{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,3]],"date-time":"2025-11-03T22:55:02Z","timestamp":1762210502230,"version":"3.33.0"},"publisher-location":"Berlin, Heidelberg","reference-count":64,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540729112"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-3-540-72912-9_14","type":"book-chapter","created":{"date-parts":[[2007,9,12]],"date-time":"2007-09-12T09:20:17Z","timestamp":1189588817000},"page":"395-440","source":"Crossref","is-referenced-by-count":15,"title":["Challenges of Testing Web Services and Security in SOA Implementations"],"prefix":"10.1007","author":[{"given":"Abbie","family":"Barbir","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chris","family":"Hobbs","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Elisa","family":"Bertino","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Frederick","family":"Hirsch","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lorenzo","family":"Martino","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"14_CR1","unstructured":"OASIS eXtensible Access Control Markup Language 2 (XACML) Version 2.0 OASIS Standard, 1 Feb 2005."},{"key":"14_CR2","doi-asserted-by":"crossref","unstructured":"M. Mecella, M. Ouzzani, F. Paci, E. Bertino. Access Control Enforcement for Conversational-based Services. Proceedings of 2006 WWW Conference, Edimburgh, Scotland, May 23-26, 2006.","DOI":"10.1145\/1135777.1135818"},{"key":"14_CR3","doi-asserted-by":"crossref","unstructured":"N. Damianou ,N. Dulay, E. Lupu and M. Sloman. The Ponder Policy Specification Language. Proceedings of the 2nd IEEE International Workshop on Policies for Distributed Systems and Networks, 2001.","DOI":"10.1007\/3-540-44569-2_2"},{"key":"14_CR4","doi-asserted-by":"crossref","unstructured":"T. Yu, M. Winslett, K. Seamons. Supporting Structured Credentials and Sensitive Policies through Interoperable Strategies for Automated Trust Negotiation. ACM Transactions on Information and System Security, Vol. 6, No. 1, February 2003.","DOI":"10.1145\/605434.605435"},{"key":"14_CR5","unstructured":"E. Bertino, E. Ferrari, A.C. Squicciarini. X -TNL: An XML-based Language for Trust Negotiations. Proceedings of the 4th IEEE International Workshop on Policies for Distributed Systems and Networks, 2003."},{"key":"14_CR6","doi-asserted-by":"crossref","first-page":"27","DOI":"10.4018\/jwsr.2006070102","volume":"3","author":"E. Bertino","year":"2006","unstructured":"E. Bertino, A.C. Squicciarini, L. Martino, F. Paci. An Adaptive Access Control Model for Web Services. International Journal of Web Service Research, (3), 27-60 July-September 2006.","journal-title":"International Journal of Web Service Research"},{"issue":"2","key":"14_CR7","doi-asserted-by":"crossref","first-page":"37","DOI":"10.4018\/jwsr.2004040103","volume":"1","author":"E. Bertino","year":"2004","unstructured":"E. Bertino, B. Carminati, E. Ferrari. Merkle Tree Authentication in UDDI Registries. International Journal of Web Service Research, 1(2): 37-57(2004).","journal-title":"International Journal of Web Service Research"},{"key":"14_CR8","unstructured":"E. Bertino, J. Crampton, F. Paci. Access Control and Authorization Constraints for WS-BPEL. Submitted for publication."},{"key":"14_CR9","unstructured":"OASIS Web Services Business Process Execution Language Version 2.0. Committee Specification, 31 January 2007"},{"key":"14_CR10","unstructured":"Schwarz, J, Bret Hartman B., Nadalin A, Kaler C., F. Hirsch, and Morrison S, , Security Challenges, Threats and Countermeasures Version 1.0, WS-I, May, 2005, http:\/\/www.ws-i.org\/Profiles\/BasicSecurity\/SecurityChallenges-1.0.pdf"},{"key":"14_CR11","unstructured":"Barbir, A. Gudgin M and McIntosh M., , Basic Security Profile Version 1.0, WS-I, May 2005, http:\/\/www.ws-i.org\/Profiles\/BasicSecurityProfile-1.0-2004-05-12.html"},{"key":"14_CR12","unstructured":"Nadalin, A., Kaler C., Hallam-Naker, P., Monzillo R., Web Services Security: SOAP