Vis enkel innførsel

dc.contributor.advisorHerrmann, Peter
dc.contributor.advisorChristensen, Carl C.
dc.contributor.authorBrekken, Lars Arne
dc.contributor.authorÅsprang, Rune Frøysa
dc.date.accessioned2018-11-05T15:02:27Z
dc.date.available2018-11-05T15:02:27Z
dc.date.created2006-06-01
dc.date.issued2006
dc.identifierntnudaim:1420
dc.identifier.urihttp://hdl.handle.net/11250/2571132
dc.description.abstractAccepting unvalidated input is considered today's greatest web security threat. This master's thesis addresses that threat by proposing an automatic and centralized mechanism for validating web services input. By building on existing web services standards, the proposed solution intercepts incoming web service requests and validates them against a security policy. A major design goal for this work was to realize web services input validation without modifying existing functionality. That is, the input validation security mechanism should be added out of code. This is achieved by keeping the web services and the validation mechanism separate. Input validation configuration is accomplished by modifying a configuration file. Even when the validation mechanism logic is correct, it may not function as intended. Such anomalies are in most cases caused by human-introduced errors in the configuration file, resulting in the need for a configuration file verification tool. This thesis proposes a verification tool that quantifies the level of security by analyzing the configuration file.
dc.languageeng
dc.publisherNTNU
dc.subjectKommunikasjonsteknologi, Telematikk
dc.titleAdding Security to Web Services - An Automatic, Verifiable, and Centralized Mechanism for Web Services Input Validation
dc.typeMaster thesis


Tilhørende fil(er)

Thumbnail
Thumbnail
Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel