September 05, 2015

Finding a Single Version of Truth Within Big Data

“The ‘best’ data depends on its source and purpose,” Jonas writes. “While a company may have employee data in different systems, like IT, HR, Finance etc., the employee name and address maintained by the payroll system is probably the best one to use for tax filing.” That doesn’t mean Jonas thinks organizations should not try to reconcile data plurality. But instead of the traditional “merge-purge” technique that involves massive batch jobs that compare new data against the old data, Jonas thinks we are better of using an “entity resolution system.” “Entity resolution systems generally retain every record and attribute, each with its associated attribution,” he writes. “Because entity resolution systems have no data survivorship processing, there is no chance future relevant data will be prematurely discarded.”


Agile Introduction: Are You a Laggard?

While much has been written about the strengths and weaknesses of the technology, little data has been published to show how widely agile methods are used. This paper corrects that by providing data from our databases for public consumption. ... Some of these organizations are offshoots of the 120 firms and government organizations from which we have received data. Figure 2 summarizes which agile methodologies are in use by these organizations. As many said that they were using a hybrid approach, i.e., one that combined agile with traditional concepts, we have included their response and categorized them as either hybrid or hybrid/lean


Data Visualizations: 11 Ways To Bring Analytics To Life

"The ability to slice and dice has been around for a while. It's more exploratory now. You have a lot of data sources, so finding a needle in a haystack boils down to being interactive," said George Ramonov, founder and CTO at meeting planner provider Qurious.io, in an interview. "Now that we have cross-functional teams, it's important to be able to share visualizations embedded in a website or app to allow sharing without all the extra time of putting together an email." Regardless of how large or small an audience is, good data visualizations speed understanding. Bad visualizations cloud the issues. Here are six ways to best leverage the graphical presentation of data.


Building a Cyber-Resilient Business

Unfortunately, blocking four out of five attacks still leaves open the possibility that a substantial number of attacks might succeed. And today, it’s more a matter of when rather than if you will, eventually, be successfully attacked. What happens then?  Even well prepared companies may not know immediately that they have been breached. But those that have prepared for such an event will be much better off than those that have not. Just as conducting fire drills can save lives in the event of a real fire, preparing for the aftermath of a cyber attack can make an enormous difference in how quickly your company gets back on its feet and how well officers and board members do in the limelight after a major breach becomes public.


How DevOps fits into the modern network

If Company A builds protocol Cat, and Company B builds protocol Dog, how do they get those protocols to talk? They can't! It's just like someone who speaks Japanese and someone else who speaks English would need a translator to communicate effectively. By embracing open standards, we can make pieces of network equipment talk to each other, servers, laptops, phones, etc. If we didn't promote open standards, we would be locked into solutions where everything is controlled by a single vendor from A to B. We have many customers at Cumulus Networks that run multi-vendor environments, and open standards are not just encouraged, they're crucial.


A Guide to Lean Healthcare Workflows

It describes each step in-depth and includes techniques, example worksheets, and materials that can be used during the overall analysis and implementation process. And it provides insights that are derived from the real-world experience of the authors. This paper is intended to serve as a guide for readers during a process-improvement project and is not necessarily intended to be read end-to-end in one sitting. It is written primarily for clinical practitioners to use as a step-by-step guide to lean out clinical workflows without having to rely on complex statistical hypothesis-testing tools. This guide can also be used by clinical or nonclinical practitioners in non-patient-centered workflows. The steps are based on a universal Lean language that uses industry-standard terms and techniques and, therefore, can be applied to almost any process.


How Can Healthcare Big Data Analytics Bust Data Silos?

