Visible to the public Biblio

Filters: Author is Bertolino, Antonia  [Clear All Filters]
2019-06-28
Miranda, Breno, Cruciani, Emilio, Verdecchia, Roberto, Bertolino, Antonia.  2018.  FAST Approaches to Scalable Similarity-Based Test Case Prioritization. Proceedings of the 40th International Conference on Software Engineering. :222-232.

Many test case prioritization criteria have been proposed for speeding up fault detection. Among them, similarity-based approaches give priority to the test cases that are the most dissimilar from those already selected. However, the proposed criteria do not scale up to handle the many thousands or even some millions test suite sizes of modern industrial systems and simple heuristics are used instead. We introduce the FAST family of test case prioritization techniques that radically changes this landscape by borrowing algorithms commonly exploited in the big data domain to find similar items. FAST techniques provide scalable similarity-based test case prioritization in both white-box and black-box fashion. The results from experimentation on real world C and Java subjects show that the fastest members of the family outperform other black-box approaches in efficiency with no significant impact on effectiveness, and also outperform white-box approaches, including greedy ones, if preparation time is not counted. A simulation study of scalability shows that one FAST technique can prioritize a million test cases in less than 20 minutes.

2017-09-26
Bertolino, Antonia, Daoudagh, Said, Lonetti, Francesca, Marchetti, Eda.  2016.  Testing Access Control Policies Against Intended Access Rights. Proceedings of the 31st Annual ACM Symposium on Applied Computing. :1641–1647.

Access Control Policies are used to specify who can access which resource under which conditions, and ensuring their correctness is vital to prevent security breaches. As access control policies can be complex and error-prone, we propose an original framework that supports the validation of the implemented policies (specified in the standard XACML notation) against the intended rights, which can be informally expressed, e.g. in tabular form. The framework relies on well-known software testing technology, such as mutation and combinatorial techniques. The paper presents the implemented environment and an application example.