DocumentCode :
3051764
Title :
Penetration Testing Tool for Web Services Security
Author :
Mainka, Christian ; Somorovsky, Juraj ; Schwenk, Jörg
Author_Institution :
Horst Gortz Inst. for IT Security, Ruhr Univ., Bochum, Germany
fYear :
2012
fDate :
24-29 June 2012
Firstpage :
163
Lastpage :
170
Abstract :
XML-based SOAP Web Services are a widely used technology, which allows the users to execute remote operations and transport arbitrary data. It is currently adapted in Service Oriented Architectures, cloud interfaces, management of federated identities, eGovernment, or millitary services. The wide adoption of this technology has resulted in an emergence of numerous - mostly complex - extension specifications. Naturally, this has been followed by a rise in large number of Web Services attacks. They range from specific Denial of Service attacks to attacks breaking interfaces of cloud providers [1], [2] or confidentiality of encrypted messages [3]. By implementing common web applications, the developers evaluate the security of their systems by applying different penetration testing tools. However, in comparison to the wellknown attacks as SQL injection or Cross Site Scripting, there exist no penetration testing tools for Web Services specific attacks. This was the motivation for developing the first automated penetration testing tool for Web Services called WS-Attacker. In this paper we give an overview of our design decisions and provide evaluation of four Web Services frameworks and their resistance against WS-Addressing spoofing and SOAPAction spoofing attacks.
Keywords :
SQL; Web services; cloud computing; cryptography; program testing; service-oriented architecture; software performance evaluation; SOAPAction spoofing attacks; SQL injection; WS-Addressing spoofing attacks; WS-Attacker; Web services attacks; XML-based SOAP Web services security; automated penetration testing tool; cloud interfaces; cross site scripting; denial-of-service attacks; eGovernment; encrypted messages; federated identity management; millitary services; service oriented architectures; Security; Servers; Simple object access protocol; Standards; Testing; XML; Penetration Testing Tool; SOAP-based Web services; SOAPAction spoofing; WS-Addressing spoofing; WS-Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Services (SERVICES), 2012 IEEE Eighth World Congress on
Conference_Location :
Honolulu, HI
Print_ISBN :
978-1-4673-3053-4
Type :
conf
DOI :
10.1109/SERVICES.2012.7
Filename :
6274046
Link To Document :
بازگشت