The AVANTSSAR Platform for the Automated Validation of Trust and Security of Service-Oriented Architectures

被引:0
|
作者
Armando, Alessandro [1 ]
Arsac, Wihem [2 ]
Avanesov, Tigran [3 ]
Barletta, Michele
Calvi, Alberto [4 ]
Cappai, Alessandro [1 ]
Carbone, Roberto [1 ]
Chevalier, Yannick [5 ]
Compagna, Luca [2 ]
Cuellar, Jorge [6 ]
Erzse, Gabriel
Frau, Simone [8 ]
Minea, Marius [7 ]
Modersheim, Sebastian [9 ]
von Oheimb, David
Pellegrino, Giancarlo [2 ]
Ponta, Serena Elisa [1 ,2 ]
Rocchetto, Marco [4 ]
Rusinowitch, Michael [3 ]
Dashti, Mohammad Torabi [8 ]
Turuani, Mathieu [3 ]
Vigano, Luca [4 ]
机构
[1] Univ Genoa, DIST, AI Lab, Genoa, Italy
[2] SAP Res, Mougins, France
[3] INRIA, LORIA, Nancy, France
[4] Univ Verona, Dept Comp Sci, Verona, Italy
[5] Univ Paul Sabatier, IRIT, Pau, France
[6] Siemens AG, Corp Technol, Munich, Germany
[7] Politehn Univ, Inst Austria, Timisoara, Romania
[8] Inst Informat Secur, ETH Zurich, Zurich, Switzerland
[9] IBM Zurich Res Lab, Switzerland & DTU, Lyngby, Denmark
关键词
WEB SERVICES; CL-ATSE; PROTOCOL; TOOL;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The AVANTSSAR Platform is an integrated toolset for the formal specification and automated validation of trust and security of service-oriented architectures and other applications in the Internet of Services. The platform supports application-level specification languages (such as BPMN and our custom languages) and features three validation backends (CL-AtSe, OFMC, and SATMC), which provide a range of complementary automated reasoning techniques (including service orchestration, compositional reasoning, model checking, and abstract interpretation). We have applied the platform to a large number of industrial case studies, collected into the AVANTSSAR Library of validated problem cases. In doing so, we unveiled a number of problems and vulnerabilities in deployed services. These include, most notably, a serious flaw in the SAML-based Single Sign-On for Google Apps (now corrected by Google as a result of our findings). We also report on the migration of the platform to industry.
引用
收藏
页码:267 / 282
页数:16
相关论文
共 50 条
  • [41] A survey of patterns for Service-Oriented Architectures
    Zdun, Uwe
    Hentrich, Carsten
    van der Aalst, Wil M. P.
    INTERNATIONAL JOURNAL OF INTERNET PROTOCOL TECHNOLOGY, 2006, 1 (03) : 132 - 143
  • [42] Service-oriented architectures & mobile applications
    Houlding, D
    DR DOBBS JOURNAL, 2004, 29 (07): : S11 - S14
  • [43] Reference metrics for service-oriented architectures
    Science Applications International Corporation
    不详
    CrossTalk, 2007, 12 (15-17):
  • [44] Usage control in service-oriented Architectures
    Pretschner, Alexander
    Massacci, Fabio
    Hilty, Manuel
    TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, PROCEEDINGS, 2007, 4657 : 83 - +
  • [45] Service-Oriented Architectures: Myth or Reality?
    Luthria, Haresh
    Rabhi, Fethi A.
    IEEE SOFTWARE, 2012, 29 (04) : 46 - 52
  • [46] Web services and service-oriented architectures
    Alonso, G
    Casati, F
    ICDE 2005: 21ST INTERNATIONAL CONFERENCE ON DATA ENGINEERING, PROCEEDINGS, 2005, : 1147 - 1147
  • [47] Service-oriented Architectures for collaborative automation
    Colombo, AW
    Jammes, F
    Smit, H
    Harrison, R
    Lastra, JLM
    Delamer, IM
    IECON 2005: THIRTY-FIRST ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, VOLS 1-3, 2005, : 2649 - 2654
  • [48] Service-oriented architectures: Orchestrating the OSDE
    Maas, G
    Marien, J
    ALCATEL TELECOMMUNICATIONS REVIEW, 2005, (04): : 270 - 273
  • [49] A Redundancy Protocol for Service-Oriented Architectures
    May, Nicholas R.
    SERVICE-ORIENTED COMPUTING - ICSOC 2008 WORKSHOPS, 2009, 5472 : 211 - 220
  • [50] Component contracts in service-oriented architectures
    Curbera, Francisco
    COMPUTER, 2007, 40 (11) : 74 - +