DocumentCode :
909701
Title :
Scalable and Effective Test Generation for Role-Based Access Control Systems
Author :
Masood, A. ; Bhatti, Rafae ; Ghafoor, Arif ; Mathur, Aditya
Author_Institution :
Dept. of Avionics Eng., Air Univ., Islamabad, Pakistan
Volume :
35
Issue :
5
fYear :
2009
Firstpage :
654
Lastpage :
668
Abstract :
Conformance testing procedures for generating tests from the finite state model representation of Role-Based Access Control (RBAC) policies are proposed and evaluated. A test suite generated using one of these procedures has excellent fault detection ability but is astronomically large. Two approaches to reduce the size of the generated test suite were investigated. One is based on a set of six heuristics and the other directly generates a test suite from the finite state model using random selection of paths in the policy model. Empirical studies revealed that the second approach to test suite generation, combined with one or more heuristics, is most effective in the detection of both first-order mutation and malicious faults and generates a significantly smaller test suite than the one generated directly from the finite state models.
Keywords :
authorisation; fault tolerance; finite state machines; conformance testing; finite state model; first-order mutant; for role-based access control system; malicious fault detection; Role-Based Access Control (RBAC); fault model; finite state models; first-order mutants; malicious faults.;
fLanguage :
English
Journal_Title :
Software Engineering, IEEE Transactions on
Publisher :
ieee
ISSN :
0098-5589
Type :
jour
DOI :
10.1109/TSE.2009.35
Filename :
4967616
Link To Document :
بازگشت