Daily Tech Digest - December 17, 2017

With 2018 upon us, the worlds of both business and personal software are ramping up to make the next few years something of an artificial intelligence arms race. On the consumer side of things, machine learning and AI make our lives easier in small ways. Case in point: many of us now have a smart speaker like an Amazon Echo or Google Home sitting on our countertops. While these kinds of AI applications are helpful and entertaining, their self-learning capabilities are limited, to say the least. In the world of business, there’s more immediate potential for self-learning software. “We are drowning in information,” says Vita Vasylyeva of Artsyl Technologies. “The biggest bottlenecks in any business process involve the handling of documents and manual input of data from those documents. At the heart of those bottlenecks is the transformation of unstructured content into structured data.”


A Review on Business Intelligence and Big Data

Technological advancements of IT have led to storing more data at lower cost and drastically  increased transmitting rates. Parallel computing has increased computing power as well by processing multiple cores simultaneously. It is hard to find any device that doesn’t generate data like sensors, plane engines, online transactions, emails, videos, audios, images, click streams, logs, posts, search queries, health records, social networking interactions, science data, and mobile phones. All of these and their applications have begun to generate huge volume data at high velocity and variety which is impossible to store and process with classical technologies and programming paradigms. This kind of data is called big data. International Data Corporation (IDC) reports that digital universe will continuously expand, be complex and interesting. The volume of data is expected to be 8 ZB by 2020. Data generation speed is also increasing exponentially. 


Deep learning is currently one of the main focuses of machine learning. It has led to many speculative comments about A.I. and its possible impact on the future. Although deep learning garners much attention, people fail to realize that deep learning has inherent restrictions which limit its application and effectiveness in many industries and fields. Deep learning requires human expertise and significant time to design and train. Deep learning algorithms lack interpretability as they are not able to explain their decision-making. In mission critical applications, such as medical diagnosis, airlines, and security, people must feel confident in the reasoning behind the program, and it is difficult to trust systems that does not explain or justify their conclusions. Another limitation is minimal changes can induce big errors. For example, in vision classification, slightly changing an image which was once correctly classified in a way that is imperceptible to the human eye can cause a deep neural network to label the image as something else entirely. 


The day when the computer becomes a data scientist

The data scientist usually starts every project by digging into the data (using charts, scatter plots, histograms and other visual tools), then cleaning it by dropping irrelevant variables (and adding missing data) – AKA preprocessing. The next step is choosing the right classifier / regression method followed by picking the right features in the data in order to get the most accurate prediction. In between, the data scientist tests different combinations of classifiers parameters for obtaining the most optimal and efficient prediction mechanism. All the mentioned steps and methods demand high analytical and comprehension skills from the person who apply them, and right now, it doesn't look like a computer can do all of these steps better than a human being. Nevertheless, the computer plays an important role in many parts of the data scientist's projects. A good example for this - is the Cross Validation in the Model Selection module where an algorithm 'finds' best classifier or the best classifier parameters. 


Why telcos will soon be betting on Artificial Intelligence to build their networks
“As more reliable and affordable bandwidth is enabled, it unleashes a plethora of opportunities that can traverse over telecom networks. So, a convergence at network level becomes possible. This is then value enhanced by adding dynamism and intelligence in to the systems through AI which makes the solution intuitive, proactive as well as reactive to the situations,” said Faisal Kawoosa, Lead Analyst, CyberMedia Research. ... One may not see the telecom the way we look at it presently, meaning a different set of revenue streams as well. “AI is expected to have an impact in a multitude of areas – the most important being traffic classification, anomaly detection and prediction, resource utilization and network optimization, along with network orchestration. Further, it will also assist the mobile devices with virtual assistants and bots,” said Arjun Vishwanathan, Associate Director, Emerging Technologies, IDC


2018: The Year Central Banks Begin Buying Cryptocurrency

In 2018, G7 central banks will witness bitcoin and other cryptocurrencies becoming the biggest international currency by market capitalization. This event, together with the global nature of cryptocurrencies with 24/7 trading access, will make it intuitive to own cryptocurrencies as they become a de-facto investment as part of a central banks investment tranche. Cryptocurrencies will also fulfil a new requirement as digital gold. Furthermore, foreign reserves are used to facilitate international trade. This means holding reserves in a trading partner's currency makes trading simpler. In 2018, cryptocurrencies like bitcoin will be utilized for international trade on a moderate basis because the high returns as an investment will encourage a ‘hold’ strategy for G7 countries. Foreign reserves are also used as monetary policy tool. Central banks may pursue the option to sell and buy foreign exchange currencies to control exchange rates.


Bluetooth 5 – the Biggest Breakthrough in the IoT in 20 Years

bluetooth 5 with IoT
The capabilities of the Bluetooth 5 were nothing short of remarkable. The new devices were twice as fast, had four times the range and over nine times the broadband messaging capacity as their predecessor, the Bluetooth 4. These new devices are leading to new IoT applications that we didn’t envision a year ago. Keyinsight predicted that the new IoT devices would be used in every industry from agriculture to transportation. These predictions will finally come to fruition due to advances in Bluetooth technology. ... When Bluetooth first hit the market, it was one of the first IoT devices available. People could use their Bluetooth to connect to automobile CD players, radios and other devices. It was an unprecedented level of connectivity between previously segregated devices. It was only the first major breakthrough with the IoT, but it wouldn’t be the last. Nearly 20 years later, Bluetooth is still a pioneer in the IoT.


The lesson behind 2017’s biggest enterprise security story


For one, security teams are overwhelmed. The average security team typically examines less than 5 percent of the alerts flowing into them every day (and in many cases, much less than that). Ironically, some attempts to improve this efficacy may backfire. Automation is clearly required to help security teams prioritize their work and defend their environments, but many systems prioritize alerts based on measures of the severity and impact of the threat itself rather than measuring its potential impact within the context of the business. In other words, while a human analyst may understand that a “simple” exploit of an unpatched vulnerability on a server that houses your crown jewels is a higher priority than a sophisticated zero-day attack targeting the machine housing the cafeteria menu, automated tools may mistakenly believe otherwise.


Why do Decision Trees Work?

Decision trees are a type of recursive partitioning algorithm. Decision trees are built up of two types of nodes: decision nodes, and leaves. The decision tree starts with a node called the root. If the root is a leaf then the decision tree is trivial or degenerate and the same classification is made for all data. For decision nodes we examine a single variable and move to another node based on the outcome of a comparison. The recursion is repeated until we reach a leaf node. At a leaf node we return the majority value of training data routed to the leaf node as a classification decision, or return the mean-value of outcomes as a regression estimate. ... For true conditions we move down and left, for falsified conditions we move down and right. The leaves are labeled with the predicted probability of account cancellation. The tree is orderly and all nodes are in estimated probability units because Practical Data Science with R used a technique similar to y-aware scaling


Q&A With Eberhard Wolff On the Book “A Practical Guide to Continuous Delivery”

The obvious and original goal of CD is to improve time to market for new features and thereby to get better business results. But there is more to CD: Constantly testing the software with reproducible results and a high degree of automation improves the quality of the software. Deploying more often and automating deployment decreases the risk of the deployment. This has a positive impact on software development and IT. These benefits might be reason enough to implement CD. How far you can go with CD depends on the buy-in from business as well as software development, operations, and QA. With limited buy-in from business you won’t be able to get better time-to-market. With limited buy-in from Ops you won’t be able to extend the automated pipeline to go directly into production. Still even a limited implementation of CD will be worth it and of course it can always grow. The early adopters were looking for a more agile way to work.



Quote for the day:


“If you’re not a risk taker, you should get the hell out of business.” -- Ray Kroc


Daily Tech Digest - December 16, 2017

Will augmented reality make lying obsolete?

eyedetect
The future of lie detection is A.I. A.I. can take various “signals,” such as eye movements, facial gestures, body movements, voice intonations and others, to estimate the truthfulness of a person’s statements. In fact, lie detection is just one of the many uses for emotion or mood detection generally. When A.I. can tell when a person is happy or sad or mad or stressed, it can generally detect changes during conversation and figure out that some of those changes are caused by lie-induced mental activity or stress. Because lie-detection A.I. is currently being developed by numerous companies, universities and governments, it’s inevitable that the capability will become available broadly and inexpensively to businesses and consumers over the next two years. In fact, lie-detection A.I. is already on the market. ... EyeDetect is already in use for hiring and bank fraud, as well as by police departments as an alternative to the polygraph.


Designing human-shaped artificial intelligence

artificial intelligence
Designing for conversational interfaces involves a whole host of new challenges, including personality design. Artificial intelligence with human-like personality makes for more natural interaction, so the approach to personality design must continually be developed to explore how brands translate into AI personalities. ... In addition to building tools, it is important to supplement this with informed conversations about the needs and opportunities which AI brings to practice. The best products, services, systems and spaces are those that are designed to help real people live easier, smarter, enjoyable and more meaningful lives. It is entirely possible to create a human-shaped world where everything is designed to meet real human needs. Getting there requires all contributing innovators to answer complex problems with simple, focused solutions. When designing human-shaped AI, as with any design process, it is easy to over-complicate.



Making Regulation Machine Readable

fintech
Much progress has been made to automate these processes, but offering international services remains a challenge as each country has its own complex regulatory requirements. To offer scalable solutions across multiple markets, regulatory advice as provided by legal and compliance experts today, must also be digitized. I believe an automated solution, a “digital compliance officer”, is the key to enabling digital services such as Robo Advisors. Therefore, by applying machine-learning techniques, we today cluster regulatory requirements country by country and transform them into digital rule-sets. These rule-sets are always up-to-date and verified, allow for a transparent audit trail on past and current rules, and provide our clients with a sophisticated regulatory risk management framework. To ensure consistency, applications such as eBanking, CRM and Robo Advisors communicate via APIs with our solution.


8 Steps for Building an IT Security Career Path Program

Conduct a Needs Assessment

Before a career path can be chartered for current or prospective employees, you first need to know where you currently stand with your cybersecurity workforce.

'Define the type of work you want done, so you can create a career path and path for learning,' says Andrew Smallwood, cyber human capital specialist with Booz Allen Hamilton.

Jason Hite, founder of Daoine Centric and industry co-chair for the National Initiative on Cybersecurity Education (NICE) and a member of the NICE workforce sub-group, agrees. 

He notes that the ISO/IEC 27001 is one resource organizations can use to develop their security posture. It's an international standard that government agencies and companies use to manage the security of their assets.

Image Source: Shahril KHMD via Shutterstock
Cybersecurity professionals are in steep demand, given the projected shortfall of 1.8 million workers by 2022. ...A majority of companies don't provide such a program for their cybersecurity team, according to IT security career experts. But it's a key tool to keep in-house security talent fulfilled and challenged in their jobs, and to help recruit additional talent. "The number one reason people leave their jobs today is their company doesn't take security seriously. What this means is that they don't have a plan, which includes a career path plan too," says Deidre Diamond, founder and CEO of Cyber Security Networks. Career path programs show existing employees the role they currently hold within the organization and potential positions they may later ascend into through promotions or other moves, depending upon their interests, say cybersecurity career experts. It also gives prospective employees a view of their security career opportunities at an organization.


Putting Industrial Cyber Security at the Top of the CEO Agenda

Study reveals low adoption of cyber security capabilities and technology among industrial companies despite the increasing number of global industrial attacks and changing threat landscape. The study was conducted by LNS Research with strategic decision makers from industrial companies on their approach to the Industrial Internet of Things (IIoT) and use of industrial cyber security technologies and practices. Among the findings were: The study suggests that cyber security must be part of a CEO’s agenda to ensure the fast and effective long-term deployment of strategies and technologies. It also recommends three immediate actions. Honeywell’s industrial cyber security technologies and expertise addresses many of the issues identified in the LNS Research study.


How Taking the Time to Verify Your Network Could Save You Millions


More advanced technologies have given rise to modern artificial intelligence and automation tools. One emerging in the business world is related to network verification. It utilizes a series of statistics and data, performance information and predictive analytics to help business goals match reality, or more specifically to guarantee your network can handle incoming loads. It’s not just about handling a known or predicted performance requirement, however. It’s also about the fluctuation of said patterns. Frequent change happens in the world of technology, your network and the resources it needs to operate. ... Verification is often confused with testing. However, they are not synonymous. When you verify, you follow through a series of checks and balances to ensure things are as they seem and you’re prepared for the future. This is not quite the same as testing, is it? Testing checks the performance and capabilities of a system. You already know the capabilities of your network, you understand what resources it needs, and you know how it’s going to be used.


We need to talk about mathematical backdoors in encryption algorithms


Security researchers regularly set out to find implementation problems in cryptographic algorithms, but not enough effort is going towards the search for mathematical backdoors, two cryptography professors have argued. Governments and intelligence agencies strive to control and bypass or circumvent cryptographic protection of data and communications. Backdooring encryption algorithms is considered as the best way to enforce cryptographic control. In defence of cryptography, researchers have set out to validate technology that underpins the secure exchange of information and e-commerce. Eric Filiol, head of research at ESIEA, the operational cryptology and virology lab, argued that only implementation backdoors (at the protocol/implementation/management level) are generally considered. Not enough effort is being put into looking for mathematical backdoors or by-design backdoors, he maintains.


Denmark considers blockchain a new weapon in the fight for human rights

"The use of blockchain and cryptocurrency is merely some of the technologies which can give us new tools in the development cooperation toolbox," Danish Minister for Development Cooperation Ulla Tørnæs said. "It is clear that if we are to succeed in relation to the sustainable development goals we need digital and technological solutions and some of these we do not know of, but we will help find them." A report published by the ministry, alongside think tank Sustainia and blockchain currency platform Coinify, investigates how blockchain technology might solve problems in providing development aid, noting that by using cryptocurrency, money can be transferred faster and safer, and without a middleman or fees. In addition, contracts and other legal papers can be digitalised to combat corruption and ensure a more effective development aid and better protection of the rights of marginalised groups, the report, Hack the Future of Development Aid, explains.


The AI mindset: designing the workforce of the future

7 artificial intelligence
The AI mindset prioritizes imagination and creativity over tasks and execution. If we are going to reinvent half of the jobs that are out there, what we are looking at in the next decade is a talent revolution. Because AI for business is all about reinforcing decision-making and capabilities, supported by data and models, it is still ultimately about humans at the end of the day– human innovation. Organizing teams around a goal begins by looking at how you hire your individual players. It is much easier to teach skills than to teach a mindset. Nurturing talent to dig deep into our human capabilities to become better facilitators, collaborators, presenters, and persuaders–this is where innovation happens. Those who embody the AI mindset will help accelerate how AI serves businesses.


The next wave? Modular component malware against industrial control safety systems

malware cybersecurity skull crossbone
The modules used with the associated malware are specifically designed to disrupt Triconex safety controllers, which are used widely in critical infrastructure. The malware requires the key switch to be in the “PROGRAM” mode in order to deliver its payload. Among others, the reported malware has the capability to scan and map the industrial control system environment to provide reconnaissance and issue commands directly to Tricon safety controllers. A DHS statement mentioned, “This marks the first report of a safety system breach at an industrial plant by hackers, who have in recent years placed increasing attention on hacking into utilities, factories and other types of critical infrastructure. Such attacks could allow hackers to shut down safety systems in advance of attacking an industrial plant, which could prevent plants from identifying and halting destructive attacks on those facilities.”



Quote for the day:


"A good leader leads the people from above them. A great leader leads the people from within them." -- M.D. Arnold


Daily Tech Digest - December 15, 2017

Digital Disruption: 10 Ways To Survive & Thrive

Digital disruption: 10 ways to survive and thrive
Some CEOs are embarking on vision quests to help navigate digital disruption, which is marked by a shift in profitability from one prevailing business model to another. Puthiyamadam, who leads the PwC's digital services practice and oversees its experience center, recalls one recent conversation with a CEO client who attended a "digital bootcamp" in Europe. The CEO was told he must join Twitter and that his business would be disrupted in two years. Puthiyamadam quickly assured the CEO that the threats weren’t so imminent. Indeed, he regularly cautions clients against acting rashly because the wrong bets, from service ideation to technology choices, can set a business back years. "Don't believe you need to act frantically and in panic mode because your business is going to get completely overwhelmed," Puthiyamadam tells CIO.com.



DevOps in the public sector: Assessing the challenges and the benefits

“The public sector is often saddled with a significant burden of legacy systems which must be maintained and, where possible, modernised,” says Jason Rolles, CEO of software development monitoring software supplier BlueOptima. This means making use of open source development tools, such as Git and Jenkins, but also having the right IT environment to reap the benefits of these DevOps tools. It is inevitable that legacy systems will slow down a DevOps approach which is meant to bring an organisation both flexibility and speed. This shift away from incumbent providers and legacy infrastructure is to do with finance too. But, without the budget needed to move away from legacy technologies, recruiting DevOps personnel gets even harder, and this becomes a vicious cycle that encourages departments to remain the same.


