상세 보기
UNWRAP: An approach on wrapping-attack tolerant SOAP messages
- Nasridinov, Aziz;
- Byun, Jeong-Yong;
- Park, Young-Ho
SCOPUS
4초록
The group of security standards in WS-Security is used to secure exchanges of SOAP messages in Web Service environment. However, despite all of these security standards, SOAP messages can still be vulnerable to types of attacks based on the malicious interception, manipulation, and transmission of SOAP messages. We refer to these types of attacks as XML Signature Wrapping Attacks. In this paper, we propose an approach on wrapping-attack tolerant SOAP messages called UNWRAP. In our approach, we first build SOAP message elements structure using ontology and then attach it in SOAP message header. By validating the ontology in the receiving end, we will be able to detect attacks early in validating process. Also, in our approach, all modifications on SOAP messages are written to a log. So if security failures are occurred, we could check this log and recover from effect of successful execution. Experiments show that the proposed solution has better performance in securing the exchange of SOAP messages. © 2012 IEEE.
키워드
- 제목
- UNWRAP: An approach on wrapping-attack tolerant SOAP messages
- 저자
- Nasridinov, Aziz; Byun, Jeong-Yong; Park, Young-Ho
- 발행일
- 2012-11
- 유형
- Conference Paper
- 저널명
- 2012 Second International Conference on Cloud and Green Computing
- 권
- 2013-FEB
- 페이지
- 794 ~ 798
- 언어
- ENG
- 출판사
- IEEE
- 분량
- 5 페이지
- ISSN
- P 0000-0000