Title
An automated model-based test oracle for access control systems.
Abstract
In the context of XACML-based access control systems, an intensive testing activity is among the most adopted means to assure that sensible information or resources are correctly accessed. Unfortunately, it requires a huge effort for manual inspection of results: thus automated verdict derivation is a key aspect for improving the cost-effectiveness of testing. To this purpose, we introduce XACMET, a novel approach for automated model-based oracle definition. XACMET defines a typed graph, called the XAC-Graph, that models the XACML policy evaluation. The expected verdict of a specific request execution can thus be automatically derived by executing the corresponding path in such graph. Our validation of the XACMET prototype implementation confirms the effectiveness of the proposed approach.
Year
DOI
Venue
2018
10.1145/3194733.3194743
AST@ICSE
Keywords
DocType
Volume
XACML, Testing, Oracle derivation
Journal
abs/1809.02724
ISSN
ISBN
Citations 
Proceedings of the 13th International Workshop on Automation of Software Test, pp. 2-8. ACM, 2018
978-1-4503-5743-2
3
PageRank 
References 
Authors
0.38
18
4
Name
Order
Citations
PageRank
Antonia Bertolino11961140.25
Said Daoudagh29911.31
Francesca Lonetti327929.13
Eda Marchetti439241.68