|
Enterprise Web Services Security (Networking & Security)
Enterprise Web Services Security provides the information developers, application architects, and security professionals need to build security policies and strategies from the ground up in a Web Services environment. Most security books focus on computer, network, or Web Services Security in isolation, relegating the other areas to overview chapters
or appendices. This book takes a holistic approach that mirrors the perspective one must have regardless of whether they are planning and implementing the security mechanisms for a Web Service, a Web site, or an enterprise. It details how to secure critical components such as workstations, servers, and networks, the goals behind an enterprise's security policies, the policies an organization should have in place, and how to communicate those policies using WS-Policy Framework and WS-Security Policy. The book also covers various threats and attacks, and the identity management, authentication, authorization, access control, confidentiality, and integrity mechanisms needed to protect messages and transactions, including how to implement and communicate those mechanisms using WS-Security, XML Encryption, XML Signature, SAML, and XACML. The importance of auditing at both the server and network level and how to create trust relationships and domains are also covered. Enterprise Web Services Security explains in detail how to have all your security mechanisms working to successfully thwart attacks and protect assets.
Contents:
Chapter 1: Introduction and Overview
- Chapter 2: Threats and Attacks
- Chapter 3: Security Goals
- Chapter 4: The Internet and World Wide Web Infrastructure
- Chapter 5: Web Services
- Chapter 6: Security Policy Basics
- Chapter 7: Communicating Policy
- Chapter 8: Protecting the Physical Components
- Chapter 9: Protecting Messages, Transactions, and Data
- Chapter 10: Communicating Security Credentials
- Chapter 11: Audit
- Chapter 12: Virtual Domain Model for Web Services Security
- Chapter 13: Establishing and Communicating Trust Information
- Chapter 14: Putting it All Together - Using Virtual Trust Domains to Secure Web
- Appendix: About the CD-ROM
- Index.
|