Home > Ask the SOA Experts > Questions & Answers > What security concerns does WS-Security address?
Ask The SOA Expert: Questions & Answers
EMAIL THIS

What security concerns does WS-Security address?

Donald Flinn EXPERT RESPONSE FROM: Donald Flinn

Pose a Question
Other SOA Categories
Meet all SOA Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 02 December 2003
What security concerns are addressed by the WS-Security standard? Very briefly describe how each of these concerns are handled.

>
The overarching solution that WS-Security provides is security for multi-hop XML messaging. In particularly, it is designed to provide the security for SOAP messages. At a high level it supplies a means to transmit authentication evidence pertaining to the initiator and, if different, the sender of the message by means of security tokens. This evidence may be used by the receiver to verify the initiator and sender of the SOAP message. The other two major constituents of WS-Security are digital signatures, which support integrity, i.e. proof that the message has not changed, and XML encryption, which supports confidentiality, i.e. encrypts the message so that only the intended receiver can read it.

Some of the specific threats that WS-Security can protect against are listed below. The syntax is the threat followed by the defense.

Un-authenticated sender – Use tokens and digital signature

Unauthorized receiver – Use XML encryption

Replay – Digital signatures alone are not enough to defeat replay. Other parts of the specification must be used with d-sig, such as timestamp, sequence number and nonce.

Token Substitution – Sign both the security header and the body.

Message modification – Sign the message

Message substitution - Sign both the security header and message body

Man-in-the-middle – Sign both the request and response

Multiple tokens using the same key – Require that the token be included in WS-Security header.

While WS-Security provides the means to protect against these attacks, it is up to the users of WS-Security to apply the appropriate protections depending on the level of risk management required. For example, if a sender is requesting a casual stock quote they might not deem it necessary to use the above protection mechanisms. However, if they were buying a stock then they would want to protect against the above threats. The receiver of the request may have different risk requirements and thus require some of above mechanisms, which are not important to the sender. For example, for the request for a quote, they may require authentication and additionally may require different level of authentication for different value transactions.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
SOA security
Trends 2008: Outsourcing, agile development
SOA prompts changes in quality assurance
Top 10 issues with mashups
Partnership aims at governance for SOA and Web 2.0
SOA, Web services create software security challenges
SecureCloud via SaaS
AmberPoint offers SOA visibility
Talking SOA appliances
Using JSON for Ajax security
The case against WS-Security

SOA security strategy
Common Web application security exploits and how to stop them
CA adds federated security to fight growing threats to SOA
Weak encryption creates SOA vulnerabilities
SOA runtime major step for Eclipse – Milinkovich
IBM, Microsoft, Google join OpenID
SOA needs RIA – Burton Group
Green computing takes center stage
Software AG boosts SOA security
SOA governance called vital to security
SOA, Web services create software security challenges

WS-Security (Web services security standards)
The technology of Web Service Security
Web 2.0 at the old ballgame
SOA complicated by ESB proliferation
BPEL4People and WS-HumanTask get reference implementation
Liberty offers Web 2.0 open source security
The case against WS-Security
SOA governance, security concerns drive XACML interop
New BizTalk Services rolling out
Will acquisitions stifle SOA innovation?
Burton: WS-* specs good, but SOA security needs more

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Web Services Trust Language  (SearchSOA.com)
WS-Security  (SearchSOA.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



SOA Governance White Papers - BPM, EDA, IT Governance
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2001 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts