An Architecture for An XML Enabled Firewall
نویسنده
چکیده
XML is rapidly becoming the default way for organizations to sharing information across networks and organizational boundaries. XML was designed as an information mark-up language and was not designed with security in mind. Consequently we are left with the problem of security XML documents from attacks such as malicious modification or fabrication. With modern VPN technology such as SSL we can encrypt and secure a data stream as it cross the network. However, when the data stream encounters an organizational boundary such as a firewall the XML document has to be parsed and forwarded to any back-end systems that require it. Current IDS and Firewall Technology does not have the ability to identify when the contents of an XML document is being attacked. This paper outlines a firewall architecture for the secure exchange of information using the extensible mark up language (XML). The architecture can be used to create a virtual private network suitable for an e-commerce application, allowing secure communication over the Internet. This paper identifies the elements required to build an XML enabled firewall that will (1) ensure the secure communication of data, and (2) validate the data to ensure data integrity. The architecture addresses the issue of information integrity using the Document Type Definition and additional rules applied by a proxy.
منابع مشابه
Securing Service-oriented Systems Using State-Based XML Firewall
Web services security has been a challenging issue in recent years because current security mechanisms, such as conventional firewalls, are not sufficient for protecting service-oriented systems from XML-based attacks. In order to provide effective security mechanisms for service-oriented systems, XML firewalls were recently introduced as an extension to conventional firewalls for web services ...
متن کاملApply Uncertainty in Document-Oriented Database (MongoDB) Using F-XML
As moving to big data world where data is increasing in unstructured way with high velocity, there is a need of data-store to store this bundle amount of data. Traditionally, relational databases are used which are now not compatible to handle this large amount of data, so it is needed to move on to non-relational data-stores. In the current study, we have proposed an extension of the Mongo...
متن کاملApply Uncertainty in Document-Oriented Database (MongoDB) Using F-XML
As moving to big data world where data is increasing in unstructured way with high velocity, there is a need of data-store to store this bundle amount of data. Traditionally, relational databases are used which are now not compatible to handle this large amount of data, so it is needed to move on to non-relational data-stores. In the current study, we have proposed an extension of the Mongo...
متن کاملA petri net based XML firewall security model for web services invocation
An XML firewall differs from a conventional firewall because its major task is to control access to web services rather than to filter untrusted addresses. An XML firewall can effectively protect web services from being attacked by inspecting a complete XML message including its head and data segments, and rejecting unauthorized web services invocation. In this paper, we propose a formal XML fi...
متن کاملDefending Against XML-Based Attacks Using State-Based XML Firewall
With the proliferation of service-oriented systems and cloud computing, web services security has gained much attention in recent years. Web service attacks, called XML-based attacks, typically occur at the SOAP message level, thus they are not readily handled by existing security mechanisms such as a conventional firewall. In order to provide effective security mechanisms for service-oriented ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- I. J. Network Security
دوره 8 شماره
صفحات -
تاریخ انتشار 2009