Web services have emerged as a new Web-based
technology paradigm for exchanging information on the
Internet using platform-neutral standards, such as XML
and adopting Internet-based protocols. They offer
greater accessibility of data, dynamic establishment of
inter-service relationships and communication paths,
inter-applications interactions and data interchange on
different platforms in different locations without or with
a minimal amount of direct human involvement, and a
high degree of service autonomy. Most, if not all, of
these features are in conflict with traditional security
models and controls and hence introduce new security
challenges that are different than traditional security
issues. This paper presents and classifies the new
security challenges introduced by Web services, and
summarizes the current existing techniques on dealing
with such challenges.