Posts mit dem Label technology werden angezeigt. Alle Posts anzeigen
Posts mit dem Label technology werden angezeigt. Alle Posts anzeigen

Acquihires - Apple acquires someone's startup to extend own team




Apples's M&A strategy is different from the strategy of other internet gigants like Google, Microsoft or Facebook.

Timothy D. Cook, the company’s chief executive, has said in the past that Apple would have no problem paying billions for another company if it would help Apple make more high-quality products.

And that is exactly what they do. The very specialized companies get aquired by Apple if they can bring the need technology for the better products in the future.

In the most of the cases there are essentially tiny acquisitions where Apple buys someone's startup in order to get that person to work for them.

It seems to be a better strategy than so called big deals. The history of the tech industry is littered with big deals that turned out poorly. As example we could take the example from the year 2010 as Hewlett-Packard bought Palm. Or other example from the year 2012 as Google bought Motorola Mobility.

A lot of the tech acquisitions, in my opinion, have gone way off the tracks...

Apple bought the one-man company SnappyLabs this year and made the founder and electrical engineer Mr. Papandriopoulos a software engineer at Apple.The goal is an app development to make the iPhone’s camera take high-resolution photos at a faster frame rate.

But also other deals are made in an effort to quickly blend new technology into existing Apple products.

The acqui-hiring or a talent acquisition is the process of acquiring a company to recruit its employees, without necessarily showing an interest in its products and services (or their continued operation). Sometimes also called "being acqhired".

It is a new dimension of M&A and definitely an interesting one with a bright future!

Some more sources:
For Hints at Apple’s Plans, Read Its Shopping List
For Buyers of Web Start-Ups, Quest to Corral Young Talent

Read more

Predict fires in the cities by using big data


The best-known examples of big data implementations is the analysis of customers' behaviour enabling to support the customer during a buying process very effectively.

So I was very happy to read about the usage of big data increasing the proactive measures in fight against the fire in the cities.

Based on certain factors like neighbourhood income, age of the building, electrical issues etc. authorities in New York City can identify the critical buildings with high probability of fire.

In the mean time the NY fire department has defined about 60 of these factors and based on them a ranking buildings database has been created in order of their risk of fire and which ones should be inspected first.
Before this big data analysis the NY firefighters inspected with high-priority buildings like schools and libraries more frequently. But all other inspections were random.

The new system makes it possible to reduce the number of fires and make fires less severe, according to the fire department.

Although one thing stays difficult...
How to evaluate the impact, the results and merits of the big data approach to prevent injuries or fire.
Read more

EDI without Mapping



Our company offers B2B integration know-how that has been built up over 15 years - and deals with the entire process chain in EDI in different branches.

It does not matter in which part of industry, there is still the same challenge if two companies try to establish an electronic data interchange (EDI).

The most painful and costly step in the on-boarding process of a B2B integration are the mappings from one message to the message understandable by the enterprise applications (CRM, ERP, Business Intelligence, ...) of the particular business partner.

And it is not just one time operation (expense), every time the data structures in the enterprise has been changed the associated mappings have to be modified.

Another challenge is the dependency of the developed mappings to one translation tool, without any easy possibility to be ported into another translation tool. The mappings need to be rewritten completely new.

Wouldn’t it be possible to find a way to do B2B integration without having to manually develop any mappings?
Does it sounds like Sci-Fi to you? Not to me!

Just think about technologies behind such products like Siri, Shazam, Google Translator, OCR, IBM Watson, and many more.

In case of EDI we are talking about structured data based on identifier what the data fields in the source file map to the respective fields in a target structure.

One approach could be developing such an algorithm with enough sample data to test and optimize it until it reaches 99.999999% rate. Sort of "learning".

In my opinion the time is ripe and some products from different areas show us, what is actually possible today. So this type of transformation is certainly within reach!

... and the vendor that can master this challenge will have no competition. It will be possible to save a huge budget in B2B integration projects.

The one will be the winner!






Read more

Discrete Event Simulation - identity and state

In this post I would like to address some aspects of reactive programming before we can get a deeper insight in this topic.

On of problematic areas of maximal approach of concurrency are functions and stateful objects. The world is normally described as a set of objects, some of which have state that changes over the course of time.
An object has a state if its behavior is influenced by its history.

Second interesting area is the Identity of an object and its change. The new problem of deciding whether two expressions are “the same”.
This property is usually called referential transparency specifying what is meant by “thesame”
Objects x and y are operationally equivalent if no possible test can distinguish between them.

So it is not so difficult to proof the difference of two objects, however it is not so easy to offer an infinite variety of solutions to prove otherwise.

As example we can use The Discrete Event Simulation interactive programing we could describe using “Digital Circuits”



Let’s start with a small description language for digital circuits.
A digital circuit is composed of wires and of functional components.
Wires transport signals that are transformed by components.
Usually We represent signals using Boolean true and false.

The base components (gates) are:
  • The Inverter - whose output is the inverse of its input.
  • The AND Gate -  whose output is the conjunction of its inputs.
  • The OR Gate -, whose output is the disjunction of its inputs.


Other components can be constructed by combining these base components.
The components have a reaction time (or delay), i.e. their outputs don’t change immediately after a change to their inputs

All we have left to do now is to implement the Simulation trait.
The idea is to keep in every instance of the Simulation trait an agenda of actions to perform.
The agenda is a list of (simulated) events .
Each event consists of an action and the time when it must be produced.
The agenda list is sorted in such a way that the actions to be performed.  First are in the beginning.

Summary
State and assignments make our mental model of computation more complicated.
In particular, we lose referential transparency.
On the other hand, assignments allow us to formulate certain programs in an elegant way.

Example: Discrete Event Simulation.
  • Here, a system is represented by a mutable list of actions.
  • The effect of actions, when they’re called, change the state of objects and can also install other actions to be executed in the future.
Read more

What is Reactive Programming?



In the recent years the application requirements have changed dramatically. For the system integration based on cloud computing technologies, the change is more then obvious.

A few years ago a large application was built by tens of servers, used gigabytes of data, the response time was counted in seconds and the offline maintenance has been accepted.

Available technologies in cloud computing area have changed the rules. Applications are running cross the platforms from mobile devices to cloud-based clusters. We are talking about thousands of servers, using petabytes of data, with expected response times in milliseconds without any downtime.


A new system architectures have evolved to let developers conceptualize and build applications and frameworks that satisfy today’s demands - Reactive Applications.





All this is reason enough for me to look at this topic more in detail. I have subscribed to the online course “Principles of Reactive Programming” at Coursera.




Reactive Programming is the next evolution after the observer pattern. If you are currently using the observer pattern and are observing more than one thing then you will more than likely be seeing state bugs. Reactive Programming is a simple set of tools that manage state and therefore eliminate state bugs.




Reactive Applications should be capable to:

  • React to events: the event-driven nature enables the following qualities.
  • React to load: focus on scalability rather than single-user performance.
  • React to failure: build resilient systems with the ability to recover at all levels.
  • React to users: combine the above traits for an interactive user experience.

The relationships can be seen at the picture below:






What is the coolest thing?

This new paradigm enables us to develop application which scale from one mobile phone up to thousands of servers.

Read more

Threaded vs. Evented Concurency


In the time of cloud computing the question raises at our company about the exposed well-defined backend services. In the current architecture, the services spend most of their time calling other services and waiting on I/O. In the common praxis most server technologies rely on a thread pool to handle I/O. In the business integration area we are confronted with very high traffic environments and processes.

Typical usage of the thread pools can be hard to manage. Big thread pools cause a lot of overhead and small thread pools may get exhausted if there is a spike in latency or traffic.

There are two general approaches –Threaded and Evented



Most development teams are using Threaded approach: one thread is dedicated to each request, and that thread does all the processing for the request until a response is sent. Any I/O, such as a call to a remote service, is typically synchronous, which means the thread will become blocked and sit around idle until the I/O completes.

