A Test-Based Security Certification Scheme for Web Services

被引:30
|
作者
Anisetti, Marco [1 ]
Ardagna, Claudio A. [1 ]
Damiani, Ernesto [1 ]
Saonara, Francesco [2 ]
机构
[1] Univ Milan, Dipartimento Informat, Crema, CR, Italy
[2] ROTOTYPE SpA, Milan, Italy
关键词
Security; Verification; Model-based testing; service-oriented architecture; security certification; symbolic transition systems; web services;
D O I
10.1145/2460383.2460384
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Service-Oriented Architecture (SOA) paradigm is giving rise to a new generation of applications built by dynamically composing loosely coupled autonomous services. Clients (i.e., software agents acting on behalf of human users or service providers) implementing such complex applications typically search and integrate services on the basis of their functional requirements and of their trust in the service suppliers. A major issue in this scenario relates to the definition of an assurance technique allowing clients to select services on the basis of their nonfunctional requirements and increasing their confidence that the selected services will satisfy such requirements. In this article, we first present an assurance solution that focuses on security and supports a test-based security certification scheme for Web services. The certification scheme is driven by the security properties to be certified and relies upon a formal definition of the service model. The evidence supporting a certified property is computed using a model-based testing approach that, starting from the service model, automatically generates the test cases to be used in the service certification. We also define a set of indexes and metrics that evaluate the assurance level and the quality of the certification process. Finally, we present our evaluation toolkit and experimental results obtained applying our certification solution to a financial service implementing the Interactive Financial eXchange (IFX) standard.
引用
收藏
页数:41
相关论文
共 50 条
  • [1] Test-Based Security Certification of Composite Services
    Anisetti, Marco
    Ardagna, Claudio
    Damiani, Ernesto
    Polegri, Gianluca
    [J]. ACM TRANSACTIONS ON THE WEB, 2019, 13 (01)
  • [2] Test-based Interoperability Certification for Web Services
    Elia, Ivano Alessandro
    Laranjeiro, Nuno
    Vieira, Marco
    [J]. 2015 45TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, 2015, : 196 - 206
  • [3] A Test-Based Incremental Security Certification Scheme for Cloud-Based Systems
    Anisetti, Marco
    Ardagna, Claudio A.
    Damiani, Ernesto
    [J]. 2015 IEEE 12TH INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (SCC 2015), 2015, : 736 - 741
  • [4] Test-based risk assessment and security certification proposal for the Internet of Things
    Matheu Garcia, Sara N.
    Hernandez-Ramos, Jose L.
    Skarmeta, Antonio E.
    [J]. 2018 IEEE 4TH WORLD FORUM ON INTERNET OF THINGS (WF-IOT), 2018, : 641 - 646
  • [5] Test-based cloud service certification of opportunistic providers
    Stephanow, Philipp
    Srivastava, Gaurav
    Schuette, Julian
    [J]. PROCEEDINGS OF 2016 IEEE 9TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2016, : 843 - 848
  • [6] Evaluating the performance of continuous test-based cloud service certification
    Stephanow, Philipp
    Banse, Christian
    [J]. 2017 17TH IEEE/ACM INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND GRID COMPUTING (CCGRID), 2017, : 1117 - 1126
  • [7] A Study on Feasibility and Establishment of a Security Grade Certification Scheme for the New IT Services
    Chang, Hangbae
    Kang, Jonggu
    Kwon, Hyukjun
    [J]. ADVANCES IN INFORMATION SECURITY AND ASSURANCE, 2009, 5576 : 769 - +
  • [8] The AssureMOSS security certification scheme
    Milankovich, Akos
    Eberhardt, Gergely
    Lukacs, David
    [J]. PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022, 2022,
  • [9] A XML-based quality model for Web services certification
    Dias, J. Jorge
    Cunha, J. Adson O. G. da
    Alvaro, Alexandre
    de Barros, Roberto S. M.
    Meira, Silvio
    [J]. ICEIS 2007: PROCEEDINGS OF THE NINTH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS: DATABASES AND INFORMATION SYSTEMS INTEGRATION, 2007, : 288 - 294
  • [10] Security of Web services
    Krawczyk, H.
    Wielgus, M.
    [J]. DEPCOS-RELCOMEX 2006, 2006, : 183 - +