首页> 外文期刊>Information and software technology >Intelligent security and access control framework for service-oriented architecture
【24h】

Intelligent security and access control framework for service-oriented architecture

机译:面向服务的体系结构的智能安全性和访问控制框架

获取原文
获取原文并翻译 | 示例
           

摘要

One of the most significant difficulties with developing Service-Oriented Architecture (SOA) involves meeting its security challenges, since the responsibilities of SOA security are based on both the service providers and the consumers. In recent years, many solutions to these challenges have been implemented, such as the Web Services Security Standards, including WS-Security and WS-Policy. However, those standards are insufficient for the new generation of Web technologies, including Web 2.0 applications. In this research, we propose an intelligent SOA security framework by introducing its two most promising services: the Authentication and Security Service (NSS), and the Authorization Service (AS). The suggested autonomic and reusable services are constructed as an extension of WS-~* security standards, with the addition of intelligent mining techniques, in order to improve performance and effectiveness. In this research, we apply three different mining techniques: the Association Rules, which helps to predict attacks, the Online Analytical Processing (OLAP) Cube, for authorization, and clustering mining algorithms, which facilitate access control rights representation and automation. Furthermore, a case study is explored to depict the behavior of the proposed services inside an SOA business environment. We believe that this work is a significant step towards achieving dynamic SOA security that automatically controls the access to new versions of Web applications, including analyzing and dropping suspicious SOAP messages and automatically managing authorization roles.
机译:开发面向服务的体系结构(SOA)的最重大困难之一就是应对其安全性挑战,因为SOA安全性的责任是基于服务提供者和使用者的。近年来,已经针对这些挑战实施了许多解决方案,例如Web服务安全标准,包括WS-Security和WS-Policy。但是,这些标准不足以用于新一代Web技术,包括Web 2.0应用程序。在本研究中,我们通过介绍其两个最有前途的服务(身份验证和安全服务(NSS)和授权服务(AS))来提出一个智能SOA安全框架。建议的自主性和可重用服务是WS-〜*安全标准的扩展,并添加了智能挖掘技术,以提高性能和有效性。在这项研究中,我们应用了三种不同的挖掘技术:有助于预测攻击的关联规则,用于授权的在线分析处理(OLAP)多维数据集和用于促进访问控制权限表示和自动化的集群挖掘算法。此外,还探索了一个案例研究来描述SOA业务环境中所提议服务的行为。我们认为,这项工作是实现动态SOA安全性的重要一步,该安全性将自动控制对Web应用程序新版本的访问,包括分析和删除可疑SOAP消息以及自动管理授权角色。

著录项

  • 来源
    《Information and software technology》 |2010年第2期|220-236|共17页
  • 作者单位

    Department of Computer Science, Faculty of Computers and Informatics. Suez Canal University, The Old Campus, tsmailia. Egypt;

    Department of Electrical and Computer Engineering, Faculty of Engineering. The University of Western Ontario, London, ON. Canada N6A 5B9;

    Department of Electrical and Computer Engineering, Faculty of Engineering. The University of Western Ontario, London, ON. Canada N6A 5B9;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    SOA; web services; intelligent security; web 2.0; data mining;

    机译:SOA;网页服务;智能安全;Web 2.0;数据挖掘;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号