Securities Perspective in ESB-Like XML-Based Attacks
Ayush Kumar Gupta, Ravinder Kumar Verma · Advances in business information systems and analytics book series · 2017
In today's world where technology drastically changing and we supposed to believe that layer 7 protocol HTTP(s) is sufficient from the security perspective. But it's not, malicious user or hackers are so prudent in their attacks that most of the breaches occurs at layer 7 i.e. HTTP/HTTPS. And XML based attacks either of XML parser attack, XML generator attack or XXE Denial of service attack etc. are all comes in the first place of OWASP TOP 10 vulnerability. HTTPS connection is not sufficient enough to stop masqueraders or attackers, as XML injection or XSS attack doesn't care about the encryption of data as it deals with the scripts mainly. ESB where considered as pluggable device where all the existing systems or IT infrastructure devices can be exposed to new applications and cut the time and cost by implementing this. But data travels on the bus is always be preferred on XML and here it's all security & privacy issues comes into picture and the same has been highlighted in this chapter throughout.