Thursday, September 16, 2010

DDOS DDOS tracking the introduction and





Chain-level test (Link Testing)

Most of the tracking technologies are starting from the closest to the victim's router, and then began to check the upstream data link, until you find the origin of attack traffic hair. Ideally, this process can be recursive implementation of the attack until you find the source. This technique assumed attack remains active until the completion of tracking, it is difficult after the attack, intermittent attacks or attacks on the track adjustment to track. Including the following two chain-level testing:

1, Input debugging

Many routers offer Input debugging features, which allow administrators to filter certain number of exit data packets, and can decide who can reach the entrance. This feature was used as a traceback: First of all, victim was attacked in determining when all packets from the description of the attack packet flag. Through these signs in the upper reaches of the outlet manager configuration suitable Input debugging. This filter will reflect the relevant input port, the filtration process can continue in the upper class, until to reach the original source. Of course, a lot of this work by hand, some foreign ISP tools for the joint development of their network can automatically follow-up.

But the biggest problem with this approach is the management cost. Multiple ISP links and cooperation with them will take time. Therefore, this approach requires a lot of time, and almost impossible.

2, Controlled flooding

Burch and Cheswick proposed method. This method is actually manufactured flood attacks, by observing the state of the router to determine the attack path. First of all, there should be an upper road map, when under attack, they can start from the victim's upstream routers in accordance with road map on the upstream routers to control the flood, because the data packets with attack-initiated packet router also shared, thus increasing the possibility of the router packet loss. Through this continued up along the road map for, we can close the source of attacks launched.

This idea is very creative but also very practical, but there are several drawbacks and limitations. The biggest drawback is that this approach is itself a DOS attack, it will also carry out some of the trust path DOS, this shortcoming is also difficult procedure. Moreover, Controlled flooding requires an almost covers the entire network topology. Burch and Cheswick also pointed out that this approach could be used for DDOS attacks on the track. This method can only be effective on the ongoing situation in the attack.

CISCO router is CEF (Cisco Express Forwarding) is actually a kind of chain-level test, that is, to use CEF up to the final source, then the link on the router had to use CISCO routers, and support CEF. Must be Cisco 12000 or 7500 series router has. (Do not know how, do not check the latest CISCO document), but the use of this feature is very cost resources.

In the CISCO router (ip source-track support for the router) the IP source tracking in order to achieve the following steps:

1, when the purpose was found to be attacked, opened on the router the destination address of the track, enter the command ip source-track.

2, each Line Card was created to track the destination address specific CEF queue. The line card or port adapter with a specific ASIC for packet transformation, CEF queue is used to package into line card or port adapter's CPU.

3, each line card CPU collect information to track the purpose of communication

4, the timing data generated by export to the router. Be realistic summary of the flow of information, enter the command: show ip source-track summary. Each input interface to display more detailed information, enter the command show ip source-track

5, statistical tracking of IP addresses is a breakdown. This can be used to analyze the upstream router. You can close the current router IP source tracker, enter the command: no ip source-track. And then re-open at the upstream router on this feature.

6, repeat steps 1 through 5, until you find the attack source.

This almost answers securitytest to mention the bar.

Logging

Through this method to record the main data packet router, and then through the data collection techniques to determine the path packets through. While this approach can be used to track the data after the attack, it also has a Ming Xian's shortcomings, such Kenengyaoqiu Daliang of Zi Yuan (or sampling), a large number of data of Syndicated news Bingjuduifu problem.

ICMP tracking

This approach mainly rely on self-generated ICMP router tracking information. Each router has a very low probability (for example: 1 / 200000), the contents of the packet will be copied to an ICMP message in the package, and contains the information near the source address of the router. When the flood attacks beginning, victim can use ICMP messages to reconstruct the attacker path. In this way comparison with the above description, there are many advantages, but there are some disadvantages. For example: ICMP traffic may be filtered from the ordinary, and, ICMP messages should follow the same input debugging feature (the packet with the data packet input port and / or to get the MAC address associated capacity) related, but that in some router has no such function. At the same time, this approach also must be a way to deal with an attacker could send a forged ICMP Traceback message. In other words, we can approach this way, used in conjunction with other tracking mechanisms to allow more effective. (IETF iTrace)

This is the yawl that the IETF working group to study the content, when I made some comments to the Bellovin, but did not get an answer. For example:

1, although a random 1 / 20000 to track packages sent, but the package for forgery TRACEBACK cases, the efficiency of the router will have some effect.

2, track packages, and can not solve the counterfeit problem of authentication. To determine whether it is fake because the package, you must go to certification, and increased workload.

3, even with NULL authentication, also serve the purpose of (a certified case). And will not be much affected.

4, itrace purpose is to deal with the original DOS source of the problem of deception, but now the design seems to make us more concerned about the path and not the source. Is the path is more than the source of our problem to solve DOS useful?

So, there is a bunch of issues that I think iTrace will face the difficult issue.

Packet Marking

The technology concept (because there is no practical) is to the existing agreement on the basis of changes, and changes very little, not like the idea of iTrace, think better than iTrace. There are many details of this tracking study, the formation of a variety of labeling algorithm, but the best is compressed edge sampling algorithm.

Principle of this technique is a change in IP header, in which the identification heavy domain. That is, if not used to the identification domain, then this field is defined as the tag.

The 16bit of idnetification into: 3bit the offset (allows 8 slice), 5bit the distance, and the edge of 8bit slice. 5bit the distance allows 31 routes, which for the current network is already enough.

