A Performance Evaluation of Security Mechanisms for Web services

被引:2
|
作者
Alrouh, Bachar [1 ]
Ghinea, Gheorghita [1 ]
机构
[1] Brunel Univ, Sch Informat Syst Comp & Math, Uxbridge UB8 3PH, Middx, England
关键词
Web Services; Security; Performance; WSIT;
D O I
10.1109/IAS.2009.252
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recently, web services security has shown a significant gesture as several specifications have been developed and implemented to meet the security challenges of web services. However, the performance of the security mechanisms is fraught with concerns due to additional security, contents in SOAP messages, the higher number of message exchanges to establish trust as well as extra CPU time to process these additions. In this paper, we consider and compare the performance of various security mechanisms applied on a simple web service tested with different initial message sizes. The test results show that transport layer security mechanisms are considerably faster than message level security mechanisms. Moreover, the effect of adding SAMIL-tokens is negligible and the performance of SAML-based web services depends mostly on the underlying security mechanisms. Finally, the performance penalty of applying STS security mechanisms is significantly high comparing to non-STS mechanisms.
引用
下载
收藏
页码:715 / 718
页数:4
相关论文
共 50 条
  • [21] Stochastic Bounds for Performance Evaluation of Web Services
    Fourneau, Jean-Michel
    Mokdad, Lynda
    Pekergin, Nihal
    ISCC: 2009 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS, VOLS 1 AND 2, 2009, : 1041 - +
  • [22] Performance Evaluation of Transactional Composite Web Services
    Ding, Zhijun
    Sun, Youqing
    Jiang, Changjun
    Zhou, MengChu
    Liu, Junjun
    Song, Wenqi
    IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2016, 46 (08): : 1061 - 1074
  • [23] Stochastic bounds for performance evaluation of Web services
    Fourneau, Jean-Michel
    Mokdad, Lynda
    Pekergin, Nihal
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2010, 22 (10): : 1286 - 1307
  • [24] Evaluation of Web Security Mechanisms Using Vulnerability & Attack Injection
    Fonseca, Jose
    Vieira, Marco
    Madeira, Henrique
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2014, 11 (05) : 440 - 453
  • [25] A survey of web services security
    Gutiérrez, C
    Fernández-Medina, E
    Piattini, M
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2004, PT 1, 2004, 3043 : 968 - 977
  • [26] Considerations on web services security
    Gutiérrez, C
    Fernández-Medina, E
    Piattini, M
    IC'04: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON INTERNET COMPUTING, VOLS 1 AND 2, 2004, : 999 - 1005
  • [27] Web services security.
    Gordon, RS
    LIBRARY JOURNAL, 2003, 128 (18) : 119 - 119
  • [28] XML and Web services security
    Sun, Lili
    Li, Yan
    PROCEEDINGS OF THE 2008 12TH INTERNATIONAL CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK IN DESIGN, VOLS I AND II, 2008, : 765 - 770
  • [29] Security and reliability for web services
    Maeda, T
    Nomura, Y
    Hara, H
    FUJITSU SCIENTIFIC & TECHNICAL JOURNAL, 2003, 39 (02): : 214 - 223
  • [30] Security architecture for web services
    Rao, Y
    Feng, BQ
    Han, JC
    GRID AND COOPERATIVE COMPUTING GCC 2004, PROCEEDINGS, 2004, 3251 : 341 - 347