Monday, May 29, 2006

Internet: The Network of Networks

The Internet, also called the Net, is an international network that connects many thousands of networks and millions of computers across the world. Used by many people and organizations to communicate and share information, the Internet links computers of different sizes and types.
To be able to communicate with each other and exchange information, these different types of computers need to comply with a set of standard communication rules called protocol. All computers connected to the Internet use IP, Internet Protocol, which controls the break up of data messages into units called packets, and governs the routing of data from sender to receiver.
IP is one of a suite of protocols known as Transmission Control Protocol/Internet Protocol, or TCP/IP, which was developed by the US Department of Defense to enable communications over different types of networks.

To connect to the Internet, you need Internet access. For home computer users, this is usually accomplished by dialing up an Internet Service Provider (ISP) via a modem. Another way to gain Internet access is through a dedicated line (such as a T1 carrier), connected to a local area network (LAN). A dedicated line is usually used by a large organization or company, which either has its own node on the Internet or is connected to an ISP.

The backbone of the Internet consists of high-speed data communication lines linking major nodes or host computers. These lines carry the bulk of the data traffic. Major Internet service providers (ISPs) own the largest networks, which comprise the backbone of the Internet. By connecting together, these networks form an extremely fast data pipeline that crisscrosses the world.

No one can cause the Internet to crash, as no single computer or node controls it. One or more Internet nodes could fail without jeopardizing the Internet as a whole or preventing communications. However, different parts of the world are not equally well defended against Internet service failure. In more developed countries, the backbone of the Internet usually has redundant intersecting points. If one part fails, data traffic is quickly rerouted to another. This feature is called Redundancy. The more redundancy the backbone has, the more reliable the Internet service is.
The earliest model of the Internet was created with extreme reliability in mind. The start of the Internet was a decentralised network called ARPANET (Advanced Research Projects Agency Network) created in 1969 by the US Department of Defense to provide a communications network capable of surviving a nuclear attack. Eventually, other networks, such as Usenet, BITNET, and NSFnet (created by US National Science Foundation) were connected to ARPANET.
To deliver Internet services, many technologies such as fiber optics, cable television wires and satellites have been used. Virtual libraries and museums, games, E-business, and online monetary transactions are some of the many applications being developed and driven by the Internet.
The original services
The services that were used in the Internet immediately after its inception were primarily intended to make use of the greater possibilities made available by a network as opposed to stand-alone computers: resource-sharing and the exchange of messages. Three original application protocols developed were e-mail, file transfer and remote logon.
1. Electronic mail
Electronic mail, or e-mail, is one of the original applications of the Internet. It is based on the simple mail transfer protocol (SMTP) and the post office protocol (POP) and is used for the transmission of short text messages between two users. E-mail is certainly one of today's major Internet teleservices.
2. File transfer
The purpose of the file transfer application is to provide a number of users with the possibility of sharing common storage resources from which files can be retrieved when required - with or without some form of authorisation control (for example, user name and password). Transfer is normally performed using the file transfer protocol (FTP).
Retrieving files from different file archives is a popular service. Some file archives function as anonymous FTP servers, meaning that no special authorisation is required to gain access to the material stored there.
3. Remote logon
Remote logon enables users to connect to other computers and use their resources. This service originated at a time when computers and processing power were in short supply but in great demand. The protocol for the service is called TELNET.
Other Services on the Internet include the following:
1. Discussion groups
The Internet has not only made worldwide data communication possible but has also made it simple and inexpensive. The most common communication service is e-mail, but the Internet can also be used as a meeting place where users can "congregate" and discuss issues of common interest.
2. News groups
Internet news groups are forums for debate and exchange of information on different subjects. There is a wide variety of subjects ranging from cooking to programming; however, technology-oriented subjects (in particular those related to computer science) dominate. The news-group service can be described as e-mail addressed to an impersonal party - a subject field.
Discussion groups are not based on real-time communication. Instead, users submit their articles or questions after which a response may be entered by other members of the group. The various questions and answers are saved in a catalogued structure so that they can be read at a time convenient for the reader. The advantage of this arrangement is that users have access to topics discussed earlier, although it is somewhat difficult to maintain a concise overview of the structure.
The network news transfer protocol (NNTP) is used for the transfer of information to and from discussion-group members.
3. Chat
Chat is a sort of discussion forum in which members converse - via a text-based interface - over a network of interconnected servers. Numerous users can communicate with one another at the same time. A channel is created when the first user connects and ceases to exist when the last user terminates communication. A message that is written by one user and then sent over the channel is immediately distributed to all other users connected to that channel. Unlike news, chat is based on real-time communication.
The protocol that connects the servers with one another, and the individual clients with their respective servers, is called the Internet relay chat (IRC) protocol.
4. Information retrieval
Information retrieval over the Internet has almost become synonymous with the World Wide Web (WWW). The Web represented an enormous breakthrough for the Internet and is probably the application that has been most instrumental in the rapid spread of the Internet around the world. Ironically, the Web is also responsible for a good portion of the criticism that has been aimed at the Internet. There is an enormous amount of information making it more or less impossible to maintain a simplified overview, and dramatic increases in Internet traffic have also led to lengthy response times.
Information retrieval is greatly facilitated by the use of search engines (such as Alta Vista or Yahoo!), which help locate the desired type of information by browsing through millions of pages in hundreds of thousands of servers. A search engine can search on titles, uniform resource locators (URLs), key words and phrases.
5. Commerce
Commerce over the Internet represents one of the most interesting application areas for future Internet services. One idea is for the Internet to be used as a sort of gigantic, continuously updated mail-order catalogue containing products and services. The physical delivery of ordered software and information will be performed directly over the Internet. The international features of the Internet will make it suitable as a tool for commerce across national borders, with the ensuing problems relating to customs and value-added tax collection.
6. Telephony
Telephony over the Internet is a more recent service. An important advantage of this service is the low price. Users only pay for the connection set-up to their Internet service supplier - usually the price of a local call - and can then call other users anywhere in the world. The disadvantage is that the Internet, as a packet-switched network, is not designed for the transfer of services that are sensitive to delays and delay variations, in particular. Delays can become significantly large (in the range of seconds) and can also vary with time. Moreover, no common standard exists. This means that parties wishing to carry on telephone conversations over the Internet must install the special telephony software from the same service provider.
7. Multimedia services
a. Multimedia
Multimedia is a term often used in connection with the Internet. It can be described as a service that employs at least two of the three service types voice, data and video and also entails a certain degree of interactivity. The term "voice" can be expanded to include audio in general. Data traffic is currently the primary traffic type transmitted over the Internet, but the transmission of sound and video is increasing. A reasonable prediction is that the Internet will be carrying large volumes of multimedia traffic in the near future.
b. Videoconferencing
High-quality videoconferencing requires at least six times the bandwidth of ordinary telephony. It works best if run over an intranet since these networks offer approximately 10 times greater bandwidth than the Internet.
c. Video transmission
Multicast backbone (Mbone) and streaming video are used when transmitting video over the Internet. Mbone is a logical, broadband network that is superimposed on the ordinary Internet network. It consists of a number of servers that support multicast, that is, one sender and several receivers. Although some Internet routers do not "understand" IP multicast, they can be used for Mbone traffic if the traffic is encapsulated in normal TCP packets by means of special Mbone computers.
The streaming video technique employs a high degree of video information compression and display of information at the receivers' concurrent with the transfer of subsequent information. The flow is smoothed by a buffer in the receiving equipment.
8. Business services
Companies have a number of alternatives when employing the Internet or Internet technologies in their internal networks.
a. Intranets
An intranet is a company network based on the use of Internet technology. The prime advantage of an intranet is a possibility provided by WWW techniques: having a common interface for different information formats. Information can be disseminated quickly and in a uniform manner. Employees can use the same software that they use when retrieving information directly from Internet sources. An intranet can be used to retrieve information from databases, to distribute company news or for special Web pages that serve as bulletin boards. An intranet is ordinarily protected by a firewall to prevent intrusion (unauthorised access). An extranet is a solution whereby a company offers certain external individuals (customers and subcontractors) limited access to the information available on the company's intranet.
b. Virtual private networks
A company can interconnect local data networks to form a virtual private network (VPN) by using the Internet. The service is offered by Internet operators in the form of a "public intranet", a term which in itself is a contradiction. Internet operators can provide better quality of service (QoS) via a public intranet than in the public Internet.
Internet Development Organisations
Many organizations and institutions contribute their computing resources to maintain and update various parts of the Net. The Internet is indisputably a collaborative, joint entity. No one person, governmental or non-governmental organization can claim ownership or control of the Internet.
On the other hand, IT industry leaders exert their influence through setting standards that the various hardware and software systems should comply with. Also, many governments have begun to legislate the Internet.
Among the organizations that play significant roles in the development of the Internet are:
• ISOC (Internet Society): ISOC is a professional membership society made up of many entities of the Internet Economy (individuals, government agencies, corporations, foundations, and non-profit organizations). The group comments on Internet policies and practices. Overseeing IAB and IESG, ISOC promotes the use, development and maintenance of the Internet. It is a free-standing organisation with headquarters in Reston, Virginia, in the US.
The objectives of the ISOC are:
• to maintain and develop Internet standards;
• to develop effective administrative processes for the operation of the Internet;
• to expand and develop Internet architecture; and
• to promote the development of and accessibility to the Internet.
ISOC membership has grown steadily since the organisation was formed in 1992. Today, members include government agencies, other non-profit organisations, private corporations and private individuals. (www.isoc.org)
• IETF (Internet Engineering Task Force): IETF is a large open international community of network designers, which focuses on the development of the Internet, and proposes solutions to technical problems related to the Internet. The IETF's most important function is to assign priorities to the various protocols that are to be developed and integrated into the Internet protocol suite. The IETF started as a forum for the coordination of technical matters that concerned the various suppliers to the ARPA 1986 project. The association has since then grown into an open, international organisation of network designers, network operators, manufacturers and researchers all involved in the development of the Internet. (www.ietf.org)
The IETF's objectives are:
• to identify and suggest solutions to technical operational problems arising in the Internet;
• to specify the development and use of protocols and architecture;
• to be a forum for the exchange of information between manufacturers, users, researchers and network operators.
All technical work is carried out in working groups, each being responsible for a particular area - for example, applications, network management and security. Each of the areas has an area director. The IETF nominates future members of the IESG and the IAB.
• IESG (Internet Engineering Steering Group): IESG is a group that manages IETF activities, and reviews standards proposed by IEFT. IESG is responsible for the technical control of the Internet Engineering Task Force's (IETF's) work and administers the Internet standardisation process in accordance with a set of established rules. IESG consists of the IETF's area directors and the IETF's chairman, who is also chairman of the IESG. (http://www.ietf.org/iesg.html)
• W3C (World Wide Web Consortium): W3C is a body encouraging the development of open Web standards such as HTML (Hypertext Markup Language). The World Wide Web Consortium (W3C) promotes the use of the World Wide Web by developing specifications and products. Different member companies finance W3C operations. However, the products that are developed are free of charge and can be used freely by anyone. (www.w3.org)
• IAB (Internet Architecture Board): IAB is a technical advisory group that provides guidance to the IETF, and defines the overall architecture of the Internet and its backbone. Formerly the Internet Activities Board, the Internet Architecture Board (IAB) consists of 13 members, each of whom has one vote. IAB members are not appointed on the basis of any specialist competence but rather because of their broad overall knowledge of the Internet. Issues addressed by the IAB often deal with future strategies and international cooperation. The objective is results that can be used as guidelines by the IESG. The IAB, which is a technical reference group affiliated with the ISOC, publishes Internet Official Standards on a quarterly basis. (www.iab.org)
• IANA (Internet Assigned Numbers Agency): Protocol specifications contain parameters (such as port numbers and error codes) that must be uniquely defined. The IAB is responsible for this undertaking but delegates the task to the Internet Assigned Numbers Agency (IANA), which publishes the defined parameters in a periodic RFC under the title Assigned Numbers. (www.iana.org)

• IRSG (Internet Research Steering Group): The Internet Research Steering Group (IRSG) functions as the decision-making group for the Internet Research Task Force (IRTF). It has the same relationship to IREF as that existing between the IESG and the IETF. (www.irsg.org)

• IRTF (Internet Research Task Force): The IRTF, which does not directly participate in the standardisation process, investigates subjects that are considered too uncertain, advanced or insufficiently scrutinised to be included in the standardisation process. The IRTF's efforts may then lead to specifications of sufficient maturity to become a standard. (www.irtf.org)
• ICANN (The Internet Corporation for Assigned Names and Numbers): ICANN is a non-profit corporation responsible for administering IP addresses and domain names. (www.icann.org)
• InterNIC (Internet Network Information Center): InterNIC is an organization responsible for assigning domain names. (www.internic.net)

Internet Firewalls for Trusted Systems

Many organizations have connected to or want to connect their private LAN’s to the Internet so that their users can have convenient access to Internet services. Since the Internet as a whole is not trustworthy, their private systems are vulnerable to misuse and attack. A firewall is a safeguard one can use to control access between a trusted network and a less trusted one.

A firewall is a set of related programs, located at a network gateway server that protects the resources of a private network from users from other networks. Basically, a firewall, working closely with a router program, filters all network packets to determine whether to forward them toward their destination. A firewall is often installed away from the rest of the network so that no incoming request can get directly at private network resources.

As with any safeguard, firewalls also need to have a trade-offs between convenience and security. In order to be convenient firewalls are typically configured to be transparent to internal network users on the other hand, they are configured to be non-transparent for outside network users coming through the firewall. This generally provides the highest level of security without placing an undue burden on internal users. Firewalls provide several types of protection, some of which are as under:
• They can block unwanted traffic.
• They can direct incoming traffic to more trustworthy internal systems.
• They hide vulnerable systems, which can’t easily be secured from the Internet.
• They can log traffic to and from the private network.
• They can hide information like system names, network topology, network device types, and internal user ID’s from the Internet.
• They can provide more robust authentication than standard applications might be able to do.

Role of Firewalls
The firewall imposes restrictions on packets entering or leaving the private network. All traffic from inside to outside, and vice versa, must pass through the firewall, but only authorised traffic will be allowed to pass. Packets are not allowed through unless they conform to a filtering specification, or unless there is negotiation involving some sort of authentication. The firewall itself must be immune to penetration.

Firewalls create checkpoints (or choke points) between internal private network and the Internet. Once the choke points have been clearly established, firewall can monitor, filter and verify all inbound and outbound traffic.

Firewall may filter on the basis of IP source and destination addresses and TCP port number. Firewalls may block packets from the Internet that claim a source address of a system on the intranet, or they may require the use of an access negotiation and encapsulation protocol like SOCKS to gain access to the intranet. SOCKS is a security protocol used to communicate through a firewall or proxy server.

The firewall also enforces logging, and provides alarm capacities as well. By placing logging services at firewalls, security administrators can monitor all access to and from the Internet. Good logging strategies are one of the most effective tools for proper network security.

Firewalls may block TELNET or RLOGIN connections from the Internet to the intranet. They also block SMTP and FTP connections to the Internet from internal systems not authorised to send e-mail or to move files. The firewall provides protection from various kinds of IP spoofing and routing attacks.

The firewall certainly has some negative aspects as well for example it cannot protect against internal threats such as an employee who cooperates with an external attacker; it is also unable to protect against the transfer of virus-infected programs or files because it is impossible for it to scan all incoming files, e-mail and messages for viruses. However, since a firewall acts as a protocol endpoint, it may use an implementation methodology designed to minimize the likelihood of bugs.

Firewall-Related Terminology
To understand the concept of firewall, some familiarity with the basic terminology is required. It is useful to understand the following important terms commonly applicable to firewall technologies.

1. Bastion Host
A bastion host is a publicly accessible device for the network’s security, which has a direct connection to a public network such as the Internet. The bastion host serves as a platform for any one of the four types of firewalls: packet filter, circuit-level gateway, application-level gateway and hybrid or complex gateways. Bastion hosts must check all incoming and outgoing traffic and enforce the rules specified in the security policy. They must be prepared for attacks from external and possibly internal sources. They should be built with the least amount of hardware and software in order for a potential hacker to have less opportunity to overcome the firewall.

Bastion hosts are armed with logging and alarm features to prevent attacks. The bastion host’s role falls into the following three common types:
• Single-homed bastion host: This is a device with only one network interface, normally used for an application-level gateway. The external router is configured to send all incoming data to the bastion host, and all internal clients are configured to send all outgoing data to the host. Accordingly, the host will test the data according to security guidelines.
• Dual-homed bastion host: This is a firewall device with at least two network interfaces. Dual-homed bastion hosts serve as application-level gateways, as packet filters and circuit-level gateways as well. The advantage of using such hosts is that they create a complete break between the external network and the internal network. This break forces all incoming and outgoing traffic to pass through the host. The dual-homed bastion host will prevent a security break-in when a hacker tries to access internal devices.
• Multi-homed bastion host: Single-purpose or internal bastion hosts can be classified as either single-homed or multi-homed bastion hosts. The latter are used to allow the user to enforce strict security mechanisms. When the security policy requires all inbound and outbound traffic to be sent through a proxy server, a new proxy server should be created for the new streaming application. On the new proxy server, it is necessary to implement strict security mechanisms such as authentication. When multi-homed bastion hosts are used as internal bastion hosts, they must reside inside the organisation’s internal network, normally as application gateways that receive all incoming traffic from external bastion hosts. They provide an additional level of security in case the external firewall devices are compromised. All the internal network devices are configured to communicate only with the internal bastion host.
• A tri-homed firewall: It connects three network segments with different network addresses. This firewall may offer some security advantages over firewalls with two interfaces. An attacker on the unprotected Internet may compromise hosts on the DMZ (De-militarised Zone) but still not reach any hosts on the protected internal network.

2. Proxy Server
Proxy servers are used to communicate with external servers on behalf of internal clients. A proxy service is set up and torn down in response to a client request, rather than existing on a static basis. The term proxy server typically refers to an application-level gateway, although a circuit-level gateway is also a form of proxy server. The gateway can be configured to support an application-level proxy on inbound connections and a circuit-level proxy on outbound connections. Application proxies forward packets only when a connection has been established using some known protocol. When the connection closes, a firewall using application proxies rejects individual packets, even if they contain port numbers allowed by a rule set.

In contrast, circuit proxies always forward packets containing a given port number if that port number is permitted by the rule set. Thus, the key difference between application and circuit proxies is that the latter are static and will always set up a connection if the rule set allows it. Each proxy is configured to allow access only to specific host systems.

The audit log is an essential tool for detecting and terminating intruder attacks. Therefore, each proxy maintains detailed audit information by logging all traffic, each connection and the duration of each connection.

Since a proxy module is a relatively small software package specifically designed for network security, it is easier to check such modules for security laws. Each proxy is independent of other proxies on the bastion host. If there is a problem with the operation of any proxy, or if future vulnerability is discovered, it is easy to replace the proxy without affecting the operation of the proxy’s applications. If the support of a new service is required, the network administrator can easily install the required proxy on the bastion host. A proxy generally performs no disk access other than to read its initial configuration file. This makes it difficult for an intruder to install Trojan horse, sniffers or other dangerous files on the bastion host.

3. SOCKS
The SOCKS protocol version 4 provides for unsecured firewall traversal for TCP-based client/server applications, including HTTP (Hypertext Transfer Protocol), TELNET (Telnet is a protocol for remote computing on the Internet. It allows a computer to act as a remote terminal on another machine, anywhere on the Internet) and FTP (File Transfer Protocol). The new protocol extends the SOCKS version 4 model to include UDP (User Datagram Protocol), and allows the framework to include provision for generalised strong authentication schemes, and extends the addressing scheme to encompass domain name and IPv6 addresses. The implementation of the SOCKS protocol typically involves the recompilation or relinking of TCP-based client applications so that they can use the appropriate encapsulation routines in the SOCKS library.

When a TCP-based client wishes to establish a connection to an object that is reachable only via a firewall, it must open a TCP connection to the appropriate SOCKS port on the SOCKS server system. The SOCKS service is conventionally located at TCP port 1080. If the connection request succeeds, the client enters negotiation for the authentication method to be used, authenticates with the chosen method, and then sends a relay request. The SOCKS server evaluates the request, and either establishes the appropriate connection or denies it. In fact, SOCKS defines how to establish authenticated connections, but currently it does not provide a clear-cut solution to the problem of encrypting the data traffic. Since the Internet at large is considered a hostile medium, encryption by using ESP (Encapsulated Security Payload, the IPSEC protocol, which provides encryption. It can also provide authentication service.) is also assumed in this scenario.

4. Choke Point
The most important aspect of firewall placement is to create choke points. A choke point is the point at which a public internet can access the internal network. The most comprehensive and extensive monitoring tools should be configured on the choke points. Proper implementation requires that all traffic be funnelled through these choke points. Since all traffic is flowing through the firewalls, security administrators, as a firewall strategy, need to create choke points to limit external access to their networks. Once these choke points have been clearly established, the firewall devices can monitor, filter and verify all inbound and outbound traffic.

Since a choke point is installed at the firewall, a prospective hacker will go through the choke point. If the most comprehensive logging devices are installed in the firewall itself, all hacker activities can be captured. Hence, this will detect exactly what a hacker is doing.

5. De-militarised Zone (DMZ)
The DMZ is an expression that originates from the Korean War. It meant a strip of land forcibly kept clear of enemy soldiers. In terms of a firewall, the DMZ is a network that lies between an internal private network and the external public network. DMZ networks are sometimes called perimeter networks. A DMZ is used as an additional buffer to further separate the public network from the internal network.

6. VPN
Some firewalls are now providing VPN services. VPNs are appropriate for any organisation requiring secure external access to internal resources. All VPNs are tunneling protocols in the sense that their information packets or payloads are encapsulated or tunneled into the network packets. All data transmitted over a VPN is usually encrypted
because an opponent with access to the Internet could eavesdrop on the data as it travels over the public network.

The VPN encapsulates all the encrypted data within an IP packet. Authentication, message integrity and encryption are very important fundamentals for implementing a VPN. Without such authentication procedures, a hacker could impersonate anyone and then gain access to the network. Message integrity is required because the packets can be altered as they travel through the Internet. Without encryption, the information may become truly public.

Several methods exist to implement a VPN. Windows NT or later versions support a standard RSA (A public key cryptographic algorithm named after its inventors namely Rivest, Shamir, and Adelman. It is used for encryption and digital signatures. RSA was developed in 1977 and is today the most commonly used encryption and authentication algorithm.) connection through a VPN. Specialised firewalls or routers can be configured to establish a VPN over the Internet. New protocols such as IPsec are expected to standardise on a specific VPN solution. Several VPN protocols exist, but the Point-to-Point Tunnelling Protocol (PPTP) and IPsec are the most popular.
Types of Firewalls
Firewall constitutes a network configuration, usually both hardware and software, that forms a fortress between networked computers within an organization and those outside the organization. It is commonly used to protect information such as a network's e-mail and data files within a physical building or organization site. Firewalls act as an intermediate server in handling SMTP and HTTP connections in either direction. Firewalls also require the use of an access negotiation and encapsulation protocol such as SOCKS to gain access to the Internet, the intranet, or both. Many firewalls support tri-homing, allowing use of a DMZ network. It is possible for a firewall to accommodate more than three interfaces, each attached to a different network segment. Firewalls can be classified into four main categories: packet filters, circuit-level gateways, application-level gateways and hybrid or complex gateways.

1. Packet Filtering Firewalls
Packet filtering firewalls use routers with packet filtering rules to grant or deny access based on source address, destination address and port. They offer minimum security but at a very low cost, and can be an appropriate choice for a low risk environment. They are fast, flexible, and transparent. Filtering rules are not often easily maintained on a router, but there are tools available to simplify the tasks of creating and maintaining the rules.
The type of router used in a packet-filtering firewall is known as a screening router. The screening router is configured to filter packets from entering or leaving the internal network. The routers can easily compare each IP address to a filter or a series of filters.

Packet filters typically set up a list of rules that are sequentially read line by line. Filtering rules can be applied based on source and destination IP addresses or network addresses. A packet filter will provide two actions, forward and discard. If the action is in the forward process, the action takes place to route the packet as normal if all conditions within the rule are met. The discard action will block all packets if the conditions in the rule are not met. Thus, a packet filter is a device that inspects each packet for predefined content. Although it does not provide an error-correcting ability, it is almost always the first line of defence.

Since a packet filter can restrict all inbound traffic to a specific host, this restriction may prevent a hacker from being able to contact any other host within the internal network. However, the significant weakness with packet filters is that they cannot discriminate between good and bad packets. Even if a packet passes all the rules and is routed to the destination, packet filters cannot tell whether the routed packet contains good or malicious data. Another weakness of packet filters is their susceptibility to spoofing. In IP spoofing, an attacker sends packets with an incorrect source address. When this happen, replies will be sent to the apparent source address, not to the attacker. This might seem to be a problem.

Filtering gateways do have inherent risks including:
• The source and destination addresses and ports contained in the IP packet header are the only information that is available to the router in making decision whether or not to permit traffic access to an internal network.
• They don’t protect against IP or DNS address spoofing.
• An attacker will have a direct access to any host on the internal network once access has been granted by the firewall.
• Strong user authentication isn’t supported with some packet filtering gateways.
• They provide little or no useful logging.

2. Circuit-Level Gateways
The circuit-level gateway represents a proxy server that statically defines what traffic will be forwarded. Circuit proxies always forward packets containing a given port number if that port number is permitted by the rule set. A circuit-level gateway operates at the network level of the OSI model. This gateway acts as an IP address translator between the Internet and the internal system. The main advantage of a proxy server is its ability to provide Network Address Translation (NAT). NAT hides the internal IP address from the Internet. NAT is the primary advantage of circuit-level gateways and provides security administrators with great flexibility when developing an address scheme internally.

Circuit-level gateways are based on the same principles as packet filter firewalls. When the internal system sends out a series of packets, these packets appear at the circuit-level gateway where they are checked against the predetermined rules set. If the packets do not violate any rules, the gateway sends out the same packets on behalf of the internal system. The packets that appear on the Internet originate from the IP address of the gateway’s external port, which is also the address that receives any replies. This process efficiently shields all internal information from the Internet.

3. Application Gateways
An application gateway uses server programs (called proxies) that run on the firewall. These proxies take external requests, examine them, and forward legitimate requests to the internal host that provides the appropriate service. Application gateways can support functions such as user authentication and logging.
The application-level gateway represents a proxy server, performing at the TCP/IP application level, that is set up and torn down in response to a client request, rather than existing on a static basis. Application proxies forward packets only when a connection has been established using some known protocol. When the connection closes, a firewall using application proxies rejects individual packets, even if the packets contain port numbers allowed by a rule set.

The application gateway analyses the entire message instead of individual packets when sending or receiving data. When an inside host initiates a TCP/IP connection, the application gateway receives the request and checks it against a set of rules or filters. The application gateway (or proxy server) will then initiate a TCP/IP connection with the remote server. The server will generate TCP/IP responses based on the request from the proxy server. The responses will be sent to the proxy server (application gateway) where the responses are again checked against the proxy server’s filters. If the remote server’s response is permitted, the proxy server will then forward the response to the inside host.

Application gateways (proxy servers) are used as intermediate devices when routing SMTP traffic to and from the internal network and the Internet. The main advantage of a proxy server is its ability to provide NAT for shielding the internal network from the Internet.

Since an application gateway is considered as the most secure type of firewall, this configuration provides a number of advantages to the medium-high risk site:
• The firewall can be configured as the only host address that is visible to the outside network, requiring all connections to and from the internal network to go through the firewall.
• The use of proxies for different services prevents direct access to services on the internal network, protecting the enterprise against insecure or misconfigured internal hosts.
• Strong user authentication can be enforced with application gateways.
• Proxies can provide detailed logging at the application level.
4. Hybrid or Complex Gateways
Hybrid gateways combine the above types of firewalls and implement them in series rather than in parallel. If they are connected in series, then the overall security is enhanced; on the other hand, if they are connected in parallel, then the network security perimeter will be only as secure as the least secure of all methods used. In medium to high-risk environments, a hybrid gateway may be the ideal firewall implementation.
Limitations of Firewalls
Firewalls have some limitations as well. Some of them are discussed as under:
1. Firewalls offer excellent protection against network threats, but they aren't a complete security solution. Certain threats are outside the control of the firewall. Other ways to protect against these threats can be figured out by incorporating physical security, host security, and user education into the overall security plan.
2. A firewall might keep a system user from being able to send proprietary information out of an organization over a network connection. But that same user could copy the data onto disk, tape, or paper and carry it out.
3. If the attacker is already inside the firewall, a firewall can do virtually nothing. Inside users can steal data, damage hardware and software, and subtly modify programs without ever coming near the firewall. Insider threats require internal security measures, such as host security and user education.
4. A firewall can effectively control the traffic that passes through it. However, there is nothing a firewall can do about traffic that doesn't pass through it. Sometimes, technically expert users or system administrators set up their own "back doors" into the network (such as a dial-up modem connection), either temporarily or permanently, because they chafe at the restrictions that the firewall places upon them and their systems.
5. A firewall is designed to protect against known threats. A well-designed one may also protect against new threats. However, no firewall can automatically defend against every new threat that arises. Periodically people discover new ways to attack, using previously trustworthy services, or using attacks that simply hadn't occurred to anyone before. A firewall can't protect against viruses
6. Detecting a virus in a random packet of data passing through a firewall is very difficult; it requires:
• Recognizing that the packet is part of a program
• Determining what the program should look like
• Determining that the change is because of a virus
Conclusion
No doubt, firewalls have become an important part of a security mechanism today still it is equally essential to have a reliable, up-to-date anti-virus program on computers.

Radio Frequency Identification

Introduction
Radio Frequency Identification (RFID) can be defined as a method of identifying unique items using radio waves. RFID is based on analog-to-digital conversion technology to transfer data between a moveable item and a reader to identify, track or locate that item. The reader sends a request in the form of electromagnetic waves for identification information to the tag. A passive RFID tag draws power from field created by the reader and uses it to power the microchip's circuits. The chip then modulates the waves that the tag sends back to the reader and the reader converts the new waves into digital data.

In some systems, the link between the reader and the computer is wireless. RFID has several advantages over bar codes such as it can hold more data, has the ability to change the stored data as processing occurs, it does not require line-of-sight to transfer data and is very effective in harsh environments where bar code labels won't work.

Some companies are combining RFID tags with sensors that detect and record temperature, movement, even radiation. Some day, the same tags used to track items moving through the supply chain may also alert staff if goods are not stored at the right temperature, if they have gone bad, or even if someone has injected a biological agent into them.

