首页> 外文会议>IEEE International Conference on Technologies for Homeland Security >Cyber security for service oriented architectures in a Web 2.0 world: An overview of SOA vulnerabilities in financial services

Cyber security for service oriented architectures in a Web 2.0 world: An overview of SOA vulnerabilities in financial services

机译:Web 2.0 World中服务面向服务的网络安全性:金融服务中SOA漏洞的概述



Service oriented architecture is fast becoming ubiquitous enterprise software architecture standard in public and private sector alike. Study of literature and current attacks suggests that with the proliferation of Web API and RESTFul services, the attack vectors prioritized by OWASP top 10, including but not limited to cross site scripting (XSS), cross site request forgery (CSRF), injection, direct object reference, broken authentication and session management now equally apply to web services. In addition service oriented architecture relies heavily on XML/RESTFul web services which are vulnerable to XML Signature Wrapping Attack, Oversize Payload, Coercive parsing, SOAP Action Spoofing, XML Injection, WSDL Scanning, Metadata Spoofing, Oversized Cryptography, BPEL State Deviation, Instantiation Flooding, Indirect Flooding, WS-Addressing spoofing and Middleware Hijacking to name a few. In this paper, we review various such security issues pertaining to service oriented architecture. These and similar techniques, have been employed by Anonymous and other hacktivists, resulting in denial of service attacks on financial applications. While discussing the national security perils of hacktivism, there is an excessive focus on network layer security, and the application layer perspective is not always part of the discussion. In this research, we provide background information and rationale for securing application layer vulnerabilities to facilitate true defense in depth approach for cyber security.
机译:面向服务的架构快速成为公共和私营部门的无处不在的企业软件架构标准。文学和当前攻击的研究表明,随着Web API和RESTful服务的扩散,由OWASP前10名优先考虑的攻击向量,包括但不限于跨站点脚本(XSS),跨站点请求伪造(CSRF),注射,直接对象引用,损坏的身份验证和会话管理现在同样适用于Web服务。另外,面向服务的架构依赖于XML / RESTful Web服务易受XML签名包装攻击的攻击,超大有效载荷,强制解析,肥皂动作欺骗,XML注入,WSDL扫描,元数据欺骗,超大加密,BPEL状态偏差,实例化泛滥,间接洪水,WS-risting欺骗和中间件劫持到少数几个。在本文中,我们审查了与服务导向架构有关的各种这些安全问题。这些和类似的技术已被匿名和其他黑客活动受雇,导致对财务应用的服务攻击。虽然讨论了Hacktivis的国家安全危险,但在网络层安全性过度侧重,并且应用层的角度并不总是讨论的一部分。在这项研究中,我们提供了用于保护应用层漏洞的背景信息和理由,以便于网络安全深度方法的真实防御。



  • 外文文献
  • 中文文献
  • 专利


京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号