• DocumentCode
    2508664
  • Title

    Software Vulnerability Analysis for Web Services Software Systems

  • Author

    Yu, Weider D. ; Aravind, Dhanya ; Supthaweesuk, Passarawarin

  • Author_Institution
    San Jose State University, USA
  • fYear
    2006
  • fDate
    26-29 June 2006
  • Firstpage
    740
  • Lastpage
    748
  • Abstract
    The use of Web Services has begun to significantly impact organizations and companies. Major business oriented objectives in reducing costs, shortening time, and improving quality and productivity can be achieved by using the Web Services technology. The Web Services software technology enables software components independently developed in disparate platforms to interact and collaborate in a seamless manner. They constitute a loosely-coupled, distributed system that is highly scalable. However, they also inherit the potential vulnerabilities of such systems. As Web Services increase in complexity and connectivity, the associated security risks also increase exponentially. Many of the security breaches can be traced back to poor verification and validation tasks. In this paper, a study on security related software vulnerabilities in SOAP-based Web Services is presented. The security context of traditional Web applications is compared to that of Web Services. An attempt has been made to map common attack patterns to security verification requirements with regard to Web Service software systems.
  • Keywords
    Application software; Collaborative software; Companies; Context-aware services; Costs; Independent component analysis; Productivity; Security; Software systems; Web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computers and Communications, 2006. ISCC '06. Proceedings. 11th IEEE Symposium on
  • ISSN
    1530-1346
  • Print_ISBN
    0-7695-2588-1
  • Type

    conf

  • DOI
    10.1109/ISCC.2006.151
  • Filename
    1691113