Multi-Tier Security Feature Modeling for Service-Oriented Application Integration

被引:4
|
作者
Zhao, Fengyu [1 ]
Peng, Xin [1 ]
Zhao, Wenyun [1 ]
机构
[1] Fudan Univ, Sch Comp Sci, Shanghai 200433, Peoples R China
关键词
D O I
10.1109/ICIS.2009.80
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In Service oriented architecture (SOA) environment, the communication and infrastructure security is crucial. The most important specification addressing web services security is WS-Security, which collaborates with the SOAP message specifications, providing integrity, confidentiality and authentication for web services. However, WS-Security focuses SOAP message security between trusted partners. In SOA applications, there are other vulnerabilities which can be exploited to attack by anonymous customer or even trusted partners, and these vulnerabilities do not gain enough attention as WS-Security. Among them, Denial-of-Service (DoS) is one attack cluster, which exhausts computer and network resources and reduces the availability of web services. Another one is sensitive data leakage in a specific application domain. In this paper, the security of SOA applications is viewed as the security domain and a three-tier domain was divided based on security domain analysis. For each security sub-domain, security requirement scenario and requirements are presented The security domain models were given which can be used to build up security services for sub-domain. Based on security model and security service assets, which can evolve along with understanding on security domain, the developers can establish the security implementation for SOA application integration.
引用
收藏
页码:1178 / 1183
页数:6
相关论文
共 50 条
  • [1] Service-Oriented Trust and Reputation Management System for Multi-Tier Cloud
    Nicanfar, Hasen
    Amiri, S. Mohsen
    Zhu, Chunsheng
    TalebiFard, Peyman
    Leung, Victor C. M.
    Nasiopoulos, Panos
    [J]. PROCEEDINGS OF THE 2013 IEEE 2ND INTERNATIONAL CONFERENCE ON CLOUD NETWORKING (CLOUDNET), 2013, : 180 - 184
  • [2] Mobility-Aware Controller Orchestration in Multi-Tier Service-Oriented Architecture for IoT
    Chakraborty, Aishwariya
    Misra, Sudip
    Maiti, Jhareswar
    [J]. IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2022, 71 (02) : 1820 - 1831
  • [3] Using a domain-specific language and custom tools to model a multi-tier service-oriented application -: Experiences and challenges
    Vokác, M
    Glattetre, JM
    [J]. MODEL DRIVEN ENGINEERING LANGUAGES AND SYSTEMS, PROCEEDINGS, 2005, 3713 : 492 - 506
  • [4] Service Differentiation in Multi-tier Application Architectures
    Habib, Mursalin
    Viniotis, Yannis
    Callaway, Bob
    Rodriguez, Adolfo
    [J]. SOFTWARE AND DATA TECHNOLOGIES, 2011, 50 : 46 - +
  • [5] Integration of a Security Product in Service-oriented Architecture
    Dikanski, Aleksander
    Emig, Christian
    Abeck, Sebastian
    [J]. 2009 THIRD INTERNATIONAL CONFERENCE ON EMERGING SECURITY INFORMATION, SYSTEMS, AND TECHNOLOGIES, 2009, : 1 - 7
  • [6] Understanding and Evaluating Replication in Service Oriented Multi-tier Architectures
    Ameling, Michael
    Roy, Marcus
    Kemme, Bettina
    [J]. SOFTWARE AND DATA TECHNOLOGIES, 2009, 47 : 91 - +
  • [7] Trust Mechanism-Based Multi-Tier Computing System for Service-Oriented Edge-Cloud Networks
    Huang, Mingfeng
    Li, Zhetao
    Xiao, Fu
    Long, Saiqin
    Liu, Anfeng
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 1639 - 1651
  • [8] Performance Modeling to Support Multi-Tier Application Deployment to Infrastructure-as-a-Service Clouds
    Lloyd, Wes
    Pallickara, Shrideep
    David, Olaf
    Lyon, Jim
    Arabi, Mazdak
    Rojas, Ken
    [J]. 2012 IEEE/ACM FIFTH INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING (UCC 2012), 2012, : 73 - 80
  • [9] Feature Modeling for Service Variability Management in Service-Oriented Architectures
    Abu-Matar, Mohammad
    Gomaa, Hassan
    Kim, Minseong
    Elkhodary, Ahmed
    [J]. 22ND INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING & KNOWLEDGE ENGINEERING (SEKE 2010), 2010, : 468 - 473
  • [10] Multi-level security for service-oriented architectures
    Ramasamy, HariGovind V.
    Schunter, Matthias
    [J]. MILCOM 2006, VOLS 1-7, 2006, : 3129 - +