Communication Protocol Test Harness SCADA Data Gateway.

Ruben Gonzalez Jr. Worked his way through a chemistry degree at Florida International University (FIU) in Miami, first at a fast-food joint, then at a video store, where he eventually became assistant manager. Somehow, he also found time for science, spending his last three years in Stephen Winkle’s lab researching changes in the shape of DNA when it switches from a normal, right-handed helix to the opposite, left-handed form.

“I got lucky—hit the jackpot—[when] Ruben decided he wanted to work in my lab,” says Winkle, who knew Gonzalez as the student in his biochemistry class acing all of the tests. Gonzalez had planned on becoming a high school chemistry teacher after college, but Winkle saw a different path for the young scientist and encouraged him to apply to graduate programs.

In 1995, the pair were in San Francisco for a meeting of the Biophysical Society when Gonzalez got the news he’d been accepted into the University of California, Berkeley, where Winkle had done his own graduate work years earlier. They headed across the bay to meet Winkle’s former advisor, Ignacio “Nacho” Tinoco Jr., who immediately sold Gonzalez on RNA. “The idea that this molecule could carry the genetic information like DNA does, but could also fold into really complicated three-dimensional structures that could do chemistry like proteins... I fell in love with that idea,” Gonzalez recalls. In Tinoco’s lab at Berkeley, Gonzalez studied RNA pseudoknots, the simplest known tertiary structure of RNA, consisting of two intertwined hairpin loops.

Gonzalez solved the structure of a magnesium ion binding site in a pseudoknot from the mouse mammary tumor virus. He accomplished this by swapping out the magnesium ions, which help stabilize the structure but are not visible using nuclear magnetic resonance (NMR), replacing them with cobalt hexammine ions, which are NMR active. “I could actually see where the cobalt hexammine bound to the RNA and detect how it stabilized that particular structure,” says Gonzalez. “He was not only smart, but he was ambitious and really cared about the science,” Tinoco says of Gonzalez. Gonzalez went to Stanford University for a postdoc, working under RNA expert Joseph (Jody) Puglisi and physicist Steve Chu to develop single-molecule fluorescence tools that could aid in imaging ribosomes interacting with tRNA during protein translation. “[This was] the very first demonstration ever that one could study ribosomes and translation using single-molecule fluorescent approaches,” Gonzalez says. In 2006, Gonzalez arrived at Columbia University, where he now oversees four postdocs, 11 graduate students, and one undergrad.

Much of his group’s current work involves extending discoveries about translation in E. Coli to the process in eukaryotes, with an eye toward human health and disease. Gonzalez also continues to innovate on the technological front, most recently by applying single-molecule field-effect transistors (smFET)—carbon nanotubes covalently bonded to the nucleic acids or proteins of interest that can help illuminate molecular structure—to the study of RNA, ribosomes, and translation. Gonzalez says he’s excited about how this new tool is going to allow him to dissect the process of translation at an ever-finer scale, in particular at much faster timescales, opening a window on how “ribosomes or other enzymes make decisions about correct or incorrect substrates.” • R.L. Gonzalez Jr., I. Tinoco Jr., “Solution structure and thermodynamics of a divalent metal ion binding site in an RNA pseudoknot,”, 289:1267-82, 1999. (Cited 97 times) • S.C.

• R.L. Gonzalez Jr., I. Tinoco Jr., "Solution structure and thermodynamics of a divalent metal ion binding site in an RNA pseudoknot,", 289:1267-82, 1999. (Cited 97 times) • S.C. Blanchard et al., "tRNA dynamics on the ribosome during translation,", 101:12893-98, 2004. (Cited 311 times) • S. Sorgenfrei et al., "Label-free single-molecule detection of DNA-hybridization kinetics with a carbon nanotube field-effect transistor,", 6:126-32, 2011. (Cited 111 times).

OTT brands have become synonymous with attractive features and competitive pricing, and mobile consumers regularly turn to well-known OTT providers for myriad services. Leading OTT communications services include Microsoft's Skype, Viber, Facebook's Whatsapp, Line and Kik Messenger. Streaming video is routinely delivered to mobile devices from Google's YouTube, Hulu and Netflix, while streaming audio is supplied by services as iHeartRadio, Pandora, Rhapsody, Samsung Milk, Slacker and Spotify. The massive and growing proliferation of OTT services has resulted in flattening or declining voice and messaging revenues for mobile operators as OTT providers take more and more revenue share for those services.

That's an increasingly popular and practical notion. As a result, adoption of a, sometimes called a cloud portfolio, is growing quickly. In its, RightScale, a provider of cloud portfolio management services, noted that as of January 2015, 82% of surveyed enterprises are now employing a multi-cloud deployment model, up from 74% just one year earlier. Within that group, a mix of public and private clouds is favored by 55%, while those opting solely for multiple private or multiple public clouds are split almost equally (14% and 13%, respectively). As companies simultaneously move applications and data to the public cloud, keep others on premises, and integrate with, it's important for them to deploy services in a consistent and repeatable way. '[Fail] to work this way and IT operations will not be able to maintain control,' said Bailey Caldwell, RightScale's vice president of customer success.

Consistency through automation In its, a cadre of nine Forrester Research analysts states that automating is the answer to the fundamental issues of scale, speed, costs and accuracy. 'It's not how well your cloud is organized or how shiny and new it is; it's about how well does that the application and workload perform together.' Roy Ritthaller Vice president of marketing for IT operations management, Hewlett-Packard Enterprise Commenting on the report in relation to cloud deployment, analyst said, 'You may have a built a workload for Amazon [Web Services] that you now want to run in [Microsoft] Azure, or replace with a database in Salesforce, or use an ERP system like SAP in the cloud. You need a consistent way to deploy this.' The problem, Bartoletti explained, is that businesses find deployment across these varied platforms difficult largely due to a lack of tools with cross-platform intelligence. 'Traditionally, you'd use the tool that comes with the platform, perhaps vCenter Server for VMware vSphere environments or AWS OpsWorks to deploy on Amazon.' The tools landscape is still adapting to the reality of the multi-cloud deployment model.

In his October 2015 survey of hybrid cloud management offerings, Bartoletti analyzed 36 vendors, several of which offer tools that along with application development and delivery. Switching between cloud environments Consistency appears to be the keyword for existing in a multi-cloud universe. It matters because nothing stays still in the cloud for very long, including the apps and data you provide and the actual infrastructures, services and pricing of each provider. 'If you want to move applications, data and services among different providers -- and you will as part of a continuous deployment strategy -- it's important to have consistency and a level of efficiency for managing those disparate environments,' said, senior analyst at the Enterprise Strategy Group. For enterprises, multicloud strategy remains a siloed approach by Enterprises need a multicloud strategy to juggle AWS, Azure and Google Cloud Platform, but the long-held promise of portability remains more dream than reality. Most enterprises utilize more than one of the hyperscale cloud providers, but 'multicloud' remains a partitioned approach for corporate IT. Amazon Web Services (AWS) continues to dominate the public cloud infrastructure market it essentially created a decade ago, but other platforms, especially Microsoft Azure, inside enterprises, too.

As a result, companies must balance management of the disparate environments with questions of how deep to go on a single platform, all while the notion of connectivity of resources across clouds remains more theoretical than practical. Similar to hybrid cloud before it, has an amorphous definition among IT pros as various stakeholders glom on to the latest buzzword to position themselves as relevant players. It has come to encompass everything from the use of multiple infrastructure as a service (IaaS) clouds, both public and private, to public IaaS alongside platform as a service (PaaS) and software as a service (SaaS). The most common definition of a multicloud strategy, though, is the use of multiple public cloud IaaS providers.

By this strictest definition, multicloud is already standard operations for most enterprises. Among AWS customers, 56% said they already use IaaS services from at least one other vendor, according to IDC. 'If you go into a large enterprise you're going to have different teams across the organization using different cloud platforms,' said Jeff Cotten, president of Rackspace, based in Windcrest, Texas, which offers managed services for AWS and Azure. 'It's not typically the same product teams leveraging both platforms. It's often different business units, with a different set of apps, likely different people and organizational constructs.' The use of multiple clouds is often foisted upon enterprises. Large corporations may opt for a second vendor when their preferred vendor has no.

