Comments
litl_phil wrote: While it's nice that Google and Acer share the vision of cloud-based computing, it's also worth noting that we at litl already have a webbook on the market (available at litl.com) that runs our own cloud-based OS. Unlike Chrome, litlOS is focused on creating a new and better web experience for the home, so we don't have the usual browser interface, we have our own innovative UI. In conjunction with easel mode (litl's inverted-V position) and our growing cohort of litl channels (special apps t...
Cloud Computing
Conference & Expo
November 2-4, 2009 NYC
Register Today and SAVE !..


2008 West
DIAMOND SPONSOR:
Data Direct
SOA, WOA and Cloud Computing: The New Frontier for Data Services
PLATINUM SPONSORS:
Red Hat
The Opening of Virtualization
GOLD SPONSORS:
Appsense
User Environment Management – The Third Layer of the Desktop
Cordys
Cloud Computing for Business Agility
EMC
CMIS: A Multi-Vendor Proposal for a Service-Based Content Management Interoperability Standard
Freedom OSS
Practical SOA” Max Yankelevich
Intel
Architecting an Enterprise Service Router (ESR) – A Cost-Effective Way to Scale SOA Across the Enterprise
Sensedia
Return on Assests: Bringing Visibility to your SOA Strategy
Symantec
Managing Hybrid Endpoint Environments
VMWare
Game-Changing Technology for Enterprise Clouds and Applications
Click For 2008 West
Event Webcasts

2008 West
PLATINUM SPONSORS:
Appcelerator
Get ‘Rich’ Quick: Rapid Prototyping for RIA with ZERO Server Code
Keynote Systems
Designing for and Managing Performance in the New Frontier of Rich Internet Applications
GOLD SPONSORS:
ICEsoft
How Can AJAX Improve Homeland Security?
Isomorphic
Beyond Widgets: What a RIA Platform Should Offer
Oracle
REAs: Rich Enterprise Applications
Click For 2008 Event Webcasts
Everyone wants to lower their capital expenditures and increase operational efficiency - it's a sign of the times. The economy of the past 12 - 18 months has forced all organizations to do more with less and become more efficient. While everyone can identify with the request to do more with less, th...
SYS-CON.TV
Opinion: Web Services Security Hype
If we're going downhill, that means we're gaining momentum, right?

Related Links:

  • SYS-CON Media and Burton Group to Stage Application Server Shoot-Out at Web Services Edge Conference 2005
  • Application Servers to Vie for Top Position in Boston Shoot-Out 


    According to the latest Web services "hype cycle" from Gartner, both Web services security standards and the deployment of Web services with security are rushing headlong into the dreaded "Trough of Disillusionment." This means that the greatest levels of hype in these areas are supposedly behind us and the reality of just what can and cannot be done is collectively dawning on us.

    Taken at face value, this news could be either good or bad. The good news could be that now that the hype is over and we have passed the lofty "Peak of Inflated Expectations," we can all get down to the serious work of putting together workable security solutions and solid security standards to help bring Web services to where they deserve to be. The bad news could be the security components of Web services getting mired in the "Trough of Disillusionment" for too long and losing their appeal for the enterprise.

    Rightful Place?
    One question we should ask ourselves is, do the Web services security categories belong where Gartner has placed them on the hype curve? There are a number of ways that we can look at it. One way is to examine the position of the security elements on the hype curve relative to their peers. The security pieces still have a long way to go to catch up with established components of Web services, such as SOAP and WSDL, which are already on the "Plateau of Productivity" and are on the verge of exiting the hype cycle as they approach full mainstream adoption.

    Another way to look at it is to consider how these components are progressing over time. If you look at where they were placed on the curve at the same time last year, the security elements have been big movers - especially when compared to some other areas, like UDDI, which have been essentially frozen in place. In last year's hype cycle, Web services security standards had not even made it to the top of the "Peak of Inflated Expectations." In just a year's time, by Gartner's estimation, the security standards have made respectable advances toward broad acceptance and implementation; secure Web services made a roughly equal advance along the curve.

    Unfortunately, the path to productivity must inevitably pass through disillusionment, which is where Gartner sees the current state of Web services security. To really make a judgment about whether Gartner has made the right call about where we are with security, and where we might be heading, it is useful to understand how we got here.

    Keeping the Momentum
    Gartner's hype cycle assumes that all new technologies will eventually hit some rough spots in their life cycle, especially if they fail to meet the lofty expectations that are so often set for them early on. This is certainly true of Web services security. As Web services took off, there seemed to be no shortage of efforts to answer the need for securing this new paradigm. Creativity, and even unprecedented cooperation, appeared to be the order of the day: rival authentication standards banding together to create SAML; Microsoft and IBM joining hands to chart out a whole family of standards; promises of quick action from standards bodies to "fast track" Web services security standards; dozens of companies responding to the call to create technologies for implementing the standards. Plus, the newly conceived security standards showed bright promise for applications far beyond the world of Web services. It all felt so good, we should have known it would have to end. Competition, old rivalries, "standards bloat," and many other factors have served to pull us collectively back to reality. For example, Microsoft and IBM started to see different directions for their WS-* roadmap. And, the notion that standards would make security products interoperable right out of the box remains a dream for most. So, perhaps the assessment that we are in a state of disillusionment around Web services security, if it is off the mark at all, is not off by much.

    But that doesn't mean this is the end of the story. The descent into disillusionment could mean that real productivity and value from Web services security is just over the next rise. The danger is that if momentum is lost, these key components of the Web services world could suffer the same fate that intrusion detection technologies have suffered in the larger security space - a permanent place in the "trough." Losing momentum at this critical juncture could have dire consequences for security in Web services and the usefulness of Web services as a whole.

    The Next Big Step
    So, how can we ensure that security stays on track to help Web services deliver on their promises? I see three things that we can do for a start:

    • Keep it real: If we can properly manage our expectations and not fall back on the overblown hype of the past, then our disillusionment will likely be short-lived;
    • Close the gap: Right now, Gartner shows deployment of Web services with security as being a good deal further along in the cycle than the Web services security standards. This is a dangerous gap since it could indicate that many Web services security deployments are not using standards. I hope it is actually more of a matter of definitions, since Gartner considers the use of Secure Sockets Layer (SSL) encryption to constitute a Web service deployed with security (most robust applications Web services require much more to be secure). Whether the gap is real or just a gap in understanding, we must work to close it;
    • Maintain the focus: If those who are experimenting with or adopting Web services for use in their environments keep a strong focus on the importance of security to Web services, then the momentum should be able to carry these components over the hump.
    It will be exciting to see if this next year turns out to be one in which the security pieces of the Web services puzzle at last snap firmly into place.


    Related Links:
  • SYS-CON Media and Burton Group to Stage Application Server Shoot-Out at Web Services Edge Conference 2005
  • Application Servers to Vie for Top Position in Boston Shoot-Out
  • About Michael Mosher
    Michael Mosher is the technology director of the CSC Consulting Business and Technology Risk Management practice. He specialized in security architecture and security strategy, and has designed security solutions for Fortune 500 clients in financial services, manufacturing, energy, and health care. Michael has a broad background in government and commercial security, including six years as a special agent with the U.S. government investigating computer and white-collar crimes.

    In order to post a comment you need to be registered and logged in.

    Register | Sign-in

    Reader Feedback: Page 1 of 1

    SOA World Latest Stories
    This coming Tuesday, December 8, at 2:00PM EST, SYS-CON.TV will be broadcasting live from its 4th-floor studio overlooking Times Square in New York City a very special "Power Panel" in which Cloud Computing Expo Conference Chair Jeremy Geelan and three top industry guests will be looki...
    If you are like me, you are regularly receiving unsolicited email from various quarters, telling you about the latest and greatest SEO solutions on the planet. Just buy the book, or guide, or download the promotional whitepaper and this expert will offer you the latest "Secrets" to sea...
    There's a lot of talk about how we need to focus on our buyers' issues and provide them educational insights to help them learn what they need to know to make buying decisions. Heck, I say it in my book...in several places, I think. I've said it on this blog, and I'll continue to say i...
    This past weekend I set out explore some of the extension capabilities of Google Wave. One of the weaknesses that have been identified by many is the lack of integration with email. For me, in particular, because Wave is new, many Waves are being orphaned as those playing and testing o...
    More good news for cloud computing! Google last week released its once mysterious Chrome Operating System to open source. Chrome OS, available in 2010 – is a web-based operating system that promises to boot up super-fast on a netbook – way faster than the time it takes to start your ba...
    In CloudBerry Lab we are striving to make our customer service better. In this competitive market with the abundance of free offerings this is the only way to stay afloat. One of the ways to keep customers happy is to be very responsive when it comes to support request resolution. Shou...
    Subscribe to the World's Most Powerful Newsletters
    Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
    Click to Add our RSS Feeds to the Service of Your Choice:
    Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
    myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
    Publish Your Article! Please send it to editorial(at)sys-con.com!

    Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021


    SYS-CON Featured Whitepapers
    ADS BY GOOGLE