Thursday, September 29, 2011
Choosing a Messaging System: WebSphere MQ vs. WebSphere Application Server Service Integration Bus
A question that sometimes comes up in our architecture whiteboarding sessions is about the different messaging strategies that are available in Websphere Application Server. IBM developerWorks has now published a great article detailing the differences between WebSphere MQ and the Service Integration Bus that comes with WebSphere Application Server. Check it out by clicking here.
Thursday, September 15, 2011
Cyber Security in High Demand
The old adage says: "keep your friends close, but your enemies closer". In this day and age, the IT department of your organization does not have to worry about the second part. The enemies are already at the gates. And keeping them out is an increasingly challenging task.
A recent study sponsored by Juniper Networks showed that not only there has been a dramatic rise in the number of security breaches in the past year, but the targets have also gotten bigger. The CIA, the FBI, the U.S. Senate, and various state police agencies had their systems under attack. In the first half of 2011 security and data breaches have cost U.S. enterprises almost $96 billion. At this rate the cost for the whole 2011 will be almost twice as much as it was in all of 2010. Consider the fact that 2010 saw 90% of businesses compromised with least one security breach. More than 50% of the compromised businesses had at least two breaches.
Another problem is that "the gates", where the enemies are trying to get through, are everywhere now. The entry points are in the software used by employees. They are in files, emails, web apps, web sites, databases, in everything that is on the information highway. The number of incidents related to malware went up from 4 million in the first quarter of 2010 to 6 million in the first quarter of 2011. It is expected that last year's record $63 billion that companies spent on security will be $75.6 billion in 2011.
As the study showed, the enemies get smarter and the attacks get more complicated in every year. Throw all your defenses up, get every firewall ready, the host and network intrusion protection and detection system, anti-virus, anti-malware, application firewalls and it will still be not enough, because the enemies are a step ahead. The solution? "Know yourself and know your enemy" (Sun Zhu, "Art of War"). Get the right security talent on board and use the right strategy.
The correct strategy, rooted in the governance, risk management and compliance methodology can go a long way. Consider the governance, a system by which an organization controls and directs security development, as a backbone of the approach to managing security and how it relates to the business (http://www.cert.org/governance/ges.html). Then, focus on the compliance and regulations, a key to proactive defenses and enforced regulations of a company's behavior as it pertains to security for a specific nature of the business. Governance is strategic, while compliance is tactical and specific. Addressing compliance and security regulations allows business to focus on particular challenges and vulnerabilities specific to the business type and the vertical it operates in. Finally, adjust risk management, a set of technologies that address day-to-day security work, and include mature components of security such as penetration testing, application security analysis, firewalls and intrusion prevention systems. The success of the security strategy depends on the attention to all three components.
The talent is a different thing. With the increase in the demand for the security experts, in response to the increased attacks, the security talent is becoming more expensive and harder to find. So far, the number of college students with who focus on cyber-security has not been keeping up with the demand. There are even less opportunities in finding experienced security consultants who are up to par with the criminal masterminds of the security underground. Security may be on the radar for around 1.9 million people, but there are only around 346,000 fully dedicated security professionals.
There are, however, security consulting firms, like Prolifics Security Practice (http://www.prolifics.com/business-solutions-security.htm) that can help you both with the talent and the strategy. They bring the best and the brightest security personnel on site to analyze, architect, develop and implement proper defenses and policies to address modern security threats. They help set up proper strategy, so you protect the flanks, tie up the loose ends and govern smartly.
With the increasing number and the caliber of the security breaches you cannot afford to sit around and wait. Find what others are doing, go to conferences, ask consultants, bring help, but do something, because enemies are at the gate.
If you want to read more on the recent rise of the cyber attacks look here: http://articles.latimes.com/2011/jul/05/business/la-fi-hacking-security-20110705
Prolifics will be discussing cyber security in greater depth as a sponsor and speaker at the upcoming Cyber Security for Energy Delivery Conference on September 27-28. The event takes place in San Jose, CA and brings together major utility and asset owners and key government agencies from across North America. I will be co-speaking with IBM at this conference. With experience providing security solutions for the energy and utilities industry, we will be sharing our security solutions and recent case studies around ID and password management, single sign-on, directory services, Web-based authorization, federation and other areas. For more information on the Cyber Security for Energy Delivery conference, please click here.
Alex Ivkin is a senior IT Security Architect with a focus in Identity and Access Management at Prolifics. Mr. Ivkin has worked with executive stakeholders in large and small organizations to help drive security initiatives. He has helped companies succeed in attaining regulatory compliance, improving business operations and securing enterprise infrastructure. Mr. Ivkin has achieved the highest levels of certification with several major Identity Management vendors and holds the CISSP designation. He is also a speaker at various conferences and an active member of several user communities.
A recent study sponsored by Juniper Networks showed that not only there has been a dramatic rise in the number of security breaches in the past year, but the targets have also gotten bigger. The CIA, the FBI, the U.S. Senate, and various state police agencies had their systems under attack. In the first half of 2011 security and data breaches have cost U.S. enterprises almost $96 billion. At this rate the cost for the whole 2011 will be almost twice as much as it was in all of 2010. Consider the fact that 2010 saw 90% of businesses compromised with least one security breach. More than 50% of the compromised businesses had at least two breaches.
Another problem is that "the gates", where the enemies are trying to get through, are everywhere now. The entry points are in the software used by employees. They are in files, emails, web apps, web sites, databases, in everything that is on the information highway. The number of incidents related to malware went up from 4 million in the first quarter of 2010 to 6 million in the first quarter of 2011. It is expected that last year's record $63 billion that companies spent on security will be $75.6 billion in 2011.