History of RFID
The roots of radio frequency identification technology can be traced back to World War II. The Germans, Japanese, Americans and British were all using radar, which had been discovered in 1935 by Scottish physicist Sir Robert Alexander Watson-Watt — to warn of approaching planes while they were still miles away. The problem was, there was no way to identify which planes belonged to the enemy and which were a country’s own pilots returning from a mission. The Germans discovered that if pilots rolled their planes as they returned to base, it would change the radio signal reflected back. This crude method alerted the radar crew on the ground that these were German planes and not allied aircrafts.

Under Watson-Watt, who headed a secret project, the British developed the first active identify friend or foe (IFF) system. They put a transmitter on each British plane. When it received signals from radar stations on the ground, it began broadcasting a signal back that identified the aircraft as friendly. RFID works on this same basic concept. A signal is sent to a transponder, which wakes up and either reflects back a signal (passive system) or broadcasts a signal (active system).

RFID Tag
RFID tag is a microchip attached to an antenna that is packaged in a way that it can be applied to an object. The tag picks up signals from and sends signals to a reader. The tag contains a unique serial number, but may have other information, such as a customers' account number. A typical RFID tag can carry no more than 2KB of data, which is enough to store some basic information about the item it is on. Companies are now looking at using a simple "license plate" tag that contains only a 96-bit serial number. The simple tags are cheaper to manufacture and are more useful for applications where the tag will be disposed of with the product packaging.

Microchips in RFID tags can be read-write, read-only, or write once read many (WORM). With read-write chips, one can add information to the tag or write over existing information when the tag is within range of a reader. Read-write tags usually have a serial number that can't be written over.

Additional blocks of data can be used to store additional information about the items the tag is attached to (these can usually be locked to prevent overwriting of data). Read-only microchips have information stored on them during the manufacturing process. The information on such chips can never been changed. WORM tags can have a serial number written to it once and then that information can't be overwritten later.

RFID tags can also be classified as active, passive and semi-passive. Active RFID tags have a transmitter and their own power source (typically a battery). The power source is used to run the microchip's circuitry and to broadcast a signal to a reader (the way a cell phone transmits signals to a base station). Passive tags have no battery. Instead, they draw power from the reader, which sends out electromagnetic waves that induce a current in the tag's antenna. Semi-passive tags use a battery to run the chip's circuitry, but communicate by drawing power from the reader. Active and semi-passive tags are useful for tracking high-value goods that need to be scanned over long ranges, such as railway cars on a track, but they cost more than passive tags, which means they can't be used on low-cost items.

Advancements in the RFID technology have enabled companies to produce chipless RFID tags. A Chipless RFID uses RF energy to communicate data but they don't store a serial number in a silicon microchip in the transponder. Some chipless tags use plastic or conductive polymers instead of silicon-based microchips. Other chipless tags use materials that reflect back a portion of the radio waves beamed at them. A computer takes a snapshot of the waves beamed back and uses it like a fingerprint to identify the object with the tag. Companies are experimenting with embedding RF reflecting fibers in paper to prevent unauthorized photocopying of certain documents. However, chipless tags that use embedded fibers have one drawback for supply chain uses i.e. only one tag can be read at a time.

Every RFID chip has a read range i.e. distance from which a tag can be read. Read range depends on a number of factors, including the frequency of the radio waves being used for tag-reader communication, the size of the tag antenna, the power output of the reader, and whether the tags have a battery to broadcast a signal or gather energy from a reader and merely reflect a weak signal back to the reader. Battery-powered tags typically have a read range of 300 feet (100 meters). These are the kinds of tags used in toll collection systems. High-frequency tags, which are often used in smart cards, have a read range of three feet or less. UHF tags-the kind used on pallets and cases of goods in the supply chain-have a read range of 20 to 30 feet under ideal conditions. If the tags are attached to products with water or metal, the read range can be significantly less. If the size of the UHF antenna is reduced, that will also dramatically reduce the read range. Increasing the power output could increase the range, but most governments restrict the output of readers so that they don't interfere with other RF devices, such as cordless phones.

RFID Readers
RFID Reader is a device used to communicate with RFID tags. The reader has one or more antennas, which emit radio waves and receive signals, back from the tag. The reader is also sometimes called an interrogator because it "interrogates" the tag.

There are many different RFID reader makers. They may make smart readers or dumb readers. Some focus only on UHF. Others sell low, high and ultra-high frequency systems. RFID readers can be classified as intelligent and dumb readers. An intelligent reader has the ability not just to run different protocols, but also to filter data and even run applications. Essentially, it is a computer that communicates with the tags. A dumb reader, by contrast, is a simple device that might read only one type of tag using one frequency and one protocol. And it typically has very little computing power, so it can't filter reads, store tag data and so on.

Applications of RFID Technology

  • RFID technology offers several consumer benefits. Its application in supply chain enables reduction in costs and improving the overall efficiencies. Companies can pass some of these savings on to consumers to try to gain market share from less efficient competitors.
  • It can be used by retailers to expedite returns and by manufacturers to manage warrantee claims and improve after-sales support of items such as computers and DVD players.
  • It can reduce the counterfeiting of pharmaceutical drugs and insure the integrity of products purchased by consumers.
  • It can also be used to secure the food supply and prevent terrorists from sneaking weapons of mass destruction into a country through shipping containers.
  • Hitachi, the Japanese high-technology company, has developed a very tiny RFID chip, called the mu-chip, designed to help governments prevent the counterfeiting of passports, securities and other documents. There have been reports that the European Union and Japan are considering embedding these chips in large bills.
  • Ford Motors at its North American plants has rolled out a battery-charging system for its electric vehicles that uses RFID to transmit data about these vehicles and their batteries.
  • Nearly 45 colleges in Pune have decided to put a stop to vanishing books and low attendance records, turning to RFID identity cards for help. The colleges have introduced the cards to allow students access to hostels and monitor their classroom attendance. Students only need to swipe his or her card at a reader to record their attendance. At Pune University's Jayakar library, for instance, members don't return books to a librarian or register the books they borrow at a counter behind which the librarian sits. He or she simply places a smart card on one of the three "readers" or devices in the library and the books are automatically registered in his or her account.
  • Airbus' A380 double-decker aircraft, which is the world's largest and seats 555 passengers, will have passive RFID chips on removable parts such as life vests to help ease maintenance processes. The jet is equipped with 10,000 radio-frequency identification chips
  • Wal-Mart has recently reported that it was "live" with three distribution centers, 104 Wal-Mart stores, and 36 Sam's Clubs reading radio frequency tags on pallets shipped by 57 suppliers. Wal-Mart's top 100 suppliers, plus a few dozen others that volunteered to be part of the initial RFID implement will soon be going live. So far, the biggest impact of RFID has been felt in the area of process review. Wal-Mart associates previously used manually generated pick lists telling them what products needed to be brought from the stockroom out to the sales floor. Now, backroom pick lists are generated automatically for RFID tagged items. RFID is providing visibility of what's really in the back room and what needs to be reordered.

Conclusion
RFID tags are poised to become the most far-reaching wireless technology since the cellphone, according to a market analysis from In-Stat, with worldwide revenues from RFID tags are forecast to jump from US$300 million in 2004 to US$2.8 billion in 2009. During this period, the technology will appear in many industries with significant impact on the efficiency of business processes.

Electronic-Governance: Empowering Masses

Introduction
The advent of Information Technology as a high leverage-enabling tool for delivery of services in the public and the private sector has by now been universally recognised. This has redefined the fundamentals and has the potential to change the institutions as well as the mechanisms of delivery of services forever. Quite obviously, therefore, the objective of achieving Electronic Governance (EG) goes far beyond mere computerisation of stand alone back office operations. It means to fundamentally change how the Government operates and this implies a new set of responsibilities especially for the State Governments and local bodies.

Government departments, which have maximum interaction with the public, must be identified for the use of IT. Listed below are a few such departments that can be considered:

Public Grievances: Electricity, Water, Telephone, Ration Card, Sanitation, Public Transport etc.

Rural Services: Land Records, Below Poverty Line (BPL) Families etc.

Police: FIR Registration, Lost and Found etc.

