DocumentCode
48262
Title
Automated testing of eXtensible Access Control Markup Language-based access control systems
Author
Bertolino, Antonia ; Daoudagh, Said ; Lonetti, Francesca ; Marchetti, Eda ; Schilders, Louis
Author_Institution
Istituto di Scienza e Tecnologie dell´Informazione ´A. Faedo´, CNR via G. Moruzzi 1, 56124 Pisa, Italy
Volume
7
Issue
4
fYear
2013
fDate
Aug-13
Firstpage
203
Lastpage
212
Abstract
The trustworthiness of sensitive data needs to be guaranteed and testing is a common activity among privacy protection solutions, even if quite expensive. Accesses to data and resources are ruled by the policy decision point (PDP), which relies on the eXtensible Access Control Markup Language (XACML) standard language for specifying access rights. In this study, the authors propose a testing strategy for automatically deriving test requests from a XACML policy and describe their pilot experience in test automation using this strategy. Considering a real two-level PDP implemented for health data security, the authors compare the effectiveness of the test plan automatically derived with the one derived by a standard manual testing process.
fLanguage
English
Journal_Title
Software, IET
Publisher
iet
ISSN
1751-8806
Type
jour
DOI
10.1049/iet-sen.2012.0101
Filename
6562943
Link To Document