Tuesday, September 13, 2016

Review: Tarleton School of Criminology Cybersecurity 2016 Summit

Today, I attended the Tarleton School of Criminology Cybersecurity 2016 Summit held at the George W. Bush Presidential Library. I have to say that it was extremely well done. The various speakers brought forth an upbeat, hopeful message about the future of cybersecurity. With presentations from former military, law enforcement, lawyers, professors, and consultants, it was packed full of useful information.



One of the nice little nuggets I ran across was the concept of the "kill chain" presented by Col Jeff Schilling (ret). Naturally, this came from one of the former military presenters. A quick Google and the meaning behind it was clear and the extension to the field of cybersecurity could be easily extrapolated. Essentially, the kill chain is all the steps necessary to successfully eliminate a target. As it relates to cybersecurity, it would simply be all the steps necessary to compromise a target (read data). Remove any step in the kill chain and the objective of compromise cannot be completed. Now, here's the kicker. As security professionals, you can attack the kill chain at each and every stage OR you can focus your efforts on a single stage. Basically, this was the argument made today. The point is not to ignore all the other stages. Patching is still important. So it user education. But focus on the data. Focus on the prize.



The thought process behind this is that if we spread our focus on all steps in the kill chain, it divides our focus and we become less effective. As long as we do not lose sight on our most valuable asset, we can focus our efforts where we can be most efficient and effective.



We also had presentations from the Secret Service as well as the FBI (no photos or names please).



Our keynote during lunch was Mr. Brian Sartin, Managing Director Verizon RISK Services over Verizon's 2016 data breach report. No surprises here. Same thing as last year. Threats continue to grow, particularly as they relate to nation state hacking/espionage.



Then we had Candy Heath, AUSA and Lead Cyber Attorney for the United States Northern District of Texas confirm some of the keynote speaker's findings that the vast majority of those compromised don't know it. Rather, one a perpetrator's is taken into custody and their systems are evaluated, numerous targets (sometimes dozens to hundreds) are discovered. This explains the concept of why it takes so long for organizations to discover that a breach has occurred. They are not discovering the breach. Others are...usually about 9 months after the breach originates.



Then a panel discussion over the state of educating security professionals and meeting the needs of employers occurred. The consensus was that we have a lot of work to do. Security professionals are very mobile. They can afford to be. They have highly sought after skills and few competitors. Depending on the presenter, there is a roughly 200,000 person shortage in this country. And, they predicted the problem would get worse. They also recognized the even within the general field of security, that there are specializations and the sometimes, an organization has security specialists, just not the specific ones they need.



Shawn Tuma, another attorney spoke about representing organizations that were the target of cyber attacks and noted the importance of simply have procedures in place and following them. Failure to protect data in and of itself is not the problem. But, failing to take reasonable precautions and not following established procedures opens up an organization to liability.



The second to last speaker was Chuck Easttom, computer scientist and author. He teaches, consults, testifies (prosecution and defense), etc. Bright guy. Would love to take some of his classes. He outlined an incident response template. The big take away from that was about verifying the credentials of the forensic expert. By that, he meant actually verify. Do not just take their word for it. Make sure they do the work and/or that they supervise those who do.



Lastly, Randell Casey, retired from the Army gave a great presentation. The take away there was "where are your electricians?" His point was that at the turn of the century in 1900, electricity was new. The government and large organizations had electricians on staff. When they needed new lines or a problem fixed, they just got their electricians to do it. Today, we simply expect to be about to flip a switch and for everything to work. If we need an electrician, we outsource it. His point was that security is moving in that direction. As things become more virtualized, more cloud based, organizations should shift to what they do best and leave the commoditization of infrastructure and security to professionals. But, he also restated the issue regarding the limited number of professionals on the market. His point here was was as the government continues to develop and employee many of those with these specialties, that as organizations start to wake up and truly understand how wide spread this issue truly is, that the shortage today could grow substantially before market forces can begin to correct the situation.



Now, I do not know if this was a one off event. I hope not. It was extremely well done. All the speakers were top notch from beginning to end. It has me rethinking our CIS programs at Tarleton to see how we might be able to collaborate with the CJ folks in order to generate some synergies. This was exciting, cool stuff.



