Paper published in a journal (Scientific congresses, symposiums and conference proceedings)
Access Control Enforcement Testing
El Kateb, Donia; ElRakaiby, Yehia; Mouelhi, Tejeddine et al.
2013In Abstract book of 2013 8TH INTERNATIONAL WORKSHOP ON AUTOMATION OF SOFTWARE TEST (AST), p. 64-70
Peer reviewed
 

Files


Full Text
access control.pdf
Publisher postprint (801.75 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Access Control Policies; PEP; PDP; Security Test Cases
Abstract :
[en] A policy-based access control architecture comprises Policy Enforcement Points (PEPs), which are modules that intercept subjects access requests and enforce the access decision reached by a Policy Decision Point (PDP), the module implementing the access decision logic. In applications, PEPs are generally implemented manually, which can introduce errors in policy enforcement and lead to security vulnerabilities. In this paper, we propose an approach to systematically test and validate the correct enforcement of access control policies in a given target application. More specifically, we rely on a two folded approach where a static analysis of the target application is first made to identify the sensitive accesses that could be regulated by the policy. The dynamic analysis of the application is then conducted using mutation to verify for every sensitive access whether the policy is correctly enforced. The dynamic analysis of the application also gives the exact location of the PEP to enable fixing enforcement errors detected by the analysis. The approach has been validated using a case study implementing an access control policy.
Disciplines :
Computer science
Author, co-author :
El Kateb, Donia;  Univ Luxembourg, Interdisciplinary Res Ctr, SnT, Luxembourg, Luxembourg.
ElRakaiby, Yehia;  Univ Luxembourg, Interdisciplinary Res Ctr, SnT, Luxembourg, Luxembourg.
Mouelhi, Tejeddine;  Univ Luxembourg, Interdisciplinary Res Ctr, SnT, Luxembourg, Luxembourg.
Le Traon, Yves ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
External co-authors :
yes
Title :
Access Control Enforcement Testing
Publication date :
2013
Event name :
8th International Workshop on Automation of Software Test (AST)
Event place :
San Francisco, United States - California
Event date :
MAY 18-19, 2013
Journal title :
Abstract book of 2013 8TH INTERNATIONAL WORKSHOP ON AUTOMATION OF SOFTWARE TEST (AST)
Publisher :
Ieee, New York, Unknown/unspecified
Pages :
64-70
Peer reviewed :
Peer reviewed
Commentary :
978-1-4673-6161-3
Available on ORBilu :
since 09 April 2016

Statistics


Number of views
86 (1 by Unilu)
Number of downloads
293 (0 by Unilu)

Scopus citations®
 
2
Scopus citations®
without self-citations
2
WoS citations
 
1

Bibliography


Similar publications



Contact ORBilu