Istituto di Informatica e Telematica     
Martinelli F., Mori P., Bertolino A., Daoudagh S., Lonetti F., Marchetti E. Testing of PolPA Authorization Systems. In: 7th International Workshop on Automation of Software Test (AST2012) (Zurich, Switzerland, 2012). Proceedings, pp. 8 - 14. IEEE Digital Libraries, 2012.
The implementation of an authorization system is a difficult and error-prone activity that requires a careful verification and testing process. In this paper, we focus on testing the implementation of the PolPA authorization system and in particular its Policy Decision Point (PDP), used to define whether an access should be allowed or not. Thus exploiting the PolPA policy specification, we present a fault model and a test strategy able to highlight the problems, vulnerabilities and faults that could occur during the PDP implementation, and a testing framework for the automatic generation of a test suite that covers the fault model. Preliminary results of the test framework application to a realistic case study are presented.
Subject Authorization systems
PolPA language
request generation
D.4.6 Security and Protection (Access Control)

Icona documento 1) Download Document PDF

Icona documento Open access Icona documento Restricted Icona documento Private


Per ulteriori informazioni, contattare: Librarian http://puma.isti.cnr.it

Valid HTML 4.0 Transitional