Injection attacks against web applications are still frequent, and organizations like OWASP places them within the Top Ten of security risks to web applications. The main goal of this work is to contribute to the community with the design of an effective protection of web applications against common injection attacks. Our proposal is a validation filter of input fields that is based on OWASP Stinger, a set of regular expressions, and a sanitization process. It validates both fundamental characters (letters, numbers, dot, dash, question marks, and exclamation point) and complex statements (JSON and XML files) for each field. The procedure of deploying the proposed filter is detailed, specifying the sections and contents of the configuration file. In addition, the infrastructure for running the tests is described, including the setting of an attack tool, and the implementation of a controller. The attack tool is used as a security scanner for common injection attacks, and the controller is developed for routing the requests in two steps; first a request is addressed to the filter, and if it is valid, it will redirect to the web application itself. The proposal filter has been tested on three public as well as on a real private web application. An accuracy of 98,4% and an average processing time of 50 ms are achieved, based on wich it is possible to conclude the proposed filter is highly reliable and does not require additional computational resources.
To detect security vulnerabilities in a web application, the security analyst must choose the best performance Security Analysis Static Tool (SAST) in terms of discovering the greatest number of security vulnerabilities as possible. To compare static analysis tools for web applications, an adapted benchmark to the vulnerability categories included in the known standard Open Web Application Security Project (OWASP) Top Ten project is required. The information of the security effectiveness of a commercial static analysis tool is not usually a publicly accessible research and the state of the art on static security tool analyzers shows that the different design and implementation of those tools has different effectiveness rates in terms of security performance. Given the significant cost of commercial tools, this paper studies the performance of seven static tools using a new methodology proposal and a new benchmark designed for vulnerability categories included in the known standard OWASP Top Ten project. Thus, the practitioners will have more precise information to select the best tool using a benchmark adapted to the last versions of OWASP Top Ten project. The results of this work have been obtaining using widely acceptable metrics to classify them according to three different degree of web application criticality.
Smart Cities of the future have a potential to serve as a holistic platform for generating values from the abundance of currently untapped human, societal and ICT capital. Currently, Smart Cities are ever-stronger facing numerous challenges and a stringent need to optimize their urban processes, infrastructure and facilities, such as urban transportation and energy management. Unfortunately, at the moment, small portion of urban data is being exploited for gaining better insights and optimizing Smart City processes. In this chapter, we introduce a novel Smart City platform being developed in the context of SMART-FI project. The SMART-FI platform aims to facilitate analyzing, deploying, managing and interoperating Smart City data analytics services. Firstly, SMART-FI strives to enable collecting the data from a variety of sources, such as sensors and public data sources. Secondly, the platform provides mechanisms for homogenizing the data coming from various networks and protocols. Finally, it provides facilities to develop, deploy and orchestrate novel, added-value Smart City data analytic services. To demonstrate the practical feasibility of the proposed solutions and showcase their benefits for the variety of involved stakeholders, SMART-FI will be piloted in three cities: Malaga (Spain), Karlshamn (Sweden), and Malatya (Turkey).
Cloud Computing providers offer diverse services and capabilities, which can be used by end-users to compose heterogeneous contexts of multiple cloud platforms to deploy their applications, in accordance with the best offered capabilities. However, this is an ideal scenario, since cloud platforms are being conducted in an isolated way by presenting interoperability and portability restrictions. Each provider defines its own API, non-functional requirements, QoS, add-ons, etc., and developers are often locked-in a concrete cloud environment, hampering the integration of heterogeneous provider services to achieve cross-deployment. This work presents an approach to deploy cross-cloud applications by using standardisation efforts of design, management and deployment of cloud applications. Specifically, using mechanisms specified by the TOSCA and CAMP standards, we propose a methodology to describe the topology and distribution of modules of a cloud application and to deploy the inter-connected modules over heterogeneous clouds. We present our prototype TOMAT, which supports the automatic distribution of cloud applications over multiple providers.
The diversity in the way different cloud providers offer their services, give their SLAs, present their QoS, support different technologies, etc., complicates the portability and interoperability of cloud applications, and favors vendor lockin. Standards like TOSCA, and tools supporting them, have come to help in the provider-independent description of cloud applications. After the variety of proposed cross-cloud application management tools, we propose going one step further in the unification of cloud services with a deployment tool in which IaaS and PaaS services are integrated into a unified interface. We provide support for applications whose components are to be deployed on different providers, indistinctly using IaaS and PaaS services. The TOSCA standard is used to define a portable model describing the topology of the cloud applications and the required resources in an agnostic, and providers- and resources-independent way. We include in this paper some highlights on our implementation on Apache Brooklyn and present a non-trivial example that illustrates our approach.
