AT&T’s new AppCenter is an Android app store which will sell “unwrapped” HTML5 apps, promoting HTML5 as an alternative to native mobile apps. The AppCenter was launched January 9, 2012, and is available in beta form on Android devices, with plans for additional platforms in 2012. According to a January 11, 2011 article in Ars Technica, “AT&T Offers HTML5 SDK for Third-party Mobile Web App Developers”, the company has also “released a set of JavaScript APIs and a software development kit (SDK) that provide Web developers with access to certain mobile network features”.
Apple has filed two new lawsuits in Germany citing 10 Samsung smartphones and five Samsung tablets with infringing its design IP, the kind of peculiarly European intellectual property it used to get the Galaxy Tab 10.1 outlawed in Germany last year. Apparently the Düsseldorf Regional Court will hear the phone case in August and tablet case in September. The FOSS Patents blog figures Apple’s design rights assertions may make it impossible for the two companies to structure a mutually acceptable settlement and that they “may just need the courts to clarify the boundaries of Apple’s exclusive design-related rights.”
I highly recommend this book to everyone in the business of building software. Before you attempt to automate your testing, read this book! Every once in a while a book is put together that should be read by every person with a relationship to software development. This book is one of them. Everyone dreams of automating their software testing, but few make it a reality. This down to earth book is the stories of 28 teams that went for it. It includes both successes and failures. That is not something you see everyday. Many books simply provide you the success path. This book also provides you with the steps you could possibly be taking that could lead to failure helping you to change your path before fully failing.
Disappointed with your SOC in a box solution? Here are a few steps to improve your static rule based correlation solution... During these past few weeks, we have looked at several reasons why a static rule based correlation is not the "SOC in a Box", end-all be all that many thought it was. Indeed what to think about a "solution" that: Can only address a very limited set of attack scenarios Requires meticulous consideration on how to map out the few selected attack scenarios Doesn't guarantee you to catch attacks in progress even when one of the few selected scenario is taking place Obliges you to think of minute details to slightly reduce false positives Yields hundreds and thousands of basic correlation rules that need to be programmed, tuned, managed, kept up to date and constantly revisited Needs massive computing power and memory resources to run Cannot manage all of your logs or IT Data, otherwise the engine blows up in smoke
I am already an avid believer of Mobility and Tablet computing in the Enterprise, so this week I decided to think about what could be achieved within Education. For the rest of my thoughts I will use my Converged Mobile Device of choice … the iPad. There is already a student web page on the Apple website saying why the iPad is ready for college/university. It obviously states its great features, the generally available apps and novel books but I think the next step will be beyond that and will leave us asking ourselves 'Why didn't we think of that already?'
Gartner has revised its outlook downward and now expects worldwide IT spending to total $3.8 trillion in 2012, up 3.7% from 2011. The researcher previously thought spending would grow 4.6% – roughly a $100 billion more – but says “faltering global economic growth, the eurozone crisis and the impact of Thailand’s floods on hard-disk drive (HDD) production have taken their toll on the outlook for IT spending.” It figures all four major technology sectors – hardware, enterprise software, IT services and telecommunications equipment and services – will experience slower spending.
Defining "Who sees what" and "who does what" are the two important aspects of access control in any software application. "Security" is a much larger subject, but this article focuses on just the access control aspects of Security in a software application. When you build a custom application for a specific customer, the access control policies of the organization are often defined upfront as part of the requirements phase. Depending on the vertical, domain and the specific organizational structure of the business, first the roles are defined. And then each role is given access to a set of screens, forms, pages and reports. What role A sees might be different from what role B sees. What role A can do could be different from what role B is allowed to do. Of course, certain areas in the application can be accessed by multiple roles. While building software products (used by several customers), the roles are often generalized and predefined. The various access control policies of the product are often hard coded in to the roles. The customer will be able to assign one or more roles to their users.
Between unimaginative products, competition from tablets and smartphones, the flood-created squeeze on hard drives and high prices, PC shipments dropped somewhere between 0.2% and 1.4% in the fourth quarter compared to 4Q10 according to IDC and Gartner. IDC is the more optimistic one. And remember Q4 is usually strong because of the holidays. HP was the author of its own peculiar problems. Although still the sector’s leader it shipped 14.7 million boxes in Q4, 16% fewer units than the year before because of doubts over the fate of its PC unit.
The world is getting smarter – more instrumented, interconnected and intelligent. At the same time, IT leaders are faced with the challenge to do more and support aggressive business growth, while reducing costs. Business leaders feel pressure to initiate new revenue streams, drive faster time-to-market for new services and meet changing customer expectations. With cloud computing, business and IT can create and deliver value in fundamentally new ways by removing IT boundaries, improving speed-to-market, and empowering users to drive innovation like never before. Next-generation cloud platforms and new “as-a-service” industry solutions are emerging to help shape this innovation. In his general session at the 9th International Cloud Expo, Rich Lechner, Vice President Energy & Environment at IBM, discussed the latest in these cloud technologies and how they enable companies to truly re-think IT and re-invent business.
