Title
Testing access control policies against intended access rights.
Abstract
Access Control Policies are used to specify who can access which resource under which conditions, and ensuring their correctness is vital to prevent security breaches. As access control policies can be complex and error-prone, we propose an original framework that supports the validation of the implemented policies (specified in the standard XACML notation) against the intended rights, which can be informally expressed, e.g. in tabular form. The framework relies on well-known software testing technology, such as mutation and combinatorial techniques. The paper presents the implemented environment and an application example.
Year
DOI
Venue
2016
10.1145/2851613.2851829
SAC 2016: Symposium on Applied Computing Pisa Italy April, 2016
Field
DocType
ISBN
Computer access control,Notation,Computer security,Computer science,Correctness,Role-based access control,XACML,Access control,Software testing
Conference
978-1-4503-3739-7
Citations 
PageRank 
References 
1
0.35
14
Authors
4
Name
Order
Citations
PageRank
Antonia Bertolino11961140.25
Said Daoudagh29911.31
Francesca Lonetti327929.13
Eda Marchetti439241.68