The AVANTSSAR Platform for the Automated Validation of Trust and Security of Service-Oriented Architectures

被引:0
|
作者
Armando, Alessandro [1 ]
Arsac, Wihem [2 ]
Avanesov, Tigran [3 ]
Barletta, Michele
Calvi, Alberto [4 ]
Cappai, Alessandro [1 ]
Carbone, Roberto [1 ]
Chevalier, Yannick [5 ]
Compagna, Luca [2 ]
Cuellar, Jorge [6 ]
Erzse, Gabriel
Frau, Simone [8 ]
Minea, Marius [7 ]
Modersheim, Sebastian [9 ]
von Oheimb, David
Pellegrino, Giancarlo [2 ]
Ponta, Serena Elisa [1 ,2 ]
Rocchetto, Marco [4 ]
Rusinowitch, Michael [3 ]
Dashti, Mohammad Torabi [8 ]
Turuani, Mathieu [3 ]
Vigano, Luca [4 ]
机构
[1] Univ Genoa, DIST, AI Lab, Genoa, Italy
[2] SAP Res, Mougins, France
[3] INRIA, LORIA, Nancy, France
[4] Univ Verona, Dept Comp Sci, Verona, Italy
[5] Univ Paul Sabatier, IRIT, Pau, France
[6] Siemens AG, Corp Technol, Munich, Germany
[7] Politehn Univ, Inst Austria, Timisoara, Romania
[8] Inst Informat Secur, ETH Zurich, Zurich, Switzerland
[9] IBM Zurich Res Lab, Switzerland & DTU, Lyngby, Denmark
关键词
WEB SERVICES; CL-ATSE; PROTOCOL; TOOL;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The AVANTSSAR Platform is an integrated toolset for the formal specification and automated validation of trust and security of service-oriented architectures and other applications in the Internet of Services. The platform supports application-level specification languages (such as BPMN and our custom languages) and features three validation backends (CL-AtSe, OFMC, and SATMC), which provide a range of complementary automated reasoning techniques (including service orchestration, compositional reasoning, model checking, and abstract interpretation). We have applied the platform to a large number of industrial case studies, collected into the AVANTSSAR Library of validated problem cases. In doing so, we unveiled a number of problems and vulnerabilities in deployed services. These include, most notably, a serious flaw in the SAML-based Single Sign-On for Google Apps (now corrected by Google as a result of our findings). We also report on the migration of the platform to industry.
引用
收藏
页码:267 / 282
页数:16
相关论文
共 50 条
  • [1] A framework for automated service composition in service-oriented architectures
    Majithia, S
    Walker, DW
    Gray, WA
    SEMANTIC WEB: RESEARCH AND APPLICATIONS, 2004, 3053 : 269 - 283
  • [2] Requirements of federated trust management for service-oriented architectures
    Zhengping Wu
    Alfred C. Weaver
    International Journal of Information Security, 2007, 6 : 287 - 296
  • [3] Requirements of federated trust management for service-oriented architectures
    Wu, Zhengping
    Weaver, Alfred C.
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2007, 6 (05) : 287 - 296
  • [4] ACVS: an Advanced Certificate Validation Service in Service-Oriented Architectures
    Ruiz-Martinez, Antonio
    Sanchez-Martinez, Daniel
    Inmaculada Marin-Lopez, C.
    Gil-Perez, Manuel
    Gomez-Skarmeta, Antonio F.
    2008 3RD INTERNATIONAL CONFERENCE ON INTERNET AND WEB APPLICATIONS AND SERVICES (ICIW 2008), 2008, : 297 - 302
  • [5] A security framework for developing service-oriented software architectures
    Rafe, Vahid
    Hosseinpouri, Ramin
    SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (17) : 2957 - 2972
  • [6] Forming a security certification enclave for service-oriented architectures
    Hepner, M.
    Gamble, M. T.
    Gamble, R.
    SCW 2006: IEEE SERVICES COMPUTING WORKSHOPS, PROCEEDINGS, 2006, : 148 - +
  • [7] A Security Meta-Model for Service-oriented Architectures
    Menzel, Michael
    Meinel, Christoph
    2009 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING, 2009, : 251 - 259
  • [8] Analysis of Security and Performance Aspects in Service-Oriented Architectures
    Rodrigues, Douglas
    Estrella, Julio C.
    Branco, Kalinka R. L. J. C.
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2011, 5 (01): : 13 - 30
  • [9] Systematic security analysis for service-oriented software architectures
    Liu, Yanguo
    Traore, Issa
    ICEBE 2007: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2007, : 612 - 621
  • [10] Towards Security Awareness in Designing Service-oriented Architectures
    Nassar, Pascal Bou
    Badr, Youakim
    Biennier, Frederique
    Barbar, Kablan
    ICEIS: PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS - VOL 3, 2013, : 347 - 355