Storage News
Security News
Networking News 
FREE NEWSLETTERS
search
 

internet.commerce
Partner With Us














internet.com
IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers




Latest Headlines
Security News
Mozilla, Microsoft and VeriSign Tackle MD5 Flaw
MS-SQL Injection Flaw Exploit Code Surfaces
Coordinated Attacks Were Behind CheckFree Breach

Security

Anti-spam | Anti-virus | Biometrics | Encryption | Filtering/Monitoring | Firewalls | Identity | Intrusion Detection/Prevention | Privacy | Security Administration Tools | Tools
Submit Products *

SOAPSonar

Testing and Diagnosis of Web Services

The core offering from Crosscheck Networks, SOAPSonar is a .NET-based platform that provides the ability to test Web service-based applications in multiple ways; including functional/regression testing, performance testing, interoperability testing, and vulnerability testing. The vendor bills their product as providing "code-free" testing; relying primarily on published or stand-alone WSDL files and mutation technology for the loading of Web service definitions and generation of test suites.

WSDL files (and therefore the Web services that they describe) can be loaded into the application by providing the WSDL file's URL or by dragging/dropping a stand alone WSDL into the product's interface. The product automatically parses the WSDL to generate virtual clients that have the ability to interact with the target Web service. The vendor states that multiple WSDLs can be loaded and tests can be mix-and-matched across different WSDL operations. Furthermore, tests can be chained such that the output from one operation becomes the input for another. Secure access testing is supported via integrated PKI and support for WS-UserName Token, WS-X509 Token, WS-Kerberos Token, WS-Encryption, WS-Signatures, SAML Assertions, and SOAP with Attachments MIME & DIME.

Test cases can be defined and saved (for functional/regression testing) via drag-n-drop management. Test results can be reported in PDF, CSV, and MS Word formats.

For interoperability testing, the product supplies both design- and run-time analysis; running a set of WSI Basic Profile 1.1-based tests during the loading of the WSDL, and additionally applying "WSI Profile Mutation" techniques to generate WSDL tests that determine whether or not the Web service responds per WSI Profile specifications.

For performance testing, the vendor notes that a "Performance Mode" is available for the Enterprise version of the product within which up to 100 virtual clients can be setup per instance. Additional distributed test agents can also be purchased, each supporting an additional 100 virtual clients, with the vendor noting that there is no limit to the number of agents that can be managed by the product. Performance tests can be setup to execute for a set duration or a set number of iterations; and previously saved regression tests can additionally be used as performance tests.

Finally, for vulnerability testing, the product relies on the vendor's "XSD-Mutation technology," which generates mutated requests based on the original WSDL and launches automated attacks against the Web services. Responses to these mutated attacks are captured and automatically analyzed for potential vulnerabilities; with results and remediation techniques reported.

Some of the new features in the latest release of SOAPSonar include:

- WS-Policy consumption and policy generation

- SmartCard support

- Support for XSD Schema Validation for non-WSDL projects, and support for Schematron validation success criteria

- A WSDL scoring module that enables development teams to measure the quality of WSDL documents against one another or between development runs. The scoring methodology focuses on the WSDL schema, WSDL bindings, WSDL operations, WSDL messages, and WSDL services; with analysis based on adherence to published specifications, interoperability recommendations, and naming conventions. Results are displayed with scores from A to F across different segments of the WSDL, and teams can also define custom, organization specific rules on any aspect of the WSDL document with their own scores and weighting.

SOAPSonar is available now; in Personal and Enterprise flavors. The Personal Version can be downloaded for free from the vendor's Web site, as can a trial version of the Enterprise version. The Personal version does not include support for compliance, performance, or vulnerability testing. Base Enterprise version pricing starts at $799/per year/per instance; with add-on features (including the Automated Processing Component and the Performance Agent Module) available for additional fees.

Note that not all features described above are available in all versions. Visit the vendor's Web site for further information and version comparisons.

product submission by EITPlanet Staff

E-Mail this page to a colleague
send info about SOAPSonar

Suggest a link
for the SOAPSonar fact sheet

fact sheet
DPW id#: 1184252855
date posted: Sep. 4, 2008
category: Security:Security Administration Tools
platform: Windows 2000/XP/2003/Vista
vendor: Crosscheck Networks, Inc
(www.crosschecknet.com)
vendor's information:
Download SOAPSonar
about SOAPSonar
about Crosscheck Networks, Inc


Security

Anti-spam | Anti-virus | Biometrics | Encryption | Filtering/Monitoring | Firewalls | Identity | Intrusion Detection/Prevention | Privacy | Security Administration Tools | Tools
Submit Products *

Latest category updates via our RSS feed
RSS




Jupiter Online Media: internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and Jupiter Online Media

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Web Hosting | Newsletters | Tech Jobs | Shopping | E-mail Offers