An automated testing framework of model-driven tools for XACML policy specification

被引:2
|
作者
Bertolino, Antonia [1 ]
Daoudagh, Said [1 ]
Lonetti, Francesca [1 ]
Marchetti, Eda [1 ]
机构
[1] Consiglio Nazl Ric CNR, Ist Sci & Tecnol Informaz A Faedo, I-56124 Pisa, Italy
关键词
access control; model-driven development; testing;
D O I
10.1109/QUATIC.2014.17
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Access Control is among the most important security mechanisms to put in place in order to secure applications. XACML is the de facto standard for storing and deploying access control policies. However, due to the complexity of the XACML language, policy definition becomes a difficult and error prone process. In recent years, the combined use of models for the access control policy specification, and the model-to-code facilities, for the automatic transformation of the model into the XACML language, has been proposed as a possible solution. These model-driven methodologies and facilities need to be thoroughly validated and verified. In this paper we provide an integrated framework for testing the automatic translation of the specification of an access control model into an XACML policy. The framework includes different test strategies for the derivation of test cases and some facilities for making easier their execution against the XACML policy and the test results collection and analysis. In addition, we illustrate the use of the framework on a case study.
引用
收藏
页码:75 / 84
页数:10
相关论文
共 50 条
  • [31] A Model-driven Implementation of PSCS Specification for C++
    Hammer, Maximilian
    Maschotta, Ralph
    Wichmann, Alexander
    Jungebloud, Tino
    Bedini, Francesco
    Zimmermann, Armin
    PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON MODEL-DRIVEN ENGINEERING AND SOFTWARE DEVELOPMENT (MODELSWARD), 2021, : 100 - 109
  • [32] Model-driven Framework for Requirement Traceability
    Kesserwan, Nader
    Al-Jaroodi, Jameela
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (02) : 1 - 12
  • [33] A model-driven choreography conceptual framework
    Arroyo, Sinuhe
    Duke, Alistair
    Lopez-Cobo, Jos-Manuel
    Sicilia, Miguel-Angel
    COMPUTER STANDARDS & INTERFACES, 2007, 29 (03) : 325 - 334
  • [34] A framework for model-driven pattern matching
    de Guzman, Ignacio Garcia-Rodriguez
    Polo, Macario
    Piattini, Mario
    ICEIS 2007: PROCEEDINGS OF THE NINTH INTERNATIONAL CONFERENCE ON ENTERPRISE INFORMATION SYSTEMS: DATABASES AND INFORMATION SYSTEMS INTEGRATION, 2007, : 553 - 557
  • [35] Evolution of a Model-driven Process Framework
    Padua, Wilson
    ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2016, 321 : 41 - 65
  • [36] A Survey of Model-Driven Testing Techniques
    Mussa, Mohamed
    Ouchani, Samir
    Al Sammane, Waseem
    Hamou-Lhadj, Abdelwahab
    2009 NINTH INTERNATIONAL CONFERENCE ON QUALITY SOFTWARE (QSIC 2009), 2009, : 167 - 172
  • [37] Testing of model-driven development applications
    Beatriz Marín
    Carlos Gallardo
    Diego Quiroga
    Giovanni Giachetti
    Estefanía Serral
    Software Quality Journal, 2017, 25 : 407 - 435
  • [38] Model-driven Testing of RESTful APIs
    Fertig, Tobias
    Braun, Peter
    WWW'15 COMPANION: PROCEEDINGS OF THE 24TH INTERNATIONAL CONFERENCE ON WORLD WIDE WEB, 2015, : 1497 - 1502
  • [39] Model-Driven Method for Performance Testing
    Javed, Z.
    Mohammadian, Masoud
    2018 7TH INTERNATIONAL CONFERENCE ON RELIABILITY, INFOCOM TECHNOLOGIES AND OPTIMIZATION (TRENDS AND FUTURE DIRECTIONS) (ICRITO) (ICRITO), 2018, : 147 - 155
  • [40] Testing of model-driven development applications
    Marin, Beatriz
    Gallardo, Carlos
    Quiroga, Diego
    Giachetti, Giovanni
    Serral, Estefania
    SOFTWARE QUALITY JOURNAL, 2017, 25 (02) : 407 - 435