Logic-based management of security in web services

被引:0
|
作者
Tziviskou, Christina [1 ]
Di Nitto, Elisabetta [1 ]
机构
[1] Politecn Milan, Via Ponzio 34-5, I-20133 Milan, Italy
关键词
D O I
暂无
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The increasing use of the Web as the platform for delivering business processes arises the need to protect both sensitive data exchanged over the Internet and the applications using these data. In this context, authentication, integrity and confidentiality of exchanged messages are requested during interactions between processes, and are commonly called WS* specifications. In this paper, we propose a formal specification of the above security requirements and the corresponding assertions in the exchanged messages, built on the XSB logic programming language. Our framework analyzes the generated models and verifies that incoming messages fulfill the security requirements of a Web service. Furthermore, it verifies the compatibility between two policies, which is a significant condition in order to guarantee secure end-to-end SOAP invocations, and it is not currently supported by WS* specifications.
引用
收藏
页码:228 / +
页数:2
相关论文
共 50 条
  • [21] A logic-based framework for the security analysis of Industrial Control Systems
    Lemaire L.
    Vossaert J.
    Jansen J.
    Naessens V.
    Automatic Control and Computer Sciences, 2017, 51 (2) : 114 - 123
  • [22] A Logic-Based Redundancy Filtering Approach for Web Service Composition
    Deng, Shiyang
    Du, Yuyue
    PROCEEDINGS OF THE 2015 2ND INTERNATIONAL CONFERENCE ON ELECTRICAL, COMPUTER ENGINEERING AND ELECTRONICS (ICECEE 2015), 2015, 24 : 1008 - 1013
  • [23] A Fuzzy Logic-based Information Security Control Assessment for Organizations
    Otero, Angel R.
    Tejay, Gurvirender
    Otero, Luis Daniel
    Ruiz-Torres, Alex J.
    2012 IEEE CONFERENCE ON OPEN SYSTEMS (ICOS 2012), 2012, : 190 - 195
  • [24] Logic and logic-based control
    Hongsheng QI
    JournalofControlTheoryandApplications, 2008, (01) : 26 - 36
  • [25] Logic and logic-based control
    Qi H.
    Cheng D.
    J. Control Theory Appl., 2008, 1 (26-36): : 26 - 36
  • [26] Design and Security Analysis of web application based and web services based Patient Management System (PMS)
    Rajput, Sahil
    Vadivel, S.
    Shetty, Sujala D.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2010, 10 (03): : 22 - 28
  • [27] A logic-based policy definition language for network management
    Li, YX
    Chen, M
    Jiang, XP
    Song, LH
    LCN 2001: 26TH ANNUAL IEEE CONFERENCE ON LOCAL COMPUTER NETWORKS, PROCEEDINGS, 2001, : 34 - 40
  • [28] A logic-based policy definition language for network management
    Li, YX
    Chen, M
    Jiang, XP
    Song, LH
    COMPUTER SCIENCE AND TECHNOLOGY IN NEW CENTURY, 2001, : 178 - 182
  • [29] Macaron: A Logic-based Framework for Software Supply Chain Security Assurance
    Hassanshahi, Behnaz
    Mai, Trong Nhan
    Michael, Alistair
    Selwyn-Smith, Benjamin
    Bates, Sophie
    Krishnan, Padmanabhan
    PROCEEDINGS OF THE 2023 WORKSHOP ON SOFTWARE SUPPLY CHAIN OFFENSIVE RESEARCH AND ECOSYSTEM DEFENSES, SCORED 2023, 2023, : 29 - 37
  • [30] A novel logic-based automatic approach to constructing compliant security policies
    BAO YiBao1
    2Institute of Electronic Technology
    3Beijing University of Posts and Telecommunications
    4Graduate University
    Science China(Information Sciences), 2012, 55 (01) : 149 - 164