• DocumentCode
    237730
  • Title

    Security solutions for Web Service attacks in a dynamic composition scenario

  • Author

    Sindhu, S.M. ; Kanchana, R.

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Anna Univ., Chennai, India
  • fYear
    2014
  • fDate
    8-10 May 2014
  • Firstpage
    624
  • Lastpage
    628
  • Abstract
    Web Services can be invoked from anywhere through internet without having enough knowledge about the implementation details. In some cases, single service cannot accomplish user needs. One or more services must be composed which together satisfy the user needs. Therefore, security is the most important concern not only at single service level but also at composition level. Several attacks are possible on SOAP messages communicated among Web Services because of their standardized interfaces. Examples of Web Service attacks are oversize payload, SOAPAction spoofing, XML injection, WS-Addressing spoofing, etc. Most of the existing works provide solution to ensure basic security features of Web Services such as confidentiality, integrity, authentication, authorization, and non-repudiation. Very few of the existing works provide solutions such as schema validation and schema hardening for attacks on Web Services. But these solutions do not address and provide attack specific solutions for SOAP messages communicated between Web Service. Hence, it is proposed to provide solutions for two of the prevailing Web Service attacks. Since new types of Web Service attacks are evolving over time, the proposed security solutions are implemented as APIs that are pluggable in any server where the Web Service is deployed.
  • Keywords
    Web services; application program interfaces; authorisation; data integrity; protocols; service-oriented architecture; API; Internet; SOA; SOAP messages; SOAPAction spoofing; WS-Addressing spoofing; Web service attacks; XML injection; authentication; authorization; confidentiality; dynamic composition scenario; integrity; nonrepudiation; schema hardening; schema validation; security solutions; service oriented architecture; simple object access protocol; Electronic publishing; Information services; Lead; Security; Simple object access protocol; Standards; SAS API; SOAP; UDDI; WSAS API; WSDL; Web Services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Communication Control and Computing Technologies (ICACCCT), 2014 International Conference on
  • Conference_Location
    Ramanathapuram
  • Print_ISBN
    978-1-4799-3913-8
  • Type

    conf

  • DOI
    10.1109/ICACCCT.2014.7019163
  • Filename
    7019163