Inderscience PublishersInderscience PublishersInderscience Publishers About Inderscience Contact Information Current Site Map General Help
  PUBLISHERS OF DISTINGUISHED ACADEMIC, SCIENTIFIC AND PROFESSIONAL JOURNALS

The full text of this article:

Formal modelling and analysis of XML firewall for service-oriented systems
by Haiping Xu, Mihir Ayachit, Abhinay Reddyreddy
International Journal of Security and Networks (IJSN), Vol. 3, No. 3, 2008
Abstract: Firewalls have been designed as a major component to protect a network or a server from being attacked. However, due to their emphasis on packet filtering rather than verifying user permissions and examining packet contents, conventional firewalls are not suitable for protecting service-oriented systems from unauthorised service invocations. In this paper, we present a formal XML firewall security model for service-oriented systems, which supports user authentication and role-based user authorisation according to policy rules that can be updated dynamically. The formal model consists of two major components, namely the application model and the XML firewall model, which are designed compositionally using coloured Petri nets. We analyse both the application model and the XML firewall model using an existing Petri net tool, and demonstrate how key properties of the formal models can be verified, and how design errors can be detected and corrected at an early design stage.

is only available to individual subscribers or to users at subscribing institutions.

ATTENTION SUBSCRIBERS:
Please re-direct your browser by clicking on this Inderscience Online Journals link, to access the full-text of this article.

Pay per view: If you are not a Subscriber and you just want to read the full contents of this article, please click here to purchase online access to the full-text of this article. Please allow 3 days + mailing time. Current price for article is Thirty Euros (€30)

Complimentary Subscribers, Editors or Members of the Editorial Board of the International Journal of Security and Networks (IJSN) journal, that have been redirected here, please check if you have a registered username/password subscription with Inderscience. If that is the case, please Login:

    Username:        Password:         Forgotten your Password?

If you are not yet a Subscriber to International Journal of Security and Networks (IJSN) journal, you can subscribe by following a few simple and quick steps. A subscription will give you complete access to all articles in the current issue, as well as to all articles in the previous three years, where applicable. Click here to subscribe.

Should you experience further difficulties or have any enquiries, please email subs@inderscience.com