president, league secretary, 11 members and 3 HKTA Staffs .The seventh is the Membership Services Committee which includes chairman, 6 members, 2 ex-officio members and 3 HKTA staffs .The eighth is the Officiating Committee which includes chairman, 8 members, 2 ex-officio members, 3 HKTA staffs .The last is the Tournament Committee which includes Chairman, 7 members, 2 ex-officio members, 5 HKTA staffs . 

In Hong Kong Tennis Association, it includes patrons and council. For patrons, there are three main patrons, the Life Patrons Dr. Stanley Ho, GBS, the Honorary Patrons the Hon. Ronald Arculli, GBS, JP Mr. L Cyril Kotewall, and the Patron Mr. Hu Fa-kuang, GBS, JP

In Hong Kong Tennis Association Council, there six officers of the association, the president, the Hon. Secretary, the Hon. Treasurer, and three vice president. Also, it includes nine councilors

星期六, 2月 04, 2012

Past paper for HKIT (GE150 - Information Systems / ISY10212 - Contemporary Issues in MM and IT / IT106 - Information Systems and Multimedia)


EXAMINATION FOR TERM OCTOBER 2009
Course:
1. Associate Degree of Science in Computing and Information Technology
2. Associate Degree of Business Administration


Subject:
IT106 Information And Multimedia Systems
All the documents need to be submitted to CMS on or before 5pm, 22nd Jan 2010 (Friday)


Instructions to Students:
This is a take home exam. Students are required to finish 4 forum discussions and one report.
  1. For each forum, contributions need to display an understanding of multiple perspectives regarding the issue under discussion. Specific positions are encouraged, but need to be argued based upon critical thinking and utilize published materials from the media and academic literature. Each discussion should have a words length of 300 words to 600 words.
  2. Write a report which identifies, discusses and assesses a current issue in the area of Multimedia and Information Technology. Particular attention should be given to any social, cultural, ethical, and legal implications of these new technologies. The report should have a words length of 2500 words to 3500 words.


(5 marks)


What is privacy in the modern world?
What role does celebrity play?
How does Multimedia and Information Technology impact upon privacy and celebrity?


In recent days the death of Michael Jackson has received blanket coverage in conventional news media (newspapers, radio news and television news).

Other media have been dealing with high volumes of traffic too. Google thought that it may have been under cyber attack due to the very high rate of inquiries of "Michael Jackson" that happened with such an immediacy in time.
(See: http://www.smh.com.au/technology/technology-news/jackson-queries-cause-google-meltdown-20090627-d06w.html)

Some people are literally born as a celebrity - these are the princes and princesses of this world who inherit a role in public life from their parents, the kings and queens. There are very few such people left on the planet, and their level of celebrity may be localized to just a few countries.

All other celebrities are "produced" or "manufactured". Movie stars (especially when married to each other, as are Angelina Joli and Brad Pitt) are a marketers dream. Prominent sports and music stars (again, especially when married as are Victoria (Posh Spice) and David Beckham) can no longer live their private lives privately. Event such as births of children along with the disruptions or unhappiness that occur in family life such as separations and divorce, are played out in the public media whenever they occur.

Why is this so? And what are the rights and wrongs of this? After all, if the general public payed no attention to these "stories" then they would not appear in the news media because they would not be the material that sold papers, or gained viewers or was considered to "be news".


Forum 2: First Person Computer Games.

(5 marks)

What are the implications?
Can these games be seen as training young users to commit acts of violence?


Check out this site:
http://www.smh.com.au/digital-life/games/outrage-as-terrorist-game-lets-players-massacre-civilians-20091029-hmey.html?autostart=1
There was a documentary aired last night (4/10/09) on SBS about "The Samurai", a TV series produced in the 60's and 70's which achieved a cult status in the minds of Australian children at the time. It was the first TV series that produced a range of merchandise associated with a show in Australia.
http://www.tvseriesgalore.com/blog/?p=2217
Lots of school kids at the time were crazed about the show and although the merchandise consisted mainly of ninja costumes and plastic swords, many took to using tin-snips to fabricate their own star knives from discarded tin can lids.



(5 marks)

What is privacy in the modern world?
What role does threats to security play?
How does Multimedia and Information Technology impact upon privacy and security?

Last week the headlines were again reporting hotel bombings in Indonesia (http://www.aol.com.au/news/story/Jihad-in-Jakarta/2348587/index.html), resulting in several deaths.

Such bombings are not isolated to Indonesia.

