...
首页> 外文期刊>Security and Communications Networks >A histogram-based method for efficient detection of rewriting attacks in simple object access protocol messages
【24h】

A histogram-based method for efficient detection of rewriting attacks in simple object access protocol messages

机译:基于直方图的有效检测简单对象访问协议消息中的重写攻击的方法

获取原文
获取原文并翻译 | 示例
           

摘要

In order to secure the content of simple object access protocol (SOAP) messages in Web services, several security standards of Web service security, such as XML digital signature, are used. However, the content of a SOAP message, protected with XML digital signature, can be altered without invalidating the signature. Existing methods for detecting XML rewriting attacks are inefficient because the cost of performing detection operation is linear to the height of the SOAP message tree. Thus, each element of SOAP message needs to be accessed and checked. In this paper, we propose an efficient method for detecting XML rewriting attacks on SOAP messages using a histogram. With our method, once the source of attacks is identified, we save it in the form of a histogram, which enables us to maintain a statistical information about the location of the attack in the SOAP message. We can use this information to detect attacks in the future and thus avoid unnecessary check of all elements in the SOAP message. Experiments show that our methods outperform existing methods by several times in many cases. Copyright (c) 2014 John Wiley & Sons, Ltd.
机译:为了保护Web服务中简单对象访问协议(SOAP)消息的内容,使用了几种Web服务安全性的安全标准,例如XML数字签名。但是,可以更改受XML数字签名保护的SOAP消息的内容,而不会使签名无效。用于检测XML重写攻击的现有方法效率不高,因为执行检测操作的成本与SOAP消息树的高度成线性关系。因此,需要访问和检查SOAP消息的每个元素。在本文中,我们提出了一种使用直方图检测SOAP消息的XML重写攻击的有效方法。使用我们的方法,一旦确定了攻击源,便以直方图的形式保存它,这使我们能够维护有关攻击在SOAP消息中位置的统计信息。我们可以使用此信息来检测将来的攻击,从而避免不必要地检查SOAP消息中的所有元素。实验表明,在许多情况下,我们的方法要比现有方法好几倍。版权所有(c)2014 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号