<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Layer 7 - Blogs &#187; Matt McLarty</title>
	<atom:link href="http://www.layer7tech.com/blogs/index.php/author/matt/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.layer7tech.com/blogs</link>
	<description>API Management &#124; SOA Governance &#124; Cloud Integration</description>
	<lastBuildDate>Wed, 19 Jun 2013 23:16:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Nation Building in the Age of APIs</title>
		<link>http://www.layer7tech.com/blogs/index.php/nation-building-in-the-age-of-apis/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/nation-building-in-the-age-of-apis/#comments</comments>
		<pubDate>Sat, 09 Mar 2013 00:27:33 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[API]]></category>
		<category><![CDATA[API Academy]]></category>
		<category><![CDATA[API Design & Optimization]]></category>
		<category><![CDATA[API Management]]></category>
		<category><![CDATA[API Security]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=4027</guid>
		<description><![CDATA[I’ve been working with a number of companies lately on their API strategies.  People seem to recognize that having an API is modern day necessity, but they’re not sure how to get started.  Since APIs are viewed as a technical innovations, responsibility for rolling them out is frequently handed to IT groups. Clearly, there is [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.layer7tech.com/blogs/wp-content/uploads/2013/03/nations-blog-Graphic1.jpg"><img class="alignleft size-full wp-image-4042" style="padding-right: 15px;"title="nations-blog-Graphic" src="http://www.layer7tech.com/blogs/wp-content/uploads/2013/03/nations-blog-Graphic1.jpg" alt="" width="300" height="220" /></a>I’ve been working with a number of companies lately on their API strategies.  People seem to recognize that having an API is modern day necessity, but they’re not sure how to get started.  Since APIs are viewed as a technical innovations, responsibility for rolling them out is frequently handed to IT groups.</p>
<p>Clearly, there is business value to be attained by companies who utilize an API, and an accessible web API is a requirement for modern corporations.  For companies looking to launch an API, there is a temptation to focus on the technological aspects of implementation.  Good API design, architecture, and infrastructure are vital to the success of a company’s API, but there are other areas to address first.  I am currently reading the book “<a href="http://whynationsfail.com/">Why Nations Fail</a>”, and recently read “<a href="http://www.amazon.ca/Thinking-Fast-Slow-Daniel-Kahneman/dp/0385676514">Thinking Fast and Slow</a>” by Daniel Kahneman.  Although the former is a geopolitical study whereas the latter focuses on the human mind, both share an identical observation that is the foundation of their arguments: a great amount of economic study is flawed because it fails to account for human behavior and tendencies.  I feel the same way about technology.</p>
<p>Every paradigm shift in technology has been driven by both innovation—the new technology itself—and application—how that technology can be used.  In other words, there is a machine side and a people side to every technology change.  The technologists responsible for implementing these changes often bias towards their comfort zone—the machine side—and overlook the people side.  This has led to frustration for companies who invest significantly in new technology only to miss the intended benefits of the change.  For APIs, the people side of the change is especially important.  In fact, the social nature of the API world means there are even more groups of people to consider.  Ultimately, the success of a company’s API will depend on the creation of a diverse community for that API—end users, partners, developers, and more—as well as the adoption of a business model that allows the API to contribute to the company’s bottom line.  Taking the community and the economics together, this means you will need to build a nation for your API.</p>
<p>Some of the biggest companies on the web have taken this approach with their APIs, and I recently explored some of their winning tactics in this <a href="http://venturebeat.com/2013/03/08/5-lessons-from-api-giants-like-twitter-and-google/">VentureBeat article</a>.  Please have a read and let me know your thoughts, and perhaps your own API lessons</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/nation-building-in-the-age-of-apis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>“Mobile App Security: Always Keep the Back Door Locked” – Our Take</title>
		<link>http://www.layer7tech.com/blogs/index.php/mobile-app-security-always-keep-the-back-door-locked-our-take/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/mobile-app-security-always-keep-the-back-door-locked-our-take/#comments</comments>
