Physical Media
Physical Media
Physical media refers to the physical materials that are used to store or transmit information in data communications. These physical media are generally physical objects made of materials such as copper or glass. They can be touched and felt, and have physical properties such as weight and color. For a number of years, copper and glass were the only media used in computer networking.
The term physical media can also be used to describe data storage media like records, cassettes, VHS, LaserDiscs, CDs, DVDs, and Blu-rays, especially when compared with modern streaming media or content that has been downloaded from the Internet onto a hard drive or other storage device as files.
PHYSICAL TRANSMISSION MEDIA
Physical transmission media used in communications include twisted-pair cable, coaxial cable, and fiber-optic cable. These cables typically are used within or underground between buildings. Ethernet and token ring LANs often use physical transmission media.
Twisted-Pair Cable
One of the more commonly used transmission media for network cabling and telephone systems is twisted-pair cable. Twisted-pair cable consists of one or more twisted-pair wires bundled together (Figure 8-24). Each twisted-pair wire consists of two separate insulated copper wires that are twisted together. The wires are twisted together to reduce noise. Noise is an electrical disturbance that can degrade communications.
Coaxial Cable
Coaxial cable, often referred to as coax (pronounced KO-ax), consists of a single copper wire surrounded by at least three layers: (1) an insulating material, (2) a woven or braided metal, and (3) a plastic outer coating (Figure 8-25).
Cable television (CATV) network wiring often uses coaxial cable because it can be cabled over longer distances than twisted-pair cable. Most of today’s computer networks, however, do not use coaxial cable because other transmission media such as fiber-optic cable transmit signals at faster rates.
Fiber-Optic Cable
The core of a fiber-optic cable consists of dozens or hundreds of thin strands of glass or plastic that use light to transmit signals. Each strand, called an optical fiber, is as thin as a human hair. Inside the fiber-optic cable, an insulating glass cladding and a protective coating surround each optical fiber. (Figure 8-26).
Fiber-optic cables have the following advantages over cables that use wire, such as twisted-pair and coaxial cables:
- Capability of carrying significantly more signals than wire cables
- Faster data transmission
- Less susceptible to noise (interference) from other devices such as a copy machine
- Better security for signals during transmission because they are less susceptible to noise
- Smaller size (much thinner and lighter weight)
Disadvantages of fiber-optic cable are it costs more than twisted-pair or coaxial cable and can be difficult to install and modify. Despite these limitations, many local and long- distance telephone companies are replacing existing telephone lines with fiber-optic cables, enabling them to offer fiber Internet access to home and business users.
WIRELESS TRANSMISSION MEDIA
Many users opt for wireless transmission media because it is more convenient than installing cables. In addition, businesses use wireless transmission media in locations where it is impossible to install cables. Types of wireless transmission media used in communications include infrared, broadcast radio, cellular radio, microwaves, and communications satellites.
Infrared
As discussed earlier in the chapter, infrared (IR) is a wireless transmission medium that sends signals using infrared light waves. Mobile computers and devices, such as a mouse, printer, and smart phone, often have an IrDA port that enables the transfer of data from one device to another using infrared light waves.
Broadcast Radio
Broadcast radio is a wireless transmission medium that distributes radio signals through the air over long distances such as between cities, regions, and countries and short distances such as within an office or home. Bluetooth, UWB, Wi-Fi, and WiMAX communications technologies discussed earlier in this chapter use broadcast radio signals.
Cellular Radio
Cellular radio is a form of broadcast radio that is used widely for mobile communications, specifically wireless modems and cell phones. A cell phone is a telephone device that uses high-requency radio waves to transmit voice and digital data messages. Some mobile users connect their notebook computer or other mobile computer to a cell phone to access the Web, send and receive e-mail, enter a chat room, or connect to an office or school network while away from a standard telephone line.
Personal Communications Services (PCS)
is the term used by the United States Federal Communications Commission (FCC) to identify all wireless digital communications. Devices that use PCS include cell phones, PDAs, pagers, and fax machines.
is the term used by the United States Federal Communications Commission (FCC) to identify all wireless digital communications. Devices that use PCS include cell phones, PDAs, pagers, and fax machines.
Microwaves
Microwaves are radio waves that provide a high-speed signal transmission. Microwave transmission, often called fixed wireless, involves sending signals from one microwave station to another. Microwaves can transmit data at rates up to 4,500 times faster than a dial-up modem.
A microwave station is an earth-based reflective dish that contains the antenna, transceivers, and other equipment necessary for microwave communications. Microwaves use line-of-sight transmission. To avoid possible obstructions, such as buildings or mountains, microwave stations often sit on the tops of buildings, towers, or mountains. Microwave transmission is used in environments where installing physical transmission media is difficult or impossible and where line-of-sight transmission is available. For example, microwave transmission is used in wide-open areas such as deserts or lakes; between buildings in a close geo- graphic area; or to communicate with a satellite. Current users of microwave transmission include universities, hospitals, city governments, cable television providers, and telephone companies. Home and small business users who do not have other high-speed Internet connections available in their area also opt for lower-cost fixed wireless plans.
Communications Satellite
A communications satellite is a space station that receives microwave signals from an earth-based station, amplifies (strengthens) the signals, and broadcasts the signals back over a wide area to any number of earth-based stations. These earth-based stations often are microwave stations. Other devices, such as smart phones and GPS receivers, also can function as earth-based stations. Transmission from an earth-based station to a satellite is an uplink. Transmission from a satellite to an earth-based station is a downlink.
Applications such as air navigation, television and radio broadcasts, weather forecasting, video conferencing, paging, global positioning systems, and Internet connections use communications satellites. With the proper satellite dish and a sat- ellite modem card, consumers access the Internet using satellite technology. With satellite Internet connections, however, uplink transmissions usually are slower than downlink transmissions. This difference in speeds usually is acceptable to most Internet satellite users because they download much more data
than they upload. Although a satellite Internet connection is more expensive than cable Internet or DSL connections, sometimes it is the only high-speed Internet option in remote areas.
than they upload. Although a satellite Internet connection is more expensive than cable Internet or DSL connections, sometimes it is the only high-speed Internet option in remote areas.
Shared and point-to-point media
Shared and Point-to-Point Media
Connections (Ethernet shared media and point-to-point)
Data can be shared using wired or wireless media. Wired media uses different cables such as fiber optic cable, Coaxial cable, twisted pair, etc. In wireless media, radio frequency is used. Computers connected by communication channels that each connect exactly two computers with access to the full channel bandwidth. It allows flexibility in communication hardware, packet formats, etc. It provides security and privacy because the communication channel is not shared.
Connections (Ethernet shared media and point-to-point)
Point-to-point:
- Computers connected by communication channels that each connect Exactly two computers with access to full channel bandwidth.
- Forms a mesh or point-to-point network.
- Allows flexibility in communication hardware, packet formats, etc.
- Provides security and privacy because communication channel is not shared.
- Number of channels grows as square of number of computers
Shared or Broadcast Channel:
- All computers connected to a shared broadcast-based communication channel and share the channel bandwidth.
- Security issues as a result of broadcasting to all computers.
- Cost effective due to reduced number of channels and interface hardware components.
Ethernet: Ethernet is the most widely used LAN technology. Invented at Xerox PARC (Palo Alto Research Center) in 1970s. Defined in a standard by Xerox, Intel and Digital - DIX standard. Standard is now managed by IEEE - defines formats, voltages, cable lengths, etc., IEEE 802.3:
- 10BASE-T: Standard Ethernet 10Mbps.
- 100-BASE-T: Fast Ethernet 100Mbps.
- 1000-BASE-T: Gigabit Ethernet 1000Mbps.
- One Ethernet cable is sometimes called a segment.
- Limited to 500 meters in length for 10BASE-T.
Uses:
- Bus Topology: Single coax, cable forming a segment - the ether
- Star Topology: Using hubs or switches (several segments).
Common Technologies
Twisted-Pair Copper Wire
The least expensive and most commonly used guided transmission medium is twisted-pair copper wire. For over a hundred years it has been used by telephone networks. In fact, more than 99 percent of the wired connected from telephone handset to the local telephone switch use twisted-pair copper wire. Most of us have seen twisted pair in our homes and work environments. Twisted pair consists of two insulated coper wires, each about 1 mm thick , arranged in a regular spiral pattern. The wires are twisted together to reduce the electrical interference from similar pairs close by. Typically, a number of pairs are bundled together in a cable by wrapping the pairs in a protective shield. A wire pair constitutes a single communication link. Unshielded twisted pair (UTP) is commonly used for computer networks within a building, that is, for LANs. Data rates for LANs using twisted pair today range from 10
Mbps to 10 Gbps. The data rates that can be achieved depend on the thickness of the wire and the distance between transmitter and receiver.
Mbps to 10 Gbps. The data rates that can be achieved depend on the thickness of the wire and the distance between transmitter and receiver.
When fibre-optic technology emerged in 1980s, many people disparaged twisted pair because of its relatively low bit rates. Some people even felt that fibre optic technology would completely replace twisted pair. But twisted pair did not give up easily. Modern twisted-pair technology , such as category 6a cable, can achieve data rates of 10 Gbps for distances up to a hundred meters. In the end, twisted pair has emerged as the dominant solution for high-speed LAN networking.
