Semantics-Aware Perimeter Protection [chapter]

Marco Cremonini, Ernesto Damiani, Pierangela Samarati
2004 IFIP International Federation for Information Processing  
Web services security is becoming a critical concern for any organization adopting the XML-based Web services approach to application integration. While many access control techniques for Web services are becoming available, several issues still need to be solved in order to correctly split the burden of securing Web services between the perimetral and the service level. In this paper, a technique is presented able to make perimetral defences semantics-aware. Application-level semanticsaware
more » ... ewalls enforce filtering rules directly on SOAP messages based on the nature of the services they request. Our semantics-aware firewalls rules are written using a flexible XML-based syntax that allows sharing metadata concepts with service level access control policies, supporting complex security policies that integrate perimetral defences with access control. Moreover, they can be quickly integrated into organizations' existing infrastructure, deployed rapidly and scaled as needed. Also, they integrate easily with existing infrastructure and can be operated by current staff, potentially achieving a low total cost of ownership with respect to service level solutions.
doi:10.1007/1-4020-8070-0_17 fatcat:mfa4likuv5dl5kvtm6n2bgslhy