The Way of the great learning involves manifesting virtue, renovating the people, and abiding by the highest good.

2009年4月10日星期五

Ubuntu Server To Offer Amazon-Compatible Cloud Capabilities

The next iteration of Ubuntu Linux will really help companies lift up into the clouds.

The April 30 release of Ubuntu Server will have the ability to migrate KVM-based virtual machines from one physical server to another, similar to VMware's ability to use VMotion to migrate virtual machines, said Steve George, director of the enterprise group at Linux supplier Canonical.

KVM is the Kernel Virtual Machine, an open source hypervisor that was produced by Israeli company Qumranet. Red Hat (NYSE: RHT) purchased Qumranet last year. Qumranet developer Avi Kivity submitted KVM to the Linux kernel development process, and it was included in a refresh of the kernel in early 2007.

In addition, Canonical is adding clustering software that will manage a set of x86 Ubuntu servers as if they were a combined cloud resource. If a virtual workload is assigned to the cluster, Ubuntu's new "cloud controller" will determine which server to deploy it to, no further administrative action needed. In effect, it will balance the load, based on policy decisions that the cluster administrator has put into the controller, George said in an interview.

The cloud controller will be a "tech preview" feature that won't be considered stable and available for production use until Ubuntu Server 9.10 is released. According to the Ubuntu naming convention, which lists the year and month of the release, 9.10 will become available in October.

Ubuntu Server 9.04 will have an additional "cloud" feature as it comes out of the blocks at the end of April. It will be available to run in the Amazon (NSDQ: AMZN) Elastic Compute Cloud, George said.

Ubuntu developers began "cloud computing away about a year ago," said George, as members of the Ubuntu community talked about their experiences in using Amazon EC2. The development team wants Ubuntu Server users to be able to put Ubuntu on a set of x86 servers and then build inside the company an Amazon-compatible cloud.

"You will be able to start investigating cloud capabilities," said George. Ubuntu will incorporate the open source Eucalyptus Project APIs, which seek to mimic Amazon's proprietary APIs in open source code. "The Amazon APIs are well understood, and the Eucalyptus Project has a great team doing work in this area," he added.

Canonical isn't committed to incorporating every Eucalyptus API into Ubuntu Server, but it expects to include enough of them to give its users a chance to build an Amazon cloud lookalike and gain experience from it. Although the notion remains unproven, it's hoping to expand its use among cloud enthusiasts who would see such an internal cloud as having the ability to export to or federate with Amazon's EC2.

Updates to Ubuntu Desktop 9.04 and Ubuntu Netbook Remix 9.04 also will be available April 30, as well as Ubuntu Server for free download.

  

2009年4月8日星期三

A Computational Framework for Ultrastructural Mapping of Neural Circuitry

James R. Anderson1, Bryan W. Jones1, Jia-Hui Yang1, Marguerite V. Shaw1, Carl B. Watt1, Pavel Koshevoy2,3, Joel Spaltenstein3, Elizabeth Jurrus3, Kannan UV3, Ross T. Whitaker3, David Mastronarde4, Tolga Tasdizen3,5, Robert E. Marc1*

1 Department Ophthalmology, Moran Eye Center, University of Utah, Salt Lake City, Utah, United States of America, 2 Sorenson Media, Salt Lake City, Utah, United States of America, 3 Scientific Computing and Imaging Institute, University of Utah, Salt Lake City, Utah, United States of America, 4 The Boulder Laboratory For 3-D Electron Microscopy of Cells, University of Colorado, Boulder, Colorado, United States of America, 5 Department Electrical and Computer Engineering, University of Utah, Salt Lake City, Utah, United States of America

