Monday, April 26, 2010

CTOEdge: Crosscheck Models Cloud Computing Performance

"One of the biggest problems with cloud computing is that IT organizations are hesitant to move an application into the cloud when they don’t know what to expect in terms of performance.  Crosscheck Networks intends to help IT organizations overcome that uncertainty with a new modeling tool for cloud computing called CloudPort. " Mike Vizard, CTOEdge
For complete article, see: http://www.ctoedge.com/content/crosscheck-models-cloud-computing-performance


 

Monday, April 12, 2010

SOA-Cloud Testing: CloudPort simulates data-center to cloud migrations

In the absence of quantifiable data, enterprises are challenged to make well-informed choices when it comes to migrating to the cloud.  Instead, they often find themselves forced to make these strategic decisions based on ad-hoc or partial information.  This is a risky and unproductive approach, especially when typical migration process requires moving numerous components -- including databases, application servers, ESBs, identity stores, and BEPL orchestration engines -- to the cloud.  Once a full reference system is deployed, the behavior of the enterprise applications interacting with the cloud-based components must be tested -- using customized production code.  This is an expensive, time-consuming and potentially error-prone proposition.

With CloudPort, enterprises benefit by never having to touch production code -- while eliminating the substantial time, capital and IT staff resource expenses related to building a distinct cloud test environment.

For further information, see SD Times article:
http://www.sdtimes.com/link/34249

For details on CloudPort, see:
http://www.crosschecknet.com/products/cloudport.php

Monday, March 29, 2010

The modern XML Gateway appliance: from acceleration to integration an into the cloud

XML appliances, a core component of IT deployments, process XML-based information including SOAP and REST messages.   In the early 2000s, the first phase of XML appliances focused on providing security at the enterprise edge where traditional firewalls could not prevent against XML-based threats.  As XML adoption increased, accelerating XML traffic that is typically bloated and verbose became a requirement.  This is where companies such as Forum Systems pioneered the first XML appliance with acceleration, security, and threat mitigation functionality.  Forum Systems was granted a patent for XML Appliances in 2009 for its visionary work in XML security, acceleration and threat mitigation.

The second stage of XML Appliance evolution was to add significant support for the enterprise ecosystem; including transport protocol support - required for moving messages around; identity management support - required for interact with existing identity management solutions for authentication and authorization decisions; and monitoring and governance support - for enterprise-level management and monitoring of appliances and transaction flow.

Almost a decade later, XML appliances are now in the eye-of-the-storm again.  As enterprise build private clouds and off-load commodity functions to public clouds, XML appliance are serving a critical part in acting as an enterprise-to-cloud gateway.  Since its inception, XML appliances have been used for controlling and securing enterprise-to-SaaS interaction.  This XML Appliance function has now evolved  to controlling enterprise-to-IaaS (Infrastructure as a Service) interaction.  For more about XML appliances see:

http://searchsoa.techtarget.com/news/article/0,289142,sid26_gci1445628,00.html

Monday, February 22, 2010

Customer Case Study: SOA and Cloud in 2010 - Talking with Crosscheck and Omega Financial

Insightful podcast by Jessica Ann Mola, Managing Editor at eBizQ with John Woolbrigth, CIO of Omega Financials and former CTO of Synovus Financial and Mamoon Yunus, CEO of Crosscheck Networks that explores the following items:

  • Defining cloud computing. Are SOA and cloud synonymous?
  • Pre-requisites and barriers to enabling cloud computing in an enterprise IT infrastructure.
  • Impact of current economic climate as hurting or helping cloud/SOA adoption.
  • Architectural moving parts necessary for building SOA.
  • Real-life, high-scale SOA and cloud-based deployments.
"Cloud and SOA are not really synonymous; they're more supportive of each other...SOA enables cloud computing." - Mamoon Yunus

"There are three or four things that can get you to a place to take advantage of cloud computing..." - John Woolbright

eBizQ: SOA and Cloud in 2010: Talking with Crosscheck and Omega Financial

Monday, February 01, 2010

Tale of Two XML Gateways

Here's an interesting article on XML Gateways, their use in SOA deployments, and a comparison between hardware, software and cloud-based form factors.  SOA Tester have to be cognizant of identity, encryption, and signature artifacts that are consumed and generated by XML Gateways so as to build proper test cases for comprehensive end-to-end SOA testing.

Tale of Two XML Gateways
— These days XML Gateways are a core infrastructure component of any enterprise SOA deployment. XML Gateways provide the ability to integrate services securely with granular access control, data-level encryption, integrity through signatures and XML threat mitigation. XML Gateways can be deployed as a hardware appliance or as a software gateway. Both these form factors have their advantages and disadvantages. This article provides readers a quick synopsis of the advantages and disadvantages of each form factor.

Monday, January 25, 2010

XML Threat and Trust Modeling and Testing

Understanding XML Threat and Trust models enables SOA testing and QA professionals to build robust test suites that verify functional, performance, interoperability and security profiles of Web services.  SOA testing has to cover a XML identity tokens, XML signature generation and verification, and XML encryption-decryption to establish trust.  The test suites have to ensure that trust-based artifacts are scalable and interoperable.  In addition to testing such trust-based artifacts, SOA testers have to ensure that the web services have threat mitigation in place against threats such as SQL Injection, Denial of Service attacks and Malware threats over SOAP and XML traffic.

Here is an article published on XML Threat and Trust Models:

XML Security Trust and Threat Models for Dummies
— It is very rare today to find a business application that has not exposed its interface via SOAP/XML. XML is the building block that enables business or consumer applications to exchange data in a standard structured format. The exchange of XML data typically takes place through an SOAP/XML interface based on the Web Services standard or through the REST-based standard. These flexible standards that richly describe interface functions of an application also introduce a host of XML and Web Services security vulnerabilities. This article is a quick start guide to most common XML and Web Services security vulnerabilities and the two basic security models they follow.
Full Article: XML Security Trust and Threat Models for Dummies

Tuesday, January 19, 2010

Forum Systems joins Cloud Security Alliance

BOSTON--Forum Systems, a wholly owned subsidiary of Crosscheck Networks, Inc., today announced that it has joined the Cloud Security Alliance to help further the organization’s efforts in the areas of data security, privacy and integrity best practices. An early sponsor of the Cloud Security Alliance, Forum Systems recognized the fundamental need in providing security assurance within cloud computing environments. As a Cloud Security Alliance Corporate Member, Forum Systems advocates that enterprises must first establish secure XML, SOAP and REST-based transactions before implementing their cloud-based initiatives.

Read Full Description >>

Friday, January 15, 2010

Strategies for Securing Enterprise-to-Cloud Communication

Extending corporate boundaries to cloud infrastructure providers requires focused review of security practises used to integrate from the enterprise DMZ to external trading partners.  Here is an article that covers Enterprise-to-Cloud communications issues and how best to prepare from them.  SOA Testing and XML Gateway play an intergral part in ensuring that the security provisions are well tested and strictly enfored while interacting with cloud providers.

Strategies for Securing Enterprise-to-Cloud Communication
— The Cloud Security Alliance (CSA) published Version 2.1 of its Guidance for Critical Areas of Focus in Cloud Computing with a significant and comprehensive set of recommendations that enterprises should incorporate within their security best practices if they are to use cloud computing in a meaningful way. The Guidance provides broad recommendations on operational security concerns including application security, encryption & key management, and identity & access management. In this article, we will consider security implications of REST- and SOAP-based communication between consumers and specifically, Infrastructure as a Service (IaaS) providers.

Thursday, January 07, 2010

Federated SOA impacts SOA Testing

Comprehensive SOA testing, using commercial and mature products such as SOAPSonar from Crosscheck Networks, is critical for companies as they expand beyond their localized SOA domains and integrate with SaaS, PaaS, and IaaS providers to build a Federated SOA.  Here's an article that highlights the relationship between Federated SOA and Cloud Computing.

