Intelligent security cycle: A rule based run time malicious code detection technique for SOAP messages

Ahmad Mohsin, Sundas Asghar, Tariq Naeem · 2016

Service Oriented Architecture (SOA), based on producer consumer model, is vulnerable for malicious code attacks. Web Services are prone to malicious code attacks due to the non-availability of state of the art detection and filtration techniques. There has been considerable work on Web Services security in the domain of query classification based on XML structured message. However, there is lack of research work on malicious code detection based on independent platforms. During the detection process a scheme should be maintained in a way which supports the current state of threat and as well as the coming threats. A rule-based intelligent security cycle, for malicious code detection, filtration and threat analysis of SOAP Messages is presented in this research paper. The proposed technique suggests addressing malicious code detection early in the design phase of a Web Service. In order to validate this technique, a case study was devised to detect and filter malicious code using rule based SOAP service composition. Moreover, the results showed that by applying this technique the capability of SOAP Web Service to detect malicious code attacks at runtime was significantly improved.

Read the paper · More papers on PaperTik