Showing posts with label Computer Science. Show all posts
Showing posts with label Computer Science. Show all posts

Saturday, 26 January 2013

Cisco VoIP Phones


Computer scientists find vulnerabilities in Cisco VoIP Phones:


Columbia Engineering Computer Science PhD candidate Ang Cui and Computer Science Professor Salvatore Stolfo found serious vulnerabilities in Cisco VoIP (voice over Internet protocol) phones, devices used worldwide by a wide range of network organizations of governments to banks to large corporations, and beyond. In particular, they have found safety violations concern Cisco VoIP phone technology. At a recent conference on the safety of the devices connected, Cui demonstrates how you can insert malicious code into a Cisco VoIP phone (any model 14 Cisco Unified IP Phone) and start spying private conversations - not only by telephone, but also in around the phone - from anywhere in the world.
"There are only Cisco phones at risk. All VoIP phones are particularly problematic as they are everywhere and reveal our private communications," says Stolfo. "It is relatively easy to penetrate any corporate phone system, phone system any government, any house with Cisco VoIP phones - are not safe."
Cui and Stolfo analyzed phone firmware (the software that runs on the computer on the phone) and they were able to identify many vulnerabilities. They are particularly concerned with integrated systems that are widely used in network and via the Internet, including VoIP phones, routers and printers, and have focused their research on developing new advanced security technologies to protect these systems.
"The binary firmware analysis is commonly used to identify faulty software hackers 'white hat' and scientists and security researchers like our team," says Stolfo. "We conducted this analysis to demonstrate a defense technology, software called symbionts, which protects them from exploitation."
Symbionts software is designed to protect embedded systems from attacks malicious code injection in these systems, including routers and printers.
"This is a defense mechanism that is based on host code structure inspired by a natural phenomenon known as defensive symbiotic mutualism," said Cui. "The symbiote is especially suitable for embedded systems with sophisticated reinforcement legacy host-based defenses."
The researchers see these symbionts as a sort of digital lifestyle that coexists well with arbitrary executables in a mutually defensive. "They draw computing resources (CPU cycles) from the host at the same time protecting the host against attacks and exploitation," said Cui. "And, because they are so diverse in nature, which can provide self-protection against direct attack by adversaries that directly affect host defenses."
"We envision an architecture for general purpose computing systems consisting of two mutual defense by a machine that is embedded Symbiote autonomous, distinct and unique to each instance of a host program," says Stolfo. "The symbiote can reside within any arbitrary body of software, regardless of its place in the system stack. Could be injected into a host arbitrary in many different ways, while your code can be" random "for a number of well known methods. "
The symbiote, which at runtime is required by your host to run successfully for the host to operate, then monitors the behavior of its host to make sure it is working properly, and if not, the host stops to damage. Removal or attempted removal of the Symbiote host makes inoperable.
"The beauty of the Symbiote", Cui says, "is that it can be used to protect all types of embedded systems, from phones and printers to ATMs and even cars -. Systems we all use every day"
Cisco has since released a patch to fix these vulnerabilities, but is ineffective. "It does not solve the fundamental problems we have pointed to Cisco," said Cui. "I know of no solution to solve the systemic problem with the firmware Cisco IP Phone, except Symbiote technology or rewrite the firmware. We intend to demonstrate your Cisco IP Symbiote protected at an upcoming conference."

Engineers Develop New Energy-Efficient Computer Memory

Engineers Develop New Energy-Efficient Computer Memory Using Magnetic Materials :

By using voltage instead of an electric current, researchers at the UCLA Henry Samueli School of Engineering and Applied Science have made great improvements in an ultra-fast, high capacity type of computer memory known as Access Memory Random magneto-resistance, or MRAM.
Improving Memory The UCLA team, ask Merriam magneto-electric random access memory, has great potential for use in future memory chips for almost all electronic applications, such as smartphones, tablets, computers and microprocessors and data storage and solid state drives used in computers and data centers large.
Me-ram key advantage over existing technologies is that it combines low power consumption with an extremely high density, high speed read and write, and the lack of volatility - the ability to retain data when power is applied, similar to hard drives and flash memory cards, but it is much faster Me-ram.
Currently, magnetic memory is based on a technology called spin-transfer torque (STT), which uses the magnetic property of electrons - called spin - apart from its cargo. STT uses an electrical current to move electrons to write data to memory.
However, while STT is superior in many respects to the memory of competing technologies, the electrical mechanism based on actual scripts still requires a certain amount of energy, which means that heat is generated when data is written to it. Additionally, memory capacity is limited by the closing of each of the other data bits can be placed physically, a process that is limited by the current required to write information. The low bit capacity, in turn, translates into a cost per bit relatively large, which limits the application range of STT.
With Me-ram  the UCLA team has replaced the current STT voltage to write data to memory. This eliminates the need to transfer large amounts of electrons through wires and instead uses a voltage - the electrical potential difference - to change the magnetic bits and write information in memory. This has resulted in computer memory that generates much less heat, which is 10 to 1,000 times more energy efficient. And the memory can be more than five times denser, more bits of information stored in the same physical area, which also reduces the cost per bit.
The research team was led by principal investigator Kang L. Wang, Raytheon UCLA, Professor of Electrical Engineering and included the author John G. Alzate, an electrical engineering graduate student and Pedram Khalili, a research associate in electrical engineering and project director of the UCLA-DARPA research programs in nonvolatile logic.