We present the open reference architecture of the SeaClouds solution. It aims at enabling a seamless adaptive multi-cloud management of complex applications by supporting the distribution, monitoring and reconfiguration of app modules over heterogeneous cloud providers.
How to deploy and manage, in an efficient and adaptive way, complex applications across multiple heterogeneous cloud platforms is one of the problems that have emerged with the cloud revolution. In this paper we present context, motivations and objectives of the EU research project SeaClouds, which aims at enabling a seamless adaptive multi-cloud management of complex applications by supporting the distribution, monitoring and migration of application modules over multiple heterogeneous cloud platforms. After positioning SeaClouds with respect to related cloud initiatives, we present the SeaClouds architecture and discuss some of its aspect, such as the use of the OASIS standard TOSCA and the compatibility with the OASIS CAMP initiative.
Cloud Computing platforms offer diverse services and capabilities with own features. Hence, the provider services could be used by end users to compose a heterogeneous context of multiple cloud platforms in order to deploy their cloud applications made up of a set of modules, according to the best capabilities of the cloud providers. However, this is an ideal scenario, since the cloud platforms are being conducted in an isolated way by presenting many interoperability and portability restrictions, which complicate the integration of diverse provider services to achieve an heterogeneous deployment of multi-cloud applications. In this ongoing work, we present an approach based on model transformation to deploy multi-cloud applications by reusing standardization efforts related to the management and deployment of cloud applications. Specifically, using mechanisms specified by both standards, TOSCA and CAMP, we propose a methodology to describe the topology and distribution of modules of a cloud application and to deploy the interconnected modules over heterogeneous clouds. We illustrate our idea using a running example.
The Future Internet has emerged as a new initiative to pave a novel infrastructure linked to objects (things) of the real world to meet the changing global needs of business and society. It offers internet users a standardized, secure, efficient and trustable environment, which allows open and distributed access to global networks, services and information. There is a need for both researchers and practitioners to develop platforms made up of adaptive Future Internet applications. In this sense, the emergence and consolidation of Service-Oriented Architectures (SOA), Cloud Computing and Wireless Sensor Networks (WSN) give benefits, such as flexibility, scalability, security, interoperability, and adaptability, for building these applications.
Building service-based applications requires providing the ability to handle, maintain or upgrade the services that compose these applications. As same services may be used by a wide variability of applications, the management of the heterogeneity at runtime is required. This is crucial to reconfigure applications in case of service failures. The DAMASCo framework reduces the complexity of modeling services focusing on the discovery, composition and adaptation of context-aware services. But currently, it does not support the dynamic reconfiguration of service-based applications. In this work, we follow a Dynamic Software Product Line approach to extend DAMASCo for providing reconfiguration to support specific situations of fails at runtime. We propose a novel approach of grouping services in families facilitating the selection and usage of similar services in case of fails. We apply our approach to an intelligent transportation system case study where DAMASCo composes and reconfigure the necessary services to provide a dynamic route for a driver's request.
SeaClouds is a European FP7 research project, whose goal is to develop a novel open solution to provide developers with the capabilities to design, configure, deploy, and manage complex applications across multiple heterogeneous clouds in an efficient and adaptive way. 1 General data of the project Name Seamless adaptive multi-cloud management of service-based applications
The adaptive management of complex applications deployed across multiple heterogeneous PaaS platforms is one of the problems that have emerged with the cloud revolution. The ongoing EU research project SeaClouds aims at providing seamless adaptive multi-cloud management of complex applications by supporting the distribution, monitoring and migration of application modules over multiple heterogeneous PaaS platforms. In this paper we present context, motivations and objectives of SeaClouds, its relation with other cloud initiatives, and its initial architecture.
A common feature of ambient intelligence is that many objects are inter-connected and act in unison, which is also a challenge in the Internet of Things. There has been a shift in research towards integrating both concepts, considering the Internet of Things as representing the future of computing and communications. However, the efficient combination and management of heterogeneous things or devices in the ambient intelligence domain is still a tedious task, and it presents crucial challenges. Therefore, to appropriately manage the inter-connection of diverse devices in these systems requires: (1) specifying and efficiently implementing the devices (e.g., as services); (2) handling and verifying their heterogeneity and composition; and (3) standardizing and managing their data, so as to tackle large numbers of systems together, avoiding standalone applications on local servers. To overcome these challenges, this paper proposes a platform to manage the integration and behavior-aware orchestration of heterogeneous devices as services, stored and accessed via the cloud, with the following contributions: (i) we describe a lightweight model to specify the behavior of devices, to determine the order of the sequence of exchanged messages during the composition of devices; (ii) we define a common architecture using a service-oriented standard environment, to integrate heterogeneous devices by means of their interfaces, via a gateway, and to orchestrate them according to their behavior; (iii) we design a framework based on cloud computing technology, connecting the gateway in charge of acquiring the data from the devices with a cloud platform, to remotely access and monitor the data at run-time and react to emergency situations; and (iv) we implement and generate a novel cloud-based IoT platform of behavior-aware devices as services for ambient intelligence systems, validating the whole approach in real scenarios related to a specific ambient assisted living application.
The adaptive management of complex applications deployed across multiple heterogeneous PaaS platforms is one of the problems that have emerged with the cloud revolution. The recently started EU research project SeaClouds aims at providing seamless adaptive multi-cloud management of complex applications by supporting the distribution, monitoring and migration of application modules over multiple heterogeneous PaaS platforms. We present the context, motivations and objectives of SeaClouds, its relation with other cloud initiatives, and its initial architecture.
Cita: J. Carrasco, J. Cubo y E. Pimentel. Propuesta de metodologia de despliegue de aplicaciones en nubes heterogeneas con TOSCA. XIX Jornadas de Ingenieria del Software y Bases de Datos. pp. 321-334. Cadiz. 2014.
AbstractThe adaptive management of complex applications deployed across multiple heterogeneous PaaS platforms is one of the problems that have emerged with the cloud revolution. The recently started EU research project SeaClouds aims at providing seamless adaptive multi-cloud management of complex applications by supporting the distribution, monitoring and migration of application modules over multiple heterogeneous PaaS platforms. We present the context, motivations and objectives of SeaClouds, its relation with other cloud initiatives, and its initial architecture.
Future Internet and Service Mashups provide novel infrastructures linked to objects, services and things of the real world to meet the changing global needs of business and society. Thanks to them, integration of data and services worldwide distributed are more easily accessible, reachable and usable. The synergy existing among Adaptive Services for Future Internet and Web APIs and Service Mashups have provided us with the chance of celebrating these two workshops together and publishing these joined proceedings for those researches and developers interested on these supplementary fields. Future Internet has emerged as a new initiative to pave a novel infrastructure linked to objects and things of the real world to meet the changing global needs of business and society. Technologies such as those based on XML and RDF or OWL to describe data and semantic information, SOAP or REST to define protocols and BPEL or BPMN to orchestrate business processes are being increasingly used to specify Future Internet services in a standardized manner, which will allow software and data no longer to be stored and distributed on individual computers. Instead, multitenancy will enable their remote access as Software as a Service (SaaS), even by performing the integration into larger networks of communicating software (e.g., a mashup or a plug-in to a Cloud platform). Future Internet applications will have to support the interoperability between many diverse stakeholders by governing the convergence and life-cycle of Internet of Contents (IoC), Services (IoS), Things (IoT), and Networks (IoN). In this sense, there is a need for both researchers and practitioners to develop platforms made up of adaptive Future Internet applications. Hence, the emergence and consolidation of Service-Oriented Architectures (SOA), Cloud Computing and Wireless Sensor Networks (WSN) rise benefits, such as flexibility, scalability, security, interoperability, and adaptability, for building these applications.
The new Internet is evolving into the vision of the Internet of Things, where physical world entities are integrated into virtual world things. Things are expected to become active participants in business, information and social processes. Then, the Internet of Things could benefit from the Web Service architecture like today's Web does; so Future service-oriented Internet things will offer their functionality via service-enabled interfaces. As demonstrated in previous work, there is a need of considering the behaviour of things to develop applications in a more rigorous way. We proposed a lightweight model for representing such behaviour based on the service-oriented paradigm and extending the standard DPWS profile to specify the (partial) order with which things can receive messages. To check whether a mashup of things respects the behaviour, specified at design-time, of composed things, we proposed a static verification. However, at run-time a thing may change its behaviour or receive requests from instances of different mashups. Then, it is required to check and detect dynamically possible invalid invocations provoked by the behaviour's changes. In this work, we extend our static verification with an approach based on mediation techniques and complex event processing to detect and inhibit invalid invocations, checking that things only receive requests compatible with their behaviour. The solution automatically generates the required elements to perform run-time validation of invocations, and it may be extended to validate other issues. Here, we have also dealt with quality of service and temporal restrictions.
How to deploy and manage, in an efficient and adaptive way, complex applications over multiple heterogeneous PaaS platforms is one of the problems that have emerged with the cloud revolution. The recently started EU research project SeaClouds aims at enabling a seamless adaptive multi-cloud management of complex applications by supporting the distribution, monitoring and migration of application modules over multiple heterogeneous PaaS platforms. In this paper, after presenting context, motivations and objectives of the project, we position SeaClouds with respect to related cloud initiatives and discuss its initial
Emilio Pimentel合作论文数Dpto. de Lenguajes y Ciencias de la Computacion
University of Malaga38
Lidia Fuentes合作论文数Dpto. Lenguajes y Ciencias de la Computaci??n;ETSI Telecomunicaci??n;Universidad de M??laga4