Announce - Wrox Press releases "Professional Web Services Security" book

From: Manjiri (manjiride@wrox.com)
Date: 12/30/02


From: manjiride@wrox.com (Manjiri)
Date: 30 Dec 2002 06:29:42 -0800

Today web services is attracting many businesses to incorporate the
technology, and soon many applications are seen using it. Web services
offers certain benefits over other technologies, one of them being
integration, making it suitable for e-business. They are faster and
cheaper to develop, easier to deploy and be discovered, and offer more
flexibility and interoperability. However, these advantages come along
with some security risks, which is the primary concern for most
managers today. The security architecture designed for the Web is
limited when used for the web services architecture, and the need for
new standards is realized. The solutions to these problems are
emerging and standards are being created for the Internet world to
quickly adapt to the new security architecture.

These emerging security standards that promise to solve most of the
security threats is the primary focus of this book. It pinpoints the
security loopholes in the current system with web services in mind.
The use cases stating the problem area along with the various
available techniques, standards, and toolkits are discussed to help
developers understand, develop, and deploy a secured web service.

Overview:
Professional Web Services Security" ISBN 1861007655 is a book for
those who have worked on web services and on enterprise level
applications. It is for those who plan to migrate to this wonderful
technology of the future but have stopped themselves for fear of
writing insecure applications plagued by "Internet hackers." This book
will kick start your learning of various concepts of security in an
XML and SOAP filled world and provide you with case studies and
template code. The book transcends the platform and language barriers
by providing code samples in both Java and C# languages.

The book is divided into three parts: concepts, principles, and
application. It first introduces the concept of web services, and then
introduces the concept of security and the technology associated with
security. A detailed analysis of various concepts of technology like
the Authentication mechanisms, SSL, PKI, XML Signatures, XML
Encryption, XML Key Management etc. follow, giving the reader the need
for each of these technologies, what the specifications say, how one
can practically apply these tools and the relative advantages and the
limitations of each one of these.

Finally, to apply all the concepts and to give you an idea of
implementing security in your applications, the books comes up with
two case studies – one in Java and the other in C# that contains
practical modular code which you can use as a template code for your
application.

The book covers a broad spectrum of topics related to security for web
services. With a simplistic and practical approach, this book will
eliminate your need to buy any other commercial literature on the
aspects of web services security and can provide you with some
practical and modular code for your applications. Even if you don't
intend to indulge in security at this moment, this book will help you
realize the importance of it in you web services applications.

Read more at www.wrox.com/books/1861007655.htm

For any further information or reviewing the book contact :
manjiride@wrox.com



Relevant Pages

  • Announce - Wrox Press releases "Professional Web Services Security" book
    ... Today web services is attracting many businesses to incorporate the ... technology, and soon many applications are seen using it. ... The security architecture designed for the Web is ...
    (comp.security.unix)
  • Re: Wavelets and Encryption
    ... >>determining if there are applications of the technology. ... then the relevance of wavelets to encryption ... I didn't say these were insecure, just that questioning their security ...
    (sci.crypt)
  • Federated Security Applications and Implications.
    ... web services. ... Is there any solution out there which implements federated security model ... Is this viable or does this technology has the pie in the sky status? ... SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers of ...
    (Focus-Microsoft)
  • Microsoft .NET
    ... reading up various documents that discuss - "What is Microsoft .Net" ... I'm trying to write a paper on security and software development using ... utilize connected solutions using Web services, ... language, of course, but also: ...
    (microsoft.public.dotnet.general)
  • Re: C# Exceptions
    ... What attack scenarios could be possible on such an application? ... > Are these issues really a security threat for a desktop application? ... > this application gets from its web services. ... > Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)