Circuitry mapping of metazoan neural systems is difficult because canonical neural regions (regions containing one or more copies of all components) are large, regional borders are uncertain, neuronal diversity is high, and potential network topologies so numerous that only anatomical ground truth can resolve them. Complete mapping of a specific network requires synaptic resolution, canonical region coverage, and robust neuronal classification. Though transmission electron microscopy (TEM) remains the optimal tool for network mapping, the process of building large serial section TEM (ssTEM) image volumes is rendered difficult by the need to precisely mosaic distorted image tiles and register distorted mosaics. Moreover, most molecular neuronal class markers are poorly compatible with optimal TEM imaging. Our objective was to build a complete framework for ultrastructural circuitry mapping. This framework combines strong TEM-compliant small molecule profiling with automated image tile mosaicking, automated slice-to-slice image registration, and gigabyte-scale image browsing for volume annotation. Specifically we show how ultrathin molecular profiling datasets and their resultant classification maps can be embedded into ssTEM datasets and how scripted acquisition tools (SerialEM), mosaicking and registration (ir-tools), and large slice viewers (MosaicBuilder, Viking) can be used to manage terabyte-scale volumes. These methods enable large-scale connectivity analyses of new and legacy data. In well-posed tasks (e.g., complete network mapping in retina), terabyte-scale image volumes that previously would require decades of assembly can now be completed in months. Perhaps more importantly, the fusion of molecular profiling, image acquisition by SerialEM, ir-tools volume assembly, and data viewers/annotators also allow ssTEM to be used as a prospective tool for discovery in nonneural systems and a practical screening methodology for neurogenetics. Finally, this framework provides a mechanism for parallelization of ssTEM imaging, volume assembly, and data analysis across an international user base, enhancing the productivity of a large cohort of electron microscopists.

Funding. National Eye Institute R01 EY02576, R01 EY015128, P01 EY014800 (REM); support from the Cal and JeNeal Hatch Presidential Endowed Chair (REM); an unrestricted grant from Research to Prevent Blindness to the Moran Eye Center; a Research to Prevent Blindness Career Development Award (BWJ); National Institute of Biomedical Imaging and Bioengineering EB005832 (TT). TT would like to acknowledge the support of the Utah Science Technology and Research Initiative (USTAR). DM's work was supported by grant number P41RR00592 to A.H. Hoenger from the National Center for Research Resources (NCRR), a component of the National Institutes of Health (NIH). This paper's contents are solely the responsibility of the authors and do not necessarily represent the official view of NCRR or NIH. The funders had no role in study design, data collection and analysis, decision to publish, or preparation of the manuscript.

Competing interests. Robert E. Marc is a principal of Signature Immunologics. All other authors declare no other competing interests.

Academic Editor: Kristen M. Harris, University of Texas, United States of America

Citation: Anderson JR, Jones BW, Yang JH, Shaw MV, Watt CB, et al. (2009) A Computational Framework for Ultrastructural Mapping of Neural Circuitry. PLoS Biol 7(3): e1000074 doi:10.1371/journal.pbio.1000074

Received: August 21, 2008; Accepted: February 17, 2009; Published: March 31, 2009

Copyright: © 2009 Anderson et al. This is an open-access article distributed under the terms of the Creative Commons Attribution License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited.

Abbreviations: AC, amacrine cell; AGB, 1-amino-4-guanidobutane; BC, bipolar cell; CMP, computational molecular phenotyping; CN, complete network; GC, ganglion cell; IgG, immunoglobulin; LM, light microscopy; rgb, red, green, blue image mapping; ssLM, serial section light microscopy; ssTEM, serial section transmission electron microscopy; TEM, transmission electron microscopy

Deep packet inspection

Deep Packet Inspection (DPI) (also called complete packet inspection and Information eXtraction - IX -) is a form of computer network packet filtering that examines the data and/or header part of a packet as it passes an inspection point, searching for protocol non-compliance, viruses, spam, intrusions or predefined criteria to decide if the packet can pass or if it needs to be routed to a different destination, or for the purpose of collecting statistical information. This is in contrast to shallow packet inspection (usually called Stateful Packet Inspection) which just checks the header portion of a packet.[1]

Deep Packet Inspection (and filtering) enables advanced security functions as well as internet data mining, eavesdropping, and censorship. Advocates of net neutrality fear that DPI technology will be used to reduce the openness of the Internet. DPI is currently being used by the enterprise, service providers and governments in a wide range of applications.


Communications networks have been the key to the social cohesion, political unity and economic development of Canada as a nation. Both burdened and blessed by our vast territory, generations of Canadians have trusted that their personal messages would be quickly and confidentially carried by the technology of the day — horse, telegraph, trans-Atlantic cable, microwave and satellite – to  their destination.

These networks have been subject to oversight by state and public bodies for many years. As a result, network providers have been subject to legislation, regulations and guidelines addressing factors including regional service levels, the production of domestic content, competitive positioning within the domestic marketplace, and the protection of personal information. Similar expectations, and regimes, exist elsewhere around the world.

In 2007 and 2008, telecommunications pioneers, consumer activists and privacy advocates in the United Kingdom and the United States were disturbed to discover that a few telecommunications providers were participating in experiments to test the use of a network management tool in targeting marketing campaigns and advertisements at specific individuals.