Marking and path reconstruction algorithm is:

Marking procedure at router R: let R''= BitIntereave (R, Hash (R)) let k be the number of none-overlappling fragments in R''for each packet w let x be a random number from [0 .. 1 ) if xlet o be a random integer from [0 .. k-1] let f be the fragment of R''at offset o write f into w.frag write 0 into w.distance wirte o into w.offset else if w . distance = 0 then let f be the fragment of R''at offset w.offset write f? w.frag into w.frag increment w.distance
Path reconstruction procedure at victim v:
let FragTbl be a table of tuples (frag, offset, distance) let G be a tree with root v let edges in G be tuples (start, end, distance) let maxd: = 0 let last: = v for each packet w from attacker FragTbl.Insert (w.frag, w.offset, w.distance) if w.distance> maxd then maxd: = w.distance for d: = 0 to maxd for all ordered combinations of fragments at distance d construct edge z if d! = 0 then z: = z? last if Hash (EvenBits (z)) = OddBits (z) then insert edge (z, EvenBits (z), d) into G last: = EvenBits (z); remove any edge (x, y, d) with d! = distance from x to v in G extract path (Ri.. Rj) by enumerating acyclic paths in G


Under laboratory conditions only victim of such markers can be caught from 1000 to 2500 package will be able to reconstruct the entire path, and should be said that the result is good, but not put to practical, mainly manufacturers and ISP router support needed .

Ip traceback's been almost a practical technology and laboratory techniques, or inanimate, on the main these, although there are other.

For a long time did not engage in a DDOS against it, and the domestic like product have a black hole, previously know some foreign, such as floodguard, toplayer, radware so. Prompted by securitytest also learned riverhead, I immediately look at their white paper.

Bigfoot made since the previous main ip traceback subject, securitytest also went to the defense. DDOS problem for ip traceback and Mitigation is not the same, ip traceback main track, mainly because of DDOS spoof, which is difficult to determine the real source of attack, and if the attack is easy to find the real source, not just to deal with DDOS, attacks against the other is also helpful, such as legal issues. And Mitigation is the angle from the victims, because the victim is generally unable to investigate the whole network, to identify source, and even be able to find the source, there must be a legal means of communication or to source stop (the attack source and not the source of the attacker), this means that a lot of communication, inter-ISP, across other similar non-technical issues, it is often difficult to handle. But from the victim's point of view, have to be a solution, so we need to Mitigation.

This in turn happens to be my previous scope of the study, therefore, will say a lot. For Mitigation, in fact, the fundamental technology is to a large number of flows from the attack packets and legitimate packets will be separated out, the attack packets discarded out for the approval of the legal package. This is not, so the actual use of technology is to identify how the attack packets as possible, but as small as possible to affect the normal package. This is again to analyze the DDOS (or DOS) of the methods and principles. Basic has the following forms:

1, the system hole formation DOS. This feature fixed, detection and prevention are also easy to

2, protocol attacks (some deal with system-related, some related with the agreement). Such as SYN FLOOD, debris, etc.. Features Fortunately, the detection and prevention is relatively easy. Such as SYN COOKIE, SYN CACHE, debris can be discarded. Such as land attack, smurf, teardrop, etc.

3, bandwidth FLOOD. Waste flow plug-bandwidth, feature poor recognition, defense is not easy

4, the basic legal FLOOD. More difficult than three, such as distribution of Slashdot.

Real DDOS, usually combining a variety of ways. For example SYNFLOOD, may also be bandwidth FLOOD.

The main factors that affect the defense is to see whether the features available, such as 1,2 relatively easy to solve, some of the basic does not affect the use of the FLOOD, it can well be abandoned, such as ICMP FLOOD. However, the attack packets if contracting tools to better package disguised as legitimate, it is difficult to identify out.

Mitigation methods in general is:

1, Filter. For obvious characteristics, such as some worms, the router can handle that. Of course, the filter is the ultimate solution, as long as the identification of the attack packets, it is to filter out these packets.

2, random packet loss. Associated with the random algorithm, a good algorithm can make the legitimate packets are less affected

3, SYN COOKIE, SYN CACHE other specific defensive measures. For some regular means of defense and attack filtering. For example ICMP FLOOD, UDP FLOOD. SYN COOKIE are all to avoid spoof, at least there are three TCP handshake, so better to judge SPOOF

4, passive neglect. It can be said to be deceived is also a way to confirm that. The normal connection fails will try again, but the attackers generally do not try. So can temporarily abandoned for the first time the connection request and a second or third connection request.

5, take the initiative to send a RST. Against SYN FLOOD, such as on a number of IDS. Of course, the real is not valid.

6, statistical analysis and fingerprints. It would have been the main content, but in the end the algorithm into a dead end, because the main problem is an algorithm. Through statistical analysis point of view to get the fingerprint, and then to abandon the attack fingerprint package is also a anomaly detection technology. Very simple, but it is not easy to affect the legal package, and will not become a random packet loss. (In fact it was considered too complex, have to be a detailed analysis of the attack packets and legitimate packets, the actual need, as long as the attack packets to filter out enough, even to attack packets through, but as long as not to cause DOS on it.) This is also a lot of The main subject of the researchers, the purpose is identifying attack packets.

Now back to securitytest mentioned riverhead. On the riverhead of the technology, I have just learned from their white paper on, but based on my analysis methods did not exceed the above-mentioned range.

riverhead's core program is the detection of Detection, transfer Diversion and mitigation Mitigation, which is to detect attacks, and then transferred to the traffic guard on their products, and then guard for Mitigation.

Its implementation steps are:

Because there is no map, we first define what can be said clearly:

# Source close to distributed denial of service for the remote router routers

# Close to the victim's router to router proximal

# Riverhead's Guard equipment subsidiary subsidiary router router installed

Defense steps

1, first detected in a DDOS place and understand the victim

2, Guard Notice to the remote router to send BGP (BGP circular set in the victim's prefix, and get higher than the original priority notice BGP), said the victim from the remote router to have a new route, and routed to the loopback Guard interface, all to the victim's have been transferred to the subsidiary Guard on the router

3, Guard inspection flow, and remove one of the attack traffic, and then forwarded to the traffic safety sub router, in the back victim

The core is the Guard, technology is described in the MVP architecture white paper (Multi-Verification Process), which is five levels below

Filter (Filtering): This module contains the static and dynamic DDOS filtering. Static filtering, blocking non-essential traffic, which can be user-defined or default riverhead provided. Dynamic filtering is based on the details of behavior analysis and flow analysis, by increasing the flow of the recognition of suspicious or malicious traffic blocking has been confirmed to be real-time updates

Anti-cheat (Anti-Spoofing): This module verify whether the packet into the system to be deceived. Guard uses a unique, patented source verification mechanism to prevent cheating. Also adopted a mechanism to confirm the legitimate flow of legitimate data packets to be discarded to eliminate

Anomaly detection (Anomaly Recognition): The module monitors all anti-cheat has not been filtered and discard the flow module, the flow records with the normal baseline behavior, it is found abnormal. The idea is that through pattern matching, different from the black-hat and the difference between legitimate communications. The principle used to identify the attack source and type, and proposed guidelines for interception of such traffic.

Anomaly detection include: attacks on the size of packet size and flow rate of the distribution of packet arrival time of the port distribution of the number of concurrent flow characteristics of a high-level agreement, the rate of entry
Traffic Category: Source IP Source port destination port protocol type connection capacity (daily, weekly)

Protocol Analysis (Protocol Analysis): The anomaly detection module processing found in the application of suspicious attacks, such as http attack. Protocol analysis also detected a number of agreements misconduct.

Traffic restrictions (Rate Limiting): mainly those who consume too many resources dealing with the source of traffic.

So, in fact the most important content is in the statistical analysis of anomaly detection, but it seems not much to see from the above special place, but must have a good algorithm. Such as FILTER, actually deal with some very familiar features of obvious attacks, anti-cheating is against syn flood like this, perhaps also a syn cookie module, but may have more patented technologies. Protocol analysis should in fact is relatively weak, but can be common agreement on some specific attacks, protocol error detection and identification of some acts simply agreed to check that this is very simple. Traffic restrictions are that a random packet loss, the most helpless way, so the final level.

Because this product is mainly for Mitigation, not ip traceback. But can be determined or there are important issues, such as:

1, how to deal with the real bandwidth flood. If the router is gigabit, but attacks have accounted for 90% of the traffic, only to shed 10% of the legitimate use, the router has first started with random packet loss of the Guard. (No way, this is the bottleneck of all defense technology)

2, the real attack. The real attack is difficult or not identifiable. For example, the same basic form with the normal, if and statistics are very similar, it is difficult to distinguish. Some attacks, such as reflective of the e-mail attacks, it is perfectly legal, but very hard to classify them.







Recommended links:



Compare Personal Interest



xbox 360 AVCHD



Zhang Feng: NAS Really How It?



PERFORMANCE appraisal process may wish to "quick" point



"Nobunaga's Ambition 12 Innovation" 82 Hokkaido start a battlefield report



M4v



When The "vision" Into A "trap"



convert avi to mp4 online



3g2 to Mpg



Infomation File And Disk Management



Good efficacy is the Man Manao out



Vb6 how to dynamically add controls



Official Air Strike 2 Cheats



Wednesday, July 28, 2010

CMMI: tailored, is the fundamental



Respondents: quality assurance manager of Hunan Branch Chong Liu sub Mbayu
Interviewer: China's Feng Shan Software Network



Quality assurance manager of Hunan Branch Chong Liu sub Mbayu

July 9, 2007, Hunan Branch Innovation Information Technology Co., Ltd. (former long-Chako create System Integration Company) Director, passed the SEI appraisers Dr. Edward Wang chaired CMMI3 level SCAMPI Class A formal assessment. The company is upgrading from the 1.2 version of the CMMI model since the first domestic release by the model CMMI3 assessment software company.

Reporter (hereinafter referred to as "mind"): Today, the honor to interview from Hunan Changsha, Hunan Branch Information Technology Co., Ltd. The quality assurance record manager Liu sub Mbayu, first of all, please give us talk about the history of the company to implement CMMI.

Liu sub Mbayu (hereinafter referred to as "Liu"): Hunan Section creative IT industry in Hunan, a well-known enterprises, the business covers system integration, intelligent building, industrial vision, and software development, software development accounts for most of country. Since the end of 2003, Hunan Branch started with CMMI model innovation ideas and concepts, the process of building a system of software projects, especially building the independent quality assurance system, and accumulated rich experience in process improvement and process data. July 9 this year, a formal assessment by CMMI3, get CMMI3 certificate.

Process is so simple, but from the experience gained in the certification process, it is difficult to use a few words clearly.

