{"title":"Web Services Policy Generation Based on SLA Requirements","authors":"Alaeddine Saadaoui, S. Scott","doi":"10.1109/CIC.2017.00029","DOIUrl":null,"url":null,"abstract":"The deployment of web services in dynamic environments like cloud infrastructures offers flexible solutions to provide required resources to maintain web services availability and performance during peak demands. However, the lack of control and monitoring tools on the cloud infrastructure exposes the deployed web services to security threats. While there are security solutions that focus on web services, there is no tool to generate security policies documents. Therefore, this paper proposes an SLA (Service Level Agreement) based framework to generate web services policy documents. The framework allows the service provider to define security needs of a web service based on its WSDL (Web Service Description Language) description and generate required policies. The proposed framework is extensible and satisfies three web service security aspects: transport, authentication, and message encryption.","PeriodicalId":156843,"journal":{"name":"2017 IEEE 3rd International Conference on Collaboration and Internet Computing (CIC)","volume":"21 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 IEEE 3rd International Conference on Collaboration and Internet Computing (CIC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CIC.2017.00029","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5
Abstract
The deployment of web services in dynamic environments like cloud infrastructures offers flexible solutions to provide required resources to maintain web services availability and performance during peak demands. However, the lack of control and monitoring tools on the cloud infrastructure exposes the deployed web services to security threats. While there are security solutions that focus on web services, there is no tool to generate security policies documents. Therefore, this paper proposes an SLA (Service Level Agreement) based framework to generate web services policy documents. The framework allows the service provider to define security needs of a web service based on its WSDL (Web Service Description Language) description and generate required policies. The proposed framework is extensible and satisfies three web service security aspects: transport, authentication, and message encryption.