As discussed earlier, twisted pair is also commonly used for residential internet access. We saw that dial-up modem technology enables access rates of up to 56kbps over twisted pair. We also saw that DSL (digital subscriber line) technology has enabled residential users to access internet at tens of Mbps over twisted pair (when users live close to the ISP’s modem).
Coaxial Cable
Like twisted pair, coaxial cable consists of two copper conductors but the two conductor are concentric rather than parallel. With this construction and special insulation and shielding, coaxial cable can achieve high data transmission rates. Coaxial cable is quite common in cable television systems. As we saw earlier, cable television systems have recently been coupled with cable modems to provide residential users with internet access at rates of tens of Mbps. In cable television and cable internet access, the transmitter shifts the digital signal to a specific frequency band, and the resulting analog signal is sent from the transmitter to one or more receivers. Coaxial cable can be used as a guided shared medium. Specifically, a number of end systems can be connected directly to the cable, with each of the end systems receiving whatever is sent by the other end systems.
Fiber Optics
An optical fiber is a thin, flexible medium that conducts pulses of light, with each pulse representing a bit. A single optical fiber can support tremendous bit rates, up to tens or even hundreds of gigabits per second. They are immune to electromagnetic interference, have very low signal attenuation upto 100 kilometers, and are very hard to tap. These characteristics have made fiber optics the preferred long-haul guided transmission media, particularly for overseas links. Many of the long-distance telephone networks in the United States and elsewhere now use fiber optics exclusively. Fiber optics is also prevalent in the backbone of the internet. However, the high cost of optical devices- such as transmitters, receivers, and switches – has hindered their deployment for short-haul transport, such as in a LAN or into the home in a residential access network. The Optical Carrier (OC) standard link speeds range from 51.8 Mbps to 39.8 Gbps; these specifications are often referred to as OC-n, where the link speed equals nx51.8 Mbps. Standards in use today include OC-1, OC-3, OC-12, OC-24, OC-48. OC-96, OC-192, OC-768
Terrestrial Radio Channels
Radio channels carry signals in the electromagnetic spectrum. They are an attractive medium because they require no physical wire to be installed, can penetrate walls, provide connectivity to a mobile user, and can potentially carry a signal for long distances. The characteristics of a radio channel depend significantly on the propagation environment and the distance over which a signal is to be carries. Environmental considerations determine path loss and shadow fading (which decrease the signal strength as the signal travels over a distance and around/through obstructing objects), multipath fading (due to signal reflection off of interfering objects), and interference (due to other transmissions and electromagnetic signals.)
Terrestrial radio channels can be broadly classified unto three groups: those that operate over very short distance (e.g. with one or two meters); those that operate in local areas, typically spanning from 10 to a few hundred meters; and those that operate in the wide area, spanning tens of kilometres. Personal devices such as wireless handsets, keyboards, and medical devices operate over short distances; the wireless LAN technologies use local-area radio channels; the cellular access technologies use wide-area radio channels.
Satellite Radio Channels
A communication satellite links two or more Earth-based microwave transmitter/receivers, known as ground stations. The satellite receives transmissions on one frequency band, regenerates the signal using a repeater, and transmits the signal on another frequency. Two types of satellites are used in communications: geostationary satellites and low-earth orbiting (LEO) satellites.
LEO
satellites are places much closer to Earth and do not remain permanently above one spot on Earth. They rotate around Earth (just as the Moon does) and may communicate with each other, as well as with ground stations. To provide continuous coverage to an area, many satellites need to be placed in orbit. There are currently many low-altitude communication systems in development. Lloyd’s satellite constellations web page provides and collects information on satellite constellation systems for communications. LEO satellite technology may be used for internet access sometime in the future.
satellites are places much closer to Earth and do not remain permanently above one spot on Earth. They rotate around Earth (just as the Moon does) and may communicate with each other, as well as with ground stations. To provide continuous coverage to an area, many satellites need to be placed in orbit. There are currently many low-altitude communication systems in development. Lloyd’s satellite constellations web page provides and collects information on satellite constellation systems for communications. LEO satellite technology may be used for internet access sometime in the future.
Physical Interface and Connectors
Hardware characteristics and materials
Characteristics Of Hardware
The term hardware was used in English since the sixteenth century, when it designated utensils of hard or heavy metals such as iron, used for hardware or physical works. But since the 1940s, with the appearance of the first and primitive systems of automatic calculation and then computerized calculation, it became essential to distinguish between the physical aspect of the machine and the logical, so this term was rescued with a new meaning since 1947.
Delimitation
Given that the physical components of a computer or computer system can be very varied, a first delimitation of the hardware concept proposes to understand it from two categories:
Principal. The main hardware is that essential for the operation of the system itself, that is, for its basic operation.
Complementary. The complementary hardware would come to be all that destined to fulfill specific and secondary functions, only carried out if the principal is functioning correctly.
Types of hardware
Commonly, the hardware of the computer systems is classified according to its function in the system, according to six possible categories, which are:
Prosecution. Elements that constitute the heart of the system or the computer, that is, its mechanical capacity to perform logical operations. It is also known as the Central Process Unit (CPU).
Storage. Elements that allow you to save the information to retrieve it later, either on the machine’s internal supports or removable and portable supports.
Input peripherals. Devices of specific function, integrated to the machine or removable, that allow to enter information to it.
Output peripherals. Devices of specific function, integrated to the machine or removable, that allow to extract or recover information to it.
Input and output peripherals. Devices that combine the input and output of system information.
Processing units
The CPUs of modern computers are the basic element of the whole system, without which it simply can not be used. It includes a microprocessor, responsible for carrying out logical operations at superhuman speeds, inserted in a motherboard or motherboard in which also the memory units (RAM and ROM) are inserted, and the storage disks are connected. All the
electronic circuits that make up the computer system are mounted on this motherboard, it is its operative core.
electronic circuits that make up the computer system are mounted on this motherboard, it is its operative core.
Storage units
This is the name given to the different forms of memory that a computer system has, and which are commonly:
RAM (Random Access Memory). A type of random access memory that is cleaned when starting or restarting the system, since it is available as a place to temporarily store system data.
ROM (Read Only Memory). The read-only memory serves to provide the system with identical and unmodifiable information necessary for its operation, such as certain basic data systems that allow it to function.
Secondary storage disks. These are the places where the information contained in the computer is accumulated and retrieved, such as operating programs, functional programs or files generated by the user. They can be fixed (hard disks) or portable (compact disks, pen drivers, diskettes).
Input peripherals
Input peripherals are those non-fundamental elements of the system that allow information to be entered into it, either by the user or a network of them, or by a removable storage unit. Thus, digital cameras, keyboards and mice (mouse), CD players, etc. are examples of this.
Output peripherals
The output peripherals are used to extract information from the computer system, either digitally or on a physical medium (paper, for example). This means that printers, faxes, monitors and speakers are examples of output peripherals.
Input and output peripherals
Also called ‘mixed’, these peripherals comply with the function of introducing and extracting information from the computational system. Examples of this are multifunction printers, which allow a document to be scanned and then printed, or headset systems (microphone and earphones) that allow a remote interlocutor to speak and listen.
History of hardware
Four different generations are identified in the evolution of hardware, marked by a specific technological advance that revolutionized them, and which are:
1st generation (1945-1956). The first calculation machines that did not work with relays, but with vacuum tubes.
2nd generation (1957-1963). Electronics through transistors, which reduced the total size of computers considerably.
3rd generation (1964-today). Integrated circuits electronics, printed on silicon wafers.
4th generation (future). This fourth generation is spoken of as devices that overcome the silicon plates and enter new computational formats. There is much speculation about it.
Hardware examples
Common examples of hardware are: monitors, keyboards, video and sound and graphics cards, processors, RAM modules, microphones and speakers, multimedia cameras, touch screens, hearing aids, printers of all kinds, faxes, modems, network cards, electrical circuits, electric batteries, disks, pen drivers.
Hardware Vulnerability
A hardware vulnerability is a weakness in a computer system that threat actors can exploit through remote or physical means. They can then introduce malicious code to breach a network or gain unauthorized access to digital assets.
Sharing Models
Sharing resources
A network is designed to support a potentially large number of users that exchange information with each other. These users produce and consume information which is exchanged through the network. To support its users, a network uses several types of resources. It is important to keep in mind the different resources that are shared inside the network.
The first and more important resource inside a network is the link bandwidth. There are two situations where link bandwidth needs to be shared between different users. The first situation is when several hosts are attached to the same physical link.
Sharing bandwidth
In all these networks, except the full-mesh, the link bandwidth is shared among all connected hosts. Various algorithms have been proposed and are used to efficiently share the access to this resource. We explain several of them in the Medium Access Control section below.
Note: Fairness in computer networks
Sharing resources is important to ensure that the network efficiently serves its user. In practice, there are many ways to share resources. Some resource sharing schemes consider that some users are more important than others and should obtain more resources. For example, on the highways, police cars and ambulances have priority to use the highways. In some cities, traffic lanes are reserved for buses to promote public services, ... In computer networks, the same problem arise. Given that resources are limited, the network needs to enable users to efficiently share them. Before designing an efficient resource sharing scheme, one needs to first formalize its objectives. In computer networks, the most popular objective for resource sharing schemes is that they must be fair. In a simple situation, for example two hosts using a shared 2 Mbps link, the sharing scheme should allocate the same bandwidth to each user, in this case 1
Mbps. However, in a large networks, simply dividing the available resources by the number of users is not sufficient. Consider the network shown in the figure below where A1 sends data to A2, B1 to B2, ... In this network, how should we divide the bandwidth among the different flows ? A first approach would be to allocate the same bandwidth to each flow. In this case, each flow would obtain 5 Mbps and the link between R2 and R3 would not be fully loaded. Another approach would be to allocate 10 Mbps to A1-A2, 20 Mbps to C1-C2 and nothing to B1-B2. This is clearly unfair.
Mbps. However, in a large networks, simply dividing the available resources by the number of users is not sufficient. Consider the network shown in the figure below where A1 sends data to A2, B1 to B2, ... In this network, how should we divide the bandwidth among the different flows ? A first approach would be to allocate the same bandwidth to each flow. In this case, each flow would obtain 5 Mbps and the link between R2 and R3 would not be fully loaded. Another approach would be to allocate 10 Mbps to A1-A2, 20 Mbps to C1-C2 and nothing to B1-B2. This is clearly unfair.
In large networks, fairness is always a compromise. The most widely used definition of fairness is the max-min fairness. A bandwidth allocation in a network is said to be max-min fair if it is such that it is impossible to allocate more bandwidth to one of the flows without reducing the bandwidth of a flow that already has a smaller allocation than the flow that we want to increase. If the network is completely known, it is possible to derive a max-min fair allocation as follows. Initially, all flows have a null bandwidth and they are placed in the candidate set. The bandwidth allocation of all flows in the candidate set is increased until one link becomes congested. At this point, the flows that use the congested link have reached their maximum allocation. They are removed from the candidate set and the process continues until the candidate set becomes empty.
In the above network, the allocation of all flows would grow until A1-A2 and B1-B2 reach 5 Mbps. At this point, link R1-R2 becomes congested and these two flows have reached their maximum. The allocation for flow C1-C2 can increase until reaching 15 Mbps. At this point, link R2-R3 is congested. To increase the bandwidth allocated to C1-C2, one would need to reduce the allocation to flow B1-B2. Similarly, the only way to increase the allocation to flow B1-B2 would require a decrease of the allocation to A1-A2.
Network congestion
Sharing bandwidth among the hosts directly attached to a link is not the only sharing problem that occurs in computer networks. To understand the general problem, let us consider a very simple network which contains only point-to-point links. This network contains three hosts and two network nodes. All links inside the network have the same capacity. For
example, let us assume that all links have a bandwidth of 1000 bits per second and that the hosts send packets containing exactly one thousand bits.
example, let us assume that all links have a bandwidth of 1000 bits per second and that the hosts send packets containing exactly one thousand bits.
In the network above, consider the case where host A is transmitting packets to destination C. A can send one packet per second and its packets will be delivered to C. Now, let us explore what happens when host B also starts to transmit a packet. Node R1 will receive two packets that must be forwarded to R2. Unfortunately, due to the limited bandwidth on the R1-R2 link, only one of these two packets can be transmitted. The outcome of the second packet will depend on the available buffers on R1. If R1 has one available buffer, it could store the packet that has not been transmitted on the R1-R2 link until the link becomes available. If R1 does not have available buffers, then the packet needs to be discarded.
Besides the link bandwidth, the buffers on the network nodes are the second type of resource that needs to be shared inside the network. The node buffers play an important role in the operation of the network because that can be used to absorb transient traffic peaks. Consider again the example above. Assume that one average host A and host B send a group of three
packets every ten seconds. Their combined transmission rate (0.6 packets per second) is, on average, lower than the network capacity (1 packet per second). However, if they both start to transmit at the same time, node R1 will have to absorb a burst of packets. This burst of packets is a small network congestion. We will say that a network is congested, when the sum of the traffic demand from the hosts is larger than the network capacity
packets every ten seconds. Their combined transmission rate (0.6 packets per second) is, on average, lower than the network capacity (1 packet per second). However, if they both start to transmit at the same time, node R1 will have to absorb a burst of packets. This burst of packets is a small network congestion. We will say that a network is congested, when the sum of the traffic demand from the hosts is larger than the network capacity
This network congestion problem is one of the most difficult resource sharing problem in computer networks. Congestion occurs in almost all networks. Minimizing the amount of congestion is a key objective for many network operators. In most cases, they will have to accept transient congestion, i.e. congestion lasting a few seconds or perhaps minutes, but will want to prevent congestion that lasts days or months. For this, they can rely on a wide range of solutions. We briefly present some of these in the paragraphs below.
If R1 has enough buffers, it will be able to absorb the load without having to discard packets. The packets sent by hosts A and B will reach their final destination C, but will experience a longer delay than when they are transmitting alone. The amount of buffering on the network node is the first paper that a network operator can tune to control congestion inside his network. Given the decreasing cost of memory, one could be tempted to put as many buffers [2] as possible on the network nodes. Let us consider this case in the network above and assume that R1 has infinite buffers. Assume now that hosts A and B try to transmit a file that corresponds to one thousand packets each. Both are using a reliable protocol that relies on go-back-n to recover from transmission errors. The transmission starts and packets start to accumulate in R1‘s buffers. These presence of these packets in the buffers increases the delay between the transmission of a packet by A and the return of the corresponding acknowledgement. Given the increasing delay, host A (and B as well) will consider that some of the packets that it sent have been lost. These packets will be retransmitted and will enter the buffers of R1. The occupancy of the buffers of R1 will continue to increase and the delays as well. This will cause new retransmissions, ... In the end, several copies of the same packet will be transmitted over the R1-R2, but only one file will be delivered (very slowly) to the destination. This is known as the congestion collapse problem RFC 896. Congestion collapse is the nightmare for network operators. When it happens, the network carries packets without delivering useful data to the end users.
Note
Congestion collapse on the Internet
Congestion collapse is unfortunately not only an academic experience. Van Jacobson reports in [Jacobson1988] one of these events that affected him while he was working at the Lawrence Berkeley Laboratory (LBL). LBL was two network nodes away from the University of California in Berkeley. At that time, the link between the two sites had a bandwidth of 32 Kbps, but some
hosts were already attached to 10 Mbps LANs. “In October 1986, the data throughput from LBL to UC Berkeley ... dropped from 32 Kbps to 40 bps. We were fascinated by this sudden factor-of-thousand drop in bandwidth and embarked on an investigation of why things had gotten so bad.” This work lead to the development of various congestion control techniques
that have allowed the Internet to continue to grow without experiencing widespread congestion collapse events.
hosts were already attached to 10 Mbps LANs. “In October 1986, the data throughput from LBL to UC Berkeley ... dropped from 32 Kbps to 40 bps. We were fascinated by this sudden factor-of-thousand drop in bandwidth and embarked on an investigation of why things had gotten so bad.” This work lead to the development of various congestion control techniques
that have allowed the Internet to continue to grow without experiencing widespread congestion collapse events.
Besides bandwidth and memory, a third resource that needs to be shared inside a network is the (packet) processing capacity. To forward a packet, a network node needs bandwidth
on the outgoing link, but it also needs to analyze the packet header to perform a lookup inside its forwarding table. Performing these lookup operations require resources such as CPU cycles or memory accesses. Network nodes are usually designed to be able to sustain a given packet processing rate, measured in packets per second.
on the outgoing link, but it also needs to analyze the packet header to perform a lookup inside its forwarding table. Performing these lookup operations require resources such as CPU cycles or memory accesses. Network nodes are usually designed to be able to sustain a given packet processing rate, measured in packets per second.
Note
Packets per second versus bits per second
The performance of network nodes can be characterized by two key metrics :
the node’s capacity measured in bits per second the node’s lookup performance measured in packets per second
The node’s capacity in bits per second mainly depends on the physical interfaces that it uses and also on the capacity of the internal interconnection (bus, crossbar switch, ...) between the different interfaces inside the node. Many vendors, in particular for low-end devices will use the sum of the bandwidth of the nodes’ interfaces as the node capacity in bits per second. Measurements do not always match this maximum theoretical capacity. A well designed network node will usually have a capacity in bits per second larger than the sum of its link capacities. Such nodes will usually reach this maximum capacity when forwarding large packets.
When a network node forwards small packets, its performance is usually limited by the number of lookup operations that it can perform every second. This lookup performance is measured in packets per second. The performance may depend on the length of the forwarded packets. The key performance factor is the number of minimal size packets that are forwarded by the node every second. This rate can lead to a capacity in bits per second which is much lower than the sum of the bandwidth of the node’s links.
Let us now try to present a broad overview of the congestion problem in networks. We will assume that the network is composed of dedicated links having a fixed bandwidth
A network contains hosts that generate and receive packets and nodes that forward packets. Assuming that each host is connected via a single link to the network, the largest demand is. In practice, this largest demand is never reached and the network will be engineered to sustain a much lower traffic demand. The difference between the worst-case traffic demand and the sustainable traffic demand can be large, up to several orders of magnitude. Fortunately, the hosts are not completely dumb and they can adapt their traffic demand to the current state of the network and the available bandwidth. For this, the hosts need to sense the current level of congestion and adjust their own traffic demand based on the estimated congestion. Network nodes can react in different ways to network congestion and hosts can sense the level of congestion in different ways.