With the domestic software technology continues to evolve, the software has grown in scale of production, customer requirements have become more sophisticated software, the software become increasingly complex, increasingly competitive market, so the software will become increasingly demanding business high. Scale production, improve software quality and reduce software development costs, as product on schedule, is an urgent need for software companies to solve problems.

In such a background, Section creative choice in 2001 ISO9001: 2000 standard, built the quality management system, after several years of operation and continuous improvement, characteristics of the formation of a Section record in business management and project development in played a key role. We also problems in the software process analysis, on the various management concepts and methods of analysis, the end of 2003 on the use of SEI's CMMI model for philosophy, combined with the company many years of accumulation, the software development process was modified, in particular, is to build an independent quality assurance system and process R & D projects and product inspection and audit. After three years of operation, the establishment of a management system for the enterprises themselves, to determine their own management philosophy, developed his own unique corporate culture, which, using a variety of tools to manage the process of software system development process and project record, accumulated rich process data. In order to expand the software market, software product development to further improve efficiency, reduce development costs, improve risk control capability, enhance market competitiveness, the company decided to conduct a formal CMMI3 Accreditation. We ask the Beijing Aobo Ocean Consulting do for us, process improvement and evaluation of certified consulting, well prepared, in the July 9, 2007 adopted by the director of SEI appraisers Dr. Edward Wang chaired CMMI3 level formal SCAMPI Class A assessment, and get Dr. Edward Wang CMMI3 certificate issued on the spot.

CMMI assessment process by the company to improve end of a stage, it is our business beyond the starting point for further continuous improvement.

Note: by the CMM certification, what it means for your company? Its practical value for your company mainly in the where?

Liu: First of all, is the management concept is further deepened. CMMI from the United States, the United States has a strong cultural identity, the essence of which we should be gradually absorbed, in order to improve and deepen our management philosophy to improve the management level.

Second, the standard process documentation, project records of the process. This is consistent with the principles of ISO9000, the. Our business, asked the members of software projects should be required daily log registration, evaluation and testing of defects defects need to be recorded, making the project process can be transparent and controllable.

Third, the quantitative monitoring of the project process. Software project quality, schedule and cost control, from qualitative to quantitative a qualitative leap. Quantitative characteristics reflect monitoring is CMMI. Only quantified, objective comparison between the various project evaluation and assessment possible. We used to process data accumulated through the analysis of a business process measurement baseline.

Fourth, the institutionalization of internal process improvement. Process improvement can not be done overnight, but is not guaranteed, but must be with the development of enterprises, with the requirements of the outside world, as the project changes in the practice, and constantly be improved. This process will be permanent eternal. Our business will continue to improve as a specific project management and planning, from the system and the operational level to ensure improved sustainability.

Of course, the role of management is implicit, not all immediate. In the implementation of CMMI, the company's management at the beginning of the process would improve the expectations are high, I hope a significant effect within a short time, in fact very real. Is not effective, how effective, must use the data to speak, too few data samples within the short term, the effect is difficult to distinguish, even a partial will have not increased but decreased in the case. After so many years of accumulated data show that improvements were effective, especially in the general promotion of the standard process, the assessment of efficiency, and product development cycle to further control and risk control will be enhanced greatly, greatly improving customer satisfaction, and further reduce development costs the. I believe that the standard process through constant practice and improvement, process the data accumulate, our software products necessary to further improve productivity, product quality control and meet user needs further research and development to further reduce costs, and further enhance the market competitiveness of enterprises.

In addition, the current highly competitive software market, most software companies required high R & D capabilities, many software projects, especially in international projects, software companies with CMMI qualification requirements, which will undoubtedly raise the threshold of a software project competition. Our company passed the CMMI assessment, is very conducive to market competition is conducive to participation in international software outsourcing race.

Reporter: How does your company solve the CMM-length problem?

Liu: any new changes are meant to change the will and interests of the re-adjustment of force of habit. CMMI model used to transform the software process is the same need to create a new process is different from past norms, inter-face, ideas change, means that changes to certain habits, certain control flow changes in the original, but also means the thinking and work to change the way we can imagine, from management to general staff, there will be a different level of resistance, a lack of cooperation of the possible existence of a natural resistance to the implementation, which is necessary to face must be resolved.

From management, on one hand need to give yourself time to recharge, and consciously accept the CMMI concept, and constantly update their own knowledge, from the ideological to solve the problem, the most critical. Only with the support of management's conscious, fully in line with any change there will be a success. On the other hand, in the face of challenge or conflict with staff, managers should have a firm attitude towards the implementation of CMMI are determined, should not the slightest hesitation and hesitation, otherwise, it is easy to give up halfway, it is easy just a form. Have input, we will be rewarding. Also proved that the standard process based on CMMI model system did help the company improve the quality of software development, help reduce development costs, help to improve the quality of software products, which allow customers to our services more positive.

From the staff point of view, I think more important is the need to strengthen execution. Large-scale enterprises through training, to strengthen the implementation of staff awareness of staff familiarity with the standard process, in particular the process of establishing clear recommendations for improvement channel, so that employees have ownership, can directly participate in the work process improvement, can be easily put forward their suggestions for improvement. Ideological interpretation of the CMMI development processes to the specific process, the distribution of the daily norm, so employees do not care about the CMMI's profound theoretical knowledge, simply do not care enterprises are ISO standards or any CMMI model, or other management system standards, as long as the documents by the company to do on the trip. Employees in large part solved the doubts and misgivings.

From the company's top decision makers view the need to implement CMMI management philosophy, to CMMI culture into the company's culture. Corporate culture is the highest level of business operations, with good corporate culture, company policies and systems can really launch and implement. In this process, we have a good core idea of the CMM into a company's core philosophy and culture.

Would also like to emphasize that adhere to a gradual approach. Anyone involved in the process, processes, methods and tools of the larger changes should persist after the first pilot to promote the idea of the problem found in the pilot, the pilot in the improvement of a new process, new processes, new methods and become familiar with new tools This promotion is relatively easy.

Some management software companies, including some developers often complain about or that management will be strictly tied to their innovation, they think that to promote CMMI in a step by step, what activities are done according to plans and standard procedures to do, on corporate culture of innovation will play a negative role. I have met the developers, the large number of people who hold this view.

I would like to form this view for two reasons: First, when the enterprise in the implementation of CMMI, too mechanical, not on reality, not closely integrated with the practice, doing the form, for authentication and certification, dampened the enthusiasm of developers. For example, the analysis and design phase, need to develop the ability to play a larger element of creativity, if only from the records of the template's Geshi unity to requirements, including font size, indentation inspection and control, ignoring the content of the assessment, must resentment caused by the developer, but this is not a unified template that does not matter. If equipped with specialized information developer, specializing in the development of documentation, analysis and design staff can work from a standardized document freed the needs of specific creative analysis and software design, and information for professional developers to do the work of the document standardization, we will improve the efficiency of the document will be higher quality. Second, such persons lack of real software engineering experience and management experience, too few large projects to do, too little experience of failure, or failure is not conducted an objective analysis of the causes. On this point is no dispute, CMMI is a software engineering experience and a master of lessons learned, we do not go to repeat those failures.

Reporter: Finally, for those who are ready to embark on the road to CMMI business, you have nothing to say to them?

Liu: First of all, uphold the ingenious, we take the initiative. Mechanically in the implementation of the provisions of CMMI CMMI often mistakes. In the domestic software enterprises, many organizations from the workshop-style software development was a gradual, though to varying degrees set up their own software development process, but there are some limitations or shortcomings. In the enterprise, really more than 10 years experience in software engineering staff is relatively small, but very often we do not want to manage. Business groups in the formation of EPG should be fully considered and the development experience of software engineering experience. If the EPG members have a lack of engineering experience, there is no real practical experience of experts guide the understanding of the CMMI can not be very deep, easy to mechanically CMMI standard provisions or other business processes to CMMI best doctrine of good practice, not to cut and change them, in fact, this is precisely contrary to the spirit of CMMI.

CMMI is a master of software engineering experience is summed up from practice to practice guidance, CMMI is also an updated version of itself and constantly improve. Every business has its own characteristics, like Microsoft's MSF, it is the management process of Microsoft's own internal standards, Microsoft's product development experience is a summary of some of the content of the CMMI in the Mei You, Wan Quan Guo Lai can learn to use, so long as you can improve enterprise management level of their own software, they should be bold attempt.

When the implementation of CMMI, it encountered resistance, in part because copying provisions CMMI not meet the real business, no specific analysis of specific situations. In fact, the first-line managers, developers best understanding of the actual. Who understand the practical, who has a say. Therefore, in order to develop CMMI standard, especially when we want to perform in the development process, standard operating procedures and guidelines and record template, we must first seek the views of actors, fully refined, and only on the basis of consensus to promote.

In addition to modified and not revolutionary. A revolutionary way to implement the CMMI, hope that, through a campaign to address the issue of process capability, one may not understand CMMI, do not know the management of improvement is gradual, a possible the knowledge, expectations in the short term through the CMMI assessment , pure pursuit of market buzz. Although some enterprises in a short time by a high-level CMMI assessment, I'm afraid the absence of effective and not difficult to adhere to our identity, had to give up halfway, it has a lot of examples. After the introduction of an enterprise CMMI will greatly affect the corporate culture, change our thinking and ways of doing things. It has been vividly likened the process to improve weight loss, you can rely on weight loss surgery or starving to lose weight in a short time, but if you do not fundamentally improve diet, lifestyle, exercise habits, then weight will quickly return to the status quo, or even more fat. I think this analogy is very vivid.

Finally, the need to adhere to CMMI several features of culture, will ultimately succeed. First, the process of implementing the ideas, adhere to the process input and output documents, and adhering to input and output of the verification and validation. Second, establish a hierarchical management thinking. Separation of powers is the essence of America's institutional culture, CMMI is also true, naturally has its unique advantages, projects need to adhere to project managers, quality assurance personnel and process monitoring of project staff independence, while local costs will inevitably lead to increased, but ensure that the project can be controlled from the fundamentally visual, the benefits will far outweigh their investment. Third, persist in using the data to speak, that is, adhere to process and product measurement data. The level of production efficiency, product quality is good or bad, project schedule delays, the demand level of quality and risk control, qualitative description is often feeble, unconvincing, and only with objective data, quantitative comparison of only the most convincing force, which is CMMI level into the foundation and protection.

Wish all companies interested in adopting the CMMI model as soon as possible to benefit from CMMI, arrive early like.







