Sunday, July 21, 2013

more WiFi doorlocks

Some post ago I mentioned the the Lockitron project that was building a addition that can be placed on a doorlock to enable you to control it via WiFi. Already I stated that other vendors are developing solutions like this and that most of them require you to completely replace the lock. Even though that statement still holds there are some projects that deserve some attention because they build a great product that enables you to control your locks with a mobile device. Two that come to mind are the August Smart Lock and the Goij Smart lock. Both are amazing cool products and both are build by a startup.

The August Smart Lock is a bit more "complicated" then the Lockitron project as this requires you to replace your lock where the Lockitron is something you place over your existing lock.

It looks like a trend to create a cool video to promote the products of a startup and both August and Goij are not an exception to this.

Here you can see the video from August:


And we have a video from Goij


Goij is adding some nice features which are not seen with August or with Lockitron in the form of messages you can display on your lock. Again with both products, it is not clear if there will be an API available. In my opinion providing an API with products like this should be always included. This will enable developers with options to build upon cool products and ensure it is more included within other products.

As we see more and more connected devices coming to the market and all have there own mobile application this makes that you will have a large amount of applications on your mobile device, one to control your lock, one to control you music, one to control your shades, one to control,....... in a more ideal setup you have one application to control all you connected devices in your house to ensure you are not overloaded with different applications on your mobile device.

Saturday, July 20, 2013

Sonte window film

For some reason curtains are something that troubles a lot of people. It troubles some people because the have to pick them and some people it troubles because they have to make sure that hey are installed in front of the windows. Even though I am not a fan of curtains I can see the role they play in your house and that they provide some form of privacy and shielding the sun from time to time. However curtains are already taking a place in houses for hundreds of years and we have seen some "mild" improvements in them nothing to fancy has happend to them. That is at least in my opinion while a curtain specialist might differ from opinions with me.

However, now a startup company is providing a en way of thinking about curtains that is exciting me. A company called Sonte has produced a film which can be applied to your windows and can shield them and make them less transparant. The level of transparency can be adjusted to the situation and can even be controlled from a mobile device.



Sonte has started a kickstarter project to raise funding however for some, currently unknown, reason stopped the fundraising. Hopefully this is due to the fact they found one single company that is willing to invest into the Sonte window film.

What makes the idea from Sonte so exciting is that you will be able to controle your windows via a mobile app. This also should potentially give you the options to connect the Sonte window film to your home automation and add this to a more general way of controlling your house. Think about options where you can blind your house from remote, have it scheduled or make it reliant on the heat inside your house in combination with the location of the sun and the level of sunlight that is hitting your windows. We only have to hope that Sonte will include an API to its product that people will be able to build hooks into home automation solutions to control this from a more central console then only the Sonte applications.

Friday, July 19, 2013

WiFi doorlock

Not a new project or a new product for that matter. WiFi enabled doorlocks are already out there on the market for some time. However, Lockitron is having something cool and nice to it. Lockitron is growd funded project for the development of a wifi enabled lock, or more so, a wifi enabled part you can add to your already existing lock and helps you open and close it via your mobile phone or via a webportal. Next to this Lockitron is using bluetooth as a "near field communication" methode to open the door for you when you are close to the door.

Already other companies are producing WiFi enabled locks, take for example lockstate, the difference however with Lockitron is that lockstate is selling a full lock where Lockitron is providing a piece which you can add to your already existing lock.

Now the main question is if you want to put a WiFi enabled lock on your front door. There might be some security issues with that and I am not sure what insurance companies state about using such a lock. However, for a true tech lover I can imagine you want to play with such a solution and as it is not requiring you to change your lock it is a good way to start experimenting with such a locking device.



Fun thing is that when you start working with network enabled locks you can potentially add this to your full home automation solution. There are a lot of solutions in place to automate parts of your house, adding locks to this will in the future be something almost every house will have. This will also make that your phone becomes more and more important. We are already starting to pay with your phone, start the music in your house, controle you lighting and heating..... and within some time opening your doors with your phone will become very normal in my opinion.

keyless security,..... will Lockitron and the likes be the companies who are at the forefront of this new wave of connected things. I think doors will get a very well respected place in the internet of things. What I am missing at Lockitron, or I did not see it, is an API to add this to other services or get reports of your lock usage out of it. This would enable developers to create nice and cool new features for Lockitron where the current people of Lockitron might not even have thought about.

Wednesday, July 17, 2013

Oracle CEP, Hadoop and Oracle eBS

The internet has always been focussing around people, enabling people to find information on the internet was one of the first usages of the public internet next to sharing information via mail and newsgroups. The second phase was, also called WEB2.0, the sharing culture. The sharing culture is influenced by the uprising of social networks. In my opinion WEB2.0 is not about new technologies it is more about the way people think and interact with the internet and the social media that is available via the internet. Now we see a new trend coming, this trend is almost completely technology driven, it is the internet of things. Internet of things is about machines using the internet and especially using the network infrastructure of the internet.

With the internet of things phase of the internet you will see more and more equipment being connected to the internet. Your phone is quite obvious however also your music installation and your television are already connected to the internet most likely. Now your fridge, your microwave, your doorlocks, your scale and more will be connected to the internet. Some of those connections will be used to help you organize your life and make things easier. Some of those things will also help vendors create better products.

If we take for example the washing machine, your washing machine can be connected to the internet and send a tweet or other form of message to you to inform you that it is done and you can get your fresh clothing out of it. However, it can also server a purpose for the engineers building washing machine. For an engineering team it is very valuable to know how many times you use it a week, what the average load is, what program you are using. Next to this other things might be interesting to know, what is the average load put on top of a washing machine, what is the average temperature, air pressure and humidity in the room where the machine is standing. All this information can help an engineering team to build a better machine and spot possible solutions for a specific market segment based upon a geographical or demographic profile.

Building a board and connecting all sensors to measure those things is not the biggest hurdle, even if you are quite an amateur in electronics you will be able to build a device like that with ease with for example a RaspBerry Pi and some out of the box sensors from adafruit.com . Connecting it via the home wifi to the internet and have it broadcast valuable information back is also not the big issue. The main issue will be around two things.

Consider you are a large enterprise and thinking about shipping millions of your products and collecting data from that, your first issue will be storing this information in a certain way. The second issue is retracing this information and making it usable for future analysis. Future analysis can be in this case for multiple departments within your company, for example the marketing department, engineering department and your warranty and claims department.

What is interesting to me is especially the gathering and storing part. To be able to handle a hight flow of data and take correct actions on this and store this in a good way in your datastore you will have to have some sort of mechanism in place. First solution that comes to mind is writing the data to a large file in a line by line manner on a HDFS filesystem and then have it chunked into the correct format by a MapReduce algorithm. What however can be a great alternative before you write your data to HDFS is to use Oracle CEP to already look into the data and take action. Oracle CEP, or Complex Event Processing, formally known as WebLogic Event Server).

Oracle CEP is a Java server for the development and deployment of high-performance event driven applications. It is a lightweight Java application container based on Equinox OSGi, with shared services, including the Oracle CEP Service Engine, which provides a rich, declarative environment based on Oracle Continuous Query Language (Oracle CQL) - a query language based on SQL with added constructs that support streaming data - to improve the efficiency and effectiveness of managing business operations. Oracle CEP supports ultra-high throughput and microsecond latency using JRockit Real Time and provides Oracle CEP Visualizer and Oracle CEP IDE for Eclipse developer tooling for a complete real time end-to-end Java Event-Driven Architecture (EDA) development platform.

The below image is showing a deployment which is using Oracle CEP among with some other parts.


As you can see in the above image the washing machines are reporting the sensor readings to the Oracle CEP Stream Adapter. The Stream Adapter will in turn "stream" this into the CQL processor. What the CQL processor is doing in this setup is monitoring all incoming sensor readings. Most of the results will be passed directly to the HDFS storage where it will later be used by Hadoop to chop it into usable parts and fill the databases of the different departments. The big differentiator in this setup is however that by using the CEP approach is that when the CQL processor is detecting a fault in the washing machine, for example a broken part, it can call a Java Event Bean and in return the Java Event Bean can send a message to the ERP system that a repair is needed for a specific machine. If we take for example Oracle E-Business Suite we could send a trigger to Oracle E-Business Suite to spawn a service task and assign a specific service engineer to it. The service department then will inform the customer that something is broken and will, by using the correct modules in Oracle E-Business suite, plan the repair.

When the service engineer is done the machine can report, via the same way as all the sensor data is send, that the machine is correctly operating again and the service request can be closed via an automated approach.

This example is showing that by using machine-2-machine communication and by suing different technologies a company building products and a customer can benefit from reporting information directly. By implementing a Hadoop way of handling the enormous amounts of sensor reading we can ensure that every department is getting the data they need in there data-warehouse and are not overloaded with information. The above example is a very simple and very high level example, building a solution like this in the real-world is still a challenge and will need a large number of different skills however it can help a company and customers in many ways.

Saturday, July 06, 2013

Data Dimensions: Good governance in a big data world

Andy Cameron, the Capgemini head of Business Information Managent is talking in this video about big-data and also about the whole concept of data and data quality. Data is not always what people think it is, a bunch of numbers stored in a database. Data, when used in a correct way can mean the difference between success for your business or failure when interpreted in the wrong way. Also collecting data and storing this in other ways then companies are used to currently brings not only advantages. it also brings responsibility to ensure this data is secured and handled in the correct way with respect to the privacy of employees and customers.


We currently see an explosion in big-data and business intelligence requests and projects within companies. This is one of the reasons that companies will need more and more data scientists and mathematicians in the future then they need currently. A couple of years ago the term / role of data scientists was virtually none existing, today you see more and more demand for this role within enterprise size companies. Below is a infographic made by EMC2 which shows the future of the data scientist role.


The explosion in digital data, bandwidth, and processing power – combined with new tools for analyzing the data – has sparked massive interest in the field of data science. Organizations of all sizes are turning to people who are capable of translating this trove of data – created by mobile sensors, social media, surveillance, medical imaging, smart grids, and the like – into predictive insights that lead to business value. Despite the growing opportunity, demand for data scientists is outpacing the supply of talent and will do so for the next five years.


Thursday, July 04, 2013

Oracle Exadata turn on service led on disk

When working with an Oracle Exadata appliance you normally do not have to come close to the machine itself as with most servers. However in some cases a disk will be faulty and is in need of replacement. The Oracle exadata, depending on what "size" you have, will have a number of storage nodes available in the rack. Each node will have a number of disks in it. When you need to replace a broken disk with a new disk it can be quite handy to ensure you are removing the correct faulty disk and not a disk which is perfectly fine.  To help the people who will do the physical swapping of the disk there is a Service LED located on each disk which you can turn on or off. This will help the engineer to locate the correct disk without having the need to count disks and nodes.



To turn on, or to turn off, the Service LED on a disk you have to make use of the CellCLI. For example we are in need of turning the Sevice LED on for 3 disks we will use the following command:

CellCLI> alter physicaldisk  32:0,32:1,32:2 serviceled on

To disable the Service LED we use the following command:

CellCLI> alter physicaldisk  32:0,32:1,32:2 serviceled off

Tuesday, July 02, 2013

Oracle Enterprise Manager for hybrid cloud monitoring

Cloud computing comes in many forms, in some cases cloud computing is “just” another form of hosting and it is considered an IaaS (Infrastructure As A Service). In this cloud computing model some of your servers / systems will be located within the cloud of a cloud vendor. Amazon is a good example of this. By having your servers in one or more cloud and some (or none) located in your traditional datacenter you start creating a hybrid cloud model.

Having a hybrid cloud model provides you the options to make sue of the best of breed hosting options. This can be a big advantage however in some cases also brings a challenge. Even though everything can be hosted somewhere in a cloud you most likely would like to have a unified monitoring in place which gives you a holistic view of all your servers and services.

Monitoring capabilities, which provide you a holistic overview of your Enterprise IT assets are provided for Oracle products and none Oracle products by Oracle Enterprise Manager. Oracle Enterprise Manager provides you with options to monitor hardware and software within your Oracle landscape and also maintain it from the same console.

