Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Dive Carefully: Page 6 of 8

Fine print: This scenario does not take into account the possibility of regulatory compliance issues, nor does it consider expenses associated with the loss of reputation, legal fees or the multitude of additional costs related to attacks or unauthorized access to data via Web services.

Also, consider the costs associated with implementing a single-tier solution, one in which Web services platforms provide all the security for exposed services. Given the degradation in performance likely to occur due to the additional burden of encryption, signatures and policy enforcement, you'll need to provision at least two servers to provide the same level of performance as a single WS-Security gateway. Factoring in the additional cost of SSL certificates, application software and hardware proves that a WS-Security gateway will provide a measure of cost savings in addition to its security features.

Lori MacVittie is a Network Computing technology editor working in our Green Bay, Wis., labs. She has been a software developer, a network administrator and a member of the technical architecture team for a global transportation and logistics organization. Write to her at [email protected].

Post a comment or question on this story.

Web Services Security

Given the arcane attack types--including request canonicalization, structure/schema misvalidation, XML External Entities and signed integer comparison attacks--it's no wonder some business-line managers haven't a clue why you go ballistic about casually deployed Web services.