80 likes | 97 Views
OWASP Web Services Project. How OWASP can become the leading destination for “Web Service Application Security”. Alex Smolen OWASP So Cal Chapter. What are web services?. Web applications vs. web services Examples of web services Why web services?. Web Service Security. Transport Layer
E N D
OWASP Web Services Project How OWASP can become the leading destination for “Web Service Application Security” Alex Smolen OWASP So Cal Chapter
What are web services? • Web applications vs. web services • Examples of web services • Why web services?
Web Service Security • Transport Layer • SSL • Message Layer • WS-Security • XML Encryption, XML Signature, SAML,… • WS-* • Application Layer • OWASP Top Ten +
Additional Application Threats to Web Services • Parser Attacks • XML Bombs • External Entities • Backend Attacks • XPath, XQuery • XML Injection • Logical Attacks
Web Service Security Resources • OASIS • Microsoft, IBM, Sun, etc… • Books, blogs, articles • Why OWASP?
Current Projects • WebGoat 3.7 • OWASP Guide • OWASP Testing Guide
Additional Ideas • WebScarab • Web service security landing page • FAQ • Tools for web service developers (?)
How You Can Help • Learn about Web Service Security • Join OWASP Web Services Mailing List • Work on OWASP Web Services Project Charter • Contribute to OWASP Web Services Projects • Contact me (asmolen@parasoft.com, alex.smolen@owasp.org)