Oracle is providing a great, out of the box, solution when monitoring your on premise IT assets and it can even monitor in multiple datacenters when you have a dual or triple datacenter setup. However, in some cases you have servers running within the Amazon Web Service (AWS) hosting cloud. This is a trend that is seen more and more within the corporate world. Even though some of your servers are running at AWS you still want to include them in your default monitoring tool, Oracle Enterprise Manager and be able to monitor the complete hybrid cloud setup.



In the above example you can see how we leverage an already available tunnel between the enterprise datacenter and AWS to ensure that the OEM connection is secured and encrypted on a network layer. Connecting the datacenter and AWD in such a manner is common practice and when connecting Oracle Enterprise Manager to the servers in AWS you can leverage this tunnel to do so.

Oracle is providing a plugin for this in the Oracle Enterprise Manager extensibility exchange. This plugin is developed by Oracle to monitor the AWS services and by doing so provide you a single monitoring console.

  • Support for monitoring the following Amazon Web Services:
    • Amazon Elastic Block Store (EBS)
    • Amazon Elastic Compute Cloud (EC2)
    • Amazon Relational Database Service (RDS)
  • Rich and exhaustive list of metrics.  Metrics are collected remotely using the Amazon Web Services Cloudwatch API.
  • Detailed configuration information.
  • Custom Home Pages with charts and AWS configuration information.
  • Raise alerts based on thresholds set on monitoring data.

The plugin is available for Oracle Enterprise Manager 12.1.0.2.0 and later. More information can be found at the Oracle Enterprise Manager exchange website, the documentation can be found here.

Monday, July 01, 2013

Microsoft support for Hadoop opensource platform

Hadoop, the Apache opensource project is getting support from a unexpected direction. Microsoft is starting to support the opensource project.  The Apache Hadoop software library is a framework that allows for the distributed processing of large data sets across clusters of computers using simple programming models. It is designed to scale up from single servers to thousands of machines, each offering local computation and storage. Rather than rely on hardware to deliver high-availability, the library itself is designed to detect and handle failures at the application layer, so delivering a highly-available service on top of a cluster of computers, each of which may be prone to failures.



Quentin Clark, corporate VP of data platforms at Microsoft, stated "We believe Hadoop is the cornerstone of a sea change coming to all businesses" during his keynote during the Hadoop Summit.


Microsoft's data platform includes everything from its SQL Server database products to business intelligence (BI) features in Excel. In addition, playing well with Hadoop's open source community and leading Hadoop proponents like Hortonworks is a key component of Redmond's big data strategy. You can read more on this subject at informationweek.com

Tuesday, June 11, 2013

Zero Moment Of Truth for B2B

Some time ago I already discussed the new marketing concept from Google called ZMOT or Zero Moment Of Truth. The zero moment of truth is the moment where the customer is using the internet to find information about a product before purchasing it. making use of social media, search, reviews online etc. etc. to influence a purchase. In this post I discussed it primarily from a B2C point fo view. However, the ZMOT marketing approach is also applicable for B2B marketing als sales. You can find out more about this in the below video. One of the speakers in this Video is Sam Sebastian who is the Industry Director for B2B, Govt & Local Markets at Google.

Tuesday, May 28, 2013

Oracle e-Business suite notification mailer security


Oracle e-business suite makes use of workflows for the business processes. In some cases the workflows make use of the workflow notification mailer. This can for example be used to inform someone that a purchase order is pending approval and that this person needs to approve the purchase order can continue in the process. 

The workflow engine and the workflow notification mailer are great options in Oracle e-Business suite and is used for standard functionality and for custom workflows specifically created to tend to a companies need. 

There is however a security risk associated with the notification mailer. There is a SEND_ACCESS_KEY option. When you set this option to Y the mail generated and send to the user will contain a link with an access key in it. This will enable the user to directly access the notification in the system when clicked on the link. While this makes good sense from a user friendly point of view it is a bad thing when we look at it from a security point of view. 