By contrast, Evented servers typically use only a single thread per CPU core. The idea is to ensure that these scarce threads are never blocked: all I/O is asynchronous, so instead of waiting, the thread can process other requests, and only come back to the current one when the response from the I/O call is ready.

Threaded vs. Evented performance


Threads are resource-devouring and have significant memory overhead (e.g. default stack size for a single thread is 1MB on a 64bit JVM) and context switching overhead (e.g. saving register state, loading register state, impact on CPU cache/pipeline, lock contention). Creating threads on the fly tends to be expensive, so most servers use a fixed thread pool.

Therefore, the crucial parameter of Threaded servers is the size of the thread pool. If there are not enough threads, it’s easy for all of them to become tied up waiting for I/O, preventing any new requests from being processed even though most of your threads are just idly waiting. If the thread pool is too big and there are too many threads, the extra memory usage and context switching overhead become very costly. The right size of thread pool is practically impossible.

On Evented servers, waiting for I/O is very cheap: the actors are lightweight and consume about 600 bytes memory. Idle requests have negligible cost, as they don’t hold up an OS thread. It is very tempting to use evented servers to be able to handle far more concurrent requests than Threaded servers so.

But be careful! Even a single long calculation or accidental blocking I/O call can bring an Evented server to its knees!

Resources:

http://engineering.linkedin.com/play/play-framework-async-io-without-thread-pool-and-callback-hell

http://akka.io/

http://www.playframework.com





Read more

How services live forever in the Cloud

The self-service cluster-based service (CBS) is becoming more and more popular. For the CBSs vendors it is therefore all the more important to have a comprehensive reliable concept that, in addition to preventive protection measures, also contains methods for back-up and disaster recovery.

In this post I would like to concentrate on one aspect of the cloud-based infrastructure – cluster management.

Cluster management addresses the complexity of handling a dynamic, large-scale system with many servers. Such systems must handle software and hardware failures, setup tasks such as bootstrapping data, and operational issues such as data placement, load balancing, planned upgrades, and cluster expansion.



Frameworks like Apache Helix provide an abstraction for a system developer to separate coordination and management tasks from component functional tasks of a distributed system.



The term Cluster Management is a broad one. Therefore I will set of common tasks required to

run and maintain such infrastructure. These tasks are:


Resource management:The resource (database, index, etc.) of the cloud-service provides must be divided among different nodes in the cluster.
Fault tolerance:The CBS must continue to function amid node failures, including not losing data and maintaining read and writes availability.
Elasticity:As workloads grow, clusters must grow to meet increased demand by adding more nodes. The CBS resources must be redistributed appropriately across the new nodes.
Monitoring:The cluster must be monitored, both for component failures that affect fault tolerance, and for various health metrics such as load imbalance and SLA misses that affect performance. Monitoring requires follow up action, such as re-replicating lost data or re-balancing data across nodes.



There are different the system-specific models of behavior. Before we will take a look at a formal language for defining a finite state machine behavior, I would like to introduce the basic terminology for it.

NodeA single machine.
ClusterA collection of nodes, usually within a single data center, that operates collectively and constitutes the CBS.
ResourceA logical entity defined by and whose purpose is specific to the CBS.
(Examples are a database, application server, or communication system.)
PartitionA partition is a subset of the resource.Resources are often too large or must support too high a request rate to maintain them in their entirety, but instead are broken into pieces.The manner in which the resource is broken is system-specific; one common approach for a database is to horizontally partition it and assign records to partitions by hashing on their keys.
ReplicaFor reliability and performance, CBSs usually maintain multiple copies of each partition, stored on different nodes.
Copies of the same partition are known as replicas.
StateThe status of a partition replica in a CBS. A finite state machine defines all possible states of the system and the transitions between them. We also consider a partitions' state to be the set of states of all of its replicas.
TransitionA CBS-defined action specified in a finite state machine that lets a replica move from one state to another.