As the study showed, the enemies get smarter and the attacks get more complicated in every year. Throw all your defenses up, get every firewall ready, the host and network intrusion protection and detection system, anti-virus, anti-malware, application firewalls and it will still be not enough, because the enemies are a step ahead. The solution? "Know yourself and know your enemy" (Sun Zhu, "Art of War"). Get the right security talent on board and use the right strategy.
The correct strategy, rooted in the governance, risk management and compliance methodology can go a long way. Consider the governance, a system by which an organization controls and directs security development, as a backbone of the approach to managing security and how it relates to the business (http://www.cert.org/governance/ges.html). Then, focus on the compliance and regulations, a key to proactive defenses and enforced regulations of a company's behavior as it pertains to security for a specific nature of the business. Governance is strategic, while compliance is tactical and specific. Addressing compliance and security regulations allows business to focus on particular challenges and vulnerabilities specific to the business type and the vertical it operates in. Finally, adjust risk management, a set of technologies that address day-to-day security work, and include mature components of security such as penetration testing, application security analysis, firewalls and intrusion prevention systems. The success of the security strategy depends on the attention to all three components.
The talent is a different thing. With the increase in the demand for the security experts, in response to the increased attacks, the security talent is becoming more expensive and harder to find. So far, the number of college students with who focus on cyber-security has not been keeping up with the demand. There are even less opportunities in finding experienced security consultants who are up to par with the criminal masterminds of the security underground. Security may be on the radar for around 1.9 million people, but there are only around 346,000 fully dedicated security professionals.
There are, however, security consulting firms, like Prolifics Security Practice (http://www.prolifics.com/business-solutions-security.htm) that can help you both with the talent and the strategy. They bring the best and the brightest security personnel on site to analyze, architect, develop and implement proper defenses and policies to address modern security threats. They help set up proper strategy, so you protect the flanks, tie up the loose ends and govern smartly.
With the increasing number and the caliber of the security breaches you cannot afford to sit around and wait. Find what others are doing, go to conferences, ask consultants, bring help, but do something, because enemies are at the gate.
If you want to read more on the recent rise of the cyber attacks look here: http://articles.latimes.com/2011/jul/05/business/la-fi-hacking-security-20110705
Prolifics will be discussing cyber security in greater depth as a sponsor and speaker at the upcoming Cyber Security for Energy Delivery Conference on September 27-28. The event takes place in San Jose, CA and brings together major utility and asset owners and key government agencies from across North America. I will be co-speaking with IBM at this conference. With experience providing security solutions for the energy and utilities industry, we will be sharing our security solutions and recent case studies around ID and password management, single sign-on, directory services, Web-based authorization, federation and other areas. For more information on the Cyber Security for Energy Delivery conference, please click here.
Alex Ivkin is a senior IT Security Architect with a focus in Identity and Access Management at Prolifics. Mr. Ivkin has worked with executive stakeholders in large and small organizations to help drive security initiatives. He has helped companies succeed in attaining regulatory compliance, improving business operations and securing enterprise infrastructure. Mr. Ivkin has achieved the highest levels of certification with several major Identity Management vendors and holds the CISSP designation. He is also a speaker at various conferences and an active member of several user communities.
Tuesday, August 16, 2011
Test Automation for SAP Packaged Applications
SAP Packaged Applications allow you to rapidly configure and customize business processes as your environment changes. To ensure the quality, performance and reliability of these applications, you need a sophisticated testing solution that can be configured and customized as quickly as your SAP landscape. In this article, we will show you how you can use your IBM® Rational® Functional Tester (RFT) toolset along with tools from IBM Ready-for-Rational partner, Arsin.
In this blog entry, I will discuss:
A Structured Approach to SAP Testing
SAP implementations pose some of the most intriguing and difficult challenges in the QA universe. The thickly netted system is extremely integrated and is typically linked to every business process in the enterprise. To tackle such an immense system, QA engineers must approach SAP applications with care.
With more than a decade of experience in testing SAP systems for a large client base in myriad industry verticals, we have developed a test maturity model assessment and improvement framework to bring about an organized and a structured approach to SAP testing. This framework has a three pronged approach, which offers process improvement, knowledge management, and test automation, as follows:
1. Process improvement. Process improvement deals with the assessment of the current Test Maturity Model and developing a plan to improve the Test Maturity Model to the next level and then implement it. A mature test process that has standardized templates, well-defined processes, clear protocols, and no bottlenecks provides for a complete and comprehensively tested SAP system. By comparing the current test maturity model with industry standards and identifying the gaps and focusing on them, test maturity can be improved.
2. Knowledge management. Knowledge management deals with institutionalizing QA knowledge collected over time. Traditional testing for SAP systems relies on the functional and technical consultants of the SAP system for subject matter expertise to deal with various instances. In this phase, test artifact libraries are built for critical business process for regression. The following test artifacts are documented:
The remainder of this discussion focuses on the test automation aspect of the Structured SAP Testing Approach. Our belief is that RFT, in conjunction with Arsin's Effecta Validation Engine, makes SAP testing thorough, comprehensive, easy, and cost effective.
Importance of Test Automation in SAP Implementations
The SAP landscape is continuously changing, as a result of changes to SAP modules from SAP, business process changes within the client’s company, changes to the system environment, changes to applications interfacing with SAP, and a multitude of regulatory compliance mandates.