People who intercept the mail or gain access to a mailbox will be able to click on the link and access the notification without the need to know the users username and/or password. 

For this reason it is highly advisable to set SEND_ACCESS_KEY to N. When set to N the user will receive a mail which contains a link which will not contain a access key and the user will be forced to enter his credentials before he can access the notification details page. 

Making the decision to put SEND_ACCESS_KEY to Y or to N is for some parts a business decision. How friendly do we want to make the system? In another part it is a security related question, “do we want to provide access to information without the need for authentication?”.

Advisable is to set SEND_ACCESS_KEY to N. 

Oracle adpatch security considerations


When patching an Oracle database you will make use of opatch ($ORACLE_HOME/OPatch) and when patching an Oracle application you will make use of adpatch ($AD_TOP/bin). When we look at the Oracle security best practices there are some advices around the use of adpatch which are not commonly know and are not commonly applied when maintaining an application. 

Main issue in regards to security in relation to adpatch is that when you apply a patch using adpatch the log file will contain the passwords you have used. When developing adpatch this might possibly have looked OK to the developers however in most cases this is very unwelcome. Having a clear text file on your filesystem which contains passwords is never a good thing and should be prevented. 

To ensure that the password is not stored in the logfile you can set a flag to prevent this. You will have to use adpatch flags=hidepw . When using this the passwords you provide to adpatch will not be shown in the log files. 

You should ensure that your Oracle application is only patched while using this flag to prevent someone from compromising the password when they gain access to the logfile. 

Tuesday, May 07, 2013

Perl use an array variable

Perl, as many other languages has a array variable type. Accoording to Wikipedia an array is the following in computer science: In computer science, an array type is a data type that is meant to describe a collection of elements (values or variables), each selected by one or more indices (identifying keys) that can be computed at run time by the program. Such a collection is usually called an array variable, array value, or simply array. The use of an array is a very effective way of storing variabels in something that is most comparable to a list of things.

In the below example we stored some of the names of a phonetic alphabet in the variable phonetic:

my @phonetic = ( "Alpha", "Bravo", "Charlie", "Delta" );

Now if we want to do something with it we can call the variable @phonetic however this would give you the entire collection of all values in the array. For example using the print command:

my @phonetic = ( "Alpha", "Bravo", "Charlie", "Delta" );

print @phonetic;

this would give you a result you most likely do not want, namely:
AlphaBravoCharlieDelta

As you can see this is printed without any space between it or a newline. Simply using all the values from the array in the print command at once. In many cases you would like to take all the values of the array one by one. In some cases, for example adding up all the numerical values in the array, you might want to use it in this way however in most cases you would like to loop value per value.

In the example below we loop the array and do a print for every value in the array.

my @phonetic = ( "Alpha", "Bravo", "Charlie", "Delta" );

foreach (@phonetic) {
 print $_ . "\n";
}

When running this example you will see that we do not get the result all in one line as was with direct print on the array. Now we will have a result as shown below;

Alpha
Bravo
Charlie
Delta

In some cases you would like to do an action on a certain value. Every value in an array has an index number (starting at 0). So lets say we want to print the value Charlie we have to call the array value with the index number 2. The below example will print the value "Charlie"

my @phonetic = ( "Alpha", "Bravo", "Charlie", "Delta" );

print @phonetic[2];

Sunday, May 05, 2013

A lot of people do read information online and use online resources when figuring out how to code solutions. Online a lot of great resources can be found to support developers. One thing a lot of people do not think about however is that there is, in my opinion, some moral duty to also share back. People who do use online resources for free and learn from it and even make profit with the gathered knowledge should also share back. When you do share information it is good to remember also how you as a consumer of information would like to read the information. When it comes to code for example it is nice to see a good formated piece of code.

When placing code online it is good to do this in a way that it is formated in a nice way so that reading the code is more easy. To help you with this task when blogging you can make use of the Google Code Prettify project. The Google Code Prettify project brings you support for syntax highlighting of code snippets in a web page. For example the code part below is done by making use of this.

class Voila {
public:
  // Voila
  static const string VOILA = "Voila";

  // will not interfere with embedded tags.
}

The Google Code Prettify project has a number of options for syntax highlighting for specific languages. You can find a list of them at the google code page. here you can also find ways on how to implement the Google Code Prettify solution on your blogger page and or your customer website.

