Wattle Software - producers of XMLwriter XML editor
 Bookstore Home | XMLwriter Home | Search | Site Map 
XML Related
 General XML
 XSLT & Stylesheets
 XHTML
 SGML
 XML DTDs
 XML Schema
Web Development
 Web Graphics
 HTML
 Dynamic HTML
Web Services
 General Web Services
 UDDI
 SOAP
 WSDL
 Programming/Scripting 
 PHP Programming
 Perl Programming
 Active Server Pages
 Java Server Pages
 JavaScript
 VBScript
 .NET Programming
 
XMLwriter
 About XMLwriter
 Download XMLwriter
 Buy XMLwriter
XML Resources
 XML Links
 XML Training
 The XML Guide
 XML Book Samples
 

XML Security


By Blake Dournaee
 
Image of: XML Security
Pricing Details:

List Price:$59.99
You save:$12.96 (21.6%)
Your Price:$47.03
Buy Now

Book Details:

Format:Paperback, 379 pages.
Publisher:McGraw-Hill Osborne Media 2002-02-06
ISBN:0072193999

Average Customer Rating:

4.5 4.5 out of 5 stars (3 reviews)

Editorial Reviews:

Use this book as both an XML primer and to get up to speed on XML-related security issues. Written by the experts at RSA Security, Inc., you’ll get inside tips on how to prevent denial of service attacks, and how to implement security measures to keep your XML programs protected.

Get up to speed on XML and applied security technologies using this authoritative guide. Covering the fundamentals of XML structures and related security technologies--including XML signatures, XML encryption, and the XML key management specification--this resource contains both the conceptual information and the practical techniques you need to successfully work with this data-structuring language.


Customer Reviews:

4 out of 5 stars Application specific content

The above book is full of information with regards to XML Security and it's implementations. However, I found it to be VERY application oriented towards RSA's own Bsafe product Cert-J.

If you are interested in utilizing a C or C++ parser you should look for a different book. But, if you will be developing and/or utilizing XML via a Java-based program; this is definitly the book for you.

4 out of 5 stars Excellent book on XML security

When you read the XML specification, you will notice that it contains no notion of security. Critical security functionalities such as encryption, digital signatures, and authentication are simply not part of the XML standard. XML is similar to many other protocols, languages, and operating systems in that it was originally developed without any thought to security and privacy. It is only after serious security vulnerabilities are discovered and publicized that they are patched. But this find, patch, fix mentality of information security is dangerous in that security problems can exist for months or years before they are found.

Similarly within XML, much of the security functionality has been added post- facto, namely in Canonical XML, XML Signature, and XML Encryption Syntax and Processing. By adding security to the core feature set of XML, the W3C has ensured that,
to a degree, the find, patch, fix method won't be the manner in which XML security is developed. A good reference book can help you navigate this XML security landscape.

XML Security is a reader friendly title and focuses more on the implementation of XML. For readers looking for ways to use XML and less coding examples, XML Security is more useful book. The author, Blake Dournaee, is an employee of RSA Security, and the book is an RSA Press imprint. Furthermore, Chapter 8, the book's longest chapter, is about XML Signatures implementing the RSA BSAFE(c) Cert-J toolkit. Even with the RSA vendor bias, XML Security provides a good reference to the XML security functionality.

This book spends more time introducing the reader to security concepts, and Chapters 2 and 3 (Security Primer and XML Primer) provide the reader with a good overview about all of the significant concepts involved. Chapter 6 provides a plethora of XML signature examples. As XML signatures are rich in their features and syntax, combined with the vast number of elements and permutations of those elements, it can be quite difficult for someone to understand how to properly use XML signatures. Chapter 6 provides 14 different scenarios and their proposed solutions. These scenarios range from adding a single signature to a basic XML document, to adding multiple types of signatures to various documents. For readers who need good hands-on examples, Chapter 6 is worth the price of the book alone.

5 out of 5 stars Slight vendor bias - excellent info + W3C spec coverage

Given the fact that XML is a key component of web services, and extensively used in e-commerce and enterprise applications integration, this book addresses a genuinely important topic. For one reason, XML is text-based and can expose proprietary information, which is a vulnerability for competitive intelligence specialists and corporate spying.

Before going into what the book contains it's important to know that much of the material is based on RSA's view of the security. This isn't a criticism, but an up-front statement of fact because if you're looking for a book that is 100% vendor neutral you are going to have to wait until one is written - this is the only book I know of that is solely about XML security.

The book starts with primers on security and XML to set the context. It then covers, in succession, digital signatures (chapters 4, 5 and 6), and XML encryption. These chapters are consistent with work and specifications produced by XML Signature WG (joint the Working Group IETF and W3C for digital signatures) and the W3C working group for XML Encryption.

Chapter 8 is specific to RSA products. It shows how to implement XML encryption using RSA BSAFEŠ Cert-J, which can be downloaded in a trial version from RSA's website. Chapter 9 covers XML key management specification, which are consistent with the W3C working group's specifications, and how XML security relates to web services.

Despite the slight bias towards RSA this book is an invaluable reference. It provides an in-depth discussion of major security issues, as well as how they are being addressed by the W3C. It goes without saying that anyone who is responsible for system architecture, design and/or security should carefully read this book.


Customers who bought this book were also interested in:


Secure XML: The New Syntax for Signatures and Encryption


Web Services Security


Securing Web Services with WS-Security: Demystifying WS-Security, WS-Policy, SAML, XML Signature, and XML Encryption

 

Find similar books by category...


Search for more:

Search books:  



Google
 
Web XMLwriter.net




Last updated: Fri Jul 25 21:54:07 CDT 2008
© Wattle Software 2007. All rights reserved.