Why applying standards to Web services is not enough

被引:12
|
作者
Viega, John
Epstein, Jeremy
机构
关键词
D O I
10.1109/MSP.2006.110
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Importance of design and security of web services applications, are discussed. The role of traditional standards is to meet the market demand for uniformity among the vendors. The developers need to understand the security standards and limitations and drawbacks to fully secure their web services. The common pitfalls related to standards are security, use of wrong standards and ignorance of authentication of the standards. Large number of web services security standards are available to developers, including SSL (Security Sockets Layer), WS-Security, Digital Signature Services, XML-encryption, XML-signature, eXtensible Acces Control Markup Language, Security Assertion Markup language, and the XML key management Specification, to make them understand the fineness of web services applications. Dynamic testing tools can detect some operational misconfigurations that a static tool probably would not be able to identify and have the benefits of being language independent.
引用
收藏
页码:25 / 31
页数:7
相关论文
共 50 条
  • [1] Why Web standards matter
    Bickner, C
    [J]. LIBRARY JOURNAL, 2002, : 26 - 28
  • [2] Applying CBD to Web Services
    Chung, Youn-Ky
    [J]. PROCEEDINGS OF THE 2008 ADVANCED SOFTWARE ENGINEERING & ITS APPLICATIONS, 2008, : 103 - 107
  • [3] A Metamodel for the Web Services Standards
    Balazs Simon
    Balazs Goldschmidt
    Karoly Kondorosi
    [J]. Journal of Grid Computing, 2013, 11 : 735 - 752
  • [4] Using Web services standards
    Fussell, E
    [J]. INTECH, 2002, 49 (06) : 31 - 31
  • [5] A Metamodel for the Web Services Standards
    Simon, Balazs
    Goldschmidt, Balazs
    Kondorosi, Karoly
    [J]. JOURNAL OF GRID COMPUTING, 2013, 11 (04) : 735 - 752
  • [6] Applying a web engineering method to design web services
    Ruiz, M
    Valderas, P
    Pelechano, V
    [J]. SERVICE-ORIENTED COMPUTING - ICSOC 2005, PROCEEDINGS, 2005, 3826 : 576 - 581
  • [7] Web Services Specific Security Standards
    Cristescu, Marian Pompiliu
    Stoica, Eduard Alexandru
    Ciovica, Laurentiu Vasile
    [J]. 21ST INTERNATIONAL ECONOMIC CONFERENCE OF SIBIU 2014, IECS 2014 PROSPECTS OF ECONOMIC RECOVERY IN A VOLATILE INTERNATIONAL CONTEXT: MAJOR OBSTACLES, INITIATIVES AND PROJECTS, 2014, 16 : 597 - 602
  • [8] RESTful Web Services - A Question of Standards
    Archip, Alexandru
    Amarandei, Cristian-Mihai
    Herghelegiu, Paul-Corneliu
    Mironeanu, Catalin
    Serban, Elena
    [J]. 2018 22ND INTERNATIONAL CONFERENCE ON SYSTEM THEORY, CONTROL AND COMPUTING (ICSTCC), 2018, : 677 - 682
  • [9] Adding semantics to Web services standards
    Sivashanmugam, K
    Verma, K
    Sheth, A
    Miller, J
    [J]. ICWS'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON WEB SERVICES, 2003, : 395 - 401
  • [10] XML and web services security standards
    Norwegian Defence Research Establishment, Norway
    [J]. IEEE Commun. Surv. Tutor, 2009, 3 (22-36):