As companies embark on efforts to build loosely coupled service-oriented architectures they inevitably have to tackle the issue of securing their SOA service infrastructure, and many turn to XML security appliances to get the job done.
Why choose an XML appliance to protect and safely expose your SOA data services to customers, partners and software-as-a-service (SaaS) vendors? Without dedicated hardware support it is nearly impossible to withstand denial-of-service attacks and to provide the high availability necessary to ensure data confidentiality, integrity and nonrepudiation.
XML security appliances are typically positioned in the demilitarized zone between two firewalls and become the only device visible to outside clients. The appliance acts as a proxy and performs all necessary security operations, including SSL socket termination, credential validation and data verification.
The XML security appliance is then the only device permitted by the second firewall to establish connections to internal SOA endpoints. Performing security operations outside the endpoints provides a twofold benefit. First, the SOA data service no longer needs to implement any security functions and will not be compromised by hackers. Second, the security infrastructure policy is decoupled from the endpoints and therefore can be easily controlled by the infrastructure security team without having to make changes to the endpoints themselves.
Common functionality
XML security appliances, first introduced in 2000, range in price from US$30,000 to $70,000, and the feature sets vary widely. These are the most common and important features to understand.
- Transport-level security: Inbound SSL/TLS socket termination and outbound SSL/TLS socket initiation with support for server-based and mutual authentication has been one of the cornerstones of Web security and the most popular way to achieve data confidentially, integrity and nonrepudiation
- Application security: WS-Security Standard Support (1.0 and 1.1) is a key standard that defines how to secure Web service messages. In its current version (1.1), the standard defines support for several authentication profiles: Username token, X.509, Kerberos, SAML (an XML framework for exchanging authentication and authorization) and REL (Rights Expression Language, for specifying rights to content, fees or other considerations required to secure those rights) token. It also incorporates support for SOAP messages with attachments.
- Message content inspection and validation: Commonly supported features include the ability to perform schema/(document definition) validation and policy-based content and parameter filtering.
- XML threat protection: Will your appliance protect against hacker attacks that target Web service interface vulnerabilities? Common examples of such attacks include SQL injection, oversized/recursive payloads and schema poisoning.
- Application access management: Also known as AAA (authentication, authorization and accounting), the feature provides protection against unauthorized access and maintains access logging information.
- Single sign-on support: Ability to consume and generate SAML/XACML assertions to facilitate single sign-on with browser artifact (SAML 1.1) and Web services profiles (SAML 2.0).
Latest on Services
- Symantec axes GoEverywhere service
- Symantec, McAfee to pay fines over auto-renewals
- Pay as you go for security solutions
- More doubts surface over enforceability of ACMA's blacklist
- Hacker claims SQL bug on Symantec site
- With global revenue dropping, Symantec posts big loss
- Symantec releases patch for application delivery program
- Symantec takes cybercrime snapshot with new report
- Microsoft purges phony security software from 1 million PCs
- Symantec sees spike in dangerous Microsoft attacks
Security Essentials
- Good security in recessionary times
- Security ROI: Fact or Fiction?
- NetWitness releases free version of security software
- Study: critical infrastructure often under cyberattack
- Crooks can make $5M a year shilling fake security software
- Sun exec: IT security should follow business needs
- Clumsy staff more dangerous than hackers: survey
- When the watchdog is the underdog
- Mafiaboy grows up; a hacker seeks redemption
- Ouch! Security pros' worst mistakes
TechWorld Jobs (beta)
Recent Jobs
TechWorld Blogs
-

TalkingTech
The view from the top of IT with TechWorld Editor Rodney Gedda
-

Entrenched
Cooking up better code, IDG's developers reveal some of their secrets
-

Broadband Voice
Darren Pauli digs in from the front line of Australia's broadband battleground
Recent blog posts
- Nokia remains 'open' to Android amid Symbian renaissance
- KDE's Seigo gives sneak peek at version 4.3
- Was the iPhone 3G S worth queuing up for?
- Has Oracle started its mammoth technology consolidation?
- iPhone 3.0: the detail is the process, not the features
- TechWorld.com.au goes mobile
- Should Dell buy Palm? Stranger things have happened
- A big week for Linux: is user friendliness finally in sight?
- Apple, Android rain on Palm's Pre parade
- The clone attack is becoming unstoppable
Recent comments
- PSP Nintendo
4 hours 30 min ago - Interesting report. You were
1 day 38 min ago - Are you sure it is in Sydney?
1 day 11 hours ago - The mobile market has
1 day 19 hours ago - Great news.
Sms spam should
2 days 16 hours ago - now what am I gonna do with
2 days 19 hours ago - ozlotteries.com not ozlotto.cm
2 days 21 hours ago - OLAT Release
3 days 7 hours ago - and i was sure i would win...
3 days 11 hours ago - Hi SolidRadicle,
I am looking
3 days 12 hours ago - Not if I can help it
3 days 12 hours ago - Ozlotto Tips Scam
3 days 16 hours ago - Great post.
It's very
3 days 16 hours ago - Excellent review! I'm glad
5 days 13 hours ago - iTunes Helper
1 week 1 day ago - Update the link to OrangeHRM web site
1 week 1 day ago - Very informative article
1 week 2 days ago - Google Chrome is still being directed to bing instead of google
1 week 2 days ago - regd: Software Magazine
1 week 2 days ago - I seem to have missed a point
1 week 3 days ago










Comments
Post new comment