Title
A Security Evaluation Method Based on Threat Classification for Web Service.
Abstract
Web service is a distributed computing model constructed on the basis of open standard technology with the characteristics of loose coupling, language neutrality, platform-independence, etc., how to efficiently evaluate the security of Web service is a challenging research topic. Current researches concern more about the testing of Web service and rarely about the issue of service security evaluation. On the basis of analyzing the current Web services in terms of security threats, a Web service security evaluation method based on threat classification is proposed, which can process security evaluation to Web service from different angles of view, such as spoofing, tampering, repudiation, message disclosure, denial of service and elevation of privilege, and can provide a referential evaluation index of Web service security for the users through the threat modeling and evaluating the degree of security. Finally, a case study on SOA application is discussed in detail, experimental results show that the proposed model works efficiently, it can provide valuable reference to check out security vulnerabilities of Web service and help to optimize the system's security design. © 2011 ACADEMY PUBLISHER.
Year
DOI
Venue
2011
10.4304/jsw.6.4.595-603
JSW
Keywords
Field
DocType
web service,security classification
Security testing,World Wide Web,Computer security,Computer science,Threat model,Security service,Web modeling,Web application security,Security information and event management,Web service,Computer security model
Journal
Volume
Issue
ISSN
6
4
null
Citations 
PageRank 
References 
3
0.45
4
Authors
4
Name
Order
Citations
PageRank
Li Jiang130.79
Hao Chen271.28
Fei Deng330.45
Qiusheng Zhong430.45