© Copyright IONA Technologies 2002 Colby Dyess Senior Engineer, XMLBus Hacks, cracks and 13 year olds! Avoiding Web Services Security Nightmares Preparing.

Slides:



Advertisements
Similar presentations
Tuesday, June 10, 2003 Web Services Brief Overview & Security Assertion Coordinator Pattern by Mohammad Abushadi & Riaz Ahmed for Security Group CSE -
Advertisements

1 Integration Made Easy Agile Integration: Connecting Salesforce With Your Enterprise.
1 IONA Advances in Open Source SOA June Agenda Background Open Source Strategy Open Source Product Line Open Source Community Q&A.
A Public Web Services Security Framework Based on Current and Future Usage Scenarios J.Thelin, Chief Architect PJ.Murray, Product Manager Cape Clear Software.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Application Integration in Intranets and Extranets Antti Kiviluoto Antti Kiviluoto
Service Oriented Architecture Concepts March 27, 2006 Chris Armstrong
Convergence – Driving down the Cost of Enterprise IT Christoph Rau BEA Vice President, Central & Eastern Europe October 23, 2003.
Web Services Security Multimedia Information Engineering Lab. Yoon-Sik Yoo.
A New Computing Paradigm. Overview of Web Services Over 66 percent of respondents to a 2001 InfoWorld magazine poll agreed that "Web services are likely.
Web Services and Enterprise Computing. Introduction Investigate how organizations can create and consume Web services to improve communications and productivity.
Maciej Gruszka Principal System Engineer 11 October 2005 The New World Order is Fluid BEA’s integration infrastructure as a tool decreasing operational.
® IBM Software Group © IBM Corporation IBM Information Server Service Oriented Architecture WebSphere Information Services Director (WISD)
Enterprise Resource Planning
CONNECT EVERYTHING. ACHIEVE ANYTHING. ™ Top Ten Enterprise Service Bus (ESB) Myths Gordon Van Huizen CTO, Sonic Software March 17, 2005.
Office 365: Efficient Cloud Solutions Wednesday March 12, 9AM Chaz Vossburg / Gabe Laushbaugh.
CRM On Demand Integration Capabilities Joerg Wallmueller CRM Sales.
© Copyright IONA Technologies 2002 PART 2: Web Service Composition: Unlocking Your Interface Potential Seumas Soltysik Senior Software Engineer, XMLBus.
Best Practices in Deploying a PKI Solution BIEN Nguyen Thanh Product Consultant – M.Tech Vietnam
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
The effect of standards on the enterprise Bill Stangel Fidelity Investments April 26, 2004.
Internet Trust Defined. Delivered. Electronic Business the Way It Was Meant to Be.
Product Overview Added Value For Partners Features Comparison For Upselling & Cross Selling Customer Scenarios & Tactical Licensing Scenarios 1 Sell Services.
Web Services 101 Introduction to Web Services Computer Networks Natawut Nupairoj, Ph.D. Department of Computer Engineering Chulalongkorn University.
C Copyright © 2009, Oracle. All rights reserved. Appendix C: Service-Oriented Architectures.
Microsoft.NET Platform Adam Seligman Strategy Advisor and.NET Agitator
Highlights Builds on Splunk implementations – extending enterprise value to include mission-critical IBM mainframe data. Unified mainframe data source.
London e-Science Centre Imperial College London Making the Grid Pay Economic Services - Pricing and Payment William Lee.
© Copyright IONA Technologies 2002 Where to Start with Web Services Integration Thor Sigvaldason Director, Advanced Technology Group, PWCC Wednesday, May.
Web Services An introduction for eWiSACWIS May 2008.
© Copyright IONA Technologies 2000, 2001 The Enterprise Portal Company™ Manfred R. Koethe Industrial & Embedded Systems Architect IONA Technologies Applied.
Dr. Bhavani Thuraisingham October 2006 Trustworthy Semantic Webs Lecture #16: Web Services and Security.
© Copyright IONA Technologies 2002 Part 3: Business Collaboration Expanding Web Services Architectures Deborah Dulaney Tuesday, May 28, 2002.
Identifying Web Service Integration Challenges Frank Goethals SAP-Research Chair on ‘Extended Enterprise Infrastructures’ K.U.Leuven – Belgium
CSI302 实施 BTS 的策略与技巧 郑开颜应用架构顾问产品部微软有限公司. What We Will Cover: Interoperability w/ BizTalk Server Composite Business Processes Integration Broker Internals.
Web Services BOF This is a proposed new working group coming out of the Grid Computing Environments Research Group, as an outgrowth of their investigations.
SOA-14: Deploying your SOA Application David Cleary Principal Software Engineer.
Random Logic l Forum.NET l Web Services Enhancements for Microsoft.NET (WSE) Forum.NET ● October 4th, 2006.
® Gradient Technologies, Inc. Inter-Cell Interworking Access Control Across the Boundary Open Group Members Meeting Sand Diego, CA USA April 1998 Brian.
AUTHORS: MIKE P. PAPAZOGLOU WILLEM-JAN VAN DEN HEUVEL PRESENTED BY: MARGARETA VAMOS Service oriented architectures: approaches, technologies and research.
Orbix E2A Web Services Integration Platform eBusiness Network Seminar San Francisco April 17 Mangesh Bhandarkar Product Manager.
Semantic Web Technologies Research Topics and Projects discussion Brief Readings Discussion Research Presentations.
Databases JDBC (Java Database Connectivity) –Thin clients – servlet,JavaServer Pages (JSP) –Thick clients – RMI to remote databases –most recommended way.
Copyright © 2013 Curt Hill SOAP Protocol for exchanging data and Enabling Web Services.
| Copyright© 2011 Microsoft Corporation 1 journey to the cloud KOEN VAN TOLHUYZEN TSP OFFICE 365 MICROSOFT CORPORATION.
Copyright © 2003 Jorgen Thelin / Cape Clear Software 1 A Web Services Security Framework Jorgen Thelin Chief Scientist Cape Clear Software Inc.
Kemal Baykal Rasim Ismayilov
Web Services Security Patterns Alex Mackman CM Group Ltd
Comprehensive Project Management Solutions with the.NET Server family.
Welcome. Welcome to this TechNet Event URL for on-line feedback is in your reminder No Planned Fire Drills Please turn your Mobile Phones off To.
Overview of SOA and the role of ESB/OSB
Web Services Security Mike Shaw Architectural Engineer.
Interaction classes Record context Custom lookups.
Enterprise Mobility Suite: Simplify security, stay productive Protect data and empower workers Unsecured company data can cost millions in lost research,
E-commerce Architecture Ayşe Başar Bener. Client Server Architecture E-commerce is based on client/ server architecture –Client processes requesting service.
By Jeremy Burdette & Daniel Gottlieb. It is an architecture It is not a technology May not fit all businesses “Service” doesn’t mean Web Service It is.
Real time Stock quotes by web Service and Securing XML for Web Services security. Bismita Srichandan
Microsoft Office 365 Add-In Enhances Task and Project Management and Improves Workflows “With Office 365, businesses receive a comprehensive stack of technologies.
مدیریت فرایندهای کسب و کار و معماری سرویس گرا
Ebusiness Infrastructure Platform
Multi-party Authentication in Web Services
Tim Bornholtz Director of Technology Services
WEB SERVICES DAVIDE ZERBINO.
Unit 8 Network Security.
Presentation transcript:

© Copyright IONA Technologies 2002 Colby Dyess Senior Engineer, XMLBus Hacks, cracks and 13 year olds! Avoiding Web Services Security Nightmares Preparing Your Enterprise for Web Services (Part I)

© Copyright IONA Technologies 2002 History Founded in Ireland in 1991; IPO on Nasdaq in 1997 Global company with headquarters in Dublin, Ireland and Waltham, MA Financial Performance Calendar year 2001 statistics –Revenues $181 million (65% license / 35% services) –Positive operating margins Team Over 900 employees in over 30 offices worldwide with a sales force of over 300 Strong blue chip customer and partner base IONA is a leading provider of comprehensive, standards-based enterprise infrastructure solutions for customers to build, deploy and integrate mission-critical applications that power core business processes The IONA Story

© Copyright IONA Technologies 2002 Integration: The “Killer App” for Web Services Set of industry standards for distributed computing Service-oriented architectures enable End to Anywhere™ integration E2A changes the economics of integration Web services is the driving technology – Simple – Effective – Unanimous industry support

© Copyright IONA Technologies 2002 Today’s Audience Familiar with SOAP, HTTP, SSL, WSDL and XML Limited exposure to security standards Need web service security in the near future (perhaps today!)

© Copyright IONA Technologies 2002 What Will be Discussed Security concerns Three layers of security Example uses of security layers

© Copyright IONA Technologies 2002 Security Concerns Control access to services and data Credential validation Private communication Ensuring message integrity

© Copyright IONA Technologies 2002 Security Layers –Protocol –Message –Application

© Copyright IONA Technologies 2002 Security – Protocol Layer –Basic Authentication –Digest Authentication –SSL (HTTPS) –Mutual Authentication

© Copyright IONA Technologies 2002 Security – Message layer –XML-Encryption –XML-Signature –WS-Security

© Copyright IONA Technologies 2002 Security – Application layer –App server/container –Security Assertions Markup Language-SAML –Proprietary

© Copyright IONA Technologies 2002 Meeting Security Needs Controlling access to services and data –Basic and Digest Authentication –SAML for Authorization Credential validation –SAML for Authentication –XML-Signature –Mutual Authentication

© Copyright IONA Technologies 2002 Meeting Security Needs Private communication –SSL (HTTPS) –XML-Encryption Ensuring message integrity –SSL (HTTPS) –XML-Signature

© Copyright IONA Technologies 2002 Basic Example SOAP Body Web Services Server Web Services Client Data Service Data HTTP

© Copyright IONA Technologies 2002 Entry-level Security SOAP Body Web Services Server Web Services Client Data Service Data HTTPS (SSL) Credentials HTTP Header Credentials Security System Security Assertions

© Copyright IONA Technologies 2002 Mid-level Security SOAP Body Web Services Server Web Services Client Data Service Data HTTPS (SSL) Credentials HTTP Header Credentials Auth. Platform Security Assertions Certificate Signed data Certificate

© Copyright IONA Technologies 2002 Higher-level Security SOAP Body Web Services Server Web Services Client Data Service Data HTTPS (SSL) Credentials HTTP Header Credentials Auth. Platform Security Assertions Certificate Signed Encrypted data Certificate Encrypt Decrypt

© Copyright IONA Technologies 2002 Conclusions Security needs may vary There are many security levels Combine “security” for improved strength Can be adopted today!

© Copyright IONA Technologies Integration broker platform Connects existing applications and services Allows creation of automated business process flows across extended enterprise using Web Services and XML standards Application server platform for developing, deploying and managing business application logic Hosted in J2EE, CORBA or mainframe environments using Web services standards It Takes A Platform

© Copyright IONA Technologies 2002 Orbix E2A ™ “Best Web Services Product” Simplifies EAI, B2Bi, and BPM

© Copyright IONA Technologies 2002 Web Services Integration Now! XMLBus.comVisit XMLBus.com and download Orbix E2A™ XMLBus Edition. Sign up for IONA training on Web services XMLBus.comDownload IONA’s Web services white paper at XMLBus.com Check out Orbix E2A™, the first e- Business Platform for Web Services Integration.

© Copyright IONA Technologies 2002 Upcoming Webcasts Don’t forget IONA World October th, San Diego, CA PART 3: B2B Collaboration: Expanding Web Services Architectures Tuesday, May 28 PART 2: Web Service Composition: Unlocking Your Interface Potential Thursday, May 23th

© Copyright IONA Technologies 2002 Questions?

© Copyright IONA Technologies 2002 Resources Open Standards –XML-Signature –XML-Encryption –W3C SOAP WG –HTTP Auth IONA –Web Service Integration Platform - XMLBus Edition –Enterprise Security in Web Services (white paper) –IONA Web service white papers –IONA XMLBus Edition newsgroup news://inews.iona.com/iona.products.orbixE2A.xmlbusnews://inews.iona.com/iona.products.orbixE2A.xmlbus

© Copyright IONA Technologies 2002 Additional Resources Microsoft –XML Web Service site –Security in a Web Services World: A Proposed Architecture and Roadmap IBM –XML Security Suite