Monday, 26 January 2015

Amazon to acquire startup Annapurna Labs for data center muscle

Amazon.com is to acquire a semiconductor startup in Israel, which has been operating secretively since it was set up in 2011.
Jacinda Mein, a spokeswoman for Amazon Web Services, confirmed Thursday that Amazon has agreed to acquire Annapurna Labs, but added that the company had nothing else to share at this time.

The technology being acquired by Amazon could be used in the vast data centers it runs for its own retail operations and for those of its Amazon Web Services unit.

Annapurna develops midrange networking chips for data centers that transmit more data while consuming less power, according to the Wall Street Journal, which quoted sources familiar with the matter as saying that Amazon was discussing paying $350 million for the startup.

The company in Yokneam was founded by Avigdor Willenz, founder of chip design company Galileo Technologies in Israel, that was acquired by Marvell Technology Group in 2001, according to the newspaper.

"Annapurna Labs puts together some of the best talent to address significant industry challenges," Willenz wrote on the company website, which has little other information on what it does. "In my experience, their talent, innovation and open culture is unmatched in the semiconductor industry." The company said on its Twitter and LinkedIn profiles that it was operating in "stealth mode."

Annapurna has sites in Israel and Silicon Valley.


Best CCNA Training and CCNA Certification and more Cisco exams log in to Certkingdom.com

Wednesday, 14 January 2015

Recruiting challenges spur higher salaries, better perks

Climbing salaries, more voluntary departures, and flexible work options are signs of a challenging IT hiring environment that favors job seekers.

Skilled job seekers are in an enviable position in the simmering tech industry, as hiring managers compete for talent, boost job offers, and improve on-the-job perks to keep existing employees from looking elsewhere.

“It’s really the technologists’ choice right now. They can be very picky,” says Jack Cullen, president of IT staffing and recruiting firm Modis.

IT pros are more willing to consider a job change than they might have been a few years ago, and when they start exploring their options, it’s not uncommon for candidates with hot skills – in security, app development or data science, for instance – to wind up weighing multiple offers.

Candidates today know they’re marketable, says Shravan Goli, president of tech careers site Dice. “They’re feeling a lot more confident, they’re asking for more money, and they’re voluntarily leaving their jobs,” Goli says.

The pressure on wages and restlessness are confirmed by hiring managers: 64% said they’re seeing candidates ask for more money, and 40% reported an increase in the number of voluntary departures compared to mid-2014, according to Dice’s semi-annual hiring survey.

Counteroffers, too, are becoming more commonplace as workers use outside offers as leverage to negotiate for more money from their current employers. “Forty-three percent of recruiters noted that they have to make more counteroffers to retain existing staff, and that’s a 10-point upturn from just six months ago. That’s a big shift,” Goli says.

Looking ahead, demand for tech professionals won’t slow down anytime soon, according to Dice. As the new year gets underway, 75% of recruiters said they anticipate hiring more tech professionals in the first six months of 2015 than in the last six months of 2014. The numbers of new hires is fairly substantial: 72% of companies said they plan to expand their staff by more than 10% in early 2015, according to the recruiting community.

Research from Robert Half Technology (RHT) echoes that optimism.

In the first half of 2015, 19% of CIOs plan to expand their teams, according to RHT. That’s a significant gain compared to mid-2014, when 14% were planning to add more staff to their departments. (Another 68% of CIOs expect to hire for open IT roles, 10% plan to put a hold on hiring, and 3% expect to reduce their IT staffing levels in the first six months of the new year.)

Strong hiring numbers will translate into strong negotiating power for tech professionals who are looking for a job or considering leaving their current one. “If you're not addressing compensation levels, you're putting yourself at a distinct competitive disadvantage,” says John Reed, senior executive director of Robert Half Technology. “Not only does it make it difficult to attract the talent you want, but it's also causing you to lose people within your organization who are being recruited away.”

Already, IT pros are in line for the biggest pay increases compared to other working professionals. Starting salaries for professional occupations across all fields in the U.S. are projected to increase an average of 3.8% in 2015, Robert Half predicts. In tech, the average starting salary for newly hired IT pros is forecast to climb 5.7%. (See related story, “15 job titles getting big salary boosts in 2015”)

Salary bumps are just the beginning. IT pros can also expect to see greater bonus pay and more generous benefits in 2015, experts says.

