A decentralized solution for combinatorial testing of access control engine
Contributo in Atti di convegno
Data di Pubblicazione:
2019
Abstract:
In distributed environments, information security is a key factor and access control is an important means to guarantee confidentiality of sensitive and valuable data. In this paper, we introduce a new decentralized framework for testing of XACML-based access control engines. The proposed framework is composed of different web services and provides the following functionalities: I) generation of test cases based on combinatorial testing strategies; ii) decentralized oracle that associates the expected result to a given test case, i.e. an XACML request; and finally, iii) a GUI for interacting with the framework and providing some analysis about the expected results. A first validation confirms the efficiency of the proposed approach.
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
Access Control; Testing; Web Service
Elenco autori:
Daoudagh, Said; Marchetti, Eda; Lonetti, Francesca
Link alla scheda completa:
Titolo del libro:
5th International Conference on Information Systems Security and Privacy