2010 · 40 citations · 15 references
EngineeringXacml RequestsTest Data GenerationSoftware EngineeringXacml LanguageSoftware AnalysisFormal VerificationXml SecurityAccess Control PoliciesXml LibraryComputer ScienceLanguage-based SecuritySoftware DesignSecurity Testing MethodSoftware SecurityProgram AnalysisSoftware TestingTesting PurposesFormal Methods
A widely adopted security mechanism is the specification of access control policies by means of the XACML language. In this paper, we propose a framework, called X-CREATE, for the systematic generation of test inputs (XACML requests). Differently from existing tools, XCREATE exploits the XACML Context Schema. In particular, the tool applies a XML-based methodology (XPT) to systematically produce a set of intermediate instances, covering the XACML Context Schema. Moreover, for request generation, X-CREATE applies a procedure for parsing the policy under test and assigning values to the generated intermediate instances. The aim of the proposed framework is twofold: testing of policy evaluation engines and testing of access control policies. The experimental results show that the fault detection effectiveness of X-CREATE is similar or higher than that of existing approaches.
15
Verification and change-impact analysis of access-control policies
Kathi Fisler, Shriram Krishnamurthi, Leo A. Meyerovich et al. · 2005 · 393 citations
A fault model and mutation testing of access control policies
Evan Martin, Tao Xie · 2007 · 151 citations