首页> 外文会议>International Conference on Semantic Web and Web Services >Event-based SOAP Message Validation for WS-SecurityPolicy-Enriched Web Services
【24h】

Event-based SOAP Message Validation for WS-SecurityPolicy-Enriched Web Services

机译:基于事件的SOAP消息验证WS-SecurityPolicy的Web服务

获取原文

摘要

To enable checking of SOAP messages for compliance to a given security policy, extensions to the classical "Schema-only" validation of SOAP messages are required. These extensions check, if the WS-Security elements found in a SOAP message fulfill the Web Service security specification that is laid down in the WS-SecurityPolicy document. In this paper, we discuss to what extent the proposed extended validation of SOAP messages can be accomplished by an event-based validation system. We prefer this type of processing for use in network appliances like e.g. Web Service-level firewalls, because it is suited to resist DoS attacks that aim at memory exhaustion. We identify some of the constraints on the use of both WS-Security and WS-SecurityPolicy that must be introduced to allow for event-based parsing, and finally present an initial prototype for extended validation together with some performance figures.
机译:要启用检查SOAP消息以使符合给定的安全策略,因此需要对经典“架构”验证SOAP消息的扩展。如果SOAP消息中找到的WS-Security元素满足WS-SecurityPolicy文档中的WS-Security Security规范,则这些扩展选项检查。在本文中,我们讨论了基于事件的验证系统可以在多大程度上进行SOAP消息的扩展验证。我们更喜欢这种处理,以便在网络设备中使用,如例如, Web服务级防火墙,因为它很适合抵制瞄准内存耗尽的DOS攻击。我们确定了必须引入WS-Security和WS-SecurityPolicy的一些限制,以允许基于事件的解析,并且最终呈现用于扩展验证的初始原型以及一些性能数字。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号