<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Subu+Ramanathan</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Subu+Ramanathan"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Subu_Ramanathan"/>
		<updated>2026-05-06T10:11:12Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Subu_Ramanathan&amp;diff=81258</id>
		<title>User:Subu Ramanathan</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Subu_Ramanathan&amp;diff=81258"/>
				<updated>2010-04-12T22:07:45Z</updated>
		
		<summary type="html">&lt;p&gt;Subu Ramanathan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Subu Ramanathan is a security consultant with Security Compass. With his wide array of experience in application vulnerability assessments, penetration testing and source code review, Subu plays a valuable part in Security Compass’s Software and Enterprise Assessment Service practice. With reinforced fundamentals in software development, Subu brings to the table a sound understanding of the Software Development Life Cycles (SDLC). Subu is also involved in developing content for various JAVA and .NET based, developer focused security training courses including one offered by SANS institute.&lt;br /&gt;
&lt;br /&gt;
Subu holds a Bachelors in Applied Science and Engineering (Computer Engineering) from the University of Toronto.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* To see my wiki contributions, [[:Special:Contributions/Subu Ramanathan|click here]].&lt;br /&gt;
* [mailto:subu(at)securitycompass.com Email address].&lt;/div&gt;</summary>
		<author><name>Subu Ramanathan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Services_Security_Project&amp;diff=68382</id>
		<title>Category:OWASP Web Services Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Services_Security_Project&amp;diff=68382"/>
				<updated>2009-09-01T15:50:36Z</updated>
		
		<summary type="html">&lt;p&gt;Subu Ramanathan: /* Project Contributors */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main ====&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
Welcome to OWASP Web Services Security Project. This project is designed to serve as a starting point for any web services related inquiries on OWASP. Please note that this is NOT a standalone project and will draw upon relevant resources from other OWASP and external pages.&lt;br /&gt;
&lt;br /&gt;
== Goals ==&lt;br /&gt;
The OWASP Web Services Security Project aims to include and maintain a comprehensive list of links to OWASP and external resources.&lt;br /&gt;
&lt;br /&gt;
== Web Services Security ==&lt;br /&gt;
OWASP related Web Services links:&lt;br /&gt;
&lt;br /&gt;
[1] [http://www.owasp.org/index.php/Web_Services OWASP Web Services] - A comprehensive introduction to Web Services.&lt;br /&gt;
&lt;br /&gt;
[2] [http://www.owasp.org/index.php/Theres_More_to_Securing_Web_Services_Systems_Than_WS-Security There is More to Securing Web Services Systems Than WS Security] - Insightful page on Web Services Security.&lt;br /&gt;
&lt;br /&gt;
[3] [http://www.owasp.org/index.php/.NET_Web_Service_Validation .NET Web Service Validation] - .NET approach to validating Web Services.&lt;br /&gt;
&lt;br /&gt;
== Project Contributors ==&lt;br /&gt;
&lt;br /&gt;
If you contribute to this Project, please add your name here.&amp;lt;br&amp;gt;&lt;br /&gt;
Project Leads:&lt;br /&gt;
* [[User:Subu Ramanathan| Subu Ramanathan]]&lt;br /&gt;
* [[User:skazerooni| Sahba Kazerooni]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Web Services Standards ====&lt;br /&gt;
&lt;br /&gt;
== OWASP Web Services Standards Links ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Category:OWASP_Guide_Project OWASP Guide Project] - A comprehensive development guide on building secure Web Service Applications.&lt;br /&gt;
&lt;br /&gt;
== External Web Services Standards Links ==&lt;br /&gt;
&lt;br /&gt;
''This section of the page needs to be updated'' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Web Services Tools ====&lt;br /&gt;
&lt;br /&gt;
== OWASP Web Services Tools ==&lt;br /&gt;
[http://www.owasp.org/index.php/Category:OWASP_WSFuzzer_Project WSFuzzer]&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Category:OWASP_Interceptor_Project Interceptor]&lt;br /&gt;
&lt;br /&gt;
== External Web Services Tools ==&lt;br /&gt;
&lt;br /&gt;
''This section of the page needs to be updated'' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Testing Web Services ====&lt;br /&gt;
&lt;br /&gt;
== OWASP Links ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Testing_for_Web_Services Testing Web Services] - Comprehensive OWASP Guide on Testing Web Services.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
''This section of the page needs to be updated'' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Documents &amp;amp; Presentations ====&lt;br /&gt;
&lt;br /&gt;
== OWASP Documents and Presentations ==&lt;br /&gt;
&lt;br /&gt;
'''Documents Related to Web Services'''&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:Web_services_security.doc Web Services Security]&lt;br /&gt;
&lt;br /&gt;
'''Presentations Related to Web Services'''&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:InfoSec_World_2007_-_Web_services_gateways.ppt InfoSec World 2007] - Web Services Gateways presentation from InfoSec World 2007.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:AppSec2005DC-Alex_Stamos-Attacking_Web_Services.ppt Attacking Web Services] - OWASP AppSec 2005 DC presentation on Attacking Web Services by Alex Stamos.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:OWASPAppSec2006Seattle_Web_Services_Security.ppt WS Security] - OWASP AppSec 2006 Seattle presentation on Web Services Security.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:OWASPAppSecEU2006_InlineApproachforSecureSOAPRequests.ppt Secure SOAP Requests] - OWASP AppSec 2006 EU presentation on Inline Approach for Secure SOAP Requests.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:Don’t_drop_the_SOAP_OWASP.ppt Don't Drop the SOAP]&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:AppSec2005DC-Alex_Smolen-OWASP_WebServices_Project.ppt OWASP Web Services Project] - OWASP AppSec 2005 DC presentation on the OWASP Web Services Project by Alex Smolen.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:OWASPAppSecEU2006_ProtectingWebServicesAndAapplications.ppt Protecting Web Services] - OWASP AppSec 2006 EU presentation on Protesting Web Services and Applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== External Documents &amp;amp; Presentations ==&lt;br /&gt;
&lt;br /&gt;
''This section of the page needs to be updated''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== OLD_PAGE ====&lt;br /&gt;
== Welcome to the OWASP Web Services Security Project==&lt;br /&gt;
&lt;br /&gt;
[a brief about web services security in general and the current state of OWASP in web services security]&lt;br /&gt;
&lt;br /&gt;
The following document outlines a proposed layout for a new Web Services Security Project for the Open Web Application Security Project (OWASP).  &lt;br /&gt;
&lt;br /&gt;
== Current State ==&lt;br /&gt;
&lt;br /&gt;
'''Current Relevant OWASP Pages'''&lt;br /&gt;
&lt;br /&gt;
1.	Web Services&lt;br /&gt;
a.	Securing web services&lt;br /&gt;
b.	Communication security&lt;br /&gt;
c.	Passing credentials&lt;br /&gt;
d.	Ensuring message freshness&lt;br /&gt;
e.	Protecting message integrity&lt;br /&gt;
f.	Protecting message confidentiality&lt;br /&gt;
g.	Access control&lt;br /&gt;
h.	Audit&lt;br /&gt;
i.	Web services security hierarchy&lt;br /&gt;
i.	standard committees&lt;br /&gt;
j.	SOAP&lt;br /&gt;
i.	XML signatures and encryption&lt;br /&gt;
ii.	Security specifications&lt;br /&gt;
k.	WS-Security standard&lt;br /&gt;
i.	Organization of the standard&lt;br /&gt;
ii.	Purpose&lt;br /&gt;
l.	WS-Security Building blocks&lt;br /&gt;
i.	How data is passed&lt;br /&gt;
ii.	Security header’s structure&lt;br /&gt;
iii.	Types of tokens&lt;br /&gt;
iv.	Referencing message parts&lt;br /&gt;
m.	Communication protection mechanisms&lt;br /&gt;
i.	Integrity&lt;br /&gt;
ii.	Confidentiality&lt;br /&gt;
iii.	Freshness&lt;br /&gt;
n.	Access control mechanisms&lt;br /&gt;
i.	Identification&lt;br /&gt;
ii.	Authentication&lt;br /&gt;
iii.	Authorization&lt;br /&gt;
iv.	Policy agreement&lt;br /&gt;
o.	Forming web services chains&lt;br /&gt;
i.	Incompatible user access control models&lt;br /&gt;
ii.	Service trust&lt;br /&gt;
iii.	Secure connections&lt;br /&gt;
iv.	Synchronization of user directories&lt;br /&gt;
v.	Domain federation&lt;br /&gt;
p.	Available implementations&lt;br /&gt;
i.	.NET – Web services extensions&lt;br /&gt;
ii.	Java toolkits&lt;br /&gt;
iii.	Hardware software systems&lt;br /&gt;
q.	Problems&lt;br /&gt;
i.	Immaturity of the standards&lt;br /&gt;
ii.	Performance&lt;br /&gt;
iii.	Complexity and interoperability&lt;br /&gt;
iv.	Key management&lt;br /&gt;
r.	Further reading&lt;br /&gt;
&lt;br /&gt;
2.	A Tale of Two Systems&lt;br /&gt;
- case studies of two hypothetical systems, one of which involves openning a mainframe app to the web using a web service, and the risks that are posed.&lt;br /&gt;
&lt;br /&gt;
3.	Theres More to Securing Web Services Systems Than WS-Security&lt;br /&gt;
a.	What is a web service&lt;br /&gt;
b.	Web services from the information security perspective&lt;br /&gt;
c.	Some security implications of this perspective&lt;br /&gt;
i.	Emergent risks&lt;br /&gt;
ii.	End-to-end controls&lt;br /&gt;
d.	Interconnection of systems from different trust domains&lt;br /&gt;
i.	Some implications of the organization’s risk management process and system development life cycle&lt;br /&gt;
ii.	Emerging standards for securing web services&lt;br /&gt;
iii.	WS-Security specifications in process&lt;br /&gt;
iv.	Trust management revisited&lt;br /&gt;
e.	References&lt;br /&gt;
&lt;br /&gt;
4.	Web Services Architecture and Security&lt;br /&gt;
a.	The web services architecture&lt;br /&gt;
b.	Service oriented architectures and distributed systems&lt;br /&gt;
c.	Complexity is the enemy of security…&lt;br /&gt;
d.	The architectural models&lt;br /&gt;
e.	The policy model&lt;br /&gt;
f.	The service oriented model&lt;br /&gt;
g.	The resource oriented model&lt;br /&gt;
h.	The message oriented model&lt;br /&gt;
i.	The management model&lt;br /&gt;
j.	The rest&lt;br /&gt;
k.	References&lt;br /&gt;
&lt;br /&gt;
5.	Testing for Web Services (from OWASP Testing Guide)&lt;br /&gt;
a.	XML Structural Testing&lt;br /&gt;
b.	XML Content-level Testing&lt;br /&gt;
c.	HTTP GET parameters/REST Testing&lt;br /&gt;
d.	Naughty SOAP attachments&lt;br /&gt;
e.	Replay Testing&lt;br /&gt;
&lt;br /&gt;
6.	Image:Web services security.doc&lt;br /&gt;
&lt;br /&gt;
7.	Image:InfoSec_World_2007_-_Web_services_gateways.ppt&lt;br /&gt;
&lt;br /&gt;
8.	Image:AppSec2005DC-Alex_Stamos-Attacking_Web_Services.ppt&lt;br /&gt;
&lt;br /&gt;
9.	Image:OWASPAppSec2006Seattle_Web_Services_Security.ppt&lt;br /&gt;
&lt;br /&gt;
10.	.NET Web Service Validation&lt;br /&gt;
a.	Perfomance penalties&lt;br /&gt;
b.	Downloading&lt;br /&gt;
c.	Installation&lt;br /&gt;
d.	Reporting Bugs&lt;br /&gt;
e.	Use&lt;br /&gt;
i.	Methods of use&lt;br /&gt;
ii.	Attributes&lt;br /&gt;
iii.	Web.config changes&lt;br /&gt;
iv.	Using validation&lt;br /&gt;
v.	Using assertions&lt;br /&gt;
&lt;br /&gt;
11.	OWASP WSFuzzer Project&lt;br /&gt;
&lt;br /&gt;
12.	OWASP interceptor Project&lt;br /&gt;
&lt;br /&gt;
13.	OWASP Guide&lt;br /&gt;
&lt;br /&gt;
14.	OWASPAppSecEU2006_InlineApproachforSecureSOAPRequests.ppt&lt;br /&gt;
&lt;br /&gt;
15.	Category_talk:OWASP_XML_Security_Gateway_Evaluation_Criteria_Project&lt;br /&gt;
&lt;br /&gt;
16.	Don’t drop the SOAP OWASP.ppt&lt;br /&gt;
&lt;br /&gt;
17.	AppSec2005DC-Alex_Smolen-OWASP_WebServices_Project.ppt&lt;br /&gt;
&lt;br /&gt;
18.	AppSec2005DC-Jeff_Williams-OWASP_AppSec_Guide_2.0.ppt&lt;br /&gt;
&lt;br /&gt;
19.	OWASPAppSecEU2006_ProtectingWebServicesAndAapplications.ppt&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Content'''&lt;br /&gt;
&lt;br /&gt;
-	Completeness&lt;br /&gt;
&lt;br /&gt;
-	Relevance&lt;br /&gt;
&lt;br /&gt;
-	Target audience&lt;br /&gt;
&lt;br /&gt;
'''Organization'''&lt;br /&gt;
&lt;br /&gt;
-	Ease of navigation&lt;br /&gt;
&lt;br /&gt;
-	Ease of locating a specific topic&lt;br /&gt;
&lt;br /&gt;
-	Communication of updates&lt;br /&gt;
&lt;br /&gt;
'''Search'''&lt;br /&gt;
&lt;br /&gt;
-&lt;br /&gt;
&lt;br /&gt;
== Desired State ==&lt;br /&gt;
&lt;br /&gt;
'''Content'''&lt;br /&gt;
&lt;br /&gt;
-	Completeness&lt;br /&gt;
&lt;br /&gt;
-	Relevance&lt;br /&gt;
&lt;br /&gt;
-	Target audience&lt;br /&gt;
&lt;br /&gt;
'''Organization'''&lt;br /&gt;
&lt;br /&gt;
-	Ease of navigation&lt;br /&gt;
&lt;br /&gt;
-	Ease of locating a specific topic&lt;br /&gt;
&lt;br /&gt;
-	Communication of updates&lt;br /&gt;
&lt;br /&gt;
'''Search'''&lt;br /&gt;
&lt;br /&gt;
-&lt;br /&gt;
&lt;br /&gt;
== Proposed Layout ==&lt;br /&gt;
&lt;br /&gt;
The proposed OWASP Web Services Security Project will serve as a starting point for any web services-related inquiries on OWASP.  It will consist of a launchpad or home page with an introduction to the project, regular updates to pages in the project, and links to project pages and external resources. &lt;br /&gt;
&lt;br /&gt;
[[Image:WS_Launchpad.jpg|thumb|600px|LEFT|Launchpad Layout (click to see a bigger image)]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Introduction&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Updates&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;External Links&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;OWASP Pages&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Security Docs/Presentations&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Standards&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Communications&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;XML Security&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Testing Web Services&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Tools&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Gateways&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;SOA Architecture and Design&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Implementation Platforms&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;OWASP Top 10 Web Services Chapter&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Goals &amp;amp; Roadmap ==&lt;br /&gt;
&lt;br /&gt;
Currently the project goals are to:&lt;br /&gt;
&lt;br /&gt;
* Creation of launch pad layout&lt;br /&gt;
&lt;br /&gt;
* Create template start page for each subtopic &lt;br /&gt;
&lt;br /&gt;
* Find solid external resources&lt;br /&gt;
&lt;br /&gt;
* Recruit volunteer team (2-4 person)&lt;br /&gt;
&lt;br /&gt;
* For each topic: &lt;br /&gt;
&lt;br /&gt;
- Create start page for the subtopic topic&lt;br /&gt;
&lt;br /&gt;
- Gather all existing relevant articles within OWASP&lt;br /&gt;
&lt;br /&gt;
- Create plan of consolidating all the relevant information&lt;br /&gt;
&lt;br /&gt;
- Contact authors of relevant articles if change is required&lt;br /&gt;
&lt;br /&gt;
- Consolidate all information on the topic&lt;br /&gt;
&lt;br /&gt;
- Find solid external resources&lt;br /&gt;
&lt;br /&gt;
- Create link back to the main Web Services Security Project launchpad&lt;br /&gt;
&lt;br /&gt;
* Research way of communicating any updates to web services pages on launchpad&lt;br /&gt;
&lt;br /&gt;
* Search optimization (both OWASP and Google)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
A detailed project plan and schedule will be developed shortly and posted here.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Guiding Principles ==&lt;br /&gt;
&lt;br /&gt;
tbd&lt;br /&gt;
&lt;br /&gt;
== Resources and links ==&lt;br /&gt;
&lt;br /&gt;
This project is not standalone. This project will draw pieces of information from:&lt;br /&gt;
* OWASP Guide&lt;br /&gt;
* Other OWASP pages&lt;br /&gt;
* OWASP documents&lt;br /&gt;
* Relevant external links&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation: ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Web Services Security Project to be useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to sahba@securitycompass.com.&lt;br /&gt;
&lt;br /&gt;
== Project Contributors ==&lt;br /&gt;
&lt;br /&gt;
If you contribute to this Project, please add your name here.&amp;lt;br&amp;gt;&lt;br /&gt;
Project Leads:&lt;br /&gt;
* [[User:nbhalla| Nish Bhalla]]&lt;br /&gt;
* [[User:skazerooni| Sahba Kazerooni]]&lt;br /&gt;
* [[User:Subu Ramanathan| Subu Ramanathan]]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* you? ...&lt;br /&gt;
&lt;br /&gt;
==== Project Identification ====&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Web Services Security Project]]&lt;br /&gt;
[[Category:OWASP Project]]&lt;br /&gt;
[[Category:OWASP Document]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Document]]&lt;br /&gt;
&lt;br /&gt;
{{Template:OWASP Project Identification Tab&lt;br /&gt;
| project_name = OWASP Web Services Security Project&lt;br /&gt;
| project_description = This project is designed to serve as a comprehensive starting point for any web services related inquiries on the web&lt;br /&gt;
| project_license = [http://www.gnu.org/licenses/gpl-3.0.html '''GPL''']&lt;br /&gt;
| leader_name = Subu Ramanathan&lt;br /&gt;
| leader_email = &lt;br /&gt;
| leader_username = Subu Ramanathan&lt;br /&gt;
| maintainer_name = Subu Ramanathan&lt;br /&gt;
| maintainer_email = &lt;br /&gt;
| maintainer_username = Subu Ramanathan &lt;br /&gt;
| contributor_name1 = Sahba Kazerooni&lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = Skazerooni &lt;br /&gt;
| contributor_name2 = Subu Ramanathan&lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = Subu Ramanathan&lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = http://www.owasp.org/images/a/a9/Project_flyer.pdf&lt;br /&gt;
| presentation_link = http://www.owasp.org/index.php/File:Owasp_education_-_WS_Security_Project.pptx&lt;br /&gt;
| mailing_list_name = owasp-web-services&lt;br /&gt;
| links_url1 =  &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = &lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = First Release&lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = Subu Ramanathan&lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = Subu Ramanathan&lt;br /&gt;
| last_reviewed_release_name = &lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = &lt;br /&gt;
| last_reviewed_release_leader_name = &lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = &lt;br /&gt;
| current_release_details = :Category:OWASP Web Services Security Project - First Release &lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Subu Ramanathan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Subu_Ramanathan&amp;diff=68381</id>
		<title>User:Subu Ramanathan</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Subu_Ramanathan&amp;diff=68381"/>
				<updated>2009-09-01T15:45:26Z</updated>
		
		<summary type="html">&lt;p&gt;Subu Ramanathan: Added bio for Subu Ramanathan&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Subu Ramanathan is a security consultant with Security Compass. With his wide array of experience in application vulnerability assessments, penetration testing and source code review, Subu plays a valuable part in Security Compass’s Software Assessment Service practice. With reinforced fundamentals in software development, Subu brings to the table inept understanding of the Software Development Life Cycles (SDLC). Subu is also involved in developing content for various JAVA based, developer focused security training courses including one offered by SANS institute.&lt;br /&gt;
&lt;br /&gt;
Subu holds a Bachelors in Applied Science and Engineering (Computer Engineering) from the University of Toronto.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* To see my wiki contributions, [[:Special:Contributions/Subu Ramanathan|click here]].&lt;br /&gt;
* [mailto:subu(at)securitycompass.com Email address].&lt;/div&gt;</summary>
		<author><name>Subu Ramanathan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Services_Security_Project&amp;diff=66677</id>
		<title>Category:OWASP Web Services Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Services_Security_Project&amp;diff=66677"/>
				<updated>2009-07-27T17:22:50Z</updated>
		
		<summary type="html">&lt;p&gt;Subu Ramanathan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{:Template:Orphaned Projects}}&lt;br /&gt;
&lt;br /&gt;
==== Main ====&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
Welcome to OWASP Web Services Security Project. This project is designed to serve as a starting point for any web services related inquiries on OWASP. Please note that this is NOT a standalone project and will draw upon relevant resources from other OWASP and external pages.&lt;br /&gt;
&lt;br /&gt;
== Goals ==&lt;br /&gt;
The OWASP Web Services Security Project aims to include and maintain a comprehensive list of links to OWASP and external resources.&lt;br /&gt;
&lt;br /&gt;
== Web Services Security ==&lt;br /&gt;
OWASP related Web Services links:&lt;br /&gt;
&lt;br /&gt;
[1] [http://www.owasp.org/index.php/Web_Services OWASP Web Services] - A comprehensive introduction to Web Services.&lt;br /&gt;
&lt;br /&gt;
[2] [http://www.owasp.org/index.php/Theres_More_to_Securing_Web_Services_Systems_Than_WS-Security There is More to Securing Web Services Systems Than WS Security] - Insightful page on Web Services Security.&lt;br /&gt;
&lt;br /&gt;
[3] [http://www.owasp.org/index.php/.NET_Web_Service_Validation .NET Web Service Validation] - .NET approach to validating Web Services.&lt;br /&gt;
&lt;br /&gt;
== Project Contributors ==&lt;br /&gt;
&lt;br /&gt;
If you contribute to this Project, please add your name here.&amp;lt;br&amp;gt;&lt;br /&gt;
Project Leads:&lt;br /&gt;
* [[User:Subu Ramanathan| Subu Ramanathan]]&lt;br /&gt;
* [[User:nbhalla| Nish Bhalla]]&lt;br /&gt;
* [[User:skazerooni| Sahba Kazerooni]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Web Services Standards ====&lt;br /&gt;
&lt;br /&gt;
== OWASP Web Services Standards Links ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Category:OWASP_Guide_Project OWASP Guide Project] - A comprehensive development guide on building secure Web Service Applications.&lt;br /&gt;
&lt;br /&gt;
== External Web Services Standards Links ==&lt;br /&gt;
&lt;br /&gt;
''This section of the page needs to be updated'' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Web Services Tools ====&lt;br /&gt;
&lt;br /&gt;
== OWASP Web Services Tools ==&lt;br /&gt;
[http://www.owasp.org/index.php/Category:OWASP_WSFuzzer_Project WSFuzzer]&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Category:OWASP_Interceptor_Project Interceptor]&lt;br /&gt;
&lt;br /&gt;
== External Web Services Tools ==&lt;br /&gt;
&lt;br /&gt;
''This section of the page needs to be updated'' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Testing Web Services ====&lt;br /&gt;
&lt;br /&gt;
== OWASP Links ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Testing_for_Web_Services Testing Web Services] - Comprehensive OWASP Guide on Testing Web Services.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
''This section of the page needs to be updated'' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Documents &amp;amp; Presentations ====&lt;br /&gt;
&lt;br /&gt;
== OWASP Documents and Presentations ==&lt;br /&gt;
&lt;br /&gt;
'''Documents Related to Web Services'''&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:Web_services_security.doc Web Services Security]&lt;br /&gt;
&lt;br /&gt;
'''Presentations Related to Web Services'''&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:InfoSec_World_2007_-_Web_services_gateways.ppt InfoSec World 2007] - Web Services Gateways presentation from InfoSec World 2007.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:AppSec2005DC-Alex_Stamos-Attacking_Web_Services.ppt Attacking Web Services] - OWASP AppSec 2005 DC presentation on Attacking Web Services by Alex Stamos.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:OWASPAppSec2006Seattle_Web_Services_Security.ppt WS Security] - OWASP AppSec 2006 Seattle presentation on Web Services Security.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:OWASPAppSecEU2006_InlineApproachforSecureSOAPRequests.ppt Secure SOAP Requests] - OWASP AppSec 2006 EU presentation on Inline Approach for Secure SOAP Requests.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:Don’t_drop_the_SOAP_OWASP.ppt Don't Drop the SOAP]&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:AppSec2005DC-Alex_Smolen-OWASP_WebServices_Project.ppt OWASP Web Services Project] - OWASP AppSec 2005 DC presentation on the OWASP Web Services Project by Alex Smolen.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:OWASPAppSecEU2006_ProtectingWebServicesAndAapplications.ppt Protecting Web Services] - OWASP AppSec 2006 EU presentation on Protesting Web Services and Applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== External Documents &amp;amp; Presentations ==&lt;br /&gt;
&lt;br /&gt;
''This section of the page needs to be updated''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== OLD_PAGE ====&lt;br /&gt;
== Welcome to the OWASP Web Services Security Project==&lt;br /&gt;
&lt;br /&gt;
[a brief about web services security in general and the current state of OWASP in web services security]&lt;br /&gt;
&lt;br /&gt;
The following document outlines a proposed layout for a new Web Services Security Project for the Open Web Application Security Project (OWASP).  &lt;br /&gt;
&lt;br /&gt;
== Current State ==&lt;br /&gt;
&lt;br /&gt;
'''Current Relevant OWASP Pages'''&lt;br /&gt;
&lt;br /&gt;
1.	Web Services&lt;br /&gt;
a.	Securing web services&lt;br /&gt;
b.	Communication security&lt;br /&gt;
c.	Passing credentials&lt;br /&gt;
d.	Ensuring message freshness&lt;br /&gt;
e.	Protecting message integrity&lt;br /&gt;
f.	Protecting message confidentiality&lt;br /&gt;
g.	Access control&lt;br /&gt;
h.	Audit&lt;br /&gt;
i.	Web services security hierarchy&lt;br /&gt;
i.	standard committees&lt;br /&gt;
j.	SOAP&lt;br /&gt;
i.	XML signatures and encryption&lt;br /&gt;
ii.	Security specifications&lt;br /&gt;
k.	WS-Security standard&lt;br /&gt;
i.	Organization of the standard&lt;br /&gt;
ii.	Purpose&lt;br /&gt;
l.	WS-Security Building blocks&lt;br /&gt;
i.	How data is passed&lt;br /&gt;
ii.	Security header’s structure&lt;br /&gt;
iii.	Types of tokens&lt;br /&gt;
iv.	Referencing message parts&lt;br /&gt;
m.	Communication protection mechanisms&lt;br /&gt;
i.	Integrity&lt;br /&gt;
ii.	Confidentiality&lt;br /&gt;
iii.	Freshness&lt;br /&gt;
n.	Access control mechanisms&lt;br /&gt;
i.	Identification&lt;br /&gt;
ii.	Authentication&lt;br /&gt;
iii.	Authorization&lt;br /&gt;
iv.	Policy agreement&lt;br /&gt;
o.	Forming web services chains&lt;br /&gt;
i.	Incompatible user access control models&lt;br /&gt;
ii.	Service trust&lt;br /&gt;
iii.	Secure connections&lt;br /&gt;
iv.	Synchronization of user directories&lt;br /&gt;
v.	Domain federation&lt;br /&gt;
p.	Available implementations&lt;br /&gt;
i.	.NET – Web services extensions&lt;br /&gt;
ii.	Java toolkits&lt;br /&gt;
iii.	Hardware software systems&lt;br /&gt;
q.	Problems&lt;br /&gt;
i.	Immaturity of the standards&lt;br /&gt;
ii.	Performance&lt;br /&gt;
iii.	Complexity and interoperability&lt;br /&gt;
iv.	Key management&lt;br /&gt;
r.	Further reading&lt;br /&gt;
&lt;br /&gt;
2.	A Tale of Two Systems&lt;br /&gt;
- case studies of two hypothetical systems, one of which involves openning a mainframe app to the web using a web service, and the risks that are posed.&lt;br /&gt;
&lt;br /&gt;
3.	Theres More to Securing Web Services Systems Than WS-Security&lt;br /&gt;
a.	What is a web service&lt;br /&gt;
b.	Web services from the information security perspective&lt;br /&gt;
c.	Some security implications of this perspective&lt;br /&gt;
i.	Emergent risks&lt;br /&gt;
ii.	End-to-end controls&lt;br /&gt;
d.	Interconnection of systems from different trust domains&lt;br /&gt;
i.	Some implications of the organization’s risk management process and system development life cycle&lt;br /&gt;
ii.	Emerging standards for securing web services&lt;br /&gt;
iii.	WS-Security specifications in process&lt;br /&gt;
iv.	Trust management revisited&lt;br /&gt;
e.	References&lt;br /&gt;
&lt;br /&gt;
4.	Web Services Architecture and Security&lt;br /&gt;
a.	The web services architecture&lt;br /&gt;
b.	Service oriented architectures and distributed systems&lt;br /&gt;
c.	Complexity is the enemy of security…&lt;br /&gt;
d.	The architectural models&lt;br /&gt;
e.	The policy model&lt;br /&gt;
f.	The service oriented model&lt;br /&gt;
g.	The resource oriented model&lt;br /&gt;
h.	The message oriented model&lt;br /&gt;
i.	The management model&lt;br /&gt;
j.	The rest&lt;br /&gt;
k.	References&lt;br /&gt;
&lt;br /&gt;
5.	Testing for Web Services (from OWASP Testing Guide)&lt;br /&gt;
a.	XML Structural Testing&lt;br /&gt;
b.	XML Content-level Testing&lt;br /&gt;
c.	HTTP GET parameters/REST Testing&lt;br /&gt;
d.	Naughty SOAP attachments&lt;br /&gt;
e.	Replay Testing&lt;br /&gt;
&lt;br /&gt;
6.	Image:Web services security.doc&lt;br /&gt;
&lt;br /&gt;
7.	Image:InfoSec_World_2007_-_Web_services_gateways.ppt&lt;br /&gt;
&lt;br /&gt;
8.	Image:AppSec2005DC-Alex_Stamos-Attacking_Web_Services.ppt&lt;br /&gt;
&lt;br /&gt;
9.	Image:OWASPAppSec2006Seattle_Web_Services_Security.ppt&lt;br /&gt;
&lt;br /&gt;
10.	.NET Web Service Validation&lt;br /&gt;
a.	Perfomance penalties&lt;br /&gt;
b.	Downloading&lt;br /&gt;
c.	Installation&lt;br /&gt;
d.	Reporting Bugs&lt;br /&gt;
e.	Use&lt;br /&gt;
i.	Methods of use&lt;br /&gt;
ii.	Attributes&lt;br /&gt;
iii.	Web.config changes&lt;br /&gt;
iv.	Using validation&lt;br /&gt;
v.	Using assertions&lt;br /&gt;
&lt;br /&gt;
11.	OWASP WSFuzzer Project&lt;br /&gt;
&lt;br /&gt;
12.	OWASP interceptor Project&lt;br /&gt;
&lt;br /&gt;
13.	OWASP Guide&lt;br /&gt;
&lt;br /&gt;
14.	OWASPAppSecEU2006_InlineApproachforSecureSOAPRequests.ppt&lt;br /&gt;
&lt;br /&gt;
15.	Category_talk:OWASP_XML_Security_Gateway_Evaluation_Criteria_Project&lt;br /&gt;
&lt;br /&gt;
16.	Don’t drop the SOAP OWASP.ppt&lt;br /&gt;
&lt;br /&gt;
17.	AppSec2005DC-Alex_Smolen-OWASP_WebServices_Project.ppt&lt;br /&gt;
&lt;br /&gt;
18.	AppSec2005DC-Jeff_Williams-OWASP_AppSec_Guide_2.0.ppt&lt;br /&gt;
&lt;br /&gt;
19.	OWASPAppSecEU2006_ProtectingWebServicesAndAapplications.ppt&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Content'''&lt;br /&gt;
&lt;br /&gt;
-	Completeness&lt;br /&gt;
&lt;br /&gt;
-	Relevance&lt;br /&gt;
&lt;br /&gt;
-	Target audience&lt;br /&gt;
&lt;br /&gt;
'''Organization'''&lt;br /&gt;
&lt;br /&gt;
-	Ease of navigation&lt;br /&gt;
&lt;br /&gt;
-	Ease of locating a specific topic&lt;br /&gt;
&lt;br /&gt;
-	Communication of updates&lt;br /&gt;
&lt;br /&gt;
'''Search'''&lt;br /&gt;
&lt;br /&gt;
-&lt;br /&gt;
&lt;br /&gt;
== Desired State ==&lt;br /&gt;
&lt;br /&gt;
'''Content'''&lt;br /&gt;
&lt;br /&gt;
-	Completeness&lt;br /&gt;
&lt;br /&gt;
-	Relevance&lt;br /&gt;
&lt;br /&gt;
-	Target audience&lt;br /&gt;
&lt;br /&gt;
'''Organization'''&lt;br /&gt;
&lt;br /&gt;
-	Ease of navigation&lt;br /&gt;
&lt;br /&gt;
-	Ease of locating a specific topic&lt;br /&gt;
&lt;br /&gt;
-	Communication of updates&lt;br /&gt;
&lt;br /&gt;
'''Search'''&lt;br /&gt;
&lt;br /&gt;
-&lt;br /&gt;
&lt;br /&gt;
== Proposed Layout ==&lt;br /&gt;
&lt;br /&gt;
The proposed OWASP Web Services Security Project will serve as a starting point for any web services-related inquiries on OWASP.  It will consist of a launchpad or home page with an introduction to the project, regular updates to pages in the project, and links to project pages and external resources. &lt;br /&gt;
&lt;br /&gt;
[[Image:WS_Launchpad.jpg|thumb|600px|LEFT|Launchpad Layout (click to see a bigger image)]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Introduction&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Updates&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;External Links&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;OWASP Pages&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Security Docs/Presentations&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Standards&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Communications&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;XML Security&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Testing Web Services&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Tools&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Gateways&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;SOA Architecture and Design&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Implementation Platforms&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;OWASP Top 10 Web Services Chapter&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Goals &amp;amp; Roadmap ==&lt;br /&gt;
&lt;br /&gt;
Currently the project goals are to:&lt;br /&gt;
&lt;br /&gt;
* Creation of launch pad layout&lt;br /&gt;
&lt;br /&gt;
* Create template start page for each subtopic &lt;br /&gt;
&lt;br /&gt;
* Find solid external resources&lt;br /&gt;
&lt;br /&gt;
* Recruit volunteer team (2-4 person)&lt;br /&gt;
&lt;br /&gt;
* For each topic: &lt;br /&gt;
&lt;br /&gt;
- Create start page for the subtopic topic&lt;br /&gt;
&lt;br /&gt;
- Gather all existing relevant articles within OWASP&lt;br /&gt;
&lt;br /&gt;
- Create plan of consolidating all the relevant information&lt;br /&gt;
&lt;br /&gt;
- Contact authors of relevant articles if change is required&lt;br /&gt;
&lt;br /&gt;
- Consolidate all information on the topic&lt;br /&gt;
&lt;br /&gt;
- Find solid external resources&lt;br /&gt;
&lt;br /&gt;
- Create link back to the main Web Services Security Project launchpad&lt;br /&gt;
&lt;br /&gt;
* Research way of communicating any updates to web services pages on launchpad&lt;br /&gt;
&lt;br /&gt;
* Search optimization (both OWASP and Google)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
A detailed project plan and schedule will be developed shortly and posted here.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Guiding Principles ==&lt;br /&gt;
&lt;br /&gt;
tbd&lt;br /&gt;
&lt;br /&gt;
== Resources and links ==&lt;br /&gt;
&lt;br /&gt;
This project is not standalone. This project will draw pieces of information from:&lt;br /&gt;
* OWASP Guide&lt;br /&gt;
* Other OWASP pages&lt;br /&gt;
* OWASP documents&lt;br /&gt;
* Relevant external links&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation: ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Web Services Security Project to be useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to sahba@securitycompass.com.&lt;br /&gt;
&lt;br /&gt;
== Project Contributors ==&lt;br /&gt;
&lt;br /&gt;
If you contribute to this Project, please add your name here.&amp;lt;br&amp;gt;&lt;br /&gt;
Project Leads:&lt;br /&gt;
* [[User:nbhalla| Nish Bhalla]]&lt;br /&gt;
* [[User:skazerooni| Sahba Kazerooni]]&lt;br /&gt;
* [[User:Subu Ramanathan| Subu Ramanathan]]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* you? ...&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Web Services Security Project]]&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Subu Ramanathan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Services_Security_Project&amp;diff=66674</id>
		<title>Category:OWASP Web Services Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Services_Security_Project&amp;diff=66674"/>
				<updated>2009-07-27T17:12:34Z</updated>
		
		<summary type="html">&lt;p&gt;Subu Ramanathan: Added more tabs pertaining to aspects of web services&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{:Template:Orphaned Projects}}&lt;br /&gt;
&lt;br /&gt;
==== Main ====&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
Welcome to OWASP Web Services Security Project. This project is designed to serve as a starting point for any web services related inquiries on OWASP. Please note that this is NOT a standalone project and will draw upon relevant resources from other OWASP and external pages.&lt;br /&gt;
&lt;br /&gt;
== Goals ==&lt;br /&gt;
The OWASP Web Services Security Project aims to include and maintain a comprehensive list of links to OWASP and external resources.&lt;br /&gt;
&lt;br /&gt;
== Web Services Security ==&lt;br /&gt;
OWASP related Web Services links:&lt;br /&gt;
&lt;br /&gt;
[1] [http://www.owasp.org/index.php/Web_Services OWASP Web Services] - A comprehensive introduction to Web Services.&lt;br /&gt;
&lt;br /&gt;
[2] [http://www.owasp.org/index.php/Theres_More_to_Securing_Web_Services_Systems_Than_WS-Security There is More to Securing Web Services Systems Than WS Security] - Insightful page on Web Services Security.&lt;br /&gt;
&lt;br /&gt;
[3] [http://www.owasp.org/index.php/.NET_Web_Service_Validation .NET Web Service Validation] - .NET approach to validating Web Services.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Web Services Standards ====&lt;br /&gt;
&lt;br /&gt;
== OWASP Web Services Standards Links ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Category:OWASP_Guide_Project OWASP Guide Project] - A comprehensive development guide on building secure Web Service Applications.&lt;br /&gt;