Media Relations - Tarleton State University:



'via Blog this'

Wednesday, July 20, 2016

Security Theories

Computer Anxiety: "Excessive timidity in using computers, negative comments against computers and information science, attempts to reduce the amount of time spent using computers, and even the avoidance of using computersfrom the place where they are located" (Doronina, 1995).

  • Doronina, O. "Fear of Computers: Its Nature, Prevention and Cure," Russian Social Science Review (36:4) 1995, pp 79-90.


General Deterrence Theory:
  • BOSS SR, KIRSCH LJ, ANGERMEIER I, SHINGLER RA and BOSS RW (2009) If Someone Is Watching, I’ll Do What I’m Asked: Mandatoriness, Control, and Information Security. European Journal of Information Systems 18(2), 151–164. 
  • STRAUB DW and WELKE RJ (1998) Coping With Systems Risk: Security Planning Models for Management Decision Making. MIS Quarterly 22(4), 441–469.
  • D’ARCY J and HOVAV A (2009) Does One Size Fit All? Examining the Differential Effects of IS Security Countermeasures. Journal of Business Ethics 89, 59–71.
  • HERATH T and RAO HR (2009) Protection Motivation and Deterrence: A Framework for Security Policy Compliance in Organisations. European Journal of Information Systems 18(2), 106–125. 
  • PAHNILA S, SIPONEN M and MAHMOOD A (2007) Employees’ Behavior towards IS Security Policy Compliance. In: 40th Annual Hawaii International Conference on System Sciences. Waikoloa, HI: IEEE Computer Society.
  • STRAUB DW (1990) Effective IS Security: An Empirical Study. Information Systems Research 1(3), 255–276. 

Protection Motivation Theory:
  • Rogers, R.W. (1975). A protection motivation theory of fear appeals and attitude change. Journal of Psychology, 91, 93-114.
  • Rogers, R.W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In J. Cacioppo & R. Petty (Eds.), Social psychophysiology (pp. 153-176). New York: Guilford.
  • MADDUX JE and ROGERS RW (1983) Protection Motivation and Self-Efficacy: A Revised Theory of Fear Appeals and Attitude Change. Journal of Experimental Social Psychology 19(5), 469– 479.
  • CROSSLER RE (2010) Protection Motivation Theory: Understanding Determinants to Backing Up Personal Data. In: 43rd Hawaii International Conference on System Sciences. pp. 1–10.
  • HERATH T and RAO HR (2009) Protection Motivation and Deterrence: A Framework for Security Policy Compliance in Organisations. European Journal of Information Systems 18(2), 106–125.
  • JOHNSTON AC and WARKENTIN M (2010) Fear Appeals and Information Security Behaviors: An Empirical Study. MIS Quarterly 34(3), 549–A4.
  • PAHNILA S, SIPONEN M and MAHMOOD A (2007) Employees’ Behavior towards IS Security Policy Compliance. In: 40th Annual Hawaii International Conference on System Sciences. Waikoloa, HI: IEEE Computer Society.
  • VANCE A, SIPONEN M and PAHNILA S (2012) Motivating IS Security Compliance: Insights from Habit and Protection Motivation Theory. Information & Management 49(3–4), 190–198.
  • WOON I, TAN G-W and LOW R (2005) A Protection Motivation Theory Approach to Home Wireless Security. In: Proceedings of the 26th International Conference on Information Systems. pp. 367–380.
  • LEE Y and LARSEN KR (2009) Threat or Coping Appraisal: Determinants of SMB Executives’ Decision to Adopt Anti-Malware Software. European Journal of Information Systems 18(2), 177–187. 
Neutralization Theory:


