Showing posts with label articles. Show all posts
Showing posts with label articles. Show all posts

Tuesday, May 6, 2008

Internet meme


The term Internet meme is a neologism used to describe a catchphrase or concept that spreads in a fast way from person to person via the Internet.The term is a reference to the concept of memes, although this concept refers to a much broader category of cultural information.


At its most basic, an Internet meme is simply the propagation of a digital file or hyperlink from one person to others using methods available through the Internet (for example, email, blogs, social networking sites, instant messaging, etc.). The content often consists of a saying or joke, a rumor, an altered or original image, a complete website, a video clip or animation, or an offbeat news story, among many other possibilities. An Internet meme may stay the same or may evolve over time, by chance or through commentary, imitations, and parody versions, or even by collecting news accounts about itself. Internet memes have a tendency to evolve and spread extremely quickly, sometimes going in and out of popularity in a matter of days. They are spread organically, voluntarily, peer to peer, rather than by compulsion, predetermined path, or completely automated means.
The term may refer to the content that spreads from user to user, the idea behind the content, or the phenomenon of its spread. Internet memes have been seen as a form of art.There exist websites that collect and popularize Internet memes as well as sites devoted to the spread of specific Internet memes. The term is generally not applied to content or web services that are seen as legitimate, useful, and non-faddish, or that spread through organized publishing and distribution channels. Thus, serious news stories, videogames, web services, songs by established musical groups, or the like are usually not called Internet memes. Internet Memes over time can show interesting patterns, moving from individual webpages and pictures to user created remakes of popular content.

Internet access


Internet access refers to the means by which users connect to the Internet.
Common methods of internet access include dial-up, landline (over coaxial cable, fiber optic or copper wires), T- lines, Wi-Fi, satellite and cell phones.
Public places to use the Internet include libraries and Internet cafes, where computers with Internet connections are available. Some libraries provide stations that provide facilities for hooking up public-owned laptops to local area networks (LANs). There are also wireless Internet access points in many public places like airport halls, in some cases just for brief use while standing. These Access points may provide coin operated computers or Wi-Fi hot spots* that enable specially equipped laptops to pick up internet service signals. Various terms are used, such as "public Internet kiosk", "public access terminal", and "Web payphone". Many hotels now also have public terminals, though these are usually fee based.
Wi-Fi provides wireless access to computer networks, and therefore can do so to the Internet itself. Hotspots providing such access include Wi-Fi-cafes, where a would-be user needs to bring their own wireless-enabled devices such as a laptop or PDA. These services may be free to all, free to customers only, or fee-based. A hotspot need not be limited to a confined location. The whole campus or park, or even the entire city can be enabled. Grassroots efforts have led to wireless community networks.
Apart from Wi-Fi, there have been experiments with proprietary mobile wireless networks like Ricochet, various high-speed data services over cellular or mobile phone networks, and fixed wireless services. These services have not enjoyed widespread success due to their high cost of deployment, which is passed on to users in high usage fees. New wireless technologies such as WiMAX have the potential to alleviate these concerns and enable simple and cost effective deployment of metropolitan area networks covering large, urban areas. There is a growing trend towards wireless mesh networks, which offer a decentralized and redundant infrastructure and are often considered the future of the Internet.
Broadband access over power lines was approved in 2004 in the United States in the face of stiff resistance from the amateur radio community. The problem with modulating a carrier signal below 100 MHz onto power lines is that an above-ground power line can act as a giant antenna and jam long-distance radio frequencies used by amateurs, seafarers and others. A recent discovery, called "E-Line" allows propagating much higher frequency carriers, from 100 MHz through at least 10 GHz, onto a single conductor of a power line and offers the possibility of very high speed fixed and mobile information services at very low cost without the problems associated with the lower frequency signals.
The use of the Internet around the world has been growing rapidly over the last decade, although the growth rate seems to have slowed somewhat after 2000. The phase of rapid growth is ending in industrialized countries, as usage becomes ubiquitous there, but the spread continues in Africa, Latin America, the Caribbean and the Middle East. One example of a great number of people gaining access to the internet is in Brazil, thanks to lowering taxes on computers and in dial-up providers, Brazilians are growing significantly on the internet in the past 2 years.

Wednesday, April 16, 2008

Top Stories Wage hike to benefit only 5M of 34M workers

QUEZON CITY, Philippines - Only five million of 34 million Filipino workers, or about 15 percent of the total labor force, will benefit from a wage increase, while more than 28 million workers would be left to cope with the rising prices of goods.

This was the assessment released on Wednesday by Ciriaco Lagunzad, executive director of the National Wage and Productivity Commission (NWPC).

According to Lagunzad, the wage increase will not be across the board – that is, only minimum wage earners will get pay hikes determined by the regional wage boards. And those earning more than P350 a day will not be covered the increase.

The revelation prompted two groups to remark that President Gloria Macapagal-Arroyo was merely trying to boost her sagging popularity when she ordered last Monday regional wage boards to implement a wage hike.

This was the view presented in statement issued on Wednesday by the Pambansang Lakas ng Kilusang Mamamalakaya ng Pilipinas (Pamalakaya) and the Unyon ng mgaManggagawa sa Agrikultura (UMA).

The five million workers, the groups said, would not include the bulk of minimum wage earners representing organized and unorganized labor.

"Once again, President Arroyo is taking the Filipino workers to another rollercoaster ride – and to her world of make-believe," Pamalakaya national chairman Fernando Hicap said. "Her call for a wage hike last Monday is fake and was meant to counter the sharp drop in her approval rating.

"Hicap said what workers – both in private and public sectors badly – need a P 125 across-the-board pay hike to cope with the rising prices of food and other necessities.

The two groups said the P350 minimum wage is actually worth P245.61 today based on the present inflation rate.

Based on NWPC findings, each family of six needs P768 per day to survive in Metro Manila. The current P350 minimum wage, which is regularly received non-agricultural workers, is way below of the required amount for a family of six to survive.

The Autonomous Region of Muslim Mindanao (ARMM) has the lowest minimum wage, pegged at P200 a day. A family of six in that region needs P 1,008 a day to survive. But the nominal basic pay of P 200 if translated to a real wage would only be P136.

"Arroyo merely wants to divide the labor sector by announcing wage increase for 15 percent of the population, and denying 85 percent of the country’s labor force of their much needed pay hike," Hicap said.

The wage hike would not cover the 600,000 fish workers in the commercial and aquaculture sectors.

On behalf of agricultural workers, UMA national chairperson Rene Galang, a Hacienda Luisita worker, had this to say: "Mrs. Arroyo merely gave false hopes out of her empty promise. Anyway agricultural workers do not believe her, because for every 10 promises she made, 11 are broken according to her track record as enemy of labor and willing puppet of foreign and local capitalists." -





source : D’Jay Lazaro, GMANews.TV

Friday, April 11, 2008

Forwarding Plane (a.k.a. Data Plane)

For the pure Internet Protocol (IP) forwarding function, router design tries to minimize the state information kept on individual packets. Once a packet is forwarded, the router should no longer retain statistical information about it. It is the sending and receiving endpoints that keeps information about such things as errored or missing packets.
Forwarding decisions can involve decisions at layers other than the IP internetwork layer or OSI layer 3. Again, the marketing term switch can be applied to devices that have these capabilities. A function that forwards based on data link layer, or OSI layer 2, information, is properly called a bridge. Marketing literature may call it a layer 2 switch, but a switch has no precise definition.
Among the most important forwarding decisions is deciding what to do when congestion occurs, i.e., packets arrive at the router at a rate higher than the router can process. Three policies commonly used in the Internet are Tail drop, Random early detection, and Weighted random early detection. Tail drop is the simplest and most easily implemented; the router simply drops packets once the length of the queue exceeds the size of the buffers in the router. Random early detection (RED) probabilistically drops datagrams early when the queue exceeds a configured size. Weighted random early detection requires a weighted average queue size to exceed the configured size, so that short bursts will not trigger random drops.
In routing, the forwarding plane defines the part of the router architecture that decides what to do with packets arriving on an inbound interface. Most commonly, it refers to a table in which it looks up the destination address in the incoming packet header, and retrieves information telling it the outgoing interface(s) to which the receiving element should send it through the internal forwarding fabric of the router. The IP Multimedia Subsystem architecture uses the term transport plane to describe a function roughly equivalent to the routing control plane.
The table also might specify that the packet is discarded. In some cases, the router will return an ICMP "destination unreachable" or other appropriate code. Some security policies, however, dictate that the router should be programmed to drop the packet silently. By dropping filtered packets silently, a potential attacker does not become aware of a target that is being protected.
The incoming forwarding element will also decrement the time-to-live (TTL) field of the packet, and, if the new value is zero, discard the packet. While the IP specification indicates that an ICMP TTL exceeded message should be sent to the originator of the packet (i.e., the node with the source address in the packet), routers may be programmed to drop the packet silently.
Depending on the specific router implementation, the table in which the destination address is looked up could be the routing table (also known as the routing information base), or a separate forwarding information base that is populated (i.e., loaded) by the control plane, but used by the forwarding plane to look up packets, at very high speed, and decide how to handle them. Before or after examining the destination, other tables may be consulted to make decisions to drop the packet based on other characteristics, such as the source address, the IP protocol identifier field, or TCP or UDP port number.
Forwarding plane functions, run in the forwarding element. . High-performance routers often have multiple distributed forwarding elements, so that the router increases performance with parallel processing.
The outgoing interface will encapsulate the packet in the appropriate data link protocol. Depending on the router software and its configuration, functions, usually implemented at the outgoing interface, may set various packet fields, such as the DSCP field used by differentiated services.
In general, the passage from the input interface directly to an output interface, through the fabric with minimum modification at the output interface, is called the fast path of the router. If the packet needs significant processing, such as segmentation or encryption, it may go onto a slower path, which is sometimes called the services plane of the router. Service planes can make forwarding or processing decisions based on higher-layer information, such as a Web URL contained in the packet payload.

Control Plane


Routers are like junctions whereas subnets are like streets and hosts like houses
Control Plane processing leads to the construction of what is variously called a routing table or routing information base (RIB). The RIB may be used by the Forwarding Plane to look up the outbound interface for a given packet, or, depending on the router implementation, the Control Plane may populate a separate Forwarding Information Base (FIB) with destination information. RIBs are optimized for efficient updating with control mechanisms such as routing protocols, while FIBs are optimized for the fastest possible lookup of the information needed to select the outbound interface.
The Control Plane constructs the routing table from knowledge of the up/down status of its local interfaces, from hard-coded static routes, and from exchanging routing protocol information with other routers. It is not compulsory for a router to use routing protocols to function, if for example it was configured solely with static routes. The routing table stores the best routes to certain network destinations, the "routing metrics" associated with those routes, and the path to the next hop router.
Routers do maintain state on the routes in the RIB/routing table, but this is quite distinct from not maintaining state on individual packets that have been forwarded.

In routing, the control plane is the part of the router architecture that is concerned with drawing the network map, or the information in a (possibly augmented) routing table that defines what to do with incoming packets. Control plane functions, such as participating in routing protocols, run in the architectural control element.In most cases, the routing table will contain a list of destination addresses and the outgoing interface(s) associated with them. Control plane logic also can define certain packets to be discarded, as well as preferential treatment of certain packets for which a high quality of service is defined by such mechanisms as differentiated services.
Depending on the specific router implementation, there may be a separate Forwarding Information Base that is populated (i.e., loaded) by the Control Plane, but used by the Forwarding Plane to look up packets, at very high speed, and decide how to handle them.

Single-Pair High-speed Digital Subscriber Line [SHDSL]

Single-Pair high-speed digital subscriber line (SHDSL) is a telecommunications technology for Digital Subscriber Line (DSL) subscriber lines. It describes a transmission method for signals on copper pair lines, being mostly used in access networks to connect subscribers to Telephone exchanges or POP Access Points.
G.SHDSL was standardized in February 2001 internationally by ITU-T with recommendation G.991.2.
G.SHDSL features symmetrical data rates from 192 kbit/s to 2,304 kbit/s of payload in 64 kbit/s increments for one pair and 384 kbit/s to 4,608 kbit/s in 128 kbit/s increments for two pair applications. The reach varies according to the loop rate and noise conditions (more noise or higher rate means decreased reach) and may be up to 3,000 meters. The two pair feature may alternatively be used for increased reach applications by keeping the data rate low (halving the data rate per pair will provide similar speeds to single pair lines while increasing the error/noise tolerance).
The payload may be either 'clear channel' (unstructured), T1 or E1 (full rate or fractional), n x ISDN Basic Rate Access (BRA), Asynchronous Transfer Mode (ATM) or 'dual bearer' mode (i.e. a mixture of two separate streams (e.g. T1 and 'packet based') sharing the payload bandwidth of the G.shdsl loop).
In Europe, a variant of G.SHDSL was standardized by ETSI using the name 'SDSL'. This ETSI variant is not compatible with the ITU-T G.SHDSL standardized regional variant for Europe and must not be confused with the usage of the term 'SDSL' in North America.
The latest standardization efforts (G.SHDSL.bis) tend to allow for flexibly changing the amount of bandwidth dedicated to each transport unit to provide 'dynamic rate repartitioning' of bandwidth demands during the uptime of the interface and optionally provides for 'extended data rates' by using a different modulation method (32-TCPAM instead of 16-TCPAM, where TCPAM is Trellis-Coded Pulse Amplitude Modulation). Also, a new payload type is introduced: packet based, e.g. to allow for Ethernet-frames to be transported natively. (Currently, they may only be framed in ATM or T1/E1/...). G.SHDSL.bis can deliver a minimum of 2 Mbit/s and a maximum of 5.69 Mbit/s over distances of up to 2.7 km (9 Kft).

Integrated Services Digital Network [ISDN]

Integrated Services Digital Network (ISDN), originally "Integriertes Sprach- und Datennetz" (German for "Integrated Speech and Data Net"), is a circuit-switched telephone network system, designed to allow digital transmission of voice and data over ordinary telephone copper wires, resulting in better voice quality than an analog phone. It offers circuit-switched connections (for either voice or data) in increments of 64 kbit/s. One of the major use cases is Internet access, where ISDN typically provides a maximum of 128 kbit/s (which cannot be considered to be a broadband speed). More broadly, ISDN is a set of protocols for establishing and breaking circuit switched connections, and for advanced call features for the user. It was introduced in the late 1980's.
In a videoconference, ISDN provides simultaneous voice, video, and text transmission between individual desktop videoconferencing systems and group (room) videoconferencing systems.

ISDN elements

Integrated Services refers to ISDN's ability to deliver at minimum two simultaneous connections, in any combination of data, voice, video, and fax, over a single line. Multiple devices can be attached to the line, and used as needed. That means an ISDN line can take care of most people's complete communications needs at a much higher transmission rate, without forcing the purchase of multiple analog phone lines.
Digital refers to its purely digital transmission, as opposed to the analog transmission of plain old telephone service (POTS). Use of an analog telephone modem for Internet access requires that the Internet service provider's (ISP) modem converts the digital content to analog signals before sending it and the user's modem then converts those signals back to digital when receiving. When connecting with ISDN there is no analog conversion.
Network refers to the fact that ISDN is not simply a point-to-point solution like a leased line. ISDN networks extend from the local telephone exchange to the remote user and includes all of the telecommunications and switching equipment in between.
The purpose of the ISDN is to provide fully integrated digital services to the users. These services fall under three categories: bearer services, supplementary services and teleservices.

Consumer and industry perspectives

There are two points of view into the ISDN world. The most common viewpoint is that of the end user, who wants to get a digital connection into the telephone/data network from home, whose performance would be better than an ordinary analog modem connection. The typical end-user's connection to the Internet is related to this point of view, and discussion on the merits of various ISDN modems, carriers' offerings and tarriffing (features, pricing) are from this perspective. Much of the following discussion is from this point of view, but it should be noted that as a data connection service, ISDN has been mostly superseded by DSL.
There is a second viewpoint: that of the telephone industry, where ISDN is a core technology. A telephone network can be thought of as a collection of wires strung between switching systems. The common electrical specification for the signals on these wires is T1 or E1. On a normal T1, the signalling is done with A&B bits to indicate on-hook or off-hook conditions and MF and DTMF tones to encode the destination number. ISDN is much better because messages can be sent much more quickly than by trying to encode numbers as long (100 ms per digit) tone sequences. This translated to much faster call setup times, which is greatly desired by carriers who have to pay for line time and also by callers who become impatient while their call hops from switch to switch.
It is also used as a smart-network technology intended to add new services to the public switched telephone network (PSTN) by giving users direct access to end-to-end circuit-switched digital services.

Internet service provider

An Internet service provider (abbr. ISP, also called Internet access provider or IAP) is a company or business that provides access to the Internet and related services. In the past, most ISPs were run by the phone companies. Now, ISPs can be started by just about any individual or group with sufficient money and expertise. In addition to Internet access via various technologies such as dial-up and DSL, they may provide a combination of services including Internet transit, domain name registration and hosting, web hosting, and colocation.
The internet started off as a closed network between government research laboratories and relevant parts of universities. It became popular and then universities and colleges started giving more of their members access to it

ISP connection options

ISPs employ a range of technologies to enable consumers to connect to their network. For "home users", the most popular options include dial-up, DSL (typically ADSL), Broadband wireless access, Cable modem, FTTH, and ISDN (typically BRI). For customers who have more demanding requirements, such as medium-to-large businesses, or other ISPs, DSL (often SHDSL or ADSL), Ethernet, Metro Ethernet, Gigabit Ethernet, Frame Relay, ISDN (BRI or PRI), ATM, satellite Internet access and SONET are more likely. With the increasing popularity of downloading music and online video and the general demand for faster page loads, higher bandwidth connections are becoming more popular.
Typical home user connection
DSL
Broadband wireless access
Cable modem
FTTH
ISDN
Typical business connection
DSL
SHDSL
Ethernet technologies

Enterprise Routers

All sizes of routers may be found inside enterprises. While the most powerful routers tend to be found in ISPs, academic and research facilities, as well as large businesses, may need large routers.
A three-layer model is in common use, not all of which need be present in smaller networks .

Access

Access routers, including SOHO, are located at customer sites such as branch offices that do not need hierarchical routing of their own. Typically, they are optimized for low cost.

Distribution

Distribution routers aggregate traffic from multiple access routers, either at the same site, or to collect the data streams from multiple sites to a major enterprise location. Distribution routers often are responsible for enforcing quality of service across a WAN, so they may have considerable memory, multiple WAN interfaces, and substantial processing intelligence.
They may also provide connectivity to groups of servers or to external networks. In the latter application, the router's functionality must be carefully considered as part of the overall security architecture. Separate from the router may be a Firewall or VPN concentrator, or the router may include these and other security functions.
When an enterprise is primarily on one campus, there may not be a distinct distribution tier, other than perhaps off-campus access. In such cases, the access routers, connected to LANs, interconnect via core routers.

Core
In enterprises, core router may provide a "collapsed backbone" interconnecting the distribution tier routers from multiple buildings of a campus, or large enterprise locations. They tend to be optimized for high bandwidth.
When an enterprise is widely distributed with no central location(s), the function of core routing may be subsumed by the WAN service to which the enterprise subscribes, and the distribution routers become the highest tier.

A core router is a router designed to operate in the Internet backbone, or core. To fulfill this role, a router must be able to support multiple telecommunications interfaces of the highest speed in use in the core Internet and must be able to forward IP packets at full speed on all of them. It must also support the routing protocols being used in the core.
Like the term "supercomputer", the term "core router" refers to the largest and most capable routers of the then-current generation. A router that was a core router when introduced will not be a core router ten years later. At the inception of the ARPANET (the Internet's predecessor) in 1969, the fastest links were 56 kbit/s and a given routing node had at most six links. The "core router" was a dedicated minicomputer called an IMP Interface Message Processor.Link speeds increased steadily, requiring progressively more powerful routers until the mid-1990s, when the typical core link speed reached 155 Mbit/s. At that time, several breakthroughs in fiber optic telecommunications (notably DWDM and EDFA technologies) combined to permit a sudden dramatic increase in core link speeds: by 2000, a core link operated at 2.5 Gbit/s and core internet companies were planning for 10 Gbit/s speeds.
The largest provider of core routers in the 1980s and 1990s was Cisco Systems, who provided core routers as part of a broad product line. This was despite the presence of faster and more capable routers from Wellfleet Communications, which existed as an independent company until it merged with SynOptics Communications in 1994, to become Bay Networks. Juniper Networks entered the business in 1996, focusing primarily on core routers. Both companies addressed the need for a radical increase in routing capability that was driven by the increased link speed. In addition, several new companies attempted to develop new core routers in the late 1990s. It was during this period that the term "core router" came into wide use. The required forwarding rate of these routers became so high that it could not be met with a single processor or a single memory, so these systems all employed some form of a distributed architecture based on an internal switching fabric.
The Internet was historically supply-limited, and core Internet providers historically struggled to expand the Internet to meet the demand. During the late 1990s, they expected a radical increase in demand, driven by the Dot-com bubble. By 2001, it became apparent that the sudden expansion in core link capacity had outstripped the actual demand for internet services in the core. The core internet providers were able to defer purchases of new core routers for a time, and most of the new companies went out of business. Cisco and Juniper were able to deliver their newest core router products several years later.