Federated SOA: A Pre-requisite for Enterprise Cloud Computing
— Successful enterprise SOA implementations build on a set of localized, project-level efforts with services that have clearly identified and accountable business and technology owners. Ownerships defines a SOA Domain. SOA domains may exist within corporate boundaries or may be provided as services by third parties. Deciding what services are core to a business owner and should be implemented within her/his domain versus consumed from another SOA domain becomes a critical part of building Federated SOA. Understanding core capabilities provided by SOA domains is a crucial task at the enterprise-level for encouraging efficiency through re-use and for keeping focus on core business services.

As SOA domains mature, key issues arise in enabling "SOA Domain Jumping," -- easily and rapidly integrating with other SOA domains. Here are the top three Federated SOA requirements that corporations must first address before embarking on a meaningful and sustained cloud computing deployment.

Monday, January 04, 2010

Hidden Cost of Open Source SOA Testing Tools

Here is an interesting article that appeared on sys-con regarding the hidden costs associated with using open source frameworks for SOA Testing.  Corporate business process security, interoperability and scalability may depend on the kind of tools one chooses for testing services and may significantly contribute to the overall success a company's ability to safely add a growing number of business partners to its ecosystem.

Hidden Cost of Open Source SOA Testing
— Adopting an open source tool for SOA testing seems the simplest, most cost effective choice for developers and testers early on. However, you should plan and consider the implications of a longer term strategy with an open source testing tool. There are many aspects of service testing that contribute to a comprehensive solution across the SOA life cycle. Adopting a specialized tool for service testing is essential and will provide value, but may prove limiting if the adoption of the testing tool becomes something that can not grow with the business and maturity of your SOA strategy. This article will discuss some topics to consider before jumping headlong into an open source free testing solution for your production services.

Friday, January 01, 2010

Service virtualization and its effect on SOA Testing

The is article discusses the advantages of using service virtualization whereby, in the simplest case, you may import a number of WSDLs, aggregate them and then expose them via and XML Gateway, such as Forum Sentry, based on the credential presented.  The impact of service virtualization on SOA testing is significant:

  • Remote services have to be tested independently.
  • Aggregated WSDL need to be tested.
  • User specific WSDLs generated by the Cloud/XML gateway have to tested.
  • The difference between gateway-generated services has to be reconciled with the remote services.
  • Identity tokens have to be generated for both remote services as well as the gateway to ensuring that the right authentication and authorization decisions are being enforced on the gateway.
References:
  1. Virtues of Service Virtualization in a Cloud
  2. XML Gateway:  Forum Systems

Monday, December 28, 2009

MIT Techology Review covers "Swamp Computing" a.k.a. Cloud Computing

XML/SOA Testing of XML Security Policies (XML Encryption, XML Signatures) will become the centerpiece of Cloud-based deployments that are multi-tenant in nature and can inadvertently expose corporate information.

MIT Technology Review published an interesting article sumarized under MIT Technolgy Review covers "Swamp Computing"

Tuesday, December 22, 2009

Reducing the Complexity of Application Security

Integration is the Enemy of Security and so is Flexibility - an attribute that is essential for organizations to survive.  A corporation that cannot service its customers and suppliers, establish long sticky relationships with them and build an infrastruture that enables rapid addition of both suppliers, buyers and partners for information exchange will perish and get demolished by a nimble and flexible competitor whose infrastructure has integration capabilities for rapid information exchange.

Mike Vizard from CTOEdge talks about the business drivers that compel companies to integrate yet face security challenges that hamper integration efforts: Reducing the Complexity of Application Security

Here's a snippet from Mike's article:
"As business-to-business interactions over the Web become more pervasive, so too does the complexity associated with securing those transactions.
Unfortunately, all that complexity serves only to dissuade businesses from integrating business processes across the Web at a time when we want to encourage that behavior. So the challenge facing chief technologists is to find a way to make it simpler to integrate business processes without having to introduce complex layers of security."
Key components that help reduce (and improve) application security include:
  1. Strong SOA Governance Enforecement, Monitoring and Security through XML Gateway such as Forum Sentry.
  2. Portal and Web services Authentication and Authorization decisions through Secure Token Services such as Forum Sentry STS - Identity Broker.
  3. Application Security Testing and Simulation through products such as SOAPSonar and SOAPSimulator for Identity, Privacy, Integrity and Penetration Testing.

