Posted:
Editor's Note: We're pleased to welcome Chandar Pattabhiram, Vice President of Cast Iron Systems, as a guest blogger. Cast Iron is a market leader in SaaS and cloud integration with thousands of customer integrations connecting cloud and on-premise applications.

Cast Iron recently participated in our Campfire One event to announce Cast Iron for Google Apps, a ready-to-go solution for connecting hundreds of on-premise and SaaS apps to Google Apps in just days. Want to learn more? Register for Cast Iron's upcoming webinar on integrating Google Apps with other enterprise solutions.


Cloud computing is gaining momentum with organizations of all sizes. But many organizations work with a combination of cloud-based and on-premise applications. To leverage the many benefits of cloud computing, IT departments need to adapt to this hybrid world. That's where integration comes in. Whether building a recruiting app on Google App Engine or an enterprise gadget to create an analytics dashboard, IT has a fundamental need to exchange data with the rest of the enterprise.

Cast Iron focuses on solving this problem of connecting SaaS and Cloud to on-premise apps. For Google Apps users, we are excited to offer Cast Iron for Google Apps, which provides out-of-the-box integration with Google Secure Data Connector (SDC) and pre-configured connectivity to hundreds of applications to simplify Google integration projects.

SDC provides an encrypted connection between Google Apps and behind-the-firewall data, and Cast Iron provides connectivity as well as data transformation and process workflow capability. The net result is that Cast Iron for Google Apps is a one-stop tool to connect Google Apps with the rest of the enterprise.

Cast Iron offers a number of deployment models that all provide the same user experience and functionality:
  • Cast Iron Cloud: a multi-tenant integration-as-a-service offering
  • Cast Iron Physical appliances: ready-to-go-appliances for on-premise integration
  • Cast Iron Virtual appliances: the same ready-to-go-functionality available through virtualization that can be deployed on your hardware in your data center
Join Cast Iron and Google for a joint webinar to learn more about Cast Iron for Google Apps and Google's recent developer announcements.

Connect Google Apps with Other Enterprise Apps Today

Tuesday, April 28, 2009
11:00 a.m. PDT (GMT -07:00)

You'll also hear from Doug Menefee, CIO of the Schumacher Group, who will explain how they used Google Apps, gadgets, and Cast Iron to create a portal for their 2,500 medical providers and doctors to access emergency room data in the browser anywhere, anytime.

Want to see the latest from the app developer community? Don't forget to check out the I/O Developer Conference on May 27 & 28, 2009 in San Francisco, California. Learn more.

Posted:
A few weeks ago we held our first Google Apps Education Customer Summit here at the Googleplex (our Mountain View main campus), where we hosted 58 of the newest members in our Education Edition family. These customers represented 27 universities, community colleges, and K-12 schools from across the U.S. who recently moved over to Google Apps Education Edition. This Education Customer Summit provided these schools an opportunity to network with each other, hear from product specialists, and meet other customers who have been using Google Apps since the early days.

We kept the participants busy all day with many lively sessions kicking off with a customer panel that included Columbus State University, Boise State University, and San Mateo Community College District providing insights into Google Apps successes on their respective campuses.

Next, product managers and engineers led a discussion about products and features, answering a range of audience questions. This let everyone learn about some new features in detail, including improved contact sharing, the updated start page in Sites, and the new reporting in the control panel.


We hope this day was as fun and valuable for the customers as it was for us, and enabled the school representatives to go back to campus with new contacts and ideas about how to make the most of Google Apps for their students, staff, and faculty. Check out the pictures below, and maybe we'll see you at the next Summit.



Jeff Keltner, Google business development manager, kicks things off and welcomes new members of the Apps Education Edition family.



Jeff and Tudd Sutton (University of North Carolina at Greensboro) field audience questions during the customer panel.



It was a busy day for the 58 participants, but we made sure to give a refreshment break or two...



Product engineers discussed Google Apps in depth and shared insight about what's in the works.


Posted by Lauren Miskelly, Enterprise Sales Representative




Posted:
The Google I/O Developer Conference is coming up on May 27 – 28, 2009 in San Francisco, California, and we want to see you there. Google I/O is a two-day developer gathering where you can speak directly with Google's engineering and web development teams, and learn about the products, tools and techniques which are moving the web forward as a platform.


Visit the Google I/O website to learn more (search for "enterprise" to find relevant sessions) and to register, and be sure to make use of the "early bird" discount, available to all who register before May 2.

We hope to see you there.

Posted:
Every once in a while, we invite members of the developer community to visit Mountain View campus to talk shop, share news, and eat Google'sS'mores. We call these events "Google Campfire One," and we held a lively one tonight.

At tonight's Campfire One we announced some developer tools that we think will be pretty interesting to businesses: a new release of Google App Engine and the Google Secure Data Connector (SDC). Enterprise developers and IT professionals have been asking for tools like these to add custom applications to Google Apps and to connect Google Apps with their existing IT systems.

App Engine already lets Google Apps customers build apps just for their users. The new features make it even easier to build and deploy business apps that integrate with Google Apps, and SDC gives enterprises a way to help connect their firewalled data to their Google Apps domain. Ten other companies, including Oracle™ and IBM™, participated in tonight's Campfire One to announce new apps and services incorporating these tools.

Cron, JavaTM, and GWT for App Engine

Based on developer feedback, we've added several features to App Engine, including the ability to schedule tasks to run automatically (cron) and new database import/export tools to simplify moving gigabytes of data into/out of App Engine.

We also announced an early look at App Engine's support for the Java language. We made this standards-based so Java developers can build apps with familiar APIs and move them to other application servers if the need arises. In fact, tonight's Campfire showcased IBM's demo of moving an app to IBM Websphere with just a few code changes (we're giving 10,000 interested developers an early look at our Java language support, so test it out and send feedback).

We've also integrated App Engine with the Google Web Toolkit (GWT) and the Eclipse IDE so developers will be able write their apps from end-to-end in the Java language in a single IDE. During the Campfire, Appirio™, a Google Apps solution provider, showed how App Engine plus GWT and the Google Visualization API let them quickly write and deploy a complete recruiting management app without setting up servers or dealing with cross-browser compatibility.

Encrypted connection to firewalled data

We also talked about giving developers who work on cloud-based business apps access to behind-the-firewall data – previously a difficult issue to tackle. To help solve this problem, we built the Google Secure Data Connector (SDC), a downloadable agent which lets IT admins connect Google Apps to resources behind the firewall.

Today, you can use SDC with gadgets in Google Sites, App Engine applications, and spreadsheets in Google Docs. As part of tonight's event, Oracle showed how Oracle CRM gadgets will let their customers interact with sales and customer information from within Google Apps.

Several other companies announced support for SDC in their products tonight. Cast Iron Systems has added built-in support for SDC to their integration appliance, allowing Google Apps to integrate with hundreds of different systems through a point-and-click interface. Panorama Software has added support for SDC to their gadgets, allowing you to visualize and analyze business data right in the browser. ThoughtWorks™, Cloud Sherpas™, Sword Group™, Ping Identity™, and PivotLink™ also participated in this Campfire One event. You can learn more about their announcements on our Campfire One participants page.

You can visit Google Code to learn more about our developer tools, and if you're a developer, be sure to come to Google I/O in San Francisco, California, on May 27-28th.

By the way, we shared the highlights of tonight's Campfire real-time on Twitter. Visit us there at http://twitter.com/googleatwork to see the current stream.


Brandon Nutter, Engineering Manager

Java is a trademark or registered trademark of Sun Microsystems, Inc. in the United States and other countries.

All other company and product names may be trademarks of the companies with which they are associated.

Posted:
It's important for business users to have fast, easy access to their email and calendars when they're on the go – even when cell phone reception is limited. That's why we're happy to tell you about new speed and functionality improvements for Gmail and for Google Calendar for the iPhone and for Android-powered devices. Click through the links to read descriptions on the Google Mobile Blog, and to watch a video overviewing the new features.

To access these mobile apps, browse to http://www.google.com/m/a/example.com
on your iPhone or Android-powered device (you'll need to replace "example.com" with your organization's domain name.) Continue by clicking the link for either Gmail or Calendar.

by Debbie Leight, Google Apps team

Posted:
Editor's Note: There's never dull moment in the world of online security. Threat patterns evolve in volume, sophistication, and the types of exploits and sources. News about the recent Conficker virus got us talking with Scott Petry, founder of Postini (original developers of Google's suite of security and archiving services), and Wolfgang Kadek, CTO of Qualys. Their comments follow. To learn more about trends in spam, hacking, and ways of keeping email networks safe, join Google and Qualys in an on-line conversation, "In Cloud We Trust," on April 16, where we'll discuss these topics live.

Q: Ten years ago, packaged software was the norm. Yet Postini built a hosted service - what we today call cloud computing. Why did you drive a cloud architecture for Postini?

Scott: We believed that by offering a service infrastructure we could prove a lower TCO than an on-premise alternative. With that service infrastructure aggregating data, we'd also have insight into a wider sample of data, thus providing a more effective solution.

Q: How did the idea of having a "perimeter protection service" to protect email networks in the cloud first evolve? Is the right model for the future?