Tuesday, April 09, 2013

Oracle database security blueprint against network attacks

Databases play a vital role in many current enterprise systems. They are commonly used to store vital, critical and confidential data about customers, finance, logistics and other operations within the company. Due to the central role a lot of database play in an overall architectural landscape of a company it can be expected that companies do take all measures to ensure the security of a database. Security can be seen from many different angles. For example availability is a security point which is often not considered to be part of security. When people talk about security in general they think about how to protect unwanted and unauthorised people from accessing a system or data.

When thinking about how to protect a system, a database in this case from being accessed by people who are not intended to a lot of people do think in the following order about security. User accounts, networking, applications, operating systems and then the rest. All are evenly important however thinking about security is something that needs to be taken very carefully. For example the network security is not simply placing a firewall between the database and the application server or directly to the rest of the world.

Below is a start of a blueprint which might help you to start your own database security blueprint. In this case we have taken a situation in which the database is used in combination with an application server which is connected to the public internet. A couple of things to remind, we only take network security as a topic in this blogpost and we do only think about security in a way to prevent users from attacking the database via the network to gain access. Meaning this rules out DDOS kind of attacks and this rules out any attacks on the application server (directly).

In the image below you can see the implementation of the blueprint for a database in a more then average secured landscape. This however is not yet considered a full secure architecture however is providing you security against a large number of the general attacks towards the database that might be undertaken on a web-facing application.



It is common practice for most companies to place web-facing application servers in a DMZ for security reasons. What is not common practice is that both firewalls should be of a different make and model. Reason for this is that if an attacker would be able to compromise the first firewall it would be very simple to hack the second DMZ-inside firewall when this was of the same make and model.

Next to this you can notice that the application server is attached to two different (V)lan's. Reason for this is that on the user (V)LAN you most likely only want to have one singel port open which is exactly the same port you will allow to be accessed from the outside world. Due to this setup it is important that you have at least two different NIC's. One NIC attached to the User VLAN and one attached to the application VLAN. On the application VLAN you can have more ports open then you will have on the  user VLAN. As you can see all servers in the above shown blueprint design are hardend by themselves by making also use from a local firewall. This means that even though you have firewalls available on network level you also have on every server a local firewall as an extra layer of security. On Linux servers you would use ipTables for this.

In your application design and your database schema and user design you have to already have to made sure most common security features are available. For example by making use of deep application boundary validation in your code which I already discussed in a previous blogpost.

On a more database security topic, in the blueprint design shown above you can see that the application server is not connected to the database server directly. Instead it is connected to the a database firewall server which sits in its own Oracle database firewall DMZ. The reason the Oracle database firewall is placed here is that all the other firewalls, also the Linux internal firewalls, are only there to protect against unauthorised network routing. Those firewalls simply state if a connection between 2 systems on a specified port is allowed. The Oracle database firewall is adding to this that it is checking the actual SQL statements that are executed. The Oracle database firewall is protection you against a potential attack via, for example, SQL injection. I have been discussing the Oracle database firewall in more detail in a previous blogpost.

The Oracle database firewall will be the point to which your application server will connect to like it is a normal database. The Oracle database firewall will check the statements it receive for a specific database against a whitelist of statements and if approved act as a "proxy" towards the database. This is shown in the below image from Oracle.



Now we have in place firewalls on the hosts protecting the hosts with IPtables. we also have firewalls in between the network segments and have separated the different network segments. We have also deployed a Oracle database firewall to ensure that not only the network traffic is controlled we have also ensured that the statements that are send to the database are valid and do not contain any statements that could be used to exploit the database.

As a last line of defence we use a technique that is less known even by most Oracle DBA's. We limit the hosts that can connect to the database on the database itself. In case someone is able to circumvent all firewalls and bypass the Oracle database firewall we have an option to state in the database instance itself which hosts can connect. A sort of whitelist of hosts, a sidenode to this is that you will have to add for example your application servers on this list and the Oracle database firewall. If someone gains access to a shell on those servers and starts a SQL session from this server it is considered valid. However it will hold back all the SQL sessions from IP's that are not in the whitelist.