In order to keep up with these changes, SAP systems must be thoroughly tested. With every change, there is a regression library of test cases that needs to be executed to ensure stability. Each test requires time and effort when executed manually; by comparison, automated test take a very small fraction of the time and effort to execute. Automation also helps makes most of the test assets reusable.
Current SAP Testing Solutions and their Limitations
The existing SAP testing model on the market today makes a very rudimentary use of automation, in terms of:
Validation: In most cases, user interface (UI) tools that are available are used to automate test execution, which is only about 25% of the total testing effort. Validation represents more than 75% of this effort, and scrubbing the data using UI test automation tools is difficult. A certain level of validation is possible through UI based test automation tools, however it takes a long time to script this validation and any change requires a lot of coding following the first implementation.
Data management: Traditionally, data used for testing is captured and maintained in spreadsheets. Searching and sorting through this data is difficult, as is maintaining the consistency of data across users and locations. This difficulty is compounded by ever increasing volumes of test data to be maintained. In addition, there is no intelligent association between SAP metadata and its corresponding test data.
Managing change: Changes to SAP implementations occur during reconfiguration or the addition of custom-built components (programs). In these situations, the scripts for automated test execution need to be changed regularly, which is difficult. Moreover, when using UI tools for automation, 75% of the effort needs to be constantly re-worked to keep up with the changes to the SAP system.
Addressing these Limitations
The limitations above described call for a new solution that can address these issues. We offer a complete and scalable testing solution that combines Arsin Effecta Validation Engine with IBM Rational Functional Tester.
By automating the validation of data, business processes, custom development and integrations across SAP applications, you can increase the quality of implementation, support multiple changes in their environment and mitigate business risks. Also, by eliminating manual testing you can avoid greater difficulties in production that ultimately impact the quality and performance of the business. Arsin’s Effecta Test Suite provides the benefits of a complete testing solution by automating impact analyses of changes, test data maintenance, test execution and validation.
Figure 1: Arsin Effecta Solution Architecture for testing SAP applications
Test Data Manager
Stores test data along with criteria in the Effecta database. Before executing an automated test, validity of test data is checked on the target system and system is automatically updated. If the test data no longer exists in the target system or cannot be reused, the data set update feature will help to refresh with new valid data.
Script Manager
Automatically enhances recorded scripts and eliminates need for customization. Script manager enables script less automation of IBM Rational Functional Tester.
Change Impact Manager
When changes occur in a system, Change Impact Manager automatically extracts affected objects and identifies test cases to be executed for regression testing. It also identifies objects being changed that don’t have test cases in the library.
Report Manager
Report Manager provides out-of-the-box reports for tracking test artifacts, development and test execution. Detailed test results pinpoint failed events in test case.
Test Manager
Effecta promotes reusability and repeatability with the following features:
- Ability to create Test Requirements and link them to Test Cases and development objects
- Ability to create Test Cases and link them to Test Requirements for coverage analysis
- Ability to create separate Test execution steps in the form of Test Procedures and link them to Test cases
- Defect management
- Dashboard for reporting and metrics
Validation Manager for Middleware
Simulates inbound messages at various data interchange points and validates outbound messages.
Automatically validates translations and mappings
Validation Manager for Transactional Systems
Validation Manager for Transactional Systems is a completely configurable, customizable and readily deployable validation library of components for various business processes. It significantly accelerates validation by automatically extracting the actual data created by transactions and comparing it with expected results. The Validation Manager is specifically designed to support SAP systems.
Validation Manager for BI
Tests Business Intelligence systems during initial implementation and during maintenance and support pack deployments. It also automates the validation of data loaded from multiple ERP and other systems. Provides sophisticated reporting including detailed results.
Conclusion
The benefits of using automation in SAP testing are abundant. Test automation, deployed with minimal effort, enables increased test coverage, which in turn reduces cycle time and enables efficient bug detection early in the development cycle. Since test automation is designed for reusability, routine tasks are eliminated and total cost of ownership is reduced. Test automation is far more precise and consistent, and features standardized reporting, enabling clear test analysis across the QA environment.
Sarat Addanki is the Vice President, ERP Practice. He has 18 years of experience in the ERP arena including design, development and testing of ERP implementations. He was part of a SAP Quality professionals team contributing to the design of SAP Test Accelerator TAO. He founded the ERP Division at Arsin, which focuses on developing frameworks and accelerators to ensure delivery excellence, reduce the overall cost of ownership and increase productivity in ERP implementations. The Test Accelerators he designed significantly improve the testing process, knowledge management and test automation. His division focuses on providing quality services for SAP, Oracle, PeopleSoft, Sterling, Retek and Middleware applications. His domain expertise ranges from Pharmaceutical Distribution, Hi-Tech, Manufacturing to Retail industries. He is a PMI (Project Management Institute) certified Project Management Professional (PMP). Sarat holds a bachelor's degree in Computer Science and Engineering from Osmania University, Hyderabad, India.
In this blog entry, I will discuss:
- A structured approach to SAP testing
- SAP current test automation paradigm and its challenges
- The need for a new solution for SAP test automation
- How Arsin Packaged Test Automation for SAP integrated with IBM Rational Functional Tester helps address these challenges
A Structured Approach to SAP Testing
SAP implementations pose some of the most intriguing and difficult challenges in the QA universe. The thickly netted system is extremely integrated and is typically linked to every business process in the enterprise. To tackle such an immense system, QA engineers must approach SAP applications with care.
With more than a decade of experience in testing SAP systems for a large client base in myriad industry verticals, we have developed a test maturity model assessment and improvement framework to bring about an organized and a structured approach to SAP testing. This framework has a three pronged approach, which offers process improvement, knowledge management, and test automation, as follows:
1. Process improvement. Process improvement deals with the assessment of the current Test Maturity Model and developing a plan to improve the Test Maturity Model to the next level and then implement it. A mature test process that has standardized templates, well-defined processes, clear protocols, and no bottlenecks provides for a complete and comprehensively tested SAP system. By comparing the current test maturity model with industry standards and identifying the gaps and focusing on them, test maturity can be improved.
2. Knowledge management. Knowledge management deals with institutionalizing QA knowledge collected over time. Traditional testing for SAP systems relies on the functional and technical consultants of the SAP system for subject matter expertise to deal with various instances. In this phase, test artifact libraries are built for critical business process for regression. The following test artifacts are documented:
- Test Requirements
- Test Cases
- Test Procedures
The remainder of this discussion focuses on the test automation aspect of the Structured SAP Testing Approach. Our belief is that RFT, in conjunction with Arsin's Effecta Validation Engine, makes SAP testing thorough, comprehensive, easy, and cost effective.
Importance of Test Automation in SAP Implementations
The SAP landscape is continuously changing, as a result of changes to SAP modules from SAP, business process changes within the client’s company, changes to the system environment, changes to applications interfacing with SAP, and a multitude of regulatory compliance mandates.
In order to keep up with these changes, SAP systems must be thoroughly tested. With every change, there is a regression library of test cases that needs to be executed to ensure stability. Each test requires time and effort when executed manually; by comparison, automated test take a very small fraction of the time and effort to execute. Automation also helps makes most of the test assets reusable.
Current SAP Testing Solutions and their Limitations
The existing SAP testing model on the market today makes a very rudimentary use of automation, in terms of:
Validation: In most cases, user interface (UI) tools that are available are used to automate test execution, which is only about 25% of the total testing effort. Validation represents more than 75% of this effort, and scrubbing the data using UI test automation tools is difficult. A certain level of validation is possible through UI based test automation tools, however it takes a long time to script this validation and any change requires a lot of coding following the first implementation.
Data management: Traditionally, data used for testing is captured and maintained in spreadsheets. Searching and sorting through this data is difficult, as is maintaining the consistency of data across users and locations. This difficulty is compounded by ever increasing volumes of test data to be maintained. In addition, there is no intelligent association between SAP metadata and its corresponding test data.
Managing change: Changes to SAP implementations occur during reconfiguration or the addition of custom-built components (programs). In these situations, the scripts for automated test execution need to be changed regularly, which is difficult. Moreover, when using UI tools for automation, 75% of the effort needs to be constantly re-worked to keep up with the changes to the SAP system.
Addressing these Limitations
The limitations above described call for a new solution that can address these issues. We offer a complete and scalable testing solution that combines Arsin Effecta Validation Engine with IBM Rational Functional Tester.
By automating the validation of data, business processes, custom development and integrations across SAP applications, you can increase the quality of implementation, support multiple changes in their environment and mitigate business risks. Also, by eliminating manual testing you can avoid greater difficulties in production that ultimately impact the quality and performance of the business. Arsin’s Effecta Test Suite provides the benefits of a complete testing solution by automating impact analyses of changes, test data maintenance, test execution and validation.
Figure 1: Arsin Effecta Solution Architecture for testing SAP applications
Test Data Manager
Stores test data along with criteria in the Effecta database. Before executing an automated test, validity of test data is checked on the target system and system is automatically updated. If the test data no longer exists in the target system or cannot be reused, the data set update feature will help to refresh with new valid data.
Script Manager
Automatically enhances recorded scripts and eliminates need for customization. Script manager enables script less automation of IBM Rational Functional Tester.
Change Impact Manager
When changes occur in a system, Change Impact Manager automatically extracts affected objects and identifies test cases to be executed for regression testing. It also identifies objects being changed that don’t have test cases in the library.
Report Manager
Report Manager provides out-of-the-box reports for tracking test artifacts, development and test execution. Detailed test results pinpoint failed events in test case.
Test Manager
Effecta promotes reusability and repeatability with the following features:
- Ability to create Test Requirements and link them to Test Cases and development objects
- Ability to create Test Cases and link them to Test Requirements for coverage analysis
- Ability to create separate Test execution steps in the form of Test Procedures and link them to Test cases
- Defect management
- Dashboard for reporting and metrics
Validation Manager for Middleware
Simulates inbound messages at various data interchange points and validates outbound messages.
Automatically validates translations and mappings
Validation Manager for Transactional Systems
Validation Manager for Transactional Systems is a completely configurable, customizable and readily deployable validation library of components for various business processes. It significantly accelerates validation by automatically extracting the actual data created by transactions and comparing it with expected results. The Validation Manager is specifically designed to support SAP systems.
Validation Manager for BI
Tests Business Intelligence systems during initial implementation and during maintenance and support pack deployments. It also automates the validation of data loaded from multiple ERP and other systems. Provides sophisticated reporting including detailed results.
Conclusion
The benefits of using automation in SAP testing are abundant. Test automation, deployed with minimal effort, enables increased test coverage, which in turn reduces cycle time and enables efficient bug detection early in the development cycle. Since test automation is designed for reusability, routine tasks are eliminated and total cost of ownership is reduced. Test automation is far more precise and consistent, and features standardized reporting, enabling clear test analysis across the QA environment.
Sarat Addanki is the Vice President, ERP Practice. He has 18 years of experience in the ERP arena including design, development and testing of ERP implementations. He was part of a SAP Quality professionals team contributing to the design of SAP Test Accelerator TAO. He founded the ERP Division at Arsin, which focuses on developing frameworks and accelerators to ensure delivery excellence, reduce the overall cost of ownership and increase productivity in ERP implementations. The Test Accelerators he designed significantly improve the testing process, knowledge management and test automation. His division focuses on providing quality services for SAP, Oracle, PeopleSoft, Sterling, Retek and Middleware applications. His domain expertise ranges from Pharmaceutical Distribution, Hi-Tech, Manufacturing to Retail industries. He is a PMI (Project Management Institute) certified Project Management Professional (PMP). Sarat holds a bachelor's degree in Computer Science and Engineering from Osmania University, Hyderabad, India.
Friday, July 22, 2011
Panther Applications in Croatia
Brief History
When the Prolifics application development toolset came to the Croatian market in 1990, independent software vendor company Pardus (then 4-MATE) chose it to develop a back office application for a large retailer. The character-mode JAM5 application was running on an Intel-based UNIX system, with 60+ concurrent users, the largest in the region at that time.
Based on the successful experience with the Prolifics toolset, Pardus developed another large integrated information system for retail banks. The platform was again character mode JAM5 on UNIX, with custom mechanisms for distributed database support. The system has since migrated to the recent version of Panther and is still in use today.
Pardus continued to use JAM and Panther for its own development, and started to distribute it to other Independent Software Venders (ISV) and end user organizations with their own IT staff. Programs for JAM and Panther training, consulting, project management, and end-user development team mentoring were created. This contributed to the rapid success of the tool in the Croatian market.
As a result, Panther is now used by the two largest banks in the country. One of them still uses the originally Pardus-developed software for its core data processing, supported by 70+ in-house Panther developers and a team of Pardus consultants. Other users, apart from ISV houses, include departments like the Croatian postal services, customs, health insurance, several ministries and Zagreb municipal administrations.
An Example: Forensic DNA Database
Pardus uses and encourages other fellow-developers to use Panther for a wide variety of applications. One interesting example is the Pardus-developed eQMS::DNA application, a DNA “fingerprint” database, now in use in Central Forensic Laboratories in two countries.
When the opportunity to develop such an application arrived, Pardus again chose Panther because of its excellent rapid prototyping abilities, flexibility of its scripting language and the versatility of its database transaction generator. Native XML import and export capabilities were an advantage.
The resulting eQMS::DNA application is a system primarily used for maintenance and efficient searching of database of human genotypes for forensic purposes (such as identification of biological traces like blood, hair, skin etc), but also has the capability to be used in fields such as livestock lineage tracking.
DNA fingerprinting relies on the fact that certain points in human (or other) genome (loci) change relatively quickly (display polymorphism) from generation to generation – fast enough to form a combination unique for an individual, but slowly enough to be stable within single individual's cells. The type of polymorphisms and number of loci used for constructing genotypes in eQMS::DNA is configurable, but typical installation will employ a standard set of 13 to 18 STR (short tandem repeat) loci.
The system maintains data on individual donors with optional end-user configurable personal and demographic data, multiple samples containing genetic material taken from the donor, and genotypes obtained from the samples, possibly using multiple techniques and identification kits. Both processed genotypes and optional additional data such as peak quality, confidence parameters and raw electroferograms can be kept. The system also keeps profiles of unidentified traces.
Manual entry of data to Panther screens, from plate gel electrophoresis is possible, but the typical data source results from automated capillary electrophoresis sequencers. Communication with systems such as Interpol DNA Gateway is also supported.
The searches can be performed interactively or in full automatic mode. All searches, including those using partial profiles and relaxed criteria are typically done in less than a second. The system also supports mixed-stain searches with provisions for common contaminant identification (such as genotypes of laboratory or other forensic personnel).
Interpol maintains a list of available DNA profiling systems (probably the most well known being FBI CODIS). eQMS::DNA is the only application from a commercial software developer.
New Developments
Pardus has assisted many clients in modernizing their legacy character-mode JAM and Panther applications.
For example, a Complex Card Management application for a leading Croatian bank was recently ported from JAM5 character-mode to Panther5 GUI. Initial functionality was complete within a month, with an additional month spent adding capabilities made possible by the new version of the Panther tool.
Pardus mentored several of their customers as they transitioned from character-mode to GUI to the Web environment, and from 2-tier to multi-tier architecture. One example includes developing a Java wrapper to call mainframe-based Web services from within a 2-tier GUI and Web Panther application. Another customer, a public health institution, uses the similar Pardus-provided tool to provide their clients with controlled access to their LIMS software (also developed by Pardus) that contains data on analysis of food and water samples.
Despite the market focus shifting away from dedicated application development toolsets, Panther stays a viable product in the Croatian market, thanks to the high penetration and the level of experience and expertise available to its customers.
For more info see http://dna.pardus.hr/ and http://lims.pardus.hr/.
Dragi Raos is a co-founder of Pardus d.o.o a software development and IT consulting company from Zagreb, Croatia. Pardus is a distributor of Panther and JAM in Croatia. Dragi has three decades of experience in technical and scientific computing, design and development of complex financial applications and training and coaching of development teams, he has served as team leader or technical consultant with clients ranging from International Atomic Energy Agency to large regional banks to public health institutions. Dragi's technical expertise includes database management systems, middleware, CASE tools and a wide range of development environments, including 20 years of experience with Panther and all versions of JAM.
When the Prolifics application development toolset came to the Croatian market in 1990, independent software vendor company Pardus (then 4-MATE) chose it to develop a back office application for a large retailer. The character-mode JAM5 application was running on an Intel-based UNIX system, with 60+ concurrent users, the largest in the region at that time.
Based on the successful experience with the Prolifics toolset, Pardus developed another large integrated information system for retail banks. The platform was again character mode JAM5 on UNIX, with custom mechanisms for distributed database support. The system has since migrated to the recent version of Panther and is still in use today.
Pardus continued to use JAM and Panther for its own development, and started to distribute it to other Independent Software Venders (ISV) and end user organizations with their own IT staff. Programs for JAM and Panther training, consulting, project management, and end-user development team mentoring were created. This contributed to the rapid success of the tool in the Croatian market.
As a result, Panther is now used by the two largest banks in the country. One of them still uses the originally Pardus-developed software for its core data processing, supported by 70+ in-house Panther developers and a team of Pardus consultants. Other users, apart from ISV houses, include departments like the Croatian postal services, customs, health insurance, several ministries and Zagreb municipal administrations.
An Example: Forensic DNA Database
Pardus uses and encourages other fellow-developers to use Panther for a wide variety of applications. One interesting example is the Pardus-developed eQMS::DNA application, a DNA “fingerprint” database, now in use in Central Forensic Laboratories in two countries.
When the opportunity to develop such an application arrived, Pardus again chose Panther because of its excellent rapid prototyping abilities, flexibility of its scripting language and the versatility of its database transaction generator. Native XML import and export capabilities were an advantage.
The resulting eQMS::DNA application is a system primarily used for maintenance and efficient searching of database of human genotypes for forensic purposes (such as identification of biological traces like blood, hair, skin etc), but also has the capability to be used in fields such as livestock lineage tracking.
DNA fingerprinting relies on the fact that certain points in human (or other) genome (loci) change relatively quickly (display polymorphism) from generation to generation – fast enough to form a combination unique for an individual, but slowly enough to be stable within single individual's cells. The type of polymorphisms and number of loci used for constructing genotypes in eQMS::DNA is configurable, but typical installation will employ a standard set of 13 to 18 STR (short tandem repeat) loci.
The system maintains data on individual donors with optional end-user configurable personal and demographic data, multiple samples containing genetic material taken from the donor, and genotypes obtained from the samples, possibly using multiple techniques and identification kits. Both processed genotypes and optional additional data such as peak quality, confidence parameters and raw electroferograms can be kept. The system also keeps profiles of unidentified traces.
Manual entry of data to Panther screens, from plate gel electrophoresis is possible, but the typical data source results from automated capillary electrophoresis sequencers. Communication with systems such as Interpol DNA Gateway is also supported.
The searches can be performed interactively or in full automatic mode. All searches, including those using partial profiles and relaxed criteria are typically done in less than a second. The system also supports mixed-stain searches with provisions for common contaminant identification (such as genotypes of laboratory or other forensic personnel).
Interpol maintains a list of available DNA profiling systems (probably the most well known being FBI CODIS). eQMS::DNA is the only application from a commercial software developer.
Figure 1:Screen shot of eQMS::DNA profiling application
New Developments
Pardus has assisted many clients in modernizing their legacy character-mode JAM and Panther applications.
For example, a Complex Card Management application for a leading Croatian bank was recently ported from JAM5 character-mode to Panther5 GUI. Initial functionality was complete within a month, with an additional month spent adding capabilities made possible by the new version of the Panther tool.
Pardus mentored several of their customers as they transitioned from character-mode to GUI to the Web environment, and from 2-tier to multi-tier architecture. One example includes developing a Java wrapper to call mainframe-based Web services from within a 2-tier GUI and Web Panther application. Another customer, a public health institution, uses the similar Pardus-provided tool to provide their clients with controlled access to their LIMS software (also developed by Pardus) that contains data on analysis of food and water samples.
Despite the market focus shifting away from dedicated application development toolsets, Panther stays a viable product in the Croatian market, thanks to the high penetration and the level of experience and expertise available to its customers.
For more info see http://dna.pardus.hr/ and http://lims.pardus.hr/.
Dragi Raos is a co-founder of Pardus d.o.o a software development and IT consulting company from Zagreb, Croatia. Pardus is a distributor of Panther and JAM in Croatia. Dragi has three decades of experience in technical and scientific computing, design and development of complex financial applications and training and coaching of development teams, he has served as team leader or technical consultant with clients ranging from International Atomic Energy Agency to large regional banks to public health institutions. Dragi's technical expertise includes database management systems, middleware, CASE tools and a wide range of development environments, including 20 years of experience with Panther and all versions of JAM.
Wednesday, July 13, 2011
Learn About Security: Open Authorization in Federated Applications using IBM Security Tools
IBM Tivoli Federated Identity Manager (TFIM) simplifies application integration by providing single sign on between disparate web applications, so the users do not have to share their passwords or re-enter them. TFIM uses various protocols to achieve federation, which include SAML, WS-Federation, and OpenID. Our Security LoB has been invited by IBM to participate in a beta program to implement the popular authorization protocol, OAuth. OAuth, which stands for Open Authorization, is a protocol that allows users to approve applications to act on their behalf. OAuth makes it possible to exchange critical information across distinct organizations based upon a service level agreement that states one application as an OAuth client and the other as an OAuth provider. One major benefit of the OAuth protocol is its emphasis on authorization, when compared to its alternatives. This is giving rise to a hybrid model in which our customers can combine protocols like SAML or OpenID for authentication and OAuth for authorization. OAuth, besides making the token exchange mechanism transparent to the user, provides mechanisms to define the scope which the Client could access regarding the user’s data on the Provider.
