A framework for enhancing web services security

被引:0
|
作者
Sidharth, Navya [1 ]
Liu, Jigang [1 ]
机构
[1] Metropolitan State Univ, 700 E 7th St, St Paul, MN 55106 USA
关键词
web services; WS-Security; UDDI; WSDL; DoS and SOAP;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The applicability of the security protocols, such as WS-Security, WS-Trust, WS-SecureConversation, WS-Federation, WS-Authorization, and WS-SecurityPolicy, is limited as they only protect SOA (Service Oriented Architecture) communication between two trusted parties with an established security association. The pervasiveness of web services and SOAP API that can be invoked by anonymous consumers introduces security vulnerabilities are not addressed by the existing standards. In this paper, an Integrated Application and Protocol-based Framework is proposed to tackle the existing WS security problems. The proposed IAPF techniques are envisioned to be a part of the design and implementation structure of a web service endpoint within the application and transaction handling logic of the SOAP/web service producer. These techniques will empower application level web services developers to design and implement SOA producers to the IAPF standard to firstly prevent DoS and DDoS based attacks and secondly mitigate the effects of these attacks.
引用
收藏
页码:23 / +
页数:2
相关论文
共 50 条
  • [1] Integrated Security Framework for Secure Web Services
    Zhang, Wenjun
    [J]. 2010 THIRD INTERNATIONAL SYMPOSIUM ON INTELLIGENT INFORMATION TECHNOLOGY AND SECURITY INFORMATICS (IITSI 2010), 2010, : 178 - 183
  • [2] Developing a framework to implement security in web services
    Alvi, FA
    Khoja, SA
    Jabeen, Z
    [J]. GRID AND COOPERATIVE COMPUTING, PT 1, 2004, 3032 : 657 - 660
  • [3] Web services security overview and security proposal for UDDI framework
    Nasirifard, P
    [J]. 7TH WORLD MULTICONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL V, PROCEEDINGS: COMPUTER SCIENCE AND ENGINEERING: I, 2003, : 464 - 466
  • [4] Web services security overview and security proposal for UDDI framework
    Nasirifard, P
    [J]. SAM'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, VOLS 1 AND 2, 2003, : 348 - 351
  • [5] Security Framework for Context Aware Mobile Web Services
    Charles, P. Joseph
    Kumar, S. Britto Ramesh
    [J]. INTERNATIONAL CONFERENCE ON COMPUTER NETWORKS AND COMMUNICATION TECHNOLOGIES (ICCNCT 2018), 2019, 15 : 963 - 972
  • [6] A policy language for adaptive web services security framework
    Li, Jian-Xin
    Bin Li
    Li, Liang
    Che, Tong-Sheng
    [J]. SNPD 2007: EIGHTH ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING, AND PARALLEL/DISTRIBUTED COMPUTING, VOL 1, PROCEEDINGS, 2007, : 261 - +
  • [7] Scalable security description framework for mobile web services
    Morioka, M
    Yonemoto, Y
    Suzuki, T
    Etoh, M
    [J]. 2003 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, VOLS 1-5: NEW FRONTIERS IN TELECOMMUNICATIONS, 2003, : 804 - 808
  • [8] An Intelligent Agent Framework to Manage Web Services Security
    Balachandran, Bala M.
    Sharma, Dharmendra
    Peiris, Chris
    [J]. INTELLIGENT DECISION TECHNOLOGIES (IDT'2012), VOL 1, 2012, 15 : 367 - 373
  • [9] A trust management framework suitable for web services security
    Ping, AI
    Mao, YC
    [J]. DCABES 2004, PROCEEDINGS, VOLS, 1 AND 2, 2004, : 469 - 473
  • [10] Enhancing Web services in the framework of service-oriented architectures
    Adamopoulos, Dionisis X.
    [J]. SEVENTH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS AND TECHNOLOGIES, PROCEEDINGS, 2006, : 260 - 265