On the compensation front, more companies are offering financial incentives such as project bonuses. Given to employees when they complete a critical deployment, project bonuses allow companies to dole out extra compensation without committing to permanent salary increases.

Retention bonuses are also becoming more common. A tactic for retaining critical personnel who might be considering leaving, retention bonuses are typically awarded to employees for staying for a specific time period, such as through the completion of a project or merger. Likewise, some equity grants are designed to vest when project milestones are achieved, which also helps encourage employees to stay longer.

Worth noting is companies’ restraint: While pay is trending upward, it’s not increasing dramatically, notes Cullen.

“You would think in a high-demand environment that people would be paying better-than-market rates to get these folks. But companies are really trying not to do that. No one seems to be just rolling out a wheelbarrow of cash. The increases in salaries, and the increases in hourly rates for contractors, are there, but they’re increasingly slightly.”

“I was really expecting to start seeing a substantial rise. I thought we’d see it in 2014. We haven’t seen it,” Cullen says.

Hiring managers also aren't rushing into new hires, despite the competition for certain skilled workers. The time it takes to fill open positions has lengthened relative to last year, according to 46% of recruiters polled by Dice.

“Companies are very picky, too. They’re still maintaining discipline in their hiring approach,” Cullen says. Part of the reason is to avoid unnecessary employee turnover. “The turnover that companies have experienced has become very much a turnoff, so they’re really being particular in their hiring process to make sure they bring in somebody who’s going to stick,” Cullen says.

Meanwhile, instead of simply throwing cash at candidates, companies are trying to be as creative as they can in attracting talent. “Companies are doing a really good job of managing their budgets, and managing their pay rates, so they've got to find other ways to convince people to come work there,” Cullen says.

That’s where perks come in.
While compensation is paramount, it’s not the only factor IT pros consider. Amenities can make a difference, and companies are bolstering their offerings with extras such as subsidized meals and free refreshments, on-premises fitness and daycare centers, training opportunities, and subsidized public transportation.

“Certainly there’s a lot of creative stuff going on, especially around Silicon Valley. It’s sort of a comeback of what we saw 10 or 12 years ago,” Goli says. “Onsite services, from getting your shirts dry-cleaned to getting a haircut to getting a dentist appointment. Free food, more types of food, healthy food – that’s happening a lot more.”

Coveted perks include flexible schedules and the ability to occasionally work from home. “What motivates people more often than not is something that allows them to have flexibility and work-life balance,” Reed says.

The extracurricular perks that resonate with IT pros are generally the more substantive extras, Cullen adds. IT pros are a motivated group, in general, and the opportunity to keep skills fresh and stay challenged is paramount. Candidates look for an environment where they can improve their skills, do things they like to do, learn new technologies.

“Anybody who feels their environment is stagnant is immediately looking, and they’re the easiest ones to encourage about the next opportunity,” Cullen says.

Given all the churn in the marketplace today, there’s even more pressure on CIOs and IT leaders to take care of their existing people. “Culture development inside the company has become very important. Creating an environment with these extracurricular benefits, training, and flexibility is important for attraction; it’s equally as important for retention. The whole attrition game has really been bothering companies,” Cullen says.

“Your recruiting efforts really begin with the people on your team,” Reed says. “As you're looking at recruiting people into the organization, make sure you re-recruit the people who work for you now before you worry about the people you're trying to bring in from the outside."

Otherwise, as you're bringing people in the front door, more will be leaving out the back door, he warns. “You have to be engaged and make sure you have your finger on the pulse of job satisfaction of your employees,” Reed says.

In the big picture, 2015 looks really promising, Reed notes. “The new year brings new budgets, new projects and new initiatives. We anticipate a really strong start to the year.”

“It’s absolutely a great time to be a tech pro,” Goli says.


 
Best CCNA Training and CCNA Certification and more Cisco exams log in to Certkingdom.com

Thursday, 8 January 2015

More education needed to realize the Internet of Everything

The Internet of Everything (IoE) is essentially about connections, bringing people, processes, data and things together in unprecedented ways. IoE delivers the right information to the right person (or machine) at the right time, and converts data into intelligence to make better decisions.

Organizations will use the connections made by IoE to transform our work and private lives, creating smarter products and services, more convenience for consumers and new forms of work-life integration. However, in order to capitalize on these connections, organizations will need well-trained staff. Cisco predicts that approximately 220,000 new engineers will be needed globally every year for the next 10 years to keep up with the technological surge of IoE. This is a gap that must be filled if the potential of IoE is to be realized.

Because the network will serve as the hub for the Internet of Everything, it will need to be more secure, agile, context-aware, automated, dynamic and programmable. CareerBuilder projects that five job roles in particular will be in high demand as a result: Cloud architect, cybersecurity analyst, data scientist, mobile application developer and network programmer.

All five roles are good career path choices, both for those still deciding on a major and for workers looking to make their next move. The online career community ITCareerFinder, for example, named mobile application developer as the No.1 “best computer job for the future.”

Here’s a closer look at the five hot categories:
* Cloud Architect. According to a November 2012 IDC report titled “Climate Change: Cloud’s Impact on IT Organizations and Staffing,” demand for cloud-related positions will grow by 26 percent annually through 2015, with as many as 7 million cloud-related jobs available worldwide. However, the report indicates that IT hiring managers were unable to fill 1.7 million cloud positions in 2012 because job seekers lacked the training and certification needed to work in a cloud-enabled world.

* Cybersecurity Analyst. Security will be of particular concern, as the attack surface will increase significantly due to IoE. All these connected devices will generate and exchange substantial volumes of data, as well. The role of the data analyst will therefore be crucial in terms of converting this data into usable information. Getting prepared for IoE will require the existing workforce to be re-skilled and the incoming workforce to be upskilled in order to understand IT networking to a greater degree.

As opposed to other network security roles that focus on “building the castle,” a cybersecurity analyst pays closest attention to “guarding the castle.” Working in a security operations center, the cybersecurity analyst monitors security equipment, recognizes attacks, and responds to security events.

The fact that retailers, banks, healthcare providers, and other organizations reported 167 data breaches in the state of California during 2013 underscores the need for greater security in the IoE era. The 2014 Cisco Annual Security Report predicts a shortage of more than a million security professionals across the globe during the next five years.

A few of the recent data breaches provides a prime example of the necessity for three key skills for the IoE era mentioned above: enterprise networking, cybersecurity and data analysis. In some cases, the weaknesses inherent in IoE enabled a security breach (imagine connected coffee pots, air conditioners, etc. being turned against a business).

The technology exists to connect everything, but unsecured connections can spell disaster. So, IoE requires people with the skills to deploy the infrastructure that connects things, data, people and processes, and build in security simultaneously.

IoE will require IT professionals who understand this connected infrastructure so deeply that they are able to proactively secure it from threats. Cybersecurity analysts will be needed to help determine where threats are coming from, particularly if any breach attempts are successful. These analysts will act as security guards for the network with their specialized skills and insights.

* Data Scientist. IoE is a major contributor to global IP data center traffic, which is already on the order of hundreds of exabytes per month. With all of that data swirling around, the role of the data scientist will be paramount. Data scientists search for patterns in data and analyze data trends, with an eye to learning about user behavior or improving user experience. They also look for potential storage failures or even security threats. As the third annual Cisco Connected World Technology Report indicates, “The data scientist combines creative imagination with IT skills to unlock the power of data.”

The third annual report, which was based on a survey of 1,800 IT professionals in 18 countries, reveals that in this IoE era—with its dramatic increase in new connections—the majority of respondents (73%) saw their big data strategy as needing to include data from digital sensors, meters, cars, video monitors, and smart devices. The survey also indicates that 40% were already using “data in motion,” that is, data in transit—from devices, sensors, video, and monitors—that a data scientist can work with in real time.

* Mobile Application Developer. According to the Cisco Visual Networking Index (VNI) Global Mobile Data Traffic Forecast Update, 2013-2018, by the end of 2014, the number of mobile-connected devices will exceed the number of people on Earth, and by 2018 there will be nearly 1.4 mobile devices per capita. The ongoing proliferation of mobile devices will continue to make the job role of mobile application developer highly important to IoE.

