Showing posts with label Software Development. Show all posts
Showing posts with label Software Development. Show all posts

Saturday, June 20, 2015

The rise of Pair-Programming

As agile is getting into more and more software development teams so is the importance of pair-programming.

At core pair-programming is all about two people sharing single development workstation and working on same development task. They code & watch/review in turns.

While at first look it just seems to be wastage of efforts, the reduction in time taken to complete the task and improvement in quality of code delivered, outweighs any additional effort. Here are some statistics:

image

image

Read the below paper and start practicing pair-programming today.

http://www.cs.utah.edu/~lwilliam/Papers/ieeeSoftware.PDF

Friday, November 9, 2012

Microsoft Security Intelligence Report

Latest edition of Microsoft Security Intelligence Report is out.

Volume 13 of the Microsoft® Security Intelligence Report (SIRv13) provides in-depth perspectives on software vulnerabilities and exploits, malicious code threats, and potentially unwanted software in Microsoft and third-party software. Microsoft developed these perspectives based on detailed trend analyses over the past several years, with a focus on the first half of 2012.

HTML/Javascript continues to top the list when it comes to being platform for exploits.

image

You can download the full detailed report from here.

http://www.microsoft.com/en-us/download/details.aspx?id=34955

Friday, March 2, 2012

Security Development Conference

image

EVOLVING FROM PRINCIPLES TO PRACTICES

Industry and government decision makers are increasingly aware that operational security protections and regulatory compliance are insufficient in protecting global applications and infrastructures. Organizations are realizing the value of Security Development Lifecycle (SDL) practices and seek to accelerate adoption and articulate this value to management.

The inaugural Security Development Conference 2012 (SDC 2012) will bring together industry professionals to network and learn from security experts about Security Development Lifecycle (SDL) practices. SDC 2012 will include information for leaders in software engineering, process and business management who are responsible for accelerating the adoption and effectiveness of SDL practices in their organizations.

https://www.securitydevelopmentconference.com/main.aspx

Tuesday, February 7, 2012

Free and Open : Bloomberg’s market data APIs

image

Under Open Market Data Initiative, Bloomberg has released its market data interfaces as free and open APIs which can be consumed by anyone with no restrictions.

The APIs are available in Java, C, C++ and .NET

Here are some deep links to get started quickly.

http://open.bloomberg.com/

http://open.bloomberg.com/pdf/blpapi-developers-guide.pdf

http://open.bloomberg.com/pdf/bloomberg_open_market_data_whitepaper.pdf

On a side thought, they can be a very good reference on how to design high performance public interfaces and APIs.

Monday, February 6, 2012

Secure your Data in Cloud

image

Microsoft has released a new SDK and Management called “Microsoft Codename Trust Services SDK and Management Tool” to encrypt the data before storing it in the cloud.

Microsoft Codename Trust Services is an application-level end to end encryption-based framework that can be used to encrypt stored content. Data publishers can use Trust Services to encrypt data before it is stored in Windows Azure storage or SQL Azure, and authorized subscribers of data can decrypt data after it is read from storage. Using Trust Services encrypts the data, and helps reduce concerns about unauthorized access to data by Windows Azure administrators and/or unauthorized third parties. Using Trust Services helps address data security, privacy, and sovereignty issues that might block or limit typical scenarios, such as distributing data to branch offices, making data accessible to mobile employees or customers, sharing data across businesses, and leveraging cloud scale for computation and analytics.

Download SDK

Wednesday, January 11, 2012

Privacy Principles from Microsoft

Privacy Principles

Recently Microsoft released its Privacy principles based on which it provides privacy protections in software products and Internet services.

Here are they at high level:

  • Accountability in handling personal information within Microsoft and with vendors and partners
  • Notice to individuals about how we collect, use, retain, and disclose their personal information
  • Collection of personal information from individuals only for the purposes identified in the privacy notice we provide
  • Choice and Consent for individuals regarding how we collect, use, and disclose their personal information
  • Use and Retention of personal information in accordance with the privacy notice and the consent that individuals have provided
  • Disclosure or Onward Transfer of personal information to vendors and partners only for purposes that are identified in the privacy notice, and in a security-enhanced manner
  • Quality Assurance steps to ensure that personal information in our records is accurate and relevant to the purposes for which it was collected
  • Access for individuals who want to inquire about and, when appropriate, review and update their personal information in our possession
  • Enhanced Security of personal information to help protect against unauthorized access and use
  • Monitoring and Enforcement of compliance with our privacy policies, both internally and with our vendors and partners, along with established processes to address inquiries, complaints, and disputes

Loughborough University’s study on ‘Privacy Impact Assessments’ is an important work in this field.

image

Microsoft on Privacy

PIA Study

Thursday, December 8, 2011

Learn Windows Azure - Free, Live Online event

image

On Tuesday December 13th Microsoft will be holding a special Windows Azure event for developers. Join us LIVE from the Microsoft Redmond Campus to learn how to get started building applications for the cloud from Microsoft technical leaders Scott Guthrie, Dave Campbell, and Mark Russinovich. All of the sessions will be broadcast live thanks to your friends from Channel9.

The Learn Windows Azure Event will be held from 9 a.m. to 5 p.m. PST on Tuesday December 13th. Add this time to your calendar and come back to Channel9 on December 13th to watch the live stream. We also have a limited number of seats available for the in-person studio audience. Register now if you would like to reserve a seat to attend the Learn Windows Azure event for free at the Microsoft Redmond Campus.

Wednesday, December 7, 2011

Architecture Description confirming to ISO Standard

This is the third post of the series discussing the recently released ISO standard for Architecture Description.

Post 1 : Understanding ISO/IEC/IEEE 42010:2011 : Standard for Architecture description

Post 2 : Communicating Architecture : Key Terms of 42010

While the standard defines various elements of Architecture Description and their relationships, it also specifies requirements which should be complied with for conformance.

The Standard defines four cases of conformance:

  1. architecture description (AD)
  2. architecture framework
  3. architecture description language (ADL)
  4. architecture viewpoint

Here are the primary requirements for each component:

Architecture Description (AD)

  1. AD Identification & Overview
  2. Identify stakeholders and their concerns
  3. Include Viewpoints addressing those concerns
  4. Create views satisfying those viewpoints
  5. Connect views with conformance
  6. Putting down decisions and rationale behind them

Architecture Viewpoint

  1. Identification of stakeholders and their concerns
  2. Model kinds used
  3. Details for model kinds like languages, notations, modelling techniques, etc.
  4. references to its sources

Architecture Description Language

  1. Identification of stakeholders and their concerns
  2. Model kinds implemented
  3. Viewpoints & correspondence rules related to above model kinds

Architecture Framework

  1. Identification of stakeholders and their concerns
  2. Architecture viewpoints that frame those concerns
  3. Correspondence rules integrating those viewpoints

Tuesday, November 29, 2011

Communicating Architecture : Key Terms of 42010

This is in continuation to my earlier post Understanding ISO/IEC/IEEE 42010:2011 : Standard for Architecture description. If you have landed directly to this post, I recommend to read the earlier post first.

Reposting the conceptual model of the Standard for easy reading.

image

In this I will discuss the key terms of the Standard.

Architecting :  contributes to the development, operation and maintenance of a system from its initial conception through its retirement from use and disposal. It is performed throughout the system life cycle.

AD Element : Architecture Description Element. The  most  primitive  construct in AD. Every stakeholder, concern, architecture viewpoint, architecture view, model kind, architecture model, architecture decision and rationale is considered an AD element.

Stakeholders : anyone who has interest in the system. e.g.

  • users
  • operators
  • owners
  • suppliers
  • developers
  • maintainers

Concerns : interest in a system relevant to one or more of its stakeholders. e,g, technological, business, operational, performance, resource utilization, etc.

Viewpoint : establishes the conventions for the construction, interpretation and use of architecture views for specific concern(s). A concern can be framed by more than one viewpoint. Viewpoint conventions can include
languages, notations, model kinds, design rules, and/or modelling methods, analysis techniques and other
operations on views.

