Friday, November 1, 2019

Tourism and Hospitality Promotion Essay Example | Topics and Well Written Essays - 1000 words

Tourism and Hospitality Promotion - Essay Example Easyjet follows certain value systems for the purpose of objective setting strategy. This includes designing and maintaining the highest safety standards for its customers, breaking the shackles of traditional methods of thinking and find innovative ways and means to attract new customers, providing services that transcend the expectations of the travelers, converting newer customers into long term customers by providing customer satisfaction and best service possible, focusing on a double-digit growth rate in future years, enhancing capacity utilization, reducing fixed cost, providing the highest quality resorts thereby helping the customers to gain the best experience possible which will in turn bring profits. (About easyJet, n.d.) PEST Analysis of Easy Jet: Political-legal factors: The Political legal factors affecting the Easyjet include the political unrest and war signal in the Middle East. The Air Miles scheme is not recognized by the government as taxable perk in the same way s as tax is levied on company cars, which may help the Easyjet to contend on the same base with that of British Airlines. Engagement with the EU market gives them the widest network access. Economic factors: Increasing fuel costs, legal and environmental regulations and possibility of higher security along with insurance costs increases the risk for terrorism. Globalization helps the traffic to grow in longer term, the introduction of a single currency helps in boosting the business with the whole of Europe getting integrated. Socio-cultural factors: General reluctance in using credit cards seems to be the concern for attracting French and German travelers. Customers being more comfortable with cheaper flights get angry when they have to pay a premium to actual cost for a particular time of flying. Technological issues: The major issue is how much the application of Internet has synergized the cost and distribution resulted from integration of the industry causing reduction in the u pward rise in price. (Geiger, Schlottke & Schrade 2009) Porter’s model: Bargaining Power of Suppliers: Only two suppliers Airbus and Boeing provide aircrafts and face stiff competition. This helps the Easyjet to buy aircrafts at cheaper price. However the switching cost to another supplier is also very high. Bargaining power of customers: The price bargaining power of the customers is very high for Easyjet. With so many other LCCs in the market it becomes important for Easyjet to provide economical price to retain customers. Threat of New Entrants: There is a huge capital investment required upfront in the airline industry. Moreover higher efficiency is required to maintain sustainability. Moreover with so much air carriers, the introduction of a new one creates high competition facilitating price war. Threat of Substitutes: The main objective for Low cost Airlines includes faster and cheaper travel. Moreover the whole of Europe is connected with well-networked extensive trai n system, which provides transportation at a cheaper cost. So there is a definite threat for Easy jet in this regard. Rivalry among competitors: Easy jet faces huge competition among its competitors, as there is an intense competition to maintain cheaper airfare and providing better customer services. (Geiger, Schlottke & Schrade, 2009, pp. 2-4) SWOT Analysis: SWOT Team (2007) Strength: The overall cost-leadership model, the

Wednesday, October 30, 2019

Ethical issues in packaging practices Research Paper - 3

Ethical issues in packaging practices - Research Paper Example issues and packaging, views regarding how a sample company and some authors regard how ethical a number of packaging issues in the contemporary sense are, and identify various areas that have the existence of ethical gaps in packaging. Packaging is the protecting, handling, and delivering or presenting a processed good or a raw material in items like boxes, crates, pallets, containers, bags, sacks, and plastic bottles. In case an item is intended for sale to consumers and is packaged, it is considered to be safe and healthy to the consumers. For instance, a brush of mascara that forms the closure of the container part is packaging also (Shimp, 2003). Marketers can make proper use of information for labeling to mislead consumers and exaggerate their product attributes. There are several cases in which they use pictures in packaging that do not show the real or actual product that they are selling to their customers. A number of marketers label their products as friendly to the environment even at times when they do not actually have attributes that are environmentally friend. There are various issues related to ethics of packaging that affect the manner in which products are relayed to the clients. They put labels that mislead the buyers of the products. For instance, information related to nutrition like cholesterol free, low fat, and 100% pure juice can be attributes on the label of a given product. Another case can be Johnson & Johnson’s Acuvue that labels its products for use every day and different labeling. The company sells similar products in different diversified labels. There are many issues that marketers use pictures for packaging that fail to represent the actual or the real product. The product label can make it look nice and attractive to customers while in the real sense the content does not reach the exaggerated appeal. When consumers open the well-labeled product, they do not find the expected product in the same. It addition, some brands

