Logic-based management of security in web services

被引:0
|
作者
Tziviskou, Christina [1 ]
Di Nitto, Elisabetta [1 ]
机构
[1] Politecn Milan, Via Ponzio 34-5, I-20133 Milan, Italy
关键词
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The increasing use of the Web as the platform for delivering business processes arises the need to protect both sensitive data exchanged over the Internet and the applications using these data. In this context, authentication, integrity and confidentiality of exchanged messages are requested during interactions between processes, and are commonly called WS* specifications. In this paper, we propose a formal specification of the above security requirements and the corresponding assertions in the exchanged messages, built on the XSB logic programming language. Our framework analyzes the generated models and verifies that incoming messages fulfill the security requirements of a Web service. Furthermore, it verifies the compatibility between two policies, which is a significant condition in order to guarantee secure end-to-end SOAP invocations, and it is not currently supported by WS* specifications.
引用
收藏
页码:228 / +
页数:2
相关论文
共 50 条
  • [1] SUBJECTIVE LOGIC-BASED FRAMEWORK FOR THE EVALUATION OF WEB SERVICES' SECURITY
    Juszczyszyn, Krzysztof
    COMPUTATIONAL INTELLIGENCE: FOUNDATIONS AND APPLICATIONS: PROCEEDINGS OF THE 9TH INTERNATIONAL FLINS CONFERENCE, 2010, 4 : 838 - 843
  • [2] A Logic-based Approach to Web Services Composition and Verification
    Wang, Hongbing
    Wang, Chen
    Liu, Yan
    2009 WORLD CONFERENCE ON SERVICES PART, 2009, : 103 - 110
  • [3] A logic-based approach for IP network services management and configuration
    Alipio, Pedro
    Neves, Jose
    Carvalho, Paulo
    2007 10TH IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2009), VOLS 1 AND 2, 2007, : 801 - +
  • [4] Binder, a logic-based security language
    DeTreville, J
    2002 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2002, : 105 - 113
  • [5] Logic-based web information extraction
    Gottlob, G
    Koch, C
    SIGMOD RECORD, 2004, 33 (02) : 87 - 94
  • [6] Logic-based web services composition: From service description to process model
    Department of Computer Science, Norwegian Univ. Sci. and Technology, N-7491, Trondheim, Norway
    不详
    IEEE Computer Society (TCSC), 1600, 446-453 (2004):
  • [7] Logic-based web services composition:: from service description to process model
    Rao, J
    Küngas, P
    Matskin, M
    IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, 2004, : 446 - 453
  • [8] Frame Logic-based specification and discovery of semantic web services with application to medical appointments
    Sharifi, Omid
    Ataee, Shahin Mehdipour
    Bayram, Zeki
    EXPERT SYSTEMS, 2020, 37 (01)
  • [9] MulVAL: A logic-based network security analyzer
    Ou, XM
    Govindavajhala, S
    Appel, AW
    USENIX ASSOCIATION PROCEEDINGS OF THE 14TH USENIX SECURITY SYMPOSIUM, 2005, : 113 - 128
  • [10] A Logic-based Security Framework for Mobile Perimeter
    Maddumala, Mahesh Nath
    Kumar, Vijay
    2015 16TH IEEE INTERNATIONAL CONFERENCE ON MOBILE DATA MANAGEMENT, VOL 2, 2015, : 30 - 33