Typically, however, platform proliferation is driven by lines-of-business that either procured services on their own or were brought under an IT umbrella through mergers and acquisitions. 'By the time these two get to know each other it's too late and they've gone too far down the path to make the change,' said Deepak Mohan, research director at IDC.

An apples-to-apples comparison of market share among the three biggest hyperscale IaaS providers --AWS, Azure and Google Cloud Platform (GCP) -- is difficult to surmise because each company breaks out its revenues differently. Microsoft is closing the gap, while GCP saw a significant bump in 2016 as IT shops begin testing the platform, according to 451 Research. But by virtually any metric, AWS continues to lead the market by a sizable margin that is unlikely to close any time soon. Nevertheless, the competition between the big three is not always a fight for the same IT dollars, as each takes a slightly different tact to wooing customers. Amazon, though, continues its stand-alone, all-encompassing approach, while Microsoft has a greater percentage of enterprise accounts as it positions itself to accommodate existing customers' journey from on premises to the cloud. Google, meanwhile, is banking on its heritage, containers and machine learning to get ahead of the next wave of cloud applications. '[IT shops] are not evaluating the three hyperscale guys purely on if AWS is cheaper, or which has the better portal interface or the coolest features because there's parity there,' said Melanie Posey, research vice president at 451.

'It's not a typical horse race story.' The move away from commoditization has also shifted how enterprises prioritize portability. In the past, companies emphasized abstracting workloads to pit vendors against each other and get better deals, but over the past year they have come to prize speed, agility and flexibility over cost, said Kip Compton, vice president of Cisco's cloud platform and services organization. 'We're actually seeing CIOs and customers starting to view these clouds through the lens of, 'I'm going to put the workloads in the environment that's best for that workload' and 'I'm going to worry a lot less about portability and focus on velocity and speed and taking more advantage of a higher- level service that each of these clouds offer.' ' Silos within a multicloud strategy Even as the hyperscale vendors attempt to differentiate, picking and choosing providers for specific needs typically creates complications and leads to a siloed approach, rather than integration across clouds. 'It's more trouble than it's worth if you're going to do it that way,' Posey said.

'What ends up happening is company XYZ is running some kind of database function on AWS, but they're running customer-facing websites on Azure and never the two shall meet.' The idea of multicloud grew conceptually out of the traditional server model where a company would pick between Hewlett Packard Enterprise (HPE) or IBM and build its applications on top, but as the cloud evolved it didn't follow that same path, Mohan said. 'The way clouds were evolving fundamentally differs and there wasn't consistency, so integrating was hard unless you did a substantial amount of investment to do integration,' he said. It is also important to understand what is meant by a 'multicloud' strategy, whether an architecture supports a multicloud strategy or that workloads actually run on multiple clouds. 'There's a difference between being built for the cloud or built to run in the cloud, and it's difficult from a software development perspective to have an architecture that's cloud agnostic and can run in either one,' said Dave Colesante, COO of Alert Logic, a cloud security provider in Houston. Alert Logic is migrating from a mix of managed colocation and AWS to being fully in the cloud as it shifts to a microservices model.

The company offers support for AWS and Azure, but all of the data management ends up back in AWS. The company plans to design components of its SaaS application to provide flexibility and to assuage Microsoft customers that want the back end in Azure, but that creates limitations of what can be done on AWS. 'It's a Catch-22,' Colesante said. 'If you want to leverage the features and functions that Amazon makes available for you, you probably end up in a mode where you're hooked into some of the things.' The two key issues around multicloud center on the control plain and the data plain, IDC's Mohan said. A consistent way to manage, provision and monitor resources across all operational aspects of infrastructure is a challenge that's only exacerbated when enterprises go deeper on one platform than another.

On the data side, the concept of data gravity often discourages moving workloads between clouds because it's free to move data in, but. There are also limitations on the speed and ease by which they can be migrated. Getting the best of both worlds Companies with fewer than 1,000 employees typically adopt a multicloud strategy to save money and to take advantage of new services as they become available, but the rationale changes with larger enterprises, Mohan said.

