Skip to main content

2020 | OriginalPaper | Buchkapitel

WS-SM: Web Services - Secured Messaging Framework with Pluggable APIs

verfasst von : Kanchana Rajaram, Chitra Babu

Erschienen in: Computational Intelligence in Data Science

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Dynamic composition of web services is important in B2B applications where user requirements and business policies change and new services get added to the service registry frequently. In a dynamic composition environment, ensuring the security of messages communicated among the web services becomes challenging since, several attacks are possible on SOAP messages in the public network due to their standardized interfaces. Most of the existing works on web services security provide solutions to ensure basic security features such as confidentiality, integrity, authentication, authorization, and non-repudiation. Few existing works that provide solutions such as schema validation and schema hardening for attacks on web services do not provide attack-specific solutions. The web services security standard and all the existing works have addressed only the security of messages between a client and a single web service but not the security for messages between two services which is quite challenging. Hence, a security framework for secured messaging among web services has been proposed to provide attack-specific solutions. Since new types of web service attacks are evolving over time, the proposed security solutions are implemented as APIs that are pluggable in any server where the web service is deployed. The proposed framework has been tested for compliance with WSI-BP to demonstrate its interoperability and subjected to vulnerability testing which proved its immunity to attacks. The stress testing results revealed that the throughput decreased only by 35% achieving a good trade-off between performance and security.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Erl, T.: Service-Oriented Architecture concept, Technology, and Design. Pearson Education, London (2006) Erl, T.: Service-Oriented Architecture concept, Technology, and Design. Pearson Education, London (2006)
2.
Zurück zum Zitat Schmelzer, R., Vandersypen, T.: XML and Web Services Unleashed. Sams Publication, Chennai (2002) Schmelzer, R., Vandersypen, T.: XML and Web Services Unleashed. Sams Publication, Chennai (2002)
3.
Zurück zum Zitat Cerami, E.: Web Services Essentials: Distributed Applications with XML-RPC, SOAP, UDDI & WSDL. O’Reilly Media, Inc., Sebastopol (2002) Cerami, E.: Web Services Essentials: Distributed Applications with XML-RPC, SOAP, UDDI & WSDL. O’Reilly Media, Inc., Sebastopol (2002)
4.
Zurück zum Zitat Singhal, A., Winograd, T., Scarfone, K.: Guide to secure web services. Technical report of National Institute of Standards and Technology, Special Publication 800-95 (2007) Singhal, A., Winograd, T., Scarfone, K.: Guide to secure web services. Technical report of National Institute of Standards and Technology, Special Publication 800-95 (2007)
5.
Zurück zum Zitat Lemos, A.L., Daniel, F., Benatallah, B.: Web service composition: a survey of techniques and tools. ACM Comput. Surv. (CSUR) 48(3), 1–41 (2016). Article No. 33 Lemos, A.L., Daniel, F., Benatallah, B.: Web service composition: a survey of techniques and tools. ACM Comput. Surv. (CSUR) 48(3), 1–41 (2016). Article No. 33
6.
Zurück zum Zitat Mouli, V.R., Jevitha, K.P.: Web services attacks and security - a systematic literature review. Procedia Comput. Sci. 93, 870–877 (2016) Mouli, V.R., Jevitha, K.P.: Web services attacks and security - a systematic literature review. Procedia Comput. Sci. 93, 870–877 (2016)
7.
Zurück zum Zitat Masood, A., Java, J.: Static analysis for web service security - tools & techniques for a secure development life cycle. In: IEEE International Symposium on Technologies for Homeland Security (HST), pp. 1–6 (2015) Masood, A., Java, J.: Static analysis for web service security - tools & techniques for a secure development life cycle. In: IEEE International Symposium on Technologies for Homeland Security (HST), pp. 1–6 (2015)
9.
10.
Zurück zum Zitat Alotaibi, S.J.: Toward a secure web service by using WS-security specifications. J. Comput. Theoret. Nanosci. 14(8), 3837–3842 (2017) Alotaibi, S.J.: Toward a secure web service by using WS-security specifications. J. Comput. Theoret. Nanosci. 14(8), 3837–3842 (2017)
11.
Zurück zum Zitat Thelin, J., Murray, P.J.: A public web services security framework based on current and future usage scenarios. In: International Conference on Internet Computing, pp. 825–833 (2002) Thelin, J., Murray, P.J.: A public web services security framework based on current and future usage scenarios. In: International Conference on Internet Computing, pp. 825–833 (2002)
12.
Zurück zum Zitat Yue, H., Tao, X.: Web services security problem in service-oriented architecture. In: International Conference on Applied Physics and Industrial Engineering, vol. 24, no. 9, pp. 1635–1641 (2001) Yue, H., Tao, X.: Web services security problem in service-oriented architecture. In: International Conference on Applied Physics and Industrial Engineering, vol. 24, no. 9, pp. 1635–1641 (2001)
13.
Zurück zum Zitat Kumar, R.K., Kanchana, R., Babu, C.: Security for SOAP based communication among web service. In: IJCA Proceedings on International Conference on Science. Engineering and Management (ICSEM 2013), pp. 46–51. Foundation of Computer Science, USA (2013) Kumar, R.K., Kanchana, R., Babu, C.: Security for SOAP based communication among web service. In: IJCA Proceedings on International Conference on Science. Engineering and Management (ICSEM 2013), pp. 46–51. Foundation of Computer Science, USA (2013)
14.
Zurück zum Zitat Altaani, N.A., Jaradat, A.S.: Security analysis and testing in service oriented architecture. Int. J. Sci. Eng. Res. 3(2), 1–9 (1981) Altaani, N.A., Jaradat, A.S.: Security analysis and testing in service oriented architecture. Int. J. Sci. Eng. Res. 3(2), 1–9 (1981)
15.
Zurück zum Zitat Mainka, C., Somorovsky, J., Schwenk, J.: Penetration testing tool for web service security. In: IEEE 8th World Congress on Services, pp. 163–170 (2012) Mainka, C., Somorovsky, J., Schwenk, J.: Penetration testing tool for web service security. In: IEEE 8th World Congress on Services, pp. 163–170 (2012)
16.
Zurück zum Zitat Salas, M.I.P., Martins, E.: Security testing methodology for vulnerabilities detection of XSS in web services and WS-security. Electron. Notes Theoret. Comput. Sci. 302, 133–154 (2014)CrossRef Salas, M.I.P., Martins, E.: Security testing methodology for vulnerabilities detection of XSS in web services and WS-security. Electron. Notes Theoret. Comput. Sci. 302, 133–154 (2014)CrossRef
17.
Zurück zum Zitat Lowis, L., Accorsi, R.: Vulnerability analysis in SOA-based business processes. IEEE Trans. Serv. Comput. 4(3), 230–242 (2011)CrossRef Lowis, L., Accorsi, R.: Vulnerability analysis in SOA-based business processes. IEEE Trans. Serv. Comput. 4(3), 230–242 (2011)CrossRef
Metadaten
Titel
WS-SM: Web Services - Secured Messaging Framework with Pluggable APIs
verfasst von
Kanchana Rajaram
Chitra Babu
Copyright-Jahr
2020
DOI
https://doi.org/10.1007/978-3-030-63467-4_19

Premium Partner