Title :
Service Oriented Architecture (SOA) - Security Challenges and Mitigation Strategies
Author_Institution :
JCS J-6, Joint Staff J6, C4 Directorate, Laura Lee and Rod Fleischer, SPARTA, Inc. Cecilia.Phan@js.pentagon.mil
Abstract :
Service Oriented Architecture (SOA) is a new way of operating a network system, and as with all new technologies, it comes with its share of challenges. Of particular difficulty is the challenge of securing a service-oriented system. Due to the intentionally decentralized nature of this system, data flows in all directions and needs to be protected at all times. Additionally, to implement access control it must be first defined somewhere, and the rest of the system needs to be aware of the rules and respect them. Since there are many resources in such a system, it becomes cumbersome to require users to authenticate themselves every time they attempt to access a new resource. "Single Sign On" (SSO) functionality, where a user\´s credentials are promulgated throughout the Global Information Grid (GIG) to reach all desired services, is a desirable capability but problematic. Additionally, in an SOA all of these security functions are implemented in XML, which brings its own set of problems. This paper will address the security challenges for a SOA. We will describe the problems stemming from the fact that XML is not inherently secure, resulting in special vulnerabilities in the security protocols. We will present strategies for mitigating these vulnerabilities to defend against replay attacks, encryption problems and policy considerations.
Keywords :
IP networks; Information security; Internet; Military computing; Personnel; Protection; Protocols; Robustness; Service oriented architecture; XML;
Conference_Titel :
Military Communications Conference, 2007. MILCOM 2007. IEEE
Conference_Location :
Orlando, FL, USA
Print_ISBN :
978-1-4244-1513-7
Electronic_ISBN :
978-1-4244-1513-7
DOI :
10.1109/MILCOM.2007.4455012