Towards an automatic analysis of web service security

被引:0
|
作者
Chevalier, Yannick [1 ]
Lugiez, Denis [2 ]
Rusinowitch, Michael [3 ]
机构
[1] Univ Toulouse, Team LiLac, IRIT, Toulouse, France
[2] Aix Marseille Univ, CNRS, LIF, F-13284 Marseille, France
[3] LORIA INRIA Lorraine, Lorraine, France
关键词
security; web services; verification; cryptographic protocols; combination of decision procedures; equational theories; rewriting;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Web services send and receive messages in XML syntax with some parts hashed, encrypted or signed, according to the WS-Security standard. In this paper we introduce a model to formally describe the protocols that underly these services, their security properties and the rewriting attacks they might be subject to. Unlike other protocol models (in symbolic analysis) ours can handle non-deterministic receive/send actions and unordered sequence of XML nodes. Then to detect the attacks we have to consider the services as combining multiset operators and cryptographic ones and we have to solve specific satisfiability problems in the combined theory. By non-trivial extension of the combination techniques of [3] we obtain a decision procedure for insecurity of Web services with messages built using encryption, signature, and other cryptographic primitives. This combination technique allows one to decide insecurity in a modular way by reducing the associated constraint solving problems to problems in simpler theories.
引用
收藏
页码:133 / +
页数:3
相关论文
共 50 条
  • [1] Towards Automatic Comparison of Cloud Service Security Certifications
    Labaj, Martin
    Rastocny, Karol
    Chuda, Daniela
    [J]. THEORY AND PRACTICE OF COMPUTER SCIENCE, SOFSEM 2019, 2019, 11376 : 298 - 309
  • [2] Towards Security and Privacy in Dynamic Web Service Composition
    El Kassmi, Ilyass
    Jarir, Zahi
    [J]. PROCEEDINGS OF 2015 THIRD IEEE WORLD CONFERENCE ON COMPLEX SYSTEMS (WCCS), 2015,
  • [3] Amazon Web Service Microservice Security Analysis
    Cardenas Sanchez, Brian Camilo
    Olarte Rojas, Carlos Arturo
    [J]. LOGOS CIENCIA & TECNOLOGIA, 2022, 14 (02): : 42 - 52
  • [4] Web service security
    Damiani, Ernesto
    Gianini, Gabriele
    Maruyama, Hiroshi
    [J]. COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2006, 21 (05): : 323 - 323
  • [5] Towards an Automatic Non-Deterministic Web Service Composition Platform
    Markou, George
    Refanidis, Ioannis
    [J]. 2012 FOURTH INTERNATIONAL CONFERENCE ON COMPUTATIONAL ASPECTS OF SOCIAL NETWORKS (CASON), 2012, : 372 - 377
  • [6] Threats analysis and prevention for Grid and Web service security
    Ni Jiancheng
    Li Zhishu
    Gao Zhonghe
    Sun Jirong
    [J]. SNPD 2007: EIGHTH ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING, AND PARALLEL/DISTRIBUTED COMPUTING, VOL 3, PROCEEDINGS, 2007, : 526 - +
  • [7] A model for automatic matching of security requirements during semantic web service discovery
    Friesen, Andreas
    Feng, Danna
    [J]. WEBIST 2006: Proceedings of the Second International Conference on Web Information Systems and Technologies: INTERNET TECHNOLOGY / WEB INTERFACE AND APPLICATIONS, 2006, : 387 - 392
  • [8] Security Modeling and Analysis of a SDN Based Web Service
    Eom, Taehoon
    Hong, Jin B.
    Park, Jong Sou
    Kim, Dong Seong
    [J]. ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2015, 2015, 9532 : 746 - 756
  • [9] A Study on Web Service Analysis and Bio-information based Web Service Security Mechanism
    Lee, Seong-Hoon
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2014, 8 (02): : 77 - 86
  • [10] Towards an Architectural Pattern for Automatic Web Service Discovery and Selection in Business Marketplace
    Gaeta, M.
    Ritrovato, P.
    Loia, V.
    Veniero, M.
    Paolozzi, Stefano
    [J]. CISIS: 2009 INTERNATIONAL CONFERENCE ON COMPLEX, INTELLIGENT AND SOFTWARE INTENSIVE SYSTEMS, VOLS 1 AND 2, 2009, : 1199 - +