Design and Implementation of an XML Firewall

Yin-soon Loh, Wei‐Chuen Yau, Chien-thang Wong, Wai-chuen Ho · 2006

Web services provide a means to communicate easily between applications to exchange information. However, the lack in security features provided by Web services creates a window of opportunities for attackers. This paper presents the design of the architecture and filtering policies for an XML firewall. The firewall is implemented using Java language. We conduct a series of tests for verifying the functionality of the firewall. The results of the tests show that the firewall is capable of allowing valid SOAP messages while blocking malicious SOAP messages that contain attacks such as oversized payloads, recursive pay loads, and SQL injections

Read the paper · More papers on PaperTik