首页> 外文期刊>Journal of computer sciences >SSOAM: Automated Security Testing Framework for SOA Middleware in Banking Domain
【24h】

SSOAM: Automated Security Testing Framework for SOA Middleware in Banking Domain

机译:SSOAM:银行域中SOA中间件的自动化安全测试框架

获取原文
           

摘要

In the banking domain, a high level of security must be considered and achieved to prevent a core-banking system from vulnerabilities and attackers. This is especially true when implementing Service Oriented Architecture Middleware (SOAM), which enables all banking e-services to be connected in a unified way and then allows banking e-services to transmit and share information using simple Object Access Protocol (SOAP). The main challenge in this research is that SOAP is designed without security in mind and there are no security testing tools that guarantee a secure SOAM solution in all its layers. Thus, this paper studies and analyzes the importance of implementing secure banking SOAM design architecture and of having an automated security testing framework. Therefore, Secure SOAM (SSOAM) is proposed, which works in parallel with the banking production environment. SSOAM contains a group of integrated security plugins that are responsible for scanning, finding, analyzing and fixing vulnerabilities and also forecasting new vulnerabilities and attacks in all banking SOAM layers.
机译:在银行领域,必须考虑并实现高级别的安全性,以防止核心银行系统受到漏洞和攻击者的攻击。当实施面向服务的体系结构中间件(SOAM)时,尤其如此,它可以使所有银行电子服务以统一的方式连接,然后允许银行电子服务使用简单的对象访问协议(SOAP)传输和共享信息。这项研究的主要挑战是,在设计SOAP时就没有考虑安全性,并且没有安全性测试工具可以保证其所有层的安全SOAM解决方案。因此,本文研究并分析了实施安全银行SOAM设计架构和拥有自动化安全测试框架的重要性。因此,提出了与银行生产环境并行工作的安全SOAM(SSOAM)。 SSOAM包含一组集成的安全性插件,负责扫描,查找,分析和修复漏洞,并预测所有银行SOAM层中的新漏洞和攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号