Social Services: Pension, Registration of Licences and Certificates, Ration Cards, Birth Certificates, Death Certificate, Domicile Certificate, Caste/Tribe Certificate, Registration of Documents, School Registration, University Registration, Motor Vehicle Registration, Driving License etc.

Public Information: Employment Exchange Registration, Employment Opportunities, Examination Results, Hospitals / Beds Availability / Services, Railway Time Tables, Airline Time Tables, Road Transport Time Tables, Charitable Trusts, Government Notifications, Government Forms, Government Schemes etc.

Agriculture Sector: Seeds Information, Pesticides, Fertilizers, Crop disease, Weather Forecast - short range / District wise, Market Price etc.

Utility Payments / Billing : Electricity, Water, Telephone etc.

Commercial: Taxation & Return Filing, Income Tax, Corporate Tax, Custom Duty, Central / State Excise Duty, Sales Tax, House Tax, Property Tax, Octroi, Road Tax, Company Returns etc.

Government: Electronic Procurement, Education University Model for E-Governance etc.

Benefits in Developing Countries
The benefits of e-governance for developing countries are considerable. E-governance can be leveraged to provide services effectively to the poor masses of developing countries, which lack basic health, sanitation and education facilities. E-governance can also be leveraged to improve the delivery of not only these basic services, but also other services that might have been deemed inaccessible to poor, isolated villagers.

E-Governance in India
For centuries most of the India’s population living in villages was just unreachable and uninformed of various developments taking place in other parts of the country. Villagers were locked in a battle against three seemingly invincible foes: drought, poverty, and crooked landlords. The new information and communication technology developments in different states of India have changed the way government offices used to work and also the life style of the villagers and other citizens.

Some of the e-governance projects in the country are discussed as under:

  1. Akshaya: It is an E-Governance project initiated by the Kerala State Department of Information Technology with an objective to make Kerala a 100% e-literate state. Under this project e-centres with internet connectivity are being setup throughout the state to provide e-literacy to one member from every household and eventually act as ICT Dissemination nodes and IT Enabled Service Delivery points in every village.
  2. AP online- One-stop-shop on the Internet: It is an E-Governance project initiated by the Govt. of Andhra Pradesh with an objective to provide a single window online service for its citizens through a portal designed to be a one-stop-shop on the Internet. The portal seeks to provide information in respect of all services to the citizens and businesses in Andhra Pradesh. The portal was launched on 27th March 2002. Information about services offered by TWINS, FAST & CARD (ICT projects that have been initiated by AP) along with other basic information regarding all departments of the Government of Andhra Pradesh is available on this portal.
  3. Arunachal Pradesh Community Information Centre: It is an E-Governance project initiated by the Central Government and State Governments of Arunachal Pradesh, Sikkim, Assam, Nagaland, Manipur, Mizoram, Meghalaya and Tripura in August 2000. Its objective is to link the blocks in the North Eastern states through Very Small Aperture Terminals (VSATs), and provide Community Information Centres (CICs), which will act as an interface between the citizens and institutions of Government. CICs have been set up in all the 487 blocks of Northeast and Sikkim in just about 2 years. Each Centre is well- equipped with infrastructure including one server machine, five client systems, one each of a VSAT, Laser Printer, Dot Matrix Printer, modem, LAN hub, TV, Webcam and two UPS. Each CIC has two CIC Operators (CICOs) for managing the centres and providing services to the public. Basic services to be provided by CICs include Internet access and e-mail, printing, data entry and word processing and training for the local populace. Many of the CICs, already operational, charge nominal amounts from users for services which helps them to meet day-to-day running expenses such as consumables, stationery, fuel for the Genset etc. It is proposed to use the Community Information Centres for E-entertainment in the future.
  4. Bhoomi: : It is an E-Governance project initiated by the Govt. of Karnataka to ensure more secure title and decrease rural graft, by providing access to printouts of land holdings at specified Govt. offices in districts to citizen-consumers. The project was initiated in 1998. At this point, 167 of the total of 177 Talukas have already been computerized. The information has been transferred from existing manual registers and inputted into a database. The database generated in this project is going to be used for a number of other developmental applications including better agricultural and financial planning for farmers in collaboration with the Centre for Knowledge Societies, Bangalore.
  5. Computerized Panchayat in Belandur (Karnataka): It is an E-Governance project initiated by the Bellandur Gram Panchayat and Village Development Committee with an objective to limit corruption and get development resources through computerization of the Panchayat. Software packages have been developed to suit the needs of panchayat administration, handling the recording of property details, tax collection, data management and so on. The current system has aided in limiting corruption, and generated a 100-fold increase in revenue for the Panchayat. Enhanced tax collections have already been put into good use in development initiatives.
  6. Dairy Information System Kiosk (DISK): It is an E-Governance project initiated by the National Dairy Development Board with an objective to provide data analysis and decision support to help rural milk collection societies in improving their productivity and the yield of cattle. The project was conceived with two components, an application running at the rural milk collection society that could be provided Internet connectivity and a portal at the district level serving transactional and information needs of all members. The DISK application has helped in the automation of the milk buying process at 2,500 rural milk collection societies.
  7. Delhi Slum Computer Kiosks project: It is an E-Governance project initiated by the Delhi State Department of Information Technology with an objective to help improve the conditions of the Ambedkar Nagar slums as well as to spread computer awareness. After using the computer based learning modules designed as part of the project, the children's grades in subjects like science, math and the English language improved remarkably.
  8. e-Computerised Operations for Police Services (eCops): It is an E-Governance project initiated by the Govt. of Andhra Pradesh with an objective to computerise activities related to crime control, administration and support services in order to maintain information, monitor and enhance the performance and efficiency of the police department across the state. It will help police stations reduce paperwork and automate the maintenance of registers, report generation, data analysis, planning and co-ordination, enable the speedy detection of crime and monitor prosecutions. For citizens, the project will lead to online interaction with the police department over the Internet.
  9. Grameen Sanchar Sewak: It is an E-Governance project initiated by the Government of India with an objective to make the telephone accessible to people at the remotest corners of the country through postmen. Under the project, the postmen in rural areas, who have been renamed Grameen Sanchar Sewaks (GSS), will carry handsets that operate on the Wireless in Local Loop (WLL) network when they go out for their normal routine of delivering letters and money orders. Initially it will cover 8,000 villages in 21 telecom circles. The handsets are operable in an area of five km of the nearest tower.
  10. Gyandoot: It is an E-Governance project initiated by the State Government of Madhya Pradesh with an objective to cater to social, economic and development needs of the villagers through an innovative G2C (Government to Citizen) model. The Gyandoot project was initiated in January 2000 by members of the Indian Administrative Services in consultation with various gram panchayats in the Dhar district of Madhya Pradesh. The project has installed a low cost, self-sustainable, and community-owned rural Intranet system (Soochnalaya) that caters to the specific needs of village communities in the district. Thirty-five centres have been established since January 2000 and are managed by rural youth selected and trained from amongst the unemployed educated youth of the village. They run the Soochanalayas as entrepreneurs (Soochaks) and charge for the services that include agricultural information, market information, health, education, women's issues, and applications for services delivered by the district administration related to land ownership, affirmative action, and poverty alleviation.
  11. Himachal Buses: Transport Tracker: It is an E-Governance project initiated by the Himachal Pradesh Road Transport Corporation (HRTC) with an objective to remote control buses in Himachal Pradesh on the net. HRTC, which runs its network of buses on some of the harshest and highest roads in the world, will have their progress monitored through the Internet with a "remote tracking system". This will help logistics and fleet management systems including route analysis, warehouse data and vehicle dispatch. Besides, breakdown of buses will also be monitored. The salient features of the system would be real time tracking, two-way communication capabilities, online guidance, and system for distress signaling and emergency notification. There will be a graphical display on the Internet as well as pan and zoom facilities.
  12. Krishi Marata Vahini: It is an E-Governance project initiated by the Govt. of Karnataka with an objective to network agricultural produce markets in Karnataka for providing real time prices and other information on crop production, market prices of agri-products, and soil conditions to the farming community. The "Krishi Marata Vahini" or agriculture produce marketing vehicle web site www.agmarknet.nic.in, was launched on the 15th of June 2002. Karnataka is the first state to launch such a website in the country to provide reliable data on daily arrivals of agricultural commodities with minimum and maximum prices in all 142 agricultural produce marketing centres in the State of which 70 are to be computerised. Information is to be made available everyday by 4 p.m. The web site enables 24-hour automatic collection and dissemination of market information on over 100 commodities.
  13. Sampark 2003-04: : It is an E-Governance project initiated by the Income Tax Department, Government of India with an objective to facilitate filing of tax returns by citizens. The Income Tax department has released software which will help people file their tax returns in the assessment year 2003-04 through a simple question-answer session. All taxpayers, except those in the business or professional categories, can use the software, 'Sampark 2003-04'. Taxpayers have the option of either preparing their return on the Internet or taking a print out for filing, or downloading the software on their computer and reparing their return off line. The software is part of a taxpayer facilitation scheme and is available on the department's website at http://www.incometaxindia.gov.in/.
  14. Saukaryam: It is an E-Governance project initiated by the Govt. of Andhra Pradesh with an objective to provide better civic services to citizens by providing online information. Launched in the year 2000, Saukaryam the pilot project of the Municipal Corporation of Visakhapatnam is now being implemented in other parts of the state of Andhra Pradesh. Online payment of Municipal dues has been taken up as its first sub-project and other services include Online Filing and Settlement Of Complaints & Grievances, Online Tracking of Building plan Status, Online Registration of Births and Deaths, Instant Issuance of Birth and Death Certificates, Online Tracking of Garbage Lifting. The programme is built on a public-private partnership platform. Every service extended by the city corporation is being extended online.
  15. Telemedicine Service in Pune Primary Health Centres: It is an E-Governance project initiated by the Pune District Administration with an objective to provide expert medical counsel at affordable rates to people living in the interiors of Pune villages. The Pune district administration in partnership with a global health portal www.doctoranywhere.com and Tata Council for Community Initiatives (TCCI) has launched a telemedicine service from government Primary Healthcare Centres (PHCs) for those living in interior villages. There are currently 88 PHCs in Pune district, each manning five to six sub-centres. The telemedicine project aims to ultimately connect all the PHCs in the district. Doctors at the PHCs will refer complicated cases to the specialists in major cities who in turn will give their advice within 24 hours.

