or
Sign in to turn on 1-Click ordering.
 
 
Express Checkout with PayPhrase
What's this? | Create PayPhrase
More Buying Choices
42 used & new from $10.91

Have one to sell? Sell yours here
 
   
Web Services Security
 
See larger image
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get your Kindle here.
 
  

Web Services Security (Paperback)

~ Mark O'Neill (Author)
4.4 out of 5 stars  See all reviews (8 customer reviews)

List Price: $49.99
Price: $33.66 & this item ships for FREE with Super Saver Shipping. Details
You Save: $16.33 (33%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Want it delivered Tuesday, November 24? Choose One-Day Shipping at checkout. Details
23 new from $13.02 19 used from $10.91

Frequently Bought Together

Web Services Security + Securing Web Services with WS-Security: Demystifying WS-Security, WS-Policy, SAML, XML Signature, and XML Encryption + Core Security Patterns: Best Practices and Strategies for J2EE(TM), Web Services, and Identity Management
Price For All Three: $111.96

Show availability and shipping details


Customers Who Bought This Item Also Bought

Securing Web Services with WS-Security: Demystifying WS-Security, WS-Policy, SAML, XML Signature, and XML Encryption

Securing Web Services with WS-Security: Demystifying WS-Security, WS-Policy, SAML, XML Signature, and XML Encryption

by Jonathan B. Rosenberg
3.6 out of 5 stars (13)  $34.21
Core Security Patterns: Best Practices and Strategies for J2EE(TM), Web Services, and Identity Management

Core Security Patterns: Best Practices and Strategies for J2EE(TM), Web Services, and Identity Management

by Ramesh Nagappan
4.7 out of 5 stars (31)  $44.09
Restful Web Services

Restful Web Services

by Sam Ruby
4.4 out of 5 stars (41)  $26.39
SOA Security

SOA Security

by Prasad Chodavarapu
3.8 out of 5 stars (12)  $40.24
Web Service Security: Scenarios, Patterns, and Implementation Guidance for Web Services Enhancements (WSE) 3.0 (Patterns & Practices)

Web Service Security: Scenarios, Patterns, and Implementation Guidance for Web Services Enhancements (WSE) 3.0 (Patterns & Practices)

by Microsoft Corporation
5.0 out of 5 stars (1)  $34.99
Explore similar items

Editorial Reviews

Product Description

Explains how to implement secure Web services and includes coverage of trust, confidentiality, cryptography, authentication, authorization, and Kerberos. You'll also find details on Security Assertion Markup Language (SAML), XML Key Management Specification (XKMS), XML Encryption, Hypertext Transfer Protocol-Reliability (HTTP-R) and more.


From the Back Cover

Your definitive Web Services security resource

Minimize security risks in your system by successfully rolling out secure Web Services with help from this exceptional guide. Web Services Security covers everything network security professionals need to know, including details on Web Services architecture, SOAP, UDDI, WSDL, XML Signature, XML Encryption, SAML, XACML, XKMS, and more. You'll also get implementation techniques as well as case studies featuring global service-provision initiatives such as the Liberty Alliance Project. Practical, comprehensive, and up-to-date, this is a must-have reference for every administrator interested in conquering real-life security challenges through the effective use of Web Services.

  • Learn the high-level principles of security and how they apply to Web Services
  • Deploy Web Services technology following practical and clear examples
  • Use XKMS for validation and accountability
  • Ensure data integrity by using XML Signature and XML Encryption with SOAP
  • Use SAML and XACML for authentication and authorization
  • Learn the major components of the evolving ebXML standard
  • Gain valuable insight into the legal aspects of Web Services security--including digital signature laws, privacy issues, and application-to-application transactions

Product Details

  • Paperback: 312 pages
  • Publisher: McGraw-Hill Osborne Media; 1 edition (January 31, 2003)
  • Language: English
  • ISBN-10: 0072224711
  • ISBN-13: 978-0072224719
  • Product Dimensions: 9 x 7.3 x 0.9 inches
  • Shipping Weight: 1.4 pounds (View shipping rates and policies)
  • Average Customer Review: 4.4 out of 5 stars  See all reviews (8 customer reviews)
  • Amazon.com Sales Rank: #654,606 in Books (See Bestsellers in Books)


Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
 

Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

8 Reviews
5 star:
 (4)
4 star:
 (3)
3 star:
 (1)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.4 out of 5 stars (8 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
13 of 14 people found the following review helpful:
4.0 out of 5 stars Solid intro to Web Services and its security requirements, February 15, 2003
Before reading "Web Services Security" (WSS), my knowledge of Web Services relied on a few magazine articles and chapter 10 of "Hacking Exposed: Web Applications." After reading WSS, I have a better idea of how Web Services work and how a variety of acronyms (XACML, XKMS, SAML, etc.) provide security. This 312 page book isn't lengthy enough to make you a Web Services security expert, but it provides a good foundation for consultants and other professionals.

Good security books do more than teach ways to attack and defend various technologies. They assume the reader isn't an expert in the technology or concept, and provide background prior to explaining weapons and tactics to exploit vulnerabilities. WSS meets this challenge by educating readers on the purpose, history, and future of Web Services. The authors take nothing for granted, explaining why transport-level encryption via SSL is insufficient for Web Services. WSS emphasizes key security concepts like "persistence" and separating policy enforcement from decision-making. I also appreciated the authors' willingness to share key insights, like the argument that "like XKMS, XACML is more about applying XML to security, rather than about applying security to XML." (p. 120). This demonstrated knowledge of applying security to a wider range of subjects than just Web Services.

On the down side, I found the SAML section (ch. 6) confusing. The writing style implied another author contributed this material, and the chapter's "checklist" was a list of questions -- not the summaries found elsewhere. I didn't find the legal section (ch. 14) particularly clear, either, despite the hype it received on the back cover.

Overall, WSS is probably the best Web Services security guide currently available. It meets the market need for an introduction to the subject, and covers material neglected elsewhere, like the Liberty Alliance Project (ch. 11). Those with questions on Web Services security would do well to start looking for answers here!
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
15 of 17 people found the following review helpful:
3.0 out of 5 stars Good concepts coverage - But no example proof, March 8, 2003
With 2 book on our Web services library shelves, this book adds in as the best for getting introduction to Web services security specifications and popular implementations. If you are little lazy to read the specs from web sites, this book is an ideal choice to get an introduction to them. But again, this book is a bundle of content reproducing the specs of XML Security efforts at W3C, OASIS, WS-Security (IBM & Microsoft), Sun's Liberty, Microsoft Passport. Interestingly this book also contains some obsolete versions of Security specs (So be careful, before you assume things).

If your are an Architect seeking a practical implementation solution or a case study to practice in your architecture, this book DOES NOT add value at ALL. As I said, this book lacks practical implementation scenarios especially examples using real world security implementations like Passport, SunONE, EnTrust, Netegrity TransactionMinder etc. So think about it.

If you are newbie wants to get ideas about Web services security then this BOOK IS THE BEST at this time ! But always lookout for latest book so that you don't get buried with obsolete specifications.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
8 of 8 people found the following review helpful:
5.0 out of 5 stars The Best Book on Web Services Security, May 31, 2003
By Doug Kaye (Kentfield, CA USA) - See all my reviews
(REAL NAME)   
This is *the* book to date on the topic. I particularly like the blend of strategy and practice that Mark and the others have achieved. They've managed to get straight to the point: The best way to secure web services today is through XML Signature, XML Encryption, SAML, and WS-Security, and this book explains how those technologies work.

Unlike another reviewer, I found this book to be a far better way to learn than the specifications or the online white papers. True, it doesn't get into vendor-specific implementation details, but I expect the vendors to provide that info.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

4.0 out of 5 stars Points you in the right direction
Writing a book like this is always going to be a difficult task in an up and coming technology. This book handles it exceptionally well. Read more
Published on November 15, 2004 by M. Ashworth

5.0 out of 5 stars Especially for the novice website designer
A team effort, Web Services Security describes XML and Web Services security technologies, including SAML and the WS-Security roadmap, and provides practical examples in Java and... Read more
Published on July 19, 2003 by Midwest Book Review

4.0 out of 5 stars Very complete
This is a very complete reference in that it covers all the current standards that directly and indirectly impact web services security. Read more
Published on March 7, 2003 by mark_secrist

5.0 out of 5 stars Worth buying
Does a good job of covering a fast changing area, and features just about everything relevant to it's subject. Read more
Published on January 30, 2003

5.0 out of 5 stars Covers all the bases
This very readable book covers the Web services security area well, devoting chapters to all the usual suspects (XML Encryption, XKMS, WS-Security, SAML, et al). Read more
Published on January 26, 2003

Only search this product's reviews



Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 


Active discussions in related forums
Search Customer Discussions
Search all Amazon discussions
   



So You'd Like to...


Product Information from the Amapedia Community

Beta (What's this?)


Look for Similar Items by Category


Look for Similar Items by Subject

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Your Recent History

 (What's this?)

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.