Why applying standards to Web services is not enough

被引:12
|
作者
Viega, John
Epstein, Jeremy
机构
关键词
D O I
10.1109/MSP.2006.110
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Importance of design and security of web services applications, are discussed. The role of traditional standards is to meet the market demand for uniformity among the vendors. The developers need to understand the security standards and limitations and drawbacks to fully secure their web services. The common pitfalls related to standards are security, use of wrong standards and ignorance of authentication of the standards. Large number of web services security standards are available to developers, including SSL (Security Sockets Layer), WS-Security, Digital Signature Services, XML-encryption, XML-signature, eXtensible Acces Control Markup Language, Security Assertion Markup language, and the XML key management Specification, to make them understand the fineness of web services applications. Dynamic testing tools can detect some operational misconfigurations that a static tool probably would not be able to identify and have the benefits of being language independent.
引用
收藏
页码:25 / 31
页数:7
相关论文
共 50 条
  • [41] Applying Text Classification Algorithms in Web Services Robustness Testing
    Laranjeiro, Nuno
    Oliveira, Rui
    Vieira, Marco
    [J]. 2010 29TH IEEE INTERNATIONAL SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS SRDS 2010, 2010, : 255 - 264
  • [42] Applying intelligent agents and semantic web services in eGovernment environments
    Garcia-Sanchez, Francisco
    Alvarez Sabucedo, Luis
    Martinez-Bejar, Rodrigo
    Anido Rifon, Luis
    Valencia-Garcia, Rafael
    Gomez, Juan Miguel
    [J]. EXPERT SYSTEMS, 2011, 28 (05) : 416 - 436
  • [43] Applying orchestration and choreography of web services on dynamic virtual marketplaces
    Dos Santos, IJG
    Madeira, ERM
    [J]. INTERNATIONAL JOURNAL OF COOPERATIVE INFORMATION SYSTEMS, 2006, 15 (01) : 57 - 85
  • [44] Applying ecosystem services principles to the derivation of freshwater environmental quality standards
    Maltby, Lorraine
    Brown, Ross
    Wilkinson, Helen
    [J]. FRONTIERS IN ENVIRONMENTAL SCIENCE, 2022, 10
  • [45] Towards standards-compliant trust negotiation for web services
    Lee, Adam J.
    Winslett, Marianne
    [J]. TRUST MANAGEMENT II, 2008, 263 : 311 - 326
  • [46] Realizing the vision for web services: Strategies for dealing with imperfect standards
    Sanjay Gosain
    [J]. Information Systems Frontiers, 2007, 9 : 53 - 67
  • [47] Adapting Web Services Security Standards for Mobile and Wireless Environments
    Delessy, Nelly A.
    Fernandez, Eduardo B.
    [J]. ADVANCES IN WEB AND NETWORK TECHNOLOGIES, AND INFORMATION MANAGEMENT, PROCEEDINGS, 2007, 4537 : 624 - 633
  • [48] Realizing the vision for web services: Strategies for dealing with imperfect standards
    Gosain, Sanjay
    [J]. INFORMATION SYSTEMS FRONTIERS, 2007, 9 (01) : 53 - 67
  • [49] The Web is not enough
    Chowdhury, N
    [J]. FORTUNE, 2000, 142 (01) : 248 - +
  • [50] Are NFPA standards enough?
    O'Brien, Chris
    [J]. HYDROCARBON PROCESSING, 2008, 87 (01): : 118 - 118