The flying of airplanes into the twin towers of The World Trade Center in the U.S.A on September 11th 2001 captured lots of media attention. In part because of the severity of the event, but perhaps also because of the extreme nature of the footage that had been captured (both the crashing of planes into the buildings, and the crashing of the buildings to the ground).
Be warned, explicitly graphic but for example, see: http://www.youtube.com/watch?v=1lKZqqSI9-s. Several thousand people died as a direct result.

This event changed the political relationship between some countries of "the west" and groups considered to be aligned with Islamic fundamentalism, which was identified as being responsible.

The reality is that whatever the politics of the situation, bombings of public figures and public spaces (trains, buses, airplanes, hotels, restaurants, weddings) has become a relatively more common strategy employed by some groups and the location for such events has clearly become more globalised.

Information and Communication technologies such as mobile phones, email, and internet sites have been used to plan, coordinate and execute some of these attacks. Consequently, many governments have sought to modify their countries' laws regarding privacy and communications to enable greater surveillance (with varying degrees of success).

What are the rights and wrongs of such a trend towards increased surveillance? Are you happy with such a state of affairs? Does it make you feel safer? Does it make the world safer?




Forum 4: Public Information and Politics.

(5 marks)

What is public information in the modern world?
What role does politics play?
How does Multimedia and Information Technology impact upon free speech and politics?
------------------------------------------------------------
In democratic countries “freedom of thought” and “freedom of speech” are fundamental to the political process.

Freedom of thought maintains that all people have the right to think for themselves, including with respect to political issues. Freedom of speech is the right to voice publicly ones’ thoughts, without fear of reprisal from the government of the day (nor from one in the future).

The underlying ethic which drives a democracy is the principle that the people of a country, through a voting system, have the right to elect the government of that country. This enables the collective will and wisdom of the people of a nation to take responsibility for their countries future.
In democratic countries the power to determine what appears in newspapers, television and radio is generally held by the businesses that run these media. In non-democratic countries the power to determine what is presented in the newspapers, television and radio is generally held by the government.

In recent years the internet has provided a means by which any individual who holds knowledge on how to upload information and who has access to the hardware and software required, can present to the public domain any information he or she chooses to present. This can be something as benign as a recipe for fried rice, or something as destructive as a recipe for explosives. The information uploaded can also be (and often has been) of a political nature.

Governments, both democratic and non-democratic, have been moving towards increasing restrictions placed upon the nature of the content that can be presented and received on the internet. But the type of content chosen to prohibit will bring into contrast the views of governments in democratic countries compared to those in non-democratic countries.

Discuss.


Report on contemporary issue in multimedia and Information Technology

(40 marks)
Students are encouraged to select a specialised topic area focussing on a contemporary issue in multimedia and Information Technology. It will enable you to undertake detailed study in an area:
-  in which you hold intrinsic interest
-  that has specific relevance and application to an aspect of you personal and/or professional life either currently or in the future
-  that you will find more motivating, and strive to achieve a higher quality product
-  that you will embrace, and experience higher levels of self satisfaction, and
-  that you will gain greater generic knowledge, skills and attitudes regarding research and the production of reports.

星期五, 2月 03, 2012

Individual assignment - Hong Kong Tennis Association

Individual assignment-


    Hong Kong Tennis Association is an association to promote tennis, raise the standards of tennis by organizing competitions. Yet, no any association is perfect. It must have some improvements for it to become much better. And Hong Kong Tennis Association should have improvements of public relations.
    First and foremost, Hong Kong Tennis Association is deficient in media publics. Publics can only get in touch with it by access its website or visit its office. Lack of media reports the news about Hong Kong Tennis Association’s campaigns. Media is the biggest channel to make connections between publics and the association. Hence, it should be suggested when it holds some campaigns just like competitions in local or “Fun Day”, it is better to invite some famous people in order to attract media to come and report aims to make publics to know about Hong Kong Tennis Association.
    What is more, Hong Kong Tennis Association does not have any seminars to public. It just has some seminars for people who want to be coaches. The recommendation of it should be hold some seminars in primary or secondary schools or shopping malls that can let publics to feel more connected to it. It is because it let children to get in touch of tennis if it holds seminars in schools and let parents to know and let their children to play tennis through seminars in shopping malls.
    Apart from the inadequate of seminars, exhibitions are also important to Hong Kong Tennis Association because it has none of exhibitions to publics. It should be recommended to have exhibitions including to display information about Hong Kong Tennis Association by the broads, and to show the figures about tennis court, tennis ball, tennis racket or even some famous tennis player with details, of course including leaflets about the upcoming events and application forms of Hong Kong Tennis Association.
    Another recommendation for improvement to Hong Kong Tennis Association is the community service. It held a fun day on March before. However, it is not enough and also people want to join the fun day should register before. It is so troublesome to join it that people need to register. Free of charge of fun day is attractive to publics but it is better for publics to join it without register due to the problem of public do not know Hong Kong Tennis Association so much.
    All in all, Hong Kong Tennis Association should have more improvements of public relation because tennis is not really very common relatively for other sports in Hong Kong. If Hong Kong Tennis Association can improve public relations more, it effectively to let community can get in touch with it more. It will increase more people to play tennis and want to know more about tennis voluntarily. Therefore, Hong Kong Tennis Association is better to have improvements of public relations.

