2017年12月10日 星期日

Website design security: what are the security measures for the site

A website design er is more thinking about how to meet the user's application and how to implement the business. Rarely consider the exist of web application development in the process of these loopholes, loopholes in the security code design personnel do not pay attention to the eyes of almost invisible, most developers, website design and website maintenance personnel to understand website defense technology is little; in the course of normal use, even if the existence of security vulnerabilities, normal users are not aware of. But when hackers are aware of loopholes and make full use of them, vulnerabilities exist on websites, and they become opportunities for hackers to gain benefits directly or indirectly. For the SQL injection vulnerability of Web applications, experiments show that 11.3% SQL injection vulnerabilities are detected by searching for 1000 site sampling tests.
 Website design
The site environment has undergone great changes, more of a threat from the Web application layer, and the safety measures most of the site is still in the original basis of threat awareness, and even whether the site has been compromised and the implementation of the pages linked to horse, often in the investigation of visitor complaints or regulatory authorities is only aware of at this time, but has caused irreparable loss. A lot of people will ask: my website has already had security measures, and this kind of thing will still happen. Why is it? Let's analyze the existing security measures.
Firewall, anti-virus, vulnerability scanning are all widely used traditional website security measures, especially the deployment of firewall, which prevents websites from attacking most of them from the network layer, and plays an important role. But in the face of the new situation, are these traditional security measures able to deal with it?
firewall
After enabling the network access control policy, the firewall can block access to other service ports of the website, and only allow access to the HTTP service port, so that vulnerability scanning and attack attempts based on other protocols and service ports will be blocked. But for the popular Web application layer attack, its behavior is similar to a normal Web access. Firewall is unable to recognize and prevent. Once blocking, it will mean that normal Web access will also be cut off.
Antivirus
No matter it is deployed on gateway or website server, anti virus system can detect and protect virus effectively, but it can't identify malicious code in webpage, that is webpage Trojan horse. Because webpage Trojan usually appears as a normal script in web page program, it is possible to download harmful programs or steal the victim's privacy directly when it is executed. In the same way, anti virus systems are more difficult to identify for vulnerabilities in Web applications.
Vulnerability scanning
Operating system vulnerabilities, vulnerability database, publishing system in the search and repair site (such as IIS, Apache etc.) vulnerabilities, vulnerability scanning system plays a significant role, but as a general vulnerability scanning system, the recognition of Web vulnerabilities and are limited, the reason is Web application vulnerability is not a specific software or the service of the loopholes, the complex and diverse forms, usually based on automatic inspection tools, through manual review to be accurate positioning.
To sum up, identifying and blocking attacks based on Web vulnerabilities is hard to do by traditional security measures, such as vulnerability scanning, network access control, virus detection and protection. In view of the new website security threat, we should keep enough urgency and take effective measures to deal with it.

2017年12月7日 星期四

The Containmet project USES a reference design advantage

The design of a completely independent Containmet, which includes all aspects of the data center, is no longer practical and economical and has not been built before.
For the new data center, as well as to the upgrading of existing data center, choose before with the size of the data center solutions used has been adopted (with related drawings, subsystem or system design scheme is the most sensible thing to do.)
Choose the past classic design as a new project in project design reference basis, to the project itself and the data center optimization of the overall scheme design and subsequent data center to run the life cycle of the whole will have a positive impact.
The past solutions used as reference to set up in the new project or to upgrade existing data center, can simplify the project cycle, shorten the planning and implementation process, and reduce the risk of data center after running down.
The following is a description of the definition and advantages of the reference design.
 Containmet
To build a data center faster, you need to have a strong incentive to plan and delegate to a third party.
However, due to the limited budget, shortage of staff, the early can't clear IT load, other dynamic change, from the design point of view put forward high availability is not compromise, and so on practical problems, make extremely difficult to achieve this goal.
Planning and building data center realistic planning is key.
However, in the data center project construction process, "system planning is likely to be a fatal weakness in the implementation of data center projects.
Once the system planning mistakes, you will be in the later construction, the implementation stage amplifier and spread continuously, is likely to lead to system delay, construction costs, delays, and eventually involving system appear likely problem.
When planning for a data center, this tool can help planners avoid some potential pitfalls during early planning.
Usually, the reference to design the blueprint of the system is usually a reference to previous project, including the system schematic diagram, chart, (ideally), at the same time also includes a detailed list of all systems of material or component.
Although the reference design can be implemented directly, more typically, it can be used as a benchmark to meet specific user preferences or constraints.
The reference design may be used for a complete data center, or IT may be limited to a system in a data center, such as an IT machine room, power equipment, or cooling system.
A variety of directories to choose from are designed to allow users to quickly find the design best suited to their needs and require minimal adaptation to their specific projects.
Reference design is based on recommended and proven best practices.
For example, the manufacturer of electrical components often provides reference designs for their products to help their customers become more efficient in their own project applications.
The reference design also exists in the physical infrastructure system of the data center, and can provide the advantages of the electrical original and housing design mentioned just now.
Data center reference design as a starting point provides some valuable Suggestions for the project team, including:
Promote and simplify the planning stage
Reduced planning time
Reduce risk, provide forecast for future risks and improve reliability
What is the data center reference design?
What it contains and explains how the benefits listed above are implemented one by one.

邊緣機房建置的五個誤區

機房建置:隨着移動通信和最後一英里的帶寬進入高級和現代化的應用,人們需要低延遲的網絡連接,計算負載正在從集中式的數據中心移動到網絡的邊緣。但是人們關於邊緣數據中心有很多的誤區。根據正常運行時間學院首席技術官克里斯•布朗對此進行了分析與闡述,以下是組織對邊緣數據中心產生誤解的幾種原因:
 機房建置
誤區1:邊緣計算是使服務器運營成本更加低廉的一種方法
本地數據中心的分支機構模式不適用於邊緣計算工作,因爲邊緣數據中心不僅僅是本地數據中心。邊緣數據中心是它資產的一個集合,它已經接近最終用戶,並最終從某個大型數據中心提供服務。”
這使邊緣計算更像一個分佈式計算架構。人們已經看到在製造業中,集中式計算系統可以處理不需要直接輸入的作業,日常操作可以直接在工廠的生產設備中運行。但是,如果中央計算機出現故障或連接丟失,工廠系統將無法長時間運行.Brown表示,例如汽車製造設施由於系統不知道訂購什麼零件或建造什麼車輛,將會閒置24小時。
邊緣數據中心的規模可能很小,但它們不會是DSL所連接的廉價服務器.Brown說,“邊緣數據中心不會像一些人想像那樣可以降低成本。運營商不能只使用成本低廉,並不可靠的硬件,用戶仍然需要堅如磐石的基礎設施和網絡。它們需要以大區域數據中心的高可用性方式進行設計,構建、運行和操作。”
邊緣計算有利於將遠離遠程大規模數據中心的更多延遲相關服務卸載,並使其更接近用戶。從某種意義上說,它們就像一個內容分發網絡,只是針對企業的特定應用程序和服務。
誤區2:網絡並不重要
在網絡邊緣要比在具有高可用性連接和電力系統的數據中心更難提供一個良好的用戶體驗。
“網絡連接將變得更加重要,邊緣網絡不僅僅是佈線。在數據中心設計領域,人們有時把網絡視爲第二個想法,但是對於邊緣數據中心,企業需要一個穩固的網絡。”布朗指出。
構建邊緣網絡意味着需要改變管理和運行數據中心的方式。企業的系統不再位於擁有現場操作團隊的易於訪問的大型數據中心中。而需要構建更像蜂窩網絡的系統,將硬件部署在遠程站點上的模塊化設備中,而這需要時間來完成。
布朗說,“企業必須考慮使用多個網絡提供商服務和多個連接點的意義,每個連接點都能夠支持滿足邊緣數據中心業務需求的全部負載,以便即使出現故障或丟失單個網絡提供商的服務仍然可以提供相同的高質量服務。這可能意味着需要採用有線連接和無線連接的混合,以確保即使在一個路由停止時也能訪問。”
網絡邊緣的一個新的選擇是計算負載甚至可以運行在蜂窩基站或靠近城域網,而這可能是向用戶提供服務的最佳方式。
誤區3:管理邊緣計算很容易
邊緣數據中心並不是單一模式的。一個邊緣數據中心從單一機架到二三十個機器,而無論其尺寸如何,他們都需要合適的設備。
“不,要把邊緣數據中心想象成一個廉價的,小型而無關緊要的東西,而必須把每個單獨的節點看作是一個數據中心。企業必須使用商業品質的設備進行設計,建造,測試。它需要經過全面測試並投入到網絡中以支持業務需求。”布朗指出。
像Azure堆棧這樣的超融合和混合雲系統是一個常見的解決方案,因爲它們解決另一個大問題——管理邊緣.Brown說,“我們看到越來越多的公司開始走這條路。隨着越來越多的這些小型邊緣數據中心在世界各地構建,如果企業不擅長採用遠程監控其設備,那麼機載分析和自動化將會提醒企業遇到的問題,還可能提供將負載從一個它資產轉移到另一個它資產基於其健康狀況,那麼企業管理分佈在一個國家或全球各地的大量它資產將變得非常困難。”
大多數數據中心運營模式都是建立在現場工作人員能夠根據需要保持設備輪班的情況下進行的。對於邊緣計算來說,這是不可能的,現在企業可以在各種位置管理許多小型數據中心及其數據中心資產。
答案是採用有效的遠程監控和大量的自動化設備。如果訪問可能成爲一個問題,則可能還需要冗餘硬件。應用程序還需要提供某種形式的自我修復,或將故障轉移到附近的節點或中央數據中心,以確保用戶即使因延遲時間而降級也能保持服務訪問。混合雲應用程序體系結構也可以在這裏提供幫助,允許在發生故障時將功能遷移到易於管理的核心繫統。
誤區4:企業只需要擔心網絡安全
當談到邊緣計算時,大多數組織都在關心黑客和網絡安全問題,但往往忘記了自身的物理安全。
邊緣數據中心的關鍵思想之一是它們被迅速部署.Brown指出:“通常他們是獨立的機架,而企業所需要的只是提供可靠的電力和冷卻設備,並把它們放在某種設施上,以保持環境不變。所以,他們可能沒有部署在標準的數據中心,而是能夠被部署在一個倉庫中。這意味着企業沒有通常不具備保護其系統的受限訪問措施。
這使得實現物理安全成爲一項重大任務和重大開支企。業需要了解如何保護蜂窩基站作爲保護邊緣服務器的安全模型。
誤區5:網絡邊緣不是數據中心
邊緣計算並不是分支機構解決方案。它是中央數據中心的一部分,只是網絡連接的末端,這不是簡單的部署成本低廉的硬件,但如果企業做得對,自動化將降低其運營成本。如果企業的邊緣計算部署將取得成功,那麼企業需要與現有數據中心一起對其進行管理,並使用相同的流程,並對如何部署採取相同的謹慎規劃。
“企業需要認識到,他們不能只採取半途而廢的方式來處理數據中心,因爲他們會有一大堆。邊緣計算需要嚴格的設計,構建和實施測試方法。”布朗警告說。這一切歸結爲:不要把它看成是一個服務器,而是設計,構建和管理面向客戶的數據中心,只是一個縮小的版本。

