Find White Papers
Home
About Us
List Your Papers
    
> Reactivity > Executive Guide to Web Services Security

Executive Guide to Web Services Security

White Paper Published By: Reactivity

Businesses are rapidly adopting Web services to provide new levels of integration between applications. By comparison with earlier data communications techniques, Web services are faster and cheaper to develop, quicker to deploy, and easier to adapt to emerging business needs. This paper discusses the special security challenges posed by the use of Web services, and how to secure networks against them.



Tags : 
web services, web service management, web service deployment, web service, web service security, network security, secure networks, reactivity

Reactivity
Published:  Aug 21, 2009
Type:  White Paper
Length:  10 pages

Executive Guide to
Web Services Security
ABSTRACT
Businesses are rapidly adopting Web services to provide new levels of integration between applications. By comparison with earlier data-communications techniques, Web services are faster and cheaper to develop, quicker to deploy, and easier to adapt to emerging business needs.
Although these benefits are real, and more and more companies are adopting Web services for that reason, the same characteristics that make Web services quicker and cheaper to deploy, more robust and more flexible than older methods, also make them vulnerable to new kinds of security risks and opportunities.
This paper discusses the special security challenges posed by the use of Web services, and how to secure networks against them.
© 2006, Reactivity, Inc.WHITEPAPER
Contents
Special Advantages, Special Risks??????????????????????????????????????????? 3 Understanding XML Virus Attacks???????????????????????????????????????????????????8Making Sense of Standards ????????????????????????????????????????????????????? 4 Defending Denial of Service Attacks??????????????????????????????????????????????9Which Standard Fits Your Need???????????????????????????????????????????????????????5 Making the Architecture Work????????????????????????????????????????????????? 9Trust and Threats in the Web Services Paradigm???????????????????? 6 The Importance of Logging????????????????????????????????????????????????????????????10Malicious Intent or Human Error?????????????????????????????????????????????????????6 Conclusion???????????????????????????????????????????????????????????????????????????????? 10Defending Against Identity Attacks ???????????????????????????????????????????????6 About Reactivity?????????????????????????????????????????????????????????????????????? 10
© 2006, Reactivity, Inc. www.reactivity.com The Executive Guide to Web Services Security | WHITEPAPER
Special Advantages, Special Risks The universal nature of the Internet enables these unscrupulous users to intercept legitimate communications and connect The great advantage of the Internet is that it is universally to others' systems. Similarly, the standardization of Internet accessible. Because it consists of thousands of freely- protocols and data formats enables them to read, understand, communicating networks all over the world, the Internet and even forge communications between legitimate users.provides a communication infrastructure that reaches everyone, an infrastructure that a business can use without significant new capital investment. FedGovSimilarly, Internet standards define communication protocols and data formats that enable anyone to make network connections and transmit data, and rely on the fact that their Univmessages will be received and understood. BigCoInternet
When someone sends a message in a standard format using a Kwikstandard protocol, the protocol ensures that the message can Martbe delivered correctly, and the data format ensures that the receiver can read it. Mom
FedGovThe openness of XML and Web services lets you cost-effectively conduct strategic operations with customers and partners. However, openness cuts both ways.BigCoInternetUniv
FedKwikMartGov
Mom
BigCoInternetUniv
Unfortunately, these very advantages make Web services and other Internet technologies uniquely vulnerable to attack. KwikMartBecause the Internet reaches everyone, anyone can use it-not just honest people engaged in legitimate business, but vandals, Momcriminals and other abusers of the network.
© 2006, Reactivity, Inc. www.reactivity.com The Executive Guide to Web Services Security | WHITEPAPER
While standards-based solutions claiming to solve "the security effort in creating services; it's important that you choose the problem" flood the market, the problem encompasses more standards that best support your needs. The answers to these than security. Securing your Web services must take into questions can help you begin: account multiple connections to individual vendors, strategic . Which standards are the most established and reliable? partners, and customers. These connections are revenue Approved or still emerging?pipelines, so measures must assure security and enable rapid . Which standards are most beneficial to support for our customer acquisition. That's why stand... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search