Message Security 1.0, (WS-Security 2004), OASIS, March 2004, http:\/\/docs.oasis-open.org\/wss\/2004\/01\/oasis-200401-wss-soap-message-security-1.0.pdf"},{"key":"14_CR13","unstructured":"Web Services Security: SOAP Message Security 1.1, (WS-Security 2004), OASIS, February 2006, http:\/\/www.oasis-open.org\/committees\/download.php \/16790\/wss-v1.1-spec-os-SOAPMessageSecurity.pdf"},{"key":"14_CR14","unstructured":"Nadalin, A., Kaler C., Hallam-Naker, P., Monzillo R.,, Web Services Security: UsernameToken Profile 1.1,OASIS, February 2006, http:\/\/www.oasis-open.org\/committees\/download.php\/16782\/wss-v1.1-spec-os-Username TokenProfile.pdf"},{"key":"14_CR15","unstructured":"Nadalin, A., Kaler C., Hallam-Naker, P., Monzillo R., Web Services Security: X.509 Certificate Token Profile 1.1, OASIS, February 2006, http:\/\/www.oasis-open. org\/committees\/download. php\/16785\/wss-v1.1-spec-os-x509TokenProfile.pdf"},{"key":"14_CR16","unstructured":"Monzillo R., Kaler C., Nadalin A., Hallam-Naker, P.,., Web Services Security: SAML Token Profile 1.1, OASIS, February 2006, http:\/\/www.oasis-open. org\/committees\/download.php\/16768\/wss-v1.1-spec-os-SAMLTokenProfile.pdf"},{"key":"14_CR17","unstructured":"Nadalin, A., Kaler C., Hallam-Naker, P., Monzillo R.,, Web Services Security: Kerberos Token Profile 1.1, OASIS, February 2006, http:\/\/www.oasis-open.org\/committees\/download.php\/16788\/wss-v1.1-spec-os-KerberosTokenProfile.pdf"},{"key":"14_CR18","unstructured":"Monzillo R., Kaler C., Nadalin A., Hallam-Naker, P., Web Services Security: Rights Expression Language (REL) Token Profile 1.1, OASIS, February 2006, http:\/\/www.oasis-open.org\/committees\/download.php\/16687\/oasis-wss-rel-token-profile-1.1.pdf"},{"key":"14_CR19","unstructured":"Hirsch, F., Web Services Security: SOAP Messages with Attachments (SwA) Profile 1.1, OASIS, February 2006, http:\/\/www.oasis-open.org\/committees\/download.php\/16672\/wss-v1.1-spec-os-SwAProfile.pdf"},{"key":"14_CR20","unstructured":"Signature Syntax and Processing, W3C Recommendation February 2002, http:\/\/www.w3.org\/TR\/xmldsig-core\/"},{"key":"14_CR21","unstructured":"XML Encryption Syntax and Processing, W3C Recommendation December 2002, http:\/\/www.w3.org\/TR\/xmlenc-core\/"},{"key":"14_CR22","unstructured":"Nortel Unified Security Framework for corporate and government security, Nortel, http:\/\/www.nortel.com\/solutions\/security\/collateral\/nn104120-051705.pdf"},{"key":"14_CR23","unstructured":"SOAP Version 1.2 Part 1: Messaging Framework, W3C, June 2003, http:\/\/www.w3.org\/TR\/soap12-part1\/"},{"key":"14_CR24","unstructured":"Simple Object Access Protocol (SOAP) 1.1, W3C Note, May 2000, http:\/\/www.w3.org\/TR\/2000\/NOTE-SOAP-20000508\/"},{"key":"14_CR25","doi-asserted-by":"crossref","unstructured":"Rescorla E., HTTP Over TLS, RFC 2818, May 2000.","DOI":"10.17487\/rfc2818"},{"key":"14_CR26","unstructured":"Web Services Description Language (WSDL) 1.1, W3C Note 15 March 2001, http:\/\/www.w3.org\/TR\/wsdl"},{"key":"14_CR27","unstructured":"Bloomberg, J., Schmelzer, R, Service Orient or Be Doomed!: How Service Orientation Will Change Your Business, SBN: 0-471-79224-1, Wiley, May 2006."},{"key":"14_CR28","doi-asserted-by":"crossref","unstructured":"Boyer, J., Exclusive XML Canonicalization Version 1.0, W3C, July 2002, http:\/\/www.w3.org\/TR\/xml-exc-c14n\/","DOI":"10.17487\/rfc3076"},{"key":"14_CR29","unstructured":"Bray, T., Extensible Markup Language (XML) 1.0 (Third Edition), W3C, February 2004, http:\/\/www.w3.org\/TR\/REC-xml\/"},{"key":"14_CR30","unstructured":"The Transport Layer Security (TLS) Protocol,Version 1.1, RFC 4346, April 2006."},{"key":"14_CR31","doi-asserted-by":"crossref","unstructured":"Demchenko, Y.,, Web Services and Grid Security Vulnerabilities and Threats Analysis and Model, Grid Computing Workshop, 2005.","DOI":"10.1109\/GRID.2005.1542751"},{"key":"14_CR32","doi-asserted-by":"crossref","unstructured":"Nakamura, Y., Model-Driven Security Based on a Web Services Security Architecture, Proceedings of the 2005 IEEE International Conference on Services Computing (SCC\u201905), 2005.","DOI":"10.1109\/SCC.2005.66"},{"key":"14_CR33","doi-asserted-by":"crossref","unstructured":"Tarhini et al., Regression Testing Web Services-based Applications, Computer Systems and Applications, March 8, Page(s):163 - 170, 2006.","DOI":"10.1109\/AICCSA.2006.205085"},{"key":"14_CR34","unstructured":"Benharref A. et al, A Web Service Based-Architecture for Detecting Faults in Web Services, IFIP\/IEEE International Symposium on Integrated Network Management 2005."},{"key":"14_CR35","doi-asserted-by":"crossref","unstructured":"Bhoj, P. , Management of new Federated Services, Integrated Network Management V., 1997.","DOI":"10.1007\/978-0-387-35180-3_25"},{"key":"14_CR36","doi-asserted-by":"crossref","unstructured":"Weiping He, Recovery in Web Service Applications, Proceedings of the 2004 IEEE International Conference on e-Technology, e-Commerce and e-Service (EEE\u201904), 2004.","DOI":"10.1109\/EEE.2004.1287284"},{"key":"14_CR37","doi-asserted-by":"crossref","unstructured":"Papazoglou, M. and Heuvel, W., Web Services Management: A Survey, IEEE Internet Computing, November 2005.","DOI":"10.1109\/MIC.2005.137"},{"key":"14_CR38","unstructured":"Bertolino A. and Polini A., The Audition Framework for Testing Web Services Interoperability, Proceedings of the 2005 31st EUROMICRO Conference on Software Engineering and Advanced Applications (EUROMICRO-SEAA\u201905), 2005. 30. Karjoth, G., Service-oriented Assurance: Comprehensive Security by Explicit Assurances, Publications of the Network Security and Cryptography Group, 2005."},{"key":"14_CR39","doi-asserted-by":"crossref","unstructured":"Tsai, W., Ray Paul R., Weiwei S. and Cao Z.,, Coyote: An XML-Based Framework for Web Services Testing, 7th IEEE International Symposium on High Assurance Systems Engineering (HASE\u201902), 2002.","DOI":"10.1109\/HASE.2002.1173120"},{"key":"14_CR40","unstructured":"Yuan Rao, Y., Feng, O, Han, J., and Li, Z.,, SX-RSRPM: A Security Integrated Model For Web Services, Proceedings of the Third International Conference on Machine Learning and Cybernetics, Shanghai, 26-29 August 2004."},{"key":"14_CR41","doi-asserted-by":"crossref","unstructured":"Bruno, M., Gerardo, C., and Di Penta, M., Using Test Cases as Contract to Ensure Service Compliance across Releases, Proc. 3rd Int\u2019l Conf. Service Oriented Computing (ICSOC 2005), LNCS 3826, Springer, 2005, pp. 87-100.","DOI":"10.1007\/11596141_8"},{"key":"14_CR42","doi-asserted-by":"crossref","unstructured":"Tsai, W., Paul, R, Cao, Z., L. Yu, L., A. Saimi, A. and B. Xiao, B., . Verification of Web Services using an enhanced UDDI server. In Proc. of WORDS 2003, pages 131-138, Jan., 15-17 2003. Guadalajara, Mexico.","DOI":"10.1109\/WORDS.2003.1218075"},{"issue":"10","key":"14_CR43","first-page":"2130","volume":"E86-D","author":"W. Tsai","year":"2003","unstructured":"Tsai, W., Paul R., Wei S. and Cao Z. Scenario-based Web Service testing with distributed agents. IEICE Transaction on Information and System, E86-D(10):2130-2144, 2003.","journal-title":"IEICE Transaction on Information and System"},{"key":"14_CR44","unstructured":"Xu, W., Offutt, J., Juan Luo, J., Testing Web Services by XML Perturbation, Proceedings of the 16th IEEE International Symposium on Software Reliability Engineering (ISSRE\u201905), 2005."},{"key":"14_CR45","doi-asserted-by":"crossref","unstructured":"Yu, W., Supthaweesuk, P., and Aravind, D. Trustworthy Web Services Based on Testing, Proceedings of the 2005 IEEE International Workshop on Service-Oriented System Engineering (SOSE\u201905), 2005.","DOI":"10.1109\/SOSE.2005.38"},{"key":"14_CR46","unstructured":"Mei H. and Zhang L., A Framework for Testing Web Services and Its Supporting Tool, Proceedings of the 2005 IEEE International Workshop on Service-Oriented System Engineering (SOSE\u201905), 2005."