首页> 外文学位 >A Security Meta Language for using web services security standards.
【24h】

A Security Meta Language for using web services security standards.

机译:使用Web服务安全性标准的安全性元语言。

获取原文
获取原文并翻译 | 示例

摘要

Recently, the trend in information systems has shifted towards the interconnection of complex distributed systems due to the increasing availability of competing service providers and the decreasing costs of moving services online. To that end service oriented architectures with web services have become commonplace in business and government application development. Web services facilitate application implementation and deployment through the use of standards that clearly document interfaces and the message exchanges. However, the reliance on these standards has become problematic and cumbersome, especially when configuring secure systems that require explicit message properties. The standards are highly interconnected and hierarchical in nature, and correctly establishing their configuration is problematic due to the massive amounts of data that must be reviewed prior to implementation. Incorrect specifications can lead to disastrous application configurations resulting in software vulnerabilities, system unavailability and service disruption, and ultimately loss of secure protected information. The goal of this work is a reusable framework in the form of a meta-language to model secure SOAP messages. In this paper we define a Security Meta Language (SML) as a two-part model and dynamic process that documents the security relevant portions of the standards for their consistent, comprehensive, and correct application. The language contains a static portion that grounds the model in the web service standards using their documentation and data structures, and a dynamic portion that catalogs different security controls as they are applied to SOAP messages. We outline a dynamic reusable process to add new directives to the database when application requirements change or new security concerns are found. We overview all UML stereotypes and present a case study that demonstrates the correct use of the SML to guide secure message configuration in a distributed system environment.
机译:最近,由于竞争性服务提供商的可用性不断提高以及在线移动服务的成本不断降低,信息系统的趋势已转向复杂的分布式系统的互连。为此,带有Web服务的面向服务的体系结构已在企业和政府应用程序开发中变得司空见惯。 Web服务通过使用清楚地记录接口和消息交换的标准来促进应用程序的实现和部署。但是,对这些标准的依赖变得成问题且麻烦,尤其是在配置需要显式消息属性的安全系统时。这些标准本质上是高度互连和分层的,并且由于必须在实施之前检查大量数据,因此正确建立其配置是有问题的。不正确的规格可能导致灾难性的应用程序配置,从而导致软件漏洞,系统不可用性和服务中断,并最终丢失安全的受保护信息。这项工作的目标是采用可重复使用的框架,以元语言的形式对安全的SOAP消息进行建模。在本文中,我们将安全元语言(SML)定义为一个由两部分组成的模型和动态过程,该过程记录了标准中与安全性相关的各个部分,以确保这些标准的一致性,全面性和正确性。该语言包含一个静态部分,该静态部分使用其文档和数据结构为Web服务标准中的模型奠定基础,以及一个动态部分,在将其应用于SOAP消息时对不同的安全控制进行分类。我们概述了一个动态的可重用过程,以便在应用程序需求发生变化或发现新的安全问题时向数据库添加新的指令。我们概述了所有UML构造型,并提供了一个案例研究,该案例演示了SML的正确用法以指导分布式系统环境中的安全消息配置。

著录项

  • 作者

    Baird, Robert J.;

  • 作者单位

    The University of Tulsa.;

  • 授予单位 The University of Tulsa.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2011
  • 页码 145 p.
  • 总页数 145
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号