Example:

Formal language for defining Finite State Machine:

Each resource has a set of partitions P

each partition piϵP has a replica set R(pi), RX(pi) is the subset of R(pi) in state X,

and RT(pi) is the subset of R(pi) undergoing transition T.



A finite state machine has sufficient expressiveness for a system to describe, at a partition granularity, all its valid states and all legal state transitions:



On the diagram above you can see a graphical example of the cluster management in the event of the failure of the Node 3.

The cluster consists of different nodes (Node1 – Node4). For this cluster is in this case just one Resource defined, let’s say some database. The Resource is broken into more pieces – so called Partitions.

Each partition has two Replicas (Master/Slave). From the color of Replicas can be recognized on which node the particular Replica is running. For example on the Node 2 are Replicas R1.2 and R2.1 running. Only one Replica per partition on each node is allowed.

In the event of a failure of one Node, the system continues working without interruption and data loss. In this example the Node 2 crashed and it means that Replicas R2.1 and R3.2 are not available anymore.

The cluster management takes the formal declaration of the automated behavior see in the diagram.

At first the rule will be applied that every partition has at most one master. It means the Replica R2.2 change the state from Slave to Master.

As second the next rule will be applied that every partition has at least one slave. So the Slave Replicas R2.1 and R3.2 will be created on other Nodes.

Please note that the Replica R3.2 cannot be created on the Node 2 because of the last rule: At most one replica per partition on each mode is allowed!

The text and illustrations represented in these very simplified examples are of complex cluster management. This post should present the first introduction and overview about this complex topic.

References:

  • Untangling Cluster Management With Helix. In SoCC’12

  • LinkedIn Data Infrastructure Team. Data infrastructure at LinkedIn. In ICDE, 2012.

  • helix.incubator.apache.org/
Read more

New cloud-based hacking service can crack VPN passwords within 20 hours

As example of a leverage power of cloud-based services can be mentioned the twitter message we have posted today:

https://twitter.com/reanvent/status/229923837465198593

The advantages of the scalability of such services and the low costs oriented by "pay as you go" can be used to attack an keys, passwords and networks at companies or at private users.

To demonstrate how it works, we would like to describe the possible handling of such attacks. As example I would like to use the example of CloudCracker Service.
The online form of the service looks like:



How the fields in the form have to be filled can be found bellow.

How do I submit a WPA/WPA2 Job?
In order to submit a WPA/WPA2 job for processing, you'll need to capture a WPA handshake for the network you're interested in cracking. There are many publicly available tools for acquiring a network handshake such as aircrack-ng, along with online tutorials for how to use them.

Once you've gotten a network capture, simply submit the .cap (or .pcap) file along with the SSID/ESSID of the network. If your network capture is greater than 5MB, you'll have to reduce it by stripping out the handshakes. On Linux, you can use the script here to do this.

How do I submit a LM/NTLM Job?
Submit a file containing the LM or NTLM hashes you'd like to crack, formatted as a PWDUMP file. PWDUMP files are formatted as:
<user_name>:<user_id>:<lm_hash>:<ntlm_hash>:<comment>:<home_directory>:

For example, a file with two NTLM hashes might look like this:
moxie:1000:NO PASSWORD*********************:55BB1BF7C3668EE1C23D74B4C5686C1E:::
geoff:1001:NO PASSWORD*********************:CCA5A5F729D79D8DDC67524C286C126A:::

Or a file with two LM hashes would look like this:
moxie:1000:9224FC255C58C50EAAD3B435B51404EE:87F65D137998A4CE59EA65B114A0F831:::
geoff:1001:9224FC255C58C50E93E28745B8BF4BA6:A4CC3E6ADACEB79EBE88AAFDEA4B97CD:::



Sources:
http://www.zdnet.com/blog/btl/new-cloud-based-hacking-service-can-crack-wi-fi-passwords-in-20-minutes/28224
https://www.cloudcracker.com/
http://www.heise.de/security/meldung/Cloud-Dienst-knackt-VPN-Passwoerter-in-24-Stunden-1654958.html
Read more