DocumentCode :
1925088
Title :
A practical approach to secure Web services
Author :
Xu, Jie ; Yang, Erica Y. ; Bennett, Keith H.
Author_Institution :
Sch. of Comput., Leeds Univ.
fYear :
2006
fDate :
24-26 April 2006
Abstract :
Web services provide the potential to offer interoperability of distributed business-to-business application integration between autonomous organisations, regardless of platforms, operating systems or languages. For both user and vendor organisations, this raises immediate problems of trust, security, privacy and prevention of malicious attacks. Until these problems are addressed and solved properly, the use of Web services will be severely restricted because no-one will trust them. We describe in this paper a service-oriented architecture and an attack-tolerant information retrieval (ATIR) service which tackles certain classes of privacy problems. In particular, we address the problem of protecting a user against malicious attacks upon an information service when the user retrieves some information from the service. Although there have been many theoretical solutions to certain aspects of this problem, the results have yet to be adapted to real systems. We report our experience of integrating the ATIR service with Taverna, a popular workflow system used amongst the UK e-science/grid computing community, to support secure information retrieval in the biology context. Performance studies show that the overhead of ATIR server-side processing is trivial (<5%) in comparison with the total processing time of the integrated Taverna. Our experimental results also show that the major processing overhead is caused by the Taverna enactor operations which consume no less than 50% of the total processing time
Keywords :
Internet; biology computing; client-server systems; data privacy; grid computing; information retrieval; information services; open systems; scientific information systems; security of data; Taverna; UK e-science community; Web service security; attack-tolerant information retrieval; distributed business-to-business application integration; distributed information retrieval; grid computing; information service; interoperability; malicious attacks; privacy protection; server-side processing; service-oriented architecture; trust; workflow system; Biology computing; Context-aware services; Grid computing; Information retrieval; Information security; Operating systems; Privacy; Protection; Service oriented architecture; Web services; Attack tolerance; Web services; distributed information; malicious attacks; privacy protection; retrieval;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Object and Component-Oriented Real-Time Distributed Computing, 2006. ISORC 2006. Ninth IEEE International Symposium on
Conference_Location :
Gyeongju
Print_ISBN :
0-7695-2561-X
Type :
conf
DOI :
10.1109/ISORC.2006.9
Filename :
1630519
Link To Document :
بازگشت