首页 | 本学科首页   官方微博 | 高级检索  
     


Testing of PolPA-based usage control systems
Authors:Antonia Bertolino  Said Daoudagh  Francesca Lonetti  Eda Marchetti  Fabio Martinelli  Paolo Mori
Affiliation:1. Istituto di Scienza e Tecnologie dell’Informazione “A. Faedo”, Consiglio Nazionale delle Ricerche, via G. Moruzzi, 56124, Pisa, Italy
2. Istituto di Informatica e Telematica, Consiglio Nazionale delle Ricerche, via G. Moruzzi, 56124, Pisa, Italy
Abstract:The implementation of an authorization system is a critical and error-prone activity that requires a careful verification and testing process. As a matter of fact, errors in the authorization system code could grant accesses that should instead be denied, thus jeopardizing the security of the protected system. In this paper, we address the testing of the implementation of the Policy Decision Point (PDP) within the PolPA authorization system that enables history-based and usage-based control of accesses. Accordingly, we propose two testing strategies specifically conceived for validating the history-based access control and the usage control functionalities of the PolPA PDP. The former is based on a fault model able to highlight the problems and vulnerabilities that could occur during the PDP implementation. The latter combines the standard technique for conditions coverage with a methodology for simulating the continuous control of the PDP during the runtime execution. Both strategies are implemented within a testing framework supporting the automatic generation and execution of security test suites. Results produced by the application of this testing framework to a real case study are presented.
Keywords:
本文献已被 SpringerLink 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号