SIFT Web Services Security Testing Framework



SIFT has released a new Intelligence Report titled 'A Web Services Security
Testing Framework'. The framework covers the entire web services security
testing process incorporating detailed threat modelling, scoping and
planning methodologies tailored specifically for web services applications.
It also provides a structured approach to assessing the security of a web
service through an application-level penetration test and aims to deliver a
repeatable means for security assurance.

A primary goal of this framework is to stimulate community interest and
drive the further development and adoption of structured security assurance
methodologies for web services. We welcome mailing list subscribers to
review the paper and will endeavour to incorporate feedback in future
versions of the framework.

Please send feedback and suggestions to research@xxxxxxxxxxxx

The paper is available for download from the SIFT website:
http://www.sift.com.au/36/175/a-web-services-security-testing-framework.htm

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.
http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



Relevant Pages

  • Re: Book on WS-Security
    ... I don't know of a book, but for a slice of this (sans SAML and XML ... sig/encryption) feel free to download my powerpoint on Web Services Security ... You can dowload the powerpoint from there. ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: Avoiding data theft
    ... It is a web services security guide published by the Microsoft Patterns & ... Malicious user eavesdrops on that call and copies the user-specific ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: Web Services Network Infrastructure
    ... You might want to check out Web Services Security Patterns and Practices ...
    (microsoft.public.dotnet.framework.webservices)
  • Re: ByRef/Ref passing in Web Services
    ... Okay what I meant by a dumb schema was - here is an example - ... > the'yre XML messages. ... > .NET framework will map a ref param onto WebServices semantics". ... > to web services is from an object mindset which is fatal. ...
    (microsoft.public.dotnet.framework)
  • Re: ByRef/Ref passing in Web Services
    ... > say "The .NET framework will map a ref param onto WebServices semantics". ... > approach to web services is from an object mindset which is fatal. ... > framework (SOAP, WSDL, XSD, etc). ... > implementation of web services that wants to map XML messages onto classes ...
    (microsoft.public.dotnet.framework)