{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T17:59:18Z","timestamp":1775757558455,"version":"3.50.1"},"reference-count":36,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2017,11,27]],"date-time":"2017-11-27T00:00:00Z","timestamp":1511740800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["SOCA"],"published-print":{"date-parts":[[2018,6]]},"DOI":"10.1007\/s11761-017-0221-1","type":"journal-article","created":{"date-parts":[[2017,11,27]],"date-time":"2017-11-27T08:16:49Z","timestamp":1511770609000},"page":"111-121","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":19,"title":["Adaptive security architecture for protecting RESTful web services in enterprise computing environment"],"prefix":"10.1007","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4284-1919","authenticated-orcid":false,"given":"Mohamed Ibrahim","family":"Beer","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9912-6890","authenticated-orcid":false,"given":"Mohd Fadzil","family":"Hassan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,11,27]]},"reference":[{"key":"221_CR1","doi-asserted-by":"crossref","first-page":"218","DOI":"10.1016\/j.ins.2014.04.054","volume":"280","author":"Z Sheng","year":"2014","unstructured":"Sheng Z, Xiaoqiang Q, Athanasios V, Claudia S, Scott B, Xiaofei X (2014) Web services composition: a decade\u2019s overview. Inf Sci 280:218\u2013238","journal-title":"Inf Sci"},{"key":"221_CR2","doi-asserted-by":"crossref","first-page":"649","DOI":"10.1007\/s12652-015-0308-5","volume":"7","author":"F AlShahwan","year":"2016","unstructured":"AlShahwan F, Maha F, Godwin A (2016) Security framework for RESTful mobile cloud computing web services. J Ambient Intell Humaniz Comput 7:649\u2013659","journal-title":"J Ambient Intell Humaniz Comput"},{"issue":"4","key":"221_CR3","doi-asserted-by":"crossref","first-page":"767","DOI":"10.1007\/s11280-014-0278-0","volume":"18","author":"C Sepulveda","year":"2015","unstructured":"Sepulveda C, Rosa A, Jesus B (2015) QoS aware descriptions for RESTful service composition: security domain. World Wide Web 18(4):767\u2013794","journal-title":"World Wide Web"},{"key":"221_CR4","unstructured":"Fielding R (2000) Architectural styles and the design of network-based software architectures. Ph.D. Dissertation, University of California, Irvine"},{"key":"221_CR5","unstructured":"Xu B, Tianbo L, Xiaoqin W, Lingling Z, Xiaoyan Z, Wanjiang H (2013) A synthetic solution scheme for SOA security assurance. In: Proceedings of the international conference on security and management (SAM), computer engineering and applied computing (WorldComp)"},{"key":"221_CR6","doi-asserted-by":"crossref","unstructured":"Liu L, Wang D, Zhao J, Huang M (2013) SA4WSs: a security architecture for web services. In: Mustofa K, Neuhold EJ, Tjoa AM, Weippl E, You I (eds) Information and communication technology. Springer, Berlin, pp 306\u2013311","DOI":"10.1007\/978-3-642-36818-9_32"},{"key":"221_CR7","unstructured":"Masood A (2013) Cyber security for service oriented architectures in a Web 2.0 world: an overview of SOA vulnerabilities in financial services. In: IEEE international conference on technologies for homeland security (HST), pp 1\u20136"},{"key":"221_CR8","unstructured":"Jacqui C, Marijke C (2010) Towards an information security framework for service-oriented architecture. In: IEEE information security conference. South Africa, pp 1\u20138"},{"key":"221_CR9","unstructured":"Kou H (2010) A study on the security mechanism for web services. In: Proceedings of the world congress on engineering and computer science, vol I, USA"},{"issue":"4","key":"221_CR10","doi-asserted-by":"crossref","first-page":"279","DOI":"10.1108\/IJWIS-03-2013-0006","volume":"9","author":"Youcef Baghdadi","year":"2013","unstructured":"Baghdadi Youcef (2013) A comparison framework for service-oriented software engineering approaches: issues and solutions. Int J Web Inf Syst 9(4):279\u2013316","journal-title":"Int J Web Inf Syst"},{"key":"221_CR11","unstructured":"OWASP (2013) Top 10 web application vulnerabilities. Report on the ten most critical web application security risks"},{"issue":"1","key":"221_CR12","doi-asserted-by":"crossref","first-page":"112","DOI":"10.1016\/j.autcon.2006.03.004","volume":"16","author":"Shengwei Wang","year":"2007","unstructured":"Wang Shengwei, Zhengyuan Xu, Cao Jiannong, Zhang Jianping (2007) A middleware for web service-enabled integration and interoperation of intelligent building systems. Autom Constr 16(1):112\u2013121","journal-title":"Autom Constr"},{"key":"221_CR13","unstructured":"Kim SK, Han S-Y (2006) Performance comparison of DCOM, CORBA and web service. In: Parallel and distributed processing techniques and applications conference, pp 106\u2013112"},{"issue":"5","key":"221_CR14","doi-asserted-by":"crossref","first-page":"28","DOI":"10.1145\/1142031.1142044","volume":"4","author":"Michi Henning","year":"2006","unstructured":"Henning Michi (2006) The rise and fall of CORBA. ACM Queue 4(5):28\u201334","journal-title":"ACM Queue"},{"key":"221_CR15","unstructured":"Jones D (2015) Cost of cyber crime study: United States. Hewlett Packard Enterprise. http:\/\/www.ponemon.org\/blog\/2015-cost-of-cyber-crime-united-states . Accessed 1 Mar 2017"},{"key":"221_CR16","unstructured":"Symantec (2016) Internet security threat report, vol 21. https:\/\/www.symantec.com\/security-center\/threat-report Accessed 1 Mar 2017"},{"key":"221_CR17","unstructured":"WhiteHat Security (2016) Web applications security statistics report. https:\/\/www.whitehatsec.com\/info\/website-stats-report-2016-wp . Accessed 1 Mar 2017"},{"key":"221_CR18","unstructured":"National Vulnerability Database (2016) Vulnerability metrics, National Institute of Standards and Technology, USA. https:\/\/nvd.nist.gov . Accessed 1 Mar 2017"},{"key":"221_CR19","unstructured":"McAfee Labs (2016) Threats report. https:\/\/www.mcafee.com\/au\/resources\/reports\/rp-quarterly-threats-dec-2016.pdf . Accessed 1 Mar 2017"},{"key":"221_CR20","unstructured":"Hardt D (2012) The OAuth 2.0 authorization framework. RFC 6749 (Proposed Standard), http:\/\/tools.ietf.org\/html\/rfc6749 . Accessed 1 Mar 2017"},{"key":"221_CR21","doi-asserted-by":"crossref","unstructured":"Recordon D, Drummond R (2006) OpenID 2.0: a platform for user-centric identity management. In: Proceedings of the second ACM workshop on digital identity management. ACM, pp 11\u201316","DOI":"10.1145\/1179529.1179532"},{"key":"221_CR22","volume-title":"Secure RESTful interface profile security analysis and guidance","author":"M Russell","year":"2014","unstructured":"Russell M (2014) Secure RESTful interface profile security analysis and guidance. The MITRE Corporation, Bedford"},{"key":"221_CR23","unstructured":"Mladenov V, Christian M, Jorg S (2015) On the security of modern Single Sign-On Protocols: second-order vulnerabilities in OpenID connect. arXiv:1508.04324"},{"issue":"12\u20133","key":"221_CR24","first-page":"69","volume":"78","author":"B Ibrahim","year":"2016","unstructured":"Ibrahim B, Fadzil MH (2016) Construction of customizable SOA security framework using artificial neural networks. J Teknol 78(12\u20133):69\u201375","journal-title":"J Teknol"},{"key":"221_CR25","unstructured":"Gartner (2016) Top 10 strategic technology trends for 2016. http:\/\/www.itbusinessedge.com\/slideshows\/top-10-strategic-technology-trends-for-2016-08.html . Accessed 1 Mar 