Technology Threat Avoidance Theory (TTAT): Posits that threat avoidance behavior functions as a dynamic positive feedback loop (concept derived from cybernetic theory, and general systems theory) composed of two cognitive processes, threat and coping appraisals, which determine how an individual would cope with IT threats.
  • LIANG H and XUE Y (2009) Avoidance of Information Technology Threats: A Theoretical Perspective. MIS Quarterly 33(1), 71–90.
  • LIANG H and XUE Y (2010) Understanding Security Behaviors in Personal Computer Usage: A Threat Avoidance Perspective. Journal of the Association for Information Systems 11(7), 394– 413. 
Fear Appeal Theory
  • JOHNSTON AC and WARKENTIN M (2010) Fear Appeals and Information Security
  • Behaviors: An Empirical Study. MIS Quarterly 34(3), 549–A4.
Technology Anxiety (As a predictor of technology adoption): An individual's tendency to be uneasy, aprehensive, or fearful about the current or future use of technology ((Parasuraman, et al,m 1990; Allen, 2002).
  • Allen, J.W., and Parikh, M.A. "The Impact of Personal Traits on IT Adoption," Proceedings of the 8th Americas Conference on Information Systems, Dallas, TX, USA, 2002.
  • Meuter, M.L., Ostrom, A.L., Bitner, M.J., and Rountree, R. "The Influence of Technology Anxiety on Consumer Use and Experiences with Self-Service Technologies," Journal of Business Research (56) 2003, pp 899-906.
  • Parasuraman, S., and Igbaria, M. "An Examination of Gender Differences in the Determinants of Computer Anxiety and Attitudes Towards Microcomputers Among Managers," International Journal of Man-Machine Studies (32:3) 1990, pp 327-340.

Security Theories

Computer Anxiety: "Excessive timidity in using computers, negative comments against computers and information science, attempts to reduce the amount of time spent using computers, and even the avoidance of using computersfrom the place where they are located" (Doronina, 1995).

  • Doronina, O. "Fear of Computers: Its Nature, Prevention and Cure," Russian Social Science Review (36:4) 1995, pp 79-90.


General Deterrence Theory:
  • BOSS SR, KIRSCH LJ, ANGERMEIER I, SHINGLER RA and BOSS RW (2009) If Someone Is Watching, I’ll Do What I’m Asked: Mandatoriness, Control, and Information Security. European Journal of Information Systems 18(2), 151–164. 
  • STRAUB DW and WELKE RJ (1998) Coping With Systems Risk: Security Planning Models for Management Decision Making. MIS Quarterly 22(4), 441–469.
  • D’ARCY J and HOVAV A (2009) Does One Size Fit All? Examining the Differential Effects of IS Security Countermeasures. Journal of Business Ethics 89, 59–71.
  • HERATH T and RAO HR (2009) Protection Motivation and Deterrence: A Framework for Security Policy Compliance in Organisations. European Journal of Information Systems 18(2), 106–125. 
  • PAHNILA S, SIPONEN M and MAHMOOD A (2007) Employees’ Behavior towards IS Security Policy Compliance. In: 40th Annual Hawaii International Conference on System Sciences. Waikoloa, HI: IEEE Computer Society.
  • STRAUB DW (1990) Effective IS Security: An Empirical Study. Information Systems Research 1(3), 255–276. 

Protection Motivation Theory:
  • Rogers, R.W. (1975). A protection motivation theory of fear appeals and attitude change. Journal of Psychology, 91, 93-114.
  • Rogers, R.W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In J. Cacioppo & R. Petty (Eds.), Social psychophysiology (pp. 153-176). New York: Guilford.
  • MADDUX JE and ROGERS RW (1983) Protection Motivation and Self-Efficacy: A Revised Theory of Fear Appeals and Attitude Change. Journal of Experimental Social Psychology 19(5), 469– 479.
  • CROSSLER RE (2010) Protection Motivation Theory: Understanding Determinants to Backing Up Personal Data. In: 43rd Hawaii International Conference on System Sciences. pp. 1–10.
  • HERATH T and RAO HR (2009) Protection Motivation and Deterrence: A Framework for Security Policy Compliance in Organisations. European Journal of Information Systems 18(2), 106–125.
  • JOHNSTON AC and WARKENTIN M (2010) Fear Appeals and Information Security Behaviors: An Empirical Study. MIS Quarterly 34(3), 549–A4.
  • PAHNILA S, SIPONEN M and MAHMOOD A (2007) Employees’ Behavior towards IS Security Policy Compliance. In: 40th Annual Hawaii International Conference on System Sciences. Waikoloa, HI: IEEE Computer Society.
  • VANCE A, SIPONEN M and PAHNILA S (2012) Motivating IS Security Compliance: Insights from Habit and Protection Motivation Theory. Information & Management 49(3–4), 190–198.
  • WOON I, TAN G-W and LOW R (2005) A Protection Motivation Theory Approach to Home Wireless Security. In: Proceedings of the 26th International Conference on Information Systems. pp. 367–380.
  • LEE Y and LARSEN KR (2009) Threat or Coping Appraisal: Determinants of SMB Executives’ Decision to Adopt Anti-Malware Software. European Journal of Information Systems 18(2), 177–187. 
Neutralization Theory:


