A Performance Evaluation of Security Mechanisms for Web services

被引:2
|
作者
Alrouh, Bachar [1 ]
Ghinea, Gheorghita [1 ]
机构
[1] Brunel Univ, Sch Informat Syst Comp & Math, Uxbridge UB8 3PH, Middx, England
关键词
Web Services; Security; Performance; WSIT;
D O I
10.1109/IAS.2009.252
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recently, web services security has shown a significant gesture as several specifications have been developed and implemented to meet the security challenges of web services. However, the performance of the security mechanisms is fraught with concerns due to additional security, contents in SOAP messages, the higher number of message exchanges to establish trust as well as extra CPU time to process these additions. In this paper, we consider and compare the performance of various security mechanisms applied on a simple web service tested with different initial message sizes. The test results show that transport layer security mechanisms are considerably faster than message level security mechanisms. Moreover, the effect of adding SAMIL-tokens is negligible and the performance of SAML-based web services depends mostly on the underlying security mechanisms. Finally, the performance penalty of applying STS security mechanisms is significantly high comparing to non-STS mechanisms.
引用
下载
收藏
页码:715 / 718
页数:4
相关论文
共 50 条
  • [1] A performance evaluation of web services security
    Tang, Kezhe
    Chen, Shiping
    Levy, David
    Zic, John
    Yan, Bo
    10TH IEEE INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING CONFERENCE, PROCEEDINGS, 2006, : 67 - 74
  • [2] A performance evaluation of mobile web services security
    Srirama, Satish Narayana
    Jarke, Matthias
    Prinz, Wolfgang
    WEBIST 2007: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON WEB INFORMATION SYSTEMS AND TECHNOLOGIES, VOL IT: INTERNET TECHNOLOGY, 2007, : 386 - +
  • [3] Performance evaluation and modeling of web services security
    Chen, Shiping
    Zic, John
    Tang, Kezhe
    Levy, David
    2007 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2007, : 431 - 438
  • [4] Influence of security mechanisms on web services interoperability
    Kocbek, Simon
    Juric, Matjaz B.
    ELEKTROTEHNISKI VESTNIK-ELECTROCHEMICAL REVIEW, 2007, 74 (03): : 113 - 118
  • [5] Influence of security mechanisms on web services interoperability
    Kocbek, Simon
    Jurič, Matjaž B.
    Elektrotehniski Vestnik/Electrotechnical Review, 2007, 74 (03): : 113 - 118
  • [6] A performance modelling of web services security
    Tang, Kezhe
    Levy, David
    Chen, Shiping
    Zic, John
    Yan, Bo
    WEBIST 2007: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON WEB INFORMATION SYSTEMS AND TECHNOLOGIES, VOL IT: INTERNET TECHNOLOGY, 2007, : 64 - +
  • [7] Web services security evaluation considerations
    Pimenidis, Elias
    Georgiadis, Christos K.
    INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2009, 2 (03) : 239 - 252
  • [8] Security and Performance of Mobile XML Web Services
    Nguyen, Thao Thanh
    Jorstad, Ivar
    van Thanh, Do
    FOURTH INTERNATIONAL CONFERENCE ON NETWORKING AND SERVICES (ICNS 2008), PROCEEDINGS, 2008, : 261 - 265
  • [9] Web services security - Implementation and evaluation issues
    Pimenidis, Elias
    Georgiadis, Christos K.
    Bako, Peter
    Zorkadis, Vassilis
    GLOBAL E-SECURITY, PROCEEDINGS, 2008, 12 : 299 - +
  • [10] Choreographing security and performance analysis for web services
    Gilmore, S
    Haenel, V
    Kloul, L
    Maidl, M
    FORMAL TECHNIQUES FOR COMPUTER SYSTEMS AND BUSINESS PROCESSES, PROCEEDINGS, 2005, 3670 : 200 - 214