A framework for enhancing web services security

被引:0
|
作者
Sidharth, Navya [1 ]
Liu, Jigang [1 ]
机构
[1] Metropolitan State Univ, 700 E 7th St, St Paul, MN 55106 USA
关键词
web services; WS-Security; UDDI; WSDL; DoS and SOAP;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The applicability of the security protocols, such as WS-Security, WS-Trust, WS-SecureConversation, WS-Federation, WS-Authorization, and WS-SecurityPolicy, is limited as they only protect SOA (Service Oriented Architecture) communication between two trusted parties with an established security association. The pervasiveness of web services and SOAP API that can be invoked by anonymous consumers introduces security vulnerabilities are not addressed by the existing standards. In this paper, an Integrated Application and Protocol-based Framework is proposed to tackle the existing WS security problems. The proposed IAPF techniques are envisioned to be a part of the design and implementation structure of a web service endpoint within the application and transaction handling logic of the SOAP/web service producer. These techniques will empower application level web services developers to design and implement SOA producers to the IAPF standard to firstly prevent DoS and DDoS based attacks and secondly mitigate the effects of these attacks.
引用
收藏
页码:23 / +
页数:2
相关论文
共 50 条
  • [21] An agent-based policy aware framework for Web Services security
    Li, Jian-Xin
    Li, Bin
    Li, Liang
    Che, Tong-Sheng
    2007 IFIP INTERNATIONAL CONFERENCE ON NETWORK AND PARALLEL COMPUTING WORKSHOPS, PROCEEDINGS, 2007, : 849 - 854
  • [22] Enhancing the security of web applications
    Striletchi, C
    Vaida, MF
    ITI 2003: PROCEEDINGS OF THE 25TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY INTERFACES, 2003, : 463 - 468
  • [23] Enhancing web services availability
    Abraham, S
    Thomas, M
    Thomas, J
    ICEBE 2005: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2005, : 352 - 355
  • [24] Enhancing .NET Web services
    Bergman-Terrell, E
    DR DOBBS JOURNAL, 2005, 30 (02): : S12 - +
  • [25] A XKMS-based security framework for Mobile Grid into the XML Web Services
    Park, N
    Moon, K
    Jang, J
    Sohn, S
    COMPUTATIONAL SCIENCE - ICCS 2004, PT 3, PROCEEDINGS, 2004, 3038 : 124 - 132
  • [26] A survey of web services security
    Gutiérrez, C
    Fernández-Medina, E
    Piattini, M
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2004, PT 1, 2004, 3043 : 968 - 977
  • [27] Considerations on web services security
    Gutiérrez, C
    Fernández-Medina, E
    Piattini, M
    IC'04: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INTERNET COMPUTING, VOLS 1 AND 2, 2004, : 999 - 1005
  • [28] XML and Web services security
    Sun, Lili
    Li, Yan
    PROCEEDINGS OF THE 2008 12TH INTERNATIONAL CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK IN DESIGN, VOLS I AND II, 2008, : 765 - 770
  • [29] Web services security.
    Gordon, RS
    LIBRARY JOURNAL, 2003, 128 (18) : 119 - 119
  • [30] Security and reliability for web services
    Maeda, T
    Nomura, Y
    Hara, H
    FUJITSU SCIENTIFIC & TECHNICAL JOURNAL, 2003, 39 (02): : 214 - 223