Thursday, December 17, 2009

Software Magazine: Crosscheck Networks SOAPSimulator adds JMS support

Service Simulation is and essential component for end-to-end SOA Testing.  Software Magazine recently published an article on SOAPSimulator, the only stand-alone service simulation product in the market for simulating Web services, XML, REST and SOAP.

A new version of SOAPSimulator from Crosscheck Networks, the company focused on products supporting reliable Web services, adds the ability to test large attachments via IBM MQ, Tibco EMS, WebLogic JMS and native Java Messaging Services adapters...read more>

Tuesday, December 15, 2009

SOAPSonar - QTP Job Posting

The maturity of a market and a product can be judged by the related job postings. Much has been written and talked about SOA Testing, however, this data point -- A job posting looking for a Testing and Automation Professional -- validates three key trends:

  1. The number of QA Professionals focusing on SOA Testing within an enterprise has hit a point where having SOA Test Tools, such as SOAPSonar from Crosscheck Networks, alone is not sufficient. A centralized defect tracking and test cases management infrastructure such as HP Quality Center is necessary for efficient collaboration. Incidentally, SOAPSonar is HP EMAP certified with deep integration with QC v10. For details on their integration see SOAPSonar EMAP Certification.
  2. SOA Testing Skill sets are far along the comoditization trajectory with job positions not just in the US but offshore as well. This particular job posting is in Banglore, India.
  3. SOA Testing requires complex skill sets including XML, SOAP, REST, WSDL, Database, Java, Message Queues, Automation Scripting, as well as fundamental Testing Techniques such as Black Box, White Box and Grey Box testing. The skill requirements will trend towards greater complexity as more IT assets are exposed using Web services and integrated with the SOA fabric.
SOA Testing Professionals will evolve as into high skilled individuals with diverse skills that touch almost all IT assets from networking to applications within and across enterprise boundaries. UI, Database and Application Testers will have to expand beyond their domains to keep up with the demands of SOA Testing.

Monday, December 14, 2009

Gartner AADI SOA Testing Sessions

It was exciting to see the extent of interest and coverage on SOA Testing at the Gartner Application Architecture, Development and Integration (AADI) event in Las Vegas last week (December 7-9th). SOA Testing has become an integral part of Enterprise Application Life cycle Management and Thomas Murphy, Research Director at Gartner did a great job in covering the core aspects of SOA Testing at the show is the following session:

SOA Testing: Confronting the Nightmare of Testing Shared Services: The Key Issues that were covered included:

  • How will application testing and quality be affected by the shift to SOA and Web 2.0 technologies?
  • What metrics will be effective at driving improvement and assessing the efforts of those collaboratively performing the development and testing of software services?
  • Which tools will provide the best productivity and understanding of software quality and testing for the current and future SOA applications and platforms?

For more details about the SOA Testing Sessions at Gartner, click here.

Thursday, December 10, 2009

SOA Appliance for Cloud Computing

Building a robust SOA is a pre-requisite to cloud computing. Without solid provisions for SOA Testing, SOA Governance, and Federated SOA, large enterprises will unlikely embark on cloud computing initiatives that truly span Infrastructure as a Service (IaaS), Platform as a Services (PaaS), or Software as Service (SaaS).

The article below shows one of the core building blocks required for an enterprise SOA deployments - Identity Management and Enforcement. Forum Systems has recently announced Forum STS - a SOA Appliance that enables Cloud computing by managing identities within and across SOA domains. For more details, see article published by Liz McMillan:
SOA Appliance for Cloud Computing
— Web services-based Service Oriented Architectures (SOA) enable communication via ubiquitous standards such as XML and SOAP. To foster efficient, effective message exchange and satisfy increasing user demands for real-time, aggregated information from internal and external business partners, trust must be established among all entities. Comprehensive mediation, authentication, and authorization of identity exchange among customer and partner portals, Web applications, and XML-based Web services provide the business with a simplified, coherent model for identity management and build the pillars of Federated SOA.

