Title :
SOA and Web Services: New Technologies, New Standards - New Attacks
Author :
Jensen, Meiko ; Gruschka, Nils ; Herkenhöner, Ralph ; Luttenberger, Norbert
Abstract :
Being regarded as the new paradigm for Internet communication, Web Services have introduced a large number of new standards and technologies. Though founding on decades of networking experience, Web Services are not more resistant to security attacks than other open network systems. Quite the opposite is true: Web Services are exposed to attacks well-known from common Internet protocols and additionally to new kinds of attacks targeting Web Services in particular. Along with their severe impact, most of these attacks can be performed with minimum effort from the attacker´s side. In this paper we present a list of vulnerabilities in the context of Web Services. To proof the practical relevance of the threats, we performed exemplary attacks on widespread Web Service implementations. Further, general countermeasures for prevention and mitigation of such attacks are discussed.
Keywords :
Communication standards; Computer crime; Cryptography; Security; Service oriented architecture; Simple object access protocol; Transportation; Web and internet services; Web services; XML;
Conference_Titel :
Web Services, 2007. ECOWS '07. Fifth European Conference on
Conference_Location :
Halle, Germany
Print_ISBN :
978-0-7695-3044-4
DOI :
10.1109/ECOWS.2007.9