• DocumentCode
    48262
  • Title

    Automated testing of eXtensible Access Control Markup Language-based access control systems

  • Author

    Bertolino, Antonia ; Daoudagh, Said ; Lonetti, Francesca ; Marchetti, Eda ; Schilders, Louis

  • Author_Institution
    Istituto di Scienza e Tecnologie dell´Informazione ´A. Faedo´, CNR via G. Moruzzi 1, 56124 Pisa, Italy
  • Volume
    7
  • Issue
    4
  • fYear
    2013
  • fDate
    Aug-13
  • Firstpage
    203
  • Lastpage
    212
  • Abstract
    The trustworthiness of sensitive data needs to be guaranteed and testing is a common activity among privacy protection solutions, even if quite expensive. Accesses to data and resources are ruled by the policy decision point (PDP), which relies on the eXtensible Access Control Markup Language (XACML) standard language for specifying access rights. In this study, the authors propose a testing strategy for automatically deriving test requests from a XACML policy and describe their pilot experience in test automation using this strategy. Considering a real two-level PDP implemented for health data security, the authors compare the effectiveness of the test plan automatically derived with the one derived by a standard manual testing process.
  • fLanguage
    English
  • Journal_Title
    Software, IET
  • Publisher
    iet
  • ISSN
    1751-8806
  • Type

    jour

  • DOI
    10.1049/iet-sen.2012.0101
  • Filename
    6562943