Machine data, meanwhile, is a record of actions that have already occurred, such as call logs or EHR access time stamps. This data is more or less static, and while it may recount the activities of users, it is automatically created by IT systems without much human intervention. When subjected to more sophisticated analysis, the millions of data points in machine data can help a healthcare organization identify a possible breach or chart how long a clinician takes to see her patients, and even aid understanding of how patients flow into the emergency room or how often a nurse updates vital signs. Correctly and efficiently analyzing these types of big data is key for clinical and business intelligence activities, and can help healthcare organizations understand how their IT infrastructure can enable workflow improvements


How to Manage Cloud Resources Wisely

The cloud isn’t perfect. There are still outages, challenges around replicating pieces of an environment, and even confusion around all the different kinds of services that cloud can provide today. Fortunately, the entire cloud model is becoming a bit easier to understand and deploy. Why? There are simply more use cases for such a powerful architecture. Businesses of all sizes are quickly realizing that their direct competitive advantage may very well revolve around the capabilities of the cloud. However, with that in mind, what should organizations of various sizes do about physical resource requirements? What about infrastructure expansion? Most of all, what are the limitations of your cloud?


How COSO Destroyed Risk Management

COSO’s failure is due primarily to its narrow focus on internal controls as a risk management tool. Internal controls should have been considered one leg of a four-pronged approach to a comprehensive risk management framework. Fundamentally, internal controls should be considered one of the foundational components of enterprise risk management. What is missing in COSO and broadly across risk management are the other tools needed to execute ERM. Risk management must include mechanisms to measure and quantify real risks. The rise of quantitative analysts is the recognition that risk management is measureable and not simply assessed through the qualitative assessments advocated in COSO.


How Different Team Topologies Influence DevOps Culture

It has become increasingly clear to me over the past few years working with many different organisations that the idea of a single, identifiable 'DevOps culture' is misplaced. What we've seen in organisations with effective or emerging DevOps practices is a variety of cultures to support DevOps. Of course, some aspects of these different cultures are essential: blameless incident most-mortems; team autonomy; respect for other people; and the desire and opportunity to improve continuously are all key components of a healthy DevOps culture. However, in some organisations certain teams collaborate much more than other teams, and the type and purpose of communication can be different to that in other organisations.



Quote for the day:

"Keep your fears to yourself, but share your courage with others." -- Robert Louis Stevenson

September 04, 2015

A degree in data science is in demand

The work of a data scientist is really two-fold. First, the data scientist must pull together all this data, which is often just a collection of garbled text or numbers, and clean it up to the point where it can be analyzed. Then, the data scientist has to know how to extract meaningful information from the cleaned-up data. “Big data represents one of the fastest growing areas of business, estimated to become a 17-trillion-dollar industry by 2020," wrote Becker College when it introduced its new data science program earlier this year.  Locally, Worcester Polytechnic Institute and Becker offer data science programs; both convinced that data science is already a desired career path for their students.
WPI's data science program is entering its second year; it currently offers a two-year, graduate-level degree in data science, and this fall, is adding a doctorate-level degree.


US Army’s Cyber War Strategy is Not Just for Military Use

Taking threat sensor data, removing noise and analyzing the data, will provide decision makers with the ability to forecast, gain up-to-date battle damage assessments (BDA) and supply geolocation information of the enemy and the electronic signatures our own forces generate. Convergence is going to be achieved by consolidating its cyber forces operating across multiple departments into single cross operational units removing impediments to information sharing. By fiscal year 2017, the U.S. Army Cyber Command (ARCYBER) will eventually have 41 Cyber Mission Forces operationally capable. They will combine cybersecurity, electronic warfare and signal doctrine into single units. The units will use past lessons learned to develop new doctrines in cyber security.


How Edge Data Center Providers are Changing the Internet’s Geography

Ultimately, location is the main way for companies like EdgeConneX to differentiate from the big colo players like Equinix or Interxion. Edge data center providers are essentially building in tier-two markets what Equinix and its rivals have built in the big core markets: hubs where all the players in the long chain of delivering content or services to customers interconnect and exchange traffic. These hubs are where most of the internet has lived and grown for the bulk of its existence, and edge data center companies are building smaller hubs in places that don’t already have them but are becoming increasingly bandwidth-hungry.