This tool, deep packet inspection (DPI), allows network providers to peer into the digital packets that compose a message or transmission over a network. DPI has been used for several years to maintain the integrity and security of networks, searching for signs of protocol non-compliance, viruses, malicious code, SPAM and other threats.

DPI technology raises privacy concerns because it can involve the inspection of information sent from one end user to another. In other words, DPI technology has the capability to look into the content of messages sent over the Internet – enabling third parties to draw inferences about users’ personal lives, interests, purchasing habits and other activities.

The technology has the potential to give ISPs and other organizations widespread access to vast amounts of personal information sent over the Internet for:

  • Targeted advertising based on users’ behaviour while browsing the Internet:
  • Scanning network traffic for undesirable or unlawful content, such as unlicensed distribution of copyright material or dissemination of hateful or obscene materials;
  • Capturing and recording packets as part of surveillance for national security and other crime investigation purposes; and
  • Monitoring traffic to measure network performance, and plan for future facilities investments.

In light of privacy concerns prompted by this application of DPI, the Office of the Privacy Commissioner (OPC) wanted to create an opportunity for active public discussion of the issue – not only with respect to the impact of DPI technology on personal privacy, but about the broader importance of protecting personal information on the Internet. This project was the result.

In the summer and fall of 2008, the Research, Education and Outreach Branch of the OPC contacted leading academics and professionals working in telecommunications, law, privacy, philosophy, civil liberties and computer science to ask if they would provide a short essay on their views about privacy and DPI. The essays offer a variety of perspectives and divergent opinions.

At nearly the same time, an opportunity arose for the OPC to contribute to a public discussion of the traffic management practices of Canadian internet service providers. The Canadian Radio-television and Telecommunications Commission (CRTC) called for written submissions to be received by February 2009. Public consultations are planned for July 2009.

The OPC welcomed the opportunity to contribute comments focused on the privacy implications of the potential uses of DPI. The submission was a logical extension of the OPC’s legislative mandate to protect the privacy rights of individuals, foster public understanding of privacy, and promote the privacy protections available to Canadians. It is for this reason that we include it in this project.

Our submission made the case of privacy. We identified why privacy is important and how legal and public policy has historically recognized the rights of Canadians to the integrity of their physical person, their property, and their personal information – which includes their communications.

We did this to underscore two points. First, we wanted to show that privacy isn’t a “new “or novel idea to which the state, industry and policymakers have only just recently turned their minds.

Second, our submission emphasizes that protection of personal information and privacy online is necessary in the face of market forces, rapid technological developments, the threat of ID theft, fraud, other criminal activity, and pressure from law enforcement investigations.

The prospective uses of DPI have significant privacy implications for Canadians, who spend a considerable amount of their lives online as consumers, professionals, and citizens.

We hope that this collection of essays will help Canadians understanding how their privacy interests might be affected by DPI technology, and encourage policy makers to ensure that before DPI technology – or any other technology – is employed, careful consideration should be given to what impact it may have on individual privacy.

The OPC would like to thank the authors for their contribution to this project and to the greater understanding of the impact technology can have on privacy.

2009年4月3日星期五

Virtual Network Computing

In computing, Virtual Network Computing (VNC) is a graphical desktop sharing system that uses the RFB protocol to remotely control another computer. It transmits the keyboard and mouse events from one computer to another, relaying the graphical screen updates back in the other direction, over a network.

VNC is platform-independent – a VNC viewer on one operating system may connect to a VNC server on the same or any other operating system. There are clients and servers for many GUI-based operating systems and for Java. Multiple clients may connect to a VNC server at the same time. Popular uses for this technology include remote technical support and accessing files on one's work computer from one's home computer, or vice versa.

VNC was originally developed at the Olivetti Research Laboratory in Cambridge, United Kingdom. The original VNC source code and many modern derivatives are open source under the GNU General Public License.

2009年4月2日星期四

Harvard P2P lawyer: file-swapping is fair use—no, really!

Is Harvard Law professor Charlie Nesson crazy? As Nesson himself admits, "this does seem to be a question on many people's minds."

In our recent conversation with Nesson, the professor said he hopes to turn the Joel Tenenbaum P2P file-swapping case into a wide-ranging discussion on copyright. But a set of newly published e-mails indicate that Nesson wants to go further than anyone—including the most prominent "free culture" academics—previously suspected. Not content to argue that massive statutory damages are unconstitutional in such cases, Nesson plans to press an audacious claim: noncommercial P2P file-swapping is "fair use" and thus totally legal.

