【24h】

Syntactic Validation of Web Services Security Policies

机译:Web服务安全策略的语法验证

获取原文
获取原文并翻译 | 示例

摘要

The Service-Oriented Architecture (SOA) makes application development flexible in such a way that services are composed in a highly distributed manner. However, because of the flexibility, it is often hard for users to define application configurations properly. Regarding the security concerns we address in this paper, though WS-SecurityPolicy provides a standard way to describe security policies, it is difficult for users to make sure that the defined policies are valid. In this paper, we discuss the validation of WS-SecurityPolicy in the context of Service Component Architecture, and propose a method called syntactic validation. Most enterprises have security guidelines, some of which can be described in the format of Web services security messages. There also exist standard profiles for Web services such as the WS-I Basic Security Profile that also prescribes message formats. Since those guidelines and profiles are based on accepted best practices, the syntactic validation is sufficiently effective for practical use to prevent security vulnerabilities.
机译:面向服务的体系结构(SOA)使应用程序开发具有灵活性,从而可以以高度分布式的方式组成服务。但是,由于灵活性,用户通常很难正确定义应用程序配置。关于我们在本文中解决的安全问题,尽管WS-SecurityPolicy提供了描述安全策略的标准方法,但用户很难确保定义的策略有效。在本文中,我们讨论了在服务组件体系结构的上下文中对WS-SecurityPolicy的验证,并提出了一种称为语法验证的方法。大多数企业都有安全准则,其中一些准则可以Web服务安全消息的格式描述。还存在用于Web服务的标准概要文件,例如WS-I基本安全概要文件,它也规定了消息格式。由于这些准则和配置文件基于公认的最佳实践,因此语法验证对于实际使用足以有效防止安全漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号