The dual recognition properties of pyrrolidino DNA species as parallel triplex-forming oligonucleotides were previously found to be strongly dependent upon the nature of the pyrimidine bases. In the structure-activity study presented here we were able to exclude this differential binding being due to their 2-oxo function. We had previously reported on the incorporation of pyrrolidino C-nucleosides into triplex-forming 2'-deoxyoligonucleotides (TFOs). The basic nitrogen atom that replaces the 4'-oxygen atom of the 2'-deoxysugar in such modified units introduces a positive charge in the third strand, and this is able to produce favourable electrostatic interaction with the negatively charged DNA target duplex. A first series of pyrrolidino pseudonucleosides with the bases isocytosine and uracil proved successful for GC base-pair recognition, but was unsuccessful for AT base-pair recognition within the parallel triplex binding motif. Here we report on the synthesis of the two novel 2'-deoxypyrrolidino nucleosides carrying the bases pyridin-2-one and 2-aminopyridine, their phosphoramidite building blocks and their incorporation into TFOs. Pyrrolidinylpyridin-2-one (dp2P) and -2-aminopyridine (dp2AP), prepared as part of a structure-activity profiling of pyrrolidino DNA in triplex binding, are deletion mutants of T and C, respectively. We found by T-m measurements that neither modification increased triplex binding efficiency relative to the iso-C- and -U-containing pyrrolidino TFOs. These experiments clearly show that the C4 carbonyl function, although important for triplex binding through indirect contributions in general, is not responsible for the differential binding of the latter two aminonucleosides and suggest that TFO conformation is more important. ((c) Wiley-VCH Verlag GmbH & Co. KGaA, 69451 Weinheim, Germany, 2007).
We introduce a new method and system to curb junk e-mail by employing extended e-mail addresses. It enables a party to use her (core) e-mail address with different extensions and consequently classify incoming e-mail messages according to the extension they were sent to. Our contributions are threefold: First, we identify the components of a system that realizes the concept of extended e-mail addresses and investigate the functionality of these components in a manner which is backwards compatible to current e-mail tools. Secondly, we specify an adversarial model, and give the necessary properties of extended e-mail addresses and of the procedure to obtain them in the presence of the adversary. Finally, we design cryptographic functions that enable realizing extended e-mail addresses which satisfy these properties.
Pyrrolidino pseudo-C-nucleosides are isosteres of natural deoxynucleosides which are protonated at the pyrrolidino ring nitrogen under physiological conditions. As constituents of a triplex forming oligodeoxynucleotide (TFO), the positive charge is expected to stabilise DNA triple helices via electrostatic interactions with the phosphodiester backbone of the target DNA. We describe the synthesis of the pyrrolidino isocytidine pseudonucleoside and the corresponding phosphoramidite building block and its incorporation into TFOs. Such TFOs show substantially increased DNA affinity compared to unmodified oligodeoxynucleotides. The increase in affinity is shown to be due to the positive charge at the pyrrolidino subunit.
Practically every corporation that is connected to the Internet has at least one firewall, and often many more. However, the protection that these firewalls provide is only as good as the policy they are configured to implement. Therefore, testing, auditing, or reverse-engineering existing firewall configurations are important components of every corporation’s network security practice. Unfortunately, this is easier said than done. Firewall configuration files are written in notoriously hard to read languages, using vendor-specific GUIs. A tool that is sorely missing in the arsenal of firewall administrators and auditors is one that allows them to analyze the policy on a firewall.To alleviate some of these difficulties, we designed and implemented two generations of novel firewall analysis tools, which allow the administrator to easily discover and test the global firewall policy. Our tools use a minimal description of the network topology, and directly parse the various vendor-specific low-level configuration files. A key feature of our tools is that they are passive: no packets are sent, and the analysis is performed offline, on a machine that is separate from the firewall itself. A typical question our tools can answer is “from which machines can our DMZ be reached, and with which services?.” Thus, our tools complement existing vulnerability analyzers and port scanners, as they can be used before a policy is actually deployed, and they operate on a more understandable level of abstraction. This paper describes the design and architecture of these tools, their evolution from a research prototype to a commercial product, and the lessons we have learned along the way.
An increasing number of web-sites require users to establish an account before they can access the information stored on that site ("personalized web browsing"). Typically, the user is required to provide at least a unique username, a secret password and an e-mail address. Establishing accounts at multiple web-sites is a tedious task. A security-and privacy-aware user may have to invent a distinct username and a secure password, both unrelated to his/her identity, for each web-site. The user may also desire mechanisms for anonymous e-mail. Besides the information that the user supplies voluntarily to the web-site, additional information about the user may flow (involuntarily) from the user's site to the web-site, due to the nature of the HTTP protocol and the cookie mechanism. This paper describes the Janus Personalized Web Anonymizer, which makes personalized web browsing simple, secure and anonymous by providing convenient solutions to each of the above problems. Janus serves as an intermediary entity between a user and a web-site. Given a user and a web-site, Janus automatically generates an alias - typically a username, a password and an e-mail address - that can be used to establish an anonymous account at the web-site. Different aliases are generated for each user, web-site pair; however the same alias is presented whenever a particular user visits a particular web-site. Janus frees the user from the burden of inventing and memorizing distinct usernames and secure passwords for each web-site, and guarantees that an alias (including an e-mail address) does not reveal the true identity of the user. Janus also provides mechanisms to complete an anonymous e-mail exchange from a web-site to a user, and filters the information-flow of the HTTP protocol to preserve user privacy. Thus Janus provides simultaneous user identification and user privacy, as required for anonymous personalized web browsing.
