Google Search

Showing posts with label drives. Show all posts
Showing posts with label drives. Show all posts

Saturday, May 24, 2014

Ensuring solid-state drives are up to scratch: Data buffering scheme improves performance of solid-state drives

A data buffering scheme improves the performance of solid-state drives in large-scale, data-intensive applications.

Solid-state drives (SSDs) store digital information using electronic circuits. The power efficiency of SSDs and their ability to read and write data quickly means that they are becoming the primary storage device in computers. A major drawback of SSDs, however, is the limited number of times that data can be stored and deleted -- an aspect that hinders the use of these devices for data-intensive applications known as data-center environments.

Qingsong Wei and co-workers at the A*STAR Data Storage Institute and National University of Singapore have developed a scheme for writing data to SSDs that could circumvent these problems to make solid-state drives useful for an even broader range of applications.

SSDs divide their storage space into distinct areas called blocks. A computer can either save large files across consecutive blocks -- a process known as sequential writing -- or write smaller files in blocks scattered throughout the device -- so-called random writing.

The researchers conducted an intensive workload study of the distribution of read and write request sizes over ten real enterprise workload traces supplied by the Storage Network Industry Association. They found that the highest traffic was from small, random requests of less than 64 kilobytes in size.

Generally, random writing is much slower -- by as much as four times -- than sequential writing. One way around this bottleneck is to use part of the memory as a 'buffer'. The buffer briefly stores data as it comes into the drive, which then enables sequential writing at a later time. Current buffer management approaches improve sequential writing but only at low buffer usage, wasting expensive buffer space.

Wei's team helped to solve this problem through an alternative approach that categorizes the data in the buffer by its popularity, which reflects how frequently the data is likely to be needed. The scheme retains popular blocks in the buffer, rather than deleting them, and sequentially writes less popular blocks to the SSD.

"Our buffer management scheme can increase sequential writing with high buffer utilization, thus improving performance and extending the lifetime of the SSD," says Wei.

The researchers tested the approach and demonstrated that the so-called popularity-aware buffer management scheme, or PAB, can achieve an improvement in performance of up to 72 per cent and triple the device lifetime compared to existing schemes. "Our method reduces the cost of SSDs by improving buffer utilization and is easy to implement," explains Wei. "Our next step will be to design smarter SSDs by integrating these same ideas with emerging non-volatile memory."

Journal Reference:

Qingsong Wei, Lingfang Zeng, Jianxi Chen, Cheng Chen. A Popularity-Aware Buffer Management to Improve Buffer Hit Ratio and Write Sequentiality for Solid-State Drive. IEEE Transactions on Magnetics, 2013; 49 (6): 2786 DOI: 10.1109/TMAG.2013.2249579

View the original article here

Wednesday, October 16, 2013

US child porn suspect doesn't have to decrypt hard drives - yet

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Child, courtesy of ShutterstockIn a case that could have far-reaching implications for compelling criminal suspects to decrypt digital storage devices, a judge on Tuesday stayed [PDF, posted courtesy of Wired] - temporarily suspended - a previous order that would have forced him to decrypt hard drives suspected of containing child pornography.

The hard drives were seized from computer scientist Jeffrey Feldman, from the US state of Wisconsin.

The government has previously said in court papers that even without forcing Feldman to decrypt storage devices found in his house, they have managed to glean incriminating data from unencrypted portions of the storage.

The government says it found a large number of user-created links that "strongly suggest, often in graphic terms," the presence of encrypted abuse images on Feldman's hardware.

The investigators also found a peer-to-peer sharing utility that contained logs of 1,009 videos that Feldman had allegedly received, distributed and stored - most of the filenames being "unambiguously indicative" of child porn.

At question is Feldman's right, under the Fifth Amendment, to be shielded from self-incrimination.

Magistrate William Callahan Jr. of Wisconsin wrote in April that this is "a close call," but that if Feldman used a password to decrypt a storage device, it would be, more or less, the same as telling the government "something it does not already know" and would be tantamount to self-incrimination.

Callahan subsequently viewed new evidence that caused him to reconsider.

According to the order [PDF], the Federal Bureau of Investigations (FBI) had managed, given "substantial resources," to decrypt and access one single hard drive.

Hard drive, courtesy of ShutterstockOn that decrypted segment of Feldman's far more extensive storage system, the FBI says it found "an intricate electronic folder structure comprised of approximately 6,712 folders and subfolders," in which agents found 707,307 files, including "numerous files which constitute child pornography."

Writing [PDF] in late May, Callahan ordered Feldman to either enter the passwords without being observed by law enforcement or government counsel, or provide an unencrypted copy of the data.

However, a new federal judge, Rudolph Randa, has stayed that decision. Ars Technica's Cyrus Farivar writes that Callahan was taken off the case, not being an "Article III Judge" and lacking the authority to grant the order in the first place.

The latest wrinkle in Feldman's case doesn't do much but postpone the question of whether compelling somebody to decrypt their electronic storage device is a violation of Fifth Amendment rights.

But if the government already has enough evidence to convict Feldman of possessing child abuse images, is it necessary to compel decryption?

We'll keep watching this space. Regardless of this case or others like it, it's important to fight the erosion of rights such as those granted by the Fifth Amendment.

Follow @LisaVaas
Follow @NakedSecurity

Image of child and hard drive courtesy of Shutterstock.


View the original article here

Friday, August 9, 2013

US child abuse image suspect shielded from decrypting hard drives

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Person behind glass. Image courtesy of Shutterstock.A US federal magistrate has refused to order a Wisconsin computer scientist and child abuse image suspect, Jeffrey Feldman, to decrypt the hard drives the government seized from him.

The rationale of Magistrate William Callahan Jr. of Wisconsin: the Fifth Amendment to the US Constitution shields citizens from being compelled to self-incriminate.

Callahan wrote [PDF, posted courtesy of Wired] that, unlike in similar cases, where the government has compelled people to unlock the encrypted portions of their hard drives, in this case, Feldman hasn't admitted that he has access and control of the hardware.

This is in spite of the many storage devices in question having been found in his house, where he's lived alone for 15 years.

Callahan's thinking:

This is a close call, but I conclude that Feldman’s act of production, which would necessarily require his using a password of some type to decrypt the storage device, would be tantamount to telling the government something it does not already know with 'reasonably particularity' - namely, that Feldman has personal access to and control over the encrypted storage devices. Accordingly, in my opinion, Fifth Amendment protection is available to Feldman. Stated another way, ordering Feldman to decrypt the storage devices would be in violation of his Fifth Amendment right against compelled self-incrimination.

The government, trying to convince the courts to force the suspect to comply, had said [PDF, again posted courtesy of Wired] that if Feldman doesn't unlock the drives, the case could suck up even more resources than it has already, and investigators might even damage the hardware.

From the court papers:

The United States, the FBI in particular, has already expended substantial resources in the effort to break the encryption preventing it from accessing the information as ordered by the Search Warrant and more will be required if the encryption must be broken manually. Members of the FBI's Computer Analysis Response Team (CART) have spent more than ten weeks decrypting Mr. Feldman's storage devices.

In fact, the prosecutors warn, encryption is getting both tougher to crack and used more widely, painting "a grim picture of the future for law enforcement officers" as they seek to carry out court-mandated search warrants.

Locked computer. Image courtesy of Shutterstock.Even if you're a privacy absolutist, even if you believe that the FBI and other law enforcement agencies in the US have gotten a bit too cozy with surveillance of the nation's citizenry and warrantless searches, you've got to have a bit of sympathy for law enforcement here if you believe (and I hope that you all do) that putting child abuse image collectors and creators out of business is a vital job.

The government said in its court papers that what they did manage to glean from unencrypted portions of Feldman's computer storage showed a large number of user-created links that "strongly suggest, often in graphic terms," the presence of encrypted abuse images on Feldman's hardware.

The investigators also found a peer-to-peer sharing utility that contained logs of 1,009 videos that Feldman had allegedly received, distributed and stored - most of the filenames being "unambiguously indicative" of child porn.

If your first inclination is to curse the judge, check that impulse. This is about far more than this one alleged child abuse image collector.

Hanni Fakhoury, a staff attorney with the Electronic Frontier Foundation, told Wired that the decision is important beyond whether it gums up a child abuse prosecution, because it's a core issue in regards to government overreach:

This isn’t just about child porn. It’s about anything on your computer that prosecutors or government officials may want.

It's hard to get enthused about a court decision that hampers law enforcement as they work hard to fight child abuse.

But curbing law enforcement's already substantial power, particularly when it comes to power that would contradict our Constitutionally guaranteed rights, is what a properly functioning judicial system should be doing.

Add this to a recent judicial decision to deny the FBI the right to plant spyware on a bank fraud suspect's computer, and you have to come to the conclusion that US courts certainly are capable of gleaning the subtleties of where electronic information, surveillance and our rights intersect.

Should we keep watching this space? Oh, yes.

Just as encryption gets stronger and technology advances, so is the legal landscape every shifting.

That shifting landscape is a very good reason to encrypt your hard drive, though of course device loss and hacking, as always, are right up there to bolster the encryption argument.

Follow @LisaVaas
Follow @NakedSecurity

Images of Person behind glass and locked computer courtesy of Shutterstock.


View the original article here

Wednesday, December 26, 2012

LinkedIn spam drives traffic to Toronto Drug Store

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

At first glance it may look like an official email from LinkedIn, the professional business networking site, asking you to confirm your email address.

But it's not.

LinkedIn email spam

Because the emails don't really come from LinkedIn, and clicking on the link does not take you to the LinkedIn website.

Instead your browser is redirected to a website announcing that it is the "Toronto Drug Store", where a square-jawed trustworthy doctor-type is accompanied by a cut-price Anne Hathaway lookalike.

Toronto Drug Store website

The online store claims it will be able to help you with erectile disfunction, and even offers a Thanksgiving sale in the form of a Cialis+Viagra "powerpack". (A steal at $74.95).

Of course, the link embedded inside the email could just have easily taken your browser to a website hosting malicious code, or a phishing page designed to steal your LinkedIn credentials.

The gang behind this spam campaign are banking on just a tiny proportion of the email recipients being tempted to buy something from the Toronto Drug Store website. If that occurs, despite the recipients initially believing they had received an email from LinkedIn, it will be worth the effort of the spammers because of the commission they can earn.

Yes, it's hard to believe that such a business model really works - but the cost of sending spam to millions of people is so small, and requires such little effort, that it still goes on.

My advice to you is to invest in a decent security solution that protects you not only against spam and malware that arrives in your email, but also checks the websites you are visiting in case they are dodgy too.

And remember to never buy goods sold via spam. If you do, you're just encouraging the spam problem to continue.

If you receive an email out of the blue from a brand that you trust, think twice before blindly clicking on the link - it may not be taking you to the real website at all.

Follow @gcluley

View the original article here