XML Rewriting Attacks: Existing Solutions and their Limitations
Azzedine Benameur, Faisal Abdul Kadir, Serge Fenet

TL;DR
This paper explains XML rewriting attacks on SOAP messages, reviews existing solutions and their limitations, and proposes new ideas for securing web service communications against such attacks.
Contribution
It provides a comprehensive analysis of XML rewriting attacks, evaluates current defenses, and suggests novel approaches to enhance SOAP message security.
Findings
Existing solutions have significant limitations in preventing XML rewriting attacks.
The paper identifies gaps in current security measures for SOAP messages.
Proposes new ideas and implementation strategies for securing XML-based web service messages.
Abstract
Web Services are web-based applications made available for web users or remote Web-based programs. In order to promote interoperability, they publish their interfaces in the so-called WSDL file and allow remote call over the network. Although Web Services can be used in different ways, the industry standard is the Service Oriented Architecture Web Services that doesn't rely on the implementation details. In this architecture, communication is performed through XML-based messages called SOAP messages. However, those messages are prone to attacks that can lead to code injection, unauthorized accesses, identity theft, etc. This type of attacks, called XML Rewriting Attacks, are all based on unauthorized, yet possible, modifications of SOAP messages. We present in this paper an explanation of this kind of attack, review the existing solutions, and show their limitations. We also propose…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsDigital Rights Management and Security · User Authentication and Security Systems · Digital and Cyber Forensics