Technology Threat Avoidance Theory (TTAT): Posits that threat avoidance behavior functions as a dynamic positive feedback loop (concept derived from cybernetic theory, and general systems theory) composed of two cognitive processes, threat and coping appraisals, which determine how an individual would cope with IT threats.
  • LIANG H and XUE Y (2009) Avoidance of Information Technology Threats: A Theoretical Perspective. MIS Quarterly 33(1), 71–90.
  • LIANG H and XUE Y (2010) Understanding Security Behaviors in Personal Computer Usage: A Threat Avoidance Perspective. Journal of the Association for Information Systems 11(7), 394– 413. 
Fear Appeal Theory
  • JOHNSTON AC and WARKENTIN M (2010) Fear Appeals and Information Security
  • Behaviors: An Empirical Study. MIS Quarterly 34(3), 549–A4.
Technology Anxiety (As a predictor of technology adoption): An individual's tendency to be uneasy, aprehensive, or fearful about the current or future use of technology ((Parasuraman, et al,m 1990; Allen, 2002).
  • Allen, J.W., and Parikh, M.A. "The Impact of Personal Traits on IT Adoption," Proceedings of the 8th Americas Conference on Information Systems, Dallas, TX, USA, 2002.
  • Meuter, M.L., Ostrom, A.L., Bitner, M.J., and Rountree, R. "The Influence of Technology Anxiety on Consumer Use and Experiences with Self-Service Technologies," Journal of Business Research (56) 2003, pp 899-906.
  • Parasuraman, S., and Igbaria, M. "An Examination of Gender Differences in the Determinants of Computer Anxiety and Attitudes Towards Microcomputers Among Managers," International Journal of Man-Machine Studies (32:3) 1990, pp 327-340.

Security Theories

Computer Anxiety: "Excessive timidity in using computers, negative comments against computers and information science, attempts to reduce the amount of time spent using computers, and even the avoidance of using computersfrom the place where they are located" (Doronina, 1995).

  • Doronina, O. "Fear of Computers: Its Nature, Prevention and Cure," Russian Social Science Review (36:4) 1995, pp 79-90.


General Deterrence Theory:
  • BOSS SR, KIRSCH LJ, ANGERMEIER I, SHINGLER RA and BOSS RW (2009) If Someone Is Watching, I’ll Do What I’m Asked: Mandatoriness, Control, and Information Security. European Journal of Information Systems 18(2), 151–164. 
  • STRAUB DW and WELKE RJ (1998) Coping With Systems Risk: Security Planning Models for Management Decision Making. MIS Quarterly 22(4), 441–469.
  • D’ARCY J and HOVAV A (2009) Does One Size Fit All? Examining the Differential Effects of IS Security Countermeasures. Journal of Business Ethics 89, 59–71.
  • HERATH T and RAO HR (2009) Protection Motivation and Deterrence: A Framework for Security Policy Compliance in Organisations. European Journal of Information Systems 18(2), 106–125. 
  • PAHNILA S, SIPONEN M and MAHMOOD A (2007) Employees’ Behavior towards IS Security Policy Compliance. In: 40th Annual Hawaii International Conference on System Sciences. Waikoloa, HI: IEEE Computer Society.
  • STRAUB DW (1990) Effective IS Security: An Empirical Study. Information Systems Research 1(3), 255–276. 