		<pubDate>Thu, 07 Feb 2013 23:40:40 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[API Management]]></category>
		<category><![CDATA[Apps]]></category>
		<category><![CDATA[Mobile Access]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=3847</guid>
		<description><![CDATA[Today&#8217;s lead article on Ars Technica talks about the importance of protecting backend resources in the context of mobile applications. The article rightly stresses the importance of this security, talks about the uptake in OAuth and cites API Gateway solutions as a popular option in this space. However, the article clearly misstates the capabilities of [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.layer7tech.com/library/solution-briefs/layer-7-for-mobile-access/2607" target="_blank"><img class="alignleft size-full wp-image-3851" style="margin: 0px 10px;" title="Mobile App Security" src="http://www.layer7tech.com/blogs/wp-content/uploads/2013/02/Mobile-v1.jpg" alt="Mobile App Security" width="300" height="185" /></a><a href="http://arstechnica.com/security/2013/02/mobile-app-security-always-keep-the-back-door-locked/" target="_blank">Today&#8217;s lead article on Ars Technica</a> talks about the importance of protecting backend resources in the context of mobile applications. The article rightly stresses the importance of this security, talks about the uptake in OAuth and cites API Gateway solutions as a popular option in this space.</p>
<p>However, the article clearly misstates the capabilities of an API Management solution founded on an API Gateway. I am going to assume that the author only had exposure to API Gateways second hand or through a competitor of Layer 7. Here are the misconceptions propagated by the article, along with some corrections:</p>
<p><em>“These API gateway services can be prohibitively expensive for small-scale applications…  ‘You can replicate the API gateway by creating a set of proxy services in their data center in an application container in their DMZ.’&#8221;</em></p>
<p>Trying to create your own homegrown set of proxy services is expensive and risky. The <a href="http://www.layer7tech.com/library/product-data-sheets/layer-7-api-management-suite/2233" target="_blank">Layer 7 API Management Suite</a>’s Gateway technology includes 10 years of functional enrichment and optimization. Such robustness cannot be hacked together on the fly.</p>
<p><em>&#8220;An API gateway still runs on the notion that you have to be careful not to block what might be legitimate traffic. So that could cause some openness – some attacks might slip through using Web application firewall evasion techniques.&#8221;</em></p>
<p>An API Gateway is not a typical web application firewall. Layer 7’s Gateway (evident in the company’s name) has full access to all layers of the data stream and can apply protections at any of these layers.</p>
<p><em>“Of course, if they can retrieve a developer key, attackers can slip past API gateways until their activity is noticed…  That&#8217;s why it&#8217;s important to encrypt any data stored on the device, including developer keys[.]”</em></p>
<p>API keys are not treated as security tokens by an API Gateway. The term “API key” is equivalent to a “database key”, not a security key, so don’t mistake it for a robust access control mechanism. It is mainly an identification mechanism. It is a gross misunderstanding to equate API developer keys with a standard access control cryptographic mechanism like PKI public/private keys.</p>
<p><em>“But keys have other ways of getting into the wild besides breaking into the application code.”</em></p>
<p>Right, so you should not rely on these keys for access control. The good news is that the API Management Suite’s Portal/Gateway combination makes it easier to revoke and reissue developer keys.</p>
<p><em>“For enterprise applications, an API gateway isn&#8217;t always enough – users need to get access to content on servers inside the firewall that may not be easily exposed through a Web API.”</em></p>
<p>And this is where the API Gateway really adds value. The Layer 7 API Management Suite allows companies to turn those backend interfaces from their native protocols into REST APIs or other formats that are friendly to mobile devices.</p>
<p>So, thanks to Ars Technica for flagging up this important aspect of mobile security and here’s hoping that this corrected information is included in the next article.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/mobile-app-security-always-keep-the-back-door-locked-our-take/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Break in the Clouds</title>
		<link>http://www.layer7tech.com/blogs/index.php/a-break-in-the-clouds/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/a-break-in-the-clouds/#comments</comments>
		<pubDate>Mon, 03 Dec 2012 22:00:23 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[Apps]]></category>