This week, Professor Nesson published to his blog a batch of private e-mail correspondence about his strategy in the case. In the e-mails, he lays out his plan of attack. "Fair use" is not so much "defined" in US copyright law as it "bounded" by a set of four questions that can be applied to any particular use of copyrighted material to see if the use is allowed without permission. The questions ask whether the new use is "transformative," whether it uses a part of the original work or the whole thing, what the effect of the use is on the future market for the original, and what sort of work the original piece was (published or unpublished? factual biography or fictional novel?).

Using the test, even noncommercial file-sharing would seem to fail, since it is is no way transformative, copies the entire song in question, and seems to have at least some negative effects on the market for that song. But Professor Nesson believes that "fair use" as a concept goes beyond the Copyright Act. "Fair use is recognized as a common law, perhaps a constitutional concept, not defined by but merely recognized and continued by the statute (Sony, Harper); that the statutory four factors are illustrative and not exhaustive; that analysis must be case by case; and the question is a jury issue."

The strategy then is to seek a jury trial and convince the jurors that fair use goes far beyond the description in US law. Assuming the jury buys this argument, Nesson can then tap into a basic sense of fairness to claim that a federal trial with the potential of $150,000 in damages per song is unfair in a broad sense, especially when Joel was (allegedly) a noncommercial P2P user back in 2003, when rightsholders were still dragging their feet in "licensing commercial alternatives for kids to buy single songs in digital downloads."

In the attempt to codify this notion of "fairness" into a principle, Nesson comes up with this: "Seems to me to be an understandable principle that it's okay to consume and share nonrivalrous good which are available on the net for free."

Experts puzzled

Unfortunately, no one else appears to be buying it, not even the people Nesson and his students hope to call as expert witnesses at trial.

Stanford professor Lawrence Lessig said that he was "surprised if the intent is to fight this case as if what joel did was not against the law. of course it was against the law, and you do the law too much kindness by trying to pretend (or stretch) 'fair use' excuses what he did. It doesn't."

Wendy Seltzer, who heads up the Chilling Effects website and served as an EFF staff attorney, was "puzzled" by the fair use argument. "I fear that we do damage to fair use by arguments that stretch it to include filesharing—weakening our claims to fair use even for un-permissioned transformations," she wrote. "I am much more comfortable disagreeing with the law than claiming at this point in time that it already excuses filesharing."

Terry Fisher, who heads Harvard's Berkman Center for Internet & Society, pointed out that P2P filesharing would likely fail the four factors test. "This is not to suggest, of course, that it's sensible for the legal system to be set up in such a way as to enable and encourage the RIAA to go after people like Joel," he added. "I devoted much of a book to arguing that it’s not—and I'm happy to testify to that effect. But the fair use doctrine does not, in my view, provide a plausible vehicle for reform."

The discomfort with strategy extends even to Nesson's own students, who are doing much of the research and writing. Ray Bilderback, who is writing the "disclosures" about expert witness testimony, wrote that "all of this looks very bad from my perspective. I think that introducing our experts at this late stage to the very novel argument that we intend to raise at trial—an argument which has no real basis in case law or moderate academic scholarship—is a blunder that could have very serious consequences. At this point, I have no idea what our disclosures will look like. And they have to be filed TOMORROW. Bad, bad, bad. We should have been working on this for weeks rather than days."

Given the general craziness of the case already, one is tempted to say this is simply par for the course. But posting internal strategy e-mails wasn't enough for Nesson, who also uploaded a lengthy audio clip of his wife, Fern, "twittering into my life." Fern's "twittering" takes the form of a (half-joking?) diatribe against Bilderback ("he annoys me so much," "the guy is such a schmuck," "he's my enemy already,") and a rant against those who disagree with Nesson's reading of the law ("then they're going to have to go back to the fucking cases and really consider it instead of spouting all this shit that they're teaching their students").

It's all rather... extraordinary, extraordinary enough that Nesson has now taken down the e-mails from others. The Internet never forgets, however; not that Nesson is any way bothered by posting such material. Throughout this case, he has attempted a radical openness that has (to date) irritated the judge, music industry lawyers, and even those lawyers who support his position. But for those who want to see what goes into a federal case and the strategy that a noted Harvard Law prof pursues as he preps for trial, Nesson may be the ideal litigator. "Billion Dollar Charlie" certainly doesn't hold back, even on potentially embarrassing material.