Managing SOA Security and Operations with SecureSpan



Similar documents
Securely Managing and Exposing Web Services & Applications

Core Feature Comparison between. XML / SOA Gateways. and. Web Application Firewalls. Jason Macy jmacy@forumsys.com CTO, Forum Systems

WebSphere Integration Solutions. IBM Day Minsk Anton Litvinov WebSphere Connectivity Professional Central Eastern Europe

Redbook Overview Patterns: SOA Design with WebSphere Message Broker and WebSphere ESB

Federated Identity and Single Sign-On using CA API Gateway

Creating a Strong Security Infrastructure for Exposing JBoss Services

IBM WebSphere DataPower Integration Appliance XI52

An Oracle White Paper Dec Oracle Access Management Security Token Service

Mobile Identity and Edge Security Forum Sentry Security Gateway. Jason Macy CTO, Forum Systems

The bridge to delivering digital applications across cloud, mobile and partner channels

Apigee Gateway Specifications

Contents. Overview 1 SENTINET

Meet the Cloud API The New Enterprise Control Point

Sentinet for BizTalk Server SENTINET

An Open Policy Framework for Cross-vendor Integrated Governance

OPENIAM ACCESS MANAGER. Web Access Management made Easy

NIST s Guide to Secure Web Services

Oracle SOA Suite: The Evaluation from 10g to 11g

Interoperable Provisioning in a Distributed World

Web Services and Service Oriented Architectures. Thomas Soddemann, RZG

Using Layer 7 s API Gateway for vcloud Architectures How to achieve abstraction, security and management of vcloud APIs.

SOA Fundamentals For Java Developers. Alexander Ulanov, System Architect Odessa, 30 September 2008

Oracle Platform Security Services & Authorization Policy Manager. Vinay Shukla July 2010

Service Virtualization: Managing Change in a Service-Oriented Architecture

An Enterprise Architect s Guide to API Integration for ESB and SOA

Presentation Outline. Key Business Imperatives Service Oriented Architecture Defined Oracle SOA Platform SOA Maturity/Adoption Model Demo Q&A

Web Services Security: OpenSSO and Access Management for SOA. Sang Shin Java Technology Evangelist Sun Microsystems, Inc. javapassion.

<Insert Picture Here> Oracle Web Services Manager (WSM)

API Management: Powered by SOA Software Dedicated Cloud

Federated Identity and Trust Management

Sentinet for BizTalk Server SENTINET 3.1

AquaLogic Service Bus

APIs The Next Hacker Target Or a Business and Security Opportunity?

Secure Identity Propagation Using WS- Trust, SAML2, and WS-Security 12 Apr 2011 IBM Impact

Enterprise Access Control Patterns For REST and Web APIs

ebay : How is it a hit

IBM Tivoli Federated Identity Manager

A standards-based approach to application integration

Introduction to Service Oriented Architecture (SOA)

Run-time Service Oriented Architecture (SOA) V 0.1

2013 AWS Worldwide Public Sector Summit Washington, D.C.

Introduction to WebSphere Process Server and WebSphere Enterprise Service Bus

Securing Web Services From Encryption to a Web Service Security Infrastructure

Methods and tools for data and software integration Enterprise Service Bus

Federated single sign-on (SSO) and identity management. Secure mobile access. Social identity integration. Automated user provisioning.

CICS Web Service Security. Anthony Papageorgiou IBM CICS Development March 13, 2012 Session: 10282

Chapter 2: Cloud Basics Chapter 3: Cloud Architecture

IBM WebSphere application integration software: A faster way to respond to new business-driven opportunities.

Improving performance for security enabled web services. - Dr. Colm Ó héigeartaigh

Strategic Information Security. Attacking and Defending Web Services

Introduction to Service-Oriented Architecture for Business Analysts

Sun and Oracle: Joining Forces in Identity Management

How To Understand A Services-Oriented Architecture

CA Federation Manager

SaaS at Pfizer. Challenges, Solutions, Recommendations. Worldwide Business Technology

Copyright 2012, Oracle and/or its affiliates. All rights reserved.

Enterprise Application Designs In Relation to ERP and SOA

Increasing IT flexibility with IBM WebSphere ESB software.

SOA Best Practices (from monolithic to service-oriented)

Increasing IT flexibility with IBM WebSphere ESB software.

Security in integration and Enterprise Service Bus(ESB) Anton Panhelainen Principal Technology Consultant Tieto Oy

PUR1311/19. Request for Information (RFI) Provision of an Enterprise Service Bus. to the. European Bank for Reconstruction and Development

Network Test Labs (NTL) Software Testing Services for igaming

Access Management Analysis of some available solutions

Cisco AON Secure File Transfer Extension Module

Server based signature service. Overview

The Role of Identity Enabled Web Services in Cloud Computing

JBI and OpenESB. Introduction to Technology. Michael Czapski Advanced Solutions Architect, SOA/BI/Java CAPS Sun Microsystems, ANZ

The following is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into

Oracle Service Bus. Situation. Oracle Service Bus Primer. Product History and Evolution. Positioning. Usage Scenario

SCA-based Enterprise Service Bus WebSphere ESB

WEB SERVICES SECURITY

Research. A Competitive Review of SOA Appliances. Comparing SOA appliances from IBM, Layer 7 and Intel. Version 1.00 March 2010.

SEC100 Secure Authentication and Data Transfer with SAP Single Sign-On. Public

Integrated Systems & Solutions. Some Performance and Security Findings Relative to a SOA Ground Implementation. March 28, John Hohwald.

OpenAM All-In-One solution to securely manage access to digital enterprise and customer services, anytime and anywhere.

XML Signatures in an Enterprise Service Bus Environment

Service Oriented Architecture (SOA) Architecture, Governance, Standards and Technologies

Raghu R Kodali Consulting Product Manager, & Evangelist Oracle Fusion Middleware Oracle USA Author Beginning EJB 3 Application Development (Apress)

Oracle SOA Reference Architecture

Service-Oriented Architecture and Software Engineering

The Top 5 Federated Single Sign-On Scenarios

Product overview. CA SiteMinder lets you manage and deploy secure web applications to: Increase new business opportunities

Government's Adoption of SOA and SOA Examples

Policy Driven Practices for SOA

Sentinet for Windows Azure SENTINET

The Enterprise Service Bus

Enterprise Reference Architecture

Apigee Edge API Services Manage, scale, secure, and build APIs and apps

IBM WebSphere ESB V6.0.1 Technical Product Overview

1 What Are Web Services?

Transcription:

Managing SOA Security and Operations with SecureSpan Francois Lascelles Technical Director, Layer 7 Technologies 1

Customers Revenue About Layer 7 Layer 7 is the leading vendor of security and governance for: Cloud SOA XML 2003 2006 2009 2

Why Layer 7 SecureSpan? Faster time to market Governance Agility Security Reduce development, deployment and management efforts JBossESB infrastructure service, delegate business logic Faster additions, changes Enterprise-wide view of services Real time monitoring, reporting Service virtualization Decoupled policy enforcement Threat protection, access control, trust management, 3

SecureSpan XML Gateway secure ws transit point ws-security implementation trust management mediation, integration threat protection auditing, sla monitoring, reporting 4

Hardware or software appliance form factor COTS appliance form factor enables drop-in solution with minimal deployment time and instant value. No agents to deploy, no dependencies. Hardware Appliance Military grade, hardened device Telecom grade performance FIPS 140-2 certified crypto Hard and soft XML acceleration Virtual Appliance Pre-installed, hardened RHEL image ESX certified, Amazon, private clouds FIPS 140-2 certified crypto (soft mode) Soft (native) XML acceleration 5

Policy Studio Policies are created by organizing assertions in logical tree structures. Policies are changed on the fly, without service interruptions. Rich palette, extensible through JAVA API. Design, implementation and deployment in hours, not months or years. Automated, scripted provisioning and management through API. 6

Message level aware intermediary Delegate common or expensive XML related tasks from your endpoints to your infrastructure. Web Services Cut development costs and increase governance by implementing more business logic at infrastructure level. 7

How to implement security in the Enterprise SOA? IAM Security implemented in the service endpoints? Authentication Authorization Integrity Confidentiality Key management Threat protection Non-repudiation Audit Less governance Expensive development task An obstacle to loose coupling Resources not used effectively ESB and WS stacks not appropriate for edge security 8 applications endpoints

Delegating endpoint security XML Gateway enforces security for incoming traffic on behalf of protected services. XML Gateway secures outgoing traffic on behalf of protected services. protected services 9

Identity Federation, Trust Management Identity and Access Management interfacing STS, SSO Runtime access control rules enforcement LDAP, SUN OpenSSO, Novell AM, Oracle AM, Netegrity, Tivoli, MSAD SAML issuing, validation WS-Trust, SAML-P WS-SecureConversation WS Federation Fined grain trust management 10

Threat Protection Network/OS level threats Message level threats Consistent security policies for heterogeneous environment Schema poisoning Recursive entity attacks Code injections WSDL fishing Parser attacks 11

Service level monitoring, enforcement Real time contract lookup and enforcement (SLA) Throughput quotas Throttling Per identity, per operation Protect service endpoints Monitoring of response times Custom alert triggers Custom reporting Priority routing rules 12

Loose coupling, late binding Routing based on remote IP content identity, identity attribute pattern New type of request Last minute binding involving consultation of resource LDAP UDDI database external WS Who does that? Route message to appropriate endpoint 13

ESB co-processing JBossESB SecureSpan Infrastructure Service Accelerated XSLT Accelerated XSD Accelerated pattern detection WSS Processing SLA Enforcement 14

Enterprise Service Manager Agent-less WS Management Enterprise wide view of services Performance and usage reports Service and policy migration Remote gateway start/stop Custom reports Remote gateway upgrade, upload modules* 15

Assisted migration across environments 16

Enterprise services in the cloud Enterprise subscriber Enterprise deploys own services on cloud provider Monitoring? Msg level security? Quality of service? Reports? Lack of in-house service governance is a barrier to adoption 17

SecureSpan on public/enterprise cloud 18

Customer case: air traffic scheduling service provider Runway information fed from airports LHR AMS FRA YYZ Hosted service Data agglomeration Fixed file length proprietary format Repurposed data sent to airlines and outsourced systems EDS flight planner Lufthansa systems Swiss airline Edge security, threat protection Trust management Transformation Service virtualization 19

Customer case: insurance cross platform integration Distributed transaction platform JBoss - consumers - providers Centralized transaction platform Mainframe - consumers - providers.net, Office - consumers - providers Office Automation Enterprise resource planning SAP (XI/PI) - consumers - providers Central access point to all services Transport mediation (e.g. http to mq) WS mediation (e.g. addressing, security) Identity mapping 20

Customer case: healthcare electronic exchange National PKI infrastructure - Health records - Prescriptions - Provider services Hospital and emergency applications Service virtualization for simulation projects Complex security validation SHA256 based signatures Custom token extensions Full PKI integration, revocation checking Sophisticated validation (XSD, Schematron) 21

Customer case: military CDS NAVY ARMY AIR FORCE Others Guard pattern Federation/Trust Management/SAML Data screening FIPS 140-2 level 3 compliancy Common criteria EAL4+ 22

For more information about SecureSpan: http://www.layer7tech.com 23