Recommended links:



Kodak V705 Dual Lens Camera Stabilization cheap listing weekend



sound file converter



FreeBSD SNP 1. Installation of SNP



My favorite Seasonal - Screen Savers



Unicom announced iPhone BARE metal prices



4 strokes should shock



Easy Seasonal - Screen Savers



Alipay's disregard the CHANGING circumstances



Total Video Converter



How To Convert Flac To Mp3



Memory addressing modes on the 8086/88



Harder than steel



Comprehensive understanding of Redirection 301



Green ocean is no LONGER "lose"



what is rmvb



Sunday, July 25, 2010

Operators burn punched 11 million users four drama success



Over the past year, China's "3G first year." One year ago today, the global news media, flash, China issued 3G licenses FireWire. This is the national implementation of the economic stimulus plan for a strong, China Mobile, China Telecom and China Unicom were given a 3G "pass", thus China into the 3G era.

Over the past year called "crazy money-burning" of the year. Carriers to drop down nearly 150 billion yuan of the large amount of money, setting off wave after wave of 3G wave, hitting the cities and even villages, one after another, behind the market staged battle is in full swing.

Networking contest the most money-losing carrier battle

3G was named last year's "most money-losing business," this is not an exaggeration. Statistics of the Ministry of Industry and Information said that the three major carriers last year, up 143.5 billion yuan of investment. The most direct return on heavy investment is more and more cities and even towns joined the ranks of 3G.

The last day of last year, announced that China Mobile, TD completion of the network 3, for more than 70% of the country to achieve 3G coverage areas and cities. China Mobile 3G coverage of 238 cities, covering only the beginning of the licensing of 10 cities. The same day, China Unicom, also said two of the 50 cities has begun to distribute telephone numbers, its WCDMA network covering 335 cities nationwide. However, China Telecom, the fastest pace. As early as last October, China Telecom's 3G network will cover 342 prefecture-level cities, 2055 more than 6,000 county-level cities and towns developed.

While in Happy Valley enclosure, the three carriers start competing brands Raiders, from China Telecom's "Wireless LAN" to China Mobile's "G3", and then to China Unicom's "fertile" advertising campaign and amplified.

According to the latest statistics Ovid consultation, last year China has more than 11 million 3G users, of which China Mobile's TD users temporarily first, a total of 500 million users fall under his command. TD rally the Chinese telecommunications industry in this effort of communication standards, the 3G over the first year of implementation of "third world" expected.

Feast equipment manufacturers ZTE and Huawei are the international jumping

Network operators building large single-feed fertilizer equipment suppliers. Contest in the Chinese and foreign brands, local equipment manufacturers come to the fore, especially Huawei and ZTE.

Several joy are anxious that this situation is the 2009 portrait of equipment manufacturers. Telecom operators in China, followed by a round of bidding equipment, Huawei, ZTE, Datang and Putian outshine the former foreign predators.

Foreign media inventory last year in the telecommunications industry, the use of the "Western does not shine Dongfang Liang" image view. Huawei and ZTE in China "3G first year" to draw up a beautiful curve. The end of the first quarter of last year, Huawei in the global telecommunications equipment market share of 15%. The end of the third quarter, Huawei's global market share rose to 20%, crowding out Noci, become second only to Ericsson, the world's second-largest telecommunications equipment manufacturers. ZTE's global market share rose to 7%. The two Chinese companies to take off in the same time, Alcatel-Lucent, Nokia Siemens and Nortel and other foreign companies struggling.

Huawei is the envy of the financial statements of last year, sales are expected to more than 30 billion U.S. dollars, an increase of nearly 29% over the previous year to become China's largest CDMA and WCDMA providers.

ZTE's mobile phone in the "wall" and the "wall" while flowering, is expected to become the world's No. 5 mobile phone operators. This is an unprecedented leap in mobile phone business.

Melee carriers operating system, PC giants control the mobile phone chain

Last year, China Mobile Release Ophone from platform to Intel chips Gangster joint Nokia; blossom everywhere from the Google Android phone, Google-branded handsets to the Nexus One Phone hot baked; from Nokia to create Linux-based maemo, to Qualcomm Brew MP cell phone plan ; from Plam exit the market, to the popular Apple iphone wave of global ... ... 3G mobile phone operating system to unprecedented fierce competition, gave birth to many new elements and Aspect.

Smartphone end stage go it alone, "terminal + application" model gradually become the mainstream. The strength of IT industry, all have aimed at mobile Internet opportunities, China Mobile, MM (application mall) on the line, which is the world's first operators to launch an online software store. China Telecom "Tianyi space" application Mart also launched a public beta. China Unicom is not far behind in the preparation of "Wo Shopping Mall."

Smart phones Smart 3G mobile phone universal tide thousand is not a dream

Last year in the first half, kept the mobile phone operator company sounded "Assembly", industry enthusiasm unprecedented agitation. So, Apple iPhone is coming, Blackberry has come, a variety of Xphone have come - moving OPhone, Google, Gphone, Microsoft Wphone and Unicom brewing in Uphone. The latest move is that China Telecom in the field of high-end smart phones have found a breakthrough in its 3G Internet, four-channel dual network dual standby phone and WIFI / WAPI Internet access a big fuss.

Competition in addition to high-end phones, the low-cost 3G smartphone market has entered the critical point. China Telecom Head Ma Daojie terminal, said a highlight of this year will be to build more affordable 3G phone. This year, China Telecom tried to thousands of 3G smart phones to grab the user.

At the same time, thousands of mobile smart phones have also been sharpening its talons. TD Industry Alliance, Lu Yu, director of marketing, said 600 to 1,500 yuan in low-cost smart phone will achieve a breakthrough this year. She expects the number of TD users will break 30 million mark, TD end market size will reach 45 billion yuan. As of the end of December last year, TD total number of 266 terminal section.

In fact, in the terminal area, but the most eye-catching smartphone, the last year from Smarbook to the Booklet, and then to electric paper book can be described as colorful.

3G the first year of Events

Licensing

January 7, 2009, the Ministry of Industry and Information Technology of China Mobile, China Telecom and China Unicom issued three third-generation mobile communication (3G) license, a move indicates that China has formally entered into the 3G era. Among them, the approval of China Mobile TD-SCDMA-based technology to increase standard of the 3G license, China Telecom to increase technical standard based on CDMA2000 3G licenses, China Unicom to increase technical standard based on WCDMA 3G license.

Brand

December 22, 2008, China Telecom launched its 3G brand "Tian-yi." January 7, 2009, China Mobile China Mobile 3G release marking "G3". April 28, 2009, China Unicom issued a new corporate brand "fertile."

Business

April 1, 2009, China's domestic 3G mobile standard TD-led, after a 1-year commercial trial, the official launch of the commercial process.

銆??2009骞?鏈?6鏃ワ紝鍦ㄤ腑鍥?G鍙戠墝100澶╀箣闄咃紝涓浗鐢典俊瀹e竷鍦ㄩ鎵?20涓煄甯傛寮忓晢鐢ㄥ叾3G涓氬姟锛岃?133銆?53鍜?89绛夋墜鏈哄彿娈电殑鐢ㄦ埛鍙洿鎺ュ崌绾т娇鐢?G缃戠粶銆?br />
May 17, 2009, China Unicom launched 3G in 56 cities in commercial trial, on October 1, China Unicom officially commercial 3G network.

銆??鈻犺鑰呰瀵?br />
Look forward to the era of 3G civilians

"Castles in the air" as "proximity." In the past year, 3G staged the drama to ordinary foot off the eyes of addiction.

We are pleased to see that, 3G will reach the office at: phone screen makes the smiling faces of their loved ones feel warm and noble past, dressed in civilian clothes more and more of the smart phone as "3G first year of the" best move people selling point.鍚屾椂锛?G瀵瑰唴闇?殑鎷夊姩绔嬬瑙佸奖锛屾湰鍦熻澶囧晢鍦ㄥ浗闄呭法澶寸殑鏅亶鍥板涓椿寰楁湁婊嬫湁鍛炽?

However, in addition to lively advertising campaign, high-end mobile phone turns debut and peaked again in addition to statistics, the average person, 3G brings surprises, or too little, not enough to engender the urge to upgrade.

First of all, 3G's rates still too high, whether it is mobile Internet access or voice calls, the cost is still a certain threshold. Although the operator has launched the "stored Huafei for mobile phones" and other incentives, but touched upon the cell phone prices will always see a high level, but the algorithm incentives puzzled. In fact, consumers do not care what brand and what you are operators, cost is the most important measure.

Secondly, 3G licenses before the clamor of the so-called "killer application" did not give all themselves. Now look, before the general optimism of 3G video calls and did not fire up. As the first batch of 3G users, the author himself did not play a few video calls, because the concrete used in many conditions bound, for example, call each other must also be 3G users.

Some people wonder, 3G speed of development is too slow? Allegedly to a company's findings on the 3G user is melancholy: 3G "first experience were" typical of a low age, low income and low education, and the industry is expected to complete this not the same.

3G embarrassment is far more than that.澶ф妸鐨勯摱瀛愮牳杩涘幓涔嬪悗锛屽鍔犵殑甯﹀杩樻病鏈夌粰杩愯惀鍟嗗甫鏉ョ湡閲戠櫧閾躲?鍦ㄦ櫤鑳芥墜鏈哄ぇ鏅強鐨勬氮娼笅锛屽浗浜у搧鐗岀殑韬奖澶皯銆?An official said the Ministry of Industry, trapped in the core technology, 3G mobile phone standing on the top of the current mostly foreign giants. Reported last year, the production of 3G handsets in China, the foreign-funded enterprises accounted for 93%.

Fortunately, the confusion is only temporary, perhaps these questions will be resolved in 2010. We look forward to a genuine civilian era of 3G. 3G mobile phone is only as 2G handsets to sell when the 3G era that is popular.







相关链接:



Swf files



Ballmer want to trample on the spot once again boomed iphone



Stamp effect in the production of Fireworks



real player To h.264/avc



flv to Avi



Comment Multimedia Creation Tools



Thoughts on the Current Financial Report



News about FTP Servers



Simple Music Composers



Giant Imperial Shi Yuzhu set foot on "the journey"



.swf file



Using Photoshop Background ERASER Easy Matting



Five reasons for changing jobs frequently lead to university graduates



Hongtusanbao devaluation PC MALL mode



Tuesday, July 20, 2010

New worm VBS / VBSWG.an @ MM small files


Virus Name: VBS / VBSWG.an @ MM
顥?顥?found date :2002-05-26
顥?顥?found that the State: Turkey
顥?顥?virus Length: 7995 bytes
顥?顥?virus type: VBScript worm
顥?顥?br />Virus Characteristics:

E-mail in the form of the virus to spread, the virus e-mail format:

Subject: Shakira's Pictures

Text: Hi:
i have sent the photos via attachment
have funn ...

