SOA Security

May 31, 2005, 8:16pm PDT | Length: 00:02:13
When Roger Thornton of Fortify sees the letters SOA, he reads it as 'Secure Old Applications.' By integrating systems in real-time, SOA has created the potential for attacks on business applications in ways that were not initially considered.

Transcript

SOA Security

Hi. I'm Roger Thornton, CTO of Fortify Software. Today, weare going to be talking about SOA security.

When you see the letters SOA, you know what that means:Services Oriented Architectures, where we take inside the enterprise all of thesystems that run core pieces of our business, of the inventory, sales,financial and we create interfaces around those so that we can build all sortsof adhoc applications and rapidly integrate systems together in real times,both inside our company and with all our business partners in the outsideworld.

But when I see the letters SOA as a security person, I seeSecure Old Applications. Why is that? Well, in the security world, all theseaccess points, all these real-time access points that we're making into thesesystems, we call those attack surface paths, and all the threats that are outthere -- hackers, malicious insiders, viruses, and worms-- those aren't justfor operating systems those will come after your business applications too. Inthe past they never had a chance of getting near these applications. Why? Theywere deep inside the enterprise computing infrastructure of your company. Butonce you go to a Service Oriented Architecture, there are going to be numerouspaths into those systems, and what's the probability that back in the 1970s, orin the 1980s, or in the 1990s, when these were built, that people thought aboutthese threats addressing those applications were zero.

So SOA is an important technology and it's an importantenabler, but if you do it make sure you also read that as Secure Old Applications.

First steps to SOA

First steps to SOA

What does it really mean to introduce SOA into an organization? Ross Mason, CTO and co-founder...

SOA for the masses

SOA for the masses

Service-oriented architecture has long been the province of the enterprise because of its high...

Beyond calendar 1.0

Beyond calendar 1.0

Most people are still using old calendar technology to manage their time. Zimbra's Ross Dargahi...

Control XML = Successful SOA

Control XML = Successful SOA

If you've got services, you've got XML, according to Reactivity's Joelle Gropper Kaufman. In...

Why SOA is for real

Why SOA is for real

Bill Roth explains how service-oriented infrastructures emerged and how they are being used in...

Optimizing SOA

Optimizing SOA

As the number of components in SOA apps increases, an optimization layer is required in the...

Infrastructure-as-a-service

Infrastructure-as-a-service

From client servers to Web services, from SOA to pay-as-you-go, what's the next wave in IT?

What is SOA?

What is SOA?

Service oriented architecture may be over-hyped, but it does offer lower-cost and easier...

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

White Papers, Webcasts, & Resources

Facebook Activity