RE: [LC76c] Security Considerations proposal

+1
Sounds good and wiggle-room-esque.

Tom Jordahl
Macromedia Server Development 

-----Original Message-----
From: www-ws-desc-request@w3.org [mailto:www-ws-desc-request@w3.org] On
Behalf Of Jonathan Marsh
Sent: Wednesday, July 13, 2005 10:23 AM
To: www-ws-desc@w3.org
Subject: [LC76c] Security Considerations proposal


Per our AI re LC76c, Amy and I propose to:

Add a new Adjuncts section 2.4 as follows:

2.4 Security Considerations

Note that many of the message exchange patterns defined above describe
responses to an initial message (either a normal response message or a
fault.) 

Such responses may be used in attempts to disrupt, attack, or map a
network, host, or services.  When such responses are directed to an
address other than that originating the initial message, the source of
an attack may be obscured, or blame laid on a third party, or may
enable or exacerbate denial-of-service attacks.

Security mechanisms addressing such attacks may prevent the delivery of
response messages to the receiving node.  Conformance to the MEP is
measured absent these security mechanisms.

Received on Monday, 18 July 2005 00:50:30 UTC