首页 | 本学科首页   官方微博 | 高级检索  
     


Automated policy generation for testing access control software
Authors:Alejandro Felix  Michael Smith  James Miller
Affiliation:Electrical and Computer Engineering, University of Alberta, Edmonton, Alberta, Canada
Abstract:
Access control systems (ACS) are a critical component of modern information technology systems and require rigorous testing. If the ACS has defects, then the deployment is not secure and is a threat to system security. Firewalls are an important example of an ACS, and formally verifying firewall systems has recently attracted attention. We present an automated software-testing tool, PG, for the production of firewall policies for use in firewall policy enforcement testing. PG utilizes a number of heuristic techniques to improve space coverage over traditional systems based on randomly generated firewall policies. An empirical study is presented demonstrating that PG generates firewall policies with superior coverage compared to traditional policy-generation techniques. The extension of PG beyond firewall systems to other ACS situations is outlined.
Keywords:Access control system policies  access control system testing  firewall policies  firewalls policy enforcement testing  software testing
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号