Showing posts with label Azure. Show all posts
Showing posts with label Azure. Show all posts

Thursday, 25 January 2018

Google puts a SOC in it

Google X

So Google (or Alphabet as the parent is now called) has announced today that they are joining the SOC market with proactive security defence based on capture and analysis of events.

This has come out of their X projects division which aims to rapidly develop new breakthrough products.

What's Google Planning?

Presumably Google aims to provide Machine Learning based measures capitalising on the scale of its services and analysis across customer environments hosted on its GCS platforms. This should give it certain predictive advantages, enabling it to home in on certain types of attack.

What would be good to know is how will Google differentiate between poorly configured devices, failing devices and real attacks. As many APT style in infiltrations will mimick poor configuration and failures to disguise their intents. Also what will they be doing around major incident management, remediation and forensics to provide a complete service?

Details are thin on the ground so far and this is bound to spur me too imitations from AWS and Azure.

SOC Fundamentals still Apply

However, as ever the fundamentals for a working SOC will remain:

  • You need to know what assets you are managing and keep CMS/CMDB accurate, complete and up to date;
  • As far as is practicable, ensure that all assets are implemented with standard configurations, to avoid mis-configuration and creating the noise in which APT infiltration can hide;
  • Use automation and software as infrastructure to implement standardised asset configurations and maintain patching up to date;
  • Then deploy logging, automated monitoring and analysis;
  • Invest in remediation and incident management capability;
  • Use scenario planning and practice exercises to ensure that there are no gaps and you are prepared for problems.

What Else is Google Doing?

The SOC services are only part of the offering. The new business unit called Chronicle will also be offering threat intelligence and products from its VirusTotal acquisition.

Thursday, 28 December 2017

2018 in Digital

Recently, the UK budget was set with a few old fashioned measures for increasing productivity, Investment in Infrastructure and More Money for Apprenticeships.

I then read someone's blog which suggested that this had missed the mark. His premise was that investment in technology usually fails and there is a need to continue to emphasise other traditional business change and simplicity measures such as clear strategic leadership, process design and email de-cluttering. He produced statistics to show that e-mail costs more than the UK's contributions to the EU's budget. Although I thought that this particular commentary missed the disasters caused by poor collaboration by business leaders and the failure to work together as a unified team.

At the same time, a commentary in Forbes suggested that 2018 will be the year of software automation with a sudden increase in the trading of enterprise data sets and a huge increase in the number of data scientists. Although the breaks to this are whether data sets are considered valuable IPR and the need to train up a lot more people in aspects of data science.

Contino and Gartner have identified 2018 as the year of DevOps with DevOps driving Agile (Gartner) and increasing competition between Platform Vendor services between AWS, GCS and Azure as well as the new wild card entry AliBaba. Interestingly, growth rates for all of these services are in the 50-90% p.a. area. Contino also mentioned that there are many new developments not just in the area of containerisation and serverless computing, but also in improved cloud security via projects such as Calico.

Surprisingly, given the recent frenzies, most commentators were muted on the impact of AI and Machine learning. Likewise, no one bothered to mention the rapidly maturing area of wearable technology or the new promises that quantum computing may at last start to deliver.

Overall, the impression is of Lean Digital becoming mainstream whilst other post digital technologies gradually insinuate themselves into leading edge enterprises.

Thursday, 6 April 2017

Artificial Intelligence and Other Tales

Engineers at Google recently published a paper outlining their work developing a custom AI chip which is so efficient that it saved them having to build new data centres to cope with the introduction of AI based services. The paper itself provided a great insight into the scale and nature of Google's operations. However, it was the catalyst for musing on where we are going with AI and what it all means.

In the 1980s there was a lot of hype around artificial intelligence resulting in thousands of university undergraduates learning languages such as LISP and Prolog, and the Japanese Government sinking hundreds of millions of dollars into its Fifth Generation Computing programme in an attempt to progress the technology further. More modestly the UK's DTI published a few pamphlets and books on state of the art Intelligent Knowledge Based Systems (IKBSs) and Neural Networks. A few rather expensive products hit the market. There were a few relatively trivial case stydies and then it all just seemed to fizzle out, gradually becoming forgotten as the Internet Bubble grabbed people's attention.

However, AI did not go away, its development just went into submarine mode. People were there working quietly away in the background on specific applications of AI and bringing them to a level of maturity where they can be adopted wholesale in real life situations. In the process there have been substantive strides, so for example voice recognition systems now require little training and accommodate regional and national accents. Additionally, there has been a little gentle re-branding to adopt the term "Machine Learning". Consequently many people use "personal assistant" agents on their phones or built into household automation devices. Self driving cars are reaching commercial aodption and the next generation of UAV aircraft will be capable of accepting a programmed mission, taking off and completing it without human intervention or interaction, unless some mission parameter is encountered which requires human decision making or to receive required intelligence.

I was literally blown away with incredulity recently, when someone showed me how easy it is to set up a simple machine learning application in Azure and train it to produce a useful output. But I have been reading recent alarmist claims that "AI robots" will replace millions of human professions with a level of scepticism, as this is not substantiated by previous experience.

In the 1980s, when I worked for a bank, there was an interesting article in the Financial Times on the adoption of IT by the banking industry. The gist of the story was that if the banking industry had not adopted IT to mechanism a lot of its work, then the explosion in consumer banking products in the UK which happened at that time would not have been possible without employing the whole of the UK workforce to support it.

A recently touted robotic brick layer is unlikely to eliminate all brick laying jobs because there is a current shortage of bricklayers and robots will not be economic on small sized jobs. Furthermore, the reason that the United States has traditionally enjoyed higher productivity than Europe is not a result of American technical superiority, but the result of the fact that the US has always been resource rich and people poor. A shortage of labour and skills leads to new methods and investments in mechanisation and automation.

Furthermore, the UK Government Digital Strategy is promoting the investment into the development of AI skills, because the Government believes this will grow both the economy and jobs. The real impact will be in the change of the nature of the jobs. People will do less humdrum stuff and explore their curiosity more to invent new things, discover new things and do their jobs more creatively.

Monday, 3 April 2017

IoT Platforms

Companies going down the cloud bases PaaS route for hosting their applications have some interesting choices. There are 2 main leaders: Amazon, Microsoft and Google. There are also a lot of other platforms built around major applications, e.g. Salesforce & SAP, or technology stacks, e.g. IBM and Oracle.

Most of these platforms have quite features around provision of virtualised servers and storage as well as load balancing, with extensive options for scalability, as well as pricing models. All come with various database management system services as well as data analytic services for BI/Big Data usage.

Whilst Gartner makes a great show of assessing them against its own set of  Enterprise requirement criteria, this is unlikely to be meaningful for long as the leaders are engaged in an arms race to introduce an increasing number of features and capabilities which means that any 3rd party analyst's assessment is bound to be out of data almost as soon as it is published.

Enterprises have a fair guessing game about which platforms are going to be dominant in the future. This is almost impossible to get right. So more pragmatic approaches are needed. If an enterprise intends to move almost everything onto cloud platforms, then some analysis of what services its main SaaS applications uses may be appropriate. For companies tied into .Net, Microsoft Office and AD, then Azure may be a no brainer.

However, when it comes to IoT based applications, this may not be so simple. At present Amazon appears to have the leading  IoT support framework of the big 3 platform providers. Google and Microsoft appear to be trying to get in on the end device with specialist operating system offerings, so that they can own the whole stack. Likewise, Oracle is aiming to lever its Java specialism with its technology stack to provide specialist SaaS applications which facilitate rapid development in the IoT area.

My take is simple. For now anyway, most applications are going to have to deal with at least 2 PaaS platforms. One for internal applications and a second for externally facing applications and IoT. In reality, most corporations may need even more, especially if they want to exploit big application services such as SAP's and Salesforce's.

Saturday, 29 October 2016

Platform Schizophrenia

This year I became aware that there are two definitions to Digital Platforms. Whilst I had been meandering around in IT Space thinking that digital platform meant services like AWS and Azure, our friends in Marketing Space had decided that digital market places were Digital Platforms. So to them ComparetheMarket.com, Deliveroo.com and Uber.com are platforms. 

Anyway moving on from this diversion, it has for some time been a surprise to me that amazon has dominated IT thoughtspace and the market for PaaS based Digital Platforms, whilst belatedly Microsoft pushed into the market with Azure. 

In recent projects I have been involved with both AWS and Azure as well as all sort of fun with the OSS tools which are available on them. To traditionalists coming across the database as a service offerings available is quite amazing. I was also blown away when a Solution Architect who had no experience of Neural Networks was able within 2 weeks to knock up a fully working and trained prototype of a Machine Learning application on Azure.

So it has become increasingly interesting to see that Google, one of the most born in the cloud companies going, has recently started promoting its services. One has to ask why did they wait so long, especially as they have always made much of the fact that their products are all architected around a SOA concept and the ability to expose themselves as services, both internally and externally.

Oracle and IBM have also appeared actively in the market place this year promoting their own special blends. 

The thing about this is that they all have really good stories to tell. You will note that I am not stating any preferences, as to be honest, anything I say about them today will already be wrong tomorrow as this is an ever faster moving situation. Today's facts will be obsolete tomorrow.

So what does it all mean to the average business trying to go Digital?

Firstly, the means are there. You have to be comfortable with the fact that terms and conditions are what they are. You need to examine the pricing and understand how this would play out in some key real world applications. However there is plenty available to "Free Your business from the Tyranny of Infrastructure" and Focus on Value. If you choose reasonable sensibly, you will be able to scale costs with business activity and exploit platforms which support Agile and DevOps so you can move quickly and lightly in the pursuit of opportunities. All the major vendors are investing significantly in security and if you dig deeper, most offer localisation options if data cannot move outside certain jurisdictions. Additionally there are industry certification schemes which many providers are signed up to. So a lot of inhibitors have been addressed.

The key issue is going to be how much do you insulate yourself from the risk that you may need to change platform provider. Business Performance, Legislation, Pricing etc. will change with time. So you may need an exit plan. Therefore, some thought needs to be given to insulating yourself from future supply threats. Where your application is going in for short term gains, e.g. a new financial instrument which will only be around for a a few months or perhaps a couple of years, this is not a problem. But if you are locking yourself into a platforms specific machine learning solution for years, you may need to think how you would deal with problems if the platform vendor ceases training.

In the end, however, we have always faced these problems. Finding a totally vendor agnostic solution has always been too complicated and too costly. So its time to get comfortable with not being in total control. The System of Systems concept of de-optimising components to integrate and optimise the overall performance of the Big System applies. You just need to understand your risk appetitie, your risks, how you want treat them, what you will accept, what you need to insure against and get on with it. The risks of not doing so are far greater.