5 tips for better NGINX security that any admin can handle

nginxhero.jpg
NGINX continues to rise in popularity. According to the October, 2017 Netcraft stats, it has nearly caught up with Apache—meaning more and more people are making use of this lightweight, lightning fast web server. That also means more and more NGINX deployments need to be secured. To that end, there are so many possibilities. If you're new to NGINX, you will want to make sure to deploy the server in such a way that your foundation is safe. I will walk through five ways to gain better security over NGINX that won't put your skills or resolve to too much of a test. ... It is possible to limit the rate NGINX will accept incoming requests. For example, say you want to limit the acceptance of incoming requests to the /wp-admin section. To achieve this, we are going to use the limit_req_zone directory and configure a shared memory zone named one and limit it to 30 requests per minute.


Cloud computing: Getting bigger but more complicated too

art-hybrid-cloud-intro-2017.jpg
The location of the company offering a cloud service is something that has come under particular scrutiny recently. For example, the UK government's National Cyber Security Centre (NCSC) warned about the use of some cloud-based antivirus products from Russian companies, but also warned more broadly about the use of cloud services within the government supply chain. "The country of origin matters. It isn't everything, and nor is it a simple matter of flags -- there are Western companies who have non-Western contributors to their supply chain, including from hostile states. But in the national security space there are some obvious risks around foreign ownership," NCSC CEO Ciaran Martin wrote in a letter to civil service chiefs. The NCSC noted that government departments might not even be aware they are using cloud-based services: "It's easy to overlook the nature of these cloud interactions, and the security implications. 


Employers And Employees Need To Step Up On Cybersecurity

Even with the clear need for IT and network security experts, kununu found that job security ranked lowest for employees. Due to management changes or layoffs and the lack of a clear plan in place, internal organization was at an all-time low. This was leading to bad morale and disaffected employees can always be equated with company security vulnerability Within the reviews, employees even shared that their companies were not up to par in terms of the technology and were using antiquated kit, offering hackers a free pass into companies’ most sensitive data. Based in Vienna and leading the European market, kununu launched in the US last year in a joint venture with Monster and has already collected more than half a million reviews on its website. Its reviews are broken down into 18 key dimensions of workplace satisfaction to provide job seekers with workplace insights that matter in order to to make sound work-life decisions


Could blockchains rattle ECM?

Blockchains are distributed, crowd-validated ledgers which use internet-connected computers and open source software all over the world to verify transactions. One of their major benefits in financial transactions is their immunity to tampering, thanks to the built-in consensus mechanism. In theory, this could also make blockchain a secure, verifiable and permanent solution for exchanges of any kind – for managing records, for instance. Sweden’s land registry authority is currently exploring blockchains’ potential as a mechanism for recording property deals. In this context, the blockchain would confirm and save each step in the contract process between buyers and sellers, while making each deal’s information transparent to all parties such as banks and local governments. But how far could this go, and what does it mean for ECM as we know it? To assess the potential and any limitations we must consider what sets blockchains’ approach apart.


Figure 1
Enterprises that wish to deliver disruptive innovation must understand their own strategy and objectives, their current operational environment and challenges, and their external environment. They can begin by identifying opportunity areas and key markets. Once a consensus is reached, they can identify priority market segments. This may lead to redefining market segments and segmentation criteria. At this point, they should analyze the industry structure—segment clients, suppliers, potential new entrants, substitution products—and then identify what makes each player powerful, using strategic tools. For example, “The Five Competitive Forces That Shape Strategy”9 shows that suppliers boasting strong concentration, high switching costs, genuine differentiation, unique intellectual property (IP) and strong value for clients will command higher prices than industry incumbents. 


20 Ways To Rekindle Your Passion For IT

20 ways to rekindle your passion for IT
In March 2017, Zucker left the financial services firm and launched a new career providing training and advisory services in project management, agile development and leadership. "The change has been wonderful," he declares. "I'm working harder than before, but I'm passionate and enthusiastic about what I am doing." Zucker is hardly the only IT leader to watch his early enthusiasm spill into a drain of frustration, boredom and ennui. A 2016 Stress and Pride survey, sponsored by IT talent management and solutions company TEK Systems, found that a sizeable number of senior-level IT professionals are dissatisfied with their jobs. In fact, 24 percent of respondents stated that while they were proud they had chosen IT as a career, they were not proud of their current role, assignments and responsibilities. Worse yet, a discouraging 16 percent agreed that if they had to do it all over again, they wouldn't go into IT.



An Effective Cyber Hygiene Program Can Save A Business


Most small businesses have overarching cybersecurity plans that establish antivirus programs, firewalls, and other defenses to thwart cyberattacks. However, rarely do these plans consider individual behavior, which is why more than half of all cyberattacks aim for American small businesses. In addition to these cybersecurity measures, businesses need to consider cyber hygiene. Cyber hygiene, also called security hygiene, is general behavior that keeps individuals safe from cyberattack. Unlike cybersecurity, which pertains to an organization’s largescale efforts, hygiene consists of an individual’s responsibilities and actions. For example, an IT department might build and monitor firewalls and intrusion detection systems, but if individual employees fail to generate strong passwords, install software updates, or run regular malware scans, then a business remains insecure.


BlueBorne Attack Highlights Flaws in Linux, IoT Security

Researchers at IoT security firm Armis earlier this year discovered Blueborne, a new group of airborne attacks. The vulnerabilities let attackers take full control of any device running Linux, or OS derived from Linux, putting the majority of IoT devices at risk of exposure. The researchers discussed and demonstrated their latest findings at Black Hat Europe 2017, held last week in London. Vulnerabilities in the Bluetooth stack have been overlooked for the past decade, they explained. Bluetooth, often perceived as peripheral, could benefit attackers if they successfully break into a high-privilege device. As the researchers demonstrated, one compromised product can spread its attack over the air to other devices within Bluetooth range. "These attacks don't require any user interaction or any authentication," said Armis head researcher Ben Seri in their presentation.



Quote for the day:


"The most common way people give up their power is by thinking they don't have any." -- Alice Walker


Daily Tech Digest - December 14, 2017

The role of Chief Data Officer (CDO) would seem to be a godsend to answer the data monetization challenge. They should be the catalyst in helping organizations to become more effective at leveraging data and analytics to power the digital transformation. However, all is not well in the world of the CDO. Many organizations appoint a CDO with an Information Technology (IT) background – the same background and experience as the Chief Information Officer (CIO). The organization then ends up splitting the existing CIO role between the current CIO and the CDO; giving the CDO the tasks associated with data collection, governance, protection and access. Splitting the existing CIO role isn’t sufficient. Instead, the CDO needs a totally different charter than the CIO, and a key aspect of that charter must be around data monetization.


Microservices Solution Patterns


Microservices Architecture (MSA) is reshaping the enterprise IT ecosystem. It started as a mechanism to break the large monolithic applications into a set of independent, functionality focused applications which can be designed, developed, tested and deployed independently. The early adopters of MSA have used this pattern to implement their back-end systems or the business logic. Once they have implemented these so-called back-end systems, then came the idea of implementing the same pattern across the board. The idea of this article is to discuss the possible solution patterns which can be used in an MSA driven enterprise. ... On top of the back-end systems, there is the integration layer which interconnects heterogeneous back-end systems. Once these services are integrated, they need to be exposed as APIs to internal and external users as managed APIs through API management layer. Security and analytics will be used across all those 3 layers.


Outlook 2018 – Key Trends In The Indian Information Management Domain

Outlook 2018 – Key trends in the Indian Information Management domain
Paperwork is an integral part of doing business, but physical paper is not. In fact, reliance on paper documents results in costs, which could be eliminated or at least radically reduced by going paperless. As physical paperwork piles up, so do issues such as: a) Slower time to complete routine tasks that rely on paper as an input b) Increased risk of a security breach through lost or stolen documents c) Potential for data entry errors from manually keying information into systems d) Costs for office or offsite space to store paper documents.  ... Flexibility has become a business imperative with the upsurge of new technologies, BYOD and more employees working remotely. Keeping this in mind, CIOs will focus on compatibility - the ability to scale and transcend devices and platforms (i.e. the open network) for enhanced collaboration. Integration capabilities will be a basic requirement for any technological implementation.


Has Deep Learning Made Traditional Machine Learning Irrelevant?


It is true that many of the competitions you see on Kaggle these days contain unstructured data that lends itself to Deep Learning algorithms like CNNs and RNNs. Anthony Goldbloom, the founder and CEO of Kaggle observed that winning techniques have been divided by whether the data was structured or unstructured.  Regarding structured data competitions, Anthony says “It used to be random forest that was the big winner, but over the last six months a new algorithm called XGboost has cropped up, and it’s winning practically every competition in the structured data category.” More recently however, Anthony says the structured category has come to be dominated by what he describes as ‘hand crafted’ solutions heavy on domain knowledge and stochastic hypothesis testing. When the data is unstructured, it’s definitely CNNs and RNNs that are carrying the day.


Will 2018 be the big year for machine learning?

"We have reached the tipping point where adoption of machine learning in the enterprise is poised to accelerate, and will drive improved business operations, better decision making and provide enhanced or entirely new products and services," said Paul Sallomi, vice chairman of Deloitte. ML, a core element of artificial intelligence, will progress "at a phenomenal pace," according to the study. "As impressive as it is today, in 50 years' time the ML abilities of 2018 will be considered baby steps in the history of this technology," the report said. The report highlights areas that Deloitte thinks will unlock more intensive use of ML in the enterprise by making it easier, cheaper and faster. The most important key area is the growth in new semiconductor chips that will increase the use of ML, enabling applications to use less power, and at the same time become more responsive, flexible and capable.


Understanding the role of Information Rights Management


Naturally, the bigger the scale of the enterprise, the harder it’s going to be to keep IRM consistent. Many software packages and internal procedures are easy to maintain when you only have a few dozen people to worry about. The more people you add to a system, the more points of vulnerability you’ll contend with, and the less secure and less consistent your practices will become. If you want your company’s information to be safe, you need to take IRM more seriously. You should consider establishing a partnership with an IRM organization, or relying on products that give you more control over your own internal IRM. Your documents, messages, and files are the lifeblood of your organization, and all it takes is one breach to compromise your work. Don’t let it happen on your watch; invest in the right infrastructure for IRM, and don’t let it become a secondary priority.


10 data scientist interview questions job seekers can expect

istock-501221160.jpg
"To assess if a candidate can be successful as a data scientist, I'm looking for a few things: baseline knowledge of the fundamentals, a capacity to think creatively and scientifically about real-world problems, exceptional communication about highly technical topics, and constant curiosity," said Kevin Safford, senior director of engineering at Umbel. Demonstrating that you have a strong understanding of the business at hand and how data can be used to reach business goals will also set you apart. "In addition to many technical questions—knowing your algorithms, knowing your math—a great data scientist must know the business and be able to bring strong ideas to the table," said Rick Saporta, head of data science at Vydia. "When hiring, I would rather have one creative data scientist who has a strong understanding of our business, than a whole team of machine learning experts who will be in a constant 'R&D' mode."


An Introduction to Anti-Patterns - Preventing Software Design Anomalies


The common symptoms of islands of implementation are an incorrect use of technology standards, usability and interoperability issues, excessive cost and time escalations due to changing business needs. The root cause for this is typically around not having enterprise level standards, organizational structures leading to poor communications, inappropriate trained resources deployed in projects. But these can also occur during corporate mergers, acquisitions or due to vendor-lock ins. ... The root causes can be due to lack of architectural vision, technological disruptions, tight coupling, insufficient use of metadata, lack of abstraction layer etc. Use of component architectures that provides flexible substitutions of software modules due to fast-changing business/technology landscapes can solve this issue.


Is a Good Offense the Best Defense Against Hackers?

First there’s the issue of "attribution." How do you correctly identify your attacker? It’s not as easy as it sounds. What if an attack comes from a botnet? Not one computer, but thousands or millions spread over the globe. Owners of botnet computers may not know they’re contributing to an attack. If your attacker is somewhere in the cloud, good luck finding her. Are you going to strike back against your cloud provider? They’re potentially innocent middlemen. Second, ACDC wouldn’t allow striking back against distributed denial-of-service (DDoS) attacks, for example, a common attack. DDoS attacks don’t involve unauthorized access. And who are you going to blame? Typical DDoS attacks come from devices that are part of the Internet of Things (IoT). Say Grandma’s digital picture frame routed requests in a DDoS attack. Are you going to hack back against Grandma?


What Should Software Engineers Know about GDPR?


GDPR is only interested in personally identifiable information (PII). GDPR does not apply to data that is not attached to a person, such as product or accounting information. You might still classify it as sensitive and might still want to protect it, but GDPR considers it non-PII data and ignores those situations. GDPR identifies two classes of PII data. There is data that can be used to uniquely identify a person like social-security number, e-mail address, or anything directly connected to these identifiers such as purchase history. Then there is extra-sensitive data such as medical/health information, religion, sexual orientation, or any information on/collected from a minor. Do note that according to GDPR, combinations of information that may not be unique in isolation can potentially identify an Individual. So PII also includes identities that may be deduced from values like postcode, travel, or multiple locations such as places of purchase.



Quote for the day:


"Learn from the mistakes of others. You can never live long enough to make them all yourself." ― Groucho Marx


Daily Tech Digest - December 13, 2017

Cyber security skills shortage can be addressed, says (ISC)2


McCumber, who has been working in information security in military, national security and civilian roles for the past 30 years, argues that in the light of the fact that there are jobs for people coming out of trade schools, there is no reason that aspects of cyber security cannot be turned into trades. “By treating cyber security as a trade, it will enable school leavers to get some basic skills without having to do a four-year course and to provide valuable services in well-paid jobs in the cyber security field,” he said. “There are a lot of productive jobs in the cyber security field that do not need a four-year degree.” ... “We work with industry to ensure we are training people to meet industry’s needs, and government that wants to drive down unemployment rates, and provide transportable certifications that are recognised by government, industry and academia,” he said.



HP Spectre 13 review: This stylish ultrabook conceals real power

HP Spectre Laptop 13 af0xx
Whether open or closed, the Spectre 13’s elegance shines through. It’s a beautifully architected notebook PC, with metallic accents that complement the understated white of the chassis. (Normally, the Spectre 13 ships in black; the Ceramic White option our test machine included is an extra $10—and worth it.) Would I have chosen a series of circular holes to replace the hexagonal slits of the fan grille? Maybe. A narrow power button to one side also feels a bit out of place. But these are just nitpicks. ... At 2.4 pounds, the Spectre 13 is light, yet solidly constructed. Many aspects reminded me, though of a tablet: its weight; the power-efficient, 1080p display; and the pair of silver hinges that conceal the I/O and electric connections, slightly lifting the display above the keyboard. HP also includes a pleather laptop sleeve to protect the Spectre Laptop from nicks and scratches while in your bag.


Programmers and developers more important to companies than IT managers

istock-670517478.jpg
"IT is really going to have to shift to more of a partner to the business, and making sure they are in lockstep with what the business goals are," Hayman said. ... Decentralization makes it challenging for IT and the business to align, Hayman said. For successful digital transformation projects, both parties need to be at the table for important conversations about how technology can help realize goals, rather than IT waiting for direction from the business. "Digital transformation is going to give organizations this unique opportunity to use technology as that strategic asset for the whole enterprise," Hayman said. "Those capable IT teams that can support it are really going to help separate and differentiate organizations from the rest of their competition. That's going to mean identifying areas to increase efficiency, and add greater value to the technology."


Cyber attack surface facts, figures and statistics for 2017 to 2022

Cyber attack surface grows immensely, raises security concerns
The far corners of the Deep Web — known as the Dark Web — is intentionally hidden and used to conceal and promote heinous criminal activities. Some estimates put the size of the Deep Web (which is not indexed or accessible by search engines) at as much as 5,000 times larger than the surface web and growing at a rate that defies quantification, according to one report. ABI has forecasted that more than 20 million connected cars will ship with built-in software-based security technology by 2020 — and Spanish telecom provider Telefonica states by 2020, 90 percent of cars will be online, compared with just 2 percent in 2012. Hundreds of thousands — and possibly millions — of people can be haced now via their wirelessly connected and digitally monitored implantable medical devices (IMDs) — which include cardioverter defibrillators (ICD), pacemakers, deep brain neurostimulators, insulin pumps, ear tubes and more. Check out over 300+ Cybersecurity statistics & Trends here.


GDPR and the human element of personal data protection

Finding the precise location of data defined as ‘personal’ under GDPR from among the thousands of tables and columns (or fields) in complex and customized packaged systems, represents a significant challenge. Traditional tools and methods, such as searching for documentation, using templates and reference models or employing external consultants, do not address the challenge in an effective and timely fashion. Safyr offers an interesting approach - it interfaces with all the most popular ERP and CRM solutions in order to speed up that discovery process. Speed and accuracy here are vital for several reasons - obviously ‘bad’ data discovery initially means that risk assessments will be skewed, and even worse it may cause a loss of focus, so that less critical issues are fixed first, rather than the real high risk issues. These issues are the major benefit of using a discovery tool, rather than attempting hand cranked scripted procedures.


