An automated testing framework of model-driven tools for XACML policy specification

被引:2
|
作者
Bertolino, Antonia [1 ]
Daoudagh, Said [1 ]
Lonetti, Francesca [1 ]
Marchetti, Eda [1 ]
机构
[1] Consiglio Nazl Ric CNR, Ist Sci & Tecnol Informaz A Faedo, I-56124 Pisa, Italy
关键词
access control; model-driven development; testing;
D O I
10.1109/QUATIC.2014.17
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Access Control is among the most important security mechanisms to put in place in order to secure applications. XACML is the de facto standard for storing and deploying access control policies. However, due to the complexity of the XACML language, policy definition becomes a difficult and error prone process. In recent years, the combined use of models for the access control policy specification, and the model-to-code facilities, for the automatic transformation of the model into the XACML language, has been proposed as a possible solution. These model-driven methodologies and facilities need to be thoroughly validated and verified. In this paper we provide an integrated framework for testing the automatic translation of the specification of an access control model into an XACML policy. The framework includes different test strategies for the derivation of test cases and some facilities for making easier their execution against the XACML policy and the test results collection and analysis. In addition, we illustrate the use of the framework on a case study.
引用
收藏
页码:75 / 84
页数:10
相关论文
共 50 条
  • [41] Towards model-driven unit testing
    Engels, Gregor
    Gueldali, Baris
    Lohmann, Marc
    MODELS IN SOFTWARE ENGINEERING, 2007, 4364 : 182 - +
  • [42] Model-driven development using standard tools
    Garrido, Julian
    Angeles Martos, M.
    Berzal, Fernando
    ICEIS 2007: PROCEEDINGS OF THE NINTH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS: DATABASES AND INFORMATION SYSTEMS INTEGRATION, 2007, : 433 - 436
  • [43] Creating and Testing a Model-Driven Framework for Accessible User-Centric Design
    Wilkinson, Christopher R.
    Walters, Andrew
    Evans, Jarred
    DESIGN JOURNAL, 2016, 19 (01): : 69 - 91
  • [44] Delta-based regression testing: a formal framework towards model-driven regression testing
    Abadeh, Maryam Nooraei
    Mirian-Hosseinabadi, Seyed-Hassan
    JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2015, 27 (12) : 913 - 952
  • [45] Software Development Tools in Model-Driven Engineering
    Jacome-Guerrero, Santiago P.
    Ferreira, Juan M.
    Corral, Alexandra
    2017 5TH INTERNATIONAL CONFERENCE IN SOFTWARE ENGINEERING RESEARCH AND INNOVATION (CONISOFT 2017), 2017, : 140 - 148
  • [46] A Model-Driven Architecture for Automated Deployment of Microservices
    Aksakalli, Isil Karabey
    Celik, Turgay
    Can, Ahmet Burak
    Tekinerdogan, Bedir
    APPLIED SCIENCES-BASEL, 2021, 11 (20):
  • [47] A Survey of Requirements Specification in Model-Driven Development of Web Applications
    Valderas, Pedro
    Pelechano, Vicente
    ACM TRANSACTIONS ON THE WEB, 2011, 5 (02)
  • [48] A Model-Driven Service Specification Approach from BPMN Models
    Blal, Redouane
    Leshob, Abderrahmane
    2017 IEEE 14TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE 2017), 2017, : 126 - 133
  • [49] A Model-Driven Approach for the Specification and Analysis of Access Control Policies
    Massacci, Fabio
    Zannone, Nicola
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS: OTM 2008, PT II, PROCEEDINGS, 2008, 5332 : 1087 - +
  • [50] A Model-driven Perspective on the Rule-based Specification of Services
    Iacob, Maria-Eugenia
    Jonkers, Henk
    EDOC 2008: 12TH IEEE INTERNATIONAL ENTERPRISE DISTRIBUTED OBJECT COMPUTING, PROCEEDINGS, 2008, : 75 - +