• DocumentCode
    1973014
  • Title

    SOA-Scanner: An Integrated Tool to Detect Vulnerabilities in Service-Based Infrastructures

  • Author

    Antunes, Nuno ; Vieira, Marco

  • Author_Institution
    Dept. of Inf. Eng., Univ. of Coimbra, Coimbra, Portugal
  • fYear
    2013
  • fDate
    June 28 2013-July 3 2013
  • Firstpage
    280
  • Lastpage
    287
  • Abstract
    Service Oriented Architectures are nowadays used in a wide range of organizations to support critical daily operations. Although the underlying services should behave in a secure manner, they are often deployed with bugs that can be maliciously exploited. The characteristics of service-based environments open the door to security challenges that must be handled properly, including services under the control of multiple providers and dynamism of interactions and compositions. This paper presents an extensible tool able to widely test such infrastructures for vulnerabilities. The tool is based in an iterative process that uses interface monitoring to automatically monitor and discover the existing services, resources and interactions, and applies different testing approaches depending on the level of access to each existing services. Two case studies has been developed do demonstrate the tool, and results show that the tool can effectively be used in different service-based scenarios, under different access conditions to the target services.
  • Keywords
    iterative methods; organisational aspects; service-oriented architecture; SOA-scanner; iterative process; organizations; service oriented architectures; service-based infrastructures; Benchmark testing; Instruments; Monitoring; Runtime; Security; Web services; SOA; security; security testing; vulnerability detection; web-services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Services Computing (SCC), 2013 IEEE International Conference on
  • Conference_Location
    Santa Clara, CA
  • Print_ISBN
    978-0-7695-5026-8
  • Type

    conf

  • DOI
    10.1109/SCC.2013.28
  • Filename
    6649706