Home > Ask the SOA Experts > Questions & Answers > What do you think are the major security concerns for Web Services architecture?
Ask The SOA Expert: Questions & Answers
EMAIL THIS

What do you think are the major security concerns for Web Services architecture?

Paul Butterworth EXPERT RESPONSE FROM: Paul Butterworth

Pose a Question
Other SOA Categories
Meet all SOA Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 20 September 2002
What do you think are the major security concerns for Web Services architecture?

>

When it comes to security, the issues usually revolve around confidentiality, authentication, integrity, non-repudiation and authorization. However, Web services bring additional challenges to the security landscape. A few things to keep in mind:

  • Application, Platform and Transport Independence: Web services systems are meant to be distributed, federated and heterogeneous. You'll want to make sure that your security spans all your Web services, regardless of what those Web services are built on, the applications they interface with and the underlying transports that are used.

  • Flexibility: Your security must provide fine-grained control of any Web service operation, be enforced at any point that it is needed and be appropriate for requesters both inside and outside your organization.

  • End-to-end Security: You need to allow for the participation of intermediaries, without jeopardizing your business-critical systems

  • Leverage Existing Security Infrastructure: No sense in starting again from scratch. Instead, you'll want to integrate with your existing systems--authentication, transport, LDAP, etc.

  • Standards: To ensure system interoperability, your security must be based on existing and evolving standards

  • Without addressing these security concerns, most enterprises are restricting Web services to pilot projects or to applications that do not extend beyond their firewalls. The good news is that much progress has been made in developing security standards to stem these concerns. Additionally, the structure of Web services messages makes it possible to leverage mid-stream message content (e.g., order size) and context (e.g., user identity or time-of-day) to apply additional security measures.

    Where should you start? Probably with authentication. If you don't know who the requester is you aren't going to be able to address further security issues--unless you're happy with an anonymous SSL connection, that is. You have to decide what authentication mechanism makes the most sense in your environment and then determine if it properly integrates with your Web service infrastructure. (No point in deciding to use certificates if your infrastructure doesn't easily allow certificate-based authentication for your services.) Once you have an authenticated user, the next likely problem is authorization--who can do what. It's likely you will need to do something more complex than "user X can send a message to service Y." You may need the capability to say "user X can send a message to service Y only if the message containing data X is authorized to update." Once basic authentication and authorization are in place you can address additional security issues such as support for Web services intermediaries, encryption and signature of SOAP elements and non-repudiation.

    Standards bodies such as OASIS, W3C and IETF are working with major platform and security vendors (IBM, Microsoft, Sun, BEA, VeriSign, Netegrity, AmberPoint, etc.) and customers to create specifications that augment the existing security infrastructures and address some of the challenges faced within service-oriented architectures. A few that are gaining industry traction are XML Signatures & Encryption, WS-Security, SAML, XACML and Liberty.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



SOA Governance White Papers - BPM, EDA, IT Governance
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2001 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts