Home | Business News | Browse by Publication | X | XML Journal

Malicious attack protection for XML Web services: communication behind a firewall isn''t always safe.

Publication: XML Journal
Publication Date: 01-DEC-03
Format: Online - approximately 1925 words
Delivery: Immediate Online Access
Full Article Title: Malicious attack protection for XML Web services: communication behind a firewall isn''t always safe.(Web Services)

Article Excerpt
As the vast majority of Global 2000 organizations are transitioning pilot projects into production, the hype over XML Web services might finally be turning into reality. Web services usage has varied from simple data information sharing between two applications to corporate-wide, service-oriented architecture (SOA) initiatives.

**********

There are many reasons why Web services are gaining traction, including ease-of-use, their loosely coupled nature, and effectiveness in application integration with the lowest cost and least effort required. Yet the use of Web services is not without challenges. Security continues to be a top concern, and with good reason, as Web services interfaces are different than Web site pages and cannot rely on the same mechanisms to protect them.

Security as Top Priority

Security has taken a priority role in organizations as the threat of breached assets and downtime is compounded with regulatory requirements, including HIPAA and Gramm-Leach Bliley. Chief security officers (CSO) are now common-place and are charged with maintaining not only digital integrity, but physical security as well. As these C-level executives are pulled in two opposite directions, it is up to internal developers, QA staff, internal operations, and compliance officers to be aware of their company's security and auditing requirements.

With regards to XML security, Web services interfaces are generally much more complex, expose more functionality, and have a more sophisticated levcl of interactions than Web site pages. Though network firewalls do a good job of stopping network-level attacks, they do not provide the granularity or the proper rule sets to handle complex application attacks. Implementation of Secure Sockets Layer (SSL) and other existing technologies is useful but hinders value in scalability and interoperability costs.

The majority of early Web services projects have been conducted internally, behind...

Read the FULL article now - Try Goliath Business News - FREE!   
You can view this article PLUS...

  • Over 5 million business articles
  • Hundreds of the most trusted magazines, newswires, and journals (see list)
  • Premium business information that is timely and relevant
  • Unlimited Access

Now for a Limited Time, try Goliath Business News - Free for 3 Days!
Tell Me More   Terms and Conditions

Get Goliath Business News for 1 year - Just $99 (Save 65%)
Tell Me More   Terms and Conditions

Already a subscriber? Log in to view full article



More articles from XML Journal
4th annual International Developer Conference & Expo., December 01, 2003
Finding the fit for XSLT: filling a hole in the puzzle.(Standards), December 01, 2003
Open integration and security: XML firewalls provide ease of integrati..., December 01, 2003
XML acceleration: the truth behind the myths: don't assume that bandwi..., December 01, 2003
The challenge of Web services security inside the firewall: a true sto..., December 01, 2003

Looking for additional articles?
Search our database of over 3 million articles.

Looking for more in-depth information on this industry?
Search our complete database of Industry & Market reports by text, subject, publication name or publication date.

About Goliath
Whether you're looking for sales prospects, competitive information, company analysis or best practices in managing your organization, Goliath can help you meet your business needs.

Our extensive business information databases empower business professionals with both the breadth and depth of credible, authoritative information they need to support their business goals. Whether it be strategic planning, sales prospecting, company research or defining management best practices - Goliath is your leading source for accurate information.