A Security Gateway for Message exchange in Services by Streaming and Validation
نویسندگان
چکیده
Cloud Computing is found to be today’s most commonly used Service Oriented Architecture (SOA) implementation. Cloud services are exposed as Web Services which follow the industry standards such as WSDL for service description, SOAP for enabling request and response and so on. Hence Web services security is of particular importance for the security assessment of cloud systems. Securing SOAP message exchange using WS-Security standards introduces new surface for attacks. The system proposed uses a gateway at client side as well as server side which could counter the attacks introduced due to WS-Security standards as well as other attacks introduced. The handlers at the gateway uses hardened SOAP schema as the source for validating the restricted form of request according to the requestor and provider and ensures security. The SOAP Schemata which introduces loopholes in terms of security needs to be hardened, as a result of which high resource consumption leading to DOS attack is introduced. This type of attack is countered by streaming the request before the service execution at a trusted gateway and enabling earlier detection of security violations.
منابع مشابه
A Lightweight Privacy-preserving Authenticated Key Exchange Scheme for Smart Grid Communications
Smart grid concept is introduced to modify the power grid by utilizing new information and communication technology. Smart grid needs live power consumption monitoring to provide required services and for this issue, bi-directional communication is essential. Security and privacy are the most important requirements that should be provided in the communication. Because of the complex design of s...
متن کاملProtecting Web Services from DoS Attacks by SOAP Message Validation
Though Web Services become more and more popular, not only inside closed intranets but also for inter-enterprise communications, few efforts have been made so far to secure a Web Service’s availability. Existing security standards like e.g. WS-Security only address message integrity and confidentiality, and user authentication and authorization. In this article we present a system for protectin...
متن کاملStreaming-based Processing of Secured XML Documents
WS-Security is a standard providing message-level security in Web Services. It allows exible application of security mechanisms in SOAP messages. Therewith it ensures their integrity, con dentiality and authenticity. However, using sophisticated security algorithms can lead to high memory consumptions and long evaluation times. In the combination with the standard XML DOM processing approach th...
متن کاملPolicy-driven and Content-based Web Services Security Gateway
Web Services are widely used to provide services and exchange data among business units, customers, partners and suppliers for enterprises. Although Web Services significantly improve the interaction and development of processes in the business world, they raise several security concerns, since they greatly increase the exposure of critical enterprise data. Web Services exchange data using SOAP...
متن کاملA Gateway to Web Services Security - Securing SOAP with Proxies
Integrating applications and resources using Web Services increases the exposure of critical resources. Consequently, the introduction of Web Services requires that additional effort be spent on assessing the corresponding risks and establishing appropriate security mechanisms. This paper explains the main challenges for securing Web Services and summarizes emerging standards. The most importan...
متن کامل