• DocumentCode
    1732067
  • Title

    Test-Driven Assessment of Access Control in Legacy Applications

  • Author

    Le Traon, Yves ; Mouelhi, Tejeddine ; Pretschner, Alexander ; Baudry, Benoit

  • Author_Institution
    IT-TELECOM Bretagne, Cesson-Sevigne
  • fYear
    2008
  • Firstpage
    238
  • Lastpage
    247
  • Abstract
    If access control policy decision points are not neatly separated from the business logic of a system, the evolution of a security policy likely leads to the necessity of changing the system´s code base. This is often the case with legacy systems. We present a test- driven methodology to assess the flexibility of a system, a property that describes the degree of coupling between the access control logic and the business logic of a system. A low flexibility indicates that a modification of the policy will lead to substantial changes of the code. In this paper, we analyze the notion of flexibility which is related to the presence of hidden and implicit security mechanisms in the business logic. We detail how testing can be used for detecting such mechanisms and how it may drive the incremental evolution of a security policy. We use several case studies to illustrate and validate the methodology.
  • Keywords
    authorisation; program testing; software maintenance; access control logic; business logic; legacy system; security policy; test-driven methodology; Access control; Application software; Automatic logic units; Data security; Databases; Logic testing; Permission; Software systems; Software testing; System testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Testing, Verification, and Validation, 2008 1st International Conference on
  • Conference_Location
    Lillehammer
  • Print_ISBN
    978-0-7695-3127-4
  • Type

    conf

  • DOI
    10.1109/ICST.2008.60
  • Filename
    4539551