Insert title here

Case Studies

Bringing your idea to life and in front of billions of eyes



Security is critical to web services. However, neither XML-RPC nor SOAP specifications make any explicit security or authentication requirements.
Web Services (Santosh Shinde)

Security is critical to web services. However, neither XML-RPC nor SOAP specifications make any explicit security or authentication requirements.

There are three specific security issues with web services −

  • Confidentiality
  • Authentication
  • Network Security

Confidentiality

If a client sends an XML request to a server, can we ensure that the communication remains confidential?

Answer lies here −

  • XML-RPC and SOAP run primarily on top of HTTP.
  • HTTP has support for Secure Sockets Layer (SSL).
  • Communication can be encrypted via SSL.
  • SSL is a proven technology and widely deployed.

A single web service may consist of a chain of applications. For example, one large service might tie together the services of three other applications. In this case, SSL is not adequate; the messages need to be encrypted at each node along the service path, and each node represents a potential weak link in the chain. Currently, there is no agreed-upon solution to this issue, but one promising solution is the W3C XML Encryption Standard. This standard provides a framework for encrypting and decrypting entire XML documents or just portions of an XML document. You can check it 

Authentication

If a client connects to a web service, how do we identify the user? Is the user authorized to use the service?

The following options can be considered but there is no clear consensus on a strong authentication scheme.

  • HTTP includes built-in support for Basic and Digest authentication, and services can therefore be protected in much the same manner as HTML documents are currently protected.
  • SOAP Digital Signature (SOAP-DSIG) leverages public key cryptography to digitally sign SOAP messages. It enables the client or server to validate the identity of the other party. Check it 
  • The Organization for the Advancement of Structured Information Standards (OASIS) is working on the Security Assertion Markup Language (SAML).

Network Security

There is currently no easy answer to this problem, and it has been the subject of much debate. For now, if you are truly intent on filtering out SOAP or XML-RPC messages, one possibility is to filter out all HTTP POST requests that set their content type to text/xml.

Another alternative is to filter the SOAPAction HTTP header attribute. Firewall vendors are also currently developing tools explicitly designed to filter web service traffic.

 


Comments
Add Comment     See All Comments


oawviwey@gmail.com
nfl nike authentic jerseys the bar silk twist dress los angeles dodgers fitted hat lyrics leopard shirt outfit boston red sox hat flex fit black kit name nike air vortex retro calmission http://www.calmission.com/


ncbrio@gmail.com
black tie guest wedding dresses nike air revolution sky hi black patent adidas superstar track pants red nike air max 2014 unisexo rojo.negro efornak http://www.efornak.com/


mzqsqw@gmail.com
reebok tennessee titans cortland timmons 31 blue replica jerseys sale nike roshe run svart polka dot new balance 877 walking shoe noirkhaki adidas eqtnike air max zero svart fridayair jordan retro 6 violet lakers outfit air max white with flowers pandora jewelry heart necklace masalokumak http://www.masalokumak.com/


arkomuj@gmail.com
reebok tennessee titans cortland timmons 31 blue replica jerseys sale nike roshe run svart polka dot new balance 877 walking shoe noirkhaki adidas eqtnike air max zero svart fridayair jordan retro 6 violet lakers outfit air max white with flowers pandora jewelry heart necklace alhudahuda http://www.alhudahuda.net/


vppsve@gmail.com
nike kobe 9 low graunike tiempo nero legacyair jordan 1 hvit and greyair jordan 30 university bleu redskins t shirt walmart for cheaplem barney jersey for cheapchelsea shirt 2009 for cheapgrimaldi rocco 22 jersey for cheap super bowl 51 shirt for cheap monster energy hats free shipping xfinity 4k suspender dress plus size air max 90 flyknit grey noirnike zoom hyperfuse todas negronike for kids gold pink shoesyellow onitsuka tiger bruce lee taedits http://www.taedits.com/

-->
Tech Divinity cloud enable faster performance