Intelligent security and access control framework for service-oriented architecture

被引:10
|
作者
El Yamany, Hany F. [2 ]
Capretz, Miriam A. M. [1 ]
Allison, David S. [1 ]
机构
[1] Univ Western Ontario, Fac Engn, Dept Elect & Comp Engn, London, ON N6A 5B9, Canada
[2] Suez Canal Univ, Fac Comp & Informat, Dept Comp Sci, Ismailia, Egypt
关键词
SOA; Web Services; Intelligent security; Web; 2.0; Data mining;
D O I
10.1016/j.infsof.2009.10.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
One of the most significant difficulties with developing Service-Oriented Architecture (SOA) involves meeting its security challenges, since the responsibilities of SOA security are based on both the service providers and the consumers. In recent years, many solutions to these challenges have been implemented, such as the Web Services Security Standards, including WS-Security and WS-Policy. However, those standards are insufficient for the new generation of Web technologies, including Web 2.0 applications. In this research, we propose an intelligent SOA security framework by introducing its two most promising services: the Authentication and Security Service (NSS), and the Authorization Service (AS). The suggested autonomic and reusable services are constructed as an extension of WS- security standards, with the addition of intelligent mining techniques, in order to improve performance and effectiveness. In this research, we apply three different mining techniques: the Association Rules, which helps to predict attacks, the Online Analytical Processing (OLAP) Cube, for authorization, and clustering mining algorithms, which facilitate access control rights representation and automation. Furthermore, a case study is explored to depict the behavior of the proposed services inside an SOA business environment. We believe that this work is a significant step towards achieving dynamic SOA security that automatically controls the access to new versions of Web applications, including analyzing and dropping suspicious SOAP messages and automatically managing authorization roles. (C) 2009 Elsevier B.V. All rights reserved.
引用
收藏
页码:220 / 236
页数:17
相关论文
共 50 条
  • [31] A taxonomic framework for autonomous service management in Service-Oriented Architecture
    Du Wan CHEUN
    Hyun Jung LA
    Soo Dong KIM
    [J]. Frontiers of Information Technology & Electronic Engineering, 2012, (05) : 339 - 354
  • [32] A Service-Oriented Hybrid Access Network and Clouds Architecture
    Velasco, Luis
    Contreras, Luis Miguel
    Ferraris, Giuseppe
    Stavdas, Alexandros
    Cugini, Filippo
    Wiegand, Manfred
    Fernandez-Palacios, Juan Pedro
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2015, 53 (04) : 159 - 165
  • [33] A security framework for developing service-oriented software architectures
    Rafe, Vahid
    Hosseinpouri, Ramin
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (17) : 2957 - 2972
  • [34] Service-oriented architecture
    Perrey, R
    Lycett, M
    [J]. 2003 SYMPOSIUM ON APPLICATIONS AND THE INTERNET WORKSHOPS, PROCEEDINGS, 2003, : 116 - 119
  • [35] A Control System Framework Model for Cloud Robots Based on Service-Oriented Architecture
    Qian, Kui
    Liu, Yiting
    Song, Aiguo
    Li, Jialu
    [J]. INTELLIGENT ROBOTICS AND APPLICATIONS, ICIRA 2019, PT II, 2019, 11741 : 579 - 588
  • [36] A service-oriented data access control model
    Meng, Wei
    Li, Fengmin
    Pan, Juchen
    Song, Song
    Bian, Jiali
    [J]. SEVENTH INTERNATIONAL CONFERENCE ON ELECTRONICS AND INFORMATION ENGINEERING, 2017, 10322
  • [37] A Hybrid Architecture Framework for Simulations in a Service-Oriented Environment
    Hannay, Jo Erskine
    Brathen, Karsten
    Mevassvik, Ole Martin
    [J]. SYSTEMS ENGINEERING, 2017, 20 (03) : 235 - 256
  • [38] Service-oriented Architecture in IT
    Xin, Chen
    [J]. 2009 ASIA-PACIFIC CONFERENCE ON INFORMATION PROCESSING (APCIP 2009), VOL 2, PROCEEDINGS, 2009, : 493 - 496
  • [39] A Novel ERP Framework Based on Service-Oriented Architecture
    Wang, Jing
    Lv, Guonian
    Zheng, Feifei
    Lv, Meidan
    [J]. ADVANCED MECHANICAL ENGINEERING, PTS 1 AND 2, 2010, 26-28 : 913 - 918
  • [40] A Service-Oriented Architecture (SOA) Framework for Choreography Verification
    Rebai, Sirinc
    Kacem, Hatem Hadj
    Karaa, Mohamed
    Pomares, Saul E.
    Kacem, Ahmed Hadj
    [J]. 2015 IEEE/ACIS 14TH INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION SCIENCE (ICIS), 2015, : 642 - 646