A Business Process Oriented Approachto Secure Web Services
Idir Bakdi, Jochen Speyerer · Journal of the Association for Information Systems · 2004
Recently, interest in Web Services has grown throughout the IT community.Especially when it comes to application integration, the employment of Web Services seems to be a promising approach.But despite the advantages of this technology, its deployment, particularly in the inter-organizational domain, remains very sparse.As studies show, companies are reluctant to use it mainly due to security concerns.In this paper we show how to improve the security of Web Services protecting them against "semantic" attacks by considering entire business processes instead of single method invocations.We propose a solution consisting of an authorization engine, which makes its decisions about the admissibility of a given call taking the relations between successive requests into account.Further, we sketch an implementation and explain how a modeling formalism such as the Business Process Execution Language for Web Services (BPEL4WS) can help to realize it.Concluding with an analysis of weak points, we pinpoint possible areas of future research activities.