'As you move up the spectrum, the big reason is to avoid lock-in,' he said. 'We attribute that to the nature of apps that are being run, and that they're probably more business critical IT app run by organizations internally.' The largest organizations, though, seem get the best of both worlds. 'Especially if it's for experimentation with new initiatives, they have much higher tolerance for going deep onto one platform,' Mohan said. 'For bread-and-butter workloads, volatility and jumping around services is not as important.' At the same time, large organizations that prioritize reliability, predictability, uptime and resiliency tend to favor the lowest common denominators of cost savings and commodity products, he said. Motorola Mobility takes an agnostic view of cloud and does in fact look to move workloads among platforms when appropriate.

It has a mix of AWS, GCP and Azure, along with its own OpenStack environment, and the company has put the onus on standardized tooling across platforms. 'If I can build an application at the simplest level of control, I should be able to port that to any cloud environment,' said Richard Rushing, chief information security officer at Motorola Mobility. 'This is kind of where we see cloud going.' Ultimately, a multicloud strategy comes down to IT shops' philosophical view, whether it's another form of a hosted environment, or a place and put databases in order to take advantage of higher-level services, but can lead to lock-in, he added. 'I don't think there's a right way or a wrong way,' Rushing said. 'It depends on what you feel comfortable with.'

Despite that agnostic view, Motorola hasn't completely shied away from services that tether it to a certain provider. 'Sometimes the benefit of the service is greater than [the concern] about what you want to be tied down to,' Rushing said. 'It's one of those things where you have to look at it and say, is this going to wrap me around something that could benefit me, but what else is it going to do?' Experimentation and internal conversations about those tradeoffs can be healthy because it opens an organization to a different way of doing things, but it also forces developers to justify a move that could potentially restrict the company going forward, he added. Cross-cloud not yet reality A wide spectrum of companies has flooded the market to fill these gaps created by multicloud, despite some high-profile failures. Smaller companies, such as RightScale and Datapipe, compete with legacy vendors, such as HPE, IBM and Cisco, and even AWS loyalists like 2nd Watch look to expand their capabilities to other providers.

Other companies, such as NetApp and Informatica, focus on data management across environments. Of course, the ultimate dream for many IT shops is true portability across clouds, or even workloads that span multiple clouds.

It's why organizations abstract their workloads to avoid lock-in. It's also what gave OpenStack so much hype at its inception in 2010, and helped when Docker first emerged in 2013. Some observers see that potential coming to fruition in the next year or two, but for now those examples remain the exception to the rule. What you'd eventually like to get to is data science analytics on platform A, your infrastructure and processing and storage on platform B and something else on platform C, but that's a number of years before that becomes a reality.

Dave Colesante  COO, Alert Logic. The hardest path to span workloads across clouds is through the infrastructure back end, Colesante said. For example, if an AWS customer using DynamoDB, Kinesis or Lambda wants to move to Azure, there are equivalents in Microsoft's cloud. However, the software doesn't transparently allow users to know the key-value store equivalent between the two, which means someone has to rewrite the application for every environment it sits on. Another obstacle is latency and performance, particularly the need for certain pieces of applications to be adjacent.

Cisco has seen a growing interest in this, Compton said, with some banks putting their database in a colocation facility near a major public cloud to resolve the problem. Alert Logic's data science teams are exploring what Google has to offer, but Colesante pumped the brakes on the cross-cloud utopia, noting that most companies are still in of cloud adoption. 'What you'd eventually like to get to is data science analytics on platform A, your infrastructure and processing and storage on platform B and something else on platform C,' he said, 'but that's a number of years before that becomes a reality.'

Trevor Jones is a news writer with SearchCloudComputing and SearchAWS. Next Steps • See what drivers for have changed • Learn to know about multicloud • Reduce risk with. Multifactor authentication combines two or more independent credentials: what the user knows (), what the user has () and what the user is (). The goal of MFA is to create a layered defense and make it more difficult for an unauthorized person to access a target such as a physical location, computing device, network or database.