},{"key":"14_CR47","doi-asserted-by":"crossref","unstructured":"Canfora G. and Di Penta M., Testing Services and Service-Centric Systems: Challenges and Opportunities, IT Pro Published by the IEEE Computer Society, April 2006.","DOI":"10.1109\/MITP.2006.51"},{"key":"14_CR48","unstructured":"Zapthink, www.zapthink.org"},{"key":"14_CR49","unstructured":"Fox A. and D. Patterson D., When does fast recovery trump high reliability? In 2nd Workshop on Evaluating and Architecting Systems for Dependability (EASY), 2002."},{"key":"14_CR50","unstructured":"Candea G. and A. Fox A., Crash-only software. In 9th Workshop on Hot Topics in Operating Systems, 2003."},{"key":"14_CR51","unstructured":"Candea G. Et, Microreboot-a technique for cheap recovery. In Proceedings of the 6th Symposium on Operating Systems Design and Implementation, 2004."},{"key":"14_CR52","unstructured":"Gray J., Why do computers stop and what can be done about it? In 5th Symposium on Reliability in Distributed Systems, 1986."},{"key":"14_CR53","unstructured":"OASIS SOA Reference Model TC. Reference model for service-oriented architecture 1.0. Technical report, OASIS, 2006."},{"key":"14_CR54","unstructured":"Fielding, R., Architectural Styles and the Design of Network-based Software Architectures. Ph.D. Dissertation. University Of California, Irvine, 2000."},{"key":"14_CR55","doi-asserted-by":"crossref","unstructured":"K. Vaidyanathan, K. et al., Analysis and implementation of software rejuvenation in cluster systems. In SIGMETRICS \u201901: Proceedings of the 2001 ACM SIGMETRICS international conference on Measurement and modeling of computer systems, pages 62-71, New York, NY, USA, 2001. ACM Press.","DOI":"10.1145\/378420.378434"},{"key":"14_CR56","unstructured":"OASIS (www.oasis-open.org) Web Services Reliable Exchange Technical Committe (WS-SX). 49. W3C (www.w3.org ) WS-Policy WG."},{"key":"14_CR57","unstructured":"IBM; The Enterprise Privacy Authorization Language (EPAL 1.1) - Reader\u2019s Guide to the Documentation."},{"key":"14_CR58","unstructured":"OASIS eXtensible Access Control Markup Language 2 (XACML) Version 2.0 OASIS Standard, 1 Feb 2005."},{"key":"14_CR59","doi-asserted-by":"crossref","unstructured":"T. Yu, M. Winslett, K. Seamons. Supporting Structured Credentials and Sensitive Policies through Interoperable Strategies for Automated Trust Negotiation. ACM Transactions on Information and System Security, Vol. 6, No. 1, February 2003.","DOI":"10.1145\/605434.605435"},{"key":"14_CR60","unstructured":"OASIS (www.oasis-open.org) WS-BPEL TC."},{"key":"14_CR61","doi-asserted-by":"crossref","unstructured":"Mecella, M., Ouzzani, M., Paci, F., Bertino, E. Access Control Enforcement for Conversation-based Web Services. Proceedings of the 2006 WWW Conference, Edinburgh, Scotland, May 23-26, 2006.","DOI":"10.1145\/1135777.1135818"},{"key":"14_CR62","unstructured":"Bertino, E., Crampton J.,, and Paci F. Access Control and Authorization Constraints for WS-BPEL. Submitted for publication."},{"issue":"2","key":"14_CR63","doi-asserted-by":"crossref","first-page":"37","DOI":"10.4018\/jwsr.2004040103","volume":"1","author":"E. Bertino","year":"2004","unstructured":"Bertino, E., B. Carminat, and E. Ferrari, E. Merkle Tree Authentication in UDDI Registries. International Journal of Web Service Research, 1(2): 37-57 (2004).","journal-title":"International Journal of Web Service Research"},{"key":"14_CR64","unstructured":"Liberty Alliance Project - Introduction to the Liberty Alliance Identity Architecture Revision 1.0 March, 2003"}],"container-title":["Test and Analysis of Web Services"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-540-72912-9_14.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,20]],"date-time":"2025-01-20T23:32:12Z","timestamp":1737415932000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-540-72912-9_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9783540729112"],"references-count":64,"URL":"https:\/\/doi.org\/10.1007\/978-3-540-72912-9_14","relation":{},"subject":[]}}