12/5/2003 - Parasoft, a leading provider of Automated Error Prevention software solutions, announced that Parasoft SOAPtest offers businesses a solution for building security into their web services.
A recent Gartner report argues that web services security is immature and that complex, multi-party web services will require newer, more versatile security patterns for electronic transactions. Gartner warns that the key security specification, WS-Security, which protects the confidentiality of a message and is backed by the Organization for the Advancement of Structured Information Standards, will not provide a complete security solution for complex web services, where transactions cross organizational boundaries.(1)
"Leading analysts are telling companies to use vendor-provided technology to build security into their web services transactions while web services security standards are maturing," said Adam Kolawa, Parasoft Chairman/CEO. "Our web services product, SOAPtest, already includes the pattern recognition technology to serve as a security filter. SOAPtest can act as a proxy server, allowing companies to view and verify messages between a client and a web service."
With the SOAPtest RuleWizard feature, companies can establish and verify specific patterns contained in the SOAP message. As messages are sent from a client, SOAPtest will check for consistencies, and send the messages on to the appropriate service. If a message is inconsistent with the established pattern, a SOAP fault is returned to the client, thereby ensuring security across the service.
"Many security issues arise today because systems don’t know how to deal with unexpected inputs, which can cause the system to crash or to perform in an unexpected way," said Kolawa. "Since such a large number of clients may access the server, it will inevitably receive unexpected requests. Companies must verify web service security by confirming that unexpected inputs do not violate security safeguards, and SOAPtest can perform this testing automatically."
Parasoft SOAPtest is an Automated Error Prevention product for Web services and enterprise applications built with SOAP. SOAPtest automatically performs server functional testing, load testing, and client testing with just the click of a button. It automatically creates test suites from WSDL documents to test every operation associated with those documents. The same test suites used for functional testing can be used for load testing and monitoring, enabling users to verify whether traffic levels, patterns, or combinations cause functionality problems or decreased performance. SOAPtest verifies that clients send appropriate requests to services, and are able to handle responses as expected. In addition to one-click server functional testing, load testing, and client testing, SOAPtest also works as a proxy server, enabling users to view and verify messages between a client and a Web service. By using SOAPtest throughout the software lifecycle, users can prevent errors and improve the quality and reliability of their SOAP services.
SOAPtest 2.1 runs on Windows 2000/XP, Linux and Solaris. Pricing starts at: $3495. For more information, please go to http://www.parasoft.com/soaptest.
We make software work. – Parasoft provides Automated Error Prevention solutions that combine advanced products, services and expertise to help companies automatically prevent errors throughout the software lifecycle, to improve software quality and reliability. Based on Parasoft AEP Methodology, the company’s solutions and products automate practices such as coding standards, static analysis, unit testing, regression testing, load & stress testing, functional testing, integration testing, application testing and monitoring. The solutions enable software development and IT organizations to significantly reduce costs by shortening production cycles, improving overall quality and reducing time-to-market. Parasoft is has been granted nine patents and numerous awards for the technology behind its innovative line of solutions and products. Founded in 1987, Parasoft is a privately held company whose clients include IBM, HP, Daimler Chrysler and over 10,000 companies worldwide. Parasoft is headquartered in Monrovia, CA. Telephone (888) 305-0041. Fax (626) 305-3036. Email to email@example.com. URL: http://www.parasoft.com.
Parasoft and SOAPtest are registered trademarks of Parasoft.
(1) Kelly, Lisa. vnunet.com, “Ignore Standards for Web Services Security.” October 11, 2003.
Previous Page | News by Category | News Search
If you found this page useful, bookmark and share it on: