Istituto di Scienza e Tecnologie dell'Informazione     
Bertolino A., Daoudagh S., Lonetti F., Marchetti E., Martinelli F., Mori P. Testing of PolPA authorization systems. In: AST 2012 - 7th International Workshop on Automation of Software Test (Zurich, Switzerland, 2-3 June 2012). Proceedings, pp. 8 - 14. IEEE, 2012.
The implementation of an authorization system is a difficult and error-prone activity that requires a careful verification and testing process. In this paper, we focus on testing the implementation of the PolPA authorization system and in particular its Policy Decision Point (PDP), used to define whether an access should be allowed or not. Thus exploiting the PolPA policy specification, we present a fault model and a test strategy able to highlight the problems, vulnerabilities and faults that could occur during the PDP implementation, and a testing framework for the automatic generation of a test suite that covers the fault model. Preliminary results of the test framework application to a realistic case study are presented.
URL: http://ieeexplore.ieee.org/xpl/articleDetails.jsp?tp=&arnumber=6228997&contentType=Conference+Publications&searchField%3DSearch_All%26queryText%3DTesting+of+PolPA+authorization+systems
DOI: 10.1109/IWAST.2012.6228997
Subject Authorization systems
PolPA language
Request generation
D.2.5 Testing and Debugging
D.2.6 Security and Protection

Icona documento 1) Download Document PDF

Icona documento Open access Icona documento Restricted Icona documento Private


Per ulteriori informazioni, contattare: Librarian http://puma.isti.cnr.it

Valid HTML 4.0 Transitional