Title
Automated testing of eXtensible Access Control Markup Language-based access control systems
Abstract
The trustworthiness of sensitive data needs to be guaranteed and testing is a common activity among privacy protection solutions, even if quite expensive. Accesses to data and resources are ruled by the policy decision point (PDP), which relies on the eXtensible Access Control Markup Language (XACML) standard language for specifying access rights. In this study, the authors propose a testing strategy for automatically deriving test requests from a XACML policy and describe their pilot experience in test automation using this strategy. Considering a real two-level PDP implemented for health data security, the authors compare the effectiveness of the test plan automatically derived with the one derived by a standard manual testing process.
Year
DOI
Venue
2013
10.1049/iet-sen.2012.0101
Software, IET
Field
DocType
Volume
Data security,Test plan,XML,Computer science,Manual testing,XACML,Access control,Test strategy,Database,Markup language
Journal
7
Issue
ISSN
Citations 
4
1751-8806
17
PageRank 
References 
Authors
0.85
16
4
Name
Order
Citations
PageRank
Antonia Bertolino11961140.25
Said Daoudagh29911.31
Francesca Lonetti327929.13
Enrico Marchetti4252.19