DocumentCode
2726101
Title
Roles-based Access Control Modeling and Testing for Web Applications
Author
Bo Song ; Shengbo Chen
Author_Institution
Coll. of Inf. Sci. & Technol., Qingdao Univ. of Sci. & Technol., Qingdao, China
fYear
2012
fDate
6-8 Nov. 2012
Firstpage
57
Lastpage
62
Abstract
Web applications are widely used in people´s everyday life. They have permeated financial sectors, banking sectors, e-business and online shopping. Usually, different users have different permissions on these applications. Additionally, role-based access control (RBAC) mechanisms have been wildly integrated into web applications. The security and correctness of web applications are the most fundamental, crucial aspects to the success of business and organizations. In existing research work on modeling of RBAC, the user´s roles and permissions are fixed and static, and do not consider that with the evolution and running of the system, the roles and permissions are dynamic. To the best of our knowledge, research work on role-based access control modeling and testing for web application has been seldom done. In this paper, taking the dynamic feature of roles and permissions into account, we propose an approach to modeling and testing web applications with role-based access control. We give out an algorithm to capture and compute the dynamicity of roles and permissions in running time. The FSM is employed to model the behavior of web applications, and then the augmented FSM (AFSM) is plied as a tool to model role-based access control. Finally, using the construction algorithm, the tests are generated automatically which satisfy the corresponding test coverage criteria.
Keywords
Internet; authorisation; finite state machines; program testing; AFSM; RBAC mechanisms; Web application correctness; Web application security; augmented FSM; banking sectors; dynamic features; e-business; financial sectors; online shopping; role-based access control mechanisms; roles-based access control modeling; roles-based access control testing; user permissions; user roles; Access control; Computational modeling; Gold; Heuristic algorithms; Silver; Testing; Web pages; FSM; RBAC; Software testing; access control; tests generation; web applications;
fLanguage
English
Publisher
ieee
Conference_Titel
Software Engineering (WCSE), 2012 Third World Congress on
Conference_Location
Wuhan
Print_ISBN
978-1-4673-4546-0
Type
conf
DOI
10.1109/WCSE.2012.19
Filename
6394924
Link To Document