On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

October 11th, 2005

Security: standards aren't enough

Posted by Joe McKendrick @ 8:12 am

Categories: General, Web Services

Tags:

A lot of people worry about the security of Web services transactions, and rightfully so. However, some experts are concerned that we’re taking a ham-handed approach to Web services security, and worrying too much about the wrong types of threats. Such concern was voiced recently in a ZDNET commentary by Scott Morrison, director, architecture and security at Layer 7 Technologies.

"Web services expose higher-value transactions to attack, and therefore have a proportionately higher risk," he wrote. "Decoupling messages from the security measures ‘baked in’ to applications, platforms and transport protocols brings risk. We need to be aware of the dangers with the Web services model, and be concerned about the risks associated with deploying them, even within the relatively benign shores of our internal networks."

Morrison makes the point that we shouldn’t waste our time and resources worrying about individual hacker attacks directed exclusively against your system. The real problems come from mass attacks which target all servers across the globe.  These include API attacks, including attachments, the biggest overlooked area, which attempt to crash your applications or directly exploit them for malicious purposes. Another threat is infrastructure attacks (including parser attacks, such as well-documented Web services provider weaknesses) that aim to deny access to services or paralyze your infrastructure. Then there’s transaction attacks, which may insert bogus transactions or suppress legitimate ones.

Web services security standards help, but only so far, Morrison adds. The OASIS Web Services Security (WSS) model "provides a framework to implement message-based security that can defend against a number of well-known attacks. But it describes a means to secure messages; it doesn’t necessarily tell you how to do it. Similarly, WS-I Basic Security Profile constrains and disambiguates OASIS WSS for the purposes of promoting interoperability, but it doesn’t explicitly tell you how to make your messages secure."

The key to effective security is a centralized, consistent, infrastructure-based approach to security, not an application-by-application approach. Ironically, Morrison observes, "this is the antithesis of loose coupling - the reason for adopting Web services and SOA in the first place - where a security model is baked into the code; it defeats the best attempts to compose future applications. Web services security needs to be drawn out of individual applications and managed centrally and declaratively."

 

Joe McKendrickJoe McKendrick is an author and consultant with deep knowledge and insights regarding trends and developments in the technology industry. See his full profile and disclosure of his industry affiliations.


Email Joe McKendrick

Subscribe to Service Oriented via Email alerts or RSS.

  • Talkback
  • Most Recent of 4 Talkback(s)
I don't believe he missed the boat by much
I don't think the internet has been subject to unrestricted electronic warfare as of yet. While you're right that to date the mass attacks have been primarily distractions the fact remains if EW tact... (Read the rest)
Posted by: maldain Posted on: 10/12/05 You are currently: a Guest | | Terms of Use
Morrison misses the boat  cburgess | 10/12/05
I don't believe he missed the boat by much  maldain | 10/12/05
... One more time ......  An_Axe_to_Grind | 10/12/05
He spends so much time grinding that axe...  Iain D | 10/12/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here