<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Cross-organizational Service Security { Solutions for Attack Modeling and Defense</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Andre Miede Supervised by Ralf Steinmetz</string-name>
          <email>Andre.Miede@KOM.tu-darmstadt.de</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Multimedia Communications Lab, KOM</institution>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Technische Universitat Darmstadt Department of Electrical Engineering &amp; Information Technology Merckstra e 25</institution>
          ,
          <addr-line>D-64283 Darmstadt</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Security is an important aspect of Service-oriented Architectures (SOAs), enabling the service-based integration of partner IT systems across organizational boundaries, i. e., in the Internet of Services. Current trends in SOA security, e. g., reducing it to Web service security, do not take into account SOA-speci c threats, vulnerabilities, and attacks. In this paper, measures to support the modeling of attacks in general and in order to show the service-oriented di erence regarding security are introduced. Based on this understanding, mechanisms to defend against SOA-speci c attacks will be designed and evaluated.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>Challenging market dynamics and the rise of complex value networks require
organizations to adjust their business processes rapidly in order to stay
competitive. As many organizational processes are supported or even enabled by
information technology (IT), a process is only as exible as its underlying
technological representation. A special integration challenge in this context are processes
which span across organizational boundaries, e. g., customer creation processes,
where data has to be checked against external watch lists in order to ght
organized crime. Another example are trading processes in investment banking,
where market data or credit ratings are bought from external providers.</p>
      <p>
        The Service-oriented Architecture paradigm (SOA) [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] o ers possibilities on
both a technological and organizational level to integrate company-wide and
inter-company IT systems. SOAs are based on the \service" concept, where
services can be seen as black boxes representing business functionalities. These
services are used to assemble business processes as service compositions and may
even cross enterprise boundaries, thus, being cross-organizational service-based
work ows [
        <xref ref-type="bibr" rid="ref2 ref3">2, 3</xref>
        ], e. g., in the Internet of Services scenario [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>The rest of the paper is structured as follows: Section 2 presents the problem
statement and the research questions which are at the foundation of my thesis.
Section 3 structures both preliminary results and open challenges for the
proposed questions. Section 4 concludes the paper and gives an outlook on next
steps.</p>
      <p>Problem Statement and Research Objectives
Just as any economic system requires security in order to work and to be accepted
by its participants, the security of the involved systems, exchanged messages, and
used communication channels has to be ensured for cross-organizational
servicebased collaboration. Achieving and guaranteeing basic IT security goals such
as con dentiality, authentication, authorization, non-repudiation, integrity, and
availability [5{7] is an absolute must in this context and still an active topic,
both in research and industry. Thus, the di erences SOA introduces into the
eld of IT security have to be analyzed and addressed.</p>
      <p>The main tenor of current SOA security research is that conventional security
measures are not su cient in the SOA context [2, 8{10]. For example, a major
argument in this context is the necessity to switch from point-to-point-security
to end-to-end-security, because any used service can call an arbitrary number of
di erent services on its own. Another argument is the need for decoupled security
decision points, in SOA usually called security-as-a-service. Yet another trend
is to equalize SOA security with Web service security, reducing SOA security
requirements to Web service security standards and their con guration.</p>
      <p>While these approaches are important building blocks for SOA security, they
are not su cient as they do not take into account SOA-speci c threats,
vulnerabilities, and the corresponding attacks. In order to close this gap, the following
research challenges and objectives were identi ed:
1. Analyze SOAs regarding security challenges and speci c attack scenarios,
e. g., for the Internet of Services. The analysis must not be limited to
particular SOA implementations, i. e., Web services, but focuses on SOA
characteristics such as loose coupling, composability, etc. Based on the analysis of
these security impacts, SOA-speci c attacks have to identi ed and modeled.
2. Develop means to understand and model attacks in general, i. e., analyze
and de ne the elements they consist of. This objective is not service-speci c,
but a general IT security challenge. The results of this objective are used to
model the SOA-speci c attacks identi ed in the rst objective.
3. Provide technology-independent solutions to defend against SOA-speci c
attacks. Based on the modeled attack scenarios, selected countermeasures have
to be developed or adapted from other areas of research in order to make
cross-organizational SOA scenarios safer.</p>
      <p>The next section discusses my proposed solutions and their expected outcomes
for theses challenges.
3</p>
      <p>Proposed Solutions and Expected Outcomes
Addressing the research challenges and objectives outlined in Section 2, my
research focuses on the following solution building blocks as depicted in Figure 1.
In the following, for each of these solution building blocks, rst results, their
impact, and the progress beyond the state of the art is brie y discussed.
A Generic Metamodel for IT Security</p>
      <p>Core</p>
      <p>Cross-organizational Service-oriented Architectures</p>
      <p>ASpcpelnicaartioiosn Metamodel
Attacks</p>
      <p>Countermeasures</p>
      <p>Security Analysis
Attacks on Cross-organizational Service-oriented Architectures</p>
      <p>Taxonomy</p>
      <p>Scenarios, e.g.,
Internet of Services</p>
      <p>Model Inventory</p>
      <p>Simulation
(ATCK.KOM)</p>
      <p>Selected Attack Defense Mechanisms for</p>
      <p>Cross-organizational Service-oriented Architectures
Trust/Reputation Obfuscation Profiling</p>
      <p>Service-Proxy-Architecture</p>
      <p>Self-X Mechanisms
Prototype Suite (DFENS.KOM)</p>
      <p>
        Evaluation
Cross-organizational SOA security deals with the application of core IT
security concepts such as threats, vulnerabilities etc. on the elements of
crossorganizational SOA such as loose coupling, composability, etc. These elements
are assembled in the form of a metamodel which is based on SOA de nitions and
descriptions found in standard literature on SOA [2, 3, 11{13] (cf. Figure 2). The
goal is to evaluate the security impact of single SOA elements and their
relationships. While single security aspects of these elements are already well-known,
i. e., for distributed systems characteristics, the combination of and relationships
between the SOA elements as well as their impact makes cross-organizational
SOA a special security challenge [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. An example for such an impact is
compromising an organization's legal or regulatory compliance, which can result in
nes, the revocation of licenses, or loss of customer trust. Composability has
also a high security impact, creating seams for exploitation, e. g., caused by the
incomplete integration of di erent security technology, or by the possibility to
introduce malicious services into the composition.
      </p>
      <p>
        Compared to standard literature on SOA [2, 3, 11{13], which di er in their
de nitions, presentation, and coverage of SOA core elements, this approach o ers
a compact and visual inventory as a basis for communication and analysis, i. e.,
a dedicated SOA security analysis.
The proposed generic metamodel for IT security [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] brings together the most
important ideas of IT security (including their relationships) and consists of three
main parts: a Core of basic IT security concepts, Attacks, and Countermeasures.1
It lays the foundation for describing and understanding the di erent elements of
attacks and countermeasures in an IT security context.
      </p>
      <p>1http://www.kom.tu-darmstadt.de/~miede/soasecurity/secmetamodel.pdf
Distribution
Heterogeneity</p>
      <p>is
Loose
Coupling</p>
      <p>Business
processorientation
Distributed</p>
      <p>Systems
Characteristic
is
has</p>
      <p>Reusable</p>
      <p>Stateless</p>
      <p>Composable</p>
      <p>
        In order to show the applicability of the metamodel to real-life scenarios,
attacks on di erent distributed systems were modeled, i. e., on Peer-to-Peer
systems, on Mobile ad hoc Networks, and on SOAs. Compared to similar concepts
such as attack patterns [
        <xref ref-type="bibr" rid="ref15 ref16">15, 16</xref>
        ] or security patterns [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ], this metamodel o ers
building blocks which help with actually assembling such patterns, thus,
improving the means to understand and model attack knowledge.
3.3
      </p>
      <p>
        Attacks on Cross-organizational Service-oriented Architectures
Cross-organizational SOA-speci c attacks target vulnerabilities of single SOA
elements and combinations thereof (cf. Figure 2). All types of attacks which
are already known from classic distributed systems or which focus on speci c
technologies, i. e., Web services, are not considered cross-organizational
SOAspeci c attacks. This is due to the fact that these attacks can also occur outside
SOA contexts. Examples for such attacks are XML injections to manipulate the
structure of messages or Denial of Service attacks via oversized payload using
a very large message [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. However, these attacks still pose a threat for
crossorganizational SOA and have to be addressed by common countermeasures such
as message validation and processing mechanisms [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. This approach is depicted
in Figure 3, using abstraction layers as an attack taxonomy for SOA.