Routers


Routers are networking devices that forward data packets between networks using headers and forwarding tables to determine the best path to forward the packets. Routers work at the network layer of the TCP/IP model or layer 3 of the OSI model. Routers also provide interconnectivity between like and unlike media (RFC 1812). This is accomplished by examining the Header of a data packet, and making a decision on the next hop to which it should be sent (RFC 1812) They use preconfigured static routes, status of their hardware interfaces, and routing protocols to select the best route between any two subnets. A router is connected to at least two networks, commonly two LANs or WANs or a LAN and its ISP's network. Some DSL and cable modems, for home use, have been integrated with routers to allow multiple home computers to access the Internet.
A router (pronounced /rou'tər/) is a computer whose software and hardware are usually tailored to the tasks of routing and forwarding, generally containing a specialized operating system (e.g. Cisco's IOS or Juniper Networks JUNOS and JUNOSe or Extreme Networks XOS), RAM, NVRAM, flash memory, and one or more processors. High-end routers contain many processors and specialized Application-specific integrated circuits (ASIC) and do a great deal of parallel processing. Chassis based systems like the Nortel MERS-8600 or ERS-8600 routing switch, (pictured right) have multiple ASICs on every module and allow for a wide variety of LAN, MAN, METRO, and WAN port technologies or other connections that are customizable. However, with the proper software (such as SmoothWall, XORP or Quagga), even commodity PCs can act as routers.
Routers connect two or more logical subnets, which do not necessarily map one-to-one to the physical interfaces of the router. The term layer 3 switch often is used interchangeably with router, but switch is really a marketing term without a rigorous technical definition. In marketing usage, it is generally optimized for Ethernet LAN interfaces and may not have other physical interface types.
Routers operate in two different planes
Control Plane, in which the router learns the outgoing interface that is most appropriate for forwarding specific packets to specific destinations,
Forwarding Plane, which is responsible for the actual process of sending a packet received on a logical interface to an outbound logical interface.



Network switch




Switches

A switch is a device that performs Linksys 8-port switching. Specifically, it forwards and filters OSI layer 2 datagrams (chunk of data communication) between ports (connected cables) based on the Mac-Addresses in the packets.This is distinct from a hub in that it only forwards the datagrams to the ports involved in the communications rather than all ports connected. Strictly speaking, a switch is not capable of routing traffic based on IP address (layer 3) which is necessary for communicating between network segments or within a large or complex LAN. Some switches are capable of routing based on IP addresses but are still called switches as a marketing term. A switch normally has numerous ports with the intention that most or all of the network be connected directly to a switch, or another switch that is in turn connected to a switch.
"Switches" is a marketing term that encompasses routers and bridges, as well as devices that may distribute traffic on load or by application content (e.g., a Web URL identifier). Switches may operate at one or more OSI layers, including physical, data link, network, or transport (i.e., end-to-end). A device that operates simultaneously at more than one of these layers is called a multilayer switch.
Overemphasizing the ill-defined term "switch" often leads to confusion when first trying to understand networking. Many experienced network designers and operators recommend starting with the logic of devices dealing with only one protocol level, not all of which are covered by OSI. Multilayer device selection is an advanced topic that may lead to selecting particular implementations, but multilayer switching is simply not a real-world design concept.
A network switch is a computer networking device that connects network segments.
Low-end network switches appear nearly identical to network hubs, but a switch contains more "intelligence" (and comes with a correspondingly slightly higher price tag) than a network hub. Network switches are capable of inspecting data packets as they are received, determining the source and destination device of that packet, and forwarding it appropriately. By delivering each message only to the connected device it was intended for, a network switch conserves network bandwidth and offers generally better performance than a hub.
In the past, it was faster to use Layer 2 techniques to switch, when only MAC addresses could be looked up in content addressable memory (CAM). With the advent of ternary CAM (TCAM), it was equally fast to look up an IP address or a MAC address. TCAM is expensive, but very appropriate for enterprise switches that use default routes plus a moderate number of other routes. For routers that need a full Internet routing table, TCAM may not be cost-effective.




Network Interface Cards




Network card



A network card, network adapter or NIC (network interface card) is a piece of computer hardware designed to allow computers to communicate over a computer network. It provides physical access to a networking medium and often provides a low-level addressing system through the use of MAC addresses. It allows users to connect to each other either by using cables or wirelessly.
Although other network technologies exist, Ethernet has achieved near-ubiquity since the mid-1990s. Every Ethernet network card has a unique 48-bit serial number called a MAC address, which is stored in ROM carried on the card. Every computer on an Ethernet network must have a card with a unique MAC address. No two cards ever manufactured share the same address. This is accomplished by the Institute of Electrical and Electronics Engineers (IEEE), which is responsible for assigning unique MAC addresses to the vendors of network interface controllers.
Whereas network cards used to be expansion cards that plug into a computer bus, the low cost and ubiquity of the Ethernet standard means that most newer computers have a network interface built into the motherboard. These either have Ethernet capabilities integrated into the motherboard chipset, or implemented via a low cost dedicated Ethernet chip, connected through the PCI (or the newer PCI express bus). A separate network card is not required unless multiple interfaces are needed or some other type of network is used. Newer motherboards may even have dual network (Ethernet) interfaces built-in.
The card implements the electronic circuitry required to communicate using a specific physical layer and data link layer standard such as Ethernet or token ring. This provides a base for a full network protocol stack, allowing communication among small groups of computers on the same LAN and large-scale network communications through routable protocols, such as IP.
There are four techniques used to transfer data, the NIC may use one or more of these techniques.
Polling is where the microprocessor examines the status of the peripheral under program control.
Programmed I/O is where the microprocessor alerts the designated peripheral by applying its address to the system's address bus.
Interrupt-driven I/O is where the peripheral alerts the microprocessor that it's ready to transfer data.
DMA is where the intelligent peripheral assumes control of the system bus to access memory directly. This removes load from the CPU but requires a separate processor on the card.
A network card typically has a twisted pair, BNC, or AUI socket where the network cable is connected, and a few LEDs to inform the user of whether the network is active, and whether or not there is data being transmitted on it. The Network Cards are typically available in 10/100/1000 Mbit/s(Mbit/s). This means they can support a transfer rate of 10 or 100 or 1000 Megabits per second.
A repeater is an electronic device that receives a signal and retransmits it at a higher level or higher power, or onto the other side of an obstruction, so that the signal can cover longer distances without degradation.
The term "repeater" originated with telegraphy and referred to an electromechanical device used to regenerate telegraph signals. Use of the term has continued in telephony and data communications.
In telecommunication, the term repeater has the following standardized meanings:
An analog device that amplifies an input signal regardless of its nature (analog or digital).
A digital device that amplifies, reshapes, retimes, or performs a combination of any of these functions on a digital input signal for retransmission.
See also: Federal Standard 1037C and MIL-STD-188
Because repeaters work with the actual physical signal, and do not attempt to interpret the data being transmitted, they operate on the Physical layer, the first layer of the OSI model.