Hardware Architecture
Hardware architecture refers to the physical design of a computer system, including the arrangement of components such as the motherboard, processor, memory, storage devices, and input/output interfaces.
There are several different hardware architectures used in computer systems, including Von Neumann architecture, Harvard architecture, and RISC (Reduced Instruction Set Computing) architecture.
The Von Neumann architecture, which is also known as the Von Neumann model, is the most widely used hardware architecture in modern computers. It is based on the concept of a shared memory that stores both data and instructions, and a control unit that retrieves instructions from memory and executes them.
Harvard architecture, on the other hand, separates memory for data and instructions, which can improve the efficiency of the system.
RISC architecture is designed to simplify the processor, making it easier to manufacture and leading to faster performance.
The choice of hardware architecture depends on the specific requirements of the computer system, such as performance, power consumption, and cost.
The Von Neumann architecture is a basic design for modern computers, but there have been several variations and adaptations of the original concept. Here are a few types of Von Neumann architecture:
- Simple Von Neumann architecture: This is the original Von Neumannarchitecture, which consists of a control unit, an arithmetic logic unit (ALU), memory, and input/output (I/O) devices.
- Modified Von Neumann architecture: This is an evolution of the Simple Von Neumann architecture, which includes an instruction cache and adata cache to improve performance.
- Harvard architecture: This architecture is similar to the ModifiedVon Neumann architecture but separates the memory into two parts, one for data and one for instructions, improving performance and reliability.
- Princeton architecture: This is a hybrid of the Simple Von Neumann architecture and the Harvard architecture, where the memory can be used for both data and instructions, but the memory access is separated into two separate buses.
Overall, all these variations of the Von Neumann architecture share the same basic concept of a control unit that retrieves instructions from memory and executes them, and a shared memory that stores both data and instructions. However, the specific implementation of these components can vary, leading to different types of Von Neumann architecture.
Processor architecture refers to the design of the computer's central processing unit (CPU), including the instruction set, memory access, and other key features. Here are some common types of processor architecture:
- x86 Architecture: This is one of the most widely used processor architectures and is the basis for Intel's Pentium and AMD's Athlon processors.
- ARM Architecture: This is a reduced instruction set computing (RISC) architecture that is commonly used in mobile devices and other low-power devices.
- Power Architecture: This architecture is used by IBM in its PowerPC processors and is used in many high-performance systems, including servers and workstations.
- RISC Architecture: RISC stands for Reduced Instruction Set Computing, and it is designed to simplify the processor, making it easier to manufacture and leading to faster performance.
- CISC Architecture: CISC stands for Complex Instruction Set Computing, and it is designed to perform a wide range of functions using a large set of instructions.
- EPIC Architecture: EPIC stands for Explicitly Parallel Instruction Computing, and it is used in Intel's Itanium processor, which is designed for high-end servers and workstations.
The choice of processor architecture depends on the specific requirements of the computer system, such as performance, power consumption, cost, and compatibility with existing software.
RISC (Reduced Instruction Set Computing), CISC (Complex Instruction Set Computing), and ARM (Advanced RISC Machine) are three different processor architectures. Here's a comparison of the key differences between them:
- Instruction Set: RISC architectures use a smaller and simpler instruction set, while CISC architectures use a larger and more complex instruction set. ARM is a type of RISC architecture.
- Performance: RISC architectures are designed to perform a limited number of tasks quickly, while CISC architectures are designed to perform a wide range of tasks using a large set of instructions. In general, RISC architectures tend to be faster than CISC architectures.
- Power Consumption: RISC architectures consume less power than CISC architectures, making them ideal for use in mobile devices and other low-power devices.
- Hardware Complexity: RISC architectures are simpler and easier to manufacture than CISC architectures, leading to lower costs and improved reliability.
- Compatibility: CISC architectures are generally compatible with a wide range of software, including older software, while RISC architectures may not be compatible with older software.
Overall, the choice of processor architecture depends on the specific requirements of the computer system, such as performance, power consumption, cost, and compatibility with existing software. RISC architectures are well-suited for low-power devices, while CISC architectures are well-suited for compatibility with older software. ARM is a type of RISC architecture that is widely used in mobile devices and other low-power devices.
Example
Apple has used both RISC and CISC architectures in its computer systems over the years. The choice of architecture depends on the specific requirements of each system, including performance, power consumption, and compatibility with existing software.
In the early days of the Macintosh, Apple used the Motorola 68000, a CISC processor. Later, Apple switched to RISC processors, such as the PowerPC, for improved performance.
With the introduction of the iPhone and other mobile devices, Apple switched to ARM processors, which are RISC-based and designed for low power consumption. However, with the introduction of the Apple M1 processor in 2020, Apple has switched back to a CISC-based architecture, specifically a hybrid of RISC and CISC, known as Reduced Instruction Set Computing with Complex Instruction Set Computing (RISC-CISC).
The reason for this change is to improve performance and efficiency, while still maintaining compatibility with existing software. The M1 is designed to perform a wide range of tasks using a large set of instructions, making it well-suited for use in Apple's high-performance computing devices.
Overall, the choice of architecture depends on the specific requirements of each system, and Apple has used both RISC and CISC architectures over the years to meet the needs of its users.
Computer hardware refers to the physical components that make up a computer system, including the motherboard, CPU, RAM, storage devices, input/output devices, and peripheral devices.
The main components of a computer system are:
- Central Processing Unit (CPU)
- Memory (RAM)
- Motherboard
- Storage (Hard Drive/SSD)
- Graphics Processing Unit (GPU)
- Power Supply Unit (PSU)
- Input/Output Devices (Keyboard, Mouse, Monitor, etc.)
- Peripherals (Printer, Scanner, etc.)
John von Neumann was a Hungarian-American mathematician, computer scientist, and physicist who made significant contributions to many fields of science. One of his most important concepts is the Von Neumann architecture, which is a fundamental design for modern computers.
The Von Neumann architecture consists of the following components:
- Memory: stores both data and instructions
- Control Unit: retrieves instructions from memory and executes them
- Arithmetic Logic Unit (ALU): performs arithmetic and logical operations
- Input/Output (I/O) Devices: communicate with the computer's external environment.
This architecture, also known as the Von Neumann model, describes how a computer should be organized in order to efficiently perform a wide range of tasks. It is still used as the basis for the design of most modern computers.
Data Bus and Representation
A data bus is a group of electrical lines or wires in a computer system that is used to transfer data between different components. It is a key part of the computer's architecture, allowing the processor, memory, and other components to communicate with each other.
The data bus carries information such as instructions, operands, and data between different parts of the computer. The width of the data bus, also known as its "bit-width," determines the amount of data that can be transferred in each cycle. A wider data bus can transfer more data in each cycle, leading to improved performance.
The data bus is one of the main factors that determine the performance of a computer system. In general, a wider data bus and a faster bus speed will result in improved performance, but these factors are balanced against other design considerations, such as cost and power consumption.
Overall, the data bus is an essential component of a computer system that enables the transfer of data between different components, and its design is critical to the performance and efficiency of the system.
In computer architecture, there are three main buses that are used to transfer data and control information between different components:
- Data bus: A data bus is a group of electrical lines or wires that are used to transfer data between different components of a computer system, such as the processor, memory, and input/output devices. The width of the data bus, also known as its "bit-width," determines the amount of data that can be transferred in each cycle.
- Address bus: An address bus is a group of electrical lines or wires that are used to specify the location of data or an instruction that is to be transferred over the data bus. The address bus is used by the processor to request data or an instruction from memory, or to send data to an input/output device. The width of the address bus determines the maximum amount of memory that can be addressed by the system.
- Control bus: A control bus is a group of electrical lines or wires that are used to transfer control signals between different components of a computer system. The control bus is used by the processor to control the operation of the memory, input/output devices, and other components. Control signals can include read and write requests, interrupt signals, and status signals.
These three buses - the data bus, address bus, and control bus - are the main channels of communication in a computer system, and their design and performance are critical to the overall performance and efficiency of the system.
Example
A data bus in a computer system can be thought of as a highway that transfers data between different parts of the computer, such as the processor, memory, and input/output devices. Just as a highway has multiple lanes to allow multiple cars to travel at the same time, the data bus has multiple wires or lines that allow multiple bits of data to be transferred at the same time.
The width of the data bus, also known as its "bit-width," is like the number of lanes on a highway. A wider data bus with a higher bit-width is like a wider highway with more lanes, which allows for more data to be transferred in each cycle, just like more cars can travel on a wider highway.
However, just as building a wider highway can be more expensive and consume more resources, increasing the bit-width of a data bus can also increase the cost and power consumption of the computer system. This is why the choice of bit-width is a trade-off between performance and cost, just as the choice of highway width is a trade-off between capacity and cost.
Overall, the data bus can be thought of as a vital "highway" that transfers data between different parts of a computer system, and its design is critical to the performance and efficiency of the system.
Cache
Cache is a type of memory in a computer system that is used to temporarily store data that is likely to be used again in the near future. Cache is much faster than main memory (also known as RAM), so by keeping frequently used data in cache, the processor can access it more quickly and avoid the slower process of retrieving data from main memory.
Cache memory is organized into cache lines, each of which contains a small amount of data. When the processor needs to access data, it first checks the cache to see if the data is stored there. If the data is in cache, it is quickly retrieved from there. If the data is not in cache, it is retrieved from main memory and stored in cache for future use.
There are several different levels of cache memory, with the highest-level cache (known as L1 cache) being the fastest and closest to the processor, and the lowest-level cache (known as L3 cache or larger) being slower but larger in size.
The use of cache memory is an important part of computer architecture, as it helps to speed up the processing of data and improve overall system performance. However, cache memory is limited in size, so not all data can be stored in cache at the same time. As a result, the use of cache is carefully managed by the processor, with algorithms to decide which data to keep in cache and which data to replace.
Buffer Overflow
Buffer overflow is a type of security vulnerability that occurs when a program writes more data to a buffer (a temporary storage area in memory) than it can hold, causing data to overflow into adjacent memory locations. This can result in unexpected or malicious behavior, such as crashing the program, modifying data or executing malicious code.
Buffer overflows often occur when a program does not properly validate the input it receives from a user or another program. If an attacker is able to provide data that is larger than the buffer can hold, the extra data will overflow into other parts of memory, potentially overwriting critical data or even allowing the attacker to execute arbitrary code.
To prevent buffer overflows, programmers must be careful when designing and coding their programs, and must validate all inputs to ensure that they are of the expected size and format. Other techniques, such as stack canaries, address space layout randomization (ASLR), and data execution prevention (DEP), can also be used to mitigate the risks associated with buffer overflows.
Overall, buffer overflows are a serious security issue that can compromise the integrity and security of computer systems, and must be carefully managed to ensure the safety and stability of computer systems and the data they store.
Arbitrary code refers to computer instructions that are executed without the intention of the programmer or user. This can happen as a result of a security vulnerability, such as a buffer overflow or a code injection attack, where an attacker provides input that is designed to execute arbitrary code.
When arbitrary code is executed, it can carry out any number of malicious actions, such as modifying or deleting data, stealing sensitive information, installing malware, or launching a
denial-of-service (DoS) attack. This can result in serious security risks, such as data theft, system crashes, or loss of control over the affected computer.
denial-of-service (DoS) attack. This can result in serious security risks, such as data theft, system crashes, or loss of control over the affected computer.
To prevent arbitrary code execution, software must be designed and coded with security in mind, and must be tested and validated to ensure that it does not contain vulnerabilities that could be exploited by an attacker. In addition, users must be cautious about downloading and running untrusted software, and must keep their systems and software up to date with the latest security patches and updates.
Overall, arbitrary code execution is a serious security issue that can compromise the integrity and security of computer systems, and must be carefully managed to ensure the safety and stability of computer systems and the data they store.
Race Condition
Race condition is a term used in computer science to describe a situation where the outcome of a program depends on the timing or order of events that occur in the system. In a race condition, multiple threads or processes are accessing and updating the same data concurrently, and the final result depends on which of these updates occurs first.
For example, consider a program that transfers money from one bank account to another. If two threads try to transfer money from the same account at the same time, a race condition could occur, causing the final balance in the account to be incorrect.
Race conditions can result in unpredictable or unintended behavior, such as data corruption or incorrect results, and can be difficult to diagnose and fix. To prevent race conditions, programmers must be careful when designing and coding concurrent programs, and must use synchronization techniques, such as locks or semaphores, to ensure that data is accessed and updated in a controlled and predictable manner.
Overall, race conditions are a type of concurrency issue that can cause unpredictable or incorrect behavior, and must be carefully managed to ensure the reliability and correctness of concurrent programs.
Threat actors often exploit race conditions because they can provide a way to gain unauthorized access or take control of a system. By carefully timing their actions and exploiting the race condition, the attacker can cause the system to behave in unexpected or unintended ways, such as granting them access to sensitive data, modifying system settings, or executing malicious code.
For example, an attacker may exploit a race condition in a web application to bypass authentication and gain access to sensitive data. By carefully timing their requests and exploiting the race condition, the attacker can trick the system into thinking that they are authorized to access the data.
Another example is an attacker exploiting a race condition in an operating system to gain elevated privileges, such as root or administrator access. By exploiting the race condition, the attacker can modify the behavior of the system in such a way that they are able to execute arbitrary code with elevated privileges.
Race conditions are often difficult to detect and prevent, and can have serious consequences for the security and stability of a system. As a result, it is important for software developers and system administrators to be aware of race conditions and to implement measures to prevent or mitigate their effects.
Distributed Systems Architecture
Distributed Systems Architecture refers to the design of a computer system consisting of multiple autonomous components that are connected and work together to achieve a common goal. In a distributed system, each component runs on a different physical or virtual machine, and they communicate and exchange information with each other through a network.
The architecture of a distributed system defines the components, their relationships, and the protocols they use to communicate with each other. It also determines how data is stored, processed, and accessed in a decentralized manner, how consistency and reliability are maintained, and how security and privacy are ensured.
The design of a distributed system architecture must take into account various challenges such as scalability, fault tolerance, data consistency, and security. Common patterns used in distributed systems architecture include client-server, peer-to-peer, and microservices. The choice of architecture depends on the specific requirements of the system and the trade-off between scalability, performance, and reliability.
The Internet is a global network of interconnected computer networks that use the standard Internet protocol suite (TCP/IP) to link devices worldwide. It is a network of networks that consists of millions of private, public, academic, business, and government networks of local to global scope, linked by a broad array of electronic, wireless, and optical networking technologies. The Internet carries a vast range of information resources and services, such as the World Wide Web (WWW), electronic mail, telephony,
The Internet has a multitude of uses, some of the most common ones include:
- Communication: The Internet provides a variety of communication tools such as email, instant messaging, video conferencing, and social media, allowing people to communicate with each other from anywhere in the world.
- Information access: The Internet is a vast source of information and knowledge, with millions of websites and online databases that provide access to a wide range of topics.
- E-commerce: The Internet has revolutionized commerce by enabling the buying and selling of goods and services online.
- Education: The Internet provides access to a wealth of educational resources, including online courses, tutorials, and digital libraries.
- Entertainment: The Internet offers a variety of entertainment options, such as music and video streaming, gaming, and online communities.
- Work and productivity: The Internet provides many tools and
The history of the Internet in a military context dates back to the 1960s, when the US Department of Defense created a research project called the ARPANET. The aim of this project was to develop a communication network that would allow researchers to share information and collaborate on projects, even in the event of a nuclear attack.
The ARPANET was the precursor to the Internet and was the first operational packet switching network. Over time, other organizations, universities, and government agencies joined the ARPANET, and eventually, it became the Internet we know today.
The military continued to play a role in the development of the Internet, and many of the technologies that form the foundation of the Internet, such as packet switching and TCP/IP, were developed with military funding. In addition, the military has used the Internet for various purposes, including secure communications, intelligence gathering, and training.
However, the military's use of the Internet has also led to concerns about privacy, security, and the impact on civil liberties. The military has been involved in various controversies related to its use of the Internet, such as the use of data mining, cyber espionage, and the use of the Internet for propaganda and psychological operations.
Overall, the military has played a significant role in the history and development of the Internet and continues to be an important player in the online world.
The Internet is a vast network of interconnected computers and devices that communicate with each other using a variety of protocols. Protocols are sets of rules and standards that govern how data is transmitted, received, and processed over a network. Some of the most widely used Internet protocols include:
- Transmission Control Protocol/Internet Protocol (TCP/IP): This is the primary protocol used by the Internet to transmit data packets between computers. TCP provides reliable, ordered, and error-checked delivery of data packets, while IP provides the routing and addressing functions.
- Hypertext Transfer Protocol (HTTP): This protocol is used for transferring data over the World Wide Web, and is the foundation of the modern web. It defines how web browsers and servers exchange data, and is used for accessing websites, downloading files, and performing other web-based tasks.
- Simple Mail Transfer Protocol (SMTP): This protocol is used for sending and receiving email messages over the Internet. It defines how email clients and servers communicate with each other, and is responsible for ensuring that messages are properly delivered to their intended recipients.
- File Transfer Protocol (FTP): This protocol is used for transferring files between computers over the Internet. It allows users to upload and download files to and from remote servers, and is commonly used for website maintenance and file sharing.
- Domain Name System (DNS): This protocol is responsible for translating domain names (such as google.com) into IP addresses that computers can understand. It allows users to access websites using human-readable domain names, rather than having to remember a series of numbers.
These are just a few examples of the many protocols that make up the Internet. Each protocol serves a specific purpose and has its own set of rules and standards, but together they form the foundation of the modern digital world.
The World Wide Web (WWW or Web) is a system of interlinked, hypertext documents that are accessed through the Internet. It was created in 1989 by Sir Tim Berners-Lee, a British computer scientist, and has since become the largest and most widely used information system in the world.
The Web is based on the concept of hypertext, where text is linked to other related text and multimedia content, allowing users to easily navigate from one document to another by clicking on hyperlinks. This makes it possible to access a vast array of information and resources, such as websites, online databases, and multimedia content, from anywhere in the world.
