Welcome!

@CloudExpo Authors: Pat Romanski, Elizabeth White, Liz McMillan, Mehdi Daoudi, Rene Buest

Related Topics: @CloudExpo, Microservices Expo, Cloud Security, Government Cloud

@CloudExpo: Article

Service-Oriented Architecture & Cyber Security

The impact of a Federal SOA application and the Cyber-Warrior

In an earlier article, I stated that we can view Service-Oriented Architecture (SOA) as a synthesis of Enterprise Application Integration (EAI) platforms with middleware tools. This evolution has evolved into an architectural style which, entities can then utilize to execute and align key services with their operational model to achieve strategies, goals and objectives.

Most who interact with or have interacted with the Department of Defence (DoD), will know of the various domains through which operations are implemented.

As with any effective entity within the federal realm, the DoD in its effort to ensure that mission critical information is accessible, discernible, implicitly clear for its end-users and available as demanded in an efficient manner; has implemented a technical architectural approach with SOA implementations.

Of course as with any SOA implementation regardless of industry there will be areas of need that requires addressing; for instance the existence of disparities within data and service modeling.

But can we really take a random command centre with diverse DBMS implementations possibly stocked with multifarious client server applications, which are in turn probably coded in several languages and integrate them into a functional SOA execution?  Maybe, at least in theory... right?

Unfortunately due to one reason or another in the past, the process of sharing data across domains was difficult if at all possible i.e. stuck in a stove pipes or information silos. The DoD in an effort to mitigate this, moved to adopting and employing a series of strategies one of which is metadata registry and service registry implementations.

However a key challenge faced with the volume of both structured and unstructured information available is adequately matching system searches with user intent and context ­­­-- the right metadata. This so that related information/data can be effectively utilised per the discovery cycle.

Enter the terminology NetCentric. According to Network Centric Operations Industry Consortium NCOIC; "Net-centricity seeks to leverage evolving networking capabilities to improve global enterprise efficiency."

By this definition we can hope to assume in terms of combat the intention is to capitalize on technology. A route which incorporate systems/processes in a move away from simply automating processes to parse and output data into a system (SOA), but rather where technology is inversely exploited to improve combat situations in real time.

These strategies evolved within the SOA - DOD intelligence space, stemming from three DOD CIO memos aimed at all services and was termed the DOD Net-Centric Data Strategy.

In summary this Strategy calls for data to be: Visible, Accessible, Understandable, Trustworthy, Interoperable, Responsive and Institutionalized (this is the process of embedding something within an organization and establishing it as customary within a given environment).

According to Cohen and Taylor, one objective of the DoD, "is to building improvements into current capabilities using the pieces of SOA and service-orientation that work best, passing the shortfalls back to industry and the educational community for prospective new solutions".

An example of such an instance of gains from private industry, was detailed to me in a conversation I had a few days ago with a team from Modus Operandi. The team reached out to discuss their contribution in terms of SOA within the federal and intelligence areas as it impacts an improvement in exploiting available intelligence and shortening the decision cycle.

The result of Modus Operandi's work is to supply actionable intelligence within tactically useful timelines

Of course they only shared publicly available information with me.

The company states "Massive volumes of raw data present a significant challenge. Users are typically left to manually interpret separate silos of data and search results to sift the relevant from the irrelevant."

As a result, one area that this firm addresses is a means to allow analysts to overcome the barrage of data that is thrown at them, with a proposed framework to manage this volume of unstructured data.

This is turn can lead to allowing authorised users to seamlessly work together regardless of location.

According to Tod Hagan Director, ISR Software Solutions; the framework this firm has developed, can allow an analyst to produce essential and immediate field ready intelligence within a timeline which enables effective counteraction e.g. data which normally takes several days to parse and interpret can now be parsed and interpreted within several hours or minutes.

In essence, this framework called Wave-EF performs semantic enrichment of data which in turn enables ontology-based data fusion & discovery.

Modus Operandi defines Semantic Enrichment and Ontology Based Data Fusion as follows:

Semantic Enrichment: the automated and scalable addition of XML metadata tags to raw data that represent the embedded meaning and relevant facts.

Ontology-Based Data Fusion: the correlation of related facts to a domain ontology's concepts, and support for semantic queries and machine reasoning.

The Wave-EF framework facilitates an increased level of data automation and machine reasoning. The benefit of machine reasoning is the ability to infer information which is not explicit in the data. Wave-EF not only parses raw intelligence but also supplements additional meta-tags.

This process augments the construction of a process which, not only enables information discovery; but also increases the amount of relevant data on top of the ability for information to become discoverable.

In conclusion whilst, I have not personally interacted with this system; based on the data sheets, conversations and presentations I was privy to, the system seems to focus on an area of core functionality and user interface components with concise and integral hardware/software integration.

