An automated testing framework of model-driven tools for XACML policy specification

被引:2
|
作者
Bertolino, Antonia [1 ]
Daoudagh, Said [1 ]
Lonetti, Francesca [1 ]
Marchetti, Eda [1 ]
机构
[1] Consiglio Nazl Ric CNR, Ist Sci & Tecnol Informaz A Faedo, I-56124 Pisa, Italy
关键词
access control; model-driven development; testing;
D O I
10.1109/QUATIC.2014.17
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Access Control is among the most important security mechanisms to put in place in order to secure applications. XACML is the de facto standard for storing and deploying access control policies. However, due to the complexity of the XACML language, policy definition becomes a difficult and error prone process. In recent years, the combined use of models for the access control policy specification, and the model-to-code facilities, for the automatic transformation of the model into the XACML language, has been proposed as a possible solution. These model-driven methodologies and facilities need to be thoroughly validated and verified. In this paper we provide an integrated framework for testing the automatic translation of the specification of an access control model into an XACML policy. The framework includes different test strategies for the derivation of test cases and some facilities for making easier their execution against the XACML policy and the test results collection and analysis. In addition, we illustrate the use of the framework on a case study.
引用
收藏
页码:75 / 84
页数:10
相关论文
共 50 条
  • [21] A text-based visual notation for the unit testing of model-driven tools
    Strueber, Daniel
    Rieger, Felix
    Taentzer, Gabriele
    COMPUTER LANGUAGES SYSTEMS & STRUCTURES, 2017, 49 : 196 - 215
  • [22] A Model-Driven Framework for Automated Generation and Verification of Cloud Solutions from Requirements
    Nezhad, Hamid R. Motahari
    Nakamura, Taiga
    Sosnovich, Adi
    Yin, Peifeng
    Yorav, Karen
    SERVICE-ORIENTED COMPUTING (ICSOC 2018), 2018, 11236 : 714 - 721
  • [23] Towards a Framework for the Generic Specification of Model-driven Decision Support Systems: Classification Criteria of Model Relationships
    Schultewolter, Christian
    43RD HAWAII INTERNATIONAL CONFERENCE ON SYSTEMS SCIENCES VOLS 1-5 (HICSS 2010), 2010, : 3436 - 3445
  • [24] A Model-Based Framework for Security Policy Specification, Deployment and Testing
    Mouelhi, Tejeddine
    Fleurey, Franck
    Baudry, Benoit
    Le Traon, Yves
    MODEL DRIVEN ENGINEERING LANGUAGES AND SYSTEMS, PROCEEDINGS, 2008, 5301 : 537 - 552
  • [25] A Model-Driven Engineering approach for the observation needs specification
    Zendagui, Boubekeur
    ICALT: 2009 IEEE INTERNATIONAL CONFERENCE ON ADVANCED LEARNING TECHNOLOGIES, 2009, : 67 - 69
  • [26] Model-driven business process security requirement specification
    Wolter, Christian
    Menzel, Michael
    Schaad, Andreas
    Miseldine, Philip
    Meinel, Christoph
    JOURNAL OF SYSTEMS ARCHITECTURE, 2009, 55 (04) : 211 - 223
  • [27] Model-driven user requirements specification using SysML
    Soares, Michel dos Santos
    Vrancken, Jos
    Journal of Software, 2008, 3 (06) : 57 - 68
  • [28] Requirements specification using templates: a model-driven approach
    Darif, Ikram
    El Boussaidi, Ghizlane
    Kpodjedo, Segla
    SOFTWARE AND SYSTEMS MODELING, 2025,
  • [29] A UML Extension for the Model-Driven Specification of Audit Rules
    Hoisl, Bernhard
    Strembeck, Mark
    ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS, CAISE 2012, 2012, 112 : 16 - 30
  • [30] XACML Policy Performance Evaluation Using a Flexible Load Testing Framework
    Butler, Bernard
    Jennings, Brendan
    Botvich, Dmitri
    PROCEEDINGS OF THE 17TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'10), 2010, : 648 - 650