AT&T has joined OpenStack. It’s the first US telecom service provider to sign up for the free Rackspace-NASA-spawned open source cloud initiative. AT&T CTO John Donovan said AT&T has been participating in OpenStack for more than a year and has contributed a blueprint for a potential new function in OpenStack focused on transactional task management. Donovan said the OpenStack IaaS is housed on dedicated infrastructure in AT&T data centers in Dallas, San Diego and Secaucus, New Jersey, to start. The company means to more than double the number of centers with open source capabilities this year. Evidently AT&T is using OpenStack – or elements of it – underneath a new commodity-style cloud for developers called Cloud Architect that’s presumably intended to compete with Amazon Web Services et al.
Oracle can’t appeal the judge’s decision to cut the $1.3 billion jury award in its suit against SAP to a mere $272 million unless it rejects the $272 million, the judge told Oracle last Friday. Oracle is trying to avoid the other option the judge gave it, which is a new trial. If Oracle rejects the $272 million, there would be a new trial and then it could appeal the judge’s decision. The judge contends Oracle only proved actual damages of $272 million when SAP’s now defunct TomorrowNow third-party maintenance subsidiary illegally downloaded reams of Oracle software. Reuters, which reported the decision, said the order did not indicate if Oracle could accept the $272 million and then appeal, but an IP lawyer the wire service talked to said probably not. If SAP appealed to the size of the judge’s award Oracle might be able to try for the $1.3 billion.
You remember that "False Sense of Security," the feeling that you are secure, but in fact you're not...? Attackers know that an attack is a process, it is not an event. And they use this - and they use time - to their advantage. They use time scales that static rule-based correlation simply cannot cope with. If you want to correlate disparate events, you need to keep state information on these events, and of course the longer you need to keep the state, the more expensive it becomes, expensive in RAM, CPU, storage etc etc., to the point where it is not affordable anymore. Did you know that many/most static rule-based correlation engines cannot keep state for more than a few minutes? This means for example that many correlation engines will not even be able to address the Scenario 1 - Identity Theft - discussed above.
Last week Oracle’s long-simmering Java infringement suit against Google, already postponed from Halloween, was scheduled to go to trial “on or after March 19.” On Thursday the court entered another order saying it won’t set a trial date any time soon and suggesting that given the demands on its calendar it could be 2013 before the case gets heard. Presiding Judge William Alsup, who figures, speaking “from experience,” that the trial will take two months, also said in his order that “The court will not set a trial date until Oracle adopts a proper damages methodology, even assuming a third try is allowed (or unless Oracle waives damages beyond those already allowed to go to the jury). For this ‘delay,’ Oracle has no one to blame but itself, given that twice now it has advanced improper methodologies obviously calculated to reach stratospheric numbers.”
Fabric Engine, a software engineering company focused on bringing multi-threaded, compiled performance to web applications, has announced that its Fabric Engine server technology now supports Node.js, boosting its computational performance more than 25X. Fabric Engine has published the results of its performance benchmark online (http://fabric-engine.com/2011/11/server-performance-benchmarks/), and will be showcasing its support for Node.js at NodeJam this January. Fabric Engine is designed to tap into the power of modern, multi-core processing to bring true, multi-threaded, compiled performance to web applications. As web applications grow, they start to run into performance and scalability problems that dynamic languages like JavaScript are not well-suited to solve. Consequently, these applications need to be re-architected using compiled languages like C++, introducing significant costs to the developer. Fabric Engine gives the same performance as C++, yet retains the ease of use and speed of iteration of dynamic languages.
During the last month my colleagues and I were immersing into the world of modern JavaScript frameworks. We didn’t start from scratch though. My business partners spent the first 5 years of this century porting PowerBuilder, a used-to-be-popular client server tool, to a JavaScript framework. That product was called XMLSP and you can still find its 5-year old version online. The word AJAX was not even invented back then. In 2006, a killer UI framework Adobe Flex 2 was released and we started using it. It was clearly better than any AJAX offering, and I was not shy in publishing blogs and articles explaining its superiority to any AJAX solution available at the time. Flex remains a great solution for developing UI for the enterprise Web applications, and our company,Farata Systems, is committed to support any client who decides to hire us for any Flex/AIR Web/Desktop/Mobile project. But the world of software and hardware is hugely different in 2012 comparing to 2006. And we are stepping into the same JavaScript river once again.
Each application developer faces the problem of logging usage information. On the one hand, the more logging that’s done the easier it is to detect and locate the source of problems. On the other hand, large volume logging might impair an application’s performance. This problem is typically solved by defining various log levels dependent on a program’s maturity. For example, a program in developmental stages would have a higher logging requirements; logging requirements would be relatively lower in the production phase. If an application requires a lot of logging for audit purposes, then special measures are required to protect performance. This article provides a possible solution for this problem by using Spring asynchronous support. Logging is used extensively to help find problems within applications. A developer who finds a problem can investigate it by enabling debug logging. He may then reproduce the problem, or create additional logging if needed. Programmers usually require extensive logging to locate problems.
