Title :
Investigation of Access Control Models with Formal Concept Analysis: A Case Study
Author :
Gauthier, François ; Merlo, Ettore
Abstract :
Web applications manage increasingly large amounts of sensitive information and often need to implement access control (AC) models. However, documentation about the implemented AC model is often sparse and few, if no tool exists to support AC model investigation. Based on the results of a previous study, we show how formal concept analysis (FCA) can support the understanding and visualization of reverse-engineered AC models. Results of applying FCA to Moodle, a medium-sized (625 473 LOC) Web application, are presented and discussed. We show how FCA enhances the overall comprehension of reverse-engineered AC models and sheds light on previously unknown features of Moodle´s AC model.
Keywords :
Internet; authorisation; formal concept analysis; reverse engineering; Moodle AC model; Web applications; access control models; formal concept analysis; reverse-engineered AC models; Access control; Analytical models; Automata; Context; Documentation; Lattices; Mathematical model; access control models; formal concept analysis; reverse-engineering; web applications;
Conference_Titel :
Software Maintenance and Reengineering (CSMR), 2012 16th European Conference on
Conference_Location :
Szeged
Print_ISBN :
978-1-4673-0984-4
DOI :
10.1109/CSMR.2012.50