Title :
SOAP-based Secure Conversation and Collaboration
Author :
Rahaman, Mohammad Ashiqur ; Schaad, Andreas
Author_Institution :
SAP Res., Mougins
Abstract :
Web services in different trust boundaries interact with each other via SOAP messages to realize functionality in a collaborative environment. Exchanging SOAP messages for remote service invocation has gained wide acceptance among web service developers. Several web service security standards are widely deployed aiming at securing exchanges of a single SOAP message and a conversation of SOAP messages among partners in a collaborative environment. Concerns have been raised about the possibility of XML rewriting attacks within this context and their early detection. In this paper, we demonstrate such possible attacks with respect to WS* policy based scenarios to set a security context and to use a security context for conversations of SOAP messages. We show how our proposed SOAP Account [21] solution could be applied for early detection of XML rewriting attacks, specifically regarding secure SOAP-based conversations. A simulation-based performance analysis and comparison of our SOAP Account approach vs. a WS* policy based approach complements our observations.
Keywords :
Web services; XML; authorisation; groupware; SOAP-based secure conversation; Web service security; XML rewriting attack; collaborative environment; simple object access protocol; Analytical models; Collaboration; Cryptography; Measurement standards; Performance analysis; Security; Service oriented architecture; Simple object access protocol; Web services; XML;
Conference_Titel :
Web Services, 2007. ICWS 2007. IEEE International Conference on
Conference_Location :
Salt Lake City, UT
Print_ISBN :
0-7695-2924-0
DOI :
10.1109/ICWS.2007.167