The AVANTSSAR Platform for the Automated Validation of Trust and Security of Service-Oriented Architectures

被引:0
|
作者
Armando, Alessandro [1 ]
Arsac, Wihem [2 ]
Avanesov, Tigran [3 ]
Barletta, Michele
Calvi, Alberto [4 ]
Cappai, Alessandro [1 ]
Carbone, Roberto [1 ]
Chevalier, Yannick [5 ]
Compagna, Luca [2 ]
Cuellar, Jorge [6 ]
Erzse, Gabriel
Frau, Simone [8 ]
Minea, Marius [7 ]
Modersheim, Sebastian [9 ]
von Oheimb, David
Pellegrino, Giancarlo [2 ]
Ponta, Serena Elisa [1 ,2 ]
Rocchetto, Marco [4 ]
Rusinowitch, Michael [3 ]
Dashti, Mohammad Torabi [8 ]
Turuani, Mathieu [3 ]
Vigano, Luca [4 ]
机构
[1] Univ Genoa, DIST, AI Lab, Genoa, Italy
[2] SAP Res, Mougins, France
[3] INRIA, LORIA, Nancy, France
[4] Univ Verona, Dept Comp Sci, Verona, Italy
[5] Univ Paul Sabatier, IRIT, Pau, France
[6] Siemens AG, Corp Technol, Munich, Germany
[7] Politehn Univ, Inst Austria, Timisoara, Romania
[8] Inst Informat Secur, ETH Zurich, Zurich, Switzerland
[9] IBM Zurich Res Lab, Switzerland & DTU, Lyngby, Denmark
关键词
WEB SERVICES; CL-ATSE; PROTOCOL; TOOL;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The AVANTSSAR Platform is an integrated toolset for the formal specification and automated validation of trust and security of service-oriented architectures and other applications in the Internet of Services. The platform supports application-level specification languages (such as BPMN and our custom languages) and features three validation backends (CL-AtSe, OFMC, and SATMC), which provide a range of complementary automated reasoning techniques (including service orchestration, compositional reasoning, model checking, and abstract interpretation). We have applied the platform to a large number of industrial case studies, collected into the AVANTSSAR Library of validated problem cases. In doing so, we unveiled a number of problems and vulnerabilities in deployed services. These include, most notably, a serious flaw in the SAML-based Single Sign-On for Google Apps (now corrected by Google as a result of our findings). We also report on the migration of the platform to industry.
引用
收藏
页码:267 / 282
页数:16
相关论文
共 50 条
  • [31] Architectural translucency in service-oriented architectures
    Stantchev, V
    Malek, M
    IEE PROCEEDINGS-SOFTWARE, 2006, 153 (01): : 31 - 37
  • [32] Correlation patterns in service-oriented architectures
    Barros, Alistair
    Decker, Gero
    Dumas, Marlon
    Weber, Franz
    FUNDAMENTAL APPROACHES TO SOFTWARE ENGINEERING, PROCEEDINGS, 2007, 4422 : 245 - +
  • [33] QoS management in service-oriented architectures
    Menasce, Daniel A.
    Ruan, Honglei
    Gomaa, Hassan
    PERFORMANCE EVALUATION, 2007, 64 (7-8) : 646 - 663
  • [34] Service-oriented architectures: Potential and challenges
    Schill, A.
    2005 15th International Crimean Conference Microwave & Telecommunication Technology, Vols 1 and 2, Conference Proceedings, 2005, : 16 - 18
  • [35] Formal Analysis of Service-oriented Architectures
    Rafe, Vahid
    PRZEGLAD ELEKTROTECHNICZNY, 2011, 87 (11): : 310 - 313
  • [36] Quantitative Analysis of Service-Oriented Architectures
    Iacob, Maria-Eugenia
    Jonkers, Henk
    INTERNATIONAL JOURNAL OF ENTERPRISE INFORMATION SYSTEMS, 2007, 3 (01) : 42 - 60
  • [37] Determining the dependability of Service-Oriented Architectures
    Looker, Nik
    Xu, Jie
    Munro, Malcolm
    International Journal of Simulation and Process Modelling, 2007, 3 (1-2) : 88 - 97
  • [38] Semantic lookup in service-oriented architectures
    Zdun, U
    ENGINEERING ADVANCED WEB APPLICATIONS, 2004, : 124 - 135
  • [39] Modelling of Service-Oriented Architectures with UML
    Lopez-Sanza, Marcos
    Acuna, Cesar J.
    Cuesta, Carlos E.
    Marcos, Esperanza
    ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2008, 194 (04) : 23 - 37
  • [40] An Extensible ADL for Service-Oriented Architectures
    Bashroush, R.
    Spence, I.
    INFORMATION SYSTEMS DEVELOPMENT: TOWARDS A SERVICE PROVISION SOCIETY, 2009, : 227 - 237