Conclusion
E-governance is an essential element in addressing the inter-related economic and social challenges in the country. India would be able to drastically reduce its poverty and accelerate economic growth if initiatives to apply IT and e-governance are effectively done in all the government departments.

ITC’s e-Choupal: Bridging gap between haves and have nots

Introduction
The potential for universal computer access is something we must all believe in and strive for before our global village can be truly blind to difference. As the work force becomes more specialized, the technology gap between those who have access to communication technologies and those who do not becomes a critical issue. Computer equity and the technology gap are increasingly becoming an issue because of a fundamental change in the social fabric. Economic movement has shifted from industrial/national to information/global. A paradigm shift from the industrial age to an information-based society has led to the rapid increase in technology.

The Issues
Agriculture is vital to India as it contributes 23% to GDP, feeds a billion people, and employs 66% of the workforce. Due to Green Revolution, India’s agricultural productivity has improved to the point that it is both self-sufficient and a net exporter of a variety of food grains. Yet most Indian farmers have remained quite poor. The causes include remnants of scarcity-era regulation and an agricultural system based on small, inefficient landholdings. The agricultural system has traditionally been unfair to primary producers. Soybeans, for example, are an important oilseed crop that has been exempted from India’s Small Scale Industries Act to allow for processing in large, modern facilities. Yet 90% of the soybean crop is sold by farmers with smallholdings to traders, who act as purchasing agents for buyers at a local, government-mandated marketplace, called a mandi. Farmers have only an approximate idea of price trends and have to accept the price offered to them at auctions on the day that they bring their grain to the mandi. As a result, traders are well positioned to exploit both farmers and buyers through practices that sustain system-wide inefficiencies.

ITC’s Initiative
ITC is one of India’s leading private companies, with annual revenues of around Rs. 10,000 crores. Its International Business Division was created in 1990 as an agricultural trading company; it now generates Rs. 750 crores in revenues annually. The company has initiated an e-choupal effort that places computers with Internet access in rural farming villages; the e-choupals serve as both a social gathering place for exchange of information (choupal means gathering place in Hindi) and an e-commerce hub. What began as an effort to re-engineer the procurement process for soy, tobacco, wheat, shrimp, and other cropping systems in rural India has also created a highly profitable distribution and product design channel for the company—an e-commerce platform that is also a low-cost fulfillment system focused on the needs of rural India. The e-Choupal system has also catalyzed rural transformation that is helping to alleviate rural isolation, create more transparency for farmers, and improve their productivity and incomes.

BUSINESS MODEL
A pure trading model does not require much capital investment. The e-Choupal model, in contrast, has required that ITC make significant investments to create and maintain its own IT network in rural India and to identify and train a local farmer to manage each e-Choupal. The computer, typically housed in the farmer’s house, is linked to the Internet via phone lines or, increasingly, by a VSAT connection, and serves an average of 600 farmers in 10 surrounding villages within about a five kilometer radius. Each e-Choupal costs between Rs. 1,50,000 and Rs. 3,00,000 to set up and about Rs. 5,000 per year to maintain. Using the system costs farmers nothing, but the host farmer, called a sanchalak, incurs some operating costs and is obligated by a public oath to serve the entire community; the sanchalak benefits from increased prestige and a commission paid him for all e-Choupal transactions. The farmers can use the computer to access daily closing prices on local mandis, as well as to track global price trends or find information about new farming techniques—either directly or, because many farmers are illiterate, via the sanchalak. They also use the e-Choupal to order seed, fertilizer, and other products such as consumer goods from ITC or its partners, at prices lower than those available from village traders; the sanchalak typically aggregates the village demand for these products and transmits the order to an ITC representative. At harvest time, ITC offers to buy the crop directly from any farmer at the previous day’s closing price; the farmer then transports his crop to an ITC processing center, where the crop is weighed electronically and assessed for quality. The farmer is then paid for the crop and a transport fee. “Bonus points,” which are exchangeable for products that ITC sells, are given for crops with quality above the norm. In this way, the e-Choupal system bypasses the government-mandated trading mandis.

The Samyojaks, or cooperating commission agents play a secondary, but still important, role. Samyojaks earn income from ITC by providing logistical services that substitute for the lack of rural infrastructure, by providing information and market signals on trading transactions to the e-Choupal system. In effect, ITC uses agents as providers of essential services, not as principals in a trading transaction. They play an especially important role in the initial stages of setting up the e-Choupals, because they know which farmers grow soya, what kind of families they have, what their financial situation is, and who is seen as “acceptable” in the villages and might thus make a good sanchalak. ITC is strongly committed to involving samyojaks in the on-going operation of the e-Choupal system, allowing them revenue streams through providing services such as management of cash, bagging and labor in remote ITC procurement hubs, handling of mandi paperwork for ITC procurement, and as licensed principals for the retail transactions of the e-Choupal.

