• DocumentCode
    3201869
  • Title

    Using Labeled Transition System Model in Software Access Control Politics Testing

  • Author

    Hong Yu ; Huang Song ; Hu Bin ; Yao Yi

  • Author_Institution
    Inst. of Command Autom., PLA Univ. of Sci. & Technol., Nanjing, China
  • fYear
    2012
  • fDate
    8-10 Dec. 2012
  • Firstpage
    680
  • Lastpage
    683
  • Abstract
    Access control model is widely used in access control politics testing, it usually consists of three hierarchy fields: roles, permissions and contexts. But the relations information between the three fields is not taken into consideration intact when building the access control models. Because of the information is leaking, engineers has to use random testing or pair wise testing when using access control model, they has to exchange test coverage for test efficiency. Some researchers extended the original access control model with rules, priority and status in order to complementary the missing information, but due to the structure disadvantage of original access control model, few works showed promising result. This paper presents a method using labeled transition system model in formalizing software access control politics though several examples, the method can formalize key information like rules, priority and status along with roles, permissions and contexts into model. This paper also briefly introduces how to use labeled transition system model in security test cases automatic generating.
  • Keywords
    authorisation; automatic test pattern generation; program testing; access control model; automatic security test case generation; hierarchy fields; information leakage; labeled transition system model; pairwise testing; random testing; software access control politics testing; test coverage; test efficiency; Access control; Computational modeling; Data models; Information security; Software; Testing; access control politics; labeled transition system model; model based testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Instrumentation, Measurement, Computer, Communication and Control (IMCCC), 2012 Second International Conference on
  • Conference_Location
    Harbin
  • Print_ISBN
    978-1-4673-5034-1
  • Type

    conf

  • DOI
    10.1109/IMCCC.2012.165
  • Filename
    6429000