A Comprehensive Model to Enhance Performance of WS-Security Processing
نویسندگان
چکیده
Service Oriented Architecture with Simple Object Access Protocol based Web Services enable flexible software system integration, especially in heterogeneous environments. These web services require proper security when they communicate critical information. These services are exposed to a variety of external threats and attacks. Therefore, security is an important issue for Web Services. Several security technologies and standards are developed to secure web services. SOAP protocol inherits problems related to XML. SOAP processing performance is one of the issues. Adding security requires extra computations. Lower performance not only affects the efficiency of system but it also affects the availability and quality of web services. A comprehensive parallel model for stream-based processing of secured web services is introduced to address these issues. It is used as application level gateway to enhance performance of security processing especially for large documents. The architectural design of the comprehensive model is described in detail in the paper. The overall performance of the new model is evaluated on different hardware platforms by conducting tests for different size of SOAP messages with varying levels of security. Significant reduction in the processing time and early detection of attacks is observed by successful implementation of the model.
منابع مشابه
Permutation of Httpi and HTTPS in Web Services against Attacks for Security enhancement
The Hyper Text Transfer Protocol (HTTP) protocol plays a vital role in Web Services Security. Though the HTTPs provide excellent security, they are not flexible enough to allow caches. HTTPi provides high integrity and low security whereas HTTPs provide low integrity and high security. The goal of WS activity is to build up set of technologies in order to direct WS to their complete prospective...
متن کاملImplementation and Performance of WS-Security
This article describes performance improvements for the Web Services Security (WS-Security) specification. In the course of its development and performance measurement, we identified bottlenecks in the XML parsing and public key operations such as RSA signature and encryption. We are working on minimizing the impact of both of these bottlenecks. We implemented a stream-based WS-Security process...
متن کاملHow Effectiveness Of Comprehensive Performance Measurement Systems on Manager's Performance Through Modification of Mental Models (Learning Process)
One of the ways to reduce agency costs is to plan for the creation of effective decision-making information by designing appropriate comprehensive performance evaluation systems according to managers' learning process One of the important factors in the processing and classification of information for cognitive learning is mental models that are categorized in two dimensions of mental model co...
متن کاملStreaming-based Processing of Secured XML Documents
WS-Security is a standard providing message-level security in Web Services. It allows exible application of security mechanisms in SOAP messages. Therewith it ensures their integrity, con dentiality and authenticity. However, using sophisticated security algorithms can lead to high memory consumptions and long evaluation times. In the combination with the standard XML DOM processing approach th...
متن کاملEvent-Based SOAP Message Validation for WS-SecurityPolicy-Enriched Web Services
To enable checking of SOAP messages for compliance to a given security policy, extensions to the classical “Schema-only” validation of SOAP messages are required. These extensions check, if the WS-Security elements found in a SOAP message fulfill the Web Service security specification that is laid down in the WS-SecurityPolicy document. In this paper, we discuss to what extent the proposed exte...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2016