A robotic path lined with cybersecurity bumps

robot
The robot controller is a complex device composed of multiple interconnected subsystems and computer systems. A controller can work in automatic mode – typically for regular operation of the robot; and in manual mode, in which the robot performs movements according to specific inputs fed by the operator.  Under this attack, the cybercriminal changes the setting of the control system so the robot moves unexpectedly or inaccurately. This type of attack could lead to production of defective or modified products, subsequently resulting in massive recalls. The first time a robot is connected to a controller, the sensing equipment must be calibrated. The controller uses the calibration data to compensate for known measurement errors. Manipulation on the calibration parameters can cause the servo motor to move erratically or unexpectedly. If an attack is launched when a robot is moving, the controller can detect it and engage stopping procedures.


A Pragmatic Assessment Of Disruptive Potential In Financial Services

Fintechs have seized the initiative – defining the direction, shape and pace of innovation across almost every subsector of financial services – and have succeeded as both stand‐alone businesses and crucial parts of financial value chains Fintechs have reshaped customer expectations, setting new and higher bars for user experience. Through innovations like rapid loan adjudication fintechs have shown that the customer experience bar set by large technology firms, such as Apple and Google, can be met in financial services Customer willingness to switch away from incumbents has been overestimated. Customer switching costs are high, and new innovations are often not sufficiently material to warrant the shift to a new provider, especially as incumbents adapt* Fintechs have struggled to create new infrastructure and establish new financial services ecosystems, such as alternative payment rails or alternative capital markets.


AIG launches new cyber threat analysis to gauge companies' risks

AIG.N
AIG’s underwriters have been using the computerized analysis since November, which combines information from a new insurance application designed for the process and data about current cyber threats to generate scores on various related factors, said Tracie Grella, AIG’s global head of Cyber Risk Insurance, in an interview. The analysis scores companies on the degree to which a cyber attack may affect their businesses and the potential costs of various cyber incidents, among other issues, according to a sample report seen by Reuters. Cyber coverage is a mounting concern worldwide as hackers increasingly target companies’ technology systems. Insurers are also struggling to estimate their potential exposure as cyber risks and interest in coverage increase.


Cloud-to-cloud backup: What it is and why you need it


In small-scale scenarios, users can copy files from, for example, Office 365 and G Suite to a local volume, or if security rules permit, an external drive. But this is a manual process that might not be reliable, and will struggle to scale. For larger files and larger applications, this is rarely practical. Enterprises using infrastructure-as-a-service (IaaS) or SaaS applications can use application programming interfaces (APIs) or third-party software to back up to local servers, network-attached storage (NAS) equipment or their own datacentre. But backing up cloud services to local storage is a step backwards. Instead of taking advantage of the cloud, it forces companies to retain on-site infrastructure, increases costs and limits flexibility. Enterprises that back up software-as-a-service applications will have the reassurance that they have copies of their data, but they will not be able to replicate or run the SaaS environment in-house.


Top 5 open source tools for MySQL administrators

Top 5 open source tools for MySQL administrators
For database administrators (DBAs), keeping databases running at peak performance can be a little like spinning plates: It takes agility, concentration, quick reactions, a cool head, and an occasional call out from a helpful onlooker. Databases are central to the successful operation of almost every application. As DBAs are responsible for an organization’s data, finding dependable tools that help them to streamline the database management process and ease day-to-day maintenance tasks is essential. DBAs need good tools to keep their systems spinning smoothly. So what are the tried and trusted tools for MySQL administrators? Here I share my top five open source tools for MySQL administrators and discuss their value in the support of day-to-day MySQL administration tasks. For each of them, I’ve provided a link to the GitHub repository and listed the number of GitHub stars at the time of writing.



Quote for the day:


"Failure defeats losers, failure inspires winners.” -- Robert T. Kiyosaki


Daily Tech Digest - December 12, 2017

Microsoft's Edge browser is in serious trouble

microsoft edge browser resized
Edge wasn't the only browser that came out looking worse than presumed prior. Microsoft's legacy browser, Internet Explorer (IE) also was revealed as a Potemkin village. Under the old data regime, which included bots, IE's user share was overblown, at times more than double the no-bots reality. Take May 2016 as an example. With bots, Net Applications pegged IE at 33.7%; without bots, IE's user share dwindled to just 14.9%. Together, IE and Edge - in other words, Microsoft's browsers - accounted for only 16.3% of the global user share last month using Net Applications' new calculations. Back in January, however, IE+Edge had a user share of 24.1% with bots, just 14.9% without the shady tools. Put plainly, Microsoft's place in the browser race, while definitely dismal when calculated previously, became ghastly when the bot traffic was subtracted. Other data sources also called IE's and Edge's position weak, and long before Net Applications scoured its data.


Using Big Data to transform business processes


Too often, businesses build data centers that are fragmented into unusable silos, which bar them from gaining the actionable insights they seek. One of the most overlooked of these silos is the call centre audio data, which is tremendously valuable since it holds the very voice of the customer in a specific moment in time," he says. "This is where the expertise and technology available with established analytics programs make the difference. Figuring out how to pull Big Data into one usable trove of information is a large part of the task, ultimately breaking open the floodgates for gaining valuable insights that allow businesses to operationalise on their findings." ... "A treasure trove of Big Data doesn't provide answers. A carefully managed analytics program designed around business goals and desired outcomes, alongside constant review of where the program is successful or needs improvement, is how organisations ultimately rise into the sweet spot of fast and efficient decision making and operationalisation of insights," he adds.


