Introduction to Assessing and Securing Web Services.
Christoff Breytenbach · 2005
The primary purpose of the paper is to provide an introduction to security related problems in web services implementations, describe approaches used to identify these issues, and provide brief recommendations to resolve these problems. Questions such as the following are important in this respect: • How does the web service authenticate the service consumer or client? • How does the client authenticate the web service? • Is data protected between the web service provider and client? • Does the web service provide an adequate authorisation framework to ensure user privileges are uniformly and consequently enforced? • Does the application properly clean client or requester input? Identification and exploitation of vulnerabilities in the above areas will be practically illustrated. Even though tools are important in this area, the analyst has to have a good understanding of the technology in question. The paper will focus on the high-level critical thinking that needs to be applied in assessing and securing web services.