DocumentCode :
2089809
Title :
Automatic XACML Requests Generation for Policy Testing
Author :
Bertolino, Antonia ; Daoudagh, Said ; Lonetti, Francesca ; Marchetti, Eda
Author_Institution :
Ist. di Scienza e Tecnol. dell´´Inf. A. Faedo, Consiglio Naz. delle Ric., Pisa, Italy
fYear :
2012
fDate :
17-21 April 2012
Firstpage :
842
Lastpage :
849
Abstract :
Access control policies are usually specified by the XACML language. However, policy definition could be an error prone process, because of the many constraints and rules that have to be specified. In order to increase the confidence on defined XACML policies, an accurate testing activity could be a valid solution. The typical policy testing is performed by deriving specific test cases, i.e. XACML requests, that are executed by means of a PDP implementation, so to evidence possible security lacks or problems. Thus the fault detection effectiveness of derived test suite is a fundamental property. To evaluate the performance of the applied test strategy and consequently of the test suite, a commonly adopted methodology is using mutation testing. In this paper, we propose two different methodologies for deriving XACML requests, that are defined independently from the policy under test. The proposals exploit the values of the XACML policy for better customizing the generated requests and providing a more effective test suite. The proposed methodologies have been compared in terms of their fault detection effectiveness by the application of mutation testing on a set of real policies.
Keywords :
XML; authorisation; program testing; PDP implementation; XACML language; access control policies; automatic XACML requests generation; error prone process; fault detection effectiveness; fundamental property; mutation testing; policy testing; test strategy; test suite; Access control; Boolean functions; Context; Fault detection; Proposals; Testing; XML;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Testing, Verification and Validation (ICST), 2012 IEEE Fifth International Conference on
Conference_Location :
Montreal, QC
Print_ISBN :
978-1-4577-1906-6
Type :
conf
DOI :
10.1109/ICST.2012.185
Filename :
6200197
Link To Document :
بازگشت