Protection Motivation Theory:
  • Rogers, R.W. (1975). A protection motivation theory of fear appeals and attitude change. Journal of Psychology, 91, 93-114.
  • Rogers, R.W. (1983). Cognitive and physiological processes in fear appeals and attitude change: A revised theory of protection motivation. In J. Cacioppo & R. Petty (Eds.), Social psychophysiology (pp. 153-176). New York: Guilford.
  • MADDUX JE and ROGERS RW (1983) Protection Motivation and Self-Efficacy: A Revised Theory of Fear Appeals and Attitude Change. Journal of Experimental Social Psychology 19(5), 469– 479.
  • CROSSLER RE (2010) Protection Motivation Theory: Understanding Determinants to Backing Up Personal Data. In: 43rd Hawaii International Conference on System Sciences. pp. 1–10.
  • HERATH T and RAO HR (2009) Protection Motivation and Deterrence: A Framework for Security Policy Compliance in Organisations. European Journal of Information Systems 18(2), 106–125.
  • JOHNSTON AC and WARKENTIN M (2010) Fear Appeals and Information Security Behaviors: An Empirical Study. MIS Quarterly 34(3), 549–A4.
  • PAHNILA S, SIPONEN M and MAHMOOD A (2007) Employees’ Behavior towards IS Security Policy Compliance. In: 40th Annual Hawaii International Conference on System Sciences. Waikoloa, HI: IEEE Computer Society.
  • VANCE A, SIPONEN M and PAHNILA S (2012) Motivating IS Security Compliance: Insights from Habit and Protection Motivation Theory. Information & Management 49(3–4), 190–198.
  • WOON I, TAN G-W and LOW R (2005) A Protection Motivation Theory Approach to Home Wireless Security. In: Proceedings of the 26th International Conference on Information Systems. pp. 367–380.
  • LEE Y and LARSEN KR (2009) Threat or Coping Appraisal: Determinants of SMB Executives’ Decision to Adopt Anti-Malware Software. European Journal of Information Systems 18(2), 177–187. 
Neutralization Theory:


Technology Threat Avoidance Theory (TTAT): Posits that threat avoidance behavior functions as a dynamic positive feedback loop (concept derived from cybernetic theory, and general systems theory) composed of two cognitive processes, threat and coping appraisals, which determine how an individual would cope with IT threats.
  • LIANG H and XUE Y (2009) Avoidance of Information Technology Threats: A Theoretical Perspective. MIS Quarterly 33(1), 71–90.
  • LIANG H and XUE Y (2010) Understanding Security Behaviors in Personal Computer Usage: A Threat Avoidance Perspective. Journal of the Association for Information Systems 11(7), 394– 413. 
Fear Appeal Theory
  • JOHNSTON AC and WARKENTIN M (2010) Fear Appeals and Information Security
  • Behaviors: An Empirical Study. MIS Quarterly 34(3), 549–A4.
Technology Anxiety (As a predictor of technology adoption): An individual's tendency to be uneasy, aprehensive, or fearful about the current or future use of technology ((Parasuraman, et al,m 1990; Allen, 2002).
  • Allen, J.W., and Parikh, M.A. "The Impact of Personal Traits on IT Adoption," Proceedings of the 8th Americas Conference on Information Systems, Dallas, TX, USA, 2002.
  • Meuter, M.L., Ostrom, A.L., Bitner, M.J., and Rountree, R. "The Influence of Technology Anxiety on Consumer Use and Experiences with Self-Service Technologies," Journal of Business Research (56) 2003, pp 899-906.
  • Parasuraman, S., and Igbaria, M. "An Examination of Gender Differences in the Determinants of Computer Anxiety and Attitudes Towards Microcomputers Among Managers," International Journal of Man-Machine Studies (32:3) 1990, pp 327-340.

Monday, June 6, 2016

AACSB Impact Forum

The College of Business at Tarleton State University is pushing to obtain accreditation from the Association to Advance Collegiate Schools of Business (AACSB), the premier accrediting body for business schools. Before this process began, I knew that AACSB existed. I knew the general idea behind accreditation. But, I can honestly say that I did not know the degree to which they can drive value within a business school by helping to establish and maintain standards by which schools can first be measured and second, continuously improve.

As part of our push for accreditation, this last weekend, I attended one of their "Impact Forums" held at their international headquarters in Tampa Florida. They have identified impact as one of the three pillars of accreditation along with engagement and innovation. But impact is something that can be a little nebulous at times. After all, how do we know that our teaching is having real "impact"? Hence, the reason behind the forum.

So, what is "impact" and how does it apply to the college of business? Well, impact is pretty easy to define: to have a strong effect on something or someone. But, how does that apply to the college of business? Well, we want our teaching, research, and service to have impact. Of course, the assumption is that the impact is positive and hopefully it is.

