Semantics-aware perimeter protection

被引:0
|
作者
Cremonini, M [1 ]
Damiani, E [1 ]
Samarati, P [1 ]
机构
[1] Univ Milan, Dipartimento Tecnol Informaz, I-26013 Crema, Italy
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Web services security is becoming a critical concern for any organization adopting the XML-based Web services approach to application integration. While many access control techniques for Web services are becoming available, several issues still need to be solved in order to correctly split the burden of securing Web services between the perimetral and the service level. In this paper, a technique is presented able to make perimetral. defences semantics-aware. Application-level semantics-aware firewalls enforce filtering rules directly on SOAP messages based on the nature of the services they request. Our semantics-aware firewalls rules are written using a flexible XML-based syntax that allows sharing metadata concepts with service level access control policies, supporting complex security policies that integrate perimetral defences with access control. Moreover, they can be quickly integrated into organizations' existing infrastructure, deployed rapidly and scaled as needed. Also, they integrate easily with existing infrastructure and can be operated by current staff, potentially achieving a low total cost of ownership with respect to service level solutions.
引用
收藏
页码:229 / 242
页数:14
相关论文
共 50 条
  • [21] Special issue - Semantics-aware techniques for security
    Damiani, E
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2004, 19 (03): : 119 - 120
  • [22] Learning with Semantics: Towards a Semantics-Aware Routing Anomaly Detection System
    Chen, Yihao
    Yin, Qilei
    Li, Qi
    Liu, Zhuotao
    Xu, Ke
    Xu, Yi
    Xu, Mingwei
    Liu, Ziqian
    Wu, Jianping
    PROCEEDINGS OF THE 33RD USENIX SECURITY SYMPOSIUM, SECURITY 2024, 2024, : 5143 - 5160
  • [23] Semantics-aware data integration for heterogeneous data sources
    Leida, Marcello
    Gusmini, Alex
    Davies, John
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2013, 4 (04) : 471 - 491
  • [24] Extending context descriptions in semantics-aware Access Control
    Damiani, E.
    di Vimercati, S. De Capitani
    Fugazza, C.
    Samarati, P.
    INFORMATION SYSTEMS SECURITY, PROCEEDINGS, 2006, 4332 : 162 - +
  • [25] A Process Framework for Semantics-Aware Tourism Information Systems
    Daramola, Olawande J.
    CURRENT TRENDS IN WEB ENGINEERING, 2010, 6385s : 521 - 532
  • [26] Semantics-aware data integration for heterogeneous data sources
    Marcello Leida
    Alex Gusmini
    John Davies
    Journal of Ambient Intelligence and Humanized Computing, 2013, 4 : 471 - 491
  • [27] Preserving details in semantics-aware context for scene parsing
    Shuai Ma
    Yanwei Pang
    Jing Pan
    Ling Shao
    Science China Information Sciences, 2020, 63
  • [28] Semantics-Aware Document Retrieval for Government Administrative Data
    Kulkarni, Apurva
    Ramanathan, Chandrashekar
    Venugopal, Vinu E.
    INTERNATIONAL JOURNAL OF SEMANTIC COMPUTING, 2023, 17 (03) : 477 - 491
  • [29] Semantics-aware typographical choices via affective associations
    Tugba Kulahcioglu
    Gerard de Melo
    Language Resources and Evaluation, 2021, 55 : 105 - 126
  • [30] Semantics-Aware Hidden Markov Model for Human Mobility
    Shi, Hongzhi
    Li, Yong
    Cao, Hancheng
    Zhou, Xiangxin
    Zhang, Chao
    Kostakos, Vassilis
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2021, 33 (03) : 1183 - 1194