那是相当的复杂,建议看一些文章:
http://www.microsoft.com/china/technet/security/guidance/secmod83.mspx
http://www.microsoft.com/china/msdn/library/webservices/asp.net/securitybarriers.mspx?mfr=true
http://www.microsoft.com/china/msdn/library/architecture/architecture/architecturetopic/ImpWebSec/iwassecmod92.mspx?mfr=true