Title :
Security solutions for Web Service attacks in a dynamic composition scenario
Author :
Sindhu, S.M. ; Kanchana, R.
Author_Institution :
Dept. of Comput. Sci. & Eng., Anna Univ., Chennai, India
Abstract :
Web Services can be invoked from anywhere through internet without having enough knowledge about the implementation details. In some cases, single service cannot accomplish user needs. One or more services must be composed which together satisfy the user needs. Therefore, security is the most important concern not only at single service level but also at composition level. Several attacks are possible on SOAP messages communicated among Web Services because of their standardized interfaces. Examples of Web Service attacks are oversize payload, SOAPAction spoofing, XML injection, WS-Addressing spoofing, etc. Most of the existing works provide solution to ensure basic security features of Web Services such as confidentiality, integrity, authentication, authorization, and non-repudiation. Very few of the existing works provide solutions such as schema validation and schema hardening for attacks on Web Services. But these solutions do not address and provide attack specific solutions for SOAP messages communicated between Web Service. Hence, it is proposed to provide solutions for two of the prevailing Web Service attacks. Since new types of Web Service attacks are evolving over time, the proposed security solutions are implemented as APIs that are pluggable in any server where the Web Service is deployed.
Keywords :
Web services; application program interfaces; authorisation; data integrity; protocols; service-oriented architecture; API; Internet; SOA; SOAP messages; SOAPAction spoofing; WS-Addressing spoofing; Web service attacks; XML injection; authentication; authorization; confidentiality; dynamic composition scenario; integrity; nonrepudiation; schema hardening; schema validation; security solutions; service oriented architecture; simple object access protocol; Electronic publishing; Information services; Lead; Security; Simple object access protocol; Standards; SAS API; SOAP; UDDI; WSAS API; WSDL; Web Services;
Conference_Titel :
Advanced Communication Control and Computing Technologies (ICACCCT), 2014 International Conference on
Conference_Location :
Ramanathapuram
Print_ISBN :
978-1-4799-3913-8
DOI :
10.1109/ICACCCT.2014.7019163