Secure Coding mailing list archives
Web Services vs. Minimizing Attack Surface
From: johwi at ida.liu.se (John Wilander)
Date: Wed, 16 Aug 2006 11:22:36 +0200
Thanks for all the replies so far! I would just like to comment on Holger Peine's and Mike Hines' viewpoints. Holger.Peine at iese.fraunhofer.de wrote:
I don't see a conflict here: A web service (just as any network-accessible service, no matter whether programmed using sockets, Java RMI, SOAP or whatever) is _intended_ to provide some function to the outside world, so you have to open _some_ door into your system. The advice about minimizing the attack surface is about not opening any doors you don't really need (or worse, didn't even intend to open).
As you say, any kind of system is _intended_ to provide some function.
But security bugs often hide in unintended, undocumented or unknown
functionality. By increasing the attack surface you also increase the
risk of adding unknown functions.
Mike Hines commented on web services running everything through port 80
(HTTP) as negating "... any value of firewalls and most likely intrusion
detection systems". Indeed, web services tunnel a lot of functionality
through port 80, effectively hiding it from many system monitoring
defense measures. The security will rely on validating SOAP envelopes
and prevention at the application/run-time system level. It seems to me
like a huge burden.
Regards, John
____________________________
John Wilander, PhD student
Computer and Information Sc.
Linkoping University, Sweden
http://www.ida.liu.se/~johwi
Current thread:
- Web Services vs. Minimizing Attack Surface John Wilander (Aug 15)
- Web Services vs. Minimizing Attack Surface Gunnar Peterson (Aug 15)
- Web Services vs. Minimizing Attack Surface Nash (Aug 15)
- <Possible follow-ups>
- Web Services vs. Minimizing Attack Surface Holger.Peine at iese.fraunhofer.de (Aug 15)
- Web Services vs. Minimizing Attack Surface Gadi Evron (Aug 15)
- Web Services vs. Minimizing Attack Surface John Wilander (Aug 16)
- Web Services vs. Minimizing Attack Surface mikeiscool (Aug 16)
- Web Services vs. Minimizing Attack Surface Gadi Evron (Aug 16)
- Web Services vs. Minimizing Attack Surface Gunnar Peterson (Aug 16)
- secure integer library Robert C. Seacord (Aug 17)
- secure integer library Pascal Meunier (Aug 17)
- secure integer library Robert C. Seacord (Aug 17)