		<category><![CDATA[Cloud Integration]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Mobile Access]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=3433</guid>
		<description><![CDATA[A recent study by researchers at North Carolina State University and the University of Oregon describes a threat scenario that allows attackers to exploit cloud-based resources for malicious purposes like cracking passwords or launching denial-of-service attacks. The study has gotten a lot of attention, including articles in reputable sources like Dark Reading, Ars Technica and [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.layer7tech.com/blogs/wp-content/uploads/2012/12/A-Break-in-the-Clouds-Large.jpg"><img class="alignleft size-medium wp-image-3435" style="margin: 10px;" title="Click to see full-size" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/12/A-Break-in-the-Clouds-Large-300x230.jpg" alt="A Break in the Clouds" width="300" height="230" /></a>A <a href="http://adl.csie.ncu.edu.tw/~jhhe/doc/bmr.pdf" target="_blank">recent study</a> by researchers at North Carolina State University and the University of Oregon describes a threat scenario that allows attackers to exploit cloud-based resources for malicious purposes like cracking passwords or launching denial-of-service attacks. The study has gotten a lot of attention, including articles in reputable sources like <a href="http://www.darkreading.com/cloud-security/167901092/security/news/240142718/new-hack-abuses-cloud-based-browsers.html" target="_blank">Dark Reading</a>, <a href="http://arstechnica.com/security/2012/11/hack-could-let-browsers-use-cloud-to-carry-out-big-attacks-on-the-cheap/" target="_blank">Ars Technica</a> and <a href="http://www.networkworld.com/news/2012/112812-vulnerability-hackers-cloud-computing-264610.html" target="_blank">Network World</a>.</p>
<p>In order to optimize the performance of mobile apps or browsers, some computation-heavy functions have been offloaded to cloud-based resources, which in turn access backend resources and Web pages. This creates a middle ground in the cloud that is exploited in the attack, which the authors call “Browser Map Reduce (BMR)”. In reading the paper, it’s clear that this is a legitimate threat. The authors actually carried it out using free resources, although they limited the scope in order not to be abusive.</p>
<p>Aside from questions of curiosity around the mechanics of the vulnerability, the obvious question is this: How can we mitigate this threat? Here are a few perspectives here as well as a method for each.</p>
<p><strong>Apps</strong> – This “cloud offload” architecture has arisen because of the processing limitations of mobile devices. When a backend resource is requested by a mobile user, it makes sense to have the data returned in the most consumable format, in order to optimize user experience. Whenever possible, instead of doing this through “browser offload”, data should be returned as JSON objects. This API approach is a proven method that works for mobile devices and is not subject to the BMR threat.</p>
<p><strong>Cloud Services</strong> – This threat should not be viewed as a dismissal of the “cloud offload” approach. Cloud-based resources are necessary for handling caching, data indexing and other key functions in the mobile paradigm. However, it serves as a warning that these dedicated cloud-based resources cannot be considered part of a walled garden that includes the associated mobile app. The resource’s entry point must be protected against attackers. <a href="http://www.layer7tech.com/products/mobile-access-gateway" target="_blank">Layer 7’s SecureSpan Mobile Access Gateway</a> is an ideal choice for this access control, as it uses identity-based measures to ensure that only requests from legitimate sources are serviced.</p>
<p><strong>Web-Based Resources</strong> – Although the backend Web resource was not exploited in this scenario, the study is a reminder that the topology of the mobile Web is changing and increasing in complexity. P2P app-to-API connections cannot be assumed and therefore inbound API calls cannot be implicitly trusted. API access must be controlled and the <a href="http://www.layer7tech.com/products/api-proxy" target="_blank">SecureSpan API Proxy</a> is a leading solution for this purpose.</p>
<p>To sum up, this is a legitimate threat but not a reason to abandon the use of cloud-based resources for mobile app optimization. Be aware of the threats, employ the mitigations and then you can continue to enjoy the exciting growth of the mobile Web.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/a-break-in-the-clouds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Non-Function Junction: API Automation for Enterprise Operations</title>
		<link>http://www.layer7tech.com/blogs/index.php/non-function-junction-api-automation-for-enterprise-operations/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/non-function-junction-api-automation-for-enterprise-operations/#comments</comments>
		<pubDate>Tue, 02 Oct 2012 21:00:46 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[API Design & Optimization]]></category>
		<category><![CDATA[API Management]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=3102</guid>
		<description><![CDATA[Recently, I’ve been working closely with a number of large enterprise clients who have already gone or will soon go live with Layer 7 solutions at the core of mission-critical infrastructure. I’ve observed that, in the API Management space, proof of concept and initial projects often focus on functional needs but the emphasis shifts to [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"><a href="http://www.layer7tech.com/solutions/api-management-solutions-for-mobile-and-web" target="_blank"><img class="alignleft size-full wp-image-3106" style="margin: 10px;" title="API Operations Automation" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/10/Non-Function-Junction-v1.jpg" alt="API Operations Automation" width="204" height="300" /></a>Recently, I’ve been working closely with a number of large enterprise clients who have already gone or will soon go live with <a href="http://www.layer7tech.com/solutions/api-management-solutions-for-mobile-and-web" target="_blank">Layer 7 solutions</a> at the core of mission-critical infrastructure. I’ve observed that, in the API Management space, proof of concept and initial projects often focus on functional needs but the emphasis shifts to non-functional requirements as environments mature and sharing increases. There’s a clear, three-phase progression for large enterprises, which moves along these lines:</p>
<ol>
<li>Solve the basic functional use cases – The 80% in the 80-20 rule</li>
<li>Solve the remaining, more complex use cases – The 20%</li>
<li>Deploy the basic functions on an enterprise scale – Back to the 80%</li>
</ol>
<p style="text-align: left;">In Phase 3, it’s all about performance, scalability, operability, security, availability and consumability. The problems are very complex but the goal is to make the resulting solution as usable and simple as possible, given the wide range of users, developers, testers and operators that will be involved in its execution. As technology vendors, we are often guilty of focusing inwardly on bells and whistles, rather than outwardly on interoperability. This works well for phases 1 and 2 but brings a reckoning in the third phase. Fortunately, at Layer 7, we’ve spent the past decade working with enterprise clients and have evolved our products to meet their adaptability, reliability and automation needs.</p>
<p style="text-align: left;"><a href="http://www.layer7tech.com/library/product-data-sheets/layer-7-sdk-management-api/2449" target="_blank">The Layer 7 Management API</a> is at the core of this capability. The Management API ships with all Layer 7 Gateways, to enable automated administration of policies, resources and access control that can plug into enterprise configuration management, deployment and monitoring systems. It can be accessed programmatically through a Java API, on the network through a Web service API or built into command line scripts. For the clients I have worked with, this capability and the assurance it provides on moving through the systems development lifecycle is quite simply a must have.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/non-function-junction-api-automation-for-enterprise-operations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Layer 7 at Your Service</title>
		<link>http://www.layer7tech.com/blogs/index.php/layer-7-at-your-service/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/layer-7-at-your-service/#comments</comments>
		<pubDate>Fri, 13 Jul 2012 21:00:17 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[API]]></category>
		<category><![CDATA[API Academy]]></category>
		<category><![CDATA[Company Announcements]]></category>
		<category><![CDATA[Services]]></category>
		<category><![CDATA[Company Announcement]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=2530</guid>
		<description><![CDATA[Layer 7 has been providing solutions for more than a decade. In this time, we have gained valuable experience of how to make our industry-leading products deliver maximum benefit in critical customer environments. In particular, we’ve gained a great deal of knowledge about how to translate clients’ business needs into robust solutions that meet the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.layer7tech.com/services/services-overview" target="_blank"><img class="alignleft size-full wp-image-2532" style="margin: 10px;" title="Layer 7 Services" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/07/layer-7-services-v2.jpg" alt="Layer 7 Services" width="300" height="274" /></a>Layer 7 has been providing solutions for more than a decade. In this time, we have gained valuable experience of how to make our industry-leading products deliver maximum benefit in critical customer environments. In particular, we’ve gained a great deal of knowledge about how to translate clients’ business needs into robust solutions that meet the functional requirements and address key non-functional areas like performance, security and operations.</p>
<p>Recently, we’ve added a number of <a href="http://www.reuters.com/article/2012/06/18/idUS180975+18-Jun-2012+BW20120618" target="_blank">industry experts</a> to our full-time team, in order to deepen this expertise and expand our delivery. Services have become an increasingly important part of our business and we have just launched a new <a href="http://www.layer7tech.com/services/services-overview" target="_blank">Services section</a> on our Web site in order to provide details of our service offerings.</p>
<p><a href="http://www.layer7tech.com/services/layer-7-training" target="_blank">Training Services</a> are always the right starting point for new clients and we have a number of courses we can tailor to meet any customer’s needs. Following training, we can customize <a href="http://www.layer7tech.com/services/layer-7-it-services" target="_blank">IT Services</a> to provide consulting, configuration and any implementation activity. Our <a href="http://www.layer7tech.com/services/layer-7-business-services" target="_blank">Business Services</a> help companies explore new opportunities through technology. The current focus is on the many possibilities offered by APIs and we’re very excited to have noted industry experts <a href="http://www.layer7tech.com/blogs/index.php/author/mikea/" target="_blank">Mike Amundsen</a> and <a href="http://www.layer7tech.com/blogs/index.php/author/rmitra/" target="_blank">Ronnie Mitra</a> leading this practice.</p>
<p>Please have a look at all the services we offer and let us know if any of these would help your company out. No matter what phase of a project you’re in, we will be happy to be at your service!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/layer-7-at-your-service/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Start Spreading the News… Cloud Expo, New York</title>
		<link>http://www.layer7tech.com/blogs/index.php/start-spreading-the-new-cloud-expo-new-york/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/start-spreading-the-new-cloud-expo-new-york/#comments</comments>
		<pubDate>Wed, 06 Jun 2012 18:45:49 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Integration]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Hybrid Clouds]]></category>
		<category><![CDATA[Talks]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=2195</guid>
		<description><![CDATA[Cloud Expo 2012 is almost here. This promises to be an incredible event, with thousands of attendees and over 100 speakers. As previously mentioned, I’m privileged to be presenting on Making Hybrid Cloud Safe &#38; Reliable. I’m particularly excited that I’ll be introducing attendees to the new concept of API-Aware Traffic Management. It will also [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://cloudexpo2012east.sys-con.com/" target="_blank"><img class="alignleft size-full wp-image-2199" style="margin: 10px;" title="Cloud Expo 2012" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/06/Cloud-Expo-2012.jpg" alt="Cloud Expo 2012" width="300" height="201" /></a><a href="http://cloudexpo2012east.sys-con.com/" target="_blank">Cloud Expo 2012</a> is almost here. This promises to be an incredible event, with thousands of attendees and over 100 speakers. As previously mentioned, I’m privileged to be presenting on <a href="http://www.layer7tech.com/blogs/index.php/cloud-clear/" target="_blank">Making Hybrid Cloud Safe &amp; Reliable</a>. I’m particularly excited that I’ll be introducing attendees to the new concept of <a href="http://www.layer7tech.com/blogs/index.php/api-aware-traffic-management/" target="_blank">API-Aware Traffic Management</a>. It will also be great to be back in New York City!</p>
<p>I recently read Daniel Kahneman’s book <a href="http://www.amazon.com/Thinking-Fast-Slow-Daniel-Kahneman/dp/0374275637" target="_blank"><em>Thinking Fast &amp; Slow</em></a>, a fascinating study of how the human mind works. With the new capabilities offered by big data and Cloud computing — the dual themes for next week’s event — and the increasing personalization of technology through Mobile devices, I think we have an opportunity to make our digital systems more human in their processing. What does that mean?  Well, more intuitive in user experience, more lateral through caching of unstructured data and more adaptive to changing conditions. API-Aware Traffic Management certainly reflects this potential.</p>