星期二, 1月 31, 2012

星期六, 11月 19, 2011

罕見血病青年急求藥費續命



27歲的冲仔患上罕有白血病,每 3個星期需要 13萬元購買自費藥吊命。梁御和攝

2011-11-10

生命無價,治病卻有價! 27歲的冲仔初踏社會,對人生充滿盼望,卻被罕有白血病襲擊,數月間雙目幾近失明,現依靠每三星期逾 13萬元的自費藥吊命,並等候配對合適骨髓進行移值。最禍不單行是傾盡積蓄為他支付藥費的母親近日又發現乳房有腫瘤,令瀕臨斷藥的樂仔深受打擊。不甘生命就此消逝的他撐起軟弱的身軀求援,盼善心人助他重燃生命之火。
「我希望可以好番,照顧阿媽!」現在沙田威爾斯親王隔離病房的冲仔,癌細胞攻擊雙眼致視物模糊,目無焦點地說:「我已經幾個月未返過屋企,醫生幫我做過一、二線化療療程都冇效。之後醫生話我眼球內出現血塊,家只可以睇到模糊光影」。

自費療程每次需 13萬元
今年五月,原本身體健壯的冲仔發現頸部腫起,全身出現瘀痕,入院檢查後確診為急性淋巴細胞白血病。數年前大專畢業的冲仔在政府部門任職合約制電腦工程人員,他不斷進修,一直以成為正式公務員為目標,奈何患上惡疾,人生計劃被打破,生命更一度危在旦夕。醫生見冲仔年紀尚輕,建議他嘗試一種香港較少用的自費藥物 Nelarabine療程,每三星期一次,每次需費 13萬元。冲仔父母動用所有儲蓄,讓他注射了兩針,初步效果理想,癌細胞指數下降至 10%。到醫院日以繼夜照顧兒子的冲母焦急地說:「醫生 8月時已經幫佢搵骨髓,醫生話大概要等半年,呢段時間要好好控制病情,估計仲要等多三個月,要捱到做移植,估計藥費隨時過百萬」。


冲仔年輕時身體健康,料不到突然患上惡疾。


冲仔幼時樣子精靈可愛,圖為與父母及姊姊合照。

母親驗出胸部有腫瘤
冲仔患病後停工,生活全賴任職三行工人的父親支持。父母為救他騰出畢生積蓄,惟藥費高昂,根本無法繼續支持。看到父母為自己憂心,媽媽更可能因此憂出病來,冲仔深感歉疚,「阿媽之前驗身發現胸部有腫瘤,家等候進一步化驗係咪惡性,我好擔心」。他希望可繼續用藥保住性命,趕及找到合適骨髓移植,得以康復,報答父母劬勞。
在病旁侍候兒子的冲母聽見兒子孝心,雙眼發紅說:「佢可以好番,開開心心咁生活,已經係最大嘅報答」。母慈子孝,還望社會善長集結力量,以實際行動給予他們支持,讓冲仔好好地活下去。
「冲仔」捐款編號: C3122

網上捐款: http://hk.charity.nextmedia.com/site/index.php?fuseaction=site.donate

星期二, 9月 20, 2011

TAKE ASSESSMENT: TEST 7 TOPIC 7

Take Assessment: Test 7 Topic 7      
Name Test 7 Topic 7
Instructions Instructions:
   1. You have 30 minutes to complete this test
   2. You only have one attempt and must finish it once started
   3. Answer all 6 questions
Timed Assessment This Test has a 30 minute timer.The elapsed time appears at the top right of the window.
A 1 minute warning will be displayed.
Multiple Attempts Not allowed. This Test can only be taken once.
Force Completion This Test must be completed now. 

