The AVANTSSAR Platform for the Automated Validation of Trust and Security of Service-Oriented Architectures

被引:0
|
作者
Armando, Alessandro [1 ]
Arsac, Wihem [2 ]
Avanesov, Tigran [3 ]
Barletta, Michele
Calvi, Alberto [4 ]
Cappai, Alessandro [1 ]
Carbone, Roberto [1 ]
Chevalier, Yannick [5 ]
Compagna, Luca [2 ]
Cuellar, Jorge [6 ]
Erzse, Gabriel
Frau, Simone [8 ]
Minea, Marius [7 ]
Modersheim, Sebastian [9 ]
von Oheimb, David
Pellegrino, Giancarlo [2 ]
Ponta, Serena Elisa [1 ,2 ]
Rocchetto, Marco [4 ]
Rusinowitch, Michael [3 ]
Dashti, Mohammad Torabi [8 ]
Turuani, Mathieu [3 ]
Vigano, Luca [4 ]
机构
[1] Univ Genoa, DIST, AI Lab, Genoa, Italy
[2] SAP Res, Mougins, France
[3] INRIA, LORIA, Nancy, France
[4] Univ Verona, Dept Comp Sci, Verona, Italy
[5] Univ Paul Sabatier, IRIT, Pau, France
[6] Siemens AG, Corp Technol, Munich, Germany
[7] Politehn Univ, Inst Austria, Timisoara, Romania
[8] Inst Informat Secur, ETH Zurich, Zurich, Switzerland
[9] IBM Zurich Res Lab, Switzerland & DTU, Lyngby, Denmark
关键词
WEB SERVICES; CL-ATSE; PROTOCOL; TOOL;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The AVANTSSAR Platform is an integrated toolset for the formal specification and automated validation of trust and security of service-oriented architectures and other applications in the Internet of Services. The platform supports application-level specification languages (such as BPMN and our custom languages) and features three validation backends (CL-AtSe, OFMC, and SATMC), which provide a range of complementary automated reasoning techniques (including service orchestration, compositional reasoning, model checking, and abstract interpretation). We have applied the platform to a large number of industrial case studies, collected into the AVANTSSAR Library of validated problem cases. In doing so, we unveiled a number of problems and vulnerabilities in deployed services. These include, most notably, a serious flaw in the SAML-based Single Sign-On for Google Apps (now corrected by Google as a result of our findings). We also report on the migration of the platform to industry.
引用
收藏
页码:267 / 282
页数:16
相关论文
共 50 条
  • [21] Formalizing service-oriented architectures
    Arab Academy for Banking and Financial Sciences
    IT Prof, 2008, 4 (34-38):
  • [22] A Model of Service-Oriented Architectures
    Malkis, Alexander
    Marmsoler, Diego
    PROCEEDINGS 2015 NINTH BRAZILIAN SYMPOSIUM ON SOFTWARE COMPONENTS, ARCHITECTURES AND REUSE - SBCARS 2015, 2015, : 110 - 119
  • [23] Clouds and service-oriented architectures
    Liu, Lu
    Xu, Jie
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF GRID COMPUTING AND ESCIENCE, 2013, 29 (01): : 271 - 272
  • [24] D-XMAN: A Platform For Total Compositionality in Service-Oriented Architectures
    Arellanes, Damian
    Lau, Kung-Kiu
    2017 IEEE 7TH INTERNATIONAL SYMPOSIUM ON CLOUD AND SERVICE COMPUTING (SC2 2017), 2017, : 283 - 286
  • [25] A component-based middleware platform for reconfigurable service-oriented architectures
    Seinturier, Lionel
    Merle, Philippe
    Rouvoy, Romain
    Romero, Daniel
    Schiavoni, Valerio
    Stefani, Jean-Bernard
    SOFTWARE-PRACTICE & EXPERIENCE, 2012, 42 (05): : 559 - 583
  • [26] Distributed Security Policies for Service-Oriented Architectures over Tactical Networks
    Lopes, Roberto Rigolin F.
    Wolthusen, Stephen D.
    2015 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM 2015), 2015, : 1548 - 1553
  • [27] Service Redundancy Strategies in Service-Oriented Architectures
    May, Nicholas R.
    Schmidt, Heinz W.
    Thomas, Ian E.
    2009 35TH EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS, PROCEEDINGS, 2009, : 383 - 387
  • [28] Dynamic Service Substitution in Service-Oriented Architectures
    Fredj, Mane
    Georgantas, Nikolaos
    Issarny, Valerie
    Zarras, Apostolos
    IEEE CONGRESS ON SERVICES 2008, PT I, PROCEEDINGS, 2008, : 101 - 104
  • [29] Towards Service Architectures in Service-oriented Computing
    Maki, Matti
    Pakkala, Daniel
    EMERGING WEB SERVICES TECHNOLOGY VOL III, 2009, 3 : 131 - 141
  • [30] The DigiHome Service-Oriented Platform
    Romero, Daniel
    Hermosillo, Gabriel
    Taherkordi, Amirhosein
    Nzekwa, Russel
    Rouvoy, Romain
    Eliassen, Frank
    SOFTWARE-PRACTICE & EXPERIENCE, 2013, 43 (10): : 1205 - 1218