New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 23)
· Marcia's (CO8)
· Bill G's (CO11)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 983
Comments: 19
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
image prot: Security HeadLines: Web Services: Protecting Yourself from Partners' Security Problems image
Protocols

OASIS unveils XML schema to provide initial threat, impact, and risk ratings guidance in consistent manner

The Organization for the Advancement of Structured Information Standards (OASIS), a global consortium that sets worldwide standards for security, Web services, conformance, business transactions, electronic publishing, topic maps, and interoperability within and between marketplaces, announced its members are creating a new, open data format to describe Web application security vulnerabilities. The model will provide initial threat, impact, and risk ratings guidance for companies, as well as an XML schema to describe Web security conditions that can be used by both assessment and protection tools.






June 04, 2003
By Mathew Schwartz

The goal of the web applications security (WAS) standard will be to reduce the amount of redundant information produced for security vulnerability alerts, and simplify the process of understanding which systems are affected. In particular, the application vulnerability description language, as it’s also known, will create a uniform way of describing application security vulnerabilities through the XML format.

“The growing sophistication of security threats requires standards for classifying risk and determining the impact of new Web Security vulnerabilities,” notes Gerhard Eschelbeck, chief technology officer and vice president of engineering of security audit company Qualys Inc. in Redwood Shores, Calif.

The potential of Web Services is to increase the flow and automation of information exchange between Web servers, or between servers and people. Unfortunately, tying different servers together—often across different corporate firewalls—means that organizations are exposed to a greater range of security threats. What starts out as a breach in a partner’s Web server can quickly work its way into a Web Services partner’s server, or an attacker can compromise the integrity of data flowing between servers, potentially sabotaging important information. In a supply chain, for example, incorrect inventory requests could trigger unwanted manufacturing operations, with grave financial consequences.

To deal with potential Web Services threats, organizations need more automated, standardized ways of disseminating security warnings, say experts.

Article continues...
Enterprise Systems


Posted on Wednesday, 04 June 2003 @ 07:05:00 EDT by cj
image

 
Login
Nickname

Password

· New User? ·
Click here to create a registered account.
image
Related Links
· TrackBack (0)
· HotScripts
· W3 Consortium
· TCP/IP Protocol Suite
· More about Protocols
· News by cj


Most read story about Protocols:
Free Online Port Scanning Utilities

image
Article Rating
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


image
Options

Printer Friendly Page  Printer Friendly Page

image
"Login" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register