* Network Programmer. In the IoE world, leveraging programmable networks facilitates a gathering of information that, in turn, enables automation in the configuration of the IT infrastructure. As a result, information can be intelligently applied to infrastructure configuration, allowing the needed scale in the number of devices that can be effectively managed. Programmability helps ensure the correct level of automation, easing the pressure on the IT infrastructure, streamlining the identification and resolution of data bottlenecks, and thereby increasing efficiency.

It is the combination of deep network engineering knowledge and the ability to utilize a programming language such as C, Java, or Python that puts the network programmer in high demand.
Educating to Fill the Gap

The networker’s view and responsibilities are expanding to include many new technologies as well as duties. There are many emerging roles in the future for IoE – business transformation specialists, cloud brokers, network programmers and data scientists. Cyber security becomes more pervasive and networking careers becomes more specialized.

Application developers who are implementing SDN technologies, as well as those at the business application layer, will need a tighter grasp of the new world they operate in. With the convergence of operational technologies and IT on the horizon, engineers will need to become trained in IT and networking. Companies will need to work with industries throughout the world to create the pathway for IT networking skills and talent development.

In addition, students must be prepared from the beginning to understand the network and its underlying connection to everything. It is incumbent on IT companies to work with universities, secondary schools, networking academies and learning partners to develop curricula to ensure that rising talent is well prepared to understand the functioning of the network and its relationship to IoE.

Network training needs to filter down to grade school in order for the next generation to be equipped with critical thinking, complex problem solving, data analysis, and communication and collaboration skills associated with IoE.
Chart of cloud education

As students move to a Bring Your Own Device, ubiquitous access model, their needs and preferences regarding where and when they get training are changing along with what they are learning. Students now prefer mobile, video-based, game-based learning that not only is an evolution of traditional delivery but also helps remove barriers to education. A 2013 survey of Cisco certified professionals revealed a strong preference for hands-on practice labs, simulations and video-based training. Rather than attending a class on each of these subjects, this core knowledge set will be available in real time on an as-needed basis.
Cloud education chart

Shifts in technology require us to consider not only how job roles are changing but also how learner preferences are changing and, therefore, how education is delivered. The good news is that the technology with connected devices and collaboration software can help make this happen, since the technology and infrastructure are there to move in this direction.

Harnessing the potential of IoE means a faster path to strategic insights and increased profitability; rapid delivery of differentiated IoE-enabled services and experiences; and security that helps enable IoE business because it’s integrated, open, continuous and pervasive. These create sustainable competitive advantage. In order to reach this goal, though, current and future employees must be properly trained. Organizations, educational institutions and industries must work together to instill the 21st-century skills needed to gather in the full harvest of IoE benefits that will improve all aspects of human life.



Comptia A+ Training, Comptia A+ certification

Best CCNA Training and CCNA Certification and more Cisco exams log in to Certkingdom.com

Wednesday, 24 December 2014

Top 10 Tech stories 2014: Backlash! Disrupting the disruptors

Blowing up entrenched business models and picking up the profits that spill onto the floor is a time-honored tradition in tech, these days known by the cliche of the moment, “disruption.” This year everyone was trying to push back against those upstarts, whether by buying them like Facebook did, reorganizing to compete with them like HP and Microsoft have done, or just plain going out against them guns blazing, as it seemed that every city and taxi company did with Uber. European courts fought the disruptive effect Google search has had on our very sense of the historical record. But meanwhile, legions of net neutrality supporters in the US spoke up to save the Internet’s core value of disruption against the oligopoly of a handful of communications carriers. Here are our picks for the top stories of a very, well, disruptive year.
year in review 2014

Nadella aims Microsoft toward relevancy in a post-PC world
Taking over from Steve Ballmer in February, CEO Satya Nadella faced several uncomfortable truths, among them: Windows powers only 15 percent of all computing devices worldwide, including smartphones, tablets and PCs, meaning Microsoft is no longer at the center of most people’s computing experience. Nadella says he wants Microsoft to be the productivity and platform company for a “mobile first, cloud first world.” Under Nadella, Microsoft has launched Office for the iPad, embraced open source software for its Azure cloud and launched the beta for Windows 10, which promises to smooth out Windows 8’s confusing, hybrid user interface. Shortly after closing the Nokia acquisition he inherited, Nadella announced 18,000 job cuts, 14 percent of its global staff. The bulk of those cuts are in Nokia, which has been relegated to the “other” market share category in smartphones. Microsoft’s sales looked good last quarter, jumping 25 percent year-over-year to $23.2 billion, though profit was hurt by the Nokia buy. Nadella claimed the company is “innovating faster,” which had better be true if he is to succeed.

HP says breaking up is hard, but necessary
Agility appears to be more important than size these days. In an about-face from the direction CEO Meg Whitman set three years ago, Hewlett-Packard announced in October that it will split up, divorcing its PC and printer operations from its enterprise business. When Whitman took the reins from former HP chief Leo Apotheker in 2011, she renounced his idea to split up the venerable Silicon Valley company, saying PCs were key to long-term relationships with customers. But shedding assets is becoming a common strategy for aging tech giants. IBM has focused on enterprise technology and services after selling first its PC operations years ago, and then its server business this year, to Lenovo, and agreeing in October to pay GlobalFoundries $1.5 billion to take over money-losing chip facilities. Symantec announced this year that it would spin off its software storage business, the bulk of which it acquired 10 years ago from Veritas Software for $13.5 billion. The big question for HP is whether it can avoid alienating users and distracting its hundreds of thousands of employees.

Uber’s bumpy ride shakes up the “sharing” economy
Legal challenges and executives behaving badly marked the ascendancy of Uber this year as much as its explosive growth and sky-high valuation. The startup’s hard-driving, take-no-prisoners culture has made it an unlikely poster child for the innocuous—and perhaps misleadingly labeled—“sharing” economy. Announcing the company’s latest billion-dollar cash injection in December, CEO Travis Kalanick bragged that Uber had launched operations in 190 cities and 29 countries this year. The service is now valued at $40 billion. But the company’s army of private drivers face legal challenges, inquiries and preliminary injunctions against operating, from Germany and the UK to various US states. Executives have made matters worse by threatening to dig up dirt on critical journalists and bragging about a tool called “god view” that lets employees access rider logs without permission. Rival app-based ride services like Lyft and Sidecar, whose operations are also the target of inquiries, are distancing themselves from Uber. Added to all this, there are complaints about the legality of other sorts of so-called sharing services, like apartment-rental site Airbnb, which has spawned not just opportunities for regular folks with an extra room and a hospitable nature, but created a class of real-estate investors who are de facto hoteliers. All this suggests that Web-based companies seeking a “share” of profits using middleman tech platforms to disrupt highly regulated businesses like taxis and lodging have some real battles against entrenched interests still to fight.

Facebook gambles $16 billion on WhatsApp
Established companies are snapping up upstarts at a pace not seen since the dot-com boom days, but in February Facebook’s plan to buy WhatsApp for $16 billion had jaws dropping at the price tag. WhatsApp has hit about a half billion users with its mobile messaging alternative to old-school carriers. Facebook already had a chat feature, as well as a stand-alone mobile app called Messenger. But people don’t use them for quick back and forth conversations, as CEO Mark Zuckerberg has acknowledged. At the Mobile World Congress in Barcelona, he confessed that he could not prove in charts and figures that WhatsApp is worth the money he spent, but said that not many companies in the world have a chance at cracking the billion-user mark, and that in itself is incredibly valuable.

Mt Gox implodes, deflating Bitcoin hype
Last year, Bitcoin seemed poised to disrupt conventional currencies. But this year the high-flying cryptocurrency hit some turbulence. The largest Bitcoin exchange in the world, Tokyo-based Mt Gox, fell to earth amid tears and lawsuits after an apparent hack cost the company about 750,000 bitcoins worth about $474 million. The company said a flaw in the Bitcoin software allowed an unknown party to steal the digital currency. A few weeks later Flexcoin, a smaller site, closed after it got hacked. The closures sent tremors of fear through the fledgling Bitcoin market. The leaders of Coinbase, Kraken, Bitstamp, BTC China, Blockchain and Circle all signed a statement lambasting Mt Gox for its “failings.” But the incidents took the luster off Bitcoin. Still, New York’s proposed Bitcoin regulations may establish a legal framework, and confidence, to help exchanges grow in one of the world’s biggest financial centers. Bitcoin concepts may also spur spinoff technology. A company called Blockstream is pursuing ideas to use Bitcoin’s so-called blockchain, a distributed, public ledger, as the basis for a platform for all sorts of transactional applications.

Apple Pay starts to remake mobile payments
Apple’s ascendance to the world’s most valuable company came on top of market-defining products like the iPod, iTunes, the iPhone and the iPad. This year, it was not the iPhone 6 or the as-yet unreleased Apple Watch that came close to redefining a product category—it was Apple Pay. Apple Pay requires an NFC-enabled Apple device, which means an iPhone 6 or 6 Plus, but by early next year, Apple Watch as well. Businesses need NFC-equipped payment terminals. With Apply Pay, you can make a credit or debit card payment simply by tapping your iPhone to the NFC chip reader embedded in a payment terminal. As you tap, you put your finger on the iPhone 6’s biometric fingerprint reader. Apple was careful to line up partners: while Google stumbled trying to get support for its Wallet, more than 500 banks and all major credit card companies are working with Apple Pay. The potential security benefits top it off: When you enter your credit or debit card number, Apple replaces it with a unique token that it stores encrypted. Your information is never stored on your device or in the cloud.

Alibaba’s IPO marks a new era for Chinese brands
In their first day of trading on the New York Stock Exchange in September, Alibaba shares opened at $92.70, 35 percent over the $68 initial public offering price, raking in $21.8 billion and making it the biggest tech IPO ever. Alibaba is an e-commerce behemoth in China, now looking to expand globally. But don’t expect a direct challenge to Amazon right away. Its strategy for international dominance depends not only on broad e-commerce, but also on carving out different niche marketplaces. Shares three months after its opening are going for about $10 more, suggesting that shareholders have faith in that strategy. The IPO also marked the ascendancy of Chinese brands. After scooping up IBM’s PC business years ago, and this year spending $2.3 billion for IBM’s server business as well as $2.9 billion for Motorola, Lenovo is the world’s number one PC company and number three smartphone company. Meanwhile Xiaomi, the “Apple of China,” has become the world’s number-four smartphone vendor.

Regin and the continuing saga of the surveillance state
Symantec’s shocking report on the Regin malware in November opened the latest chapter in the annals of international espionage. Since at least 2008, Regin has targeted mainly GSM cellular networks to spy on governments, infrastructure operators, research institutions, corporations, and private individuals. It can steal passwords, log keystrokes and read, write, move and copy files. The sophistication of the malware suggests that, like the Stuxnet worm discovered in 2010, it was developed by one or several nation-states, quite possibly the U.S. It has spread to at least 10 countries, mainly Russia and Saudi Arabia, as well as Mexico, Ireland, India, Afghanistan, Iran, Belgium, Austria and Pakistan. If Regin really is at least six years old, it means that sophisticated surveillance tools are able to avoid detection by security products for years, a chilling thought for anyone trying to protect his data.

EU ‘right to be forgotten’ ruling challenges Google to edit history
The EU’s Court of Justice’s so-called right to be forgotten ruling in May means that Google and other search engine companies face the mountainous task of investigating and potentially deleting links to outdated or incorrect information about a person if a complaint is made. The ruling came in response to a complaint lodged by Spanish national insisting that Google delete links to a 1998 newspaper article that contained an announcement for a real-estate auction related to the recovery of social security debts owed by him. The complaint noted the issue had been resolved. But while EU data-privacy officials cheer, free-speech advocates say the ruling’s language means that people can use it to whitewash their history, deleting even factually correct stories from search results. As of mid-November, Google had reviewed about 170,000 requests to delist search results that covered over 580,000 links. The headaches are just starting: Now the EU says the delinking must be applied to all international domains, not just sites within the region.

Obama weighs in as FCC goes back to the drawing boards on net neutrality
In January, a U.S. appeals court struck down the FCC’s 2011 regulations requiring Internet providers to treat all traffic equally. The court said the FCC did not have the authority to enact the rules, challenged in a lawsuit brought by Verizon. The ruling reignited the net neutrality debate, with FCC Chairman Tom Wheeler proposing new rules in April. President Obama in November made his strongest statement on net neutrality to date, urging the FCC to reclassify broadband as a regulated utility, imposing telephone-style regulations. Obama’s move, which critics say is an unprecedented intrusion on an independent government agency, puts political pressure on Wheeler, who reportedly favors a less regulatory approach. The proposal from Wheeler earlier this year stopped short of reclassification, and allowed broadband providers to engage in “commercially reasonable” traffic management. Public comments on Wheeler’s proposal had hit nearly 4 million by September. The ball is now back in Wheeler’s court, as he negotiates a resolution to the whole affair with his fellow commissioners.




Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Monday, 15 December 2014

Cisco patches traffic snooping flaw in its networking gear

The vulnerability affects the OSPF routing protocol implementation on Cisco networking equipment

Cisco Systems said attackers could disrupt or intercept traffic in many of its networking products unless a new security update is applied to the software they run.

The issue affects the implementation of the Open Shortest Path First (OSPF) routing protocol and its Link State Advertisement (LSA) database in particular. This protocol is used for determining the shortest routing paths inside an Autonomous System (AS) -- a collection of routing policies for IP (Internet Protocol) addresses controlled by ISPs and large organizations.

[ InfoWorld's expert contributors show you how to secure your Web browsers in a free PDF guide. Download it today! | Learn how to protect your systems with Roger Grimes' Security Adviser blog and Security Central newsletter, both from InfoWorld. ]

[ Security expert Cricket Liu lays out the workings of a DNS-based DDoS attack -- and how to prevent one from hitting your company. Download the PDF today! | Stay up to date on the latest security developments with InfoWorld's Security newsletter. ]

The OSPF protocol is commonly used on large enterprise networks. It gathers link state information from available routers into a database in order to built a network topology map which is then used to determine the best route for IP traffic.

"This vulnerability could allow an unauthenticated attacker to take full control of the OSPF Autonomous System (AS) domain routing table, blackhole traffic, and intercept traffic," Cisco said in a security advisory.

Exploiting the vulnerability doesn't require authentication and can be achieved remotely by sending specifically crafted OSPF LSA type 1 packets via unicast or multicast to the vulnerable device. The packets could contain false routes that would then get propagated throughout the entire OSPF AS domain.

However, the attacker does need to determine some information in advance in order to launch a successful attack, Cisco said. This information includes the network placement and IP address of the targeted router, the LSA database sequence numbers and the router ID of the OSPF Designated Router (DR).

The vulnerability affects networking devices running most versions of Cisco IOS, IOS-XE and NX-OS operating systems if they are configured for OSPF operations. It also affects the software running on the Cisco Adaptive Security Appliance (ASA), Cisco ASA Service Module (ASA-SM), Cisco Pix Firewall, Cisco Firewall Services Module (FWSM) and the Cisco ASR 5000 carrier class platform.

Comptia A+ Training, Comptia A+ certification

Best CCNA Training and CCNA Certification and more Cisco exams log in to Certkingdom.com

Wednesday, 10 December 2014

What happens next in the Cisco suit against Arista?

Although the outcome is uncertain, the case will likely go to trial

Arista Networks’ stock took it on the chin when Cisco slapped the company with patent infringement and copyright law suits last Friday, losing almost 20% of its value at one point as investors and others mulled the long term implications of the suits.

The short answer: this is going to take a long time and could get pretty ugly for Arista.

One of the suits accuses Arista of violating 14 Cisco patents, while the second is for extensive copying of Cisco’s user manuals and multi-word CLI commands (see Cisco slaps Arista Networks with patent, copyright infringement suits).

Arista has been fairly mum on the suits, but did post a piece by board member Dan Scheinman, who formerly worked for Cisco, saying “Arista’s EOS was developed from the ground up as a next generation network operating system for the cloud based upon the pioneering technologies invented by Arista” (see Arista fires back at Cisco's suits).

Scheinman ends his post posing the question, “Why now? The answer to that question speaks volumes about the real motivation going on here.”

The conclusion we are apparently expected to reach is that Arista has unique technology and its growing success is a thorn in Cisco’s side, hence the suits. Sales growth would support that notion. When Arista filed for its IPO last June it said sales in 2013 were $361 million, up more than 90% compared to 2012, and according to some estimates, the company will finish 2014 with sales leaping another 60% to $577 million (across that magic $500 million line that proves to be the limit for many network startups).

“Arista has good products and obviously a strong engineering staff,” says Joel Snyder, a senior partner at tech consulting firm Opus One, and a longtime product reviewer for Network World. “People are starting to take note, and obviously they are making some noise that Cisco is noticing.”

One large financial services company I spoke with this summer said they are installing Arista equipment to complement their largely Cisco network environment, adding anecdotal evidence that Arista is making inroads in critical accounts. Asked if this lawsuit will make them reconsider adding Arista equipment, the company said it will proceed as planned.

That’s at least some good news. The bad news: Arista will have its hands full with these suits, says Charles Steenburg, an associate at Wolf Greenfield, an intellectual property law firm in Boston. While Arista might file a motion to dismiss the complaints, “in a case like this, dismissal is highly unlikely,” he says.

While trials are the exception rather than the rule in patent infringement cases, especially in cases brought by patent trolls who are just after cash settlements, “cases involving competitors more often go to trial,” Steenburg says.

Discovery and the claim construction phase, in which the judge asks for input from the parties and outlines certain key patent terms, can take about a year, he says. Using the Apple/Samsung trials as a gauge, which were filed in the same California district, Steenberg says these cases might start in 16 to 26 months.

Asked how dire a situation this could create for Arista, Steenburg says “the nuclear scenario would be for Cisco to get an injunction that prohibits Arista from selling the products in question.” But at the very least, the cases are “certainly going to make life difficult” for Arista.

“The discovery process itself is not just expensive, but also time consuming and can sap morale,” Steenburg says. “It stinks to have engineers and other employees being deposed or gathering documents instead of doing constructive work. That is often an unappreciated cost and risk of litigation.”

Snyder says he thinks “Cisco has a legitimate beef. They may or may not prevail, but it opens up enough FUD to give the Cisco sales team something to use in competitive deals. Right now Cisco is fighting hard to keep its place in the enterprise, and one of their tools is pricing. If they can force others to have higher costs, either through engineering or litigation or both, then this is a competitive edge.”


Should potential customers worry? “I would counsel any client thinking of doing business with a company that has been sued for patent infringement to ask to be indemnified in case the company goes after them,” Steenburg says. “That said, presumably Cisco does business with most of Arista’s customers, so it would be unusual for Cisco to go after customers.”

In the copyright suit Cisco says that, among other infringements, Arista has copied 500 of its multi-word command line instructions. While Google and others argue copyright protection shouldn’t address interfaces, some observers see it otherwise.

“’Ip host’ all by itself isn't copyrightable,” writes Florian Mueller, an intellectual property activist with 25 years of software industry expertise in his blog Foss Patents, “Same with ‘show inventory.’ Arista could have copied one or two of those and Cisco couldn't complain if that were the case. But when one looks at the whole list of 500 multi-word commands, many of which truly involve creative choices (for example, ‘show ip igmp snooping querier’ or ‘spanning-tree potfast bpdufilter default’), the threshold for copyrightability is easily met.”

Best CCNA Training and CCNA Certification and more Cisco exams log in to Certkingdom.com

Thursday, 13 November 2014

Internet goes ad-free for an hour as Google ad server fails

Websites around the world lost their ads after DoubleClick for Publishers outage

A Google ad server went down Wednesday morning, leaving many websites without advertising. Sites like Computerworld and CNBC.com were affected.

The ad server, known as DoubleClick for Publishers, is an advertisement software-as-a-service application.

"DoubleClick for Publishers experienced an outage this morning impacting publishers globally, across their video, display, native and mobile formats," Google said in an email to Comuterworld. "Our team has worked quickly to fix the software bug and [DoubleClick for Publishers] is now back up and running, so our publisher partners can return to funding their content."

According to multiple accounts, the ad server was down for about an hour.

Dan Olds, an analyst with The Gabriel Consulting Group, said the outage likely cost companies across the world millions of dollars.

""First of all, I'm very surprised that Google's DoubleClick service could go down so completely and for so long. This service is Google's cash cow, with huge revenue and high margins," he added. ""This outage won't be devastating to any particular company or set of companies, but it's a shot to Google's reputation and I'm sure that some companies will be looking to see if they have any recourse."

The failure, though short lived, could cause a lot of pain for any company that was launching new products or running specific sales this morning.



Best CCNA Training and CCNA Certification and more Cisco exams log in to Certkingdom.com