Farmers benefit from more accurate weighing, faster processing time, and prompt payment, and from access to a wide range of information, including accurate market price knowledge, and market trends, which help them decide when, where, and at what price to sell. Farmers selling directly to ITC through an e-Choupal typically receive a higher price for their crops than they would receive through the mandi system, on average about 2.5% higher (about Rs. 300 per ton). The total benefit to farmers includes lower prices for inputs and other goods, higher yields, and a sense of empowerment. The e-Choupal system has had a measurable impact on what farmers chose to do: in areas covered by e-Choupals, the percentage of farmers planting soy has increased dramatically, from 50 to 90% in some regions, while the volume of soy marketed through mandis has dropped as much as half. At the same time, ITC benefits from net procurement costs that are about 2.5% lower (it saves the commission fee and part of the transport costs it would otherwise pay to traders who serve as its buying agents at the mandi) and it has more direct control over the quality of what it buys. The system also provides direct access to the farmer and to information about conditions on the ground, improving planning and building relationships that increase its security of supply. The company reports that it recovers its equipment costs from an e-Choupal in the first year of operation and that the venture as a whole is profitable.

In mid-2003, e-Choupal services reached more than 1 million farmers in nearly 11,000 villages, and the system is expanding rapidly. ITC gains additional benefits from using this network as a distribution channel for its products (and those of its partners) and a source of innovation for new products. For example, farmers can buy seeds, fertilizer, and some consumer goods at the ITC processing center, when they bring in their grain. Sanchalaks often aggregate village demand for some products and place a single order, lowering ITC’s logistic costs. The system is also a channel for soil testing services and for educational efforts to help farmers improve crop quality. ITC is also exploring partnering with banks to offer farmers access to credit, insurance, and other services that are not currently offered or are prohibitively expensive. Moreover, farmers are beginning to suggest—and in some cases, demand—that ITC supply new products or services or expand into additional crops, such as onions and potatoes. Thus farmers are becoming a source of product innovation for ITC.

DEVELOPMENT BENEFIT
The e-Choupal system gives farmers more control over their choices, a higher profit margin on their crops, and access to information that improves their productivity. By providing a more transparent process and empowering local people as key nodes in the system, ITC increases trust and fairness. The increased efficiencies and potential for improving crop quality contribute to making Indian agriculture more competitive. Despite difficulties from undependable phone and electric power infrastructure that sometimes limit hours of use, the system also links farmers and their families to the world. Some sanchalaks track futures prices on the Chicago Board of Trade as well as local mandi prices, and village children have used the computers for schoolwork, games, and to obtain and print out their academic test results. The result is a significant step toward rural development.

Features of the E-Choupal Web Site

  1. Weather

Users can select their district of interest by clicking on the appropriate region of a

map. Localized weather information is presented on regions within a 25 kilometer

range. Typically 24- to 72-hour weather forecasts are available along with an

advisory. Advisories are pieces of information directly related to the farmer—

information he can put to use. For instance, during the sowing season, a weather

forecast for days following heavy rains may include an advisory that instructs the

farmer to sow seeds while the soil is still wet. Weather data is obtained from Indian Meteorological Department, which has a presence even in small towns and can provide forecasts for rural areas.

  1. Pricing

The e-Choupal Web site displays both the ITC procurement rate and the local mandi rates. ITC’s next day rates are published every evening. The prices are displayed prominently on the top of the Web page on a scrolling ticker.

  1. News

For the soyachoupal Web site, relevant news is presented from various sources. In addition to agriculture related news, this section also includes entertainment, sports, and local news.

  1. Best Practices

Best farming practices are documented by crop. Here again, the information

presented is action-based. For instance, this section not only highlights what kind of fertilizers to use but also how and when to use them.

  1. Q & A

This feature enables two-way communication. Here a farmer can post any

agriculture related question he needs answered.

Other Internet Resources Accessed at the E-Choupal

  1. News: Dainik jagran, Web Dunia.
  2. Market Prices: One sanchalak actually followed Chicago board of Trade (CBOT) prices for a month and arrived at a correlation with the local market prices. He used this information and helped other farmers decide when to sell.
  3. Entertainment

· Rent CDs to watch movies on the computer.

· Music downloads from the Internet.

· Movie Trivia.

  1. Sports: Cricket related news.
  2. Education: Students use the Internet to check their exam results and grades online.
  3. Communication

Email: The samchalaks have an email account at yahoo.

Chat: Some samchalaks use chat room to chat with other samchalaks and ITC managers.

  1. General Interest/Other: Information about cell phones.

KEY LESSONS
The e-Choupal model demonstrates that a large corporation can play a major role in recognizing markets and increasing the efficiency of an agricultural system, while doing so in ways that benefit farmers and rural communities as well as shareholders. The case also shows the key role of information technology—in this case provided and maintained by a corporation, but used by local farmers—in helping bring about transparency, increased access to information, and rural transformation. Critical factors in the apparent success of the venture are ITC’s extensive knowledge of agriculture, the effort ITC has made to retain many aspects of the existing production system, including maintenance of local partners, the company’s commitment to transparency, and the respect and fairness with which both farmers and local partners are treated.

e-Choupal, the unique web based initiative of ITC's International Business Division, offers the Farmers of India all the information, products and services they need to enhance farm productivity, improve farm-gate price realisation and cut transaction costs. Farmers can access latest local and global information on weather, scientific farming practices as well as market prices at the village itself through this web portal - all in Hindi. Choupal also facilitates supply of high quality farm inputs as well as purchase of commodities at their doorstep.

Given the literacy and infrastructure constraints at village level, this model is designed to provide physical service support through a Choupal Sanchalak - himself a lead farmer - who acts as the interface between computer terminal and the farmers. Full contents of this site are therefore made available to the registered sanchalaks only.

ITC is looking forward to offer a whole range of products and services through its e-choupal network now extended to over 12,000 villages. While marketing of insurance products has already been finalised, the company plans to offer even healthcare and family planning services to the rural population.

STRATEGY FOR THE FUTURE
ITC recognizes the limitations of today’s e-Choupals as a vehicle of procurement efficiency. Not every crop lends itself to such an intervention. In crops such as soy where value can be maximized, followers will soon imitate ITC and eliminate the company’s competitive advantage. ITC’s vision for e-Choupal extends many generations as e-Choupal evolves into a full-fledged orchestrator of a two-way exchange of goods and services between rural India and the world. The soy e-Choupal is “Wave 1,” with several more to follow.

  • Wave 2. The source of value in this generation will be identity preservation through the chain. This is a significant source of value in crops such as wheat, where the grade of the grain determines its end use. The ability to separate different grades from field to consumer will command a price premium. E-Choupals in Uttar Pradesh have already started wheat procurement.

  • Wave 3. This wave takes identity a step further by building the concept of traceability into the supply chain. This is vital for perishables where traceability will allow ITC to address food safety concerns and once again provide a value that the customer is willing to pay for. Shrimp is a good example of a crop for which Wave 3 will be important. ITC’s intervention in such products will occur level of production. ITC will define standards that producers must adhere to and work with farmers to ensure product quality. Farmers in turn will get the best price from ITC because ITC commands the traceability premium.

  • Wave 4. The first three waves fill institutional voids while Wave 4 creates institutions. The first three waves apply to environments in which ITC is the sole buyer in the e-Choupal channel. In commodities where the underlying markets have reached a high degree of efficiency, such basic sources of value will not exist. In crops such as these, e-Choupal will serve as the market-place where multiple buyers and sellers execute a range of transactions. A good example of this is coffee. ITC’s source of value will be the sunk cost of the IT infrastructure and the transaction fees.

  • Wave 5. While the first four waves related to sourcing from rural India, the fifth wave elaborates the rural marketing and distribution strategy. This is not the same as the rudimentary distribution of agri-inputs that is being done today. ITC plans to bring together knowledge of the customer, knowledge of the business, deployed infrastructure, its reputation, and experience gained over the first four waves, with an organization of people, processes, and partners. This base will allow ITC to bring value-added products and services to rural India.

  • Wave 6. After the sourcing of goods from rural India, ITC’s last wave has the ambitious vision of eventually sourcing IT-enabled services from rural India. Telemedicine, eco-tourism, traditional medicine, and traditional crafts are some of the services that can be sourced from rural India. While still a ways off, it is an agenda that inspires scale of the vision and potential impact on development in rural India.