The Web is accessed through a web browser, which interprets HTML (Hypertext Markup Language) and other Web technologies to display content on a user's device. It is an important tool for communication, commerce, education, and entertainment, and has revolutionized the way people access and share information.
The World Wide Web (WWW or Web) is a global system of interconnected documents and resources that are accessed via the Internet. It is a platform for sharing and accessing information, and has become an integral part of modern life. Some of the key technologies that make up the Web include:
- HyperText Markup Language (HTML): This is the primary language used to create and structure Web pages. HTML uses a system of tags and attributes to define the content, layout, and formatting of Web pages.Cascading Style Sheets (CSS): This technology is used to define the presentation and visual styling of Web pages, such as font sizes, colors, and layout. CSS is used in conjunction with HTML to create visually appealing and consistent Web pages.
- JavaScript: This is a programming language that is used to add interactivity and dynamic behavior to Web pages. JavaScript is commonly used to create animations, interactive forms, and other dynamic elements on Web pages.
- Hypertext Transfer Protocol (HTTP): This protocol is used to transfer data between Web servers and clients. It defines how Web browsers and servers exchange data, and is responsible for loading Web pages and other resources.
- Uniform Resource Locators (URLs): These are the addresses used to access Web pages and other resources on the Web. URLs consist of a protocol (such as HTTP), a domain name (such as google.com), and a path to the specific resource being accessed.
- Web browsers: These are the software applications used to access and display Web pages. Popular Web browsers include Google Chrome, Mozilla Firefox, and Microsoft Edge.
These technologies work together to create the Web as we know it today. They allow users to access and interact with an immense amount of information, and have transformed the way we communicate, work, and learn.
The Internet and World Wide Web (WWW) have become integral parts of modern life, with far-reaching implications for communication, commerce, education, and culture. Here are some of the reasons why these technologies are so important:
- Global communication: The Internet and WWW have made it possible for people to communicate with each other from anywhere in the world, in real-time, and at low cost. This has enabled individuals, businesses, and organizations to connect and collaborate across borders, time zones, and languages.
- Access to information: The Web has become a vast repository of information, offering users instant access to a wealth of knowledge on virtually any topic. This has transformed the way we learn, research, and explore the world around us.
- Online commerce: The Web has created new opportunities for businesses to reach customers and sell products and services. E-commerce has become a multi-billion dollar industry, with consumers able to shop from the comfort of their own homes and businesses able to sell to a global audience.
- Social networking: The Web has also given rise to social media platforms, allowing people to connect with each other and share information, ideas, and experiences in real-time. This has created new avenues for social interaction and community building.
- Democratization of knowledge: The Web has broken down barriers to accessing knowledge and information, making it possible for anyone with an Internet connection to learn new skills and pursue their passions. This has the potential to create a more informed, educated, and empowered global citizenry.
- Innovation and creativity: The Web has also become a platform for innovation and creativity, with individuals and organizations using it to develop new technologies, create new forms of art and media, and build new communities.
Overall, the Internet and WWW have transformed the way we live, work, and interact with each other. They have opened up new possibilities for communication, knowledge-sharing, and collaboration, and have the potential to create a more connected, informed, and prosperous global society.
High Performance Computing
What is High Performance Computing? High Performance Computing (HPC) refers to the use of computer clusters, supercomputers, and parallel processing techniques to solve
complex problems that require significant computing power and storage capabilities. HPC systems are designed to deliver high computational speeds and large data processing capabilities to solve problems that are beyond the reach of conventional computing systems.
complex problems that require significant computing power and storage capabilities. HPC systems are designed to deliver high computational speeds and large data processing capabilities to solve problems that are beyond the reach of conventional computing systems.
HPC is typically used in scientific research, engineering, finance, and other fields that require large amounts of data processing, such as climate modeling, molecular dynamics simulations, and genome sequencing. HPC systems can also be used to run large-scale simulations, perform data analysis, and develop complex models and simulations.
Some of the key characteristics of HPC systems include:
- High-speed processing: HPC systems are designed to perform a large number of calculations in a short amount of time, typically using parallel processing techniques.
- Large-scale data storage: HPC systems are capable of storing and processing large amounts of data, often in the petabyte range.
- High-speed interconnects: HPC systems typically use high-speed networking technologies, such as InfiniBand, to connect multiple processors and nodes.
- Distributed computing: HPC systems often use distributed computing architectures, where different parts of a computation are run on separate processors or nodes, in parallel.
- Specialized software: HPC systems often require specialized software to manage the parallel processing of data and to optimize the use of hardware resources.
Overall, HPC plays a critical role in enabling scientific and technical advancements by providing the necessary computational power to tackle complex problems that would otherwise be infeasible or prohibitively expensive to solve.
High Performance Computing (HPC) has a wide range of applications across various industries and fields. Some of the common uses of HPC include:
- Scientific research: HPC is extensively used in scientific research for simulations, modeling, and data analysis. It enables researchers to process large amounts of data and perform complex calculations quickly, allowing them to make faster and more accurate discoveries.
- Weather forecasting: HPC plays a vital role in weather forecasting by running complex models that simulate atmospheric conditions. This enables meteorologists to predict weather patterns more accurately and provide more reliable forecasts.
- Aerospace and defense: HPC is used extensively in aerospace and defense industries for simulation and testing of various components such as aircraft wings, engines, and missiles. It also helps in designing and optimizing complex systems and improving the efficiency and performance of military operations.
- Energy and environmental research: HPC is used in the energy sector for simulating and optimizing energy production and distribution systems. It is also used in environmental research for modeling and predicting the effects of climate change and identifying solutions to
environmental challenges. - Financial modeling: HPC is used in the financial industry for modeling and simulating complex financial instruments and transactions. It helps in assessing risk and making investment decisions.
- Artificial Intelligence and Machine Learning: HPC accelerates the training and inference of large-scale machine learning models, enabling the development of more advanced AI applications such as image and speech recognition, natural language processing, and autonomous driving.
These are just a few examples of the many uses of HPC in various fields. HPC is a critical tool for accelerating scientific discovery, innovation, and solving complex real-world problems.
Side Note:
Floating point operations per second (FLOPS) is a measure of the computational performance of a computer, specifically its ability to perform floating-point arithmetic operations. Floating-point arithmetic is a method of performing mathematical operations with real numbers, which are represented in binary format with a certain precision.
FLOPS is typically used to measure the performance of high-performance computing (HPC) systems, including supercomputers and clusters, as well as individual processors and graphics processing units (GPUs). The FLOPS rating is often used to compare the performance of different computing systems. The FLOPS rating is expressed as the number of floating-point
operations that a computer or processor can perform in one second. For example, a computer with a rating of 1 teraflop (1 TFLOPS) can perform one trillion floating-point operations per second. Similarly, a computer with a rating of 100 petaflops (100 PFLOPS) can perform 100 quadrillion floating-point operations per second.
operations that a computer or processor can perform in one second. For example, a computer with a rating of 1 teraflop (1 TFLOPS) can perform one trillion floating-point operations per second. Similarly, a computer with a rating of 100 petaflops (100 PFLOPS) can perform 100 quadrillion floating-point operations per second.
FLOPS is an important metric for applications that require a large amount of numerical computation, such as simulations, scientific computing, and artificial intelligence. The higher the FLOPS rating of a computing system, the faster it can perform these calculations, which can lead to faster insights and discoveries.
Review Notes - Terms and Definition
Review Notes - Terms and Definition
High Performance Computing (HPC) refers to the use of computer clusters, supercomputers, and parallel processing techniques to solve complex problems that require significant computing power and storage capabilities.
Key Characteristics of HPC systems:
- High-speed processing
- Large-scale data storage
- High-speed interconnects
- Distributed computing
- Specialized software
HPC is used in various industries and fields:
- Scientific research
- Weather forecasting
- Aerospace and defense
- Energy and environmental research
- Financial modeling
- Artificial Intelligence and Machine Learning
FLOPS is a measure of the computational performance of a computer, specifically its ability to perform floating-point arithmetic operations. FLOPS is typically used to measure the performance of high-performance computing (HPC) systems.
Overall, HPC plays a critical role in enabling scientific and technical advancements by providing the necessary computational power to tackle complex problems that would otherwise be infeasible or prohibitively expensive to solve.
Network Architecture
In the context of computer networks, network architecture refers to the design of a network and the way its components are organized and interconnected to enable
communication and data exchange.
communication and data exchange.
A common concept in network architecture is the layered model, which divides the network into distinct layers, each responsible for a specific function. The most widely used layered model is the OSI (Open Systems Interconnection) model, which has seven layers:
- Physical layer: Deals with the transmission of raw bits over a communication channel.
- Data Link layer: Manages the flow of data between two directly connected nodes.
- Network layer: Provides routing and switching of packets across multiple networks.
- Transport layer: Ensures reliable and efficient data transmission between end hosts.
- Session layer: Manages the establishment and termination of communication sessions between applications.
- Presentation layer: Handles the formatting, compression, and encryption of data.
- Application layer: Provides network services to end-user applications, such as email, file transfer, and web browsing.
Another concept in network architecture is the use of network devices such as routers, switches, hubs, and firewalls, which are used to control the flow of data and ensure security. Network protocols such as TCP/IP, DNS, and DHCP are also important components of network architecture, as they define the rules and standards for communication between devices on a network
Forwarding, routing, and switching/bridging are three important concepts in computer networking. They refer to the processes involved in the movement of data packets between devices on a network.
- Forwarding: Forwarding refers to the process of sending a packet from one network device to another device on the same network. When a device receives a packet, it checks the packet's destination address and forwards it to the appropriate next-hop device to continue its journey towards its final destination. Forwarding happens at the data link layer (layer 2) of the OSI model.
- Routing: Routing refers to the process of selecting the best path for a packet to take through a network from its source to its destination. This involves examining the packet's destination address, comparing it to a routing table, and determining the next-hop device along the path. Routing happens at the network layer (layer 3) of the OSI model.
- Switching/Bridging: Switching (also known as bridging) refers to the process of forwarding data between devices on the same network. When a switch receives a packet, it examines the packet's destination MAC address and forwards it to the appropriate device on the same network. Switching happens at the data link layer (layer 2) of the OSI model.
Switching and forwarding are similar processes, but switching specifically refers to the forwarding of data between devices on the same network, while forwarding can refer to the forwarding of data between devices on different networks. Routing, on the other hand, involves the selection of the best path for a packet to take through a network.
Vulnerabilities
There are several potential vulnerabilities associated with setting up a switch to forward packets between devices on the same network:
- Security vulnerabilities: Switches can be vulnerable to attacks such as MAC address spoofing, VLAN hopping, and denial-of-service attacks. It's important to implement proper security measures such as port security, access control lists (ACLs), and VLAN tagging to protect against these types of attacks.
- Configuration errors: Improperly configured switches can cause network problems such as network loops, broadcast storms, and spanning tree protocol (STP) issues. These types of issues can disrupt network performance and cause downtime.
- Firmware vulnerabilities: Switches may have vulnerabilities in their firmware that can be exploited by attackers to gain unauthorized access to the network or compromise network security. It's important to keep switch firmware up-to-date with the latest security patches and updates.
- Physical security: Switches can be vulnerable to physical attacks such as theft or tampering. It's important to implement physical security measures such as locking cabinets or racks to protect against these types of threats.
- Human error: Human error, such as misconfigured ports or incorrect VLAN tagging, can cause network issues and potentially expose vulnerabilities. Proper training and documentation can help minimize the risk of human error.
To mitigate these vulnerabilities, it's important to implement proper security measures, keep switch firmware up-to-date, and ensure proper configuration and management of switches. Regular network security assessments and vulnerability scans can also help identify and address potential vulnerabilities.
Ways to mitigate the vulnerabilities associated with setting up a switch to forward packets between devices on the same network:
- Implement proper security measures: To protect against security vulnerabilities, implement measures such as port security, access control lists (ACLs), VLAN tagging, and user authentication. These can help prevent unauthorized access and mitigate attacks such as MAC address spoofing and VLAN hopping.
- Regularly update switch firmware: To prevent firmware vulnerabilities, it's important to regularly update switch firmware with the latest security patches and updates.
- Follow best practices for switch configuration: To minimize configuration errors, follow best practices such as configuring port speed and duplex mode correctly, and using proper VLAN tagging. Additionally, regularly test and monitor the network to detect any issues or misconfigurations.
- Implement physical security measures: To protect against physical attacks, implement physical security measures such as locking cabinets or racks, and monitoring access to network equipment.
- Provide proper training and documentation: To minimize human error, provide proper training and documentation for network administrators and users, and enforce policies for network configuration and management.
- Conduct regular network security assessments: Regular network security assessments and vulnerability scans can help identify and address potential vulnerabilities before they can be exploited.
By implementing these measures, you can mitigate the vulnerabilities associated with setting up a switch to forward packets between devices on the same network and improve the overall security and performance of your network.
Review Notes - Terms and Definition
Review Notes - Terms and Definition
- Peer-to-peer architecture is commonly used in small businesses and homes.
- Client-server architecture allows for centralized control of network resources.
- Hybrid architecture uses a combination of both client-server and peer-to-peer architecture.
- The primary advantage of a client-server architecture is that it allows for centralized control of network resources.
- The primary disadvantage of a client-server architecture is that it is more expensive than other architectures.
- The primary advantage of a peer-to-peer architecture is that it is easier to set up and maintain.
- The primary disadvantage of a peer-to-peer architecture is that it is less secure than other architectures.
- The purpose of a network protocol is to define the rules and standards for communication between devices on a network.
- SMB is the network protocol used for file sharing in a Windows environment.
- SMTP, POP3, and IMAP are network protocols used for email communication.
- RDP, SSH, and Telnet are network protocols used for remote access to a network.
- The purpose of a firewall is to prevent unauthorized access to a network.
- Packet-filtering firewall examines individual packets of data as they are transmitted across a network.
- Application-level gateway firewall is used to filter traffic based on the application or service generating the traffic.
- A circuit-level gateway firewall operates at the session layer of
the OSI model, establishing and managing connections between network
devices. - Switches are used to connect devices on a local network and transmit data packets between them.
- Routers are used to connect multiple networks together and forward data packets between them.
- Network topology refers to the physical or logical arrangement of devices on a network.
- The star topology is a network topology where all devices on the network are connected to a central hub.
- The mesh topology is a network topology where each device on the network is connected to every other device on the network.
Review Notes: Potential Vulnerabilities Associated with Switch Setup
Introduction:
- Switches are critical components in network infrastructure.
- However, they can also be vulnerable to several types of attacks, configuration errors, firmware vulnerabilities, physical attacks, and human error.
Security vulnerabilities:
- Switches can be vulnerable to attacks such as MAC address spoofing, VLAN hopping, and denial-of-service attacks.
- To protect against security vulnerabilities, implement measures such as port security, access control lists (ACLs), VLAN tagging, and user authentication.
Configuration errors:
- Improperly configured switches can cause network problems such as network loops, broadcast storms, and spanning tree protocol (STP) issues.
- To minimize configuration errors, follow best practices such as configuring port speed and duplex mode correctly, and using proper VLAN tagging.
Firmware vulnerabilities:
- Switches may have vulnerabilities in their firmware that can be exploited by attackers to gain unauthorized access to the network or compromise network security.
- To prevent firmware vulnerabilities, it's important to regularly update switch firmware with the latest security patches and updates.
Physical security:
- Switches can be vulnerable to physical attacks such as theft or tampering.
- To protect against physical attacks, implement physical security measures such as locking cabinets or racks, and monitoring access to network equipment.
Human error:
- Human error, such as misconfigured ports or incorrect VLAN tagging, can cause network issues and potentially expose vulnerabilities.
- To minimize human error, provide proper training and documentation for network administrators and users, and enforce policies for network configuration and management.
Conclusion:
- By implementing proper security measures, regularly updating switch firmware, following best practices for switch configuration, implementing physical security measures, providing proper training and documentation, and conducting regular network security assessments, the vulnerabilities associated with setting up a switch to forward packets between devices on the same network can be mitigated.
- These measures can improve the overall security and performance of the network.
Network Defense
Network defense refers to the practices, tools, and techniques used to protect computer networks from unauthorized access, misuse, or malicious activities. It involves various security measures implemented at different levels of a network to safeguard the confidentiality, integrity, and availability of data and resources.
Examples of network defense measures in Windows and Linux environments include:
- Firewalls: Firewalls are software or hardware-based network security devices that monitor and filter incoming and outgoing network traffic based on predefined rules. They can be configured to allow or block specific types of traffic based on IP addresses, ports, protocols, and other criteria. For example, Windows Firewall and iptables in Linux are popular firewall tools used for network defense.
- Intrusion Detection/Prevention Systems (IDS/IPS): IDS/IPS are security mechanisms that detect and prevent unauthorized access or attacks on a network. They analyze network traffic in real-time to identify patterns of known attacks or abnormal behaviors. For example, Windows Defender Advanced Threat Protection (ATP) and Snort are commonly used IDS/IPS solutions in Windows and Linux environments, respectively.
- Virtual Private Networks (VPNs): VPNs are used to create secure communication channels over the internet to protect data transmitted between remote locations or users. They encrypt data to prevent eavesdropping and ensure confidentiality. Windows has built-in support for VPNs, such as Windows Server Remote Access and DirectAccess, while Linux has OpenVPN
and IPsec-based solutions. - Patching and Updating: Regularly applying patches and updates to operating systems, software, and network devices is critical for network defense. These patches address known vulnerabilities and help prevent exploitation by attackers. For example, Windows Update and Package Managers in Linux (e.g., apt, yum) are used for patch management.
- User Authentication and Access Control: Proper user authentication and access control mechanisms are essential for network defense. Examples include strong password policies, multi-factor authentication (MFA), and role-based access control (RBAC). Windows Active Directory (AD) and Linux Pluggable Authentication Modules (PAM) are widely used for user
authentication and access control in their respective environments. - Network Segmentation: Network segmentation is the practice of dividing a network into smaller subnetworks to restrict the lateral movement of attackers in case of a security breach. This helps contain the impact of an attack and prevents unauthorized access to critical resources. Windows Domain Isolation and Linux VLANs (Virtual LANs) are examples of
network segmentation techniques. - Encryption: Encryption is the process of encoding data to prevent unauthorized access. It can be used to protect data transmitted over the network (e.g., SSL/TLS for securing web traffic) or stored on network devices (e.g., full disk encryption). Examples of encryption tools in Windows and Linux include BitLocker and dm-crypt, respectively.
