>>Return to the Compare IBM DataPower Site

Protecting Enterprise, SaaS & Cloud based Applications – A Comprehensive Threat model for REST, SOA and Web 2.0

This technical document describes a comprehensive threat model for a new breed of threats based on XML content, including XML languages used in the Service Oriented Architecture (SOA) paradigm such as SOAP and the Web Services Description Language [WSDL]. In today’s environment, architectures and protocols are shifting towards XML and new sets of technology vectors are emerging such as REST and XML-RPC. With Web 2.0, new threats loom on the horizon and consequently new protection methods are required to defend the application layer consuming and serving XML streams. Ajax- and RIA-based applications (Flash and Silverlight) are redefining the usage of XML streams and bringing about a shift in the threat model.

In addition, this document attempts to define the concept of XML Intrusion Prevention (XIP) as an analog to traditional network-based intrusion prevention. A new type of threat called an XML Content Attack is defined, and examples are provided for each layer in the threat model. Also, this document attempts to use the problem of lost context between XML processing layers to characterize many of the security problems that arise during XML processing. Finally, a specifc type of content-aware application-level proxy or firewall countermeasure is illustrated with Intel SOA Expressway.

First name:*
Last name:*
Job Title:*
Company:*
Work Phone:*
Country:*
Email Address:*
Contact me with instructions to download SOA Expressway Evaluation

Questions / comments.


Information Library

  1. White Paper:

    Taking Control of the Cloud for Your Enterprise

  2. White Paper:

    Securely Exposing JBOSS Services

  3. Video:

    Intel AppUp Store Video Testimonial

  4. White Paper:

    Intel BPMS ID Broker

  5. iPad Giveaway

  6. Analyst Report(New):

    OVUM Butler Group Service Gateway Technology Audit

  7. Analyst Report:

    451 Group Review of Expressway

  8. Analyst Report:

    PushToTest Performance Review of Expressway

  9. White Paper:

    Performance Comparison to
    IBM DataPower XI50

  10. White Paper:

    The XACML Enabled Gateway – The Entrance to a New SOA Ecosystem

  11. White Paper:

    Xpath 2.0 - Application to Gateway Security

  12. SOA Mag Article:

    Multi-Core Optimized
    Soft-Appliance

  13. White Paper:

    Accelerate SOA Processing
    with Intel SSE4.2 Instruction Sets

  14. Data Sheet:

    SOA Expressway

  15. Security for Oracle Fusion/11G

  16. SOA Expressway Web Site:

    News/Events

  17. Blog:

    Truth in SOA

  18. Blog:

    Joshua Painter

Learn About 8 Core SOA Appliance Usage Scenarios-Digital White Board

1. SOA Expressway/
    & Sample App
2. SOA Benchmark Kit

Thinking IBM DataPower? Think Again

The Intel® SOA Expressway

SOA Soft-Appliance

...8x the performance at ½ the cost

Contact Us Terms of Use Trademarks Privacy ©Intel Corporation