PWSSec: Process for Web Services Security
Carlos A. Gutierrez, Eduardo Fernández‐Medina, Mario G. Piattini
Abstract
Carlos A. Gutierrez, Eduardo Fernández‐Medina, Mario G. Piattini
Abstract
In the last few years, the field of Web services (WS) security has evolved rapidly producing an impressive number of WS-based security standards. This fact has caused that organizations are still reticent about adopting technologies based on this paradigm due to the learning curve necessary to integrate security into their practical deployments. In this paper, we present PWSSec (process for Web services security) as a process that enables the integration of a set of specific stages into the traditional phases of WS-based systems development providing them with security. PWSSec is composed of three stages, WSSecReq (Web services security requirements), WSSecArch (Web services security architecture) and WSSecTech (Web services security technologies) that allow the specification of WS-specific security requirements, the definition of the WS-based security architecture and the identification of the security standards that the security architecture must deploy, respectively
OpenAlex reports 36 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
In the last few years, the field of Web services (WS) security has evolved rapidly producing an impressive number of WS-based security standards. This fact has caused that organizations are still reticent about adopting technologies based on this paradigm due to the learning curve necessary to integrate security into their practical deployments. In this paper, we present PWSSec (process for Web services security) as a process that enables the integration of a set of specific stages into the traditional phases of WS-based systems development providing them with security. PWSSec is composed of three stages, WSSecReq (Web services security requirements), WSSecArch (Web services security architecture) and WSSecTech (Web services security technologies) that allow the specification of WS-specific security requirements, the definition of the WS-based security architecture and the identification of the security standards that the security architecture must deploy, respectively
Key concepts: Web application security, Computer science, Security service, Security information and event management, Web service, Computer security, Computer security model, Cloud computing security