Here is a fictitious example. Imagine PFAP as a financial application dashboard developed by Prolifics that provides a user with a consolidated view of his account balances across multiple banks. First, PFAP would have to be in an agreement as an OAuth client across all of the banks, from which account information would be obtained on behalf of the user. Once an agreement is set up with each Provider, PFAP would be registered as an OAuth client to those particular banks (Providers) and so would be provided with a client ID and a shared secret for each one. This information (Client ID, Shared Secret) would help the Provider determine, if the application (Client) requesting data on behalf of user, is one of its trusted OAuth clients. Assuming an agreement between Prolifics and a leading financial firm, PFAP is one of the OAuth clients that has access to the Firm's customer data, upon approval. The first time a user logs into the PFAP application, he will be asked to add his account number to PFAP. Once the user selects “Add Account” button, the user would be redirected to the Firm's website, where he would be asked to put in his credentials. At this step a token would be requested by PFAP from the Firm in the background, which gets authorized upon user logging into the Firm's website. This action grants access to PFAP to act on the user’s behalf.
From the user’s perspective, once logged in the Firm would display a “Consent to Authorize” page where the user would needs to permit access to PFAP to act on his behalf and retrieve information within a certain scope, which in this case would be user’s account balance. Once the user agrees to permit PFAP to act on his behalf and retrieve balance information, a verifier code is sent to PFAP in the background. PFAP would then request an access token from the Firm's application sending the verifier code, Client ID, Shared Secret and few other parameters to request an Access token. The Firm would verify the Client ID and Shared Secret to determine if PFAP is one of its OAuth clients and then would verify the Verifier Code to generate an Access token. Once PFAP receives the Access token, it enables PFAP to get the user’s data on his behalf though within a permitted scope, which in this case would be the account balance. So next time the user logs in, since PFAP would already have an Access token, the user would be able to see his balance information without having to login to the Firm's website. Now, implementation of hybrid models is being thought upon, where a combination of OAuth with protocols like SAML or OpenID would help us achieve SSO at the same time. For instance, once logged into PFAP, an implementation of hybrid model would enable the user to perform other operations in the Firm's website like balance transfers, by launching a new link to the Firm without the need to login again (SSO).
Here is a fictitious example. Imagine PFAP as a financial application dashboard developed by Prolifics that provides a user with a consolidated view of his account balances across multiple banks. First, PFAP would have to be in an agreement as an OAuth client across all of the banks, from which account information would be obtained on behalf of the user. Once an agreement is set up with each Provider, PFAP would be registered as an OAuth client to those particular banks (Providers) and so would be provided with a client ID and a shared secret for each one. This information (Client ID, Shared Secret) would help the Provider determine, if the application (Client) requesting data on behalf of user, is one of its trusted OAuth clients. Assuming an agreement between Prolifics and a leading financial firm, PFAP is one of the OAuth clients that has access to the Firm's customer data, upon approval. The first time a user logs into the PFAP application, he will be asked to add his account number to PFAP. Once the user selects “Add Account” button, the user would be redirected to the Firm's website, where he would be asked to put in his credentials. At this step a token would be requested by PFAP from the Firm in the background, which gets authorized upon user logging into the Firm's website. This action grants access to PFAP to act on the user’s behalf.
From the user’s perspective, once logged in the Firm would display a “Consent to Authorize” page where the user would needs to permit access to PFAP to act on his behalf and retrieve information within a certain scope, which in this case would be user’s account balance. Once the user agrees to permit PFAP to act on his behalf and retrieve balance information, a verifier code is sent to PFAP in the background. PFAP would then request an access token from the Firm's application sending the verifier code, Client ID, Shared Secret and few other parameters to request an Access token. The Firm would verify the Client ID and Shared Secret to determine if PFAP is one of its OAuth clients and then would verify the Verifier Code to generate an Access token. Once PFAP receives the Access token, it enables PFAP to get the user’s data on his behalf though within a permitted scope, which in this case would be the account balance. So next time the user logs in, since PFAP would already have an Access token, the user would be able to see his balance information without having to login to the Firm's website. Now, implementation of hybrid models is being thought upon, where a combination of OAuth with protocols like SAML or OpenID would help us achieve SSO at the same time. For instance, once logged into PFAP, an implementation of hybrid model would enable the user to perform other operations in the Firm's website like balance transfers, by launching a new link to the Firm without the need to login again (SSO).
Tuesday, July 12, 2011
BPM Best Practices for the Financial Industry
In our current economic environment, the financial industry is challenged today by two very significant needs to improve efficiency and enhance service. I spoke about these business needs last year at an event hosted by Prolifics and IBM, and they couldn’t be more significant today. To satisfy these requirements, organizations are tasked with driving down costs by consolidating duplicated and siloed systems into well-defined, reusable services and managing customer service levels with greater flexibility.
This industry has a collection of 'habits,' or best practices, that have a powerful effect on business performance in these critical areas. Over time, we have captured the best practices that have proven to be successful with process management programs within the financial industry. At this seminar, we reviewed 11 specific practices that help financial services organizations experience success with projects/delivery, team competency and leveraging Business Process Management (BPM) across the enterprise.
