Insert title here

Case Studies

Bringing your idea to life and in front of billions of eyes



Security is critical to web services. However, neither XML-RPC nor SOAP specifications make any explicit security or authentication requirements.
Web Services (Santosh Shinde)

Security is critical to web services. However, neither XML-RPC nor SOAP specifications make any explicit security or authentication requirements.

There are three specific security issues with web services −

  • Confidentiality
  • Authentication
  • Network Security

Confidentiality

If a client sends an XML request to a server, can we ensure that the communication remains confidential?

Answer lies here −

  • XML-RPC and SOAP run primarily on top of HTTP.
  • HTTP has support for Secure Sockets Layer (SSL).
  • Communication can be encrypted via SSL.
  • SSL is a proven technology and widely deployed.

A single web service may consist of a chain of applications. For example, one large service might tie together the services of three other applications. In this case, SSL is not adequate; the messages need to be encrypted at each node along the service path, and each node represents a potential weak link in the chain. Currently, there is no agreed-upon solution to this issue, but one promising solution is the W3C XML Encryption Standard. This standard provides a framework for encrypting and decrypting entire XML documents or just portions of an XML document. You can check it 

Authentication

If a client connects to a web service, how do we identify the user? Is the user authorized to use the service?

The following options can be considered but there is no clear consensus on a strong authentication scheme.

  • HTTP includes built-in support for Basic and Digest authentication, and services can therefore be protected in much the same manner as HTML documents are currently protected.
  • SOAP Digital Signature (SOAP-DSIG) leverages public key cryptography to digitally sign SOAP messages. It enables the client or server to validate the identity of the other party. Check it 
  • The Organization for the Advancement of Structured Information Standards (OASIS) is working on the Security Assertion Markup Language (SAML).

Network Security

There is currently no easy answer to this problem, and it has been the subject of much debate. For now, if you are truly intent on filtering out SOAP or XML-RPC messages, one possibility is to filter out all HTTP POST requests that set their content type to text/xml.

Another alternative is to filter the SOAPAction HTTP header attribute. Firewall vendors are also currently developing tools explicitly designed to filter web service traffic.

 


Comments
Add Comment     See All Comments


yflmpb@gmail.com
nike mercurialx proximo cr7 men's indoor football bootsjordan flight 45 hvit gumkyrie 2 blancoall pink nike lebron ambassador 10 barrett ruud jerseyneue nfl trikots 2021all hardwood classic jerseys 2k21arizona coyotes fanatics james harden first signature chaussurenike flyknit air max blue lagoon videonike air max 2015 slippers all grey shoesblack pink blue nike mercurial vapor ix ic jordan 1 high og bloodlinenike free tr 9 mens blancair huarache utility mens all whitegreen converse chuck 70 blanc towel night dressturtleneck open back dresswhite long hoodie dressnew patan dress girl nike james jerseyraiders hockey jerseynew celtics jerseys 2021tom brady jersey for sale emrefirin http://www.emrefirin.com/


jwzjuvhbe@gmail.com
raptors hat finals for cheap gordie howe shirt air jordan 12 svart and blue san francisco giants low crown hat 2016 air jordan 9 true red miami dolphins custom t shirts balazskoren http://www.balazskoren.com/


yhxcolxoza@gmail.com
adidas superstar sort hvid originalred black blue nike zoom kd 5jordan 3 negro oreoadidas ace 16 bleu laceless marcus smart christmas jerseykraken jersey datewild jersey with north star colorsnuggets 90s jersey 2010 england jerseysuns new jerseys 2022nike lamar jackson jerseygame day football pants mens asics gel noosa tri 9 gray yellownike air max 90 wmns hvid leopardnike air pource 1 low blanc violetadidas samba super rojo purple balenciaga triple sauthentic jordans blanczapatillas nike flex experience rn schwarznike air jordan 3 schwarz cement for verkauf moncler laplance ski jacketmoncler puffer coat menswhite moncler jacket menmoncler grenoble rodenberg quattic http://www.quattic.com/


gqisqi@gmail.com
off shoulder bodycon maxi dressklassy lady dressesmommy and me outfits h mlong skirt winter outfit realtree camouflage atlanta braves hatnew york mets black fitted hat kitsatlanta braves mitchell and ness hat ebaymiami dolphins blackout hat xampp custom notre dame shirtsnike basketball practice uniformsuswnt leggingsredbull hawaiian shirt personalised rings pandorapandora mickey necklacesquare diamond ring pandorapandora avengers charm son of mars jordan 4nike roshe run rojo wolf griskobe 11 negro mamba para ventalunar epic run nike sb blazer low gt black wheat whitenike air zoom 33 pegasus gray running shoeskobe 4kbdark grey air force 1 felicatech http://www.felicatech.com/


sdgqgbxu@gmail.com
moncler vest awake new balance 574 verde and amarillo wedding mermaid dresses new york yankees rainbow hat hatchlings ny ny mens dna woven gilet peach wedding dresses for maids dsis-conf http://www.dsis-conf.net/

-->
Tech Divinity cloud enable faster performance