DocumentCode
3054079
Title
Experimental Evaluation of Web Service Frameworks in the Presence of Security Attacks
Author
Oliveira, Rui André ; Laranjeiro, Nuno ; Vieira, Marco
Author_Institution
Dept. of Inf. Eng., Univ. of Coimbra, Coimbra, Portugal
fYear
2012
fDate
24-29 June 2012
Firstpage
633
Lastpage
640
Abstract
Web services are increasingly being used to provide critical operations in business-to-business and safety-critical environments. In these environments the exploitation of security vulnerabilities may result in major damages in the services infrastructures, financial or reputation losses to the organizations involved, and other catastrophic consequences for the users and the environment. Web services frameworks are the basis for developers to create and deploy web services, and must provide a robust and secure environment, so that an application can deliver its service, even when in presence of security attacks. In this paper we study the behavior of well-known web services frameworks in the presence of security attacks targeting the core web services specifications, i.e., those enabling basic message exchange functionalities. Results show that frameworks are quite resistant to attacks. However, they also indicate that even very popular and highly tested frameworks can be vulnerable to attacks, with potentially catastrophic consequences for the services being deployed.
Keywords
Web services; security of data; Web service frameworks; Web services specifications; business-to-business environment; message exchange functionalities; safety-critical environment; security attacks; Security; Servers; Simple object access protocol; Testing; XML; security; web service frameworks;
fLanguage
English
Publisher
ieee
Conference_Titel
Services Computing (SCC), 2012 IEEE Ninth International Conference on
Conference_Location
Honolulu, HI
Print_ISBN
978-1-4673-3049-7
Type
conf
DOI
10.1109/SCC.2012.52
Filename
6274200
Link To Document