• DocumentCode
    541935
  • Title

    Attacks on Web Services and mitigation schemes

  • Author

    Patel, Vipul ; Mohandas, Radhesh ; Pais, Alwyn R.

  • Author_Institution
    Information Security Research Lab, National Institute of Technology Karnataka, Surathkal, India
  • fYear
    2010
  • fDate
    26-28 July 2010
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Web Services have become dependable platform for e-commerce and many B2B models. Extensive adaptation of Web Services has resulted in a bunch of standards such as WS-Security, WS-Trust etc. to support business and security requirements for the same. Majority of the web services are offered over Http with Simple Object Access Protocol (SOAP) as an underlying exchange infrastructure. This paper describes attacks targeted at Web Services such as XML injection, XSS injection, HTTP header manipulation, sending stale message and other protocol specific attacks. We have used XML Re-Writing mechanism to perform “timestamp modification attack” and WS-Trust, WS-SecureConversation protocols attack. Schemas stated in WSDL file may not be accurate enough to validate messages effectively; Schemas should reflect structure of all possible genuine requests. Hence, we have proposed a new self-adaptive schema hardening algorithm to obtain fine-tuned schema that can be used to validate SOAP messages more effectively. We have also proposed mitigation techniques to counter attacks using MIME/DIME attachments.
  • Keywords
    Companies; Cryptography; Servers; Simple object access protocol; XML; Attachment Scanner; Attacks on Web Services; Frankenstein Message; Schema Hardening; Schema Validation; WS-Security; WS-Trust; XML Injection; XSS Injection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Cryptography (SECRYPT), Proceedings of the 2010 International Conference on
  • Conference_Location
    Athens
  • Type

    conf

  • Filename
    5741656