DocumentCode :
3127557
Title :
SOAP-based Secure Conversation and Collaboration
Author :
Rahaman, Mohammad Ashiqur ; Schaad, Andreas
Author_Institution :
SAP Res., Mougins
fYear :
2007
fDate :
9-13 July 2007
Firstpage :
471
Lastpage :
480
Abstract :
Web services in different trust boundaries interact with each other via SOAP messages to realize functionality in a collaborative environment. Exchanging SOAP messages for remote service invocation has gained wide acceptance among web service developers. Several web service security standards are widely deployed aiming at securing exchanges of a single SOAP message and a conversation of SOAP messages among partners in a collaborative environment. Concerns have been raised about the possibility of XML rewriting attacks within this context and their early detection. In this paper, we demonstrate such possible attacks with respect to WS* policy based scenarios to set a security context and to use a security context for conversations of SOAP messages. We show how our proposed SOAP Account [21] solution could be applied for early detection of XML rewriting attacks, specifically regarding secure SOAP-based conversations. A simulation-based performance analysis and comparison of our SOAP Account approach vs. a WS* policy based approach complements our observations.
Keywords :
Web services; XML; authorisation; groupware; SOAP-based secure conversation; Web service security; XML rewriting attack; collaborative environment; simple object access protocol; Analytical models; Collaboration; Cryptography; Measurement standards; Performance analysis; Security; Service oriented architecture; Simple object access protocol; Web services; XML;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Web Services, 2007. ICWS 2007. IEEE International Conference on
Conference_Location :
Salt Lake City, UT
Print_ISBN :
0-7695-2924-0
Type :
conf
DOI :
10.1109/ICWS.2007.167
Filename :
4279633
Link To Document :
بازگشت