Traditionally, as faculty, impact has been assessed by counting journal publications in peer reviewed journals and/or publications in high quality journals. Why? Because they are relatively easy to measure. But, we have to realize that impact has many different stakeholders. These might include faculty, staff, administrators, or the academy itself. Other stakeholders might include students, businesses, accrediting organizations, governing bodies, and so on.

So, we need to look at impact from a much broader perspective. Again, as it relates to research, while counting the number of peer reviewed journal publications a researcher had, additional impact information that might prove useful is whether or not other professors are using that work in their classes. Are businesses applying that research to their organization? That is real impact.

But, measuring such impact can prove difficult. Sometimes it takes considerable time for impact to be seen. For example, sometimes research can take more than a year to get published. Beyond that, such research must then be disseminated to various stakeholders for them to begin to be influenced by the results. Ultimately, it may be 2 or 3 years later or more before an impact can be measured. Even then, whether the impact is explicit or implicit can make measuring them difficult at best.

What about other kinds of impact though? Turns out, they are all around us. Some of them are quite easy to measure. We just need to rethink how we look at impact. For example, the number of degrees granted and student placement success (along with research quality and quantity) are the most commonly used impact metrics. These are followed by the number of consulting projects and applied research, rankings, surveys and feedback from key stakeholders, and community engagement and student projects. Finally, we have things like assurance of learning data, alumni engagement, and so on that can serve as representing impact.

So, the scope of impact is much broader than how it might have originally been interpreted. In academia, we impact all three areas: research, teaching, and service. The key is to recognize when we are having an impact and weaving it into a coherent story that helps us to tell our story as an institution.

With such a large potential scope of impact with which to tell our story, how do you know where to start? Start with your mission statement. It tells stakeholders what you value the most. If that is where your value is, that is where the focus of your impact measurements should be. For example, if you are a teaching school and you value innovative teaching, you should probably focus less on measuring and reporting the impact of research. That is not to say that research should be completely ignored. It just should not be "featured".

So, start with your mission and align appropriate metrics to assess impact. Identify what is impacted, by what, how, what the measures are, and how often they are to be measured. You are painting a road map here so that you can create repeatable results. In the end, this does not have to be a painful process. You do have openly and honestly reflect on your college. But, I think in the long run, it creates an environment for continuous improvement that keeps people engaged and excited about coming to work and doing great things!

Wednesday, February 24, 2016

What is a router and what does it do?

In working with students on their logical designs, it has become clear to me that many students get confused about the differences between routers and switches. So, I wanted to take a moment to talk specifically about routers. So, what is a router? Well, a router links together two similar networks in order to direct IP packets from one network to another. When you see IP, you should automatically start thinking about the OSI model and specifically, layer 3 of the OSI model.

Figure 1: The OSI Model

Typically, when students start creating their logical diagram, if they include logical configuration information at all, they always seem to focus on the internal side of this connection; the LAN side. But there is the WAN side of this connection as well. What kind of configuration information is on the WAN side of the connection? It (hopefully) obviously needs an IP address. Just to make this clear, every device connected to the Internet needs a unique IP address in order to be able to communicate with other devices over the Internet. The WAN connection also needs a subnet identified. The subnet is important because it tells the router on the WAN side of the connection which part of the IP address refers to the network and which part refers to the router itself (on the WAN side). The WAN side also needs a default gateway. If the router does not know where to route a particular packet, it needs the default gateway to forward the packet to a higher layer router that may in fact know where that particular packet should be sent. Lastly, the WAN side of the connection needs to know a DNS server so that it can resolve domain names and share that information with clients on the LAN side.

Now, the good news is that while you need to know how to configure these settings, you do not have to come up with the numbering scheme itself. If you have a static connection, this information will be provided to you by your ISP. This is typically the case for business class services in which you need your external address to stay the same so that web server, email servers, and so on can routinely be found in the same place logically. Consumers typically have dynamic addresses and this really makes things easy as the router reaches out to the ISP and obtains this information automatically. The advantage of this is obviously that it reduces your administrative burden.