<p>If you are going to be (or hope to be) at the event, <a href="http://www.layer7tech.com/blogs/index.php/start-spreading-the-new-cloud-expo-new-york/#comments">add a response in the comments box</a> or tweet to <a href="https://twitter.com/#!/MattMcLartyBC" target="_blank">@MattMcLartyBC</a>. Hope to see you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/start-spreading-the-new-cloud-expo-new-york/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>API-Aware Traffic Management</title>
		<link>http://www.layer7tech.com/blogs/index.php/api-aware-traffic-management/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/api-aware-traffic-management/#comments</comments>
		<pubDate>Tue, 15 May 2012 17:00:45 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[API]]></category>
		<category><![CDATA[Cloud Brokers]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Integration]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Hybrid Clouds]]></category>
		<category><![CDATA[Talks]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=2010</guid>
		<description><![CDATA[As I mentioned in my last blog post, the promise of cost reduction is compelling many enterprises to move their workloads into the Cloud but many IT leaders are reluctant to do so, for fear of compromising the security and availability of their services. These concerns are well-founded but the benefits of Cloud are too [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://cloudexpo2012east.sys-con.com/event/session/1598" target="_blank"><img class="alignleft size-full wp-image-2012" style="margin: 10px;" title="Cloud Expo" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/05/Cloud-Expo.jpg" alt="Cloud Expo" width="300" height="149" /></a>As I mentioned in <a href="http://www.layer7tech.com/blogs/index.php/cloud-clear/" target="_blank">my last blog post</a>, the promise of cost reduction is compelling many enterprises to move their workloads into the Cloud but many IT leaders are reluctant to do so, for fear of compromising the security and availability of their services. These concerns are well-founded but the benefits of Cloud are too great to ignore. To obtain these benefits, companies must adopt techniques that protect against the attendant risks, without compromise.</p>
<p>Many people are familiar with Layer 7’s <a href="http://www.layer7tech.com/Forrester-Wave/" target="_blank">industry-leading</a> security functionality, so it’s no surprise that I’d recommend using our Gateway technology to protect connections from on-premise infrastructure to off-premise Cloud services. The flexibility of deployment options we offer makes it possible to create a network of secure on- and off-premise endpoints to meet the most stringent requirements. This covers security but what about availability?</p>
<p>People seem to be less familiar with Layer 7’s routing capabilities. <a href="http://www.layer7tech.com/library/product-data-sheets/cloudspan-cloudconnect-gateway/1861" target="_blank">Our Gateway technology</a> is optimized to perform flexible, content-based routing with negligible impact on overall transaction times. In the context of the Cloud, this means that traffic proxied by a Layer 7 Gateway can be re-directed using intelligent algorithms and even dynamic, state-based awareness. This routing capability, which I call “API-aware traffic management”, brings huge benefits in ensuring availability when connecting to multiple API instances – on-premise, off-premise, in multiple Clouds… anywhere on the hybrid network.</p>
<p>I’ll be discussing this topic in detail at the upcoming <a href="http://cloudcomputingexpo.com/" target="_blank">Cloud Expo 2012</a>, June 11-14 in New York City. This promises to be a great event, so I hope you can make it and <a href="http://cloudexpo2012east.sys-con.com/event/session/1598" target="_blank">attend my discussion</a>!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/api-aware-traffic-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud &amp; Clear</title>
		<link>http://www.layer7tech.com/blogs/index.php/cloud-clear/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/cloud-clear/#comments</comments>
		<pubDate>Mon, 30 Apr 2012 16:00:31 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cloud Integration]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Hybrid Clouds]]></category>
		<category><![CDATA[Talks]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=1919</guid>