What Do Marketers Really Want in Data and Technology?

You may have heard of Data-as-a-Service (DaaS). Companies are touting DaaS as the next big thing and as a solution that gives marketers an “unfair competitive advantage.” By linking data with technology, DaaS is completely changing the game through a new model of fast-moving and real-time data acquisition. As the name implies, Data-as-a-Service begins with the data. Specifically, a company’s internal data, third party data, real-time fast data, and unique and hard-to-find data (HTFD) sourced from the Big Data ecosystem. With technology this data is structured to create insight into their best customers and ideal prospects. Real-time knowledge is also used to learn about who is actively in market for products and services, who is searching for competitors, or who is posting to social media for product recommendations.


Leveraging COBIT to Implement Information Security (Part 3)

In the context discussed here, it is envisaged that controls within the system are selected by management on a risk-assessed basis to address the perceived threats to the security of the organisation’s core business processes. Once selected, the ISMS is the basis for collecting evidence for operation and reviewing the efficacy of the implementation on an ongoing basis as part of the security forum. The forum is created by senior management, typically the chief executive officer (CEO), as a collaborative round table where managers from IT security, IT, human resources (HR) and major business functions can come together to make decisions on the basis of regular reporting from the system.


Disruptive tech and its impact on wireless protocols and networks

Internet of Things is not a new concept. It's been around for a long time. We used to call it telemetry or sensor-based computing. But the idea that we can do it today at a very low cost and that we can automate so many applications -- medical applications, security, energy management, all kinds of things like that -- means that there's going to be more and more happening on the network over time. And many of those applications will be mobile. (Not everything in IoT is mobile, but a lot of it will be.) So planning for that in terms of capacity, [security and cost is] made more complex. So, even though mobility opens up a lot of opportunities, it does come with a set of costs that we didn't have before.


Indoor positioning – Are we nearly there yet?

If the object you are locating and tracking happens to have a device with some unique identifier attached to it, like a tag or smart phone, things become significantly easier. Now you can have many fixed transmitters sending out pulses, getting received by the device that can then send out a “reply” rather than the reflected pulse that can also contain its unique identifier. The transmitters can be simple and omnidirectional, but then you need a few of them (remember each one defines a circle; in the plane, i.e., in 2D, at least 3 transmitters are needed to determine a unique position) – the determination of a location from measuring distances to a few fixed points is known as Trilateration (check out Multilateration while you’re at it).


Don’t Let Cyberattacks Take A ‘Byte’ Out Of Your Bottom Line

Should a data breach occur, having an incident response plan in place can help ease the pressure in the heat of the moment. Affected systems should immediately be closed off from the remainder of the company’s infrastructure in order to pinpoint the root cause. When a data breach does occur, use it as a learning experience, extracting as much information as possible about how and why the incident occurred. That information can then be used to strengthen IT infrastructure by plugging holes and establishing improved monitoring programs to detect threats. Reaction plans should be tested and updated regularly to ensure any future threat responses are as effective and efficient as possible.



Why Optimization and WANOP for Your Cloud Is Now Easier than Ever

We’re now pushing down rich content, a variety of applications, and a lot of new use cases. The reality here is that cloud will continue to grow as more users and verticals adopt this very versatile platform. In fact, global spending on IaaS is expected to reach almost $16.5 billion in 2015, an increase of 32.8 percent from 2014, with a compound annual growth rate (CAGR) from 2014 to 2019 forecast at 29.1 percent, according to Gartner. The report goes on to state that over time, as a business becomes more comfortable with the use of IaaS, organizations, especially in the midmarket, will eventually migrate away from running their own data centers in favor of relying primarily on infrastructure in the cloud.


Resiliency Testing Best Practices - Report

Every organization must put a plan in place for recover-ability after an outage, but testing your enterprise resilience without full business and IT validation is ineffective. Read the white paper to learn how to put a plan in place for full functional validation, and get details on the importance of validating resiliency in a live environment; learn why small-scale recovery “simulations” are inadequate and misleading; understand why validating resilience demands involvement from IT and the business; and get details on the checks and balances you need to maintain and validate business resilience.



Quote for the day:

"Let a man lose everything else in the world but his enthusiasm and he will come through again to success." -- H. W. Arnold

September 03, 2015

MySecureShell Documentation

MySecureShell is a solution which has been made to bring more features to sftp/scp protocol given by OpenSSH. By default, OpenSSH brings a lot of liberty to connected users which imply to thrust in your users. The goal of MySecureShell is to offer the power and security of OpenSSH, with enhanced features (like ACL) to restrict connected users. MySecureShell was created because of the lack of file transfer features in OpenSSH. OpenSSH was not designed as a file transfer solution, that’s why we made MySecureShell. MySecureShell is not a patch for OpenSSH, it’s a shell for users.


How big data is unfair

An immediate observation is that a learning algorithm is designed to pick up statistical patterns in training data. If the training data reflect existing social biases against a minority, the algorithm is likely to incorporate these biases. This can lead to less advantageous decisions for members of these minority groups. Some might object that the classifier couldn’t possibly be biased if nothing in the feature space speaks of the protected attributed, e.g., race. This argument is invalid. After all, the whole appeal of machine learning is that we can infer absent attributes from those that are present. Race and gender, for example, are typically redundantly encoded in any sufficiently rich feature space whether they are explicitly present or not.


Your Smartphone Can Tell If You’re Bored

While using machine learning to infer your state of mind is tricky, doing so reliably via your smartphone could be powerful. For instance, if an app were able to predict that you’re bored, and also knew where you were, it could try to feed you content it thinks you’d like in that particular context. Already at least one startup is trying to do something similar to this: Triggerhood, which built software that lets apps collect data about how the phone is being used, determines when is the best time to send you a notification (see “Smarter Smartphone Alerts Come in When You Want Them”).


Learning to Trust in the Cloud

After the prominent security breaches in retail and the public sector over the last year, it’s clear that a strong security posture is a requirement, not an option, as no one wants to be the next headline. Reviews of these breaches show that they were the result of internal policy or system failures, not the result of any weakness of a cloud service.  ... Security is a shared responsibility with your cloud provider, and companies should consider implementing tools such as next-generation and application firewalls, intrusion detection and prevention, anti-virus software, encryption, identity and access management, visibility, log and big data analytics. This can help ensure internal security standards are as high as those set by cloud providers.


TGIF(P) – Thank god it’s fried phish

Spoiler: It commonly means “Thank god it’s Friday” and probably many working people will be able to appreciate such a feeling. On the other hand, while many offices may close down for the weekend, it’s the time for bad guys to boost their activity because they count on the fact that they may go unnoticed for some time, at least until the upcoming Monday morning. The IT community is working hard to find and take down malicious sites as soon as possible, but then … the weekend is the weekend for many. What happened just last Friday may be a good example of such malicious weekend activity. We received the following email to one of our inboxes:


The Problem with Corporate Innovation

Corporate innovation faces challenges that entrepreneurs can’t fathom. Entrepreneurs often wish they had the people and resources that larger organizations do, without realizing that all those people and resources are already spoken for. Larger organizations lack the freedom and agility that smaller organizations have. Larger organizations are very slow to recognize and respond to major seismic shifts, so comfortable in their day to day operating models. Industry conventions become first defensive barriers and then comfortable blankets, reassuring large organizations that they understand what the customer needs and what the industry will do. Corporate executives face a really difficult challenge: on one hand they must meet the quarterly numbers, or heads will roll.


Data Center Consolidation: a Manager’s Checklist

The reality in today’s very competitive data center and cloud market is the one who can run most optimally and cost-effectively while still delivering prime services is a leader in the market. To accomplish this goal, there are a few things to consider. First of all, getting ahead doesn’t always mean adding more gear. Smart data center and cloud providers learn to use what they have and make the absolute most out of every resource. There are new kinds of questions being asked when it comes to new data center efficiency concepts. Is there a new technology coming out that improves density? Does the ROI help improve long-term management costs? Does a new kind of platform allow me to achieve more while requiring less?