      </p>
      <p>Examples are service selection attacks, where di erences in the security level a
provider o ers are exploited. The analysis of service
consumer-provider-communication can also be an attack to gather information about the business (requests,
used providers, time, frequency, etc.). Loosely coupled and malicious service
compositions are a likely attack as well, if \good" services are encapsulated by
\bad" ones in order to manipulate data or to gather information.</p>
      <p>
        Compared to other work on SOA attacks [
        <xref ref-type="bibr" rid="ref10 ref18 ref2 ref8">2,8,10,18</xref>
        ] which have a strong focus
on Web service technologies, this approach adds insights on attack scenarios
which target speci c SOA elements such as loose coupling and composability.
      </p>
      <p>Goal
has
builds on
Service
is</p>
      <p>Compliance with</p>
      <p>Internal</p>
      <p>Legal</p>
      <p>Regulatory
utilizes</p>
      <p>Infrastructure</p>
      <p>part-of
has
Autonomous</p>
      <p>Selfcontained</p>
      <p>Formal
Contract</p>
      <p>Enterprise
Service Bus
Service
Repository
Application
Frontend
i-suB ssen</p>
      <p>Actual process vs. target process
Combination of all systems and technology below
SOA concepts (loose coupling, composability,...)
Communication payload (SQL, XML,...)
Message exchange (HTTP(S), JMS, SOAP,...)</p>
      <p>Network traffic, packets, transport (TCP,IP,...)
Based on the above results, several areas of interest for defense mechanisms were
identi ed and now have to be evaluated regarding their potential for deeper
research activities. These areas are the following:
1. decentralized service provider reputation for securing service compositions,
2. communication obfuscation to avoid the exposure of information about
business activities in the case of tra c analysis, and
3. service consumer pro ling for detecting malicious service consumer behaviour.
It is planned not to pursue each of these areas in full depth, but to develop
initial concepts in order to determine which area is the most fruitful for valuable
contributions beyond existing approaches.</p>
      <p>A proxy-infrastructure as basis for the above areas is already in
development and based on an open-source SOA platform. There, service consumer and
provider communication is relayed via a messaging system which was enhanced
to forward messages to a proxy system (DFENS.KOM). Via a con guration
policy, this proxy is planned to trigger certain dedicated agents, e. g., for pro ling
consumer behaviour and checking against existing pro les, for obfuscating the
communication to complicate tra c analysis, or for gathering reputation
information about consumer and provider.
4</p>
    </sec>
    <sec id="sec-2">
      <title>Conclusions and Future Work</title>
      <p>As outlined above, the basic structure as well as the theoretical and conceptual
foundation of the thesis is already in place (Sections 3.1{3.3) and will be further
re ned as follows:
{ a critical revision of the SOA metamodel elements regarding completeness,
redundancies, and relationships,
{ further extensions of the IT security metamodel regarding countermeasures,
{ adapting both metamodels to the Meta-Object Facility (MOF) standard,2
{ identifying attack sub-steps from lower layers, the creation of a detailed
attack model inventory, and implementing attack models for simulating attack
behaviour in an Internet of Services scenario (ATCK.KOM).
However, the next major step will be to determine which of the above areas
(reputation, obfuscation, pro ling) to pursue further and in what direction. Basis for
this will be an extensive review of related work, its applicability to the identi ed
SOA-speci c attack scenarios, and own initial solution concepts. Furthermore,
appropriate evaluation techniques for such defense mechanisms have to be
devised. This includes determining the evaluation basis, i. e., using a testbed based
on our extensions of an open-source SOA platform or using simulation models
for Internet of Services attacks and countermeasures.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Papazoglou</surname>
            ,
            <given-names>M.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Traverso</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Dustdar</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Leymann</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          , Kramer, B.J.:
          <source>ServiceOriented Computing Research Roadmap. In: Dagstuhl Seminar Proceedings on Service Oriented Computing (SOC)</source>
          .
          <article-title>(</article-title>
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Josuttis</surname>
            ,
            <given-names>N.M.:</given-names>
          </string-name>
          <article-title>SOA in Practice: The Art of Distributed System Design (Theory in Practice)</article-title>
          .