Friday, November 13, 2009

SOA Testing in a Federated SOA environment

According to Massimo Pezzini, VP and Gartner Fellow, "Federated SOA is a systematic approach to large-scale, enterprise wide SOA that enables organizations to integrate semi-independent SOA initiatives. Often used to fix an initial lack of coordination, federated SOA should be proactively pursued from the inception of major, strategic SOA initiatives." -- Divide and Conquer: Taming Complexity Through Federated SOA.

The technology implication of Federated SOA has pushed towards a convergence of XML/Web services with HTML/Portal technologies. This has a significant impact on industry expectations on SOA Testing Tools, B2B Gateways, Application Servers and XML Gateways. For example, the latest announcement by Forum Systems, the leader in XML Gateway technology, indicates a move towards Federated SOA. See:


Continuing to set the benchmark for securing Web services, key new capabilities available via Forum Sentry include:
  • HTML Portal Virtualization – Deployed in a “proxy” setting, Forum Sentry removes the identity and security burden from Web sites and portals. Leveraging Single Sign On (SSO) functionality across existing infrastructures, Forum Sentry’s non-intrusive, agent-less design accelerates security and identity on a dedicated device – without requiring code changes to back-end Web applications and services, or additional capital expenditure costs.
  • Central Cookie and SAML Processing – Forum Sentry authenticates and authorizes both portal- and Web services-related identity tokens – the cornerstones of Federated SOA. Credentials are shared – regardless of where the services reside – throughout the entire transaction, producing an enhanced, seamless user experience without compromising security.
  • Federated Two-Factor Authentication – Promoting greater security, Forum Sentry requires two pieces of information for identity verification of internal and external partners. It removes the complexities so often associated with token sharing across portals and Web services, while still enforcing the highest levels of authentication and authorization.
  • Protocol/Document Attribute Mapping – Promoting greater ease of use, HTTP/HTML header information can be mapped into messages and documents. User information from HTTP can be transferred into a SOAP or XML message for usage elsewhere in the network – independent of protocol – enabling SOA Federation across both XML and HTML traffic.
The impact of transactional components such as Forum Sentry towards Federated SOA means that testing, monitoring and diagnostic tools now need to converge towards handling not just XML/WS traffic, but also provide the ability to test the HTTP stack as well. This is a natural fit for XML/SOA Testing vendors such as Crosscheck Networks since their core focus has been deeper in the packets in parsing and manipulating complex XML data. Floating up from the deep packet manipulation to the shallow HTTP header testing and manipulation is a simpler task that SOA testing products such as SOAPSonar are very capable of handling.

Monday, November 02, 2009

Federated SOA essential aspects: SOA Testing, SOA Identity and SOA Security

Here is an interesting article by Rob Barry titled: "In SOA, cloud resources may exacerbate security and file transfers issues." It highlights significant requirements for Federated SOA especially around large file transfer using Web services attachments. The article makes the following interesting points:


  • Attachment sizes are increasing driven by cloud computing such as transferring large files to Amazon S3 or a companies internal cloud.
  • MTOM and MIME are used now for real time file transfer over web services instead of FTP or classic MFT protocols.
  • Identity is critical to Federated SOA.
Standards such as MIME and MTOM are now being heavily deployed. For a deeper understanding regarding how MTOM works, see "Intro to MTOM."



Thursday, October 22, 2009

Techniques in Attacking and Defending SOA-XML-Web Services

At OWASP AppSec, Washington, DC, Crosscheck Networks will present a session titled, “Techniques in Attacking and Defending XML/Web Services.” This session will examine the strategies in identifying new attack vectors and classifying security threats, including SQL Injection, Denial of Service (DoS) and XSD Mutation. Additionally, the Crosscheck Networks senior executives will offer countermeasure best practices to mitigate the risk of, and exposure to, those identified XML security threats.
To register, click here.