首页    期刊浏览 2024年09月29日 星期日
登录注册

文章基本信息

  • 标题:A Security Evaluation Method Based on Threat Classification for Web Service
  • 本地全文:下载
  • 作者:Jiang, Li ; Chen, Hao ; Deng, Fei
  • 期刊名称:Journal of Software
  • 印刷版ISSN:1796-217X
  • 出版年度:2011
  • 卷号:6
  • 期号:4
  • 页码:595-603
  • DOI:10.4304/jsw.6.4.595-603
  • 语种:English
  • 出版社:Academy Publisher
  • 摘要:Web service is a distributed computing model constructed on the basis of open standard technology with the characteristics of loose coupling, language neutrality, platform-independence, etc., how to efficiently evaluate the security of Web service is a challenging research topic. Current researches concern more about the testing of Web service and rarely about the issue of service security evaluation. On the basis of analyzing the current Web services in terms of security threats, a Web service security evaluation method based on threat classification is proposed, which can process security evaluation to Web service from different angles of view, such as spoofing, tampering, repudiation, message disclosure, denial of service and elevation of privilege, and can provide a referential evaluation index of Web service security for the users through the threat modeling and evaluating the degree of security. Finally, a case study on SOA application is discussed in detail, experimental results show that the proposed model works efficiently, it can provide valuable reference to check out security vulnerabilities of Web service and help to optimize the system’s security design.
  • 关键词:web service;security classification;security evaluation model;security abilities property
国家哲学社会科学文献中心版权所有