Proceedings of the 13th International Workshop on Automation of Software Test 2018
DOI: 10.1145/3194733.3194743
|View full text |Cite
|
Sign up to set email alerts
|

An automated model-based test oracle for access control systems

Abstract: In the context of XACML-based access control systems, an intensive testing activity is among the most adopted means to assure that sensible information or resources are correctly accessed. Unfortunately, it requires a huge effort for manual inspection of results: thus automated verdict derivation is a key aspect for improving the cost-effectiveness of testing. To this purpose, we introduce XACMET, a novel approach for automated model-based oracle definition. XACMET defines a typed graph, called the XAC-Graph, … Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
4
0

Year Published

2020
2020
2022
2022

Publication Types

Select...
4
2

Relationship

1
5

Authors

Journals

citations
Cited by 8 publications
(4 citation statements)
references
References 18 publications
0
4
0
Order By: Relevance
“…Several approaches [54,55,2,3,4,56,5,57,58,59,60,61] generate access control test cases from AC policy specifications to detect AC defects in the implementations; policy specifications are defined using XACML [54,2,3,59] or declarative access control rules [4,57]. In general, these approaches are model-based and generate test models or abstract test cases that cover various (combinations of) AC rules embedded in policy specifications.…”
Section: Detection Of Ac Defects and Vulnerabilitiesmentioning
confidence: 99%
See 1 more Smart Citation
“…Several approaches [54,55,2,3,4,56,5,57,58,59,60,61] generate access control test cases from AC policy specifications to detect AC defects in the implementations; policy specifications are defined using XACML [54,2,3,59] or declarative access control rules [4,57]. In general, these approaches are model-based and generate test models or abstract test cases that cover various (combinations of) AC rules embedded in policy specifications.…”
Section: Detection Of Ac Defects and Vulnerabilitiesmentioning
confidence: 99%
“…In general, these approaches are model-based and generate test models or abstract test cases that cover various (combinations of) AC rules embedded in policy specifications. The scope of these approaches also vary: generating executable test cases (e.g., [57], prioritizing test case execution based on a given test budget constraints (e.g., [54]), localizing faults (e.g., [58]), generating test oracles (e.g., [60,61]); other approaches [62,59] focus on proposing coverage criteria, such as AC rule coverage, rule pair coverage, and modified condition/decision coverage, to measure and ensure the quality of (AC) test suites. Daoudagh et al [6] conducted a systematic literature review on 20 studies that focus on testing of the usage and access control systems inside DevOps processes.…”
Section: Detection Of Ac Defects and Vulnerabilitiesmentioning
confidence: 99%
“…Wang et al [10] realized data storage and sharing without the participation of providers, using Ethereum and an attributebased access control method. Furthermore, many other researchers have studied the access control strategy described by XACML about Policies formalization [11], Automatic Testing [12], Model testing [13], policy tracing [14], automated fault localization [15].…”
Section: Literature Reviewmentioning
confidence: 99%
“…According to the results collected in Daoudagh et al, 12 there are not specific research methods or techniques applicable during the development of access control systems. Usually, the available proposals include either methodologies for requirement specification and collection in order to improve policies specification (such as previous studies [13][14][15][16] ) or techniques for improving the policies enforcement (such as previous studies [17][18][19][20] ), but they do not provide specific approaches.…”
Section: Access Control Mechanisms and Policiesmentioning
confidence: 99%