&lt;br /&gt;
== External Web Services Standards Links ==&lt;br /&gt;
&lt;br /&gt;
''This section of the page needs to be updated'' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Web Services Tools ====&lt;br /&gt;
&lt;br /&gt;
== OWASP Web Services Tools ==&lt;br /&gt;
[http://www.owasp.org/index.php/Category:OWASP_WSFuzzer_Project WSFuzzer]&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Category:OWASP_Interceptor_Project Interceptor]&lt;br /&gt;
&lt;br /&gt;
== External Web Services Tools ==&lt;br /&gt;
&lt;br /&gt;
''This section of the page needs to be updated'' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Testing Web Services ====&lt;br /&gt;
&lt;br /&gt;
== OWASP Links ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Testing_for_Web_Services Testing Web Services] - Comprehensive OWASP Guide on Testing Web Services.&lt;br /&gt;
&lt;br /&gt;
== External Links ==&lt;br /&gt;
&lt;br /&gt;
''This section of the page needs to be updated'' &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Documents &amp;amp; Presentations ====&lt;br /&gt;
&lt;br /&gt;
== OWASP Documents and Presentations ==&lt;br /&gt;
&lt;br /&gt;
'''Documents Related to Web Services'''&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:Web_services_security.doc Web Services Security]&lt;br /&gt;
&lt;br /&gt;
'''Presentations Related to Web Services'''&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:InfoSec_World_2007_-_Web_services_gateways.ppt InfoSec World 2007] - Web Services Gateways presentation from InfoSec World 2007.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:AppSec2005DC-Alex_Stamos-Attacking_Web_Services.ppt Attacking Web Services] - OWASP AppSec 2005 DC presentation on Attacking Web Services by Alex Stamos.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:OWASPAppSec2006Seattle_Web_Services_Security.ppt WS Security] - OWASP AppSec 2006 Seattle presentation on Web Services Security.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:OWASPAppSecEU2006_InlineApproachforSecureSOAPRequests.ppt Secure SOAP Requests] - OWASP AppSec 2006 EU presentation on Inline Approach for Secure SOAP Requests.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:Don’t_drop_the_SOAP_OWASP.ppt Don't Drop the SOAP]&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:AppSec2005DC-Alex_Smolen-OWASP_WebServices_Project.ppt OWASP Web Services Project] - OWASP AppSec 2005 DC presentation on the OWASP Web Services Project by Alex Smolen.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:OWASPAppSecEU2006_ProtectingWebServicesAndAapplications.ppt Protecting Web Services] - OWASP AppSec 2006 EU presentation on Protesting Web Services and Applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== External Documents &amp;amp; Presentations ==&lt;br /&gt;
&lt;br /&gt;
''This section of the page needs to be updated''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== OLD_PAGE ====&lt;br /&gt;
== Welcome to the OWASP Web Services Security Project==&lt;br /&gt;
&lt;br /&gt;
[a brief about web services security in general and the current state of OWASP in web services security]&lt;br /&gt;
&lt;br /&gt;
The following document outlines a proposed layout for a new Web Services Security Project for the Open Web Application Security Project (OWASP).  &lt;br /&gt;
&lt;br /&gt;
== Current State ==&lt;br /&gt;
&lt;br /&gt;
'''Current Relevant OWASP Pages'''&lt;br /&gt;
&lt;br /&gt;
1.	Web Services&lt;br /&gt;
a.	Securing web services&lt;br /&gt;
b.	Communication security&lt;br /&gt;
c.	Passing credentials&lt;br /&gt;
d.	Ensuring message freshness&lt;br /&gt;
e.	Protecting message integrity&lt;br /&gt;
f.	Protecting message confidentiality&lt;br /&gt;
g.	Access control&lt;br /&gt;
h.	Audit&lt;br /&gt;
i.	Web services security hierarchy&lt;br /&gt;
i.	standard committees&lt;br /&gt;
j.	SOAP&lt;br /&gt;
i.	XML signatures and encryption&lt;br /&gt;
ii.	Security specifications&lt;br /&gt;
k.	WS-Security standard&lt;br /&gt;
i.	Organization of the standard&lt;br /&gt;
ii.	Purpose&lt;br /&gt;
l.	WS-Security Building blocks&lt;br /&gt;
i.	How data is passed&lt;br /&gt;
ii.	Security header’s structure&lt;br /&gt;
iii.	Types of tokens&lt;br /&gt;
iv.	Referencing message parts&lt;br /&gt;
m.	Communication protection mechanisms&lt;br /&gt;
i.	Integrity&lt;br /&gt;
ii.	Confidentiality&lt;br /&gt;
iii.	Freshness&lt;br /&gt;
n.	Access control mechanisms&lt;br /&gt;
i.	Identification&lt;br /&gt;
ii.	Authentication&lt;br /&gt;
iii.	Authorization&lt;br /&gt;
iv.	Policy agreement&lt;br /&gt;
o.	Forming web services chains&lt;br /&gt;
i.	Incompatible user access control models&lt;br /&gt;
ii.	Service trust&lt;br /&gt;
iii.	Secure connections&lt;br /&gt;
iv.	Synchronization of user directories&lt;br /&gt;
v.	Domain federation&lt;br /&gt;
p.	Available implementations&lt;br /&gt;
i.	.NET – Web services extensions&lt;br /&gt;
ii.	Java toolkits&lt;br /&gt;
iii.	Hardware software systems&lt;br /&gt;
q.	Problems&lt;br /&gt;
i.	Immaturity of the standards&lt;br /&gt;
ii.	Performance&lt;br /&gt;
iii.	Complexity and interoperability&lt;br /&gt;
iv.	Key management&lt;br /&gt;
r.	Further reading&lt;br /&gt;
&lt;br /&gt;
2.	A Tale of Two Systems&lt;br /&gt;
- case studies of two hypothetical systems, one of which involves openning a mainframe app to the web using a web service, and the risks that are posed.&lt;br /&gt;
&lt;br /&gt;
3.	Theres More to Securing Web Services Systems Than WS-Security&lt;br /&gt;
a.	What is a web service&lt;br /&gt;
b.	Web services from the information security perspective&lt;br /&gt;
c.	Some security implications of this perspective&lt;br /&gt;
i.	Emergent risks&lt;br /&gt;
ii.	End-to-end controls&lt;br /&gt;
d.	Interconnection of systems from different trust domains&lt;br /&gt;
i.	Some implications of the organization’s risk management process and system development life cycle&lt;br /&gt;
ii.	Emerging standards for securing web services&lt;br /&gt;
iii.	WS-Security specifications in process&lt;br /&gt;
iv.	Trust management revisited&lt;br /&gt;
e.	References&lt;br /&gt;
&lt;br /&gt;
4.	Web Services Architecture and Security&lt;br /&gt;
a.	The web services architecture&lt;br /&gt;
b.	Service oriented architectures and distributed systems&lt;br /&gt;
c.	Complexity is the enemy of security…&lt;br /&gt;
d.	The architectural models&lt;br /&gt;
e.	The policy model&lt;br /&gt;
f.	The service oriented model&lt;br /&gt;
g.	The resource oriented model&lt;br /&gt;
h.	The message oriented model&lt;br /&gt;
i.	The management model&lt;br /&gt;
j.	The rest&lt;br /&gt;
k.	References&lt;br /&gt;
&lt;br /&gt;
5.	Testing for Web Services (from OWASP Testing Guide)&lt;br /&gt;
a.	XML Structural Testing&lt;br /&gt;
b.	XML Content-level Testing&lt;br /&gt;
c.	HTTP GET parameters/REST Testing&lt;br /&gt;
d.	Naughty SOAP attachments&lt;br /&gt;
e.	Replay Testing&lt;br /&gt;
&lt;br /&gt;
6.	Image:Web services security.doc&lt;br /&gt;
&lt;br /&gt;
7.	Image:InfoSec_World_2007_-_Web_services_gateways.ppt&lt;br /&gt;
&lt;br /&gt;
8.	Image:AppSec2005DC-Alex_Stamos-Attacking_Web_Services.ppt&lt;br /&gt;
&lt;br /&gt;
9.	Image:OWASPAppSec2006Seattle_Web_Services_Security.ppt&lt;br /&gt;
&lt;br /&gt;
10.	.NET Web Service Validation&lt;br /&gt;
a.	Perfomance penalties&lt;br /&gt;
b.	Downloading&lt;br /&gt;
c.	Installation&lt;br /&gt;
d.	Reporting Bugs&lt;br /&gt;
e.	Use&lt;br /&gt;
i.	Methods of use&lt;br /&gt;
ii.	Attributes&lt;br /&gt;
iii.	Web.config changes&lt;br /&gt;
iv.	Using validation&lt;br /&gt;
v.	Using assertions&lt;br /&gt;
&lt;br /&gt;
11.	OWASP WSFuzzer Project&lt;br /&gt;
&lt;br /&gt;
12.	OWASP interceptor Project&lt;br /&gt;
&lt;br /&gt;
13.	OWASP Guide&lt;br /&gt;
&lt;br /&gt;
14.	OWASPAppSecEU2006_InlineApproachforSecureSOAPRequests.ppt&lt;br /&gt;
&lt;br /&gt;
15.	Category_talk:OWASP_XML_Security_Gateway_Evaluation_Criteria_Project&lt;br /&gt;
&lt;br /&gt;
16.	Don’t drop the SOAP OWASP.ppt&lt;br /&gt;
&lt;br /&gt;
17.	AppSec2005DC-Alex_Smolen-OWASP_WebServices_Project.ppt&lt;br /&gt;
&lt;br /&gt;
18.	AppSec2005DC-Jeff_Williams-OWASP_AppSec_Guide_2.0.ppt&lt;br /&gt;
&lt;br /&gt;
19.	OWASPAppSecEU2006_ProtectingWebServicesAndAapplications.ppt&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Content'''&lt;br /&gt;
&lt;br /&gt;
-	Completeness&lt;br /&gt;
&lt;br /&gt;
-	Relevance&lt;br /&gt;
&lt;br /&gt;
-	Target audience&lt;br /&gt;
&lt;br /&gt;
'''Organization'''&lt;br /&gt;
&lt;br /&gt;
-	Ease of navigation&lt;br /&gt;
&lt;br /&gt;
-	Ease of locating a specific topic&lt;br /&gt;
&lt;br /&gt;
-	Communication of updates&lt;br /&gt;
&lt;br /&gt;
'''Search'''&lt;br /&gt;
&lt;br /&gt;
-&lt;br /&gt;
&lt;br /&gt;
== Desired State ==&lt;br /&gt;
&lt;br /&gt;
'''Content'''&lt;br /&gt;
&lt;br /&gt;
-	Completeness&lt;br /&gt;
&lt;br /&gt;
-	Relevance&lt;br /&gt;
&lt;br /&gt;
-	Target audience&lt;br /&gt;
&lt;br /&gt;
'''Organization'''&lt;br /&gt;
&lt;br /&gt;
-	Ease of navigation&lt;br /&gt;
&lt;br /&gt;
-	Ease of locating a specific topic&lt;br /&gt;
&lt;br /&gt;
-	Communication of updates&lt;br /&gt;
&lt;br /&gt;
'''Search'''&lt;br /&gt;
&lt;br /&gt;
-&lt;br /&gt;
&lt;br /&gt;
== Proposed Layout ==&lt;br /&gt;
&lt;br /&gt;
The proposed OWASP Web Services Security Project will serve as a starting point for any web services-related inquiries on OWASP.  It will consist of a launchpad or home page with an introduction to the project, regular updates to pages in the project, and links to project pages and external resources. &lt;br /&gt;
&lt;br /&gt;
[[Image:WS_Launchpad.jpg|thumb|600px|LEFT|Launchpad Layout (click to see a bigger image)]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Introduction&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Updates&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;External Links&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;OWASP Pages&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Security Docs/Presentations&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Standards&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Communications&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;XML Security&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Testing Web Services&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Tools&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Gateways&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;SOA Architecture and Design&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Implementation Platforms&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;OWASP Top 10 Web Services Chapter&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Goals &amp;amp; Roadmap ==&lt;br /&gt;
&lt;br /&gt;
Currently the project goals are to:&lt;br /&gt;
&lt;br /&gt;
* Creation of launch pad layout&lt;br /&gt;
&lt;br /&gt;
* Create template start page for each subtopic &lt;br /&gt;
&lt;br /&gt;
* Find solid external resources&lt;br /&gt;
&lt;br /&gt;
* Recruit volunteer team (2-4 person)&lt;br /&gt;
&lt;br /&gt;
* For each topic: &lt;br /&gt;
&lt;br /&gt;
- Create start page for the subtopic topic&lt;br /&gt;
&lt;br /&gt;
- Gather all existing relevant articles within OWASP&lt;br /&gt;
&lt;br /&gt;
- Create plan of consolidating all the relevant information&lt;br /&gt;
&lt;br /&gt;
- Contact authors of relevant articles if change is required&lt;br /&gt;
&lt;br /&gt;
- Consolidate all information on the topic&lt;br /&gt;
&lt;br /&gt;
- Find solid external resources&lt;br /&gt;
&lt;br /&gt;
- Create link back to the main Web Services Security Project launchpad&lt;br /&gt;
&lt;br /&gt;
* Research way of communicating any updates to web services pages on launchpad&lt;br /&gt;
&lt;br /&gt;
* Search optimization (both OWASP and Google)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
A detailed project plan and schedule will be developed shortly and posted here.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Guiding Principles ==&lt;br /&gt;
&lt;br /&gt;
tbd&lt;br /&gt;
&lt;br /&gt;
== Resources and links ==&lt;br /&gt;
&lt;br /&gt;
This project is not standalone. This project will draw pieces of information from:&lt;br /&gt;
* OWASP Guide&lt;br /&gt;
* Other OWASP pages&lt;br /&gt;
* OWASP documents&lt;br /&gt;
* Relevant external links&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation: ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Web Services Security Project to be useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to sahba@securitycompass.com.&lt;br /&gt;
&lt;br /&gt;
== Project Contributors ==&lt;br /&gt;
&lt;br /&gt;
If you contribute to this Project, please add your name here.&amp;lt;br&amp;gt;&lt;br /&gt;
Project Leads:&lt;br /&gt;
* [[User:nbhalla| Nish Bhalla]]&lt;br /&gt;
* [[User:skazerooni| Sahba Kazerooni]]&lt;br /&gt;
* [[User:Subu Ramanathan| Subu Ramanathan]]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* you? ...&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Web Services Security Project]]&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Subu Ramanathan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Services_Security_Project&amp;diff=66670</id>
		<title>Category:OWASP Web Services Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Services_Security_Project&amp;diff=66670"/>
				<updated>2009-07-27T16:42:46Z</updated>
		
		<summary type="html">&lt;p&gt;Subu Ramanathan: Initial update - Added tabs, new introduction, list of OWASP docs and presentations&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{:Template:Orphaned Projects}}&lt;br /&gt;
&lt;br /&gt;
==== Main ====&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
Welcome to OWASP Web Services Security Project. This project is designed to serve as a starting point for any web services related inquiries on OWASP. Please note that this is NOT a standalone project and will draw upon relevant resources from other OWASP and external pages.&lt;br /&gt;
&lt;br /&gt;
== Goals ==&lt;br /&gt;
The OWASP Web Services Security Project aims to include and maintain a comprehensive list of links to OWASP and external resources.&lt;br /&gt;
&lt;br /&gt;
== Web Services Security ==&lt;br /&gt;
OWASP related Web Services links:&lt;br /&gt;
&lt;br /&gt;
[1] [http://www.owasp.org/index.php/Web_Services OWASP Web Services] - A comprehensive introduction to Web Services.&lt;br /&gt;
&lt;br /&gt;
[2] [http://www.owasp.org/index.php/Theres_More_to_Securing_Web_Services_Systems_Than_WS-Security There is More to Securing Web Services Systems Than WS Security] - Insightful page on Web Services Security.&lt;br /&gt;
&lt;br /&gt;
[3] [http://www.owasp.org/index.php/.NET_Web_Service_Validation .NET Web Service Validation] - .NET approach to validating Web Services.&lt;br /&gt;
&lt;br /&gt;
==== Documents &amp;amp; Presentations ====&lt;br /&gt;
&lt;br /&gt;
== OWASP Documents and Presentations ==&lt;br /&gt;
&lt;br /&gt;
'''Documents Related to Web Services'''&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:Web_services_security.doc Web Services Security]&lt;br /&gt;
&lt;br /&gt;
'''Presentations Related to Web Services'''&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:InfoSec_World_2007_-_Web_services_gateways.ppt InfoSec World 2007] - Web Services Gateways presentation from InfoSec World 2007.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:AppSec2005DC-Alex_Stamos-Attacking_Web_Services.ppt Attacking Web Services] - OWASP AppSec 2005 DC presentation on Attacking Web Services by Alex Stamos.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Image:OWASPAppSec2006Seattle_Web_Services_Security.ppt WS Security] - OWASP AppSec 2006 Seattle presentation on Web Services Security.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:OWASPAppSecEU2006_InlineApproachforSecureSOAPRequests.ppt Secure SOAP Requests] - OWASP AppSec 2006 EU presentation on Inline Approach for Secure SOAP Requests.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:Don’t_drop_the_SOAP_OWASP.ppt Don't Drop the SOAP]&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:AppSec2005DC-Alex_Smolen-OWASP_WebServices_Project.ppt OWASP Web Services Project] - OWASP AppSec 2005 DC presentation on the OWASP Web Services Project by Alex Smolen.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/image:OWASPAppSecEU2006_ProtectingWebServicesAndAapplications.ppt Protecting Web Services] - OWASP AppSec 2006 EU presentation on Protesting Web Services and Applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== OLD_PAGE ====&lt;br /&gt;
== Welcome to the OWASP Web Services Security Project==&lt;br /&gt;
&lt;br /&gt;
[a brief about web services security in general and the current state of OWASP in web services security]&lt;br /&gt;
&lt;br /&gt;
The following document outlines a proposed layout for a new Web Services Security Project for the Open Web Application Security Project (OWASP).  &lt;br /&gt;
&lt;br /&gt;
== Current State ==&lt;br /&gt;
&lt;br /&gt;
'''Current Relevant OWASP Pages'''&lt;br /&gt;
&lt;br /&gt;
1.	Web Services&lt;br /&gt;
a.	Securing web services&lt;br /&gt;
b.	Communication security&lt;br /&gt;
c.	Passing credentials&lt;br /&gt;
d.	Ensuring message freshness&lt;br /&gt;
e.	Protecting message integrity&lt;br /&gt;
f.	Protecting message confidentiality&lt;br /&gt;
g.	Access control&lt;br /&gt;
h.	Audit&lt;br /&gt;
i.	Web services security hierarchy&lt;br /&gt;
i.	standard committees&lt;br /&gt;
j.	SOAP&lt;br /&gt;
i.	XML signatures and encryption&lt;br /&gt;
ii.	Security specifications&lt;br /&gt;
k.	WS-Security standard&lt;br /&gt;
i.	Organization of the standard&lt;br /&gt;
ii.	Purpose&lt;br /&gt;
l.	WS-Security Building blocks&lt;br /&gt;
i.	How data is passed&lt;br /&gt;
ii.	Security header’s structure&lt;br /&gt;
iii.	Types of tokens&lt;br /&gt;
iv.	Referencing message parts&lt;br /&gt;
m.	Communication protection mechanisms&lt;br /&gt;
i.	Integrity&lt;br /&gt;
ii.	Confidentiality&lt;br /&gt;
iii.	Freshness&lt;br /&gt;
n.	Access control mechanisms&lt;br /&gt;
i.	Identification&lt;br /&gt;
ii.	Authentication&lt;br /&gt;
iii.	Authorization&lt;br /&gt;
iv.	Policy agreement&lt;br /&gt;
o.	Forming web services chains&lt;br /&gt;
i.	Incompatible user access control models&lt;br /&gt;
ii.	Service trust&lt;br /&gt;
iii.	Secure connections&lt;br /&gt;
iv.	Synchronization of user directories&lt;br /&gt;
v.	Domain federation&lt;br /&gt;
p.	Available implementations&lt;br /&gt;
i.	.NET – Web services extensions&lt;br /&gt;
ii.	Java toolkits&lt;br /&gt;
iii.	Hardware software systems&lt;br /&gt;
q.	Problems&lt;br /&gt;
i.	Immaturity of the standards&lt;br /&gt;
ii.	Performance&lt;br /&gt;
iii.	Complexity and interoperability&lt;br /&gt;
iv.	Key management&lt;br /&gt;