Annex: ShakiraPics.jpg.vbs



Annex run, the virus will be sent to the address book Zishen all e-mail addresses, while c: mircscript.ini files will be a series of instructions defined by the virus covered by these directives is mainly given by the infection itself Fasong users in IRC users within the same channel. Another will pop up a dialog box:



The virus also copies itself to the Windows directory and attempted to cover. VBS and. VBE files, then creates the following registry key:

HKEY_CURRENT_USERSoftwareShakiraPicsmailed = 1
HKEY_CURRENT_USERSoftwareShakiraPicsMirqued = 1

HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunRegistry = wscript.exe C: WINDOWSShakiraPics.jpg.vbs%
顥?顥?br />Signs of infection:

The registry keys will appear.
顥?顥?br />Mode of transmission:

Outlook address book to send virus email messages, and modifies the mIRC script.ini file to spread through IRC, but also covered. VBS and. VBE files.






相关链接:



Convert Flv To 3gp



Articles about Browser Tools



A record of random access Recordset



How To Convert Flv To 3gp



AAC CDA to RA



Storage Access Control



ConvertXtoDVD build 1000



Top Web Or Video Cams



Youtube to PSP Ultra



Mkv



X-Cloner DVD to Apple TV



First Financial Weekly: direct supply in the Shadow of Digital China



CONVERT to wmv



Expert Development



X-CLONER DVD to Mobile



Mobile Phone to OGG Creator



Monday, July 5, 2010

Ever CDA MPC Sound to WAV Conversion

Ever CDA MPC Sound to WAV Conversion - If you are a network administrator, find MP3 files that users hide on servers hogging up space. Ever CDA MPC Sound to WAV Conversion - If you are a network administrator, find MP3 files that users hide on servers hogging up space. It supports audio format of uncompressed WAV PCM,compressed WAV (ADPCM, GSM, DSP and others),MP2 (MPEG 1/2 Layer-2),MP3 (MPEG 1/2 Layer-3),VOX (Dialogic ADPCM),WMA (Windows Media Audio 9),RAW audio (PCM, A-LAW, U-LAW),MPC (MusicPack),AVI (audio track),Ogg Vorbis (Version 1.0),G.721, G.723, G.726,AIFF (Apple audio format) and AU (UNIX audio format).



Recommand Link:



M4A CD to AAC



Recommend Audio Recorders



convert ogm to avi



Bluesea DVD FLV to XviD



Hot Themes And Wallpaper



RIP Vinyl



Adventure And Roleplay reviews



Convert Mkv



Youtube FLV to AVI Home



WorldCup DVD to MOV



.mkv



Flv to swf



Swift M4V DECONDE



WinXMedia CD MP3/WAV/WMA Converter



Perpetually DVD to PDA xBox 360



AAC CDA To RA



Friday, June 25, 2010

Merry CDA WMA OGG to VQF Copying

Merry CDA WMA OGG to VQF Copying - Don't take our word for it,see for yourself. CD Ripping include full support of CDDB database, so your music files automatically are named like 'Artist - Track.mp3', instead of boring 'track01.mp3'! Merry CDA WMA OGG to VQF Copying is a unique full support of id3v2 tags. Also, after ripping tracks, it automatically saves MP3-tags in output files and creates PLS or M3U playlists! It supports burn music CD from AVI, MPEG, WMV, MPEG4, 3GP, ASF, MOV, RM, MP2, MP3, WMA, WAV, AU, M4A, RA, OGG, AC3 etc. Multithreading and batch conversion supported and you can custom the number of the files to be converted Easy to use as all the properties and settings are displayed in the interface which are easy to handle Standard mode and advanced mode provided for beginners and veterans



Recommand Link:



Picked Newsgroup Clients



AllRipper DVD to Xbox



Open Apple TV Converter



Avex-DVD To Apple TV Video Suite



Review Clocks And Alarms



Converting HD to Archos 7



Audio to Music Plus



DVD to IPOD Nano 3Gen



Youtube To MOV Popular



blackberry video format



Articles about Strategy And War Games



Audio One Pack (Audio CD Creater)



Professional PDA xBox Apple TV Convert



Thursday, June 24, 2010

Bliss MP3 CD-R APE to VQF Converter

Bliss MP3 CD-R APE to VQF Converter - You can edit the title, artist, album, year, genre and comment information of your files. Bliss MP3 CD-R APE to VQF Converter is an easy-to-use tool to convert your audio CD to MP3, WAV, WMA and OGG file. Bliss MP3 CD-R APE to VQF Converter copies the audio digitally-not through the soundcard-which enables you to make perfect copies of the originals. Bliss MP3 CD-R APE to VQF Converter support FreeDB function and you can get track title, artist, and album information. Spported conversions include: CD to WAV, MP3, WMA, and OGG; P3/WMA/OGG/WAV/AIF/VOX/MP2/MPC/G.72x/AU/RAW to MP3/WMA/OGG/WAV; WAV/MP3/WMA/OGG to CD burning, WAV/MP3 Compression, and two-way conversions among MPEG-1, MPEG-2, AVI, WMV, and ASF for video. MPEG options are available for VCD, SVCD, and DVD compliant output. DVD shrink functionality is also present. When converting from audio CD, track information can be dynamically downloaded from the CDDB and used to automatically name saved files.



Recommand Link:



video to Archos 5 software



Install And Setup introduction



Cartoons - Screen Savers reviews



video to iPod Nano conversion tool



video To iPod Nano conversion tool



Bluesea PSP PDA xBox 360 Conversion



Apps 3GP Video CONVERTER



3GP Converter



BlipTV VIDEO Downloader



Youtube Video to MP4 Box



Avex DVD to iPod Video SUITE



Lenogo Video to iPhone pro



Professional DVD to MPEG4 Divx RM



PDA to MP3 Platinum



cool shareware Download site



Communications Tools Storage