A new security framework against Web services' XML attacks in SOA
Narges Shahgholi, Mir Ali Seyyedi, Mehran Mohsenzadeh, Saleh Hafez Qorani · 2011
Service-Oriented Architecture (SOA) is an architectural style whose primary goal is to achieve minimal dependency among interacting software agents. And as with all new technologies, it comes with its share of challenges. Of particular difficulty is the challenge of securing a service oriented system. Since Web services supply a significant way to provide SOA requirements, any brought up issues, like security of SOA, can be related to Web services. On the other hand, Web services are well-known XML1_based technologies. So the security of Web services can be directly affected by XML security. In this study, a new security framework is proposed which aims to defend main XML threats, especially WSDL attacks in an SOA environment. To the best of our knowledge, it is for the first time that such a practical solution has been offered, which not only handle one aspect of XML vulnerabilities like SOAP2messages but, also try to defend WSDL3threats, in an SOA environment.