- 1、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。。
- 2、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 3、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
- 4、该文档为VIP文档,如果想要下载,成为VIP会员后,下载免费。
- 5、成为VIP后,下载本文档将扣除1次下载权益。下载后,不支持退款、换文档。如有疑问请联系我们。
- 6、成为VIP后,您将拥有八大权益,权益包括:VIP文档下载权益、阅读免打扰、文档格式转换、高级专利检索、专属身份标志、高级客服、多端互通、版权登记。
- 7、VIP文档为合作方或网友上传,每下载1次, 网站将根据用户上传文档的质量评分、类型等,对文档贡献者给予高额补贴、流量扶持。如果你也想贡献VIP文档。上传文档
查看更多
AND-302-No Interop No Security How to Build Interoperable Web Service Security
No Interop, No
Security: How to
Build Interoperable
W b S ie erv ce
Security
Pyounguk Cho
Oracle
04/23/09 | Session ID:AND-302
Session Classification: Intermediate
Agenda
Web Service Under Attack
Web Service Security As Defense Measures
W b S i I t bilit S ite erv ce n eropera y vs. ecur y
Building Interoperable Secure Web Services
2
Web
Service
U dn er
Attack
Web Service : What is it?
? Evolution of previous distributed programming
frameworks
– Process Centric
– Platform agnostic
? Web Service core
– XML : Highly structured universal message exchange format
– WSDL : Describes service interfaces
– SOAP :XML-based Transport layer independent protocol for
b iwe serv ce messages
– UDDI : Naming service for web services
? “WS-etc” : other high-level services found in
middleware systems are still evolving
– WS-Policy
– WS-SX/TX/RX
– WS-Eventing
Where is Web Service today?
? Adoption
E b d d t d h t it i– very o y un ers an s w a s
– Ubiquitously adopted and deployed
– Popular for connecting platforms and applications
– Starting to go beyond basics
? What are the pain points?
– Security(interoperability-induced pain)
– Performance
– Complexity (interoperability-induced pain)
Web Service Components
Points to
d i tiUDDI
WSDL
escr p on
Registry
Describes
Service
Finds
Service
Points to
service
Web Service
(JEE SOA
Web Service SOAP
, ,
PL/SQL,
.NET,C/C++,
Legacy …)
Client
(JEE,SOA,.NET,
PL/SQL …) Invokes with
XML Messages
Attack Against Web Service
? Why bother to attack web services?
– Business data : Potentially more rewarding to attackers
– Numerous targets due to high adoption
? Integration(intranet)
? B2Bi(public)
? Web 2.0(AJAX endpoints)
– Bypassing front-end tiers
? What makes web services vulnerable?
– Open architecture
? Protocol
? Service contract/blueprint
– Human readable messages
– Tools
? Client generation
? Message monitoring
? Automated fuzzing
Attack Vectors
? Traditional threat model
– Unauthorized service invocation
Mal
您可能关注的文档
- absolute construction.ppt
- Absolute continuity and convergence in variation for distributions of a functionals of Pois.pdf
- Absolute continuity of the spectrum of a Schrodinger operator with a potential which is per.pdf
- Absolute cross sections for excitation of the 2s S 2p P transition in B ¢ and for electr.pdf
- Absolute frequency measurement of the In$^{+}$ clock transition with a mode-locked laser.pdf
- Absolute Lineshifts - A new diagnostic for stellar hydrodynamics.pdf
- Absolute linear scale.pdf
- Absolute magnitudes for late-type dwarf stars for Sloan photometry.pdf
- Absolute measurement of cerebral.pdf
- Absolute motion parallax weakly determines visual scale in real and virtual environments.pdf
- Anderson 艾德盛 型号对照表.pdf
- andritz-report-2006-en-customer-projects-rolling-mills-and-strip-processing-lines.pdf
- android 自动调整屏幕分辨率.pdf
- Android4.4(4.2)_RDA5991 WIFI3in1调试方法V1.2.pdf
- Android5.0竖向瀑布流RecyclerView+CardView.pdf
- Android_2.2_r1_API中文文档——ImageView.ScaleType.pdf
- Android自动化测试之Monkeyrunner常用操作编程.pdf
- Android题整理.doc
- André Wendt Bounding the Minimal Completion Time Intro Splitting 2 parts Combining Classes.pdf
- Ang et al 2009 JFE high idiosyncratic volatility and low returns.pdf
最近下载
- 苏教版(2024版)七年级上册生物期末复习知识点清单.docx VIP
- 修剪指甲教学课件.pptx VIP
- NB∕T 20006.4-2021 压水堆核电厂用合金钢 第4部分:反应堆压力容器接管嘴用锰-镍-钼钢锻件.pdf
- 《智慧仓储管理》课程标准.doc VIP
- 中国骨质疏松症及骨质疏松性骨折非药物干预防治指南(2025年版)PPT课件解读(2).docx VIP
- 13《少年中国说(节选)》 公开课一等奖创新教学设计.docx VIP
- 【行业研究报告】中国金融科技行业研究报告-2022年4月.pdf VIP
- 品种混杂退化原因PPT.ppt VIP
- 储罐内壁升降作业平台施工方案.doc VIP
- 【竞品分析文档】中国元宇宙产业竞品分析报告-2022年4月.pdf VIP
文档评论(0)