Monday, October 28, 2019

Reasoning Fallacies Essay Example for Free

Reasoning Fallacies Essay A reasoning fallacy is an error in reasoning.   We all have our position on certain issues and at one point in time we have attempted to convince other persons to accept the same position.   Reasoning fallacy will be committed if there is an error in our own reasoning that led us to adopt the position or we used erroneous reasoning in trying to convince others to adopt our position. As a result, reasoning fallacy is a serious cause of concern.   It may be possible that we think in a particular manner and act in accordance with what we think not knowing that the reasoning we used in arriving at such thinking is erroneous.    Also, reasoning fallacy is troubling because a person who cannot spot reasoning fallacies in an argument will most likely be deceived by other persons who use these fallacies. Equivocation or equivocal language is the use of a single term or word to mean two different things.   One particular example is the statement: â€Å"For Kobe Bryant and Tim Duncan, basketball is their bread and butter.   Bread and butter are my favorite breakfast.  Ã‚   Therefore, for Kobe Bryant and Tim Duncan, basketball is their favorite breakfast.   In the statements mentioned, bread and butter are used in two different senses – as means to earn a living and as a meal. Non Sequitur is a fallacy that is committed when a person’s premises have no direct relationship to his conclusion.   This fallacy is most often committed by politicians, and multi-national companies to promote their product.   One example is the statements: â€Å"Oprah Winfrey is an intelligent, outspoken and strong-willed woman.   Most of her opinions are right. She also supports Barrack Obama’s presidential campaign.   Therefore Barrack Obama is the best choice for presidency.†Ã‚   Here, it is clear that Oprah’s opinions no matter how great she is, has no bearing on the issue of qualifications of Obama. Fallacy of Ignoring the Question or Red Herring is a fallacy committed by a person who does not properly respond to a question.   For example, if a person is asked whether he committed adultery, he says, â€Å"I am a religious person and I go to church everyday.† The fallacy of Begging the Question is a fallacy that attempts to prove a particular statement but the statement itself is assumed in the premises.   For example, â€Å"George W. Bush is the best president of the United States because nobody else is better.† One example of a reasoning fallacy can be found in the January 15, 2007 issue of the Time Magazine.   It was written by Jeffrey D. Sachs and the article is entitled â€Å"The $10 Solution: Malaria kills 2 million African children a year.†Ã‚   It can be found in the first paragraph of the article which states that: â€Å"Listen for a moment to the beautiful and dignified voices of Africa’s mothers.   Despite their burdens of poverty and hunger, they will tell you not of their endless toil but of their hopes for their children. But softy ever so softly, they will also recount the children they have lost, claimed by a sudden fever, children who died in their arms as they were carried in a desperate half-day’s journey by foot from the village to the nearest clinic.†Ã‚   Here, the author appeals to the emotion of his readers to arouse their sympathy and to encourage the readers to donate and contribute a portion of their money to organizations that provide assistance to the African people.   .   Bibliographies Sachs, Jeffrey D.   â€Å"The $10 Solution: Malaria kills 2 million African children a year.†Ã‚   Time. January 15, 2007.   Vol. 169 No. 1.

Saturday, October 26, 2019

Shakespeares Hamlet - Observations of Madness Essay -- Madness and I

Hamlet: Observations of Madness One of the most analyzed plays in existence is the tragedy Hamlet, with its recurring question: "Is Hamlet’s 'antic disposition' feigned or real?" In truth, this question can only be answered by observing the thoughts of the main characters in relation to the cause of Hamlet real or feigned madness. In the tragedy Hamlet, each of the main characters explains Hamlets madness in their own unique way. To discover the cause behind the madness of Hamlet, each character used their own ambitions, emotions and interpretations of past events. Characters tried to explain Hamlet's "antic disposition" by means of association to thwarted ambition, heartbreaking anguish, and denied love. In the workings of their thoughts, the characters inadvertently reveal something about their own desires, emotions and experiences to the reader. The thoughts of Guildenstern and Rosencrantz present the reader with one possible factor for the cause of Hamlets supposed madness. The two men believe that the cause for Hamlets madness is his lack of â€Å"advancement† or thwarted ambition. In a conversation with Hamlet in Act II scene II, Guildenstern and Rosencrantz come upon this idea: Hamlet: Denmark's a prison. Rosencrantz: Then is the world one. Hamlet: A goodly one; in which there are many confines, wards and dungeons, Denmark being one o' the worst. Rosencrantz: We think not so, my lord. Hamlet: Why, then, 'tis none to you; for there is nothing either good or bad, but thinking makes it so: to me it is a prison. When the heir apparent calls his heritage a prison, something must be seriously wrong, and it is not difficult for th... ...rman N. Holland, Sidney Homan and Bernard J. Paris. Berkeley and Los Angeles: University of California Press, 175-190. Leverenz, David. 1980. 'The Woman in Hamlet: An Interpersonal View.' In Representing Shakespeare: New Psychoanalytic Essays, edited by Coppelia Kahn and Murray M. Schwarz. Baltimore and London: The Johns Hopkins Press, 110-128. Levin, Richard. 1990. 'The Poetics and Politics of Bardicide.' PMLA 105: 491-504. Vickers, Brian. 1993. Appropriating Shakespeare: Contemporary Critical Quarrels. New Haven and London: Yale University Press. Watson, Robert N. 1990. 'Giving up the Ghost in a World of Decay: Hamlet, Revenge and Denial.' Renaissance Drama 21:199-223. Wright, George T. 1981. 'Hendiadys and Hamlet.' PMLA 96:168-193. Shakespeare, William. The Tradegy of Hamlet Prince of Denmark. New York: Washington Square Press, 1992

Thursday, October 24, 2019

History of Jollibee Foods Corporation Essay

Jollibee is a phenomenal success story: when beganTony Tan Caktiong and his family opened a Magnolia Ice Cream parlor from Bankerohan, Davao City to Cubao in 1975 with Jolibee as the original name. Sometime in 1978, Caktiong and his brothers and sisters engaged the services of a management consultant, Manuel C. Lumba. Lumba shifted the business focus from ice cream to hamburgers, after his studies showed that a much larger market was waiting to be exploited. Lumba became Caktiong’s first business and management mentor. Lumba next re-formed the name Jolibe to Jolly Bee and made the two words form a single name, Jollibee, changing the â€Å"y† to an â€Å"i†. They also offering hot meals and sandwiches became incorporated in 1978 with seven outlets to explore the possibilities of a hamburger concept. Thus was born the company that revolutionized fast food in the Philippines. The Jollibee mascot was inspired by local and foreign children’s books. Lumba next created the product names â€Å"Yumburger† and â€Å"Chickenjoy†. He had the company incorporated and leased a house on Main St. in Cubao, Quezon City as the first headquarters. Lumba formulated a long-term marketing strategy: listing up a number of consumer promotions and traffic building schemes. Caktiong stressed that developing internal strengths was critical. The stores were re-designed, the service transformed into a full self-service, fast-food operation with drive-through. Not long after, Caktiong and Lumba went on an observation tour in the United States, attended food service and equipment conventions. Caktiong placed Lumba in charge of franchise development In 1984, Jollibee hit the P500 million sales mark, landing in the Top 500 Philippine Corporations. In 1987, barely 10 years in the business, Jollibee landed into the country’s Top 100 Corporations. It became the first Philippine fast food chain to break the P1 billion sales mark in 1989. In 1993, Jollibee became the first food service company to be listed in the Philippine Stock Exchange; thus broadening its capitalization and laying the groundwork fo r sustained expansion locally and beyond the Philippines. As the country’s leading fast food chain, Jollibee has grown exponentially on all aspects on operation. From a handful of stores 32 years ago, Jollibee now boasts of more than 600 stores and over 50 international stores. To achieve its long-term goal to be the country’s food service leader, Jollibee acquired Greenwich Pizza in 1994. A year later, the company obtained the franchise of Delifrance, an international food company. These moves expanded Jollibee’s penetration in the pizza-pasta and French cafà ©-bakery segments. In 2000, the strategic acquisition of Chowking solidified the company’s position as the dominant leader. The move gave it leadership in the Oriental quick-service restaurant segment. Jollibee’s rapid growth is due to its superior menu line-up, creative marketing programs, and efficient manufacturing and logistics facilities. It is made possible by well-trained teams that work in a culture of integrity and humility, fun and family-like. As a corporate citizen, Jollibee is also committed to give back to its host communities through meaningful and lasting socio-civic projects. Jollibee dedicated its continuous success to the Filipinos who have been there from the very start. Jollibee is so well-loved every time a new store opens, especially overseas, Filipinos always form long lines to the store. It is more than home for them. It is a stronghold of heritage and monumen t of Filipino victory. JOLLIBEE FOODS CORPORATION TIMELINE 1975 * Mr. Tony Tan and his family opens a Magnolia Ice cream parlor at Cubao. This is later to become the 1st Jollibee Outlet. 1978 * Bakery is established in Cubao. * Jollibee posts 1st year sales of P2 million * Jollibee incorporates as a 100% Filipino-owned company, with seven Jollibee fast- food restaurants within Metro Manila as initial network and the Yumburger as flagship product. 1979 * Spaghetti Special is introduced * 1st Franchise owned store opens at Ronquillo Sta. Cruz. 1980 * Jollibee launches its 1st TV commercial. * Jollibee Chickenjoy and French Fries are launched. * The well-loved Jollibee mascot is conceived to support brand awareness and identity efforts. Other mascots are later introduced. * Jollibee launches Chickenjoy, which becomes one of its best-selling menu items. 1981 * Jollibee Foods Corporation enters list of Top 1000 Corporations. * Jollibee ended the year with 10 stores 1982 * Jollibee pioneers the use of in-store promotions, novelty premium items and Kiddie Birthday packages for kids. * Palabok Fiesta is introduced. 1983 * The Langhap-Sarap TV ad Campaign is launched. * Chickee and Lady Moo join the Jollibee mascots 1984 * Champ hamburger is launched. * Jollibee enters list of Top 500 Corporations and assumes market leadership in local fast food industry. * Mascots Champ and Hetty join the Jollibee family * WEA gives Jollibee Gold record award for the outstanding sales of Jollibee songs. 1985 * Jollibee becomes the market leader of the fastfood industry * Breakfast Joys are introduced. * Langhap-Sarap awarded most effective ad campaign in the food category during the 9th Philippine Advertising Congress 1986 * Jollibee wins the 9th International Foods Award from El Comestible in Barcelona,Spain * Tony Tan wins the Agora Award for entrepreneurship given by the Philippine Marketing Association. * Top 250 Corporation list include Jollibee Foods Corporation * Jollibee opens its 1st international store in Taiwan * Jollibee adds Chunky Chicken Sandwich in its menu. 1987 * 2nd Taiwan store opens. * Sales of 570 million pushes Jollibee into the elite Top 100 Corporations * Jollibee opens 1st fast food outlet in Brunei, marking its entry into the global market. 1988 * Jolly Twirls softserve is successfully launched. * Jollibee system wide sales hit P921 million, further leading market share of 31% in the fast food industry and a dominant 57% share in the hamburger segment. * Jollibee celebrates 10th year anniversary. * Tony Tan is named one of the Ten Outstanding Manilans. * Jollibee wins the Anvil Award for outstanding PR campaign in relation to the achievement of marketing objective with its Filipino Talents campaign. 1989 * 2nd Brunei store opens. * Balut and Ligaw TV commercials wins the Kidlat Award in the Service and Leisure Products category during the 11th Philippine Ad Congress. * Jollibee sales hit P1.3 billion marks, first fast food chain to surpass billion-peso sales mark. 1990 * Jollibee adds coleslaw, Jolly Hotdog, Chickenjoy Take-Me-Out and Peach mango Pie to its ever-growing menu. * Jollibee post sales of P1.8 billion * Tony Tan is awarded the Triple Award by AIM as Outstanding AIM Alumnus. * Jollibee receives the Excellence in Marketing Management Award from the Asian Institute of Management. 1991 * Jollibee’s 100th store opens in Davao City * Jollibee opens a record high of 35 new stores * Opens 1st store outside Luzon in Cagayan de Oro City. * Jollibee launches its Pancakes and Jolly Meals. * Jollibee sales hit a whopping P2.65 billion. * The Lola TV commercial wins the Grand Araw Award and an award of excellence for the promotion of Filipino Values during the Philippine Ad Congress. * Jollibee receives award for the outstanding Corporate Safety Consciousness Programs by the Safety Organization of the Philippines (SOP). 1992 * Jollibee stages first ever holiday musical special for children dubbed â€Å"A Magical Christmas at Jollitown† * Jollibee and the Jollibee Franchisees Association launched the 30th anniversary special novelty offering – Hug and Share Doll. Proceeds of the sales will all be donated to charity. * Biggest and grandest MaAga ang Pasko caps off Jollibee’s 30th anniversary. Total of more than 117,000 toys and books collected were the highest ever in the campaign’s 14-year history. Mission and Vision Statement Fred David, in his book Strategic management; Concept and Cases enumerated key factors in making a mission statement. He recognized that a mission statement goes beyond being a statement, for it is a declaration of the company’s attitude and outlook. The mission statement of Jollibee Foods Corporation (JFC), although it meets the primary objective of a fast food chain, is too concise and gives sole emphasis to its current services. Thus, the space for improvement was narrowed down to simply food catering to the target market, taking for granted the other aspects of the business. According to David, a mission statement should be able to â€Å"allow for the generation and consideration of a range of feasible alternative objectives and strategies, because excessive specifity would limit the potential of creative growth for the organization. Also, a mission statement has to be broad to reconcile differences effectively among, and appeal to, an organization’s diverse stakeholders, the individuals and groups of individuals who have a special stake or claim on the company.†

Wednesday, October 23, 2019

Factors That Affect Enzyme Reaction Rate

Lab Report Factors That Affect Enzymes Reaction Rate Name of lab: Effects of temperature, pH, Enzyme Concentration, and Substrate Concentration on Enzymatic Activity Introduction: Enzymes are the most important types of proteins, they act as catalysis (speed up chemical reactions). If enzymes didn’t exist, biochemical reactions would act to slowly and they couldn’t keep up with the metabolic functions. Enzymes have a three-dimensional structure that is really complex. This structure consists of one or more polypeptide chains, they form an active site, which is an area in which the substrate eventually will fit.The four factors that affect the activity and reaction rate of an enzyme are temperature, pH, enzyme concentration and substrate concentration. Research Question/Hypothesis: The hypothesis is that when the temperature is higher than 40? C, the enzyme catalysis will increase. That the enzyme activity with the pH effect is that if it isn’t at the optimum pH v alue there will be a total loss of the enzyme activity. As the change in enzyme concentration increases the activity rate will increase if there is a proportional amount of enzyme concentration and substrate.Variables: Independent: pH, enzyme concentration, substrate concentration and enzymatic activity. Dependent: the reaction rate Control variable: temperature and amount of substrates and enzymes added. Materials: Phosphate Buffers Beaker Catechol Potato Juice Parafilm Test Tubes Procedure: To study the effect of temperature: 1. Three different test tubes where filled with 3mL of phosphate. 2. They were set in three different temperature settings. First tube was placed in an ice-water bath for ten minutes, the second in a room temperature until 21?C was reached, and the third tube was placed in a beaker of warm water. To study the effect of pH: 1. The pH values of pH 4, pH 6, pH 7, pH 8, and pH 10 was used to fill five separate test tubes with 3 mL each. 2. To each test tube, ten drops of catechol and potato juice were added, each tube was covered with Parafilm, and inverted several times to mix the contents. After letting each tube stand for three to five minutes the tubes were inverted at one minute intervals. To study the effect of enzyme concentration: 1.The steps include four test tubes that were labeled A, B, C, and D. 2. The contents added to tube A are 3mL plus 20 drops of pH 7 phosphate buffer, but no potato juice. To tube B, 3 mL plus 15 drops of pH 7 phosphate buffer and 15 drops of potato juice. The amount of pH 7 phosphate buffer added to test tube C are 3 mL plus 10 drops of potato juice. To test tube D, 3 mL of pH 7 phosphate buffer and 20 drops of potato juice were added. 3. Then, each tube was covered in Parafilm and inverted several times to mix the contents.After doing so, 10 drops of catechol were added to each tube and covered with Parafilm and inverted several times to mix the contents. 4. After allowing each tube to stand for three to four minutes the tubes were mixed at one-minute intervals. To study the effects of substrate concentration: 1. Eight test tubes that were involved. 2. These test tubes were labeled 1, 2, 4, 8, 16, 24, 32, and 48. Next, each test tube had a certain amount of phosphate buffer and catechol was added to each. 3.To test tube #1: 5 mL plus 47 drops of pH 7 phosphate buffer and 1 drop of catechol; test tube #2: 5 mL plus 46 drops of pH 7 phosphate buffer and 3 drops of catechol; test tube #4: 5 mL plus 44 drops of pH 7 phosphate buffer and 4 drops of catechol; test tube #8: 5 mL plus 40 drops of pH 7 phosphate buffer and 8 drops of catechol; test tube #16: 5 mL plus 32 drops of pH 7 phosphate buffer and 16 drops of catechol; test tube #24: 5 mL plus 24 drops of pH 7 phosphate buffer and 24 drops of catechol; test tube #32: 5 Ml plus 16 drops of pH 7 phosphate buffer and 32 drops of catechol; and test tube #48: 5 mL of pH 7 phosphate buffer and 48 drops of catechol. 4. Then, each tube was c overed with Parafilm and inverted several times to mix the contents. Also, to each of the tubes, 30 drops of potato juice were added and covered with Parafilm and inverted several times to mix the contents. The test tubes set at room temperature for five minutes and were mixed at one minute intervals.

Tuesday, October 22, 2019

Database security and encryption Essays

Database security and encryption Essays Database security and encryption Essay Database security and encryption Essay Introduction Administrations are progressively trusting on the distributed information systems to derive productiveness and efficiency advantages, but at the same clip are going more vulnerable to security menaces. Database systems are an built-in constituent of this distributed information system and keep all the information which enables the whole system to work. A database can be defined as a shared aggregation of logically related informations and a description of this information, designed to run into the information demands of an organisation. A database system is considered as a aggregation of related informations, database direction system ( DBMS ) a package that manages ( define, create and maintain ) and controls the entree to the database, and a aggregation of database application ( s ) a plan that interacts with the database at some point in its executing ( typical illustration is a SQL statement ) along with the DBMS and the database itself [ 1 ] . Administrations have adopted database systems as the key informations direction engineering for decision-making and daily operations. Databases are designed to keep big sums of informations and direction of information involves both specifying constructions for storage of information and providing mechanisms for use of information. As the information is to be shared among several users the system must avoid anomalous consequences and guarantee the safety of the information stored despite system clangs and efforts at unauthorised entree. The informations involved here can be extremely sensitive or confidential, therefore doing the security of the informations managed by these systems even more important as any security breach does non impact merely a individual application or user but can hold black effects on the full administration. A figure of security techniques have been suggested over the period of clip to undertake the security issues. These can be classified as entree control, illation control, flux control, and encoding. 1.1 A Short History Get downing from the twenty-four hours one when database applications were build utilizing hierarchal and web systems to today s day of the month when we have so many different database systems like relational databases ( RDBMS ) , object-oriented databases ( OODBMS ) , object-relational databases ( ORDBMS ) , eXtended Query ( XQUERY ) ; one factor which was, is, and will be of the extreme importance is the security of the informations involved. Data ever has been a valuable plus for companies and must be protected. Organizations spend 1000000s these yearss in order to accomplish the best security criterions for the DBMS. Most of an organisations sensitive and proprietary informations resides in a DBMS, therefore the security of the DBMS is a primary concern. When we talk of procuring a DBMS, this is with regard to both the internal and the external users. The internal users are the organisation employees like database decision makers, application developers, and terminal users who m erely use the application interface, which fetch its informations from one of the databasesand the external users can be the employees who do non hold entree to the database or an foreigner who has nil to make with the organisation. The other factors which has made informations security more important is the recent rapid growing of the web based information systems and applications and the construct of nomadic databases. Any knowing or inadvertent event that can adversely impact a database system is considered as a menace to database and database security can be defined as a mechanism that protects the database against such knowing or inadvertent menaces. Security breaches can be classified as unauthorised informations observation, wrong information alteration, and informations inaccessibility, which can take to loss of confidentiality, handiness, unity, privateness, and larceny and fraud. Unauthorized informations observation consequences in revelation of information to users who might non be entitled to hold entree to such sort of information.A Incorrect data alteration intentional or unwilled leaves the database in an wrong province. Datas can halter the functionality of an full organisation in a proper manner if non available when needed. Thus the security in footings of databases can be loosely classified into entree security and internal security. Access security refers to the mechanisms implem ented to curtail any kind of unauthorised entree to the database ; illustrations can be authorization methods such as every user has a alone username and watchword to set up him as a legitimate user when seeking to link to the database. When the user tries to link to the database the login certificates will be checked against a set of usernames and watchword combinations setup under a security regulation by a security decision maker. Internal security can be referred to as an excess degree of security, which comes into image if person has already breached the entree security such as acquiring clasp of a valid username and watchword, which can assist acquiring entree to the database. So the security mechanism implemented within the database such as coding the informations inside the database can be classed as internal security, which prevents the information to be compromised even if person has got unauthorised entree to the database. Every organisation needs to place the menaces they might be subjected to and the later appropriate security programs and countermeasures should be taken, taking into consideration their execution costs and effects on public presentation. Addressing these menaces helps the endeavor to run into the conformity and hazard extenuation demands of the most regulated industries in the universe. 1.2 How Databases are Vulnerable Harmonizing to David Knox [ 2 ] , Procuring the Database may be the individual biggest action an organisation can take, to protect its assets . Most normally used database in an endeavor organisation is relational database. Data is a valuable resource in an endeavor organisation. Therefore they have a really strong demand of purely commanding and pull offing it. As discussed earlier it is the duty of the DBMS to do certain that the information is unbroken secure and confidential as it the component which controls the entree to the database. Enterprise database substructure is capable to an overpowering scope of menaces most of the times. The most common menaces which an Enterprise Database is exposed to are: Excessive Privilege Abuse when a user or an application has been granted database entree privileges which exceeds the demands of their occupation maps. For illustration an academic institute employee whose occupation merely requires merely the ability to alter the contact information for a pupil can besides alter the classs for the pupil. Legitimate Privilege Abuse legitimate database entree privileges can besides be abused for malicious intents. We have two hazards to see in this state of affairs. The first 1 is confidential/sensitive information can be copied utilizing the legitimate database entree privilege and so sold for money. The 2nd one and possibly the more common is recovering and hive awaying big sums of information on client machine for no malicious ground, but when the information is available on an end point machine instead than the database itself, it is more susceptible to Trojans, laptop larceny, etc. Privilege Elevation package exposures which can be found in stored processs, constitutional maps, protocol executions or even SQL statements. For illustration, a package developer can derive the database administrative privileges by working the exposures in a constitutional map. Database Platform Vulnerabilities any extra services or the operating system installed on the database waiter can take to an authorised entree, informations corruptness, or denial of service. For illustration the Blaster Worm which took advantage of exposure in Windows 2000 to make denial of service. SQL Injection the most common onslaught technique. In a SQL injection onslaught, the aggressor typically inserts unauthorised questions into the database utilizing the vulnerable web application input signifiers and they get executed with the privileges of the application. This can be done in the internal applications or the stored processs by internal users. Access to full database can be gained utilizing SQL injectionA A Weak Audit a strong database audit is indispensable in an endeavor organisation as it helps them to carry through the authorities regulative demands, provides research workers with forensics link interlopers to a offense discouraging the aggressors. Database Audit is considered as the last line of database defence. Audit informations can place the being of a misdemeanor after the fact and can be used to associate it to a peculiar user and mend the system in instance corruptness or a denial of service onslaught has occurred. The chief grounds for a weak audit are: it degrades the public presentation by devouring the CPU and disk resources, decision makers can turn off audit to conceal an onslaught, organisations with assorted database environments can non hold a uniform, scalable audit procedure over the endeavor as the audit procedures are alone to database waiter platform Denial of Service entree to web applications or informations is denied to the intended users. A simple illustration can be crashing a database waiter by working exposure in the database platform. Other common denial of service techniques are data corruptness, web implosion therapy, server resource overload ( common in database environments ) . Database Protocol Vulnerabilities SQL Slammer worm took advantage of a defect in the Microsoft SQL Server protocol to coerce denial of service conditions. It affected 75,000 victims merely over 30 proceedingss dramatically decelerating down general cyberspace traffic. [ Analysis of BGP Update Surge during Slammer Worm Attack ] Weak Authentication obtaining legitimate login certificates by improper manner contributes to weak hallmark strategies. The aggressors can derive entree to a legitimate users login inside informations by assorted ways: by repeatedly come ining the username/password combination until he finds the one which works ( common or weak watchwords can be guessed easy ) , by converting person to portion their login certificates, by stealing the login certificates by copying the watchword files or notes. Backup Data Exposure there are several instances of security breaches affecting larceny of database backup tapes and difficult discs as this media is thought of as least prone to onslaught and is frequently wholly unprotected signifier onslaught [ 3 ] . All these security menaces can be accounted for unauthorised informations observation, wrong informations alteration and informations inaccessibility. A complete information security solution must take into consideration the secrecy/confidentiality, unity and handiness of informations. Secrecy or confidentiality refers to the protection of informations against unauthorised revelation, unity refers to bar of wrong informations alteration and handiness refers to bar of hardware/software mistakes and malicious informations entree denials doing the database unavailable. 1.3 Security Techniques As organisations increase their acceptance of database systems as the key informations direction engineering for daily operations and decision-making, the security of informations managed by these systems has become important. Damage and abuse of informations affect non merely a individual user or application, but may hold black effects on the full organisation. There are four chief control steps which can be used to supply security of informations in databases. These are: Access Control Inference Control Flow Control Data Encoding Chapter 2 Literature Review Secure and secret agencies of communicating has been ever desired for in the field of database systems. There is ever a possibility of interception by a party outside of the sender-receiver sphere when information is transmitted. Modern digital-based encoding methods form the footing of today s universe database security. Encoding in its earlier yearss was used by military and authorities organisations to ease secret information but in present times it is used for protecting information within many sorts of civilian systems. In 2007 the U.S. authorities reported that 71 % of companies surveyed utilised encoding or some of their informations in theodolite [ 4 ] . 2.1 Encoding Encoding is defined as the procedure of transforming information ( plaintext ) utilizing an encoding algorithm ( cypher ) into indecipherable signifier ( encrypted information called as ciphertext ) doing it unaccessible to anyone without possessing particular cognition to decode the information. The encryption of the informations by a particular algorithm that renders the informations indecipherable by any plan without the decoding key , is called encoding [ 1 ] . The codification and cypher are the two methods of coding informations. The encoding of informations or a message is accomplished by one, or both, of the methods of encoding or coding. Each involves distinguishable methodological analysiss and the two are differentiated by the degree at which they are carried out. Encoding is performed at the word or block degree and trades with the use of groups of characters. Coding plants at the character degree. This includes scrambling single characters in a message, referred to as heterotaxy, and permutation, or replacing characters with others. Codes by and large are designed to replace full words or blocks of informations in a message with other words or blocks of informations. Languages can be considered codifications, since words and phrases represent thoughts, objects, and actions. There are codifications that replacement full phrases or groups of Numberss or symbols with others. A individual system may use both degrees of encoding. For il lustration, see a codification encoding strategy as follows: the = jam, adult male = barn, is = fly, unsafe = remainder. Then the message, the adult male is unsafe, would read in encrypted signifier, jam barn fly remainder. Although overly-simplistic, this illustration illustrates the footing of codifications. With the coming of electrical-based communications, codifications became more sophisticated in reply to the demands of the systems. For illustration, the innovations of Morse codification and the telegraph dictated a demand for unafraid transmittal that was more sophisticated. Codes are really susceptible to interrupting and possess a big exposure surface with respect to interception and decoding via analysis. Besides, there are no easily-implemented agencies by which to observe breaches in the system. The other method of encoding is the cypher. Alternatively of replacing words or blocks of Numberss or symbols with others, as does the codification, the cypher replaces single o r smaller sets of letters, Numberss, or characters with others, based on a certain algorithm and key. Digital information and information, including picture, sound, and text, can be separated into groups, or blocks, of spots, and so manipulated for encoding by such methods as XOR ( sole OR ) , encoding-decoding, and rotary motion. As an illustration, allow us analyze the rudimentss of the XOR method. Here, a group of spots ( e.g. , a byte ) of the information is compared to a digital key, and the exclusive-or operation is performed on the two to bring forth an encrypted consequence. Figure 2 illustrates the procedure. Figure 2: The XOR procedure for Encoding When the exclusive-or operation is performed on the plaintext and key, the ciphertext emerges and is sent. The receiving system performs the exclusive-or operation on the ciphertext and the same key, and the original plaintext is reproduced [ 5 ] . Encoding can be reversible and irreversible. Irreversible techniques do non let the encrypted informations to be decrypted, but at the same clip the encrypted informations can be used to obtain valid statistical information. Irreversible techniques are seldom used as compared to the reversible 1s. The whole procedure of conveying informations firmly over an insecure web system is called as cryptosystem that includes u An encoding key to code the information ( plaintext ) u An encoding algorithm that transforms the plaintext into encrypted information ( ciphertext ) with the encoding key u A decoding key to decode the ciphertext u A decoding algorithm that transforms the ciphertext back into plaintext utilizing the decoding cardinal [ 1 ] . 