2014
Conference article  Restricted

An automated testing framework of model-driven tools for XACML policy specification

Bertolino A., Daoudagh S., Lonetti F., Marchetti E.

Access control  Model-driven development  Testing 

Access Control is among the most important security mechanisms to put in place in order to secure applications. XACML is the de facto standard for storing and deploying access control policies. However, due to the complexity of the XACML language, policy definition becomes a difficult and error prone process. In recent years, the combined use of models for the access control policy specification, and the model-to-code facilities, for the automatic transformation of the model into the XACML language, has been proposed as a possible solution. These model-driven methodologies and facilities need to be thoroughly validated and verified. In this paper we provide an integrated framework for testing the automatic translation of the specification of an access control model into an XACML policy. The framework includes different test strategies for the derivation of test cases and some facilities for making easier their execution against the XACML policy and the test results collection and analysis. In addition, we illustrate the use of the framework on a case study.

Source: QUATIC 2014 - 9th International Conference on the Quality of Information and Communications Technology, pp. 75–84, Guimarães, Portugal, 23-26 September 2014


Metrics



Back to previous page
BibTeX entry
@inproceedings{oai:it.cnr:prodotti:310467,
	title = {An automated testing framework of model-driven tools for XACML policy specification},
	author = {Bertolino A. and Daoudagh S. and Lonetti F. and Marchetti E.},
	doi = {10.1109/quatic.2014.17},
	booktitle = {QUATIC 2014 - 9th International Conference on the Quality of Information and Communications Technology, pp. 75–84, Guimarães, Portugal, 23-26 September 2014},
	year = {2014}
}

NESSOS
Network of Excellence on Engineering Secure Future Internet Software Services and Systems


OpenAIRE