Visible to the public Testing Access Control Policies Against Intended Access Rights

TitleTesting Access Control Policies Against Intended Access Rights
Publication TypeConference Paper
Year of Publication2016
AuthorsBertolino, Antonia, Daoudagh, Said, Lonetti, Francesca, Marchetti, Eda
Conference NameProceedings of the 31st Annual ACM Symposium on Applied Computing
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-3739-7
Keywordsaccess control rights, Human Behavior, pubcrawl, Resiliency, Scalability, Security Policies Analysis, Software Testing, XACML language
Abstract

Access Control Policies are used to specify who can access which resource under which conditions, and ensuring their correctness is vital to prevent security breaches. As access control policies can be complex and error-prone, we propose an original framework that supports the validation of the implemented policies (specified in the standard XACML notation) against the intended rights, which can be informally expressed, e.g. in tabular form. The framework relies on well-known software testing technology, such as mutation and combinatorial techniques. The paper presents the implemented environment and an application example.

URLhttp://doi.acm.org/10.1145/2851613.2851829
DOI10.1145/2851613.2851829
Citation Keybertolino_testing_2016