2017"},{"key":"221_CR26","unstructured":"Neha L, Jwalant B (2014) DDoS prevention on REST based web services. Int J Comput Sci Inf Technol 5(6):7314\u20137317"},{"key":"221_CR27","doi-asserted-by":"crossref","unstructured":"Lee H, Mayur R (2014) Defense against REST-based web service attacks for enterprise systems. Commun IIMA 13:57\u201368","DOI":"10.58729\/1941-6687.1207"},{"key":"221_CR28","unstructured":"Sungchul L, Ju-Yeon J, Yoohwan K (2015) Method for secure RESTful web service. In: 14th IEEE international conference on computer and information science (ICIS)"},{"key":"221_CR29","doi-asserted-by":"crossref","unstructured":"Orellana F, Marko N (2012) Distributed computing with RESTful web services. In: Seventh international conference on P2P, parallel, grid, cloud and internet computing (3PGCIC), pp 103\u2013110","DOI":"10.1109\/3PGCIC.2012.30"},{"key":"221_CR30","doi-asserted-by":"crossref","unstructured":"Serme G, Anderson S, Julien M, Yves R (2012) Enabling message security for RESTful services. In: IEEE 19th international conference on web services (ICWS), pp 114\u2013121","DOI":"10.1109\/ICWS.2012.94"},{"key":"221_CR31","first-page":"32","volume-title":"Techniques for securing REST","author":"A Sudhakar","year":"2011","unstructured":"Sudhakar A (2011) Techniques for securing REST. CA Technology Exchange, New York, p 32"},{"key":"221_CR32","first-page":"43","volume-title":"Securing RESTful services with token-based authentication","author":"R Malisetti","year":"2011","unstructured":"Malisetti R (2011) Securing RESTful services with token-based authentication. CA Technology Exchange, New York, pp 43\u201348"},{"key":"221_CR33","doi-asserted-by":"crossref","unstructured":"Adamczyk P, Patrick S, Ralph J, Munawar H (2011) REST and web services: in theory and in practice. In: Wilde E, Pautasso C (eds) REST: from research to practice. Springer, New York, pp 35\u201357","DOI":"10.1007\/978-1-4419-8303-9_2"},{"key":"221_CR34","doi-asserted-by":"crossref","unstructured":"Brachmann E, Gero D, Klaus S (2012) Simplified authentication and authorization for RESTful services in trusted environments. In: European conference on service-oriented and cloud computing. Springer, Berlin, pp 244\u2013258","DOI":"10.1007\/978-3-642-33427-6_21"},{"key":"221_CR35","doi-asserted-by":"crossref","unstructured":"Pan G, Yongbin W (2012) Securing RESTful WCF services with XAuth and service authorization manager\u2014a practical way for user authorization and server protection. In: Fifth IEEE international joint conference on computational sciences and optimization (CSO), pp 651\u2013653","DOI":"10.1109\/CSO.2012.149"},{"key":"221_CR36","unstructured":"Pai S, Yash S, Sunil K, Radhika P, Sanjay S (2011) Formal verification of OAuth 2.0 using alloy framework. In: IEEE international conference on communication systems and network technologies (CSNT), pp 655\u2013659"}],"container-title":["Service Oriented Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11761-017-0221-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11761-017-0221-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11761-017-0221-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,29]],"date-time":"2023-08-29T06:53:59Z","timestamp":1693292039000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11761-017-0221-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,11,27]]},"references-count":36,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2018,6]]}},"alternative-id":["221"],"URL":"https:\/\/doi.org\/10.1007\/s11761-017-0221-1","relation":{},"ISSN":["1863-2386","1863-2394"],"issn-type":[{"value":"1863-2386","type":"print"},{"value":"1863-2394","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,11,27]]}}}