       

   Question 1   
  Which below are elements of a security audit and alarms model? (15.2)
 A. System logs, email logs and apache logs
 B. Operating system updates / patches, application updates / patches and anti virus updates
 C. Audit analyzer, security reports, archives and security audit trail
 D. None of the above
 

From the text, Stallings & Brown (2008), page 477 and 478, the elements of a security audit and alarms model are described as follows;

• Event discriminator: The is logic embedded into the software of the system that
monitors system activity and detects security-related events that it has been
configured to detect.
• Audit recorder: For each detected event, the event discriminator transmits the
information to an audit recorder. The model depicts this transmission as being in
the form of a message. The audit could also be done by recording the event in a
shared memory area.
• Alarm processor: Some of the events detected by the event discriminator are
defined to be alarm events. For such events an alarm is issued to an alarm
processor. The alarm processor takes some action based on the alarm. This action
is itself an auditable event and so is transmitted to the audit recorder.
• Security audit trail: The audit recorder creates a formatted record of each event
and stores it in the security audit trail.
• Audit analyzer: The security audit trail is available to the audit analyzer, which,
based on a pattern of activity, may define a new auditable event that is sent to the
audit recorder and may generate an alarm.
• Audit archiver: This is a software module that periodically extracts records from
the audit trail to create a permanent archive of auditable events.
• Archives: The audit archives are a permanent store of security-related events on
this system.
• Audit provider: The audit provider is an application and/or user interface to the
audit trail.
• Audit trail examiner: The audit trail examiner is an application or user who
examines the audit trail and the audit archives for historical trends, for computer
forensic purposes, and for other analysis.
• Security reports: The audit trail examiner prepares human-readable security
reports.



   Question 2   
  Which of the following *are* supported by the Cisco Systems' "Monitoring, Analysis and Response System (MARS)"?
 A. Network devices: Cisco software
 B. Firewall / VPN devices
 C. Intrusion detection software
 D. Anti virus
 E. Applications: Apache IIS web servers
 F. All of the above  G. None of the above
 
Refer to your text, page 503, Computer Security Principles and Practice, Stalling & Brown, 2008.


   Question 3   
  Which of the following statements best describes "system-level audit trail"? (15.5)
 A. traces the activity of individual users over time
 B. captures data such as login attempts, both successful and unsuccessful, devices used, and OS functions performed
 C. generated by equipment that controls physical access and then transmitted to a central host for subsequent storage and analysis
 D. may be used to detect security violations within an application or to detect flaws in the application's interaction with the system

Four different categories of audit trails are;

System-level audit trails: captures data such as login attempts, both successful and unsuccessful, devices used, and OS functions performed

Application-level audit trails: may be used to detect security violations within an application or to detect flaws in the application's interaction with the system.

User-level audit trails: traces the activity of individual users over time.

Physical access audit trails: generated by equipment that controls physical access and then transmitted to a central host for subsequent storage and analysis.




   Question 4   
  Which of the following areas (categories of data) should audit data be collecting? (15.4)
 A. deletion of objects
 B. identification and authentication functions
 C. printout of data
 D. use of access rights to bypass a policy check
 E. All of the above  F. Only A, B and D above

All actions that may effect access to data are to be collected by audit data.

The following are all categories of data that audit data should collect;

• Introduction of objects within the security-related portion of the software into a
subject’s address space
• Deletion of objects
• Distribution or revocation of access rights or capabilities
• Changes to subject or object security attributes
• Policy checks performed by the security software as a result of a request by a
subject
• The use of access rights to bypass a policy check
• Use of identification and authentication functions
• Security-related actions taken by an operator and/or authorized user (e.g.,
suppression of a protection mechanism)
• Import/export of data from/to removable media (e.g., printed output, tapes,
disks)



   Question 5   
  Which of the follow need to be understood to perform effective reviews and analysis of an organisation's systems audit logs?
 A. characteristics of common attack techniques
 B. organisations policies regarding acceptable use
 C. the operating systems and major applications
 D. security software used on hosts
 E. brand computers purchased by each department of the organisation
 F. All of the above
 G. Only A, B, C and D above
The brand of computers purchased is not relevant, but all other points listed are needed to be understood to review and analyse an organisation's systems audit logs.

Refer to your text, page 498, Computer Security Principles and Practise, Stalling & Brown, 2008.  


   Question 6   
  Audit logs that track user activity on an information system provide __________.
 A. identification
 B. authorization
 C. accountability  D. authentication

星期四, 8月 11, 2011

Mor-Christian General Soccer Ability Skill Test Battery

Introduction
Soccer is one of the popular sports in the world, as there is a very large number of people that play football at different levels. According to a survey conducted by FIFA published in 2008, over 300 million people from more than 200 countries regularly play football. As a result, we can see that effective skill tests are vitally important for placement, grading, diagnosis in various levels, since sport skill test is an instrument that elicits an observable respone which provides information about motor skill used in a sport.
Mor-Christian General Soccer Ability Skill Test Battery(Mor & Christian, 1979) is one of the soccer tests that evauate passing, dribbling and shooting ability in soccer. Here, the content of the tests will be discussed and evaluated in the following part. On the contrary, there are the suggestions on improving the quality of the test that instructors not only administer the tests smoothly, but also test the subjects’ ability widely.

a)    Mor-Christian Soccer Dribbling Test
( Validity-0.73 , Reability-0.80 )
There are many good criteria in this test, including short period of time for administering, equipments, human resource, availability of venue and objectives. In this test, there is a short period of time, around 2 minutes for each subjects. Besides, few human resources and equipment are required, so that the test is easy for setting and administer. But large area is oocupied by the circular path in this test, some testing area may not provide sufficient area to carry out various tests at the same time. Actually, it is good for students that three trials are allowed in this dribbling test, as the learning effect is a key factor to reduce the relibility, so trials can help the subjects to familiarize the testing procedures. Moreover, clockwise and conterclockwise direction are required to finish that the test is suitable for real situation, soccer need to dribble in all direction continually in the match, not only in their dominant direction. However, there are some suggestions in this test. The first one is the distance between cones. In the outline of setting, there is 5 yds among the cones within the path, but too long distance may cause the reduction of validity and reliability. Dribbling refers to the maneuvering of a ball around a defender through short skillful taps or kicks with either the legs, excess time is allowed for dribblers to co-ordinate their body and it is easy to dribble all the cones if there are too long distance among the cones. In fact, players in the competition often execute dribbling in the short distance from the defenders, so the distance is suggested to reduce from 5 yds to 3.5 or 4 yds, and it can let the subjects in dribbling test as well as real situation. The second suggestion is that  subjects’ liner-dribbling ability can be tested, not only in circulat direction. Since players also face the challenges face to face in the match, so the liner-dribbling part is suggested to follow the circular dribbling, this combination can fit in real situation and increase the validity of the test.

b)    Mor-Christian Soccer Shooting Test
( Validity-0.78 , Reability-0.96 )
This shooting test can verify the shooting ability exactly, especially for the soccer attackers, as it can test the object shooting accuracy. However, shooting power is not tested and scoring scheme has a contridiction. Shooting ability is mainly consist of accuracy, power and speed, and the speed is a key factor to determine the quality and the chance of scoring, but this test just test subject’s shooting accuracy only. Also, the scoring scheme has conflict that the score is counted even subjects shoot at the other corner which is not they claimed, since there is a large difference in shooting two opposite concer, so the instruction of scoring scheme is not clear and unintelligible.
Actually, there are many reasons that it is quite difficult to administer this shootiing test. First of all, time consuming is factor that every subject consume much time to finish all of the trials, around five to six minutes, so an inconvenience may be caused. Second is about the availability of venue, because not all of the testing area contain a standard goal or sufficient area for setting, so this test is limited by small venue. Thirdly, many equipments are required for setting this test when it compares with another two tests, so it increases the difficulty in setting.

c)     Mor-Christian Soccer Passing Test
( Validity-0.91 , Reability-0.98 )
This passing test has the highest validity and reability in these three tests, it prove that it has  good criteria for a sport skill test, however, it also has some drawbacks.
There are few equipments in this test like the dribbling test metioned before, so instructors can prepare the test easily. Nevertheless, subjects consume a lot of time to finish all of the passing tests in different positions when it compares with other two soccer tests , around 4 minutes for each subject. Furthermore, it requires many human resources to keep the fluency of the test. For the objectives, the test is good for subjects’ passing abiliy, since the proper distance and several passing direction in the test are essential for a soccer match and it can explain why there are the high validity and reability. On the other hand, the test result may not reflect actual ability. It is because players will not pass the ball on the fixed points like this passing test if they play in the match. Players need to run and then pass the ball continually, so this passing test is not fit to test subjects’ actual passing ability. Moreover, ability of long pass is not involved in the test, so long pass testing is suggested to administer, as long pass is an important part in soccer, it is used in defenders and side attackers normally.

Conclusion
are the basic skills in soccer, it is necessary to test players’ ability of these aspect. Mor-Christian General Soccer Ability Skill Test Battery is one the the good tests to evaluate although there are some suggestions for improvement. In fact, not only these three aspect, many skills are also required for a good soccer player. For instance, agility and header are two of the important skills in soccer, perhaps it is better that various parts are included beside dribbling, passing and shooting and test the subject comprehensively.

