A Guided Web Service Security Testing Method

S. Salva · InTech eBooks · 2012

Will-be-set-by-IN-TECHis able to take into account response delays.Our approach takes a Web Service specification and applies abstract test patterns on the operation set to generate test requirements called test purposes.These ones, which guide the tests, are then synchronized with the specification to produce the test case suite.The latter checks the satisfiability of the test relation secure, which formally defines the security level between the implementation and its specification combined with test purposes.The Amazon E-commerce Web Service (AWSECommerceService) Amazon ( 2009) is illustrated as an example on which we apply our method.Another part of the book chapter is dedicated to the experimentation of the method on existing Web Services with an academic tool.The obtained results demonstrate a dramatic lack of security in many Web Services since 11 percent dot not satisfy the restrictions given by our security test patterns.This book chapter is structured as follows: Section 2 provides an overview of the Web Service paradigm and on some related works about Web Service security testing.Sections 3 and 4 describe the Web service and test pattern modelling respectively.The testing method is detailed in Section 5.In Section 6, we discuss some experimentation results, the test coverage and the complexity of the method.Finally, Section 7 gives some perspectives and conclusions. Web services security overviewWeb Services are "self contained, self-describing modular applications that can be published, located, and invoked across the Web" Tidwell (2000).To ensure the Web Service interoperability, the WS-I organization has suggested profiles, and especially the WS-I basic profile WS-I organization (2006), composed of four major axes: the Web Service interface description with the WSDL language (Web Services Description Language World Wide Web Consortium ( 2001)), the definition and the construction of XML messages, based upon the Simple Object Access Protocol (SOAP World Wide Web consortium (2003)), the service discovery in UDDI registers (Universal Description, Discovery Integration Specification (2002)), and the Web service security, which is obtained by using the HTTPS protocol.It is surprising to notice that security was the poor relation during the rush to Web Services and it is manifest that the HTTPS protocol was not sufficient to fulfill the security requirements of service-based applications.We can now find a tremendous set of documents and specifications related to Service security.The WS-security standard (Web Service Security OASIS consortium ( 2004)) gathers most of them.This document describes a SOAP rich extension to apply security to Web services by bringing message encryptions, message signing, security token attachment, etc.Both the policy requirements of the server side and the policy capability of the client side can be expressed by means of the WS-Policy specification.Nevertheless, this one is "only" SOAP-based, and defines requirements on encryption, signing or token mechanisms.Higher level rules cannot be expressed with WS-Policy.Besides these specifications, several academic papers Gruschka & Luttenberger (2006); ISO/IEC (2009); Singh & Pattterh (2010) and the OWASP organization OWASP (2003) focused on Service security in regard to access control by decomposing it into several criteria: availability, integrity, confidentiality, authorization, authentication and freshness and by proposing recommendations for each one.Each criterion can be also modelled formally by means of security rules written with languages such as XACML (eXtensible Access Control Markup Language OASIS standards organization (2009)), Nomad (Security Model with Non 196 Emerging Informatics -Innovative Concepts and Applications www.intechopen.com How to referenceIn order to correctly reference this scholarly work, feel free to copy and paste the following: Sébastien Salva (2012).A Guided Web Service Security Testing Method, Emerging Informatics -Innovative Concepts and Applications, Prof. Shah Jahan Miah (Ed.),

Read the paper · More papers on PaperTik