Data di Pubblicazione:
2015
Abstract:
In modern pervasive applications, it is important to validate access control mechanisms that are usually defined by means of the standard XACML language. Mutation analysis has been applied on access control policies for measuring the adequacy of a test suite. In this paper, we present a testing framework aimed at applying mutation analysis at the level of the Java based policy evaluation engine. A set of Java based mutation operators is selected and applied to the code of the Policy Decision Point (PDP). A first experiment shows the effectiveness of the proposed framework in assessing the fault detection of XACML test suites and confirms the efficacy of the application of code-based mutation operators to the PDP.
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
XACML Language; Mutation analysis; Testing; Testing and Debugging; Security and Protection. Access controls
Elenco autori:
Daoudagh, Said; Marchetti, Eda; Lonetti, Francesca
Link alla scheda completa: