Web services became a crucial tool for most of the Internet and Intranet applications and distributed systems due to its interoperability. As the usage is increased, performance and the security of Web services are facing a great impact due to DDoS attacks, XML Injection, XSS Injection etc. The hacker's major target is either to track the data down the line or to break the network bandwidth and feed in vulnerable data to collapse the system. Existing trends follow a stream based approach with encryption techniques to increase robustness, or a Double Guard Intrusion Detection System with light weight virtualization is adapted to prevent the attacks over multitier web services. Various prevalent techniques focus towards securing data, increasing robustness and improve the network bandwidth. But there is no focus towards the validation of the service request. The proposed XSD DDOS Trace Handler approach is an innovative framework that uses the concepts of Validate Handler for the input request based on input data standards and request timestamps from the specific host. It also implements the "Totient Encryption Algorithm" in the case of XML Injection Attacks wherein a clean monitoring of the source attributes is performed. This is achieved with a dynamic charting technique that overcomes the predominant injection and DDOS attacks in the service oriented architecture.
[1]
Lalu Banothu.
Sigfree-A Signature-Free Buffer Overflow Attack Blocker
,
2012
.
[2]
Lutz Lowis,et al.
Vulnerability Analysis in SOA-Based Business Processes
,
2011,
IEEE Transactions on Services Computing.
[3]
Albert K. T. Hui,et al.
Universal DDoS Mitigation Bypass
,
2013
.
[4]
Mahdi Bazarganigilani,et al.
Web Service Intrusion Detection Using XML Similarity Classification and WSDL Description
,
2011
.
[5]
Angelos Stavrou,et al.
DoubleGuard: Detecting Intrusions in Multitier Web Applications
,
2012,
IEEE Transactions on Dependable and Secure Computing.
[6]
R. Mahmod,et al.
Model-based system architecture for preventing XPath injection in database-centric web services environment
,
2012,
2012 7th International Conference on Computing and Convergence Technology (ICCCT).
[7]
Nils Gruschka,et al.
Server-Side Streaming Processing of WS-Security
,
2011,
IEEE Transactions on Services Computing.
[8]
R. Pratheeba,et al.
MODELING SMARTY WEB SEARCH ENGINE USING XML CLUSTERING 1
,
2017
.