		<description><![CDATA[It’s April in Vancouver, which got me thinking about clouds.  Although the IT buzz in 2012 has been dominated by mobile and big data, Cloud computing is still a hot topic, especially since it is an enabler for both. In the public Cloud space, Google just launched Drive in the same week that Microsoft updated [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://cloudexpo2012east.sys-con.com/event/session/1598" target="_blank"><img class="alignleft size-full wp-image-1921" style="margin: 10px;" title="Hybrid Cloud" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/04/Hybrid-Cloud-v2.jpg" alt="Hybrid Cloud" width="300" height="208" /></a>It’s April in Vancouver, which got me thinking about clouds.  Although the IT buzz in 2012 has been dominated by mobile and big data, Cloud computing is still a hot topic, especially since it is an enabler for both. In the public Cloud space, Google just launched <a href="http://www.computerworld.com/s/article/9226565/Google_Drive_review_Adding_cloud_storage_to_the_mix?taxonomyId=19" target="_blank">Drive</a> in the same week that Microsoft updated <a href="http://www.informationweek.com/byte/news/personal-tech/storage-memory/232900899" target="_blank">SkyDrive</a>. In the private Cloud domain, IBM recently announced its <a href="http://www.zdnet.com/blog/btl/ibm-launches-puresystems-touts-integration-flexibility/73564" target="_blank">PureSystems</a> platform, which falls along similar lines as the Exa- line from Oracle.</p>
<p>It will be interesting to see whether or not big enterprises buy into this <a href="http://www.dbta.com/Articles/Columns/Applications-Insight/Oracles-Exalogic-%E2%80%93-Private-Cloud-or-Modern-Mainframe-71234.aspx" target="_blank">“21st century mainframe”</a> concept but what’s clear is that enterprises now want to migrate critical workloads to the Cloud, en masse. To realize the true benefits of Cloud, many of these workloads will have to be running off-premise. But since many will remain on-premise, enterprises will be relying on hybrid Cloud infrastructure for their most significant IT services.</p>
<p>Security remains a major area of concern for organizations looking to leverage the Cloud. Increasingly, availability and reliability are also significant concerns, particularly since Amazon has had a few <a href="http://techcrunch.com/2011/08/08/amazon-ec2-outage/" target="_blank">outages</a> recently. In addition to addressing these concerns, enterprises are evaluating how they can optimize processing volumes to get maximum cost benefit from their Cloud deployments.</p>
<p>Please join me at the <a href="http://cloudcomputingexpo.com/" target="_blank">Cloud Expo</a>, June 11-14 in New York, where <a href="http://cloudexpo2012east.sys-con.com/event/session/1598" target="_blank">I’ll be discussing solutions for each of these considerations</a>. Hey, we should have blue skies by then!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/cloud-clear/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BYOD is a HUGE Opportunity for Mobile App Developers</title>
		<link>http://www.layer7tech.com/blogs/index.php/byod-is-a-huge-opportunity-for-mobile-app-developers/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/byod-is-a-huge-opportunity-for-mobile-app-developers/#comments</comments>
		<pubDate>Wed, 25 Apr 2012 16:00:45 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[API]]></category>
		<category><![CDATA[BYOD]]></category>
		<category><![CDATA[Developers & Development]]></category>
		<category><![CDATA[Mobile Access]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=1903</guid>
		<description><![CDATA[Calling all mobile app developers! You have the whole IT world in your hands. Mobile migration represents a shift in IT as large as the PC explosion of the 80s or the Internet boom of the 90s. And mobile apps will prove to be the major driving force behind this shift – exerting an even [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.layer7tech.com/library/product-data-sheets/layer-7-api-portal/1877" target="_blank"><img class="alignleft size-full wp-image-1905" style="margin: 10px;" title="API Portal for Mobile Developers" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/04/API-Portal-for-Mobile-Developers-v3.jpg" alt="API Portal for Mobile Developers" width="300" height="242" /></a>Calling all mobile app developers! You have the whole IT world in your hands. Mobile migration represents a shift in IT as large as the PC explosion of the 80s or the Internet boom of the 90s. And mobile apps will prove to be the major driving force behind this shift – exerting an even greater pressure than the devices that run these apps. For evidence of this, have a look at <a href="http://digital-stats.blogspot.ca/2012/04/1m-android-versions-of-instagram-were.html" target="_blank">the launch-day download stats for Instagram’s Android app</a>.</p>
<p>Up to this point, apps have focused mainly on consumers. But with <a href="http://gigaom.com/2012/04/08/byod-is-unstoppable-smart-companies-must-build-apps/" target="_blank">the BYOD (“bring-your-own-device”) movement’s unstoppable momentum</a> driving mobile devices into the center of the enterprise IT landscape, there is a growing need for enterprise apps that give employees the user experience they are used to with consumer apps. That means a decent chunk of <a href="http://news.cnet.com/8301-1001_3-57352817-92/gartner-lowers-global-it-spending-forecast-for-2012/" target="_blank">the $3.8 trillion spent on enterprise IT this year</a> could be heading to mobile app developers like you.</p>