I’d like to share some of these ‘habits’ with you now:
Make BPM about Productivity and Visibility
Never “One and Done”
Don’t Skip Process Analysis
Build a Complete Team
Establish the Owners
In addition, financial institutions face a highly demanding environment requiring exceeding agility. The seminar focused on how customers can reap the benefits of the business rule approach to operational decision making in the areas of payments, credit and lending, risk management and customer care for financial institutions. With business rules, key decisions in your financial processes can be changed in minutes to days rather than months - bringing new levels of efficiency to day-to-day operations.
To read more about these 11 Habits for highly successful BPM programs and the benefits of a business rules management system, please take a look at this presentation. For any questions about these topics or Prolifics’ solutions for the financial industry, please email solutions@prolifics.com.
Don Rivera is a Client Executive with Prolifics managing the NY & NJ Metro territory. Don is a certified IBM WebSphere Solution Sales Professional working with SMB and Enterprise accounts to determine how to leverage IBM software technology to meet their critical business objectives. He brings over 16 years of experience working in the information technology industry in various system engineering, sales and business development roles with companies such as Computer Sciences Corporation, Level 3 Communications and BBN Technologies.
This industry has a collection of 'habits,' or best practices, that have a powerful effect on business performance in these critical areas. Over time, we have captured the best practices that have proven to be successful with process management programs within the financial industry. At this seminar, we reviewed 11 specific practices that help financial services organizations experience success with projects/delivery, team competency and leveraging Business Process Management (BPM) across the enterprise.
I’d like to share some of these ‘habits’ with you now:
Make BPM about Productivity and Visibility
- Metrics, KPIs and SLAs should be part of the DEFINE phase
- Don’t scope out metrics
- Remember: visibility is critical to improvement
Never “One and Done”
- Iterative Approach: continuous process improvement
- Additional phases or versions will always happen: The value in BPM is that you can get your first version out there quickly, but the real opportunity here is really in version 2, 3 and 4 where you are bringing entirely new levels of capability and sophistication of efficiency of effectiveness to your organization
Don’t Skip Process Analysis
- Processes are done by many different parties! Process analysis helps you understand: What does the end-to-end look like? What data is needed at different points? What is the velocity that we need in this process? How quickly do we need turnaround time?
- Process analysis sets apart traditional applications development from building process applications
Build a Complete Team
- Have the right mix of resources on the team with a broad set of skill sets
- Java (.NET) developers aren’t all you need
Establish the Owners
- A requirement for succeeding with BPM is that processes must be business-owned. You need people from the business to engage and determine what the process priorities are.
- They key benefit to this iterative approach is that you can make tradeoffs and changes to adapt to changing business conditions and requirements. A level of business engagement will ensure that the right decisions are being made.
In addition, financial institutions face a highly demanding environment requiring exceeding agility. The seminar focused on how customers can reap the benefits of the business rule approach to operational decision making in the areas of payments, credit and lending, risk management and customer care for financial institutions. With business rules, key decisions in your financial processes can be changed in minutes to days rather than months - bringing new levels of efficiency to day-to-day operations.
To read more about these 11 Habits for highly successful BPM programs and the benefits of a business rules management system, please take a look at this presentation. For any questions about these topics or Prolifics’ solutions for the financial industry, please email solutions@prolifics.com.
Don Rivera is a Client Executive with Prolifics managing the NY & NJ Metro territory. Don is a certified IBM WebSphere Solution Sales Professional working with SMB and Enterprise accounts to determine how to leverage IBM software technology to meet their critical business objectives. He brings over 16 years of experience working in the information technology industry in various system engineering, sales and business development roles with companies such as Computer Sciences Corporation, Level 3 Communications and BBN Technologies.
Thursday, May 26, 2011
Leveraging your Panther Assets with Web Services
Software applications have become a valuable component of modern enterprises. They contain critical business knowledge, and represent significant design and development effort. It only makes sense to extract as much value from these applications as possible. As enterprises grow and merge, the need to share the information in these applications becomes imperative. This applies to your Panther applications we well. For example, order entry systems need to talk to billing systems, shipping systems, and so on.
While there are many methods for accessing your Panther applications, Web Services provides a common method, across diverse platforms, products, and computer languages, in a well-defined manner. As long as each application implements the Web Services standards, applications can freely interoperate with each other. This bi-directional communication is independent of the technology that the target application was written in.
Your Panther applications can participate in this inter-application communication by implementing Web Services, multiplying the value within them. In this way, systems throughout your enterprise, or beyond, can benefit from the existing code and data within your Panther applications.
You can also utilize your Panther tools and skills to create new RAPID Database Transactional Web Services for just about any application. This is totally independent from your existing Panther applications and utilizes the same rapid development platform.
For a complimentary Discovery Call, please call your Business Development Manager at 1 (800) 458-3313 ext 2 or email crm@prolifics.com.
While there are many methods for accessing your Panther applications, Web Services provides a common method, across diverse platforms, products, and computer languages, in a well-defined manner. As long as each application implements the Web Services standards, applications can freely interoperate with each other. This bi-directional communication is independent of the technology that the target application was written in.
Your Panther applications can participate in this inter-application communication by implementing Web Services, multiplying the value within them. In this way, systems throughout your enterprise, or beyond, can benefit from the existing code and data within your Panther applications.
You can also utilize your Panther tools and skills to create new RAPID Database Transactional Web Services for just about any application. This is totally independent from your existing Panther applications and utilizes the same rapid development platform.
For a complimentary Discovery Call, please call your Business Development Manager at 1 (800) 458-3313 ext 2 or email crm@prolifics.com.
Subscribe to:
Posts (Atom)