5 Reasons the Cybersecurity Labor Shortfall Won't End Soon

In late 2013, Cisco projected there were 1 million job openings globally. For several years after that, cybersecurity labor figures were only minimally updated. Various surveys (as opposed to research) have drastically underestimated the problem because they relied on polls that didn't sample enough companies, or they focused on information/IT security and failed to take the broader cybersecurity market into consideration. This leaves out heaps of workers involved with Internet of Things security, ICS (industrial control systems) security, automotive security, embedded security, and numerous other large categories. Some surveys, ..., portray a workforce with the number of unfilled cybersecurity jobs not even doubling in nearly a decade, from 2013 to 2022. This is a stark departure from my own research, which shows the number of unfilled positions actually is expected to grow 3.5 times during an even shorter timeframe, from 1 million in 2013 to 3.5 million in 2021.


5 top machine learning use cases for security

artificial intelligence / machine learning / network
In principle, machine learning can help businesses better analyze threats and respond to attacks and security incidents. It could also help to automate more menial tasks previously carried out by stretched and sometimes under-skilled security teams. Subsequently, machine learning in security is a fast-growing trend. Analysts at ABI Research estimate that machine learning in cyber security will boost spending in big data, artificial intelligence (AI) and analytics to $96 billion by 2021, while some of the world’s technology giants are already taking a stand to better protect their own customers. Google is using machine learning to analyze threats against mobile endpoints running on Android -- as well as identifying and removing malware from infected handsets, while cloud infrastructure giant Amazon has acquired start-up harvest.AI and launched Macie, a service that uses machine learning to uncover, sort and classify data stored on the S3 cloud storage service.


Android vulnerability allows attackers to modify apps without affecting their signatures

android modify apps without affecting signatures
“Although Android applications are self-signed, signature verification is important when updating Android applications. When the user downloads an update of an application, the Android runtime compares its signature with the signature of the original version. If the signatures match, the Android runtime proceeds to install the update,” Guard Square researchers explained. “The updated application inherits the permissions of the original application. Attackers can, therefore, use the Janus vulnerability to mislead the update process and get unverified code with powerful permissions installed on the devices of unsuspecting users.” The vulnerability (CVE-2017-13156) can be exploited to replace any kind of app, even a system app, without the user noticing anything or Android preventing the installation.


AI is a Business Imperative and Boardroom Agenda

In the age of the connected customer, the most effective method of closing the customer experience gap is for companies to invest in advanced predictive analytics and artificial intelligence (AI) powered customer relationship management (CRM) platforms. According the research, forward-looking companies have invested in new technologies capable of consolidating and analyzing key customer data and have reorganized to be able to act on that customer insight in a more nimble way. The biggest and most significant shift will be the use of advanced predictive analytics to drive data-driven customer experience decisions. The competitive battleground is now squarely based on superior customer experience, and only companies that invest in AI technologies can meet the ever-growing expectations of the hyper connected, and knowledge-sharing stakeholder - employees, partners and customers.


Application-Defined Networking Basics

A core concept of the OSI model is that each layer is largely isolated from the details of any other layer. While that has led to great independence—as, for example, an application developer doesn’t have to worry about whether or not there is copper or fiber optic cable being run at the Physical Layer—it has led to siloed workers that don’t necessarily appreciate the details of the work that goes into the other layers. Traditionally, an application developer working at the top of the OSI model only cares about an IP address and a port number provided by the Network Layer, since that provides a specific place on the network where a client-server connection can be maintained. But a whole lot of design, art and maintenance goes into setting up a set of routers and switches to make sure traffic doesn’t bottleneck between any two IP addresses. This means there’s a network engineer who spends a lot of time managing tickets that represent requests for changes to an existing network design.


Faster Java Releases: A Challenge for the Spring Framework Project


"A new JDK generation every half year means a new bytecode level, which means tooling needs to be ready to handle a new JDK version," he said, "a new bytecode level, every half year. This can be quite a challenge, and quite disruptive to the Java ecosystem. Many tools are based on bytecode generation, possessing libraries such as ASM, CGLib, ByteBuddy. They historically have not needed to evolve to leniently embrace new JDK generations. They have evolved to be designed for a particular set of JDK versions only, and they had to be updated every single time." "So we'll have to change our minds a little," he added. "We'll have to design our infrastructure, our bytecode processing, in such a way that a new JDK generation is a totally normal thing." Hoeller underscored the fact that Oracle will provide a feature release every six months, update releases every quarter, and a long-term support release every three years.


Gartner analyst predicts doom for on-premises data centers

Gartner analyst predicts doom for on-premises data centers
Although he didn’t mention it by name, you have to think Microsoft is in that category because it is already cloud-first with its enterprise apps. Office 365 already outsells the packaged Office 2016, so I can see a major de-emphasis of the client product in the coming years. However, this move will be more of a win for the SaaS providers than customers. SaaS prices have risen about 8 percent in the last three years, Govekar said, who also warned that SaaS vendors such as Salesforce, Oracle and SAP are engaging in a “lock-in strategy” not unlike what enterprise software vendors used to do, integrating their products so deeply that moving or switching is prohibitively difficult. And when you are dependent on software you don’t own but rent as a service, it becomes a little like the cable monopoly where there is little anyone can do to prevent them from raising prices on a regular basis.


HP patches hundreds of laptops to remove hidden keylogger

hp spectre keyboard
If you bought an HP laptop anytime in the last five years, it could be tracking your every keystroke. Over the weekend HP revealed that nearly 500 of its notebooks dating as far back as 2012 shipped with a secret keylogger installed. Alongside the announcement, HP released driver updates to eradicate the software on affected laptops. Security researcher Michael Myng discovered the keylogger when probing the Synaptics touchpad software on an HP laptop. HP’s security bulletin says the “potential security vulnerability” affects all laptops with “certain versions of Synaptics touchpad drivers”—not necessarily just HP models. The keylogger is disabled by default, however. “A party would need administrative privileges in order to take advantage of the vulnerability,” the bulletin states. “Neither Synaptics nor HP has access to customer data as a result of this issue.” HP told Myng that the keylogger was a debugging tool.



Quote for the day:


"Problems are not stop signs, they are guidelines." -- Robert Schuller