【24h】

Security Controls Applied to Web Service Architectures

机译:安全控件应用于Web服务体系结构

获取原文
获取原文并翻译 | 示例

摘要

Security certification assesses the security posture of a software system to verify its compliance with diverse, pre-specified security controls identified by guidelines from NIST and the US Department of Defense. Service-oriented architectures (SOA) are difficult to certify because they require compliance verification over a mix of local, global, and interaction criteria dictated by the policies of the participating services and SOA governance. Web services further contribute to this difficulty because they lack direct methods to express security controls. Besides being understandable, the method of expression should indicate potential problems complying with chosen services. This paper presents a method for configuring of web service standards to enforce security requirements on service interaction specification documents within a SOA. The outcome serves as a mechanism to direct the population of constraints derived from security controls within standards specification documents, such as WS-Policy. We focus on security controls for auditing and how these can be enforced in an SOA. We introduce a reusable architecture to notate the comparison of security controls across services.
机译:安全认证评估软件系统的安全状况,以验证其是否符合NIST和美国国防部指南中确定的各种预先指定的安全控制措施。面向服务的体系结构(SOA)难以认证,因为它们要求对参与服务的策略和SOA治理所规定的本地,全局和交互标准进行合规性验证。 Web服务进一步加剧了这一困难,因为它们缺乏表达安全控制的直接方法。除了可以理解之外,表达方式还应指出符合所选服务的潜在问题。本文提出了一种用于配置Web服务标准以对SOA中的服务交互规范文档强制执行安全性要求的方法。结果是一种机制,用于指导从标准规范文档(例如WS-Policy)中的安全控制派生的约束总数。我们关注于审计的安全控制以及如何在SOA中实施这些安全控制。我们引入了可重用的体系结构来表示跨服务的安全控制的比较。

著录项

  • 来源
  • 会议地点 San Diego CA(US);San Diego CA(US)
  • 作者

    R. Baird; R. Gamble;

  • 作者单位

    Software Engineering and Architecture Team Department of Computer Science University of Tulsa 800 S. Tucker Drive Tulsa, OK 74104;

    Software Engineering and Architecture Team Department of Computer Science University of Tulsa 800 S. Tucker Drive Tulsa, OK 74104;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 计算机软件;
  • 关键词

  • 入库时间 2022-08-26 14:02:57

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号