r.	Further reading&lt;br /&gt;
&lt;br /&gt;
2.	A Tale of Two Systems&lt;br /&gt;
- case studies of two hypothetical systems, one of which involves openning a mainframe app to the web using a web service, and the risks that are posed.&lt;br /&gt;
&lt;br /&gt;
3.	Theres More to Securing Web Services Systems Than WS-Security&lt;br /&gt;
a.	What is a web service&lt;br /&gt;
b.	Web services from the information security perspective&lt;br /&gt;
c.	Some security implications of this perspective&lt;br /&gt;
i.	Emergent risks&lt;br /&gt;
ii.	End-to-end controls&lt;br /&gt;
d.	Interconnection of systems from different trust domains&lt;br /&gt;
i.	Some implications of the organization’s risk management process and system development life cycle&lt;br /&gt;
ii.	Emerging standards for securing web services&lt;br /&gt;
iii.	WS-Security specifications in process&lt;br /&gt;
iv.	Trust management revisited&lt;br /&gt;
e.	References&lt;br /&gt;
&lt;br /&gt;
4.	Web Services Architecture and Security&lt;br /&gt;
a.	The web services architecture&lt;br /&gt;
b.	Service oriented architectures and distributed systems&lt;br /&gt;
c.	Complexity is the enemy of security…&lt;br /&gt;
d.	The architectural models&lt;br /&gt;
e.	The policy model&lt;br /&gt;
f.	The service oriented model&lt;br /&gt;
g.	The resource oriented model&lt;br /&gt;
h.	The message oriented model&lt;br /&gt;
i.	The management model&lt;br /&gt;
j.	The rest&lt;br /&gt;
k.	References&lt;br /&gt;
&lt;br /&gt;
5.	Testing for Web Services (from OWASP Testing Guide)&lt;br /&gt;
a.	XML Structural Testing&lt;br /&gt;
b.	XML Content-level Testing&lt;br /&gt;
c.	HTTP GET parameters/REST Testing&lt;br /&gt;
d.	Naughty SOAP attachments&lt;br /&gt;
e.	Replay Testing&lt;br /&gt;
&lt;br /&gt;
6.	Image:Web services security.doc&lt;br /&gt;
&lt;br /&gt;
7.	Image:InfoSec_World_2007_-_Web_services_gateways.ppt&lt;br /&gt;
&lt;br /&gt;
8.	Image:AppSec2005DC-Alex_Stamos-Attacking_Web_Services.ppt&lt;br /&gt;
&lt;br /&gt;
9.	Image:OWASPAppSec2006Seattle_Web_Services_Security.ppt&lt;br /&gt;
&lt;br /&gt;
10.	.NET Web Service Validation&lt;br /&gt;
a.	Perfomance penalties&lt;br /&gt;
b.	Downloading&lt;br /&gt;
c.	Installation&lt;br /&gt;
d.	Reporting Bugs&lt;br /&gt;
e.	Use&lt;br /&gt;
i.	Methods of use&lt;br /&gt;
ii.	Attributes&lt;br /&gt;
iii.	Web.config changes&lt;br /&gt;
iv.	Using validation&lt;br /&gt;
v.	Using assertions&lt;br /&gt;
&lt;br /&gt;
11.	OWASP WSFuzzer Project&lt;br /&gt;
&lt;br /&gt;
12.	OWASP interceptor Project&lt;br /&gt;
&lt;br /&gt;
13.	OWASP Guide&lt;br /&gt;
&lt;br /&gt;
14.	OWASPAppSecEU2006_InlineApproachforSecureSOAPRequests.ppt&lt;br /&gt;
&lt;br /&gt;
15.	Category_talk:OWASP_XML_Security_Gateway_Evaluation_Criteria_Project&lt;br /&gt;
&lt;br /&gt;
16.	Don’t drop the SOAP OWASP.ppt&lt;br /&gt;
&lt;br /&gt;
17.	AppSec2005DC-Alex_Smolen-OWASP_WebServices_Project.ppt&lt;br /&gt;
&lt;br /&gt;
18.	AppSec2005DC-Jeff_Williams-OWASP_AppSec_Guide_2.0.ppt&lt;br /&gt;
&lt;br /&gt;
19.	OWASPAppSecEU2006_ProtectingWebServicesAndAapplications.ppt&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Content'''&lt;br /&gt;
&lt;br /&gt;
-	Completeness&lt;br /&gt;
&lt;br /&gt;
-	Relevance&lt;br /&gt;
&lt;br /&gt;
-	Target audience&lt;br /&gt;
&lt;br /&gt;
'''Organization'''&lt;br /&gt;
&lt;br /&gt;
-	Ease of navigation&lt;br /&gt;
&lt;br /&gt;
-	Ease of locating a specific topic&lt;br /&gt;
&lt;br /&gt;
-	Communication of updates&lt;br /&gt;
&lt;br /&gt;
'''Search'''&lt;br /&gt;
&lt;br /&gt;
-&lt;br /&gt;
&lt;br /&gt;
== Desired State ==&lt;br /&gt;
&lt;br /&gt;
'''Content'''&lt;br /&gt;
&lt;br /&gt;
-	Completeness&lt;br /&gt;
&lt;br /&gt;
-	Relevance&lt;br /&gt;
&lt;br /&gt;
-	Target audience&lt;br /&gt;
&lt;br /&gt;
'''Organization'''&lt;br /&gt;
&lt;br /&gt;
-	Ease of navigation&lt;br /&gt;
&lt;br /&gt;
-	Ease of locating a specific topic&lt;br /&gt;
&lt;br /&gt;
-	Communication of updates&lt;br /&gt;
&lt;br /&gt;
'''Search'''&lt;br /&gt;
&lt;br /&gt;
-&lt;br /&gt;
&lt;br /&gt;
== Proposed Layout ==&lt;br /&gt;
&lt;br /&gt;
The proposed OWASP Web Services Security Project will serve as a starting point for any web services-related inquiries on OWASP.  It will consist of a launchpad or home page with an introduction to the project, regular updates to pages in the project, and links to project pages and external resources. &lt;br /&gt;
&lt;br /&gt;
[[Image:WS_Launchpad.jpg|thumb|600px|LEFT|Launchpad Layout (click to see a bigger image)]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Introduction&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Updates&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;External Links&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;OWASP Pages&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Security Docs/Presentations&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Standards&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Communications&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;XML Security&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Testing Web Services&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Tools&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Gateways&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;SOA Architecture and Design&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Implementation Platforms&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;OWASP Top 10 Web Services Chapter&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Goals &amp;amp; Roadmap ==&lt;br /&gt;
&lt;br /&gt;
Currently the project goals are to:&lt;br /&gt;
&lt;br /&gt;
* Creation of launch pad layout&lt;br /&gt;
&lt;br /&gt;
* Create template start page for each subtopic &lt;br /&gt;
&lt;br /&gt;
* Find solid external resources&lt;br /&gt;
&lt;br /&gt;
* Recruit volunteer team (2-4 person)&lt;br /&gt;
&lt;br /&gt;
* For each topic: &lt;br /&gt;
&lt;br /&gt;
- Create start page for the subtopic topic&lt;br /&gt;
&lt;br /&gt;
- Gather all existing relevant articles within OWASP&lt;br /&gt;
&lt;br /&gt;
- Create plan of consolidating all the relevant information&lt;br /&gt;
&lt;br /&gt;
- Contact authors of relevant articles if change is required&lt;br /&gt;
&lt;br /&gt;
- Consolidate all information on the topic&lt;br /&gt;
&lt;br /&gt;
- Find solid external resources&lt;br /&gt;
&lt;br /&gt;
- Create link back to the main Web Services Security Project launchpad&lt;br /&gt;
&lt;br /&gt;
* Research way of communicating any updates to web services pages on launchpad&lt;br /&gt;
&lt;br /&gt;
* Search optimization (both OWASP and Google)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
A detailed project plan and schedule will be developed shortly and posted here.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Guiding Principles ==&lt;br /&gt;
&lt;br /&gt;
tbd&lt;br /&gt;
&lt;br /&gt;
== Resources and links ==&lt;br /&gt;
&lt;br /&gt;
This project is not standalone. This project will draw pieces of information from:&lt;br /&gt;
* OWASP Guide&lt;br /&gt;
* Other OWASP pages&lt;br /&gt;
* OWASP documents&lt;br /&gt;
* Relevant external links&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation: ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Web Services Security Project to be useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to sahba@securitycompass.com.&lt;br /&gt;
&lt;br /&gt;
== Project Contributors ==&lt;br /&gt;
&lt;br /&gt;
If you contribute to this Project, please add your name here.&amp;lt;br&amp;gt;&lt;br /&gt;
Project Leads:&lt;br /&gt;
* [[User:nbhalla| Nish Bhalla]]&lt;br /&gt;
* [[User:skazerooni| Sahba Kazerooni]]&lt;br /&gt;
* [[User:Subu Ramanathan| Subu Ramanathan]]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* you? ...&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Web Services Security Project]]&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Subu Ramanathan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Services_Security_Project&amp;diff=66663</id>
		<title>Category:OWASP Web Services Security Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Web_Services_Security_Project&amp;diff=66663"/>
				<updated>2009-07-27T15:50:21Z</updated>
		
		<summary type="html">&lt;p&gt;Subu Ramanathan: Added Subu Ramanathan to the list of project leads&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{:Template:Orphaned Projects}}&lt;br /&gt;
&lt;br /&gt;
== Welcome to the OWASP Web Services Security Project==&lt;br /&gt;
&lt;br /&gt;
[a brief about web services security in general and the current state of OWASP in web services security]&lt;br /&gt;
&lt;br /&gt;
The following document outlines a proposed layout for a new Web Services Security Project for the Open Web Application Security Project (OWASP).  &lt;br /&gt;
&lt;br /&gt;
== Current State ==&lt;br /&gt;
&lt;br /&gt;
'''Current Relevant OWASP Pages'''&lt;br /&gt;
&lt;br /&gt;
1.	Web Services&lt;br /&gt;
a.	Securing web services&lt;br /&gt;
b.	Communication security&lt;br /&gt;
c.	Passing credentials&lt;br /&gt;
d.	Ensuring message freshness&lt;br /&gt;
e.	Protecting message integrity&lt;br /&gt;
f.	Protecting message confidentiality&lt;br /&gt;
g.	Access control&lt;br /&gt;
h.	Audit&lt;br /&gt;
i.	Web services security hierarchy&lt;br /&gt;
i.	standard committees&lt;br /&gt;
j.	SOAP&lt;br /&gt;
i.	XML signatures and encryption&lt;br /&gt;
