XML Security

XML carries sensitive data in banking messages, healthcare records, government documents, and legal contracts. Securing XML means ensuring three things: the document is authentic (it comes from who it claims), confidential (only authorized parties can read it), and intact (it was not tampered with).

Three Core XML Security Standards

1. XML Signature (XMLDSig)

An XML Signature proves that an XML document was signed by a specific party and has not been modified since signing. It is the XML equivalent of a handwritten signature or a tamper-evident seal.

<Signature xmlns="http://www.w3.org/2000/09/xmldsig#">
  <SignedInfo>
    <CanonicalizationMethod Algorithm="..."/>
    <SignatureMethod Algorithm="...rsa-sha256"/>
    <Reference URI="#order-001">
      <DigestMethod Algorithm="...sha-256"/>
      <DigestValue>c3RhbmRhcmQ=</DigestValue>
    </Reference>
  </SignedInfo>
  <SignatureValue>
    dGhpcyBpcyB0aGUgc2lnbmF0dXJl...
  </SignatureValue>
  <KeyInfo>
    <!-- Public key or certificate information -->
  </KeyInfo>
</Signature>

2. XML Encryption (XML Enc)

XML Encryption encrypts part or all of an XML document. Only the holder of the decryption key can read the protected content. Unlike SSL which encrypts the whole HTTP connection, XML Encryption encrypts specific elements — so one part of a message can be encrypted while other parts remain readable.

<EncryptedData xmlns="http://www.w3.org/2001/04/xmlenc#"
               Type="http://www.w3.org/2001/04/xmlenc#Element">
  <EncryptionMethod Algorithm="...aes256-cbc"/>
  <CipherData>
    <CipherValue>
      a3J5cHRvZ3JhcGhpY2RhdGFoZXJl...
    </CipherValue>
  </CipherData>
</EncryptedData>

3. WS-Security (for SOAP)

WS-Security extends SOAP with security features in the SOAP Header. It includes authentication tokens, digital signatures, and encryption for web service messages.

<soap:Header>
  <wsse:Security xmlns:wsse="http://docs.oasis-open.org/wss/...">
    <wsse:UsernameToken>
      <wsse:Username>serviceUser</wsse:Username>
      <wsse:Password>hashedPassword</wsse:Password>
    </wsse:UsernameToken>
  </wsse:Security>
</soap:Header>

Common XML Security Threats

ThreatDescriptionProtection
XML InjectionAttacker injects malicious XML tags into user inputValidate and escape all user input before embedding in XML
XXE (XML External Entity)Attacker uses external entity references to read server filesDisable external entity processing in the parser
Billion Laughs AttackNested entity expansion causes memory exhaustion (DoS)Limit entity expansion depth; use secure parser settings
XML Signature WrappingAttacker moves signed elements to bypass verificationValidate signature over the exact element, not by position
EavesdroppingXML messages read in transitUse HTTPS + XML Encryption for end-to-end protection

Disabling XXE in Parsers

Java

DocumentBuilderFactory factory = DocumentBuilderFactory.newInstance();
factory.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
factory.setFeature("http://xml.org/sax/features/external-general-entities", false);
factory.setFeature("http://xml.org/sax/features/external-parameter-entities", false);

Python (lxml)

from lxml import etree
parser = etree.XMLParser(resolve_entities=False, no_network=True)
tree = etree.parse("input.xml", parser)

Key Points to Remember

  • XML Signature proves authenticity and integrity — the document was not changed after signing.
  • XML Encryption protects specific parts of an XML document, not just the transport layer.
  • WS-Security adds authentication and signature support to SOAP messages.
  • XXE attacks exploit external entity references — always disable them in production parsers.
  • The Billion Laughs attack exploits deeply nested entity references — limit entity expansion.
  • Use HTTPS for transport security AND XML Encryption for message-level security in sensitive systems.

Leave a Comment

Your email address will not be published. Required fields are marked *