An automated testing framework of model-driven tools for XACML policy specification

被引:2
|
作者
Bertolino, Antonia [1 ]
Daoudagh, Said [1 ]
Lonetti, Francesca [1 ]
Marchetti, Eda [1 ]
机构
[1] Consiglio Nazl Ric CNR, Ist Sci & Tecnol Informaz A Faedo, I-56124 Pisa, Italy
关键词
access control; model-driven development; testing;
D O I
10.1109/QUATIC.2014.17
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Access Control is among the most important security mechanisms to put in place in order to secure applications. XACML is the de facto standard for storing and deploying access control policies. However, due to the complexity of the XACML language, policy definition becomes a difficult and error prone process. In recent years, the combined use of models for the access control policy specification, and the model-to-code facilities, for the automatic transformation of the model into the XACML language, has been proposed as a possible solution. These model-driven methodologies and facilities need to be thoroughly validated and verified. In this paper we provide an integrated framework for testing the automatic translation of the specification of an access control model into an XACML policy. The framework includes different test strategies for the derivation of test cases and some facilities for making easier their execution against the XACML policy and the test results collection and analysis. In addition, we illustrate the use of the framework on a case study.
引用
收藏
页码:75 / 84
页数:10
相关论文
共 50 条
  • [1] AN AUTOMATED MODEL-DRIVEN TESTING FRAMEWORK For Model-Driven Development and Software Product Lines
    Lamancha, Beatriz Perez
    Polo Usaola, Macario
    Piattini, Mario
    ENASE 2010: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON EVALUATION OF NOVEL APPROACHES TO SOFTWARE ENGINEERING, 2010, : 112 - 121
  • [2] Model-driven Generative Framework for Automated OMG DDS Performance Testing in the Cloud
    An, Kyoungho
    Kuroda, Takayuki
    Gokhale, Aniruddha
    Tambe, Sumant
    Sorbini, Andrea
    ACM SIGPLAN NOTICES, 2014, 49 (03) : 179 - 182
  • [3] A framework of model-driven web application testing
    Li, Nuo
    Ma, Qin-qin
    Wu, Ji
    Jin, Mao-zhong
    Liu, Chao
    30TH ANNUAL INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE, VOL 2, SHORT PAPERS/WORKSHOPS/FAST ABSTRACTS/DOCTORAL SYMPOSIUM, PROCEEDINGS, 2006, : 157 - 162
  • [4] Model-Driven Policy Framework for Data Centers
    Caba, Cosmin
    Mimidis, Angelos
    Soler, Jose
    2016 5TH IEEE INTERNATIONAL CONFERENCE ON CLOUD NETWORKING (IEEE CLOUDNET), 2016, : 126 - 129
  • [5] Usage Control Model Specification in XACML Policy Language XACML Policy Engine of UCON
    Um-e-Ghazia
    Masood, Rahat
    Shibli, Muhammad Awais
    Bilal, Muhammad
    COMPUTER INFORMATION SYSTEMS AND INDUSTRIAL MANAGEMENT (CISIM), 2012, 7564 : 68 - 79
  • [6] From model-driven specification to design-level set-based analysis of XACML policies
    Mourad, Azzam
    Tout, Hanine
    Talhi, Chamseddine
    Otrok, Hadi
    Yahyaoui, Hamdi
    COMPUTERS & ELECTRICAL ENGINEERING, 2016, 52 : 65 - 79
  • [7] Diagen: A Model-Driven Framework for Integrating Bioinformatic Tools
    Jose Villanueva, Maria
    Valverde, Francisco
    Levin, Ana M.
    Pastor Lopez, Oscar
    IS OLYMPICS: INFORMATION SYSTEMS IN A DIVERSE WORLD, 2012, 107 : 49 - 63
  • [8] Realization of FGAC Model using XACML Policy Specification
    Shibli, Muhammad Awais
    Masood, Rahat
    Habiba, Umme
    2015 16TH IEEE/ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING (SNPD), 2015, : 187 - 192
  • [9] ArchiMeDeS: A model-driven framework for the specification of service-oriented architectures
    Lopez-Sanz, Marcos
    Marcos, Esperanza
    INFORMATION SYSTEMS, 2012, 37 (03) : 257 - 268
  • [10] Formal Specification and Systematic Model-Driven Testing of Embedded Automotive Systems
    Siegl, Sebastian
    Hielscher, Kai-Steffen
    German, Reinhard
    Berger, Christian
    2011 DESIGN, AUTOMATION & TEST IN EUROPE (DATE), 2011, : 118 - 123