On a Classification Approach for SOA Vulnerabilities

  • Authors:
  • Lutz Lowis;Rafael Accorsi

  • Affiliations:
  • -;-

  • Venue:
  • COMPSAC '09 Proceedings of the 2009 33rd Annual IEEE International Computer Software and Applications Conference - Volume 02
  • Year:
  • 2009

Quantified Score

Hi-index 0.01

Visualization

Abstract

Vulnerabilities in operating systems and web applications have been and are being put into various classifications, leading to a better understanding of their causes and effects, and to improved vulnerability management tool support. In a service-oriented architecture (SOA), additional vulnerabilities exist in the implementations of new standards such as BPEL and SOAP. Attackers can exploit these vulnerabilities to interfere with the business processes, which are executed as orchestration of services. We describe our approach and ongoing work of creating a SOA vulnerability classification.