A framework for enhancing web services security

被引:0
|
作者
Sidharth, Navya [1 ]
Liu, Jigang [1 ]
机构
[1] Metropolitan State Univ, 700 E 7th St, St Paul, MN 55106 USA
关键词
web services; WS-Security; UDDI; WSDL; DoS and SOAP;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The applicability of the security protocols, such as WS-Security, WS-Trust, WS-SecureConversation, WS-Federation, WS-Authorization, and WS-SecurityPolicy, is limited as they only protect SOA (Service Oriented Architecture) communication between two trusted parties with an established security association. The pervasiveness of web services and SOAP API that can be invoked by anonymous consumers introduces security vulnerabilities are not addressed by the existing standards. In this paper, an Integrated Application and Protocol-based Framework is proposed to tackle the existing WS security problems. The proposed IAPF techniques are envisioned to be a part of the design and implementation structure of a web service endpoint within the application and transaction handling logic of the SOAP/web service producer. These techniques will empower application level web services developers to design and implement SOA producers to the IAPF standard to firstly prevent DoS and DDoS based attacks and secondly mitigate the effects of these attacks.
引用
收藏
页码:23 / +
页数:2
相关论文
共 50 条
  • [41] A framework for web services procurement
    Alor-Hernandez, Giner
    Chavez-Trejo, Ana Ma.
    Pelaez-Camarena, Gustavo
    Gomez, Juan Miguel
    2006 3RD INTERNATIONAL CONFERENCE ON ELECTRICAL AND ELECTRONICS ENGINEERING, 2006, : 5 - +
  • [42] An extended Web Services framework
    Dogdu, E
    PROCEEDINGS OF THE IASTED INTERNATIONAL CONFERENCE ON COMMUNICATIONS, INTERNET, AND INFORMATION TECHNOLOGY, 2002, : 455 - 460
  • [43] A novel aspect-oriented BPEL framework for the dynamic enforcement of web services security
    Mourad, Azzam
    Ayoubi, Sara
    Yahyaoui, Hamdi
    Otrok, Hadi
    INTERNATIONAL JOURNAL OF WEB AND GRID SERVICES, 2012, 8 (04) : 361 - 385
  • [44] A Framework for Securing Web Services by Formulating an Collaborative Security Standard among Prevailing WS-* Security Standards
    Priyadharshini, M.
    Baskaran, R.
    Srinivasan, Madhan Kumar
    Rodrigues, Paul
    ADVANCES IN COMPUTING AND COMMUNICATIONS, PT 4, 2011, 193 : 269 - +
  • [45] Enhancing Web Services with diagnostic capabilities
    Ardissono, L
    Console, L
    Goy, A
    Petrone, G
    Picardi, C
    Segnan, M
    Dupré, DT
    THIRD EUROPEAN CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2005, : 182 - 191
  • [46] Enhancing Semantic Web Services with Inheritance
    Ferndriger, Simon
    Bernstein, Abraham
    Dong, Jin Song
    Feng, Yuzhang
    Li, Yuan-Fang
    Hunter, Jane
    SEMANTIC WEB - ISWC 2008, 2008, 5318 : 162 - +
  • [47] Web Services Specific Security Standards
    Cristescu, Marian Pompiliu
    Stoica, Eduard Alexandru
    Ciovica, Laurentiu Vasile
    21ST INTERNATIONAL ECONOMIC CONFERENCE OF SIBIU 2014, IECS 2014 PROSPECTS OF ECONOMIC RECOVERY IN A VOLATILE INTERNATIONAL CONTEXT: MAJOR OBSTACLES, INITIATIVES AND PROJECTS, 2014, 16 : 597 - 602
  • [48] Analysis of web services backbone security
    Abuelyaman, E
    Chopde, RS
    Elyaman, M
    ISAS/CITSA 2004: International Conference on Cybernetics and Information Technologies, Systems and Applications and 10th International Conference on Information Systems Analysis and Synthesis, Vol 1, Proceedings: COMMUNICATIONS, INFORMATION TECHNOLOGIES AND COMPUTING, 2004, : 16 - 22
  • [49] A performance evaluation of web services security
    Tang, Kezhe
    Chen, Shiping
    Levy, David
    Zic, John
    Yan, Bo
    10TH IEEE INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE, PROCEEDINGS, 2006, : 67 - 74
  • [50] A Study on the Security Mechanism for Web Services
    Kou Hongzhao
    WORLD CONGRESS ON ENGINEERING AND COMPUTER SCIENCE, VOLS 1 AND 2, 2010, : 93 - 96