InfoQ

InfoQ

Presentation

My Bookmarks

Login or Register to enable bookmarks for unlimited time.

The content has been bookmarked!

There was an error bookmarking this content! Please retry.

Recorded at:
Recorded at

SOA Threat Modeling: Attacking and Defending REST, XML and SOAP-based Services

Presented by Jason Macy on Jan 18, 2011 Length 00:50:07     Download: MP3
     Slides
Sections
Enterprise Architecture,
Architecture & Design,
Development
Topics
SOAP ,
Messaging ,
Web Services ,
SOA ,
REST ,
Architecture ,
Enterprise Architecture ,
Security ,
SOA Symposium ,
XML
 

How would you like to view the presentation?

In case you are having issues watching this video, please follow these simple steps to help us investigate the issue:
1. Right click on the video player and select Copy log
2. Paste the copied information in an email to video-issue@infoq.com (clicking this link will fill in the default details in most email clients).
Note: in case your email client hasn't automatically picked up the email subject, please include in your email the URL of the video too.
3. Done.
We will investigate the issue and get back to you as soon as possible. Thanks for helping us improve our site!
Summary
Jason Macy explains what are the security threats targeting SOA implementations, the basic requirements for security testing and SOA gateway, attack examples and countermeasures to protect against SQL Injection, DoS, XSD Mutation, and Identity type of attacks.

Bio
Jason Macy is the CTO at Crosscheck Networks, responsible for SOA Web Services based technologies. He previously served as VP of Engineering for Forum Systems, developing the industry's only FIPS certified hardware security gateway for XML and SOA. He was also architect for Raytheon responsible for testing and commissioning the Air Traffic Control system at Schipol Airport in Amsterdam, Holland.

About the conference
The International SOA Symposium is a yearly event that features the top SOA experts and authors from around the world, providing a series of keynotes, talks, demonstrations, panels, and SOA training and certification workshops - all with an emphasis on realizing SOA in the real world.
  • This article is part of a featured topic series on SOA
How to avoid XMLS SQL attacks by Tor Arne Kvaløy Posted
Informative presentation by Robert Sullivan Posted
Nice presentation by Bruno Vernay Posted
  1. Back to top

    How to avoid XMLS SQL attacks

    by Tor Arne Kvaløy

    Avoid this attack by not including SQL statements in your web service! :)

  2. Back to top

    Informative presentation

    by Robert Sullivan

    Very interesting. Thanks for posting this informative presentation!

  3. Back to top

    Nice presentation

    by Bruno Vernay

    I like the end where he outline the point that security and identity enforcement points are not anymore in the application.
    Welcome SAML and XACML.