If one factor is compromised or broken, the attacker still has at least one more barrier to breach before successfully breaking into the target. Typical MFA scenarios include: • Swiping a card and entering a. • Logging into a website and being requested to enter an additional one-time password () that the website's sends to the requester's phone or email address. • Downloading a client with a valid and logging into the VPN before being granted access to a network. • Swiping a card, and answering a security question.

• Attaching a hardware token to a desktop that generates a one-time passcode and using the one-time passcode to log into a VPN client. Background One of the largest problems with traditional user ID and password login is the need to maintain a password database. Whether encrypted or not, if the database is captured it provides an attacker with a source to verify his guesses at speeds limited only by his hardware resources. Given enough time, a captured password database will fall.As processing speeds of have increased, brute force attacks have become a real threat.

Further developments like password cracking and have provided similar advantages for attackers. GPGPU cracking, for example, can produce more than 500,000,000 passwords per second, even on lower end gaming hardware. Depending on the particular software, rainbow tables can be used to crack 14-character alphanumeric passwords in about 160 seconds. Now purpose-built cards, like those used by security agencies, offer ten times that performance at a minuscule fraction of power draw. A password database alone doesn't stand a chance against such methods when it is a real target of interest.In the past, MFA systems typically relied upon.

Increasingly, vendors are using the label 'multifactor' to describe any authentication scheme that requires more than one identity credential. Authentication factors An is a category of credential used for identity verification. For MFA, each additional factor is intended to increase the assurance that an entity involved in some kind of communication or requesting access to some system is who, or what, they are declared to be.

The three most common categories are often described as something you know (the ), something you have (the ) and something you are (the ). Knowledge factors – information that a user must be able to provide in order to log in. User names or IDs,, and the answers to secret questions all fall under this category. See also: knowledge-based authentication () Possession factors - anything a user must have in their possession in order to log in, such as a, a one-time password () token, a, an employee ID card or a phone’s.

For mobile authentication, a often provides the possession factor, in conjunction with an OTP app. Inherence factors - any biological traits the user has that are confirmed for login. This category includes the scope of methods such as,,,,, hand geometry, even earlobe geometry.

Location factors – the user’s current location is often suggested as a fourth factor for authentication. Again, the ubiquity of smartphones can help ease the authentication burden here: Users typically carry their phones and most smartphones have a GPS device, enabling reasonable surety confirmation of the login location. Time factors – Current time is also sometimes considered a fourth factor for authentication or alternatively a fifth factor. Verification of employee IDs against work schedules could prevent some kinds of user account hijacking attacks. A bank customer can't physically use their ATM card in America, for example, and then in Russia 15 minutes later. These kinds of logical locks could prevent many cases of online bank fraud. Multifactor authentication technologies:: Small hardware devices that the owner carries to authorize access to a network service.

The device may be in the form of a or may be embedded in an easily-carried object such as a or USB drive. Hardware tokens provide the possession factor for multifactor authentication. Software-based tokens are becoming more common than hardware devices. Software-based security token applications that generate a single-use login PIN. Soft tokens are often used for multifactor mobile authentication, in which the device itself – such as a smartphone – provides the possession factor.: Variations include: SMS messages and phone calls sent to a user as an method, smartphone OTP apps, SIM cards and smartcards with stored authentication data.

Such as,,,,, hand geometry and even earlobe geometry. Smartphones can also provide location as an authentication factor with this on board hardware.

Employee ID and customer cards, including magnetic strip and smartcards. The past, present and future of multifactor authentication In the United States, interest in multifactor authentication has been driven by regulations such as the Federal Financial Institutions Examination Council () directive calling for multifactor authentication for Internet banking transactions. MFA products include EMC RSA Authentication Manager and RSA SecurID, Symantec Validation and ID Protection Service, CA Strong Authentication, Vasco IDENTIKEY Server and DIGIPASS, SecureAuth IdP, Dell Defender, SafeNet Authentication Service and Okta Verify. Next Steps Learn more about the in the enterprise and read this.When it comes to, it's important to determine which deployment methods and second factors will best suit your organization. This Photo Story outlines your options. Continue Reading About multifactor authentication (MFA) • • • • •. • - The newton-second is the standard unit of impulse.

