80 likes | 99 Views
Web service security, OWASP, web application, threats
E N D
OWASP Web Services Project How OWASP can become the leading destination for “Web Service Application Security” Alex Smolen OWASP So Cal Chapter
What are web services? • Web applications vs. web services • Examples of web services • Why web services?
Web Service Security • Transport Layer • SSL • Message Layer • WS-Security • XML Encryption, XML Signature, SAML,… • WS-* • Application Layer • OWASP Top Ten +
Additional Application Threats to Web Services • Parser Attacks • XML Bombs • External Entities • Backend Attacks • XPath, XQuery • XML Injection • Logical Attacks
Web Service Security Resources • OASIS • Microsoft, IBM, Sun, etc… • Books, blogs, articles • Why OWASP?
Current Projects • WebGoat 3.7 • OWASP Guide • OWASP Testing Guide
Additional Ideas • WebScarab • Web service security landing page • FAQ • Tools for web service developers (?)
How You Can Help • Learn about Web Service Security • Join OWASP Web Services Mailing List • Work on OWASP Web Services Project Charter • Contribute to OWASP Web Services Projects • Contact me (asmolen@parasoft.com, alex.smolen@owasp.org)