>>Return to the microsite

Protecting Enterprise, SaaS & Cloud based Applications – A Comprehensive Threat model for REST, SOA and Web 2.0

This technical document describes a comprehensive threat model for a new breed of threats based on XML content, including XML languages used in the Service Oriented Architecture (SOA) paradigm such as SOAP and the Web Services Description Language [WSDL]. In today’s environment, architectures and protocols are shifting towards XML and new sets of technology vectors are emerging such as REST and XML-RPC. With Web 2.0, new threats loom on the horizon and consequently new protection methods are required to defend the application layer consuming and serving XML streams. Ajax- and RIA-based applications (Flash and Silverlight) are redefining the usage of XML streams and bringing about a shift in the threat model.

In addition, this document attempts to define the concept of XML Intrusion Prevention (XIP) as an analog to traditional network-based intrusion prevention. A new type of threat called an XML Content Attack is defined, and examples are provided for each layer in the threat model. Also, this document attempts to use the problem of lost context between XML processing layers to characterize many of the security problems that arise during XML processing. Finally, a specifc type of content-aware application-level proxy or firewall countermeasure is illustrated with Intel SOA Expressway.

First name:*
Last name:*
Job Title:*
Company:*
Work Phone:*
Country:*
Email Address:*

Comment, question, information request?

Information Library

  1. Data Sheet:

    Joint Solution

  2. White Paper:

    Extending Oracle Fusion Middleware for External Web Service Security

  3. Integration Guide:

    Oracle/Intel

  4. Solution Brief:

    Oracle/Intel

  5. White Paper:

    An Open Policy Framework for Cross-vendor Integrated Governance

  6. Analyst Report:

    451 Group Review of SOAE

  7. White Paper:

    Protecting Enterprise, SaaS & Cloud-based Application

  8. SOA Mag Article:

    Multi-Core Optimized
    Soft-Appliance

  9. White Paper:

    Performance Comparison to
    IBM DataPower XI50

  10. Web Site:

    SOA Expressway

  11. Web Site:

    Oracle SOA

  12. Web Site:

    DataPower Comparison Site




1. SOA Expressway/
    Oracle Sample App
2. SOA Benchmark Kit

Intel® SOA Expressway

Extends Oracle® Fusion Middleware

for External Web Service Security

Contact Us Terms of Use Trademarks Privacy ©Intel Corporation