Scott: Postini's innovation was to see SMTP as an integration API and DNS as a way to access traffic, thus putting us "upstream" of the customers' infrastructure, alleviating integration challenges and stopping problems before they reached the firewall. We saw this as better for a number of reasons.

Email servers have a long shelf life, and customers typically add incrementally to their system, rather than get a complete replacement. This causes a management problem for IT, creating a heterogeneous environment into which they must layer in security and compliance services.

We never saw ourselves as just an anti-spam company, so we built infrastructure that allowed a business rule to be configured as tightly as a content string for a single user. This design decision is inherently linked to the cloud. It allows us to deliver a better anti-spam solution, and also expand into content compliance areas.


Q. Wolfgang, you've been keeping a tight watch on the latest vulnerabilities impacting networks worldwide via your Laws of Vulnerabilities research. What are some of the trends you're seeing in 2009?

Wolfgang: Our research into vulnerability trends has shown that the industry overall did not improve significantly its ability to address security problems in a timely manner At the same time attackers have been getting faster and more sophisticated. Proactive security by maintaining systems updated with the latest patches is the cheapest of all security tools, nevertheless it has not grown in the way I would have hoped.

The first three months of 2009 have been a great example. We've seen Conficker infect millions of machines. The simplest way of preventing the outbreak would have been to
preventively apply a patch, if available, to stop the worm. But figuring out such patches takes time. In contrast to worms of the past which often gave us months to react, Conficker activated only two weeks after the official release of the patch, clearly showing that attackers have become faster in their timing. It's getting tougher for patches to keep up.

Q: As network security budgets continue to tighten, how can "security as a service" be advantageous to users?

Wolfgang: SaaS solutions have the advantage that they have minimal setup and are immediately usable. Companies can get their feet wet with a small pilot, show success, and then grow it at their own pace to address larger needs. Organizations of any size can take advantage of the functionality and the predictable steady cost of cloud solutions, while at the same time enjoying the usability brought through constant improvements.

Scott: Agreed. As IT faces more pressure from a changing threat landscape and increased compliance mandates, the cloud model gives maximum leverage to IT – always important, but especially in this economic climate.

Register here for "In Cloud we Trust"

Thursday, April 16, 2009 1:00 p.m. EST / 10:00 a.m. PST


Posted:
Today we're excited to announce a little something to bring some flair to people's Gmail accounts for all editions of Google Apps.

Google Apps now offers more than 30 Gmail account theme choices ranging from weather themes that are customized for your location, to nature themes that change with your timezone, to themes that are just plain fun and funky.


Themes in Gmail give you a chance to customize your inbox, and your theme settings travel with you wherever you log in to your account, just like all the information in your inbox. You can customize your inbox by clicking 'Themes' in the 'Settings' menu once your account administrator enables the 'Turn on new features' checkbox in the Google Apps control panel.

Please note that not all Gmail accounts will have these immediately – we're rolling out Themes right now, and all domains with new features enabled by their admins will see 'Themes' in 'Settings' in the next few days.

Explore the Themes possibilities – they might make opening your inbox a little more fun.

Posted by
Monali Narayanaswami, Google Apps Team

Posted:
Editor's Note: The spam data cited in this post is drawn from the Google enterprise security and archiving security network (Postini), which delivers an added layer of security for standalone mail servers and Google Apps Premier Edition customers. For a discussion of the anti-spam measures included in Gmail, please see this post from the Gmail blog.

In providing email security to more than 50,000 businesses and 15 million business users, Google security and archiving services, powered by Postini, process and cull spam from more than three billion enterprise email connections every day. This gives us strong insights into the state of the spam industry, some of which we share in regular posts to this blog.

R
ead on for a quick overview of spam trends and events in the first quarter of 2009.

What we saw in the Postini data centers

The most significant spam-related event in the first quarter of 2009 occurred when spam volume returned to pre-McColo takedown levels. By the second half of March, seven-day average spam volume was at the same volume we saw prior to the blocking of the McColo ISP in November 2008.


Spammers have clearly rallied following the McColo takedown, and overall spam volume growth during Q1 2009 was the strongest it's been since early 2008, increasing an average of 1.2% per day. To put that number into context, the growth rate of spam volume in Q1 2008 was approximately 1% per day – which, at the time, was a record high.

Of course, like every year before it, 2008 set a new record for overall spam volume. But in 2008 spam growth flattened over the summer and early fall, and then fell off a cliff after the McColo takedown (daily growth declined to .8%, .3%, and then .01% in the last three quarters of the year). This pattern raises some interesting questions regarding what we can expect in the rest of 2009: Will spam growth once again flatten or decline after a strong first quarter? Or have spammers – as part of their recovery from the McColo takedownrebuilt botnets to be capable of sustaining or even accelerating this early growth spurt?