Figure 2 below shows a router where the WAN port is labeled 'Line' and then it also happens to have a four port switch built into the router, with each port labeled 1 through 4. So, the WAN configuration information is associated with the WAN or 'Line' side of the router whereas the LAN side of the configuration information is associated with the clients associated with the four ports.
Figure 2: Router

On the internal side of the network, we also have configuration information that is needed. Specifically, we need an IP address and a subnet mask to tell the router which portion of the IP address represents the network and which part represents the router itself. The IP address serves as the default gateway for all the clients on the internal side of the network. Where is the rest of the configuration information internally? It's not there. When a client on the internal side of the network does not know where the server is that it is trying to communicate with, it sends the packet to its default gateway which is found in its own configuration information. That gateway is the router's LAN connection. When the router gets that request, if the requested server is not on the LAN side of the connection, it routes the packet to the WAN side of the connection which includes a default gateway so that it knows where to forward the packet.

Figure 3 illustrates a sample logical diagram. In this diagram, for the gateway router, you should see that the WAN connection is dynamically set. Again, this makes it easy on the network administrator. Internally, there is an IP address and a Subnet Mask (SM). There is also an SSID to indicate that this is also a wireless router as well as information indicating that this wireless router is capable as serving as a DHCP server.

Figure 3: Logical Diagram

You may also notice a second, internal router is included in the diagram. This design is segmenting the network at layer 3. I want to draw your attention to the WAN side of the internal router. It includes the IP address and the default gateway. Specifically, I want to draw your attention to the IP address and the fact that it is on the same subnet as the internal side of the gateway router. This is necessary so that the two routers can communicate. Also, note the internal IP address of the internal router. Note that it is on a different subnet. As a result, it can be said that this network is segmented to keep traffic from the business side of the network separate of the traffic on the personal side of the network.

So, that is what a router is and some basic information about the configuration information that goes into a router and whatnot. Commercial routers get much more complicated quickly. But, at the same time, commercial routers are beginning to take on similar dashboards to consumer grade routers making them easier to configure and use. If you have any questions, please leave a comment. Follow me on Twitter @SchuesslerPhD and until next time, happy networking.

Dr. S.

Tuesday, January 19, 2016

PANs, LANs, and WANs, Oh My!

Trying to cover some of the basics this week in my undergraduate networking class. One question that regularly comes up is what the differences are between LANs and WANs. Well of course, if you are familiar with this concept, then the answer is simple. But for some of my students who are just starting out in technology in general and networking specifically, the delineations may not be quite so clear. Below, I have put together a short little video going over the characteristics of each and included some additional explanation for other types of networks.


Personal Area Networks (PANs):  PANs are small networks, usually made up of BlueTooth devices to quickly and easily connect devices within a few feet of each other.  We see examples such as BlueTooth headsets that link together with cell phones, BlueTooth Printers that wirelessly connect to computers to eliminate cables for printers. I have a little Google Nexus 7” tablet that connects via BlueTooth, eliminating the need to plug in any sort of cabling.
Local Area Networks (LANs): LANs are larger in scale.  Though different texts will provide similar but often distinct definitions, recognize that it can sometimes be difficult to determine precisely what represents a LAN versus a CAN versus a PAN, etc.  For the most part, a LAN exists on a single property where cables and wireless access points can be deployed without the need to lease lines from a carrier or obtain permission from anyone else.  LANs will consist of two or more nodes to usually no more than a few hundred and they will usually stretch no more than a few hundred feet.
Campus Area Networks (CANs): CANs are larger still.  Think of your local university or large corporate headquarters like Microsoft in Redmond Washington.  These are areas that have a need for more than a couple hundred nodes on the network.  Rather, they have a need to connect multiple LANs together yet all on contiguous property.  This LAN of LANs as described here, can be referred to as a CAN.
Metropolitan Area Networks (MANs): MANs are larger in scope yet again; this time spanning the size of a city or even multiple cities.  These are becoming more and more common.  Denton and Granbury Texas both have MANs that provide services not only to citizens, but also to workers who require network access in the field.

Wide Area Networks (WANs): WANs are the ultimate in scope.  They span larger regions still to potentially covering the planet.  The Internet is the ultimate example of a WAN though certainly not the only WAN that exists.  Many corporations lease lines in various cities around the world in order to establish their WAN. WANs often utilize public carriers such as AT&T, Sprint, and so on in order to capitalize on what they do well rather than have to become experts themselves at laying and maintaining lines around the world, a very expensive endeavor.