2.2 Encoding Techniques The ends in digital encoding are no different than those of historical encoding strategies. The difference is found in the methods, non the aims. Secrecy of the message and keys are of paramount importance in any system, whether they are on parchment paper or in an electronic or optical format [ 5 ] . Assorted encoding techniques are available and loosely can be classified into two classs ; asymmetric and symmetric encoding. In symmetric encoding the transmitter and receiving system portion the same algorithm and key for encoding and decoding and depends on safe communicating web for encoding cardinal exchange whereas in asymmetric encoding uses different keys for encoding and decoding. Asymmetrical encoding gave birth to the construct of public and private keys and is preferred to symmetric encoding being more secure [ 1 ] , [ 5 ] . 2.2.1 Symmetrical Encoding Symmetrical encoding besides known as single-key encoding or conventional encoding was the lone encoding and by far the most widely used of the two types before the construct of public-key encoding came into image. The figure below illustrates the symmetric encoding procedure. The original message ( plaintext ) is converted into seemingly random information ( ciphertext ) utilizing an algorithm and a key. The key is a value independent of the plaintext. The algorithm produces different end products for specific keys used at the clip i.e. the end product of the algorithm alterations if the key is changed. The ciphertext produced is so transmitted and is transformed back to the original plaintext by utilizing a decoding algorithm and the same key that was used for encoding. Figure: Simplified Model of Conventional Encryption [ 7 page 22 ] The theoretical account can be better understood by the undermentioned illustration. A beginning produces a message X = [ X1, X2, X3 aˆÂ ¦XM ] in plaintext. The M elements of Ten are letters in some finite alphabet. The alphabet normally consisted of 26 capital letters traditionally but today ; binary alphabet { 0,1 } is used. An encoding key K = [ K1, K2, K3 aˆÂ ¦.KJ ] is generated and is shared between the transmitter and the receiving system utilizing a secure channel. Besides a 3rd party can bring forth the encoding key and firmly present it to both the transmitter and the receiving system. Using the plaintext Ten and the encoding cardinal K as input, the encoding algorithm produces the ciphertext Y = [ Y1, Y2, Y3 aˆÂ ¦.YN ] as Y = EK ( X ) where Tocopherol is the encoding algorithm and the ciphertext Y is produced as the map of the plaintext X utilizing E. At the receiving system s terminal the ciphertext is converted back to the plaintext as Ten = DK ( Y ) where D is the decoding algorithm. Figure: Model of Conventional Cryptosystem [ 7 page 23 ] The common symmetric block cyphers are Data Encryption Standard ( DES ) , Triple DES, and Advanced Encryption Standard ( AES ) 2.2.1.1 The Data Encryption Standard Data Encryption Standard has been used in the most widely used encoding strategies including Kerberos 4.0. The National Bureau of Standards adopted it as a criterion in 1977 [ 7 ] . DES operates on 64-bit blocks utilizing a 56-bit key. Like other encoding strategies, in DES there are two inputs to the encoding map, the plaintext to be encrypted and the key. The plaintext should be of 64 spots in length and the cardinal length is 56 spots obtained by depriving off the 8 para spots, disregarding every 8th spot from the given 64-bit key. The end product from the algorithm after 16 unit of ammunitions of indistinguishable operations is the 64-bit block of ciphertext. A suited combination of substitutions and combinations ( 16 times ) on the plaintext is the basic edifice block of the DES. Same algorithm is used for both encoding and decoding except for treating the cardinal agenda in the contrary order [ 6 ] , [ 7 ] . The 64-bit plaintext is passed through an initial substitution ( IP ) that produces a permuted input by rearranging the spots. This is followed by16 unit of ammunitions of the same map, which involves both substitution and permutation functions.A The last unit of ammunition consequences in the end product dwelling of 64-bits that are a map of the input plaintext and the key. The left and the right halves of the end product are swapped to bring forth the preoutput. The preoutput is passed through a concluding substitution ( IP-1 ) , an opposite of the initial substitution map to accomplish the 64-bit ciphertext. The overall procedure for DES is explained in the diagram below Figure: General Depiction of DES Encryption Algorithm [ 7 page 67 ] The right manus side of the diagram explains how the 56-bit key is used during the procedure. The key is passed through a substitution map ab initio and so for each of the 16 rounds a subkey ( Ki ) is generated, by uniting left round displacement and a substitution. For every unit of ammunition the substitution map is same, but the subkey is different because of the perennial loop of the cardinal spots. Since the acceptance of DES as a criterion, there have ever been concerns about the degree of security provided by it. The two countries of concern in DES are the cardinal length and that the design standard for the internal construction of the DES, the S-boxes, were classified. The issue with the cardinal length was, it was reduced to 56 spots from 128 spots as in the LUCIFER algorithm [ add a new mention ] , which was the base for DES and everyone suspected that this is an tremendous lessening doing it excessively short to defy brute-force onslaughts. Besides the user could non be made certain of any weak points in the internal construction of DES that would let NSA to decode the messages without the benefit of the key. The recent work on differential cryptanalytics and subsequent events indicated that the internal construction of DES is really strong. 2.2.1.2 Triple DES Triple DES was developed as an option to the possible exposure of the criterion DES to a brute-force onslaught. It became really popular in Internet-based applications. Triple DES uses multiple encodings with DES and multiple keys as shown in the figure [ below ] . Triple DES with two keys is comparatively preferable to DES but Triple DES with three keys is preferable overall. The plaintext P is encrypted with the first key K1, so decrypted with the 2nd cardinal K2 and so eventually encrypted once more with the 3rd cardinal K3.According to the figure the ciphertext C is produced as C = EK3 [ DK2 [ EK1 [ P ] ] ] These keys need to be applied in the contrary order while decoding. The ciphertext degree Celsius is decrypted with the 3rd key K3 foremost, so encrypted with the 2nd key K2, and so eventually decrypted once more with the first cardinal K1 ; besides called as Encrypt-Decrypt-Encrypt ( EDE ) manner, bring forthing the plaintext P as P = DK1 [ EK2 [ DK3 [ C ] ] ] Figure: Triple DES encryption/decryption [ 6 page 72 ] 2.2.1.3 Advanced Encryption Standard 2.3 Encoding in Database Security Organizations are progressively trusting on, perchance distributed, information systems for day-to-day concern ; hence they become more vulnerable to security breaches even as they gain productiveness and efficiency advantages. Database security has gained a significant importance over the period of clip. Database security has ever been about protecting the information information in the signifier of client information, rational belongings, fiscal assets, commercial minutess, and any figure of other records that are retained, managed and used on the systems. The confidentiality and unity of this information needs to be protected as it is converted into information and cognition within the endeavor. Core endeavor informations is stored in relational databases and so offered up via applications to users. These databases typically store the most valuable information assets of an endeavor and are under changeless menace, non merely from the external users but besides from the legitimate users such as sure insiders, ace users, advisers and spouses or possibly their unprotected user histories that compromise the system and take or modify the information for some inappropriate intent. To get down with, sorting the types of information in the database and the security needs associated with them is the first and of import measure. As databases are used in a battalion of ways, it is utile to hold some of the primary maps characterized in order to understand the different security demands. A figure of security techniques have been developed and are being developed for database security, encoding being one of them. Encoding is defined as the procedure of transforming information ( plaintext ) utilizing an encoding algorithm ( cypher ) into indecipherable signifier ( encrypted information called as ciphertext ) doing it unaccessible to anyone without possessing particular cognition to decode the information. The encryption of the informations by a particular algorithm that renders the informations indecipherable by any plan without the decoding key , is called encoding [ 1 ] . 2.3.1 Access Encoding There are multiple grounds for entree control to confidential information in endeavor computer science environments being disputing. Few of them are: First, the figure of information services in an endeavor computer science environment is immense which makes the direction of entree rights indispensable. Second, a client might non cognize which entree rights are necessary in order to be granted entree to the requested information before bespeaking entree. Third, flexible entree rights including context-sensitive restraints must be supported by entree control Access control strategies can be loosely classified in two types: proof-based and encryption-based entree control schemes. In a proof-based strategy, a client needs to piece some entree rights in a cogent evidence of entree, which demonstrates to a service that the client is authorized to entree the requested information . Proof-based entree control is preferred to be used for scenarios where client specific entree rights required are flexible. It becomes easy to include support for restraints if the entree rights are flexible. However, it is non the same instance for covert entree demands. Harmonizing to the bing designs, it is assumed that a service can inform a client of the nature of the needed cogent evidence of entree. The service does non necessitate to turn up the needed entree rights, which can be an expensive undertaking, in proof-based entree control strategy. [ 9 ] In an encryption-based access-control strategy, confidential information is provided to any client in an encrypted signifier by the service. Clients who are authorized to entree the information have the corresponding decoding key. Encryption-based access-control strategy is attractive for scenarios where there are tonss of questions to a service screening the service from holding to run client-specific entree control. As compared to proof-based entree control it is straightforward to add support for covert entree demands to bing encryption-based architectures. In peculiar, all the information is encrypted by the service as usual, but the client is non told about the corresponding decoding key to utilize. The client has a set of decoding keys, the client now needs to seek this set for a duplicate key. On the other manus, sing that cardinal direction should stay simple, it is less straightforward to add support for restraints on entree rights to the proposed architectures. [ 10 ] 2.3.1.1 Encryption-Based Access Control Encryption-based entree control is attractive, in instance there are tonss of petitions for the same information, as it is independent of the single clients publishing these petitions. For illustration, an information point can be encrypted one time and the service can utilize the ciphertext for replying multiple petitions. However, covering with restraints on entree rights and with coarseness cognizant entree rights becomes hard with the unvarying intervention of petitions. Further challenges are presented in instances of covert entree demands and service-independent entree rights. The chief demands for encoding based entree control are: u Any cognition about the used encoding key or the needed decoding key must non be revealed by the encrypted information. u For decoding encrypted information, each value of a restraint must necessitate a separate key that should be accessible merely under the given constraint/value combination and we want a strategy that supports hierarchal restraints to do cardinal direction simple. u The decoding key for farinaceous information should be derivable from the key for powdered information to further simplify cardinal direction. u A individual decoding key will be used to decode the same information offered by multiple services as implied by the service-independent entree rights. Because of this, same information can be accessed by a service coding information offered by other services in a symmetric cryptosystem. This job can be avoided by utilizing asymmetric cryptosystem. [ 8 ] 2.3.1.2 Encryption-Based Access Control Techniques An access-control architecture will be an ideal one if the entree rights are simple to pull off ; the system is constrainable and is cognizant of coarseness. The architecture besides has to be asymmetric, provide identity, and be personalizable in the instance of proof-based entree control. Some common encryption-based entree control techniques are: Identity Based Encryption An identity-based encoding strategy is specified by four randomised algorithms: u Apparatus: takes a security parametric quantity K and returns system parametric quantities and master-key. The system parametric quantities include a description of a finite message infinite m and a description of a finite ciphertext infinite c. Intuitively, the system parametric quantities will be publically known, while the master-key will be known merely to the Private Key Generator ( PKG ) . u Infusion: takes as input system parametric quantities, master-key, and an arbitrary ID I µ { 0,1 } * , and returns a private key d. ID is an arbitrary twine which is so used as a public key, and vitamin D is the corresponding private decoding key. The Extract algorithm extracts a private key from the given public key. u Encrypt: takes as input system parametric quantities, ID, and M I µ m. It returns a ciphertext C I µ degree Celsius. u Decrypt: takes as input system parametric quantities, C I µ degree Celsius, and a private key d. It returns M I µ m. Standard consistence restraint must be satisfied by these algorithms, particularly when vitamin D is the private key generated by algorithm Extract when it is given ID as the public key, so a?ˆ M I µ m: Decrypt ( params, vitamin D ) = M where C = Encrypt ( params, ID, M ) A A [ 11 ] Hierarchical Identity-Based Encryption One of the first practical IBE strategy was presented by Boneh and Franklin. Gentry and Silverberg [ 7 ] introduced Hierarchical Identity-Based Encryption strategy based on Boneh and Franklin s work. In HIBE, private keys are given out by a root PKG to the bomber PKGs, which so in bend distribute p