DocumentCode :
176227
Title :
Supporting Maintenance and Evolution of Access Control Models in Web Applications
Author :
Gauthier, F. ; Merlo, E. ; Stroulia, E. ; Turner, D.
Author_Institution :
Polytech. Montreal, Montreal, QC, Canada
fYear :
2014
fDate :
Sept. 29 2014-Oct. 3 2014
Firstpage :
506
Lastpage :
510
Abstract :
This paper presents an approach to support the maintenance and evolution of Role-Based Access Control (RBAC) models with reverse-engineered Secure UML models. Starting from the Policy Decision Points (PDP) and Policy Enforcement Points (PEP) of an application, our approach statically reverse-engineers the implemented Secure UML model of an application. The secure UML model is then stored in an RDF triple store for easy querying and exploration. In the context of this study, we extracted the Secure UML model of the GRAND Forum, a web-based forum for the members of the GRAND (Graphics, Animation and New Media) NCE (Networks of Centers of Excellence), that is developed and maintained at the University of Alberta. Using three real use-case scenarios, we illustrate how simple queries to the extracted Secure UML can save developers significant amounts of manual work and support them in their access control related maintenance and evolution tasks.
Keywords :
Internet; Unified Modeling Language; authorisation; GRAND Forum; Graphics-Animation and New Media; NCE; Networks of Centers of Excellence; PDP; PEP; RBAC models; RDF triplestore; University of Alberta; Web applications; Web-based forum; evolution tasks; maintenance tasks; policy decision points; policy enforcement points; reverse-engineered SecureUML models; role-based access control models; Access control; Context; Context modeling; Maintenance engineering; Resource description framework; Unified modeling language; Evolution; Maintenance; RDF; Role-Based Access Control; SecureUML;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Maintenance and Evolution (ICSME), 2014 IEEE International Conference on
Conference_Location :
Victoria, BC
ISSN :
1063-6773
Type :
conf
DOI :
10.1109/ICSME.2014.83
Filename :
6976127
Link To Document :
بازگشت