It's difficult to ascertain exactly how spammers have rebuilt in the wake of McColo, but data suggests they're adopting new strategies to avoid a McColo-type takedown from occurring again. Specifically, the recent upward trajectory of spam could indicate that spammers are building botnets that are more robust but send less volumeor at least that they haven't enabled their botnets to run at full capacity because they're wary of exposing a new ISP as a target.

New types of spam

The most significant development in spam vectors this quarter was the appearance of location-based spam. In this type of attack, users click on a link in a spam message and are directed to a page that contains a fraudulent news headline describing a crisis or disaster in a major city nearby. The attack customizes the location for each user by determining the geolocation of the user's source IP and then identifying the nearest major city. The addition of location creates a heightened level of interest, and the user is tempted to click on the embedded video – which in turn downloads a virus to his or her machine.

Meanwhile, the economy, financial markets, job cuts, and resume help continue to be the most prominent topics spammers are employing as lures for more traditional attacks. We also saw increased spam activity around the U.S. presidential inauguration and St. Patrick's Day, in keeping with the recent propensity spammers have demonstrated for reading the news and keeping their eyes on the holiday calendar in targeting their attacks.

Virus roundup

In early 2008, a trend emerged in which we saw spam messages with attached viruses (otherwise known as "payload viruses") spiking every Sunday, possibly targeting a maintenance window to catch corporate defenses when they were undergoing scheduled updates.


This year we've seen the payload viruses spread out across every day of the week, with no immediately obvious pattern in their distribution. It's difficult to say for certain what prompted the change, but one possible explanation is that spammers switched tactics because they weren't seeing the success they'd hoped for from the focused attacks.


Of course, p
ayload viruses have also seen a recent spike overall -- in the month of March we saw a 9x increase from February. This pales in comparison to the highs we saw last summer, but it may indicate a developing trend that's worth keeping a close eye on.

Viruses delivered as a blended threat (when a spam message directs a user to a malicious website, which then results in a virus being downloaded to the user's computer) continue to be popular with spammers. E-cards are one of the best examples of this vector, and Valentine's Day saw a flurry of activity using e-cards to direct users to malicious websites.

Conclusions

Spammers continue to prove their resilience -- whether it's bouncing back from the biggest takedown on record or finding new ways to exploit the ways we communicate for malicious purposes, they're clearly here to stay. And Google believes firmly in the power of the cloud to protect your enterprise from them: Outsourcing message security to Google enables you to leverage our technical expertise and massive infrastructure to keep spammers from your door. See how much spam is costing your business, learn how much you could be saving with Google Message Security, or contact us for more information.

Posted by Amanda Kleha, Google security and archiving team

Posted:
Sometimes a drawing is worth 1000 words – at the office or elsewhere. To broaden the ways you can work within Google Apps, we're releasing Drawings, a new feature in Google Docs. As of today, you can create and insert rich drawings into documents, presentations and spreadsheets to illustrate your ideas. You can now find 'Drawings' in the 'Insert' menu.


Read more about the ways you can use Drawings and the technology behind the feature on the Google Docs blog.


Posted by: Tony Glenning, Drawings Team Lead

Posted:
Google Site Search has now been included into an expanded version of the access provider program. The program was created last year for the web hosting community so they could easily integrate Google Webmaster tools into their customer's websites. Today we expanded the program to include three new services including AdSense, Custom Search, and Site Search under the program Google Services for Websites.

We are excited to have Google Site Search as part of the program because it provides us with better partner opportunities with the web hosting community. Webhosters who participate can enroll in the Google Affiliate program which allows them to get referral fees for every customer who creates Google Site Search.


All together, Hosting service providers can now make use of multiple Google APIs and add these services for their customers at no cost. These tools can help increase the value of customer websites by:
  • Driving traffic and visibility to their websites with Webmaster Tools
  • Enhancing their website and visitor satisfaction with customized search through Custom Search or Google Site Search
  • Monetizing their sites through the Google ad network using AdSense
The initial access provider program has already gotten off to a fantastic start, with partners including Go Daddy (who launched the first pilot back in 2007 with Webmaster Tools), IPOWER, StartLogic, PowWeb, FatCow, BizLand, and EasyCGI. Many of these partners have already integrated multiple Google services into their customer console.

If you are an existing access provider (via the Webmaster Tools Access Provider program), you will be automatically enrolled in the new program, but will still need to integrate the new services into your control panel (with their APIs). Certain services may need additional approvals. Any hosters interested in learning more can check out the Google Services for Websites Access Provider site and sign up today.

Webmasters:
let us know what you think! And if these tools aren't yet available through your hosting company, send them a link to this post and let them know we're here to help.

Posted by Nitin Mangtani and Dave Kim, Google Enteprise Search team