View : expresses the architecture of a system from the perspective of specific system concern(s) in accordance to its Viewpoint.

Model Kinds : conventions for a type of modelling. e.g. class diagrams, data flow diagrams, etc.

Architecture Model : An architecture model uses modelling conventions appropriate to the concerns to be addressed. These conventions are specified by the model kind governing that model. Within an architecture description,  an architecture model can be a part of more than one architecture view.

Rationale : Architecture rationale records explanation, justification or reasoning about architecture decisions that have been made. The rationale for a decision  can  include the basis for a decision, alternatives and trade-offs considered, potential consequences of the decision and citations to sources of additional information.

Decision : something which affect the architecture in context of a concern.

Correspondence Rules : Correspondences are governed by Correspondence Rules.

Correspondences : defines a relation between AD elements. Correspondences and correspondence rules are used to express and enforce architecture relations such as composition, refinement, consistency, traceability, dependency, constraint and obligation.

Architecture Framework :  conventions, principles and practices for the description of architectures established within a specific domain of application and/or community of stakeholder. Uses of architecture frameworks include, but are not limited to: creating architecture descriptions; developing architecture modelling tools and architecting methods; and establishing processes to facilitate communication, commitments and interoperation across multiple projects and/or organization. e.g.

  • Zachman’s information systems architecture framework
  • UK Ministry of Defence Architecture Framework
  • The Open Group’s Architecture Framework (TOGAF)
  • Kruchten’s “4+1” view model
  • Reference Model for Open Distributed Processing (RM-ODP)

Architecture Description Language (ADL) :  An ADL provides one or more model kinds as  a means to frame some concerns for its audience of stakeholders. An ADL can be narrowly focused, defining a single model kind, or widely focused to provide several model kinds, optionally organized into viewpoints. Often an ADL is supported by automated tools to aid the creation, use and analysis of its models. e.g.

  • Rapide
  • Wright
  • SysML
  • ArchiMate

Understanding ISO/IEC/IEEE 42010:2011 : Standard for Architecture description

Approved on 10 Nov 2011, ISO/IEC/IEEE 42010:2011, Systems and software engineering — Architecture description, is the latest edition of the original IEEE Std 1471:2000, Recommended Practice for Architectural Description of Software-intensive Systems.
This standard replaces IEEE 1471:2000. It is identical to the ISO standard approved in July. The new standard, designated ISO/IEC/IEEE 42010:2011, Systems and software engineering — Architecture description, is available from IEEE and ISO.
In March 2006, IEEE 1471 was adopted as an ISO standard. It was published in July 2007 as ISO/IEC 42010:2007. Its text was identical to IEEE 1471:2000.ISO/IEC/IEEE 42010:2011 replaces both ISO/IEC 42010:2007 and IEEE Std 1471:2000.
image
Here is the composite and simplified view of Architecture and its ecosystem.
image
The storyboard for reading this diagram goes like this:
  1. System which belongs to an environment addresses concerns of its stakeholders.
  2. Every system has architecture
  3. Architecture is described using Architecture Description(AD)
  4. Stakeholders use AD to understand architecture
  5. AD is created using Architecture Frameworks (AF) and Architecture Description Languages (ADL)
  6. AD includes following:
    • Stakeholders and their concerns
    • Architecture Viewpoints & Views
    • Architecture Model kinds & Models
    • Architecture Rationale & Decisions
    • Correspondence Rules and Correspondences
  7. Architecture Viewpoints include Model Kinds
  8. Architecture Views include Architecture Models
  9. Views are governed by Viewpoints
  10. Models are governed by Model Kinds
  11. Architecture Rationale justifies Decisions
  12. Correspondence Rules specify Correspondences
So, what does this Standard contains ?
This Standard defines & specifies conformance requirements on contents of following:
  • Architecture Descriptions of systems
  • Architecture Frameworks
  • Architecture Description Languages
  • Architecture Viewpoints
The Standard defines architecture this way:
fundamental concepts or properties of a system in its environment embodied in its elements, relationships, and in the principles of its design and evolution.
This post is first in the series where I will try to explain this standard. In next post I will try to go into details of various AD elements.

Part 2 : Communicating Architecture : Key Terms of 42010

Part 3 : Architecture Description confirming to ISO Standard

Thursday, November 24, 2011

Pillars of Agile Development

image

Businesses & CIOs across the world see lot of value in going Agile for Software Development. Development teams also have been quick enough in adopting the Agile methodologies. But in majority of cases, teams have failed to capitalize on the value of Agile development and in fact reduced their efficiencies by going Agile. There is also a trend where teams have started reverting back to the old way of software development.

The primary reason for this failure is that teams have failed to understand what it takes to get value out of Agile. Just by doing SCRUM or hiring a Scrum master doesn’t make you agile. In fact it creates chaos. Going Agile is a multi-dimensional approach and is based on three foundation pillars. If the team is not matured enough in even one of these, they will fail to get value out of going Agile. Higher the maturity in these pillars, more effective the agile approach will be.

The foundation pillars of Agile Development are:

1. Test Driven Development. It is about coding against tests instead of requirements. Requirements are translated into test cases and developers code to satisfy those test cases. This considerably reduces the testing cycle but increases focus on writing right test cases.

2. Agile Project Management. This is about correctly prioritizing the requirements and right sizing the iterations. I am sure everyone must have heard stories about Google having a sprint cycle of 2 days and Facebook having it of less than a day. Start with a sprint size with which the team is comfortable, even if it is 30 days. As you mature in other 2 pillars, you can start reducing your sprint duration.

3. Continuous Integration & Deployment. This is the last leg of an iteration and requires lot of support from tools. It involves building & integrating the code frequently, running automated tests and moving it to production. Some of the tools like Microsoft TFS, Cruise Control and others can help in this.

So, if you are planning to go agile for your development make sure you address it from all sides.

Tuesday, October 11, 2011

DART : Overview of Google’s new web programming language

image

So finally, the technology has started moving on the client side of web too, faster than we expected. After many years of using HTML, JavaScript, ActiveX, Flash & Silverlight came the big innovations like HTML5 & CSS3.

Here comes the latest from Google, called DART – Structured Web programming language. Personally I have never been happy with JavaScript due to readability, maintainability & lack of support of good developer tools.

So what is DART ? Here are few highlights:

  • Open source project
  • Class-based programming language (not mentioned as object-oriented language) 
  • Moving to more structured environment. It supports classes & libraries. This is what JavaScript lacked though supported in unstructured way.
  • Optional types. This is interesting as this will allow you to start prototyping your application quickly using JavaScript style programming with simple and untyped code and then as you progress in application lifecycle convert the code from untyped to typed style which is easy to debug, understand and maintain.

Google promises to provide the right tooling support to leverage the enhancements done over javascript in Dart.

Design goals of Dart as mentioned by Google :

  • structured yet flexible
  • familiar & natural
  • high performance & fast application startup
  • full range of devices on the web – phones, tablets, laptops & servers
  • support across all major modern browsers – the current test environment does not support IE.

Deployment/Execution Models

  • Translate Dart code to JavaScript and run it in browsers today except IE.
  • Execute Dart code in a virtual machine on server side
  • Use Dartboard to write and execute code snippets in browser window except IE
  • Proposes a new MIME type called ‘application/dart’ so that it can be embedded or imported into HTML pages.

Dart & HTML5 – Dart will have HTML5 Dom library to interact with HTML elements

I feel Dart will help in making the web richer without compromising the developer productivity. JQuery is helping a lot currently in this aspect on top of JavaScript. Based on the acceptance of Dart, JavaScript may continue to remain popular.

It would have been better if instead of releasing a new language, Google had advocated such advances in JavaScript itself.

With Google Chrome making big advances and may soon become second most popular browser, it could dare to take such a bold step.

http://www.dartlang.org/