          <source>O'Reilly Media, Inc. (8</source>
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Newcomer</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lomow</surname>
          </string-name>
          , G.:
          <article-title>Understanding SOA with Web Services (Independent Technology Guides)</article-title>
          .
          <source>Addison-Wesley Professional (12</source>
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Janiesch</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ruggaber</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sure</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          :
          <article-title>Eine Infrastruktur fur das Internet der Dienste</article-title>
          .
          <source>HMD { Praxis der Wirtschaftsinformatik</source>
          <volume>261</volume>
          (
          <issue>45</issue>
          ) (
          <year>2008</year>
          )
          <volume>71</volume>
          {79 (in German).
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Eckert</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          : IT-Sicherheit:
          <article-title>Konzepte { Verfahren { Protokolle. 5th edn</article-title>
          .
          <source>Oldenbourg (11</source>
          <year>2007</year>
          )
          <article-title>(in German)</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Schneier</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Secrets and Lies: Digital Security in a Networked World</article-title>
          . Wiley (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Bishop</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          : Computer Security: Art and
          <string-name>
            <surname>Science.</surname>
          </string-name>
          Addison-Wesley (
          <year>12 2002</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Kanneganti</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chodavarapu</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          : SOA Security.
          <source>Manning Publications (1</source>
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Hafner</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Breu</surname>
          </string-name>
          , R.:
          <article-title>Security Engineering for Service-Oriented Architectures</article-title>
          . Springer, Berlin (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <article-title>Bundesamt fur Sicherheit in der Informationstechnik: SOA-Security-Kompendium: Sicherheit in Service-</article-title>
          orientierten
          <string-name>
            <surname>Architekturen</surname>
          </string-name>
          (
          <year>2008</year>
          )
          <article-title>(in German)</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Krafzig</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Banke</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Slama</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <string-name>
            <surname>Enterprise</surname>
            <given-names>SOA</given-names>
          </string-name>
          :
          <string-name>
            <surname>Service-Oriented Architecture Best Practices. Prentice Hall</surname>
            <given-names>PTR</given-names>
          </string-name>
          (11
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Melzer</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          , et al.:
          <article-title>Service-orientierte Architekturen mit Web Services</article-title>
          .
          <source>Konzepte { Standards { Praxis. 2nd edn. Spektrum Akademischer</source>
          Verlag (
          <year>2007</year>
          )
          <article-title>(in German)</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Erl</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          :
          <article-title>Service-Oriented Architecture (SOA): Concepts, Technology, and</article-title>
          <string-name>
            <surname>Design. Prentice Hall PTR</surname>
          </string-name>
          (8
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Miede</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gottron</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          , Konig,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Nedyalkov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            ,
            <surname>Repp</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            ,
            <surname>Steinmetz</surname>
          </string-name>
          , R.:
          <article-title>Crossorganizational Security in Distributed Systems</article-title>
          .
          <source>Technical Report KOM-TR-2009- 01</source>
          , Technische Universitat
          <string-name>
            <surname>Darmstadt</surname>
          </string-name>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Hoglund</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>McGraw</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          :
          <article-title>Exploiting Software: How to Break Code</article-title>
          .
          <source>AddisonWesley (2</source>
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Barnum</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sethi</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Attack Patterns. \Build Security In" Initiative of the National Cyber Security Division of the U.S. Department of Homeland Security (</article-title>
          <year>2006</year>
          ) https://buildsecurityin.us-cert.gov/daisy/bsi/articles/ knowledge/attack.html.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Schumacher</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          : Security Engineering with Patterns: Origins,
          <source>Theoretical Models, and New Applications. 1 edn</source>
          . Springer (9
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18.
          <string-name>
            <surname>Jensen</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gruschka</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Herkenhoner</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Luttenberger</surname>
            ,
            <given-names>N.: SOA</given-names>
          </string-name>
          and
          <string-name>
            <surname>Web Services</surname>
          </string-name>
          : New Technologies, New Standards - New Attacks.
          <source>In: ECOWS '07: Proceedings of the Fifth European Conference on Web Services</source>
          . (
          <year>2007</year>
          )
          <volume>35</volume>
          {
          <fpage>44</fpage>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>