To enable this valid node checking function you have to add some information to your $TNS_ADMIN/sqlnet.ora configuration. You have to change (add) the following to the file:

tcp.validnode_checking = YES
tcp.invited_nodes = ( X.X.X.X, hostname, ... )

Do note that if you do not add the IP's or hostnames of the machines your DBA is using they will also be unable to connect to the system. Adding the tcp.validnode_checking option to YES is in the security best practices of Oracle and should (in my opinion) be done always unless you have a very valid point to not do this.

A good thing to note is that if you use tcp.validnode_checking in an Oracle eBS setup this is supported by the autoconfig functionality. AutoConfig supports automated configuration of this setting. If the profile option “SQLNet Access” (FND_SQLNET_ACCESS) is set to “ALLOW_RESTRICTED” at the Site level when AutoConfig is run on the database server, AutoConfig will add IP restrictions to sqlnet.ora. The list of host will be all those from the FND_NODES table that are registered as an EBS node.

For more information, refer to MOS Note 387859.1: Using AutoConfig to Manage System Configurations with Oracle Applications Release 12 - or the Oracle Applications Concepts manual.

Friday, April 05, 2013

Cloud computing risk of data silo


Companies are more and more moving to the cloud. Cloud applications in the form of SaaS are getting more common in enterprises, hosting in the cloud in the form of DBaaS, PaaS or IaaS are getting more common by the day. I the"early" days of cloud computing companies who adopted where more small and medium businesses and startup companies. Now we see a move from enterprises towards the cloud. Large vendors are jumping on the cloud solutions and almost every day new cloud services and providers are seeing the light of day. The velocity of new companies getting created takes memories back to the days before the Internet bubble, maybe we are creating a cloud bubble at the moment.

However, we have seen that from a collapsing bubble also good things can come. When the Internet bubble collapsed the good where separated from the bad, this is something we might also see from a potential collapse of a potential cloud bubble.

Even though the cloud brings a lot of good there are some things to consider when moving to the cloud. I already discussed the legal implications of moving to the cloud in another blogpost. There are however more things to consider. One of the is related to a potential collapse of a cloud bubble. 

One of the things to consider next to the legal impact of cloud computing and the fact that your data might be hosted on a country that has a different legal system then the country where your company is located is the fact of data-silos. The risk of creating a data silo is on the agenda of a lot of the CIO's currently and it is indeed a potential risk of cloud computing.

When we talk about a data silo we talk about an cloud based application where we put in a lot of information however lacks the ability to extract this information. A large number of cloud based companies, and especially SaaS like companies do offer a great way of having your application in the cloud and provide you with options to enter information into this system. However the raw stored data is in most cases not accessible or in a very limited way. This makes that it is almost impossible to leave the cloud vendor and take your data with you to a new vendor. 

In cases where this is possible, based upon a contractual obligation or via build in functionality it often is a hard task to get the data in such a format that it is usable to be migrated to a new system. In cases where you have time to plan for a migration this is often costly however not impossible. In cases where this has to be done suddenly, for example due to a vendor that is bankrupt, you will not have the time to start a project for this. In those cases it might happen that you are unable to extract the data or extract it in a form that it is usable. 

It is good practice to check with your cloud vendor who is offering you a SaaS solution, or even a PaaS or IaaS solution, what your option are to access your data and what services are available to extract this. Next to this it is good practice to check with your vendor on what the rundown policy and exit clauses are in the contract in case the contract is ended and in case of a sudden bankruptcy. 

In an ideal situation your vendor has a escrow like mechanism in place for your data to ensure that your data is still available in case of a sudden bankruptcy. This will prevent you from data loss in such a situation, it will however not prevent you from service loss.

In case you want to extract your data during the contract period or at the end of a contract period it is ideal to have a mechanism in place for data extraction. Such a mechanism can be simple dump of all information in a pre-defined format, a direct coupling to the database holding your data or access to your data via an API.