• DocumentCode
    2089809
  • Title

    Automatic XACML Requests Generation for Policy Testing

  • Author

    Bertolino, Antonia ; Daoudagh, Said ; Lonetti, Francesca ; Marchetti, Eda

  • Author_Institution
    Ist. di Scienza e Tecnol. dell´´Inf. A. Faedo, Consiglio Naz. delle Ric., Pisa, Italy
  • fYear
    2012
  • fDate
    17-21 April 2012
  • Firstpage
    842
  • Lastpage
    849
  • Abstract
    Access control policies are usually specified by the XACML language. However, policy definition could be an error prone process, because of the many constraints and rules that have to be specified. In order to increase the confidence on defined XACML policies, an accurate testing activity could be a valid solution. The typical policy testing is performed by deriving specific test cases, i.e. XACML requests, that are executed by means of a PDP implementation, so to evidence possible security lacks or problems. Thus the fault detection effectiveness of derived test suite is a fundamental property. To evaluate the performance of the applied test strategy and consequently of the test suite, a commonly adopted methodology is using mutation testing. In this paper, we propose two different methodologies for deriving XACML requests, that are defined independently from the policy under test. The proposals exploit the values of the XACML policy for better customizing the generated requests and providing a more effective test suite. The proposed methodologies have been compared in terms of their fault detection effectiveness by the application of mutation testing on a set of real policies.
  • Keywords
    XML; authorisation; program testing; PDP implementation; XACML language; access control policies; automatic XACML requests generation; error prone process; fault detection effectiveness; fundamental property; mutation testing; policy testing; test strategy; test suite; Access control; Boolean functions; Context; Fault detection; Proposals; Testing; XML;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Testing, Verification and Validation (ICST), 2012 IEEE Fifth International Conference on
  • Conference_Location
    Montreal, QC
  • Print_ISBN
    978-1-4577-1906-6
  • Type

    conf

  • DOI
    10.1109/ICST.2012.185
  • Filename
    6200197