Data center migration: where is the maintenance focus of the machine room

Data center migration: the server can generate huge energy and, of course, need good care. Since the maintenance of the server, there has been a variety of server maintenance bills of lading application. Of course, the maintenance of this server expands its scope. It is not limited to a single server maintenance, but something special to note in the whole machine room server and computer room server maintenance.
 Data centre migration
Machine room server
The first of all is the power control problem.
The most essential point of server hardware application is to achieve stability and continuity of operation, and to maintain stable operation of hardware system, power stability is the foundation. In this way, when we arrange the power system inside the computer room, besides the sufficient supply of the server room, the power supply will also be equipped to cope with the sudden blackouts.
In addition, the larger the power of the server, the greater the power consumption, the average IDC service will be valued for different sizes of servers. Hosting the Hongkong server, if more than the limit of electricity, also need to add 1000 yuan per year of power supply, and not to make a profit. It is conceivable how important it is to the server.
The next thing to mention is to avoid light and dust.
Light energy, irradiated by light, the higher the temperature of the server, the more easy to get out of the problem, for the stability of the server system is very unfavorable. In addition, the direct sunlight is very offensive to the monitors in the computer room. Because of the direct sunlight, the life of the display is easily reduced by half or even more. What is the dustproof and why? The fans of the server have a good heat dissipation function, and the intrusion of dust will only degenerate the heat dissipation function, and the internal hardware of the server is accelerated.
The end is the pressure control of the fuselage.
When finishing the cabinet should consider the server itself on the pressure bearing capacity, not all heap fall, and the next is space. A good general server chassis, 1U Rackmount chassis as an example, a 1U can withstand the pressure is roughly the same size weight (1U) in 5-7 months; some good strength pallet rack, for server pressure is also the basic between 6-8 1U server.

Website design: how to design the system interface

Website design: if a system or web site is running normally, and the desired operation needs are reached, many of them are connected with the system in series. In the process of the design of the system interface, there are two problems, which are very concerned about how to design interfaces for other system calls and how to call the interfaces of other systems.
 Website design
How to design the interface?
1. generally speaking, it is stable and less variable to publish interfaces to other systems. Therefore, it is a prerequisite to take into account various factors and possible factors in the future, so that we can minimize the change of interfaces.
2. of the data check is not passed and failed, it is best to have clear and clear that returned to the caller.
3., for the interface to generate transaction data, it is best to write log, record the data transmitted by the caller, so that it is convenient for future search and can not expect all callers to write log.
The use of variable type 4. interface to universal, especially for the use of this interface absolutely ignorant of user case, the other party may be JAVA, or VB6, may also be a specific type of C#, do not use a programming language, I think it is a good, parameters and return values are string type, such as the basic the programming language can support, then the parameters and return to use XML to define. When the interface is published, the interface definition document is published together, preferably with the XDL document.
5. the interface receives the data from the best data tested, because you can not guarantee that other system will give you full compliance with the standards of data.
How to call the interfaces of other systems?
Because it is the interface of other systems, direct call on the line, nothing, in fact, in fact, the following are some of the experiences I have summed up, or very useful.
1. for other system call interface will produce data transactions, must write Log, the future data error, it is necessary to find the source of the problem, especially the other system interface does not write log, once the data, often do not know where to look, there is a problem we give the data, or the other system to deal with problem we give data? In a recent project, because we have the data logic is very complex, and the other interface receives data we generated, will do a very complex data exchange system in action, the beginning of the line, there are a lot of sense of its second data, and we are in to call each other by writing log data interface when, soon found out some problems we have generated data, some other problems of data processing.
2. do not use other programs in various places directly system interface, it is best to write a class to encapsulate other system interface, if other system interface, can be dedicated to build a project management, such as interface changes (such as the interface, interface type), only need to replace the project DLL can, and other parts of the program can not change, not in all parts of the program directly call other system interface.
Interface development is to make the function of the system more perfect, and also a necessary way for a system to expand continuously. In addition to calling the original interface of the system, the designer also learns to design and develop interfaces to serve the system.

2017年12月6日 星期三

向硬件設備看齊 機房建置競也玩兒起了模塊化

現在國家頒佈了多項關於機房建置過程當中的指標、技術應用等相關要求和文件,對數據中心在建設過程當中的一系列細節進行了政策導向和規範,對此,微模塊數據中心進入了一個快速增長的階段。
 機房建置
隨着能源成本的不斷升高,很多企業一方面要保證數據中心的使用率維持穩定,另一方面要嚴格控制能耗成本。
這在很大程度上加重企業運營的負擔。
微模塊數據中心在土建成本方面優於傳統的機房建設,採取工廠預裝形式,減少設計、工廠管理和總包等費用,比傳統節省30%左右成本。
正如我們前文提到的那樣,微模塊數據中心能夠進行快速擴展,並允許在遠程辦公地點、臨時工作安裝部署。
在安裝部署時,只需要提供電力保障、供水以及網絡連接,就完全可以建立一個功能完整的數據中心。
因此,行業用戶方面,包括:互聯網公司、電信運營商以及大型企業在內的許多行業客戶,開始嘗試性地部署微模塊數據中心解決方案。
微模塊數據中心特徵
爲了應對現在企業對於雲計算、虛擬化、高密度等需求,提升數據中心的運營效率,微模塊數據中心利用多個具有獨立功能、統一的輸入輸出接口的微模塊、不同區域的微模塊可以互相備份,通過相關微模塊排列組合形成一個完整的數據中心。
微模塊數據中心是一個整合的、標準的、最優的、智能的、具備很高適應性的基礎設施環境和高可用計算環境。
模塊化數據中心的組成
數據中心由預製化微模塊,比如像機櫃系統、製冷系統、走線系統、監控系統等,這些部件與傳統“現場施工”系統混合部署組成的微模塊數據中心被稱爲“部分預製化數據中心”。
供電系統、機機櫃系統、製冷系統、走線系統、監控系統等爲單個獨立封閉空間。
模塊被分成幾部分送達現場,並重新拼接。
需要外部配套基礎設施的支持,比如發電機或冷水機組、高低壓配電。
對於傳統的數據中心來說,其在建設週期方面時間比較久,往往都是以年來計算,根據項目建設的實際情況,通常將數據中心的基本建設週期細分爲決策階段、實施準備階段、實施階段和投產竣工階段,整個建設週期大概在400天左右。
巨大的電力損耗數據中心的運行需要大量的電力,傳統建設沒有很好地考慮用電、製冷、氣流管理的問題,很多數據中心的PUE(Power Usage Effectiveness,數據中心能源效率指標)偏高,採用常規意義下的可靠性較高的環境動力設備,但這些設備往往效率較低。
微模塊數據中心解決什麼問題
微模塊數據中心加快了數據中心整體的規劃與設計的速度,根據設計目標以合理的方式配置系統結構,包括:模塊單元的物理排列,僅選用滿足當前 IT 需求的設備數量與類型;
微模塊批量生產可以實現現貨供應,因而提高了交貨速度;
標準化的連接方式可減少現場配置與連接的工作量,加快安裝速度;
微模塊可以採用與現場一模一樣的方式在工廠進行連接並預先測試,系統的調試速度也提高了。
採用微模塊的架構,數據中心可以逐步增加,因而可使從1個微模塊到幾十個微模塊根據需求分期建設。
大型數據中心的任何大小的 IT 空間的配置達到最佳狀態。

