Title :
UNWRAP: An Approach on Wrapping-Attack Tolerant SOAP Messages
Author :
Nasridinov, Aziz ; Jeong-Yong Byun ; Young-Ho Park
Author_Institution :
Dept. of Comput. Eng., Dongguk Univ., Gyeongju, South Korea
Abstract :
The group of security standards in WS-Security is used to secure exchanges of SOAP messages in Web Service environment. However, despite all of these security standards, SOAP messages can still be vulnerable to types of attacks based on the malicious interception, manipulation, and transmission of SOAP messages. We refer to these types of attacks as XML Signature Wrapping Attacks. In this paper, we propose an approach on wrapping-attack tolerant SOAP messages called UNWRAP. In our approach, we first build SOAP message elements structure using ontology and then attach it in SOAP message header. By validating the ontology in the receiving end, we will be able to detect attacks early in validating process. Also, in our approach, all modifications on SOAP messages are written to a log. So if security failures are occurred, we could check this log and recover from effect of successful execution. Experiments show that the proposed solution has better performance in securing the exchange of SOAP messages.
Keywords :
Web services; XML; computer network security; digital signatures; ontologies (artificial intelligence); protocols; SOAP message element structure; SOAP message exchange security; SOAP message header; SOAP message manipulation; SOAP message transmission; UNWRAP; WS-security; Web service environment; XML signature wrapping attacks; attack detection; attack vulnerability; malicious interception; ontology validation; security failures; security standards; wrapping-attack tolerant SOAP messages; Digital signatures; Ontologies; Simple object access protocol; Wrapping; XML; SOAP message; XML Signature Wrapping Attacks; ontology;
Conference_Titel :
Cloud and Green Computing (CGC), 2012 Second International Conference on
Conference_Location :
Xiangtan
Print_ISBN :
978-1-4673-3027-5
DOI :
10.1109/CGC.2012.122