Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

A General Framework for Decentralized Combinatorial Testing of Access Control Engine: Examples of Application

Capitolo di libro
Data di Pubblicazione:
2019
Abstract:
Access control mechanisms aim to assure data protection in modern software systems. Testing of such mechanisms is a key activity to avoid security flaws and violations inside the systems or applications. In this paper, we introduce the general architecture of a new decentralized framework for testing of XACML-based access control engines. The proposed framework is composed of different web services and can be instantiated for different testing purposes: i) generation of test cases based on combinatorial testing strategies; ii) distributed test cases execution; iii) decentralized oracle derivation able to associate the expected authorization decision to a given XACML request. The effectiveness of the framework has been proven into two different experiments. The former addressed the evaluation of the distributed vs non distributed testing solution. The latter focused on the performance comparison of two distributed oracle approaches.
Tipologia CRIS:
02.01 Contributo in volume (Capitolo o Saggio)
Keywords:
XACML; Oracle; Access control systems; Testing; Web service
Elenco autori:
Daoudagh, Said; Marchetti, Eda; Lonetti, Francesca
Autori di Ateneo:
DAOUDAGH SAID
LONETTI FRANCESCA
MARCHETTI EDA
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/424901
Titolo del libro:
Information Systems Security and Privacy
  • Dati Generali

Dati Generali

URL

https://link.springer.com/chapter/10.1007%2F978-3-030-49443-8_10
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)