ii.	Security specifications&lt;br /&gt;
k.	WS-Security standard&lt;br /&gt;
i.	Organization of the standard&lt;br /&gt;
ii.	Purpose&lt;br /&gt;
l.	WS-Security Building blocks&lt;br /&gt;
i.	How data is passed&lt;br /&gt;
ii.	Security header’s structure&lt;br /&gt;
iii.	Types of tokens&lt;br /&gt;
iv.	Referencing message parts&lt;br /&gt;
m.	Communication protection mechanisms&lt;br /&gt;
i.	Integrity&lt;br /&gt;
ii.	Confidentiality&lt;br /&gt;
iii.	Freshness&lt;br /&gt;
n.	Access control mechanisms&lt;br /&gt;
i.	Identification&lt;br /&gt;
ii.	Authentication&lt;br /&gt;
iii.	Authorization&lt;br /&gt;
iv.	Policy agreement&lt;br /&gt;
o.	Forming web services chains&lt;br /&gt;
i.	Incompatible user access control models&lt;br /&gt;
ii.	Service trust&lt;br /&gt;
iii.	Secure connections&lt;br /&gt;
iv.	Synchronization of user directories&lt;br /&gt;
v.	Domain federation&lt;br /&gt;
p.	Available implementations&lt;br /&gt;
i.	.NET – Web services extensions&lt;br /&gt;
ii.	Java toolkits&lt;br /&gt;
iii.	Hardware software systems&lt;br /&gt;
q.	Problems&lt;br /&gt;
i.	Immaturity of the standards&lt;br /&gt;
ii.	Performance&lt;br /&gt;
iii.	Complexity and interoperability&lt;br /&gt;
iv.	Key management&lt;br /&gt;
r.	Further reading&lt;br /&gt;
&lt;br /&gt;
2.	A Tale of Two Systems&lt;br /&gt;
- case studies of two hypothetical systems, one of which involves openning a mainframe app to the web using a web service, and the risks that are posed.&lt;br /&gt;
&lt;br /&gt;
3.	Theres More to Securing Web Services Systems Than WS-Security&lt;br /&gt;
a.	What is a web service&lt;br /&gt;
b.	Web services from the information security perspective&lt;br /&gt;
c.	Some security implications of this perspective&lt;br /&gt;
i.	Emergent risks&lt;br /&gt;
ii.	End-to-end controls&lt;br /&gt;
d.	Interconnection of systems from different trust domains&lt;br /&gt;
i.	Some implications of the organization’s risk management process and system development life cycle&lt;br /&gt;
ii.	Emerging standards for securing web services&lt;br /&gt;
iii.	WS-Security specifications in process&lt;br /&gt;
iv.	Trust management revisited&lt;br /&gt;
e.	References&lt;br /&gt;
&lt;br /&gt;
4.	Web Services Architecture and Security&lt;br /&gt;
a.	The web services architecture&lt;br /&gt;
b.	Service oriented architectures and distributed systems&lt;br /&gt;
c.	Complexity is the enemy of security…&lt;br /&gt;
d.	The architectural models&lt;br /&gt;
e.	The policy model&lt;br /&gt;
f.	The service oriented model&lt;br /&gt;
g.	The resource oriented model&lt;br /&gt;
h.	The message oriented model&lt;br /&gt;
i.	The management model&lt;br /&gt;
j.	The rest&lt;br /&gt;
k.	References&lt;br /&gt;
&lt;br /&gt;
5.	Testing for Web Services (from OWASP Testing Guide)&lt;br /&gt;
a.	XML Structural Testing&lt;br /&gt;
b.	XML Content-level Testing&lt;br /&gt;
c.	HTTP GET parameters/REST Testing&lt;br /&gt;
d.	Naughty SOAP attachments&lt;br /&gt;
e.	Replay Testing&lt;br /&gt;
&lt;br /&gt;
6.	Image:Web services security.doc&lt;br /&gt;
&lt;br /&gt;
7.	Image:InfoSec_World_2007_-_Web_services_gateways.ppt&lt;br /&gt;
&lt;br /&gt;
8.	Image:AppSec2005DC-Alex_Stamos-Attacking_Web_Services.ppt&lt;br /&gt;
&lt;br /&gt;
9.	Image:OWASPAppSec2006Seattle_Web_Services_Security.ppt&lt;br /&gt;
&lt;br /&gt;
10.	.NET Web Service Validation&lt;br /&gt;
a.	Perfomance penalties&lt;br /&gt;
b.	Downloading&lt;br /&gt;
c.	Installation&lt;br /&gt;
d.	Reporting Bugs&lt;br /&gt;
e.	Use&lt;br /&gt;
i.	Methods of use&lt;br /&gt;
ii.	Attributes&lt;br /&gt;
iii.	Web.config changes&lt;br /&gt;
iv.	Using validation&lt;br /&gt;
v.	Using assertions&lt;br /&gt;
&lt;br /&gt;
11.	OWASP WSFuzzer Project&lt;br /&gt;
&lt;br /&gt;
12.	OWASP interceptor Project&lt;br /&gt;
&lt;br /&gt;
13.	OWASP Guide&lt;br /&gt;
&lt;br /&gt;
14.	OWASPAppSecEU2006_InlineApproachforSecureSOAPRequests.ppt&lt;br /&gt;
&lt;br /&gt;
15.	Category_talk:OWASP_XML_Security_Gateway_Evaluation_Criteria_Project&lt;br /&gt;
&lt;br /&gt;
16.	Don’t drop the SOAP OWASP.ppt&lt;br /&gt;
&lt;br /&gt;
17.	AppSec2005DC-Alex_Smolen-OWASP_WebServices_Project.ppt&lt;br /&gt;
&lt;br /&gt;
18.	AppSec2005DC-Jeff_Williams-OWASP_AppSec_Guide_2.0.ppt&lt;br /&gt;
&lt;br /&gt;
19.	OWASPAppSecEU2006_ProtectingWebServicesAndAapplications.ppt&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Content'''&lt;br /&gt;
&lt;br /&gt;
-	Completeness&lt;br /&gt;
&lt;br /&gt;
-	Relevance&lt;br /&gt;
&lt;br /&gt;
-	Target audience&lt;br /&gt;
&lt;br /&gt;
'''Organization'''&lt;br /&gt;
&lt;br /&gt;
-	Ease of navigation&lt;br /&gt;
&lt;br /&gt;
-	Ease of locating a specific topic&lt;br /&gt;
&lt;br /&gt;
-	Communication of updates&lt;br /&gt;
&lt;br /&gt;
'''Search'''&lt;br /&gt;
&lt;br /&gt;
-&lt;br /&gt;
&lt;br /&gt;
== Desired State ==&lt;br /&gt;
&lt;br /&gt;
'''Content'''&lt;br /&gt;
&lt;br /&gt;
-	Completeness&lt;br /&gt;
&lt;br /&gt;
-	Relevance&lt;br /&gt;
&lt;br /&gt;
-	Target audience&lt;br /&gt;
&lt;br /&gt;
'''Organization'''&lt;br /&gt;
&lt;br /&gt;
-	Ease of navigation&lt;br /&gt;
&lt;br /&gt;
-	Ease of locating a specific topic&lt;br /&gt;
&lt;br /&gt;
-	Communication of updates&lt;br /&gt;
&lt;br /&gt;
'''Search'''&lt;br /&gt;
&lt;br /&gt;
-&lt;br /&gt;
&lt;br /&gt;
== Proposed Layout ==&lt;br /&gt;
&lt;br /&gt;
The proposed OWASP Web Services Security Project will serve as a starting point for any web services-related inquiries on OWASP.  It will consist of a launchpad or home page with an introduction to the project, regular updates to pages in the project, and links to project pages and external resources. &lt;br /&gt;
&lt;br /&gt;
[[Image:WS_Launchpad.jpg|thumb|600px|LEFT|Launchpad Layout (click to see a bigger image)]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Introduction&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Updates&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;External Links&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;OWASP Pages&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Security Docs/Presentations&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Standards&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Communications&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;XML Security&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Testing Web Services&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Tools&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Gateways&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;SOA Architecture and Design&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;WS Implementation Platforms&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;OWASP Top 10 Web Services Chapter&amp;lt;/b&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[brief description here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Goals &amp;amp; Roadmap ==&lt;br /&gt;
&lt;br /&gt;
Currently the project goals are to:&lt;br /&gt;
&lt;br /&gt;
* Creation of launch pad layout&lt;br /&gt;
&lt;br /&gt;
* Create template start page for each subtopic &lt;br /&gt;
&lt;br /&gt;
* Find solid external resources&lt;br /&gt;
&lt;br /&gt;
* Recruit volunteer team (2-4 person)&lt;br /&gt;
&lt;br /&gt;
* For each topic: &lt;br /&gt;
&lt;br /&gt;
- Create start page for the subtopic topic&lt;br /&gt;
&lt;br /&gt;
- Gather all existing relevant articles within OWASP&lt;br /&gt;
&lt;br /&gt;
- Create plan of consolidating all the relevant information&lt;br /&gt;
&lt;br /&gt;
- Contact authors of relevant articles if change is required&lt;br /&gt;
&lt;br /&gt;
- Consolidate all information on the topic&lt;br /&gt;
&lt;br /&gt;
- Find solid external resources&lt;br /&gt;
&lt;br /&gt;
- Create link back to the main Web Services Security Project launchpad&lt;br /&gt;
&lt;br /&gt;
* Research way of communicating any updates to web services pages on launchpad&lt;br /&gt;
&lt;br /&gt;
* Search optimization (both OWASP and Google)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
A detailed project plan and schedule will be developed shortly and posted here.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Guiding Principles ==&lt;br /&gt;
&lt;br /&gt;
tbd&lt;br /&gt;
&lt;br /&gt;
== Resources and links ==&lt;br /&gt;
&lt;br /&gt;
This project is not standalone. This project will draw pieces of information from:&lt;br /&gt;
* OWASP Guide&lt;br /&gt;
* Other OWASP pages&lt;br /&gt;
* OWASP documents&lt;br /&gt;
* Relevant external links&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
== Feedback and Participation: ==&lt;br /&gt;
&lt;br /&gt;
We hope you find the OWASP Web Services Security Project to be useful. Please contribute to the Project by volunteering for one of the Tasks, sending your comments, questions, and suggestions to sahba@securitycompass.com.&lt;br /&gt;
&lt;br /&gt;
== Project Contributors ==&lt;br /&gt;
&lt;br /&gt;
If you contribute to this Project, please add your name here.&amp;lt;br&amp;gt;&lt;br /&gt;
Project Leads:&lt;br /&gt;
* [[User:nbhalla| Nish Bhalla]]&lt;br /&gt;
* [[User:skazerooni| Sahba Kazerooni]]&lt;br /&gt;
* [[User:Subu Ramanathan| Subu Ramanathan]]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* you? ...&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Web Services Security Project]]&lt;/div&gt;</summary>
		<author><name>Subu Ramanathan</name></author>	</entry>

	</feed>