DocumentCode
1973014
Title
SOA-Scanner: An Integrated Tool to Detect Vulnerabilities in Service-Based Infrastructures
Author
Antunes, Nuno ; Vieira, Marco
Author_Institution
Dept. of Inf. Eng., Univ. of Coimbra, Coimbra, Portugal
fYear
2013
fDate
June 28 2013-July 3 2013
Firstpage
280
Lastpage
287
Abstract
Service Oriented Architectures are nowadays used in a wide range of organizations to support critical daily operations. Although the underlying services should behave in a secure manner, they are often deployed with bugs that can be maliciously exploited. The characteristics of service-based environments open the door to security challenges that must be handled properly, including services under the control of multiple providers and dynamism of interactions and compositions. This paper presents an extensible tool able to widely test such infrastructures for vulnerabilities. The tool is based in an iterative process that uses interface monitoring to automatically monitor and discover the existing services, resources and interactions, and applies different testing approaches depending on the level of access to each existing services. Two case studies has been developed do demonstrate the tool, and results show that the tool can effectively be used in different service-based scenarios, under different access conditions to the target services.
Keywords
iterative methods; organisational aspects; service-oriented architecture; SOA-scanner; iterative process; organizations; service oriented architectures; service-based infrastructures; Benchmark testing; Instruments; Monitoring; Runtime; Security; Web services; SOA; security; security testing; vulnerability detection; web-services;
fLanguage
English
Publisher
ieee
Conference_Titel
Services Computing (SCC), 2013 IEEE International Conference on
Conference_Location
Santa Clara, CA
Print_ISBN
978-0-7695-5026-8
Type
conf
DOI
10.1109/SCC.2013.28
Filename
6649706
Link To Document