This in turn ensures adequate integrations to other data sources provided, is scalable, handles data on the move, configures rapidly and due to its pluggable persistence avoids vendor lock-in.

More Stories By Jon Shende

Jon RG Shende is an executive with over 18 years of industry experience. He commenced his career, in the medical arena, then moved into the Oil and Gas environment where he was introduced to SCADA and network technologies,also becoming certified in Industrial Pump and Valve repairs. Jon gained global experience over his career working within several verticals to include pharma, medical sales and marketing services as well as within the technology services environment, eventually becoming the youngest VP of an international enterprise. He is a graduate of the University of Oxford, holds a Masters certificate in Business Administration, as well as an MSc in IT Security, specializing in Computer Crime and Forensics with a thesis on security in the Cloud. Jon, well versed with the technology startup and mid sized venture ecosystems, has contributed at the C and Senior Director level for former clients. As an IT Security Executive, Jon has experience with Virtualization,Strategy, Governance,Risk Management, Continuity and Compliance. He was an early adopter of web-services, web-based tools and successfully beta tested a remote assistance and support software for a major telecom. Within the realm of sales, marketing and business development, Jon earned commendations for turnaround strategies within the services and pharma industry. For one pharma contract he was responsibe for bringing low performing districts up to number 1 rankings for consecutive quarters; as well as outperforming quotas from 125% up to 314%. Part of this was achieved by working closely with sales and marketing teams to ensure message and product placement were on point. Professionally he is a Fellow of the BCS Chartered Institute for IT, an HITRUST Certified CSF Practitioner and holds the CITP and CRISC certifications.Jon Shende currently works as a Senior Director for a CSP. A recognised thought Leader, Jon has been invited to speak for the SANs Institute, has spoken at Cloud Expo in New York as well as sat on a panel at Cloud Expo Santa Clara, and has been an Ernst and Young CPE conference speaker. His personal blog is located at http://jonshende.blogspot.com/view/magazine "We are what we repeatedly do. Excellence, therefore, is not an act, but a habit."

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@CloudExpo Stories
The goal of Continuous Testing is to shift testing left to find defects earlier and release software faster. This can be achieved by integrating a set of open source functional and performance testing tools in the early stages of your software delivery lifecycle. There is one process that binds all application delivery stages together into one well-orchestrated machine: Continuous Testing. Continuous Testing is the conveyer belt between the Software Factory and production stages. Artifacts are m...
When shopping for a new data processing platform for IoT solutions, many development teams want to be able to test-drive options before making a choice. Yet when evaluating an IoT solution, it’s simply not feasible to do so at scale with physical devices. Building a sensor simulator is the next best choice; however, generating a realistic simulation at very high TPS with ease of configurability is a formidable challenge. When dealing with multiple application or transport protocols, you would be...
Cloud resources, although available in abundance, are inherently volatile. For transactional computing, like ERP and most enterprise software, this is a challenge as transactional integrity and data fidelity is paramount – making it a challenge to create cloud native applications while relying on RDBMS. In his session at 21st Cloud Expo, Claus Jepsen, Chief Architect and Head of Innovation Labs at Unit4, will explore that in order to create distributed and scalable solutions ensuring high availa...
An increasing number of companies are creating products that combine data with analytical capabilities. Running interactive queries on Big Data requires complex architectures to store and query data effectively, typically involving data streams, an choosing efficient file format/database and multiple independent systems that are tied together through custom-engineered pipelines. In his session at @BigDataExpo at @ThingsExpo, Tomer Levi, a senior software engineer at Intel’s Advanced Analytics ...
"We're a cybersecurity firm that specializes in engineering security solutions both at the software and hardware level. Security cannot be an after-the-fact afterthought, which is what it's become," stated Richard Blech, Chief Executive Officer at Secure Channels, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Enterprise architects are increasingly adopting multi-cloud strategies as they seek to utilize existing data center assets, leverage the advantages of cloud computing and avoid cloud vendor lock-in. This requires a globally aware traffic management strategy that can monitor infrastructure health across data centers and end-user experience globally, while responding to control changes and system specification at the speed of today’s DevOps teams. In his session at 20th Cloud Expo, Josh Gray, Chie...
To get the most out of their data, successful companies are not focusing on queries and data lakes, they are actively integrating analytics into their operations with a data-first application development approach. Real-time adjustments to improve revenues, reduce costs, or mitigate risk rely on applications that minimize latency on a variety of data sources. Jack Norris reviews best practices to show how companies develop, deploy, and dynamically update these applications and how this data-first...
Intelligent Automation is now one of the key business imperatives for CIOs and CISOs impacting all areas of business today. In his session at 21st Cloud Expo, Brian Boeggeman, VP Alliances & Partnerships at Ayehu, will talk about how business value is created and delivered through intelligent automation to today’s enterprises. The open ecosystem platform approach toward Intelligent Automation that Ayehu delivers to the market is core to enabling the creation of the self-driving enterprise.
"We're here to tell the world about our cloud-scale infrastructure that we have at Juniper combined with the world-class security that we put into the cloud," explained Lisa Guess, VP of Systems Engineering at Juniper Networks, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8, 2017, at the Javits Center in New York City, NY.
Historically, some banking activities such as trading have been relying heavily on analytics and cutting edge algorithmic tools. The coming of age of powerful data analytics solutions combined with the development of intelligent algorithms have created new opportunities for financial institutions. In his session at 20th Cloud Expo, Sebastien Meunier, Head of Digital for North America at Chappuis Halder & Co., discussed how these tools can be leveraged to develop a lasting competitive advantage ...
As businesses adopt functionalities in cloud computing, it’s imperative that IT operations consistently ensure cloud systems work correctly – all of the time, and to their best capabilities. In his session at @BigDataExpo, Bernd Harzog, CEO and founder of OpsDataStore, presented an industry answer to the common question, “Are you running IT operations as efficiently and as cost effectively as you need to?” He then expounded on the industry issues he frequently came up against as an analyst, and ...
The question before companies today is not whether to become intelligent, it’s a question of how and how fast. The key is to adopt and deploy an intelligent application strategy while simultaneously preparing to scale that intelligence. In her session at 21st Cloud Expo, Sangeeta Chakraborty, Chief Customer Officer at Ayasdi, will provide a tactical framework to become a truly intelligent enterprise, including how to identify the right applications for AI, how to build a Center of Excellence to ...
In his session at 20th Cloud Expo, Mike Johnston, an infrastructure engineer at Supergiant.io, discussed how to use Kubernetes to set up a SaaS infrastructure for your business. Mike Johnston is an infrastructure engineer at Supergiant.io with over 12 years of experience designing, deploying, and maintaining server and workstation infrastructure at all scales. He has experience with brick and mortar data centers as well as cloud providers like Digital Ocean, Amazon Web Services, and Rackspace. H...
You know you need the cloud, but you’re hesitant to simply dump everything at Amazon since you know that not all workloads are suitable for cloud. You know that you want the kind of ease of use and scalability that you get with public cloud, but your applications are architected in a way that makes the public cloud a non-starter. You’re looking at private cloud solutions based on hyperconverged infrastructure, but you’re concerned with the limits inherent in those technologies.
SYS-CON Events announced today that Massive Networks will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Massive Networks mission is simple. To help your business operate seamlessly with fast, reliable, and secure internet and network solutions. Improve your customer's experience with outstanding connections to your cloud.
DevOps is under attack because developers don’t want to mess with infrastructure. They will happily own their code into production, but want to use platforms instead of raw automation. That’s changing the landscape that we understand as DevOps with both architecture concepts (CloudNative) and process redefinition (SRE). Rob Hirschfeld’s recent work in Kubernetes operations has led to the conclusion that containers and related platforms have changed the way we should be thinking about DevOps and...
Everything run by electricity will eventually be connected to the Internet. Get ahead of the Internet of Things revolution and join Akvelon expert and IoT industry leader, Sergey Grebnov, in his session at @ThingsExpo, for an educational dive into the world of managing your home, workplace and all the devices they contain with the power of machine-based AI and intelligent Bot services for a completely streamlined experience.
Because IoT devices are deployed in mission-critical environments more than ever before, it’s increasingly imperative they be truly smart. IoT sensors simply stockpiling data isn’t useful. IoT must be artificially and naturally intelligent in order to provide more value In his session at @ThingsExpo, John Crupi, Vice President and Engineering System Architect at Greenwave Systems, will discuss how IoT artificial intelligence (AI) can be carried out via edge analytics and machine learning techn...
FinTechs use the cloud to operate at the speed and scale of digital financial activity, but are often hindered by the complexity of managing security and compliance in the cloud. In his session at 20th Cloud Expo, Sesh Murthy, co-founder and CTO of Cloud Raxak, showed how proactive and automated cloud security enables FinTechs to leverage the cloud to achieve their business goals. Through business-driven cloud security, FinTechs can speed time-to-market, diminish risk and costs, maintain continu...
SYS-CON Events announced today that Datera, that offers a radically new data management architecture, has been named "Exhibitor" of SYS-CON's 21st International Cloud Expo ®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Datera is transforming the traditional datacenter model through modern cloud simplicity. The technology industry is at another major inflection point. The rise of mobile, the Internet of Things, data storage and Big...