首页> 外文期刊>Computer networks >A vulnerabilities analysis and corresponding middleware security extensions for securing NGN applications
【24h】

A vulnerabilities analysis and corresponding middleware security extensions for securing NGN applications

机译:漏洞分析和相应的中间件安全扩展,用于保护NGN应用程序

获取原文
获取原文并翻译 | 示例

摘要

International standard bodies such as the Parlay Group, 3GPP (Third Generation Partnership Project), and ETSI TISPAN describe an applications middleware in the form of open service access (OSA)/Parlay Application Programming Interfaces and Parlay X Web Services which allow multimedia applications to be implemented on top of different fixed and mobile network types. These established middleware services are also applicable to the new IP Multimedia Subsystem (IMS) forming the heart of emerging next generation networks. The main objective of this kind of middleware services is to simplify and unify service creation and - as applications are realized in so-called application servers which can be flexibly connected to dedicated network gateways - also to expose available network capabilities to third parties. This results in an inherent increase of security threats and increases the risk of attacks on network resources. This article describes the security requirements and challenges to Web services-based NGN middleware. Based on this analysis the paper presents the middleware security mechanisms at application level providing end-to-end security based on standard such as XML Digital Signatures, XML Encryption and SAML (Security Assertion Markup Language). Furthermore, we propose additional security means in the form of intrusion detection and prevention (IDP) system protecting applications middleware against SQL injection attacks which are not mitigated by existing solutions.
机译:诸如Parlay Group,3GPP(第三代合作伙伴计划)和ETSI TISPAN之类的国际标准机构以开放服务访问(OSA)/ Parlay Application Programming Interfaces和Parlay X Web Services的形式描述了应用中间件,这些多媒体中间件可以使多媒体应用成为可能。在不同的固定和移动网络类型上实现。这些已建立的中间件服务也适用于构成新兴的下一代网络核心的新IP多媒体子系统(IMS)。这种中间件服务的主要目标是简化和统一服务创建,并且-当应用程序在可以灵活连接到专用网络网关的所谓应用程序服务器中实现时-还将可用的网络功能暴露给第三方。这导致安全威胁的内在增加,并增加了攻击网络资源的风险。本文介绍了基于Web服务的NGN中间件的安全要求和挑战。基于此分析,本文提出了基于应用程序级别的中间件安全机制,该机制基于XML数字签名,XML加密和SAML(安全断言标记语言)等标准提供端到端的安全性。此外,我们提出了入侵检测和防御(IDP)系统形式的其他安全措施,以保护应用程序中间件免受SQL注入攻击,而现有解决方案无法缓解这种攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号