Hubs

Network hub

A hub contains multiple ports. When a packet arrives at one port, it is copied to all the ports of the hub. When the packets are copied, the destination address in the frame does not change to a broadcast address. It does this in a rudimentary way, it simply copies the data to all of the Nodes connected to the hub.
A network hub or concentrator is a device for connecting multiple twisted pair or fiber optic Ethernet devices together, making them act as a single network segment. Hubs work at the physical layer (layer 1) of the OSI model, and the term layer 1 switch is often used interchangeably with hub. The device is thus a form of multiport repeater. Network hubs are also responsible for forwarding a jam signal to all ports if it detects a collision.
Hubs also often come with a BNC and/or AUI connector to allow connection to legacy 10BASE2 or 10BASE5 network segments. The availability of low-priced network switches has largely rendered hubs obsolete but they are still seen in older installations and more specialized applications.
Bridges

Network bridge
A network bridge connects multiple network segments at the data link layer (layer 2) of the OSI model. Bridges do not promiscuously copy traffic to all ports, as hubs do, but learns which MAC addresses are reachable through specific ports. Once the bridge associates a port and an address, it will send traffic for that address only to that port. Bridges do send broadcasts to all ports except the one on which the broadcast was received.
Bridges learn the association of ports and addresses by examining the source address of frames that it sees on various ports. Once a frame arrives through a port, its source address is stored and the bridge assumes that MAC address is associated with that port. The first time that a previously unknown destination address is seen, the bridge will forward the frame to all ports other than the one on which the frame arrived.
Bridges come in three basic types:
Local bridges: Directly connect local area networks (LANs)
Remote bridges: Can be used to create a wide area network (WAN) link between LANs. Remote bridges, where the connecting link is slower than the end networks, largely have been replaced by routers.
Wireless bridges: Can be used to join LANs or connect remote stations to LANs. , where the connecting link is slower than the end networks, largely have been replaced by routers.
A network bridge connects multiple network segments at the data link layer (layer 2) of the OSI model, and the term layer 2 switch is often used interchangeably with bridge. Bridges are similar to repeaters or network hubs, devices that connect network segments at the physical layer, however a bridge works by using bridging where traffic from one network is managed rather than simply rebroadcast to adjacent network segments. In Ethernet networks, the term "bridge" formally means a device that behaves according to the IEEE 802.1D standard—this is most often referred to as a network switch in marketing literature.
Since bridging takes place at the data link layer of the OSI model, a bridge processes the information from each frame of data it receives. In an Ethernet frame, this provides the MAC address of the frame's source and destination. Bridges use two methods to resolve the network segment that a MAC address belongs to.
Transparent bridging – This method uses a forwarding database to send frames across network segments. The forwarding database is initially empty and entries in the database are built as the bridge receives frames. If an address entry is not found in the forwarding database, the frame is rebroadcast to all ports of the bridge, forwarding the frame to all segments except the source address. By means of these broadcast frames, the destination network will respond and a route will be created. Along with recording the network segment to which a particular frame is to be sent, bridges may also record a bandwidth metric to avoid looping when multiple paths are available. Devices that have this transparent bridging functionality are also known as adaptive bridges.
Source route bridging – With source route bridging two frame types are used in order to find the route to the destination network segment. Single-Route (SR) frames comprise most of the network traffic and have set destinations, while All-Route(AR) frames are used to find routes. Bridges send AR frames by broadcasting on all network branches; each step of the followed route is registered by the bridge performing it. Each frame has a maximum hop count, which is determined to be greater than the diameter of the network graph, and is decremented by each bridge. Frames are dropped when this hop count reaches zero, to avoid indefinite looping of AR frames. The first AR frame which reaches its destination is considered to have followed the best route, and the route can be used for subsequent SR frames; the other AR frames are discarded. This method of locating a destination network can allow for indirect load balancing among multiple bridges connecting two networks. The more a bridge is loaded, the less likely it is to take part in the route finding process for a new destination as it will be slow to forward packets. A new AR packet will find a different route over a less busy path if one exists. This method is very different from transparent bridge usage, where redundant bridges will be inactivated; however, more overhead is introduced to find routes, and space is wasted to store them in frames. A switch with a faster backplane can be just as good for performance, if not for fault tolerance.

Advantages of network bridges
Self configuring
Primitive bridges are often inexpensive
Reduce size of collision domain by
microsegmentation in non switched networks
Transparent to protocols above the MAC layer
Allows the introduction of management - performance information and access control
LANs interconnected are separate and physical constraints such as number of stations, repeaters and segment length don't apply

Disadvantages of network bridges

Does not limit the scope of broadcasts
Does not scale to extremely large networks
Buffering introduces store and forward delays - on average traffic destined for bridge will be related to the number of stations on the rest of the
LAN
Bridging of different MAC protocols introduces errors
Because bridges do more than repeaters by viewing MAC addresses, the extra processing makes them slower than
repeaters
Bridges are more expensive than repeaters









Thursday, April 10, 2008

Basic Hardware Components

All networks are made up of basic hardware building blocks to interconnect network nodes, such as Network Interface Cards (NICs), Bridges, Hubs, Switches, and Routers. In addition, some method of connecting these building blocks is required, usually in the form of galvanic cable (most commonly Category 5 cable). Less common are microwave links .

Network Interface Cards

Network card
A network card, network adapter or NIC (network interface card) is a piece of computer hardware designed to allow computers to communicate over a computer network. It provides physical access to a networking medium and often provides a low-level addressing system through the use of MAC addresses. It allows users to connect to each other either by using cables or wirelessly.

Intranet / Extranet

Intranet

An intranet is a set of interconnected networks, using the Internet Protocol and uses IP-based tools such as web browsers, that is under the control of a single administrative entity. That administrative entity closes the intranet to the rest of the world, and allows only specific users. Most commonly, an intranet is the internal network of a company or other enterprise.

An intranet is a private computer network that uses Internet protocols and network connectivity to securely share part of an organization's information or operations with its employees. Sometimes the term refers only to the most visible service, the internal website. The same concepts and technologies of the Internet such as clients and servers running on the Internet protocol suite are used to build an intranet. HTTP and other Internet protocols are commonly used as well, such as FTP. There is often an attempt to use Internet technologies to provide new interfaces with corporate "legacy" data and information systems.
Briefly, an intranet can be understood as "a private version of an Internet," or as a version of the Internet confined to an organization. The term first appeared in print on April 19, 1995, in Digital News & Review in an article authored by technical editor Stephen Lawton .
Intranets differ from "Extranets" in that the former are generally restricted to employees of the organization while extranets can generally be accessed by customers, suppliers, or other approved parties.
There does not necessarily have to be any access from the organization's internal network to the Internet itself. When such access is provided it is usually through a gateway with a firewall, along with user authentication, encryption of messages, and often makes use of virtual private networks (VPNs). Through such devices and systems off-site employees can access company information, computing resources and internal communications.
Increasingly, intranets are being used to deliver tools and applications, e.g., collaboration (to facilitate working in groups and teleconferencing) or sophisticated corporate directories, sales and CRM tools, project management etc., to advance productivity.
Intranets are also being used as culture change platforms. For example, large numbers of employees discussing key issues in an online forum could lead to new ideas.
Intranet traffic, like public-facing web site traffic, is better understood by using web metrics software to track overall activity, as well as through surveys of users.
Intranet "User Experience", "Editorial", and "Technology" teams work together to produce in-house sites. Most commonly, intranets are owned by the communications, HR or CIO areas of large organizations, or some combination of the three.
Because of the scope and variety of content and the number of system interfaces, the intranets of many organisations are much more complex than their respective public websites. And intranets are growing rapidly. According to the Intranet design annual 2007 from Nielsen Norman Group the number of pages on participants' intranets averaged 200,000 over the years 2001 to 2003 and has grown to an average of 6 million pages over 2005–2007

Extranet

An extranet is a network or internetwork that is limited in scope to a single organization or entity but which also has limited connections to the networks of one or more other usually, but not necessarily, trusted organizations or entities (e.g. a company's customers may be given access to some part of its intranet creating in this way an extranet, while at the same time the customers may not be considered 'trusted' from a security standpoint). Technically, an extranet may also be categorized as a CAN, MAN, WAN, or other type of network, although, by definition, an extranet cannot consist of a single LAN; it must have at least one connection with an external network.