Beth Israel Launches Big Data Effort To Improve ICU Care

The way clinical care is documented can vary greatly; for example hypertension, high blood pressure and elevated blood pressure are three different terms that describe the same condition. “There has been a lot of data cleanup that needed to be done, and in the process, we’ve learned a lot about structured data, and quality of data,” says Folcarelli. She says it took at least a year to normalize the data and determine the data points that would work well in the model. Statisticians and analysts worked with clinicians and nurses during this process. The hospital’s IT team uses scripts that extract data from the transactional systems—the HIS, the clinical ICU systems, the HR systems—on a regular basis. The extracts are sent to the hospital’s clinical data warehouse, which is built with Microsoft SQL Server technologies.


Your Next Car Could Reveal More About You Than Your Facebook Profile

About 90 percent of new vehicles in western Europe will be able to send and receive data by 2020, compared with roughly one-third next year, Hitachi Ltd. estimates. Once hooked into the web, the car’s driving data could be coupled with information as detailed as a driver’s contact list, favorite routes to work and even financial information from mobile-payment systems. As cars get closer to driving themselves, their cameras and sensors will collect data about what happens in and around the vehicle and what passengers are doing. That prospect has created disputes about what data can be collected and who needs to agree to it. Rules in this area could hamper automakers from fully tapping their newfound gold mine.


Blythe Masters Tells Banks the Blockchain Changes Everything

In a matter of months, this word, blockchain, has gone viral on trading floors and in the executive suites of banks and brokerages on both sides of the Atlantic. You can’t attend a finance conference these days without hearing it mentioned on a panel or at a reception or even in the loo. ... Now, everyone’s trying to figure out whether the blockchain is just so much hype or if Masters’s firm and other startups are really going to change the systems that process trillions of dollars in securities trades. When investors buy and sell syndicated loans or derivatives or move money around the world, they must cope with opaque and clunky back-office processes that rely on negotiated contracts between buyers and sellers, lots of phone calls, lots of lawyers, and even the occasional fax. It still takes almost 20 days, on average, to settle syndicated loan trades.



Quote for the day:

"Everybody wants to do something to help, but nobody wants to be the first." -- Pearl Bailey

September 02, 2015

5 IT experts reveal their Windows 10 upgrade strategies

There are support costs, management issues, security problems and a host of other deployment snafus that can crop up.  Yet, the new OS is a major step forward. Microsoft resolved many of the troubling usability issues that plagued Windows 8, such as a confusing “tile” interface and hard-to-find settings. Many features – including a more streamlined update process that won’t interfere as much with daily work – are designed for the enterprise. It’s even easier to do “in place” upgrades.  To help put the finishing touches on your upgrade strategy, CIO.com talked to several experts (including those at Microsoft) about how to make a deployment as smooth as possible. We asked about general guidelines, security issues, usability, training and other considerations for enterprise users. Here’s what we found out.


Data virtualization tools move into strategic IT realm

There [are some] use cases for data virtualization [instead of traditional data integration]. One is [if] it's a new source of data. You may need at some time later on to integrate the data but you want to get to the data now to analyze and look at it, see how useful it is, and you haven't gotten to the point where you can invest in getting it integrated. That's one use case scenario: the precursor of integrating it. There are plenty of other use cases where you never integrate the data with your source of data; you may not own the data. There's social media data, there's Web data, there's data that you might be exchanging between prospects, suppliers, partners and so on, that you may never own or have the ability or desire to integrate with your data.


