Infiltrate Testing Tool for Web Services Security

Abstract

For distributed computing solutions Web Services are widely used. Web Services technology is used to integrate existing homogenous or heterogeneous enterprise applications. It can also be used to build inter-operable components that can be reused by many applications irrespective of the platforms in which they are built. Service Oriented Architecture (SOA) is being used for such distributed applications. This architecture enables integration of many services and allows access through a single interface. As this technology is widely used many extension specifications came into existences which were developed by W3C. This has caused the rise in attacks on web services applications. The attacks include denial of service attacks to various other attacks that break security of the systems. Web application developers generally test their applications for security using penetration testing tools. However, for applications built using Web Services technology no such penetration testing tools are available. Mainka et al. developed a penetration testing tool by name WSAttacker which is plug-in based. They have implemented only two plugins namely SOAPAction Spoofing and WS-Address Spoofing. In this paper we improve the tool by implementing plugins for two more attacks namely Oversize Payload Attack, Oversized Encryption Attack. The WSAttacker is meant for testing web services applications for security. The empirical results revealed that the proposed plugins are effective and they could enhance the use of the tool.

Authors and Affiliations

Shaik Kabeer, Anjini Prasad S, Venkatesh D

Keywords

Related Articles

A NEW APPROACH FOR EVALUATING THE QUALITY OF DE-BLOCKED IMAGES

JPEG Compression is the most prevalent technique or method for images codecs. But it suffers from blocking artifacts. In this paper a comparison of the perceptual quality of deblocked images based on various quality...

A Novel approach on ɸ - Disposition Pulse Width Modulation for Modular Multilevel Inverter

In this project implemented a novel approach in the modulation technique based on selective virtual loop mapping, to attain dynamic capacitor voltage balance without any compensated signal.An improvised proposed metho...

WIRELESS MONITORING SYSTEM BASED ON ARM7 FOR INDUSTRIAL ISSUES

In Industries attendance of an employee and monitoring of production are done manually which causes less efficiency and accuracy, and more over it takes much time than monitoring systems. Another problem arises when...

Effective Routing Plan For Quality Results On Linked Data Using Keyword Search

Keyword search is a natural world view for seeking connected information sources on the web. We propose to route keywords just to pertinent sources to reduce the high cost of handling keyword search queries over all...

A survey on Transmission of data through illumination - Li-Fi

Li-Fi is a new wireless technology to provide the connectivity with in localized network environment. The main principle of this technology is we can transmit the data using light illumination by using light-emitting...

Download PDF file
  • EP ID EP27607
  • DOI -
  • Views 348
  • Downloads 3

How To Cite

Shaik Kabeer, Anjini Prasad S, Venkatesh D (2013). Infiltrate Testing Tool for Web Services Security. International Journal of Research in Computer and Communication Technology, 2(7), -. https://europub.co.uk/articles/-A-27607