Towards secure web services : performance analysis, decision making and steganography approaches
Bachar Alrouh · Brunel University Research Archive (BURA) (Brunel University London) · 2011
Web services provide a platform neutral and programming language independent technology that supports interoperable machine-to-machine interaction over a network.Clients and other systems interact with Web services using a standardised XML messaging system, such as the Simple Object Access Protocol (SOAP), typically conveyed using HTTP with an XML serialisation in conjunction with other related Web standards.Nevertheless, the idea of applications from different parties communicating together raises a security threat.The challenge of Web services security is to understand and consider the risks of securing a Web-based service depending on the existing security techniques and simultaneously follow evolving standards in order to fill the gap in Web services security.However, the performance of the security mechanisms is fraught with concerns due to additional security contents in SOAP messages, the higher number of message exchanges to establish trust, as well as the extra CPU time to process these additions.As the interaction between service providers and requesters occurs via XML-based SOAP messages, securing Web services tends to make these messages longer than they would be otherwise and consequently requires interpretation by XML parsers on both sides, which reduces the performance of Web services.The work described in this thesis can be broadly divided into three parts, the first of which is studying and comparing the performance of various security profiles applied on a Web service tested with different initial message sizes.The second part proposes a multi-criteria decision making framework to aid Web services developers and architects in selecting the best suited security profile that satisfies the different requirements of a given application during the development process in a systematic, manageable, and effective way.The proposed framework, based on the Analytical Hierarchy Process (AHP) approach, incorporates not only the security requirements, but also the performance considerations as well as the configuration constraints of these security profiles.The framework is then validated and evaluated using a scenario-driven approach to demonstrate situations where the decision making framework is used to make informed the kind people around me.First and foremost, I am grateful to my supervisor, Dr George Ghinea, who has offered me invaluable support and guidance throughout my Ph.D. with his knowledge and patience.I owe my sincerest gratitude to