Of Black Hat and security awareness

Black Hat is a combination of in-depth, mostly hands-on training and briefings that tend to be presentations on various security topics, typically with a focus on security weaknesses. I am interested in briefings in which the presenters demonstrate a successful hack or compromise of something very interesting or familiar. This year’s quintessential Black Hat presentation demonstrated the ability to remotely control connected-car functions. It’s the sort of thing that really sets Black Hat apart. Of course, Black Hat also has the obligatory expo floor, and I enjoyed the opportunity to obtain demos from technology vendors that I currently use or am considering. It’s much easier to ask pressing questions in a venue like this than to schedule individual meetings and then sit through a bunch of marketing slides before getting to the real substance.


Why Startups Should Leverage Compliance

Though this particular measure focuses on payments, the same dynamic can be seen at play in other innovative sectors. During the last several months, Uber has been battling regulators both here in the United States and in many countries abroad, often because of aggravation by taxi unions. What these incidents highlight is the unsurprising fact that if you want to eat the established players’ lunches, you probably have to take their pills too. Despite the many upstarts who decry the stifling effects of regulation, governments have signaled repeatedly that they have no intention of backing down. The proper response from the technology industry is not to bemoan the state of affairs, but to recognize the opportunity to leverage compliance against their competitors.


Lone Rangers of the Underground

The underground market for malware tools, vulnerabilities, exploit kits and every other criminal niche is fully mature. The barriers to entry into the market have fallen away over the years, established criminal toolkits are available at low to no cost, former high value malware such as ZeuS have become almost open source projects, spawning a variety of improvements or imitators and basic tools such as keyloggers or system lockers are being combined to devastating effect. Take for example the Hawkeye attacks that affected small businesses on a global scale, from China through India and Europe all the way across to the United States. A simple $35 keylogger, Hawkeye, was used in sophisticated “change of supplier” fraud by two lone Nigerian criminals.


Bank-in-a-box: An innovative, easily deployable solution

The bank-in-a-box is an integrated solution set that supports the transformation of core banking operations using a service provider or third party developed interface. It is scalable and cost-effective, and includes internet and mobile banking, deposit and loan products, payment solutions, ATM and POS switching, regulatory and MIS reporting. The software can easily be used by non-IT specialists to develop new products. The suite acts as a complete technology solution spanning across multiple delivery channels, between front- and back-office, including reconciliation and settlement. Typically, the hosted core banking platform (based on the SaaS model) is provided by the application service provider. This could take the form of cloud-based hosting or on-premise hosting services.


Why you need to convert IT consumers into investment partners

Several years ago, Joe Spagnoletti, CIO of Campbell Soup Company, brought an investment management approach to IT spend. Today, he and his business partners look at four characteristics when making IT investment decisions: business outcome, operating performance, cost to serve, and risk. "We’ve educated our business leaders about how to think of an IT investment more broadly," he says. "We show them how their current portfolio is performing so they think, 'In a silo, this one investment looks good, but how does it look as a part of a collection?'" Stephen Gold, EVP of business and technology operations, and CIO, CVS Health, employs the "CIO theory of reciprocity." "Let's say the head of sales of a given company suggests, 'If I had a real-time inventory management system, I could increase revenue by $500M,'" says Gold.


Metadata-Driven Design: Building Web APIs for Dynamic Mobile Apps

For the sake of brevity, it can be summarized as an approach to software design and implementation where metadata can constitute and integrate both phases of development. ... While building these apps on iOS and Android, I took note of the additional time that was inherent to their development on a native level, especially when compared to normal desktop applications. Besides the unquantifiable test of an app’s user interactivity, a significant amount of time was required to organize the application’s flow of navigation when using a more complex framework (like Cocoa). Of course, there was also the time needed to submit the app for approval and then the subsequent effort to modify and/or tailor any aspects considered undesirable by the app store’s vendor and/or the app’s users.


Why Israel dominates in cyber security

“Connecting the talent pool coming out of defense organizations with the strong entrepreneurial spirit that exists here, and you get the perfect ingredient for a powerhouse, in terms of cyber security startups and technology companies,” says Mimran. And that connection has been making strides in digital security for decades. For instance, In 1993, Tel Aviv-based Check Point developed FireWall-1, one of the very first protection solutions for Internet-connected computers. The defensive software was developed by Israeli-entrepreneur Gil Shwed, who served in the IDF’s Unit 8200—which is responsible for collecting signal intelligence—and grew the company into one of the country’s biggest tech giants. Check Point foresaw a need for protecting computer networks, and more importantly, filled that need before most people were even online.


Barclays Hacks Its Own Systems to Find Holes Before Criminals Do

Staying ahead of the bad guys requires resources, expertise and vigilance, and even that isn’t always enough. “They improve the ways to get in all the time,” said Oerting, 58. “The reality is that there are actually more cases than you read in the press.” Barclays is boosting spending by about 20 percent as part of its new cyber-defense strategy, Oerting said, declining to elaborate.  Cyber risk is viewed as a key concern by almost a third of banks in the U.K., a survey by the Bank of England found in July. Two years ago, only 1 percent of those surveyed considered cyber attack a major risk. HSBC Holdings Plc, Lloyds Banking Group Plc andRoyal Bank of Scotland Group Plc declined to discuss their efforts to fight computer crime.



Quote for the day:

"In order to succeed, your desire for success should be greater than your fear of failure." -- Bill Cosby

September 01, 2015

How Semantic Graph Techniques Ease Data Integration

Semantic Graph Databases are most valuable for complex metadata applications where the number of classes (i.e. types of objects) change daily, properties within classes change on-the-fly, and it is critical have self-descriptions of data. Grounded in formal logic, semantic analytics can easily encompass associative and contextual concepts for richer data analysis, which provide a more expansive, exploratory querying experience. As noted in David S. Frankel’s article, “How Semantics Can Take Graph Databases to New Levels,” querying a database using formal semantics provides the ability to “infer logical consequences from a set of asserted facts or axioms … Reasoners grounded in formal semantics can be potent tools when managing large graph databases.”


Intel says GPU malware is no reason to panic, yet

While it's true that there is a shortage of tools to analyze code running inside GPUs from a malware forensics perspective, endpoint security products don't need such capabilities because they can detect the other indicators left by such attacks on the system. On one hand, moving malicious code inside the GPU and removing it from the host system makes it harder for security products to detect attacks. But on the other, the detection surface is not completely eliminated and there are trace elements of malicious activity that can be identified, the researchers said. Some of the defenses built by Microsoft against kernel-level rootkits, such as Patch Guard, driver signing enforcement, Early Launch Anti-Malware (ELAM) and Secure Boot, can also help prevent the installation of GPU threats.


Breaking the SQL Barrier: Google BigQuery User-Defined Functions

BigQuery UDFs are similar to map functions in MapReduce. They take one row of input and produce zero or more rows of output, potentially with a different schema. ... BigQuery UDFs are functions with two formal parameters. The first parameter is a variable to which each input row will be bound. The second parameter is an “emitter” function. Each time the emitter is invoked with a JavaScript object, that object will be returned as a row to the query. ... JavaScript UDFs are executed on instances of Google V8 running on Google servers. Your code runs close to your data in order to minimize added latency. You don’t have to worry about provisioning hardware or managing pipelines to deal with data import / export.


Are you a data hoarder? Hadoop offers little choice

There's a bit of absurdity here. If you throw it away, you can't get it back; if you keep it, you can eventually organize and purge what you don't need. Those who store data now while getting their governance in place are not automatically "data hoarders." This is a false dilemma. The idea that you need to come up with a perfect plan before keeping any data or bringing in any new sources is a little like saying we need perfect social justice for everyone before we can address police killings of African-Americans. Instead, get started now. Stop throwing out the baby with the bathwater and begin finding your use cases. Meanwhile, make data the point rather than a side effect of your processes and govern it accordingly. These aren't "steps," but initiatives you need to undertake, usually in parallel.