Design scheme of fire system in data center machine room

Data center fire system: in order to protect the expensive electronic equipment and data resources, the national standard specifies that the computer room with a certain scale must adopt alarm and gas fire extinguishing system. With the progress of the society and the increasing popularity of electronic equipment, various kinds of fire extinguishing agents have been launched. Because the environment of the machine room is good, there are not much special requirements for the alarm system, and all kinds of alarm systems are basically applicable. The computer is an important sector of each enterprises and institutions, and other related equipment because the equipment itself special requirements of fire, must be on these important equipment design of fire protection system, the Guan Jian relation is the normal operation of the equipment and protection equipment; room fire extinguishing system of prohibiting the use of water, foam and powder extinguishing agent, suitable for gas fire extinguishing system room fire; the system should be relatively independent of the system, but must be linked with the fire center. In order to ensure safety and correctly grasp the abnormal state of a large and medium-sized computer room, it is necessary to install an automatic fire extinguishing system when a fire is able to alarm and fire accurately and quickly.
 Fire system
The traditional water, foam, dry powder and smoke system are not suitable for fire extinguishing in the machine room. It should be a kind of gas extinguishing agent which can evaporate rapidly at normal temperature without leaving the evaporation residue, and it is non conductive and non corrosive. Gas fire extinguishing system is a gaseous compound with fire extinguishing capacity, which is stored at room temperature or at room temperature or high temperature or low temperature and low pressure container. When fire occurs, it will be put to the fire area by automatic or manual control device, so as to achieve the purpose of fire extinguishing. It has the advantages of clean, no stain and quick fire extinguishing. It is widely used in record room, electronic equipment room and expensive warehouse and so on. There are many kinds of gas fire extinguishing, but now widely used only halogenated alkane (1211, 1301), carbon dioxide, and imported FM200 and so on in recent years.
Design flow of gas fire extinguishing system:
(1) to determine the type of gas extinguishing agent in accordance with the relevant design specifications to determine the room for setting up the gas fire extinguishing system.
(2) divide the protection area and the protection space, select the system form, and confirm the location between the storage bottles.
(3) calculate the amount of fire extinguishing design in the protective area according to the relevant design specifications and determine the quantity of the extinguishing agent storage bottle.
(4) to determine the layout of the bottle group within the storage bottle and check whether the size of the storage bottle is suitable.
(5) calculation, protection zone fire extinguishing agent conveying the average flow of the main way, diameter and number of nozzles set the competent road.
(6) according to the actual situation, the protection zone spaced evenly arranged sprinklers and pipes to try to set up a balanced system, the initial pipe diameter.
(7) according to the pipe network calculation method in the design standard, check and correct the pipe layout and the pipe diameter of each section until the specification requirements are met, and determine the specifications of each sprinkler head.
(8) statistics system equipment materials according to the design scheme. The comprehensive evaluation of the design scheme and the optimization and adjustment when necessary.