Oracle Fusion Applications Provisioning is the überinstaller for OFA. Based on your input and its knowledge about OFA dependencies it will prepare and deploy OFA components to appropriate target locations. Provisioning Plan is driving the installation process. It is created when you select this option from Provisioning Wizard. Here you pick components Provisioning Plan is created for - we chose Oracle Financials module. Wizard will show you topology summary and details about the chosen configuration. Here we provide Access Manager details.
Performance is one word that is used to describe multiple scenarios when talking about application performance. When someone says I need a High Performance Application, it might mean any/all of the following: Low web latency application ( meaning low page loading times) Application that can serve ever increasing number of users (scalability) Application that does not go down (either highly available or continuously available) For each of the above, as an architect you need to dig deeper to find out what the user is asking for. With the advent of cloud, every CIO is looking to build applications that meet all of the above scenarios. With the advent of elastic compute, one tends to think that by throwing hardware to the application, we may be able to achieve all of the above objectives. The patterns employed to achieve the above scenarios at times are different and it is important to find the right approach to the solution that meets the above objectives. We will examine some of the common patterns that can help us to achieve the objectives
Dell has reorganized again, which is apparently either the cause or the result of Paul Bell, president of its Public & Large Enterprise unit, turning in his notice. The company says Bell “recently announced his intention to retire from Dell effective March 30” and that with his departure it’s “accelerating the evolution of its go-to-market organization, further simplifying the company’s customer-facing activities.” That means it’s going to move all of its customer business segments, Public, Large Enterprise, Small and Medium Business and Consumer, together under Steve Felice as president and chief commercial officer and have a single sales and marketing organization again. Felice, 53, has been running Dell’s consumer and small and mid-sized business segments.
Oracle HTTP server is one of Oracle Fusion Middleware for Oracle Identity Management components. Oracle HTTP Server provides HTTP listener services for Oracle WebLogic. Once you download software ( it is a part of Oracle Fusion Middleware 11g Media Pack; HTTP server resides in Oracle Fusion Middleware Web Tier Utilities 11g DVD ), unzip it and run installer you will be presented with welcome screen.
Oracle Forms and Reports is one of Fusion Middleware components needed for OFA installation. Forms is a GUI tool used to develop, generate and run database front end applications. Reports is a GUI tool used to develop, generate and run database reports. For the purposes of Oracle Fusion Applications installation we will secure Forms and Reports with Identity Management. Once you download and unzip Oracle Forms and Reports software and run installer you will be presented with the welcome screen.
Samsung’s bid to get a preliminary injunction outlawing the sale of Apple’s iPhone 4S in Italy has failed, according to ANSA, the Italian wire service. The decision is Samsung’s third failure in Europe. Last month a similar attempt was shot down by a French court and before that Holland said no. Apple, on the other hand, is appealing the rejection of its bid to get four Samsung widgets outlawed in the United States to the Federal Circuit Court of Appeals and the temporary injunctions it managed to get against Samsung in Germany, the Netherlands and Australia are being reviewed. If the courts find they shouldn’t have been granted Apple could wind up owing its nemesis money.
Today I noticed two very separate articles, though to me they are both interrelated and on a subject that I feel very strongly about, Tablet Devices and Mobile App Development. It is no secret that I am a total iOS convert in my personal life, living with my iPhone and iPad, but as a businessman and technologist I am just as much of a convert to Enterprise Mobility and Development, so much so that I have predicted that 2012 will be the year of the Mobile Developer, Enterprise Business App and Tablet Device… more than 2011.
Compounding the combinatory explosion in the number of static-based correlation rules, it is impossible to correlate 100% of all your logs, it is just too expensive and not practical. Read on... A correlation engine works really hard, even when dealing with a limited set of scenarios: - Each scenario requires lots of rules and exceptions, and most of these rules need to be interpreted further as dozen, if not hundred of simple checks and tests. For example, you may want to flag loops with a simple rule such as "IP Origin" = "IP Destination". If you have 1 000 logs this means that for each log you need to do 1 000 tests. Imagine having a million logs, a trillion logs, which is not uncommon on a medium sized infrastructure over a couple days.
Oracle Identity Management is a component of Oracle Fusion Middleware and part of the Oracle Fusion Applications infrastructure. Its purpose is to manage user identities across the enterprise. We are going to install Oracle Internet Directory 11g (OID), Oracle Virtual Directory 11g (OVD), Oracle Identity Manager 11g (OIM), Oracle Access Manager 11g (OAM) as well as two instances of Oracle Database (11.2.0.2) - one for the Identity Store and the other for the Policy Store. SOA Suite is first component to be installed since Identity Manager requires it. Some SOA Suite components (Oracle Identity Manager, Oracle Access Manager ) require schemas to be created in middleware repository database. We created separate database to contain Oracle Identity Manager schemas.