首页> 外文OA文献 >Security attack ontology for web services
【2h】

Security attack ontology for web services

机译:Web服务的安全攻击本体

摘要

Web services (WS) have become a significant part of the Web because of such attractive features as simple to use, platform independence, and XML/SOAP support. However, these features make WS vulnerable to many new and inherited old security threats. Semantic WS, which are capable of publishing semantic data about their functional and nonfunctional properties, add even more security issues. Now, it becomes easier to attack WS because their semantic data is publicly available. To register and prevent these attacks, especially distributed attacks, new distributed firewalls and intrusion detection systems (F/IDS) have to be applied. However, these F/IDS can be developed by different vendors and they do not have the way to cooperate with each other. This problem can be solved if various F/IDS share a common vocabulary, which can be based on ontologies, to allow them to interact with each other. In this paper, we describe WS security threats and state that they have to be analysed and classified systematically in order to allow the development of better distributed defensive mechanisms for WS using F/IDS. We choose ontologies and OWL/OWL-S over taxonomies because ontologies allow different parties to evolve and share a common understanding of information which can be reasoned and analysed automatically. We develop the security attack ontology for WS and illustrate the benefits of using it with an example.
机译:Web服务(WS)由于易于使用,平台独立性和XML / SOAP支持等吸引人的功能而成为Web的重要组成部分。但是,这些功能使WS容易遭受许多新的和继承的旧安全威胁。语义WS能够发布有关其功能和非功能属性的语义数据,从而增加了更多的安全问题。现在,由于其语义数据是公开可用的,因此攻击WS变得更加容易。为了注册并防止这些攻击,特别是分布式攻击,必须应用新的分布式防火墙和入侵检测系统(F / IDS)。但是,这些F / IDS可以由不同的供应商开发,并且它们无法相互合作。如果各种F / IDS共享可以基于本体的通用词汇表,以允许它们彼此交互,则可以解决此问题。在本文中,我们描述了WS安全威胁,并指出必须对其进行系统地分析和分类,以允许使用F / IDS为WS开发更好的分布式防御机制。我们选择本体论和OWL / OWL-S来代替分类法,因为本体论允许不同的各方发展并共享对信息的共识,这些信息可以自动推理和分析。我们为WS开发了安全攻击本体,并通过示例说明了使用它的好处。

著录项

  • 作者

    Vorobiev Artem; Han Jun;

  • 作者单位
  • 年度 2006
  • 总页数
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号