Reaction of tributylstannyl, radical generated in situ with AIBN, with (2',5'-di-O-tert-butyldimethylsilyl-3'-C-ethynyl-beta-D-ribo-furanosyl)adenine (5) gave in 690% yield the new conformationally locked nucleosides 6 (EIZ). (C) 2004 Elsevier Ltd. All rights reserved.
A novel synthesis of 2'-deoxypseudoisocytidine as well as of its phosphoramidite building block for oligonucleotide synthesis is presented. The synthesis is based on Heck-coupling between N-protected pseudoisocytosine and a silyl protected furanoid glycal. With this procedure the corresponding phosphoramidite building block is obtained in 5 steps and an overall yield of 28%.
We synthesized pyrrolidino-C-nucleosides, incorporated them into oligodeoxynucleotides and investigated their pairing properties. The thermal duplex and triplex stabilities were measured. While triplex formation is destabilized in the case of pyrrolidino-pseudo-U and -T, pyrrolidino-pseudo-iso-C leads to an increase of the Tm value for third strand dissociation. Duplexes are destabilized with all pyrrolidino-C-nucleosides.
Today, even a moderately sized corporate intranet contains multiple firewalls and routers, which are all used to enforce various aspects of the global corporate security policy. Configuring these devices to work in unison is difficult, especially if they are made by different vendors. Even testing or reverse engineering an existing configuration (say when a new security administrator takes over) is hard. Firewall configuration files are written in low level formalisms, whose readability is comparable to assembly code, and the global policy is spread over all the firewalls that are involved. To alleviate some of these difficulties, we designed and implemented a novel firewall analysis tool. Our software allows the administrator to easily discover and test the global firewall policy (either a deployed policy or a planned one). Our tool uses a minimal description of the network topology and directly parses the various vendor-specific low level configuration files. It interacts with the user through a query-and-answer session, which is conducted at a much higher level of abstruction. A typical question our tool can answer is "from which machines can our DMZ be reached and with which services?" Thus, the tool complements existing vulnerability analysis tools, as it can be used before a policy is actually deployed it operates on a more understandable level of abstraction, and it deals with all the firewalls at once.
Typically, bandwidth reservation is not made for data applications. Therefore, the only way to provide minimum bandwidth guarantees to such an application is by using a fairness mechanism to regulate the access to the network and by controlling the packet loss (i.e., congestion) inside the network. There are numerous works treating fairness in ring networks, however, there are almost no such works on fairness in arbitrary topology networks. The context of this work is fairness in an arbitrary topology network, the MetaNet, which employs convergence routing, a loss-free routing technique which is a variant on deflection routing. We note that minimum bandwidth guarantee combined with loss-free routing are the desired quality-of-service (QoS) attributes for most data applications. While developing the mechanisms, we also present performance measures to assess the new access- and flow-control algorithm: i) locality and congestion-driven-only the subnetwork containing conflicting traffic streams becomes involved in the fairness regulation. Furthermore, the fairness regulation is activated only when congestion occurs. This implies that when there is no congestion, nodes can access the network immediately and freely, which is a key requirement for distributed computing. ii) Scalability-the data-structure sizes used in the algorithm are a function of the switching node degree, and use constant space control signals of two bits only (the ATM standard, for example, dedicates four bits in the header of each cell to generic flow-control). iii) Linear access time in the congested subnetwork-measured by "the maximal clique in what we call the conflict graph to which a node belongs," and a frequency which is inverse linear in this parameter (when the traffic pattern stabilizes).
In this paper we propose and evaluate new graphical password schemes that exploit features of graphical input displays to achieve better security than text-based passwords. Graphical input devices enable the user to decouple the position of inputs from the temporal order in which those inputs occur, and we show that this decoupling can be used to generate password schemes with substantially larger (memorable) password spaces. In order to evaluate the security of one of our schemes, we devise a novel way to capture a subset of the "memorable" passwords that, we believe, is itself a contribution. In this work we are primarily motivated by devices such as personal digital assistants (PDAs) that offer graphical input capabilities via a stylus, and we describe our prototype implementation of one of our password schemes on such a PDA, namely the Palm Pilot(TM).
Yoram Ofek合作论文数Department of Information and Communication Technology (DIT), University of Trento2