CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 941
Comments: 25
block bottom
spacer spacer
image Security HeadLines: Web Services: Protecting Yourself from Partners' Security Problems image
Protocols

OASIS unveils XML schema to provide initial threat, impact, and risk ratings guidance in consistent manner

The Organization for the Advancement of Structured Information Standards (OASIS), a global consortium that sets worldwide standards for security, Web services, conformance, business transactions, electronic publishing, topic maps, and interoperability within and between marketplaces, announced its members are creating a new, open data format to describe Web application security vulnerabilities. The model will provide initial threat, impact, and risk ratings guidance for companies, as well as an XML schema to describe Web security conditions that can be used by both assessment and protection tools.






June 04, 2003
By Mathew Schwartz

The goal of the web applications security (WAS) standard will be to reduce the amount of redundant information produced for security vulnerability alerts, and simplify the process of understanding which systems are affected. In particular, the application vulnerability description language, as it’s also known, will create a uniform way of describing application security vulnerabilities through the XML format.

“The growing sophistication of security threats requires standards for classifying risk and determining the impact of new Web Security vulnerabilities,” notes Gerhard Eschelbeck, chief technology officer and vice president of engineering of security audit company Qualys Inc. in Redwood Shores, Calif.

The potential of Web Services is to increase the flow and automation of information exchange between Web servers, or between servers and people. Unfortunately, tying different servers together—often across different corporate firewalls—means that organizations are exposed to a greater range of security threats. What starts out as a breach in a partner’s Web server can quickly work its way into a Web Services partner’s server, or an attacker can compromise the integrity of data flowing between servers, potentially sabotaging important information. In a supply chain, for example, incorrect inventory requests could trigger unwanted manufacturing operations, with grave financial consequences.

To deal with potential Web Services threats, organizations need more automated, standardized ways of disseminating security warnings, say experts.

Article continues...
Enterprise Systems


Posted on Wednesday, 04 June 2003 @ 07:05:00 UTC by cj (1130 reads)
[ Trackback ]
image

"Security HeadLines: Web Services: Protecting Yourself from Partners' Security Problems" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· HotScripts
· W3 Consortium
· TCP/IP Protocol Suite
· More about Protocols
· News by cj


Most read story about Protocols:
Free Online Port Scanning Utilities

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer