Preventing Service Oriented Denial of Service (PreSODoS): A Proposed Approach

S. Padmanabhuni, Vineet Singh, Senthil Mani, Abhishek Chatterjee
{"title":"Preventing Service Oriented Denial of Service (PreSODoS): A Proposed Approach","authors":"S. Padmanabhuni, Vineet Singh, Senthil Mani, Abhishek Chatterjee","doi":"10.1109/ICWS.2006.102","DOIUrl":null,"url":null,"abstract":"Today Web services have grown in context of both business to business (B2B) and business to customer (B2C) applications. Web services are the most popular mode of implementing service oriented architecture (SOA). With this growth and acceptance in the industry, the role of security is crucial. Most of the existing security mechanisms in Web services like XML encryption, digital signatures, user tokens etc. provide security on one basic assumption that source of the request is legitimate. But a typical denial of service attacker can use these sources as reflectors and play around with the contents of a Web service body to create an attack scenario. In this paper, we propose PreSODoS - a framework to detect and prevent XML based denial of service (XDoS) attacks on Web services based applications. The framework relies on content introspection to detect any XDoS possibility. We use a Patricia trie based representation so that the schemas and the request messages can be compared and validated in a performance efficient manner. PreSODoS is capable of detecting any repetitive request message and sense an attack scenario and trigger corresponding prevention mechanisms","PeriodicalId":408032,"journal":{"name":"2006 IEEE International Conference on Web Services (ICWS'06)","volume":"30 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2006-09-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"41","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2006 IEEE International Conference on Web Services (ICWS'06)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICWS.2006.102","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 41

Abstract

Today Web services have grown in context of both business to business (B2B) and business to customer (B2C) applications. Web services are the most popular mode of implementing service oriented architecture (SOA). With this growth and acceptance in the industry, the role of security is crucial. Most of the existing security mechanisms in Web services like XML encryption, digital signatures, user tokens etc. provide security on one basic assumption that source of the request is legitimate. But a typical denial of service attacker can use these sources as reflectors and play around with the contents of a Web service body to create an attack scenario. In this paper, we propose PreSODoS - a framework to detect and prevent XML based denial of service (XDoS) attacks on Web services based applications. The framework relies on content introspection to detect any XDoS possibility. We use a Patricia trie based representation so that the schemas and the request messages can be compared and validated in a performance efficient manner. PreSODoS is capable of detecting any repetitive request message and sense an attack scenario and trigger corresponding prevention mechanisms
预防面向服务的拒绝服务(PreSODoS):一种建议的方法
今天,Web服务在企业对企业(B2B)和企业对客户(B2C)应用程序的上下文中都有增长。Web服务是实现面向服务的体系结构(SOA)的最流行的模式。随着行业的增长和接受,安全的作用至关重要。Web服务中大多数现有的安全机制(如XML加密、数字签名、用户令牌等)提供的安全性都基于一个基本假设,即请求的来源是合法的。但是典型的拒绝服务攻击者可以使用这些源作为反射器,并摆弄Web服务主体的内容来创建攻击场景。在本文中,我们提出了PreSODoS——一个检测和防止对基于Web服务的应用程序的基于XML的拒绝服务(XDoS)攻击的框架。该框架依赖于内容自省来检测任何XDoS的可能性。我们使用基于Patricia trie的表示,以便可以以一种性能有效的方式比较和验证模式和请求消息。PreSODoS能够检测任何重复的请求消息,感知攻击场景并触发相应的防御机制
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信