An extranet is a private network that uses Internet protocols, network connectivity, and possibly the public telecommunication system to securely share part of an organization's information or operations with suppliers, vendors, partners, customers or other businesses. An extranet can be viewed as part of a company's Intranet that is extended to users outside the company (e.g.: normally over the Internet). It has also been described as a "state of mind" in which the Internet is perceived as a way to do business with a preapproved set of other companies business-to-business (B2B), in isolation from all other Internet users. In contrast, business-to-consumer (B2C) involves known server(s) of one or more companies, communicating with previously unknown consumer users.
Briefly, an extranet can be understood as a private intranet mapped onto the Internet or some other transmission system not accessible to the general public, but is managed by more than one company's administrator(s). For example, military networks of different security levels may map onto a common military radio transmission system that never connects to the Internet. Any private network mapped onto a public one is a virtual private network (VPN). In contrast, an intranet is a VPN under the control of a single company's administrator(s).
An argument has been made that "extranet" is just a buzzword for describing what institutions have been doing for decades, that is, interconnecting to each other to create private networks for sharing information. One of the differences that characterized an extranet, however, is that its interconnections are over a shared network rather than through dedicated physical lines. With respect to Internet Protocol networks, RFC 4364 states "If all the sites in a VPN are owned by the same enterprise, the VPN is a corporate intranet. If the various sites in a VPN are owned by different enterprises, the VPN is an extranet. A site can be in more than one VPN; e.g., in an intranet and several extranets. We regard both intranets and extranets as VPNs. In general, when we use the term VPN we will not be distinguishing between intranets and extranets. Even if this argument is valid, the term "extranet" is still applied and can be used to eliminate the use of the above description."
It is important to note that in the quote above from RFC 4364, the term "site" refers to a distinct networked environment. Two "sites" connected to each other across the public Internet backbone comprise a VPN. The term "site" does not mean "website." Further, "intranet" also refers to just the web-connected portions of a "site." Thus, a small company in a single building can have an "intranet," but to have a VPN, they would need to provide tunneled access to that network for geographically distributed employees.
Similarly, for smaller, geographically united organizations, "extranet" is a useful term to describe selective access to intranet systems granted to suppliers, customers, or other companies. Such access does not involve tunneling, but rather simply an authentication mechanism to a web server. In this sense, an "extranet" designates the "private part" of a website, where "registered users" can navigate, enabled by authentication mechanisms on a "login page".
An extranet requires security and privacy. These can include firewalls, server management, the issuance and use of digital certificates or similar means of user authentication, encryption of messages, and the use of virtual private networks (VPNs) that tunnel through the public network.
Many technical specifications describe methods of implementing extranets, but often never explicitly define an extranet. RFC 3547 presents requirements for remote access to extranets. RFC 2709 discusses extranet implementation using IPSec and advanced network address translation (NAT).

Internetwork

Two or more networks or network segments connected using devices that operate at layer 3 (the 'network' layer) of the OSI Basic Reference Model, such as a router. Any interconnection among or between public, private, commercial, industrial, or governmental networks may also be defined as an internetwork.
In modern practice, the interconnected networks use the Internet Protocol. There are at least three variants of internetwork, depending on who administers and who participates in them:
Intranet
Extranet
Internet

Intranets and extranets may or may not have connections to the Internet. If connected to the Internet, the intranet or extranet is normally protected from being accessed from the Internet without proper authorization. The Internet is not considered to be a part of the intranet or extranet, although it may serve as a portal for access to portions of an extranet.

Internetworking involves connecting two or more distinct computer networks or network segments together to form an internetwork (often shortened to internet), using devices which operate at layer 3 (Network layer) of the OSI Basic Reference Model (such as routers or layer 3 switches) to connect them together to allow traffic to flow back and forth between them . The layer 3 routing devices guide traffic on the correct path (among several different ones usually available) across the complete internetwork to their destination.
Routers were originally called gateways, but that term was discarded in this context, due to confusion with functionally different devices using the same name.
The connecting together of networks with bridges is sometimes incorrectly termed "internetworking", but the resulting system mimics a single subnetwork, and no internetworking protocol (such as IP) is required to traverse it. However, a single computer network may be converted into an internetwork by dividing the network into segments and then adding routers or other layer 3 devices between the segments .
The original term for an internetwork was catenet. Internetworking started as a way to connect disparate types of networking technology, but it became widespread through the developing need to connect two or more local area networks via some sort of wide area network. The definition now includes the connection of other types of computer networks such as personal area networks.
The most notable example of internetworking in practice is the Internet, a network of networks running different low-level protocols, unified by an internetworking protocol, the Internet Protocol (IP).
IP only provides an unreliable packet service across an internet. To transfer data reliably, applications must utilize a Transport layer protocol, such as TCP, which provides a reliable stream (These terms do not mean that IP is actually unreliable but instead that it sends packets without contacting and establishing a connection with the destination router beforehand. The opposite applies for reliable). Since TCP is the most widely used transport protocol, people commonly refer to TCP and IP together, as "TCP/IP". Some applications occasionally use a simpler transport protocol (called UDP) for tasks which do not require absolutely reliable delivery of data, such as video streaming.

History of Internetworking

The first networks were time-sharing networks that used mainframes and attached terminals. Such environments were implemented by both IBM's Systems Network Architecture (SNA) and Digital's network architecture.
Local-area networks (LANs) evolved around the PC revolution. LANs enabled multiple users in a relatively small geographical area to exchange files and messages, as well as access shared resources such as file servers and printers.
Wide-area networks (WANs) interconnect LANs with geographically dispersed users to create connectivity. Some of the technologies used for connecting LANs include T1, T3, ATM, ISDN, ADSL, Frame Relay, radio links, and others. New methods of connecting dispersed LANs are appearing everyday.
Today, high-speed LANs and switched internetworks are becoming widely used, largely because they operate at very high speeds and support such high-bandwidth applications as multimedia and videoconferencing.
Internetworking evolved as a solution to three key problems: isolated LANs, duplication of resources, and a lack of network management. Isolated LANs made electronic communication between different offices or departments impossible. Duplication of resources meant that the same hardware and software had to be supplied to each office or department, as did separate support staff. This lack of network management meant that no centralized method of managing and troubleshooting networks existed.

Internetworking Challenges

Implementing a functional internetwork is no simple task. Many challenges must be faced, especially in the areas of connectivity, reliability, network management, and flexibility. Each area is key in establishing an efficient and effective internetwork.
The challenge when connecting various systems is to support communication among disparate technologies. Different sites, for example, may use different types of media operating at varying speeds, or may even include different types of systems that need to communicate.
Because companies rely heavily on data communication, internetworks must provide a certain level of reliability. This is an unpredictable world, so many large internetworks include redundancy to allow for communication even when problems occur.
Furthermore, network management must provide centralized support and troubleshooting capabilities in an internetwork. Configuration, security, performance, and other issues must be adequately addressed for the internetwork to function smoothly. Security within an internetwork is essential. Many people think of network security from the perspective of protecting the private network from outside attacks. However, it is just as important to protect the network from internal attacks, especially because most security breaches come from inside. Networks must also be secured so that the internal network cannot be used as a tool to attack other external sites.
Early in the year 2000, many major web sites were the victims of distributed denial of service (DDOS) attacks. These attacks were possible because a great number of private networks currently connected with the Internet were not properly secured. These private networks were used as tools for the attackers.
Because nothing in this world is stagnant, internetworks must be flexible enough to change with new demands.

E-mail address


An e-mail address identifies a location to which e-mail messages can be delivered. The term "e-mail address" is also used as the formal pre-registered authoritative electronic mail delivery site for an individual (example: an attorney's e-mail address registered for delivery of proof of service digital copies of legal pleadings). A modern Internet e-mail address (using SMTP or Usenet) is a string of the form jsmith@example.com. It should be read as "jsmith at example dot com". The part before the @ sign is the local-part of the address, often the username of the recipient, and the part after the @ sign is the domain-part which may be a host name or domain name which can be looked up in the Domain Name System to find the mail transfer agent or Mail eXchangers (MXs) accepting e-mail for that address.
The domain name of an e-mail address is often that of the e-mail service, such as Google's Gmail, Microsoft's Hotmail, etc. The domain name can also be the domain name of the company that the recipient represents, or the domain of the recipient's personal site.
Earlier forms of e-mail addresses included the somewhat verbose notation required by X.400, and the UUCP "bang path" notation, in which the address was given in the form of a sequence of computers through which the message should be relayed. This latter was widely used for several years, but was superseded by the generally more convenient SMTP form.
Addresses found in the header fields of e-mail should not be considered authoritative, because SMTP has no generally-required mechanisms for authentication. Forged e-mail addresses are often seen in spam, phishing, and many other internet-based scams; this has led to several initiatives which aim to make such forgeries easier to spot.

To indicate where the message should go, a user normally types the "display name" of the recipient followed by the address specification surrounded by angled brackets, for example: John Smith ap118@example.com.


Difficulties with e-mail forwarding

There are some additional details when an e-mail forwarder is involved. Forwarders perform a useful service in allowing you to have one simple permanent address, even if you change jobs or ISPs. List servers perform a similar function, forwarding e-mail to many receivers on behalf of one sender. Forwarders pose no problem for an end-to-end authentication method like DKIM and DomainKeys, as long as the signed message is not modified (some lists do this).
CSV limits its focus to one-hop authentications. SPF and SenderID have in essence the same limitation, they don't work directly behind the "border" ( MX ) of the receiver. For SPF forwarders to third parties could rewrite the Return-Path (MAIL FROM) in a similar way like mailing lists. This approach emulates the SMTP behaviour before RFC 1123 deprecated source routes; for a technical explanation see SRS.
For SenderID, forwarders to third parties and mailing lists are asked to add a Sender: or Resent-Sender: header. For many mailing lists, the former is already the case, but other forwarders avoid any modifications of the mail in addition to the mandatory Received-timestamp line.

Use of a forwarder prevents the receiver from directly seeing the sender's IP address. The incoming IP packets have only the forwarder's IP address. Two solutions are possible if one can trust all forwarders. Either one trusts the forwarder to authenticate the sender, or one trusts the forwarder to at least accurately record the incoming IP address and pass it on, so one can do their own authentication.
The situation gets complicated when there is more than one forwarder. A sender can explicitly authorize a forwarder to send on its behalf, in effect extending its boundary to the public Internet. A receiver can trust a forwarder that it pays to handle e-mail, in effect designating a new receiver. There may be additional "MTA relays" in the middle, however. These are sometimes used for administrative control, traffic aggregation, and routing control. All it takes is one broken link in the chain-of-trust from sender to receiver, and it is no longer possible to authenticate the sender.
Forwarders have one other responsibility, and that is to route Bounce messages (a.k.a. DSNs) in case the forwarding fails (or if it is requested anyway). E-mail forwarding is different from remailing when it comes to which address should receive DSNs. Spam bounces should not be sent to any address that may be forged. These bounces may go back by the same path they came, if that path has been authenticated.

Spamming and computer viruses

The usefulness of e-mail is being threatened by four phenomena: e-mail bombardment, spamming, phishing and e-mail worms.
Spamming is unsolicited commercial e-mail. Because of the very low cost of sending e-mail, spammers can send hundreds of millions of e-mail messages each day over an inexpensive Internet connection. Hundreds of active spammers sending this volume of mail results in information overload for many computer users who receive voluminous unsolicted email each day.
E-mail worms use e-mail as a way of replicating themselves into vulnerable computers. Although the first e-mail worm affected UNIX computers, the problem is most common today on the more popular Microsoft Windows operating system.
The combination of spam and worm programs results in users receiving a constant drizzle of junk e-mail, which reduces the usefulness of e-mail as a practical tool.
A number of anti-spam techniques mitigate the impact of spam. In the United States, U.S. Congress has also passed a law, the Can Spam Act of 2003, attempting to regulate such e-mail. Australia also has very strict spam laws restricting the sending of spam from an Australian ISP, but its impact has been minimal since most spam comes from regimes that seem reluctant to regulate the sending of spam.

E-mail spam

An e-mail program detecting spam messages. Spammers frequently disguise their messages with obfuscated text.
E-mail spam, also known as "bulk e-mail" or "junk e-mail," is a subset of spam that involves nearly identical messages sent to numerous recipients by e-mail. A common synonym for spam is unsolicited bulk e-mail (UBE). Definitions of spam usually include the aspects that email is unsolicited and sent in bulk."UCE" refers specifically to "unsolicited commercial e-mail."
E-mail spam has existed since before the beginning of the Internet, and has grown to about 90 billion messages a day, although about 80% is sent by fewer than 200 spammers. Botnets, virus infected computers, account for about 80% of spam. Laws against spam have been sporadically implemented, with some being opt-out laws and others being opt-in. The total amount of spam has leveled off slightly in recent years. The cost of spam is borne mostly by the recipient, so it is a form of postage due advertising.
E-mail addresses are collected from chatrooms, websites, newsgroups, and viruses which harvest users' address books, and are sold to other spammers. Much of the traffic is sent to invalid e-mail addresses. ISPs have attempted to recover the cost of spam through lawsuits against spammers, although they have been mostly unsuccessful in collecting damages despite winning in court.

Privacy concerns

E-mail privacy, without some security precautions, can be compromised because:
e-mail messages are generally not encrypted;
e-mail messages have to go through intermediate computers before reaching their destination, meaning it is relatively easy for others to intercept and read messages;
many Internet Service Providers (ISP) store copies of your e-mail messages on their mail servers before they are delivered. The backups of these can remain up to several months on their server, even if you delete them in your mailbox;
the Received: headers and other information in the e-mail can often identify the sender, preventing anonymous communication.
There are cryptography applications that can serve as a remedy to one or more of the above. For example, Virtual Private Networks or the Tor anonymity network can be used to encrypt traffic from the user machine to a safer network while GPG, PGP or S/MIME can be used for end-to-end message encryption, and SMTP STARTTLS or SMTP over Transport Layer Security/Secure Sockets Layer can be used to encrypt communications for a single mail hop between the SMTP client and the SMTP server.
Additionally, many mail user agents do not protect logins and passwords, making them easy to intercept by an attacker. Encrypted authentication schemes such as SASL prevent this.
Finally, attached files share many of the same hazards as those found in peer-to-peer filesharing. Attached files may contain trojans or viruses.

Terminology

Until modern times, cryptography referred almost exclusively to encryption, the process of converting ordinary information (plaintext) into unintelligible gibberish (i.e., ciphertext). Decryption is the reverse, moving from unintelligible ciphertext to plaintext. A cipher (or cypher) is a pair of algorithms which creates the encryption and the reversing decryption. The detailed operation of a cipher is controlled both by the algorithm and, in each instance, by a key. This is a secret parameter (ideally, known only to the communicants) for a specific message exchange context. Keys are important, as ciphers without variable keys are trivially breakable and therefore less than useful for most purposes. Historically, ciphers were often used directly for encryption or decryption, without additional procedures such as authentication or integrity checks.
In colloquial use, the term "code" is often used to mean any method of encryption or concealment of meaning. However, in cryptography, code has a more specific meaning; it means the replacement of a unit of plaintext (i.e., a meaningful word or phrase) with a code word (for example, apple pie replaces attack at dawn). Codes are no longer used in serious cryptography—except incidentally for such things as unit designations (e.g., Bronco Flight or Operation Overlord) —- since properly chosen ciphers are both more practical and more secure than even the best codes, and better adapted to computers as well.
Some use the terms cryptography and cryptology interchangeably in English, while others use cryptography to refer specifically to the use and practice of cryptographic techniques, and cryptology to refer to the combined study of cryptography and cryptanalysis.
The study of characteristics of languages which have some application in cryptology, i.e. frequency data, letter combinations, universal patterns, etc. is called Cryptolinguistics.

E-mail privacy

The protection of electronic mail from unauthorized access and inspection is known as electronic privacy. In countries with a constitutional guarantee of the secrecy of correspondence, e-mail is equated with letters and thus legally protected from all forms of eavesdropping.
In the United States, privacy of correspondence is derived from the Fourth Amendment to the United States Constitution and thus restricted by the requirement for a "reasonable expectation of privacy".
In France, an important precedent was set in 2000 when a criminal court found three senior academics at the École Supérieure de Physique et de Chimie Industrielles de la Ville de Paris (ESPCI), guilty of espionage on the email of a doctoral researcher. The ruling, which was confirmed by the Criminal Court of Appeals of Paris in 2001, effectively made unauthorised eavesdropping on email a crime equivalent to unauthorised tapping of phone lines and steaming open letters.

Need

The Internet is an expansive network of computers, much of which is unprotected against malicious attacks. From the time it is composed to the time it is read, e-mail travels along this unprotected Internet, perpetually exposed to electronic dangers.
Many users believe that e-mail privacy is inherent and guaranteed, psychologically equating it with postal mail. While e-mail is indeed conventionally secured by a password system, the one layer of protection is not secure, and generally insufficient to guarantee appreciable security.
Businesses are increasingly relying on electronic mail to correspond with clients and colleagues. As more sensitive information is transferred online, the need for e-mail privacy becomes more pressing.

Risks to user



The pathway of e-mail. Terminology used in this image is explained in the electronic mail article.
Because e-mail connects through many routers and mail servers on its way to the recipient, it is inherently vulnerable to both physical and virtual eavesdropping. Current industry standards do not place emphasis on security; information is transferred in plain text, and mail servers regularly conduct unprotected backups of e-mail that passes through. In effect, every e-mail leaves a digital papertrail in its wake that can be easily inspected months or years later.
The e-mail can be read by any cracker who gains access to an inadequately protected router. Some security professionals argue that e-mail traffic is protected from such "casual" attack by security through obscurity - arguing that the vast numbers of e-mails make it difficult for an individual cracker to find, much less to exploit, any particular e-mail. Others argue that with the increasing power of personal computers and the increasing sophistication and availability of data-mining software, such protections are at best temporary.
Intelligence agencies, using intelligent software, can screen the contents of e-mail with relative ease. Although these methods have been decried by civil rights activists as an invasion of privacy, agencies such as the U.S. Federal Bureau of Investigation conduct screening operations regularly.
ISPs and mail service providers may also compromise e-mail privacy because of commercial pressure. Many online e-mail providers, such as Yahoo! Mail or Google's Gmail, display context-sensitive advertisements depending on what the user is reading. While the system is automated and typically protected from outside intrusion, industry leaders have expressed concern over such data mining.
The receivers of e-mail can compromise e-mail privacy by indiscrimate forwarding of e-mail. This can reveal contact information (like e-mail addresses, full names, and phone numbers), internal use only information (like building locations, corporate structure, and extension numbers), and confidential information (trade secrets and planning).
In the United States and some other countries lacking secrecy of correspondence laws, e-mail exchanges sent over company computers are considered company property and are thus accessible by management. Employees in such jurisdictions are often explicitly advised that they may have no expectation of a right to privacy for messages sent or received over company equipment. This can become a privacy issue if employee and management expectations are mismatched.
Remedies
To provide a reasonable level of privacy, all routers in the e-mail pathway, and all connections between them, must be secured. This is done through data encryption, which translates the e-mail's contents into incomprehensible text that, if designed correctly, can be decrypted only by the recipient. An industry-wide push toward regular encryption of e-mail correspondence is slow in the making. However, there are certain standards that are already in place which some services have begun to employ.There are two basic techniques for providing such secure connections. The first involves encrypting the message directly using a secure encryption standard such as OpenPGP (Public key infrastructure) or S/MIME. These encryption methods are often a user-level responsibility, even though Enterprise versions of OpenPGP exist. The usage of OpenPGP requires the exchange of encryption keys. Even if the encrypted emails are intercepted and accessed, its contents are meaningless without the encryption key.This method is also sometimes tied with authentication. Authentication just means that each user must prove who they are by using either a password, biometric (such as a fingerprint), or other standard authentication means.The second approach is to send an open message to the recipient which contains no sensitive content but which announces a message waiting for the recipient on the sender's secure mail facility. The recipient then follows a link to the sender's secure website where the recipient must log in with a username and password before being allowed to view the message.At the ISP level, a further level of protection can be implemented by encrypting the communication between servers themselves, usually employing an encryption standard called Transport Layer Security (TLS). It is coupled with Simple Authentication and Security Layer (SASL), which confirms the target router's identity. This ensures that unintended servers don't end up with a copy of the e-mail, which happens frequently in the course of normal correspondence.Although many ISPs have implemented secure sending methods, users have been slow to adopt the habit, citing the esoteric nature of the encryption process. Without user participation, e-mail is only protected intermittently from intrusion.