Vis enkel innførsel

dc.contributor.advisorHerrmann, Peternb_NO
dc.contributor.advisorChristensen, Carl C.nb_NO
dc.contributor.authorBrekken, Lars Arnenb_NO
dc.contributor.authorÅsprang, Rune Frøysanb_NO
dc.date.accessioned2014-12-19T14:12:04Z
dc.date.available2014-12-19T14:12:04Z
dc.date.created2010-09-02nb_NO
dc.date.issued2006nb_NO
dc.identifier347405nb_NO
dc.identifierntnudaim:1420nb_NO
dc.identifier.urihttp://hdl.handle.net/11250/261666
dc.description.abstractAccepting unvalidated input is considered today's greatest web security threat. This master's thesis addresses that threat by proposing an automatic and centralized mechanism for validating web services input. By building on existing web services standards, the proposed solution intercepts incoming web service requests and validates them against a security policy. A major design goal for this work was to realize web services input validation without modifying existing functionality. That is, the input validation security mechanism should be added out of code. This is achieved by keeping the web services and the validation mechanism separate. Input validation configuration is accomplished by modifying a configuration file. Even when the validation mechanism logic is correct, it may not function as intended. Such anomalies are in most cases caused by human-introduced errors in the configuration file, resulting in the need for a configuration file verification tool. This thesis proposes a verification tool that quantifies the level of security by analyzing the configuration file.nb_NO
dc.languageengnb_NO
dc.publisherInstitutt for telematikknb_NO
dc.subjectntnudaimno_NO
dc.subjectSIE7 kommunikasjonsteknologino_NO
dc.subjectTelematikkno_NO
dc.titleAdding Security to Web Services: An Automatic, Verifiable, and Centralized Mechanism for Web Services Input Validationnb_NO
dc.typeMaster thesisnb_NO
dc.source.pagenumber137nb_NO
dc.contributor.departmentNorges teknisk-naturvitenskapelige universitet, Fakultet for informasjonsteknologi, matematikk og elektroteknikk, Institutt for telematikknb_NO


Tilhørende fil(er)

Thumbnail
Thumbnail
Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel