Home > SOA News > Weak encryption creates SOA vulnerabilities
SOA News:
EMAIL THIS

Weak encryption creates SOA vulnerabilities

By Rich Seeley, News Writer
28 Aug 2008 | SearchSOA.com

News on SOA, EAI, Web services
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Weak encryption implementations create vulnerabilities in SOA applications as business data and transactions move back and forth via Web services, says Brian Chess, co-founder and chief scientist of Fortify Software Inc. Other common security issues Fortify has identified in SOA frameworks include weak authentication, vulnerability to replay attack, and XPath injection, he added.

Architects designing service-oriented architecture (SOA) applications need to find a way to be sure the security provisions in their model are actually working when the app goes live, says Chess.

"Nobody is going to tell you necessarily if it's broken," he explained. "If the functionality is there, people won't even know that it has major security problems built into it. And the security problems might not exist in the design. They might only exist in the implementation."

Architects need to know if the implementation is faithful to their design, Chess said. "It is a difficult but critical part of getting security right," he added.

Fortify's chief scientist points out the similar SOA security concerns about the unforeseen consequences of the dynamic interaction of Web services in SOA are expressed by Thomas Erl, author of books on SOA issues. "Because SOA offers the potential to create sophisticated and complex composite solutions," Erl writes, "agnostic services can be subjected to a variety of different usage scenarios, each of which can introduce unique security risks and requirements. In order to design effective service compositions therefore requires that services be prepared for a range of security challenges."

For its part, Fortify has released analysis and testing tools for its Fortify 360 product to provide architects, developers, and others involved in SOA development with ways to identify security vulnerabilities. The new tools do automated source code analysis on a code base and dynamic security testing on a running application, Taylor McKinley, Fortify 360 product manager.

"We have three analyzers," he explained. "One looks at your code statically. One looks at your running application dynamically. And one protects your application in real time."

The analysis and testing tools are designed for the SOA frameworks in use by Fortify's customers, Chess explained. Those released this summer cover:

  • Apache Axis
  • Apache Axis 2
  • IBM WebSphere 6.1
  • Microsoft .NET Web Services Enhancements (WSE) 2.0
  • Microsoft Windows Communication Foundation (WCF)
For more information
Microsoft, Liberty join for Web services identity interop

Best practices of the SOA development lifecycle

"If you have the Fortify 360 Suite and you're looking at analyzing code using our static analyzer when you're scanning one of these SOA frameworks, it will flag an issue and say you haven't properly encrypted this or you don't have a proper authentication within that SOA framework," McKinley explained.

The tools not only flag the vulnerability is also automatically provide the suggested fix for it, he added.



Tags: SOA security toolsService-oriented architecture (SOA) developmentSOA implementationsSOA and Identity managementSOA security strategyVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
SOA security tools
Some Eclipse SOA Tools Projects are archived as work on SCA, modeling, moves ahead
CA adds federated security to fight growing threats to SOA
Faster SOA testing drives iTKO Eclipse release
SOA tools hit UML tipping point
Eclipse Ganymede: Rich Ajax Platform focuses on users
Eclipse Ganymede Part 1: What's in it for SOA?
SOA picture worth 1,000 words for HP
SOA remaking business analyst job
OpenID: Leveraging a widely accepted identity Web service
Layer 7 offers mainframe SOA appliance

Service-oriented architecture (SOA) development
SOA Video Library
Skyway restructures Skyway Builder
Altova updates MissionKit
SOA Tutorials
XAware releases XAware 5.4
Zend released Zend Server 5.0 for PHP applications
At Microsoft P&P Summit, distributed systems head talks
Cisco grows beyond its roots with new Developer Network
Open source and ESBs
Enterprise Architecture is more than a technology

SOA implementations
SOA implementation evolves from open source to Oracle SOA suite
U.S. Coast Guard adopts SOA and ESB to better track ships at sea
SOA Implementation: Should top down meet bottom up?
ESB watered down by EAI, but distinction remains
On the road to SOA – Part 1, Boubez on early insights
On the road to SOA – Part 2, Governance is fundamental
Sparx releases new SoaML profile for Enterprise Architect 7.5
SOA implementation: It's the increments, stupid
Bury SOA inside a larger architectural vision
Enterprise Architecture in the Agile age - Part 1, Styles of EA
SOA implementations Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Service Integration Maturity Model  (SearchSOA.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



SOA Web Services: Application Server, Portals, Java, Microsoft .NET
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2001 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts