InfoQ

InfoQ

News

My Bookmarks

Login or Register to enable bookmarks for unlimited time.

The content has been bookmarked!

There was an error bookmarking this content! Please retry.

SpringSource's Ben Alex Details Emerging Standards in Application Security

Posted by Srini Penchikala on Jun 05, 2008

Sections
Development,
Architecture & Design
Topics
Security ,
Java
Tags
JavaOne 2008

At JavaOne 2008 conference, Ben Alex from SpringSource talked about the emerging security requirements and standards in enterprise applications and open source frameworks that implement the standards. In the technical session, he discussed the standards like Servlet Security, Java Authentication and Authorization Service (JAAS), CAPTCHA, Single Sign-On (SSO) and Federated Identity using OpenID technology.

Ben started off the presentation with an overview of Servlet and JAAS API and the new security features in Servlet 3.0 Specification (JSR-315) such as the ability to login/logout and Self Registration. He listed the following security concerns that should be taken into consideration when designing a web application:

  • Authentication
  • Authorization
  • Accounting
  • Auditing

Component, State and Transition Security are becoming more important as the web development moves towards component-based web frameworks such as JSF, Spring Web Flow, and JBoss Seam. Spring Web Flow provides a JSF platform model and authorization of States, Flows, and Transitions. It uses Spring Security for authentication and authorization purposes. Spring Security 2 integrates with Java technology-based servlet security and JAAS software. It has a new Security Namespace as well as "Remember Me" support in the latest version.

Completely Automated Public Test to tell Computers and Humans Apart (CAPTCHA) technique is used for mitigating denial of service (DoS) and IP infringement security vulnerabilities. CAPTCHA implementation frameworks include JCaptcha and reCAPTCHA. Java platform support (MIT licensed) for reCAPTCHA is available from the Google project.

In SSO area, Spring Security supports SSO for Microsoft Windows LANs (via Samba JCIFS) and JA-SIG Central Authentication Service (CAS). Another popular technology for Federated Identity is OpenID which is currently supported by many major companies like Sun, IBM, Microsoft, Google, Yahoo, Flickr, LiveDoor, LiveJournal, Orange, and Blogger. Spring Security supports OpenID with OpenID4Java framework.

Ben also talked about advanced web security requirements like method level authorization, JSR-250 for defining method security metadata, Spring Security method metadata, and domain access control. JSR-250 (Common Annotations for the Java platform) defines the annotations like @RunAs(someRole), @RolesAllowed(someRole), @PermitAll(), @DenyAll(), @DeclareRoles(someRole) for method level authorization. These annotations can also be applied on method arguments.

The presentation also included securing web services (WS-Security), RFC-defined Basic (RFC 1945) and Digest (RFC 2617) authentication for remote client and Web 2.0 applications. Securing web services is based on WSS standard (formerly WS-Security) which provides security for SOAP messages. XWSS (part of Metro project) is a Java platform implementation of WSS. XWSS version 3.0 implements OASIS WSS Specification 1.1.

Ben talked about destination authorization when using JMS messaging in web applications. JMS 1.1 API does not provide message integrity or privacy so the JMS providers are expected to provide such features. ActiveMQ messaging framework provides three methods (read, write, and admin) for the authorization requirements. He discussed the message end-point and channel authorization and security mediation service requirements when using an Enterprise Service Bus (ESB) in Java EE applications. ESB security patterns article lists various design patterns to be considered when implementing an ESB container.

The presentation included demonstrations ranging from a simple security requirements of a web login form to implementing application security in a Google Web Toolkit (GWT) application using Spring Security framework.

Srini Penchikala currently works as Security Architect and has 17 yrs of experience in software product management.

No comments

Watch Thread Reply

Educational Content

New-age Transactional Systems - Not Your Grandpa's OLTP

John Hugg discusses high volume transaction processing applications with high and low frequency profiles, and how VoltDB can be used for that purpose.

Cool Code

Kevlin Henney examines code samples to see what can be learned from them starting from the premise that one won’t write great code unless he knows how to read it.

Collaboration: At the Extremities of Extreme

Jason Ayers share the observations he made watching a team of developers collaborating in real time on the same code base, pushing XP, pair programming and continuous integration to their extremes.

Yesod Web Framework

Michael Snoyman presents Yesod, a web framework written in Haskell and containing a web server, templating, ORM, libraries (templating, gravatar, etc.).

Transactions without Transactions

Richard Kreuter and Kyle Banker on how to avoid classical RDBMS transactional systems by using compensation mechanisms, transactional messaging or transactional procedures.

Attila Szegedi on JVM and GC Performance Tuning at Twitter

Attila Szegedi talks about performance tuning Java and Scala programs at Twitter: how to approach GC problems, the importance of asynchronous I/O, when to use MySQL/Cassandra/Redis, and much more.

10 tips on how to prevent business value risk

One category of risk that project teams need to ensure they address is business value failure – delivering a product that fails to provide value for the business investor.

Interview: Software Systems Architecture: Working With Stakeholders Using Viewpoints and Perspectives

InfoQ spoke to the authors of Software Systems Architecture on a couple of new topics, the System Context viewpoint and Agile, which have been added to the second edition.