New Smartphone Attempts to Finally Solve the Storage Problem

The startup is trying to take better advantage of the increasing ubiquity of wireless networks that most of us are already using. Apps, photos, videos, and music can pile up and take up available space on your phone, and Nextbit thinks the solution is to use the Internet to unobtrusively back up and remotely store some of that stuff. By default, the phone does this when it’s plugged in and connected to Wi-Fi, though users can change this. Robin is slated to be generally available online in January or February and will include 32 gigabytes of storage on the phone and another 68 online. It will cost $399, and Nextbit has already raised $18 million in venture funding from Accel Partners for the phone’s development. In an effort to publicize its brand with consumers and drum up early sales,


Revamping Master Data Management with Graphs

One of the more interesting aspects about utilizing graph databases with MDM is the role that Natural Language Processing (NLP) can play in the query process. Interestingly enough, the visual querying framework that Semantic graphs facilitate was described by Aasman as “even simpler than natural language”, especially because the former method does not involve code. Still, there are ways in which NLP can assist with the querying process for MDM systems augmented by graph databases. The most salient of these are when NLP is involved with certain definitions and descriptions of terms that are referred to with multiple spellings, nick names, and perhaps even slang. One of the most cogent examples of this fact is found in a use case in which Franz combined with Montefiore Medical Center to create a healthcare platform with instantaneous querying capabilities of vastly heterogeneous sources.


Six simple cybersecurity rules for all ages

Nowadays parents are getting more and more concerned about what you do on the Internet. They know that there are lots of creepy weirdos and malicious viruses on the Internet; they fear for your naivety, innocence and the potential of severe cyberbullying. Of course, sometimes they go overboard but you still need to deal with it. Do you have a smothering mother or father who wants to know what’s going on in your life both online and off? Sorry, but it’s just the way things are. If you want more freedom behave like any normal adult would do: show your parents that you can make deliberate decisions. You’ll benefit from it as well. Keeping your gaming and social accounts secured is a tangible bonus, isn’t it? As we’ve already written, cybercriminals would readily take over your Facebook page, infect your smartphone with a virus, or steal your gaming account.


New DOD cyber security regulation: is the cure worse than the disease?

In summary, this “interim rule” imposes on DOD contractors and subcontractors a contractual duty to provide “adequate security” from “unauthorized access and disclosure” for a broad array of unclassified information, including controlled technical information, export controlled information, critical information, and other information requiring protection by law, regulation or policy (protections for classified information continued to be provided for under the National Industrial Security Operating Manual (NISPOM)). The interim rule also requires DOD contractors and subcontractors to report directly to the appropriate DOD office a “cyber incident” or “malicious software.”


Latency, Bandwidth, Disaster Recovery: Selecting the Right Data Center

In selecting the right type of data center colocation, administrators must thoroughly plan out their deployment and strategies. This means involving more than just facilities teams in the planning stages. The process to select a good data center has to involve not only the physical elements of the facility but the workload to be delivered as well. ... With the increase of traffic moving through the internet, there is a greater demand for more bandwidth and less latency. As discussed earlier, it’s important to have your data reside closer to your users as well as the applications or workloads which are being accessed. Where data may have not fluctuated too much in the past, current demands are much different.


How PMOs can balance time, cost and quality

Triple constraint – the balancing act that occurs between cost, quality and time – is a term often heard in the world of project management, but what does that mean when it comes to the success or failure of a project to meet organizational objectives? Project managers are tasked with ensuring that they successfully manage the scope of a project to keep it within the cost, quality and time parameters determined by organizations at the onset. So how do project managers balance these three factors. This can be an ominous task, considering there are various internal or external factors that can rapidly change, causing any one or more of the three constraints to shift in an undesirable way. In order to decrease this risk, there are some questions you need to address in the beginning stages. Here six mportant ones that could have a significant impact on project scope.



Quote for the day:

"Continuous improvement is better than delayed perfection." -- Mark Twain