Welcome!

Weblogic Authors: Yeshim Deniz, Elizabeth White, Michael Meiner, Michael Bushong, Avi Rosenthal

Related Topics: Weblogic, Containers Expo Blog

Weblogic: Article

Watch Your Security Hole

Watch Your Security Hole

Anyone who has recently been on the job hunting circuit, looking for a position as a developer, knows that employers are getting rather picky. With the oversupply of IT professionals, recruiters are not just looking for good people, they are looking for good people with an exact skill set to match their requirements. As such, the chances of getting the position you desire is not as guaranteed as it was back in the boom times four years ago. Besides having good looks and luck, one of the ways that you can get around this dilemma is to maintain a diverse set of skills on your résumé and hope that some combination will get you the job.

One of the traditional "must-have" items on your résumé used to be working knowledge of relational database systems (and associated APIs) or application servers. Job requisitions would be combinations of Java/Oracle, WebLogic Server/J2EE/Sybase, etc. The trend now, especially in the new millennium where the Internet can sometimes appear as a vast wasteland swarming with viruses, worms, and other types of low life, is that security issues have taken center stage - both in and out of cyberspace.

For example, a leading IT consulting company has recently upgraded their methodology to include security-related issues and design. What makes this particularly interesting is that this methodology addresses security-related issues during all phases of the project life cycle, starting with the envisioning phase and on through to the operational services phase. In another case, the Microsoft Solutions Framework includes security in a number of different phases in their process model, starting early in the planning phase. As is evident in these examples, security issues are no longer an afterthought and need to be addressed throughout application and system development, and rightly so.

Now, what this means for the average Joe Developer is this: you should start thinking more about further developing your knowledge and skills related to IT security and make sure your résumé reflects whatever experience you do have. To start, you will need some working knowledge regarding basic security concepts, including encryption, authentication, and authorization. That is just the basics! When you move into the Web services space, there are other security-related specifications that you should be aware of, including WS-Security and SAML. Therefore, if you haven't paid much attention to your security-related skill sets, or if you think that it's only for the security specialist or guru, it's time to think again.

To help you begin to sort through all this stuff, this month we will focus on some of the security issues and solutions that you may come across as a WebLogic developer. You will also get up to speed on the new Enterprise Security Initiative, announced by BEA, which will introduce a number of security management services to the BEA WebLogic Server platform, including single sign-on and other advanced security features.

Finally, if you just happen to be in San Francisco during the May 24-27 time frame, come and visit the Ninth Annual BEA eWorld Technology Conference at the Moscone West Convention Center in town. The conference promises to provide you with the latest on what is happening at BEA, and will be jam-packed with new and exciting hands-on sessions and a variety of keynote speakers. You will also find an exhibit floor full of BEA partners and vendors with plenty of giveaways to help fill up your "techy" bag. For more information and to sign up for the event, check the BEA Web site at www.bea.com. I look forward to meeting all of you there!

More Stories By Joe Mitchko

Joe Mitchko is the editor-in-chief of WLDJ and a senior technical specialist for a leading consulting services company.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


IoT & Smart Cities Stories
Business professionals no longer wonder if they'll migrate to the cloud; it's now a matter of when. The cloud environment has proved to be a major force in transitioning to an agile business model that enables quick decisions and fast implementation that solidify customer relationships. And when the cloud is combined with the power of cognitive computing, it drives innovation and transformation that achieves astounding competitive advantage.
Nicolas Fierro is CEO of MIMIR Blockchain Solutions. He is a programmer, technologist, and operations dev who has worked with Ethereum and blockchain since 2014. His knowledge in blockchain dates to when he performed dev ops services to the Ethereum Foundation as one the privileged few developers to work with the original core team in Switzerland.
Machine learning has taken residence at our cities' cores and now we can finally have "smart cities." Cities are a collection of buildings made to provide the structure and safety necessary for people to function, create and survive. Buildings are a pool of ever-changing performance data from large automated systems such as heating and cooling to the people that live and work within them. Through machine learning, buildings can optimize performance, reduce costs, and improve occupant comfort by ...
René Bostic is the Technical VP of the IBM Cloud Unit in North America. Enjoying her career with IBM during the modern millennial technological era, she is an expert in cloud computing, DevOps and emerging cloud technologies such as Blockchain. Her strengths and core competencies include a proven record of accomplishments in consensus building at all levels to assess, plan, and implement enterprise and cloud computing solutions. René is a member of the Society of Women Engineers (SWE) and a m...
Early Bird Registration Discount Expires on August 31, 2018 Conference Registration Link ▸ HERE. Pick from all 200 sessions in all 10 tracks, plus 22 Keynotes & General Sessions! Lunch is served two days. EXPIRES AUGUST 31, 2018. Ticket prices: ($1,295-Aug 31) ($1,495-Oct 31) ($1,995-Nov 12) ($2,500-Walk-in)
IoT is rapidly becoming mainstream as more and more investments are made into the platforms and technology. As this movement continues to expand and gain momentum it creates a massive wall of noise that can be difficult to sift through. Unfortunately, this inevitably makes IoT less approachable for people to get started with and can hamper efforts to integrate this key technology into your own portfolio. There are so many connected products already in place today with many hundreds more on the h...
Digital Transformation is much more than a buzzword. The radical shift to digital mechanisms for almost every process is evident across all industries and verticals. This is often especially true in financial services, where the legacy environment is many times unable to keep up with the rapidly shifting demands of the consumer. The constant pressure to provide complete, omnichannel delivery of customer-facing solutions to meet both regulatory and customer demands is putting enormous pressure on...
Charles Araujo is an industry analyst, internationally recognized authority on the Digital Enterprise and author of The Quantum Age of IT: Why Everything You Know About IT is About to Change. As Principal Analyst with Intellyx, he writes, speaks and advises organizations on how to navigate through this time of disruption. He is also the founder of The Institute for Digital Transformation and a sought after keynote speaker. He has been a regular contributor to both InformationWeek and CIO Insight...
Digital Transformation: Preparing Cloud & IoT Security for the Age of Artificial Intelligence. As automation and artificial intelligence (AI) power solution development and delivery, many businesses need to build backend cloud capabilities. Well-poised organizations, marketing smart devices with AI and BlockChain capabilities prepare to refine compliance and regulatory capabilities in 2018. Volumes of health, financial, technical and privacy data, along with tightening compliance requirements by...
Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settlement products to hedge funds and investment banks. After, he co-founded a revenue cycle management company where he learned about Bitcoin and eventually Ethereal. Andrew's role at ConsenSys Enterprise is a mul...