Projects per year
Abstract
complexity.
In this work, we examine the practical application of authorization management mechanisms employed over RESTful Web APIs, which today serve as a major approach to expose service interfaces on the web. For this purpose, we have examined the integration of security mechanisms in n=523 publicWeb APIs. Our findings reveal alarming integration patterns that demonstrate a rudimentary data security and privacy protection in cross-service resource sharing.
Our analysis traces the cause back to the (1) shallow models and security capabilities offered by service providers, and (2) design deficiencies of dominantly applied OAuth 2.0 web authorization framework that restrict capabilities and lower the interoperability of underlying management functions. Following the initial discussion, we summarize potential solutions and establish an outline of the future work.
Original language | English |
---|---|
Title of host publication | Proceedings of the 33rd Annual ACM Symposium on Applied Computing |
Publisher | Association of Computing Machinery |
DOIs | |
Publication status | E-pub ahead of print - 2018 |
Keywords
- web services
- web api
- service security
- cloud services
- service integration
ASJC Scopus subject areas
- Information Systems
- Computer Networks and Communications
Fingerprint
Dive into the research topics of 'On The Structure and Authorization Management of RESTful Web Services'. Together they form a unique fingerprint.Projects
- 1 Active
-
A-SIT - Secure Information Technology Center Austria
Stranacher, K., Dominikus, S., Leitold, H., Marsalek, A., Teufl, P., Bauer, W., Aigner, M. J., Rössler, T., Neuherz, E., Dietrich, K., Zefferer, T., Mangard, S., Payer, U., Orthacker, C., Lipp, P., Reiter, A., Knall, T., Bratko, H., Bonato, M., Suzic, B., Zwattendorfer, B., Kreuzhuber, S., Oswald, M. E., Tauber, A., Posch, R., Bratko, D., Feichtner, J., Ivkovic, M., Reimair, F., Wolkerstorfer, J. & Scheibelhofer, K.
21/05/99 → 6/08/20
Project: Research area
Activities
- 1 Talk at conference or symposium
-
On The Structure and Authorization Management of RESTful Web Services
Bojan Suzic (Speaker), Bernd Prünster (Contributor) & Dominik Ziegler (Contributor)
13 Apr 2018Activity: Talk or presentation › Talk at conference or symposium › Science to science