These are just a few examples of network defense measures in Windows and Linux environments. Implementing a multi-layered defense strategy, including a combination of these measures, is crucial for protecting computer networks from various cyber threats.
Implementing a multi-layered defense strategy is a best practice in cybersecurity, as it involves using multiple security measures at different layers of a network to provide overlapping protection and increase the overall security posture. Here are some key components of a multi-layered defense strategy:
- Perimeter Defense: This layer focuses on protecting the outermost boundaries of the network. It may include firewalls, intrusion detection/prevention systems (IDS/IPS), and virtual private networks (VPNs) to filter and monitor incoming and outgoing network traffic, block known threats, and secure remote access.
- Network Segmentation: This layer involves dividing the network into smaller subnets or VLANs to restrict the lateral movement of attackers. It can be achieved through proper network architecture and configuration, and helps contain the impact of a security breach by isolating critical resources from other parts of the network.
- Access Control: This layer focuses on proper authentication and authorization mechanisms to ensure that only authorized users have access to network resources. It may involve strong password policies, multi-factor authentication (MFA), role-based access control (RBAC), and regular review of user permissions to minimize the risk of unauthorized access.
- Patch Management: Regularly applying patches and updates to operating systems, software, and network devices is crucial to address known vulnerabilities and prevent exploitation by attackers. This layer involves establishing a robust patch management process to ensure timely updates are applied to all network assets.
- Endpoint Security: This layer involves securing endpoints, such as workstations, servers, and mobile devices, as they are often the entry points for attacks. It may include ntivirus/antimalware software, host-based firewalls, and endpoint detection and response (EDR) solutions to detect and prevent malicious activities on endpoints.
- Monitoring and Logging: This layer involves monitoring network traffic, system logs, and other security events to detect and respond to potential security incidents. It may include security information and event management (SIEM) systems, log analyzers, and security analytics tools to identify abnormal behaviors and indicators of compromise (IOCs).
- User Awareness and Training: This layer focuses on educating users about cybersecurity best practices and raising awareness about potential threats, such as phishing, social engineering, and malware. Regular training and awareness programs can help users make informed decisions and avoid falling victim to cyber attacks.
- Backup and Disaster Recovery: This layer involves implementing regular data backups and establishing a robust disaster recovery plan to ensure business continuity in case of a security breach or other unexpected events. It may include offsite backups, redundant systems, and tested recovery procedures.
By implementing multiple layers of defense, organizations can create a defense-in-depth approach that provides overlapping protection and minimizes the risk of successful cyber attacks. It's important to regularly review and update the defense strategy to adapt to evolving threats and technologies.
The attack surfacehttps://www.fortinet.com/blog/industry-trends/smart-buildings-new-attack-surface is the number of all possible points, or attack vectors, where an unauthorized user can access a system and extract data. The smaller the attack surface, the easier it is to protect.
Organizations must constantly monitor their attack surface https://www.fortinet.com/blog/industry-trends/securing-the-widening-attack-surface-of-healthcare-today to identify and block potential threats as quickly as possible. They also must try and minimize the attack surface area to reduce the risk of cyberattacks succeeding. However, doing so becomes difficult as they
expand their digital footprint and embrace new technologies.
expand their digital footprint and embrace new technologies.
The attack surface is split into two categories: the digital and physical.
Digital Attack Surface
The digital attack surface https://www.fortinet.com/solutions/enterprise-midsize-business/network-security area encompasses all the hardware and software that connect to an organization’s network. These include applications, code, ports, servers, and websites, as well as shadow IT, which sees users bypass IT to use unauthorized applications or devices.
Physical Attack Surface
The physical attack surface https://www.fortinet.com/blog/industry-trends/post-mirai-managing-the-attack-surface-of-a-smart-city comprises all endpoint devices that an attacker can gain physical access to, such as desktop computers, hard drives, laptops, mobile phones, and Universal Serial Bus (USB) drives. The physical attack threat surface includes carelessly discarded hardware that contains user data and login credentials, users writing passwords on paper, and physical break-ins.
Organizations can protect the physical attack surface https://www.fortinet.com/resources/cyberglossary/what-is-mssp through access control and surveillance around their physical locations. They also must implement and test disaster recovery procedures and policies.
How Are Attack Vectors and Attack Surfaces Related?
The attack surface and attack vector are different but related. An attack vector is the method a cyber criminal uses to gain unauthorized access or breach a user's accounts or an organization's systems. The attack surface is the space that the cyber criminal attacks or breaches.
Common Attack Vectors
Common attack vector types include:
- Phishing: This attack vector involves cyber criminals sending a communication from what appears to be a trusted sender to convince the victim into giving up valuable information. Phishing messages typically contain a malicious link or attachment that leads to the attacker stealing users’ passwords or data.
- Malware: Malware refers to malicious software, such as ransomware, Trojans, and viruses. It enables hackers to take control of a device, gain unauthorized access to networks and resources, or cause damage to data and systems. The risk of malware is multiplied as the attack surface https://www.fortinet.com/resources/cyberglossary/malwareexpands.
- Compromised passwords: One of the most common attack vectors is compromised passwords, which comes as a result of people using weak or reused passwords on their online accounts. Passwords can also be compromised if users become the victim of a phishing attack.
- Encryption issues: Encryption is designed to hide the meaning of a message and prevent unauthorized entities from viewing it by converting it into code. However, deploying poor or weak encryption can result in sensitive data being sent in plaintext, which enables anyone that intercepts it to read the original message.
- Unpatched software: Cyber criminals actively search for potential vulnerabilities in operating systems, servers, and software that have yet to be discovered or patched by organizations. This gives them an open door into organizations’ networks and resources.
Common Attack Surface Vulnerabilities
Common vulnerabilities https://www.fortinet.com/blog/ciso-collective/addressing-the-impact-of-the-global-cybersecurity-skills-gap include any weak point in a network that can result in a data breach. This includes devices, such as computers, mobile phones, and hard drives, as well as users themselves leaking data to hackers.
Other vulnerabilities include the use of weak passwords, a lack of email security, open ports, and a failure to patch software, which offers an open backdoor for attackers to target and exploit users and organizations. Another common attack surface https://www.fortinet.com/products/endpoint-security/fortiedris weak web-based protocols, which can be exploited by hackers to steal data through man-in-the-middle (MITM) attacks.
How To Define Your Attack Surface Area
Visualization begins with defining and mapping the attack surface. This involves identifying potential weaknesses, assessing vulnerabilities, and determining user roles and privilege levels. Organizations can assess potential vulnerabilities by identifying the physical and virtual devices that comprise their attack surfacehttps://www.fortinet.com/resources/cyberglossary/what-is-XDR, which can include corporate firewalls and switches, network file servers, computers and laptops, mobile devices, and printers.
They then must categorize all the possible storage locations of their corporate data and divide them into cloud, devices, and on-premises systems. Organizations can then assess which users have access to data and resources and the level of access they possess. This helps them understand the particular behaviors of users and departments and classify attack vectors into categories like function and risk to make the list more manageable.
What Is Attack Surface Management and Why Is It Important?
When an attack surface https://www.fortinet.com/resources/cyberglossary/what-is-cloud-securityhas been mapped, it is important to test for vulnerabilities and continuously monitor its performance. Attack surface management is crucial to identifying current and future risks, as well as reaping the following benefits:
- Identify high-risk areas that need to be tested for vulnerabilities
- Identify changes and any new attack vectors that have been created in the process
- Determine which types of users can access each part of a system
- Mitigate against targeted cyberattacks
Attack Surface Reduction in 5 Steps
Infrastructures are growing in complexity and cyber criminals are deploying more sophisticated methods to target user and organizational weaknesses. These five steps will help organizations limit those opportunities.
1. Implement Zero-trust Policies
The zero-trust security model ensures only the right people have the right level of access to the right resources at the right time. This strengthens organizations' entire infrastructure and reduces the number of entry points by guaranteeing only authorized individuals can access networks.
2. Eliminate Complexity
Unnecessary complexity can result in poor management and policy mistakes that enable cyber criminals to gain unauthorized access to corporate data. Organizations must disable unnecessary or unused software and devices and reduce the number of endpoints being used to simplify their network.
For example, complex systems can lead to users having access to resources they do not use, which widens the attack surface available to a hacker.
3. Scan for Vulnerabilities
Regular network scans and analysis enable organizations to quickly spot potential issues. It is therefore vital to have full attack surface visibility to prevent issues with cloud and on-premises networks, as well as ensure only approved devices can access them. A complete scan must not only identify vulnerabilities but also show how endpoints can be exploited.
4. Segment Network
Network segmentation allows organizations to minimize the size of their attack surface by adding barriers that block attackers. These include tools like firewalls and strategies like microsegmentation, which divides the network into smaller units.
5. Train Employees
Employees are the first line of defense against cyberattacks. Providing them with regular cybersecurity awareness training will help them understand best practices, spot the telltale signs of an attack through phishing emails and social engineering.