InfoQ

Interview

Mohammad Akif - SOA Beyond the Hype and the Security Development Life Cycle

Interview with Mohammad Akif on Dec 19, 2006 02:00 AM

Community
.NET,
SOA
Topics
Security,
.NET Framework
Summary
InfoQ sits down Mohammad to discuss the myths of SOA, common pitfalls in designing for SOA, J2EE and .NET interoperability and injecting the Security Development Lifecycle into enterprise development lifecycles.

Bio
Mohammad Akif is a Senior Architect Evangelist at Microsoft;member of the Microsoft Architecture Editorial Board, he presents and publishes frequently about Web 2.0, Web Services, Interoperability and Software Architecture best practices.He worked as a Senior Java Architect at Sun Microsystems Inc. He co-authored several publications and he contributed to the development of the J2EE core patterns.
I'm here with Mohammed Akif at VS Live in Toronto. Would you introduce yourself and tell us what do?
SOA, What's behind the hype? What's the real story behind SOA?
With SOA, when do you go with tight-coupling vs. loose-coupling?
The key thing is not to get too granular with it and keep your services coarse.
A service with only one customer or one user isn't really necessary. If it's going to be used by one thing what's the point of abstracting that out?
To expand a little more on who's using this service, there's the whole interop story. What are the challenges on the interop space now?
What are some of the things you can do to address security in your development process?
So that is part of the whole "Secure by Default" Initiative.
Jesper Johansson does a wonderful talk where he starts with a SQL injection attack and literally hacks his way through two domains to the main accounting server in his scenario and he does it live and it's a frightening demonstration of what is possible.
As an architect how do you design security in your architecture, in your process upfront so that there's no choice but to do it because it's part of the overall architecture?
For example for each milestone you have a quality gateway that says: Are these security issues addressed and if they are not you don't move forward.
So you're not talking about somebody who knows how to configure Active Directory, but someone with experience in multiple technologies and platforms?
I'd like to thank you for showing your time with us today. Do you have any final words?
show all  show all

2 comments

Reply

Please do revert by Jeeten Masrani Posted Mar 13, 2007 10:30 AM
welcome by boran Boran Posted Jun 30, 2008 10:02 AM
  1. Back to top

    Please do revert

    Mar 13, 2007 10:30 AM by Jeeten Masrani

    Greetings Let me introduce myself , I am Jeeten C, a Bangalore based consultant. I happen to view your profile while surfing on the net and thought if I could suggest a few opportunities which I am currently working on in the area of Research and Development for few of the premier and most admired companies. Kindly get back to me with your contact number and a available slot to call so that we could discuss and take it forward or updated profile which I can take into procees. Thanks & Regards Jeeten/c Associate - Executive Search

  2. Back to top

    welcome

    Jun 30, 2008 10:02 AM by boran Boran

Exclusive Content

Rationalizing the Presentation Tier

Thin client paradigm characterized by web applications is a kludge that needs to be repudiated. Old compromises are no longer needed and it's time to move the presentation tier to where it belongs.

Agile Project Management: Lessons Learned at Google

In this presentation filmed during QCon 2007, Jeff Sutherland, the creator of Scrum, talks about his visit at Google to do an analysis of Google's first implementation of Scrum.

AtomServer – The Power of Publishing for Data Distribution

In this article, Bryon Jacob and Chris Berry introduce AtomServer, their implementation of a full-fledged Atom Store based on Apache Abdera, which is now available as open source.

An Introduction to Virtualization

It is easy to think that virtualization applies only to servers. In reality the recent resurgence of the concept is also being applied to networking, storage, and application infrastructure.

REST Anti-Patterns

In this article, Stefan Tilkov explains some of the most common anti-patterns found in applications that claim to follow a "RESTful" design and suggests ways to avoid them.

Choosing between Routing and Orchestration in an ESB

In this article, Adrien Louis and Marc Dutoo discuss the differences and relative merits of using orchestration vs. routing in a typical ESB setup, and discuss various implementation options.

Enterprise Batch Processing with Spring

Wayne Lund discusses batch processing, Spring Batch objectives and features, scenarios for usage, Spring Batch architecture, scaling, example code, failures and retrying, and the future roadmap.

User Story Estimation Techniques

Developer Jay Fields draws on his experiences as a ThoughtWorks consultant to describe effective user story estimation techniques.