星期日, 7月 24, 2011

乳字的意思

老師給小朋友解釋:“乳”就是“小”的意思。
比如“乳豬”就是“​小豬”,“乳鴿”就是“小鴿”。
小明,請你用“乳”字造個句。

小​明:我家經濟條件不太好,只能住 20坪的乳房。
老師: (我暈)這個不行。換一個。

小明:我每天上學都要跳過我家門口的​一條乳溝。
老師:(暈死)不行,再換一個。

小明:老師,我想不出​來了。把我的乳頭都想破了。

星期日, 7月 17, 2011

REVIEW ASSESSMENT: TEST 3 TOPIC 3

REVIEW ASSESSMENT: TEST 3 TOPIC 3

Question 1
Which of the following best describes a relational database? (5.2)
Question 1 answers
A. A relational database uses a single file to store data sequentially.
B. A relational database is a collection of tables (also called relations).
C. A relational database organises its data in a tree-like structure.
D. None of the above.
E. A and B and C.

Question 2
How many primary keys and how many foreign keys are required in a relational database? (5.3)
Question 2 answers
A. One primary key and zero or more foreign keys.
B. Every table must have one primary key and one foreign key.
C. None, as primary keys and foreign keys are not always required.
D. None of the above.

Question 3
Which statement below best describes a Decentralized Administration Policy? (5.4)
Question 3 answers
A. A small number of Administration users may grant and revoke access rights.
B. The owner (creator) of any table reserves all rights to grant and revoke access rights to each table that he or she has created.
C. In addition to granting and revoking access rights to a table, the owner of a table may also grant and revoke authorisation to other users, allowing them to grant and revoke access rights to the table.
D. There needs to be at least one Administration person in each organisational unit of a company who can grant and revoke access rights to any specified table.
E. All of the above

Question 4
Which statement below best describes an inference threat to a RDBMS? (5.6)
Question 4 answers
A. An inference threat arises when an unathorised person has gained access to a database.
B. An inference threat arises when the database administrator allows remote connections to the database server.
C. An inference threat arises when the database table structure is known to be poorly designed.
D. An inference threat arises when the combination of a number of data items can be used to infer data of a higher sensitivity.

Question 5
Which statement below best describes perturbation? (5.8)
Question 5 answers
A. Provides answers to all queries, but only to authorised users.
B. Provides answers to all queries, but the answers may be approximate.
C. Provides answers to all queries, but the user identification of the querry is logged.
D. Only provides answers to queries that are not classified as secret.

Question 6
Which statement below best identifies the disadvantages of database encryption? (5.9)
Question 6 answers
A. Key management
B. Insecurity
C. Inflexibility
D. Vulnerabilities
E. Both A and B
F. Both A and C
G. Both B and C
H. Both C and D

星期日, 7月 10, 2011

Essay - Let's put a halt to capital punishment

  Capital punishment, also known as death penalty or execution, is the most extreme sentence which can be devised in about 59 countries including China, Japan and the United States of America nowadays, according to Amnesty International’s figures in 2008. While more and more people actually come to realize problems of practicing capital punishment, yet, supporters insist on claiming that it is the most effective way to deter people from committing crimes. They continue to think that capital punishment is the only proportionate compensation for the victims whereas life imprisonment will solely cause a high cost which is ultimately paid by our hard-working and observant taxpayers unfairly. At first glance, their claims may seem reasonable and unassailable. However, you will probably find the flaws when you examine closer.

  First and foremost, capital punishment may actually be practiced to kill people who have not committed any crimes mistakenly or deliberately. For instance, with the help of advanced technology such as DNA investigation, 23 people executed in the United States of America in the 20th century have actually been found guiltless. Doubtless, there is absolutely no way that can compensate these innocent people who were killed only because of wrong judgment. Yet, this kind of tragedies actually happens in most, if not all, of the other countries across the globe exercising capital punishment. In China, for example, a man called Tan Hang Sin was convicted to have killed his own wife and executed 16 years ago. Surprisingly, his wife was found to be still alive later. How ridiculous it is! Capital punishment is initially established to help uphold justice, protect people and penalize criminals. Ironically, it is now practiced to kill sinless people and just let criminals go free! How many harmless people should actually sacrifice before countries exercising capital punishment finally wake up? Worse still, capital punishment is sometimes utilized by dictators or dictatorial governments to extinguish their opponents deliberately. North Korean former president, Kam Tai Chung, was once accused of betraying North Korea and sentenced to capital punishment. However, the underlying reason why he was sentenced to capital punishment was that he was the leader of an opposition party at that time. It is undeniable that such kind of abuse of capital punishment still really exists in some countries around the world. Capital punishment actually becomes a form of witch hunt.

Aside from the tragedies which may be caused by capital punishment, legal sanctions should also in no way be regarded as a means for victims or their family members to take revenge on criminals. Honestly, when people get offended, it is common and normal for people to firstly think of taking revenge. “An eye for an eye and a tooth for a tooth” seems likely to be the first sentence springs up in our mind. Nevertheless, it is also true that we should all know and be reminded that taking revenge is useless and meaningless. Victims can never be brought back to life even when the criminals are killed. However, if the criminals are executed, they will surely lose a precious chance to turn a new leaf and more families will lose their family members forever and ever. There is a Chinese saying that “Do unto others as you would be done by”. When you have lost your beloved family members and you know the pain of this, you should never support capital punishment to cause others to suffer. After all, “an eye for an eye only ends up making the whole world blind”.

Apart from uselessness and meaninglessness of capital punishment, ethical problems should also be considered thoroughly. As a matter of fact, no-one in the world should be allowed to end any others’ lives for any reasons. Isn’t it nonsensical that we claim that we respect human life but we do not respect criminals’ lives at all? Isn’t it absurd that we claim that killing is wrong but we keep on killing criminals at the same time? I am sure that no-one will deny that life is precious. I find it especially preposterous to say that we should support capital punishment because many prisons are over-crowded and under-funded now and life sentence will cause a huge burden for our taxpayers. Not to say that prisoners can actually carry out some kinds of social services in jail to keep themselves productive, should a human life be anyway weighted like this? No way! How can we support to kill someone because he or she will become a burden of our society? It is really totally non-sense. Besides, Studies in the United States of America show that capital cases actually cost between $1 million and $7 million from arrest to execution. Nevertheless, life sentence cases only costs about $500,000, which is only half of the cost of capital cases. There is actually no more ridiculous excuse for us to support capital punishment.

  In conclusion, capital punishment is actually a bane in disguise. Although it may seems that capital punishment can deter people from committing crimes, it is also capital punishment that causes more and more tragedies to make more and more people killed “legally”. Besides, acceptance of capital punishment definitely implies that taking revenge is a decent thing to do whereas it is definitely not. We should, thus, immediately stop this kind of wrong message from being passed on to the public and to our next generation. Another thing that we should immediately make clear is that life is doubtlessly invaluable and that criminals’ lives are also doubtlessly invaluable. No-one should be allowed to take away any others’ lives and high costs should not be a reason to support capital punishment. Therefore, it is my firm belief that capital punishment should be abolished at once under all circumstances and it is high time for all countries in the world to wake up to figure out what capital punishment really brings us. As the old saying goes, “to err is human”. We all have made some mistakes in our life and we all hope that others can forgive us and give us a second chance. So, why can’t we just also give all criminals a second chance?

星期二, 6月 14, 2011

Take Assessment: Test 4 Topic 4

Question 1
Which of the following is NOT identified as a intruder "class"? (6.1)

A.
 

B.
 

C.
 

D.
  

The following are identified by the text (page 177) as intruder classes;

1. Masquerader: An individual who is not authorized to use the computer and who
penetrates a system's access controls to exploit a legitimate user's account.

2. Misfeasor: A legitimate user who accesses data, programs, or resources for which
such access is not authorized, or who is authorized for such access but misuses his
or her privileges.

3. Clandestine user: An individual who seizes supervisory control
of the system and uses this control to evade auditing and access controls or to
suppress audit collection.

Question 2
Which of the following is NOT a desirable characteristics of an IDS? (6.5)

A.
 

B.
 

C.
 

D.
 

E.
 

F.
 

These are desirable characteristics (specified in textbook, p 183) of an IDS;

•Run continually with minimal human supervision.
•Be fault tolerant in the sense that it must be able to recover from system crashes
and reinitializations.
•Resist subversion. The IDS must be able to monitor itself and detect if it has been
modified by an attacker.
•Impose a minimal overhead on the system where it is running.
•Be able to be configured according to the security policies of the system that is
being monitored.
•Be able to adapt to changes in system and user behavior over time.
•Be able to scale to monitor a large number of hosts.
•Provide graceful degradation of service in the sense that if some components of
the IDS stop working for any reason, the rest of them should be affected as little as
possible.
•Allow dynamic reconfiguration; that is, the ability to reconfigure the IDS without
having to restart it. 

Question 3
Which of the following ARE useful for profile-based intrusion detection? (6.7)

A.
 

B.
 

C.
 

D.
 

E.
 

F.
 

All the following ARE useful for profile-based intrusion detection (see textbook page 186);

Counter: A nonnegative integer that may be incremented but not decremented until it is reset by management action. Typically, a count of certain event types is kept over a particular period of time.

Gauge: A nonnegative integer that may be incremented or decremented. Typically, a gauge is used to measure the current value of some entity.

Interval timer:  The length of time between two related events.

Resource utilization: Quantity of resources consumed during a specified period.

 Question 4

Which of the following best describes the "operation" of a virus or worm? (7.3)

A.
 

B.
 

C.
 

D.
 

E.
 

F.
 

Typical phases (as described by the textbook on page 220) of operation are; a dormant phase, a propagation phase, a triggering phase, and an execution phase.

 Question 5
Which of the following is NOT an effective worm countermeasure? (7.7)

A.
 

B.
 

C.
 

D.
 

E.
 

F.
 

G.
 

 A "DNS base scanning worm detector" would likely fail to detect an IM worm outbreak, because an IM worm’s attack payload will most likely be forwarded through the IM server, using the target’s user ID instead of a target IP address (Yan, Xiao,& Eidenbenz, 2008 pg 2).

See page 236 of textbook for details on the following.
Signature-based worm scan filtering: This type of approach generates a worm
signature, which is then used to prevent worm scans from entering/leaving a
network/host. Typically, this approach involves identifying suspicious flows and
generating a worm signature. This approach is vulnerable to the use of
polymorphic worms: Either the detection software misses the worm or, if it is
sufficiently sophisticated to deal with polymorphic worms, the scheme may take a
long time to react. [NEWS05] is an example of this approach.

Filter-based worm containment: This approach is similar to class A but focuses on
worm content rather than a scan signature. The filter checks a message to
determine if it contains worm code. An example is Vigilante [COST05], which
relies on collaborative worm detection at end hosts. This approach can be quite
effective but requires efficient detection algorithms and rapid alert dissemination.

Payload-classification-based worm containment: These network-based
techniques examine packets to see if they contain a worm. Various anomaly
detection techniques can be used, but care is needed to avoid high levels of false
positives or negatives. An example of this approach is reported in [CHIN05],
which looks for exploit code in network flows. This approach does not generate
signatures based on byte patterns but rather looks for control and data flow
structures that suggest an exploit.

Threshold random walk (TRW) scan detection: TRW exploits randomness in
picking destinations to connect to as a way of detecting if a scanner is in operation
[JUNG04]. TRW is suitable for deployment in high-speed, low-cost network
devices. It is effective against the common behavior seen in worm scans.

Rate limiting: This class limits the rate of scanlike traffic from an infected host.
Various strategies can be used, including limiting the number of new machines a
host can connect to in a window of time, detecting a high connection failure rate,
and limiting the number of unique IP addresses a host can scan in a window of
time. [CHEN04] is an example. This class of countermeasures may introduce
longer delays for normal traffic. This class is also not suited for slow, stealthy
worms that spread slowly to avoid detection based on activity level.

Rate halting: This approach immediately blocks outgoing traffic when a threshold
is exceeded either in outgoing connection rate or diversity of connection attempts
[JHI07]. The approach must include measures to quickly unblock mistakenly
blocked hosts in a transparent way. Rate halting can integrate with a signature- or
filter-based approach so that once a signature or filter is generated, every blocked
host can be unblocked. Rate halting appears to offer a very effective
countermeasure. As with rate limiting, rate-halting techniques are not suitable for
slow, stealthy worms.

Yan, G., Xiao, Z. & Eidenbenz, S., 2008. Catching instant messaging worms with change-point detection techniques. In Proceedings of the 1st Usenix Workshop on Large-Scale Exploits and Emergent Threats.  San Francisco, California: USENIX Association, pp. 1-10. Available at: http://portal.acm.org/citation.cfm?id=1387715 [Accessed March 14, 2010].

Question 6
Which of the following is NOT a typical USE of a BOT? (7.8)

A.
 

B.
 

C.
 

D.
 

E.
 

F.
 

G.
 

H.
 
  
See page 240 of the textbook for details.The following are uses for bots; Distributed Denial of Service (DDoS) attack, Spamming, an attacker is able to send massive amounts of bulk e-mail (spam), Keylogging, captures keystrokes on the infected machine, Spreading new malware, Botnets are used to spread new bots, Installing advertisement add-ons and browser helper objects (BHOs), Botnets are used to gain finanical advantages, Attacking IRC chat networks, Botnets are also used for attacks against internet relay channel (IRC) networks, and Manipulating online pols / games, since every bot will have a unique ip address, every vote will have the same crediability as a vote by a realp person.

推薦此文