Web service threats in e-government environment

Krasznay Csaba <>
HP Magyarország Kft.

In 2009 and 2010 many software and system developments will be realized in Hungary from domestic and EU founds which help the evolution of e-government. Technological direction points to service oriented architecture (SOA). This solution includes some new, yet unexamined information security threats which are underestimated in governmental recommendations but detailed analysis is needed for secure application development.

In my presentation I introduce the current and future, publicly available architecture of Hungarian central e-government systems, development trends and situation of web service in this environment. I review those standards and recommendations that deal with these solutions and limit the possibilities of developers. I focus to the Hungarian electronic government framework which will be under professional discussion in the time of my presentation so scientific analysis will be current.

Furthermore I present those known typical attack vectors which target specifically the service oriented architecture and those common countermeasures which can prevent these attacks. Based on actual trends it is set out that sophisticated information attacks don?t happen on network or operations system level but on application level, especially on web application level. Service oriented architecture gives an opportunity for complex solutions so a qualified attacker has good chance for undetected and unauthorized access to the system. Software architects and developers have a big chance for a mistake because of the complex system so the can facilitate the attack. As many systems as many countermeasures but common solutions can be defined to minimize errors.