A Security Meta-Language for SOAP Messaging
Robert J. Baird, Rose Gamble · INTERNATIONAL JOURNAL OF NEXT-GENERATION COMPUTING · 2014
Due to the increasing availability of competing service providers and the decreasing costs of moving services online recent trends in information systems development direct focus towards leveraging complex distributed system interconnections. To that end service-oriented architectures and web services have become commonplace in busi- ness and government application development because they facilitate rapid development and deployment through the use of standards that document interfaces and the message exchanges. However, the hierarchically related standards have complex documented interconnections and dependencies. The configuration of the services and the messages they exchange must adhere to the mandates established in these documents, yet the guidance offered by each specification is often too expansive for software developers to understand without assistance. Incorrect configurations can lead to messaging configurations that result in software vulnerabilities, system unavailability, service disruption, and ultimately loss of protected information. In this paper, we devise a Security Meta Language for secure web service communication based on a dynamic modeling framework. The framework models expert knowledge gathered from the intensive analysis of message protection protocols specified in web service standards. We outline a process to create and modify secure messaging directives through a case study investigating X.509 PKI tokens and digital signatures for SOAP communication.