• DocumentCode
    1925088
  • Title

    A practical approach to secure Web services

  • Author

    Xu, Jie ; Yang, Erica Y. ; Bennett, Keith H.

  • Author_Institution
    Sch. of Comput., Leeds Univ.
  • fYear
    2006
  • fDate
    24-26 April 2006
  • Abstract
    Web services provide the potential to offer interoperability of distributed business-to-business application integration between autonomous organisations, regardless of platforms, operating systems or languages. For both user and vendor organisations, this raises immediate problems of trust, security, privacy and prevention of malicious attacks. Until these problems are addressed and solved properly, the use of Web services will be severely restricted because no-one will trust them. We describe in this paper a service-oriented architecture and an attack-tolerant information retrieval (ATIR) service which tackles certain classes of privacy problems. In particular, we address the problem of protecting a user against malicious attacks upon an information service when the user retrieves some information from the service. Although there have been many theoretical solutions to certain aspects of this problem, the results have yet to be adapted to real systems. We report our experience of integrating the ATIR service with Taverna, a popular workflow system used amongst the UK e-science/grid computing community, to support secure information retrieval in the biology context. Performance studies show that the overhead of ATIR server-side processing is trivial (<5%) in comparison with the total processing time of the integrated Taverna. Our experimental results also show that the major processing overhead is caused by the Taverna enactor operations which consume no less than 50% of the total processing time
  • Keywords
    Internet; biology computing; client-server systems; data privacy; grid computing; information retrieval; information services; open systems; scientific information systems; security of data; Taverna; UK e-science community; Web service security; attack-tolerant information retrieval; distributed business-to-business application integration; distributed information retrieval; grid computing; information service; interoperability; malicious attacks; privacy protection; server-side processing; service-oriented architecture; trust; workflow system; Biology computing; Context-aware services; Grid computing; Information retrieval; Information security; Operating systems; Privacy; Protection; Service oriented architecture; Web services; Attack tolerance; Web services; distributed information; malicious attacks; privacy protection; retrieval;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Object and Component-Oriented Real-Time Distributed Computing, 2006. ISORC 2006. Ninth IEEE International Symposium on
  • Conference_Location
    Gyeongju
  • Print_ISBN
    0-7695-2561-X
  • Type

    conf

  • DOI
    10.1109/ISORC.2006.9
  • Filename
    1630519