Chapter 8. Security

The most critical issue limiting the widespread deployment of Web services by organizations is the lack of understanding of the security risks involved as well as the best practices for addressing those risks. Development and IT managers want to know whether the security risks and the types of attack common for Web sites will be the same for Web services. Will existing enterprise security infrastructure already in place, such as firewalls and well-understood technologies like Secure Sockets Layer (SSL), be sufficient to protect their companies from Web service security risks?

Much of the experience companies have with security is with Web sites and Web applications. Both Web sites and Web applications involve sending HTML ...

Get Developing Enterprise Web Services: An Architect's Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.