Secure Coding mailing list archives
Web Services vs. Minimizing Attack Surface
From: johwi at ida.liu.se (John Wilander)
Date: Tue, 15 Aug 2006 10:03:07 +0200
Hi!
The security principle of minimizing your attack surface (Writing Secure
Code, 2nd Ed.) is all about minimizing open sockets, rpc endpoints,
named pipes etc. that facilitate network communication between
applications. Web services and Service Oriented Architecture on the
other hand are all about exposing functionality to offer interoperability.
Have any of you had discussions on the seemingly obvious conflict
between these things? I would be very happy to hear your conclusions and
opinions!
Regards, John
____________________________
John Wilander, PhD student
Computer and Information Sc.
Linkoping University, Sweden
http://www.ida.liu.se/~johwi
Current thread:
- Web Services vs. Minimizing Attack Surface John Wilander (Aug 15)
- Web Services vs. Minimizing Attack Surface Gunnar Peterson (Aug 15)
- Web Services vs. Minimizing Attack Surface Nash (Aug 15)
- <Possible follow-ups>
- Web Services vs. Minimizing Attack Surface Holger.Peine at iese.fraunhofer.de (Aug 15)
- Web Services vs. Minimizing Attack Surface Gadi Evron (Aug 15)
- Web Services vs. Minimizing Attack Surface John Wilander (Aug 16)
- Web Services vs. Minimizing Attack Surface mikeiscool (Aug 16)
- Web Services vs. Minimizing Attack Surface Gadi Evron (Aug 16)
- Web Services vs. Minimizing Attack Surface Gunnar Peterson (Aug 16)
- secure integer library Robert C. Seacord (Aug 17)
- secure integer library Pascal Meunier (Aug 17)
