PUMA
Istituto di Scienza e Tecnologie dell'Informazione     
Bertolino A., Daoudagh S., Lonetti F., Marchetti E., Martinelli F., Mori P. Testing of PolPA-based usage control systems. In: Software Quality Journal, vol. 22 (2) pp. 241 - 271. Springer, 2014.
 
 
Abstract
(English)
The implementation of an authorization system is a critical and error-prone activity that requires a careful verification and testing process. As a matter of fact, errors in the authorization system code could grant accesses that should instead be denied, thus jeopardizing the security of the protected system. In this paper, we address the testing of the implementation of the Policy Decision Point (PDP) within the PolPA authorization system that enables history-based and usage-based control of accesses. Accordingly, we propose two testing strategies specifically conceived for validating the history-based access control and the usage control functionalities of the PolPA PDP. The former is based on a fault model able to highlight the problems and vulnerabilities that could occur during the PDP implementation. The latter combines the standard technique for conditions coverage with a methodology for simulating the continuous control of the PDP during the runtime execution.
URL: http://link.springer.com/article/10.1007%2Fs11219-013-9216-0
DOI: 10.1007/s11219-013-9216-0
Subject Authorization systems
PolPA language
Usage control
History-based access control
Testing
D.4.6 Security and Protection. Access controls
D.2.5 Testing and Debugging


Icona documento 1) Download Document PDF


Icona documento Open access Icona documento Restricted Icona documento Private

 


Per ulteriori informazioni, contattare: Librarian http://puma.isti.cnr.it

Valid HTML 4.0 Transitional