<p>Building mobile apps for the enterprise is going to create some new challenges, though. Perhaps most significantly, <a href="http://www.zdnet.com/blog/consumerization/appleization-and-the-apple-centered-appleprise/143" target="_blank">you will be much more reliant on enterprise data and applications</a>. That’s going to mean a lot of work integrating the functional requirements for your apps and even more work nailing down the non-functional areas like security, scalability and availability. Nevertheless, these challenges are well worth accepting, given the stakes.</p>
<p>The good news is that Layer 7 will be out there making things easier for you. We help enterprises <a href="http://www.layer7tech.com/library/product-data-sheets/securespan-api-proxy/1868" target="_blank">expose data and applications as RESTful APIs</a>, significantly simplifying integration with mobile apps. Additionally, our <a href="http://www.layer7tech.com/library/product-data-sheets/layer-7-api-portal/1877" target="_blank">API Portal</a> product helps developers discover and get maximum value from enterprise APIs. It’s an exciting time for mobile developers and we’re excited to be laying the foundation upon which a generation of enterprise apps will be built.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/byod-is-a-huge-opportunity-for-mobile-app-developers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Big Data &amp; API Management</title>
		<link>http://www.layer7tech.com/blogs/index.php/big-data-api-management/</link>
		<comments>http://www.layer7tech.com/blogs/index.php/big-data-api-management/#comments</comments>
		<pubDate>Mon, 09 Apr 2012 16:00:01 +0000</pubDate>
		<dc:creator>Matt McLarty</dc:creator>
				<category><![CDATA[API]]></category>
		<category><![CDATA[API Management]]></category>
		<category><![CDATA[Integration]]></category>
		<category><![CDATA[REST]]></category>

		<guid isPermaLink="false">http://www.layer7tech.com/blogs/?p=1799</guid>
		<description><![CDATA[The hottest IT trends of 2012 are shaping up to be Cloud, mobile and “big data”. The links between API management, Cloud and mobile are clear. The links between API management and big data – a concept that creates capabilities for capturing and analyzing previously unimaginable amounts of unstructured data – are less obvious but [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.layer7tech.com/blogs/wp-content/uploads/2012/04/Big-Data-v3.jpg"><img class="alignleft size-full wp-image-1802" style="margin: 10px;" title="Big Data" src="http://www.layer7tech.com/blogs/wp-content/uploads/2012/04/Big-Data-v3.jpg" alt="Big Data" width="300" height="201" /></a>The hottest IT trends of 2012 are shaping up to be Cloud, mobile and <a href="http://en.wikipedia.org/wiki/Big_data" target="_blank">“big data”</a>. The links between API management, Cloud and mobile are clear. The links between API management and big data – a concept that creates capabilities for capturing and analyzing previously unimaginable amounts of unstructured data – are less obvious but no less significant. I see two key areas of synergy…</p>
<p>First of all, in the three-tier architecture of the Web, the line was typically blurry between the presentation and logic tiers and concrete between logic and data. Big data now blurs the line between logic and data. Combine this with the fact that the mobile app development paradigm fragments the presentation platform and it is evident that the API will become the concrete and consistent border in application processing flows. In this context, <a href="http://en.wikipedia.org/wiki/API_Management" target="_blank">API management</a> will prove vital in enforcing security, collecting business metrics and normalizing protocols.</p>
<p>Second, big data allows analytics to be performed in the scope of real-time data retrieval. This will create another wave of real-time integration needs in enterprises of every size. More real-time integration means more APIs with higher volumes. The common protocol for exposing big data on the network is REST using either JSON or XML formats. Again, this will mean a greater necessity for <a href="http://www.layer7tech.com/library/product-data-sheets/layer-7-api-management-suite/2233" target="_blank">API management tools</a> and techniques and a compound benefit in their usage.</p>
<p>Simply put, mobile, Cloud and big data are driving a new era of enterprise IT and API management will provide amplified value for companies embracing these trends.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.layer7tech.com/blogs/index.php/big-data-api-management/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
