A Performance Evaluation of Security Mechanisms for Web services

被引:2
作者
Alrouh, Bachar [1 ]
Ghinea, Gheorghita [1 ]
机构
[1] Brunel Univ, Sch Informat Syst Comp & Math, Uxbridge UB8 3PH, Middx, England
来源
FIFTH INTERNATIONAL CONFERENCE ON INFORMATION ASSURANCE AND SECURITY, VOL 2, PROCEEDINGS | 2009年
关键词
Web Services; Security; Performance; WSIT;
D O I
10.1109/IAS.2009.252
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recently, web services security has shown a significant gesture as several specifications have been developed and implemented to meet the security challenges of web services. However, the performance of the security mechanisms is fraught with concerns due to additional security, contents in SOAP messages, the higher number of message exchanges to establish trust as well as extra CPU time to process these additions. In this paper, we consider and compare the performance of various security mechanisms applied on a simple web service tested with different initial message sizes. The test results show that transport layer security mechanisms are considerably faster than message level security mechanisms. Moreover, the effect of adding SAMIL-tokens is negligible and the performance of SAML-based web services depends mostly on the underlying security mechanisms. Finally, the performance penalty of applying STS security mechanisms is significantly high comparing to non-STS mechanisms.
引用
收藏
页码:715 / 718
页数:4
相关论文
共 12 条
  • [1] Booth D., 2004, WEB SERVICES ARCHITE
  • [2] Chen SP, 2007, 2007 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES, PROCEEDINGS, P431
  • [3] Securing Web services
    Hondo, M
    Nagaratnam, N
    Nadalin, A
    [J]. IBM SYSTEMS JOURNAL, 2002, 41 (02) : 228 - 241
  • [4] LIU H, 2005, P 13 ANN MARD GRAS C
  • [5] Machado A.C. C., 2005, Proceedings of the 11th Brazilian Symposium on Multimedia and the Web, P1, DOI [10.1145/1114223.1114234, DOI 10.1145/1114223.1114234]
  • [6] QoS issues in Web services
    Menascé, DA
    [J]. IEEE INTERNET COMPUTING, 2002, 6 (06) : 72 - 75
  • [7] MI Z, 2005, P 5 INT C COMP INF T, P736
  • [8] MORALIS A, 2007, P 3 INT C NETW SERV, P28
  • [9] Performance comparison of security mechanisms for grid services
    Shirasuna, S
    Slominski, A
    Fang, L
    Gannon, D
    [J]. FIFTH IEEE/ACM INTERNATIONAL WORKSHOP ON GRID COMPUTING, PROCEEDINGS, 2004, : 360 - 364
  • [10] *SUN MICR INC, METR WEB SERV INT TE