Companion to the 21st ACM SIGPLAN Symposium on Object-Oriented Programming Systems, Languages, and Applications 2006
DOI: 10.1145/1176617.1176708
|View full text |Cite
|
Sign up to set email alerts
|

Automated test generation for access control policies

Abstract: Access control policies are increasingly written in specification languages such as XACML. To increase confidence in the correctness of specified policies, policy developers can conduct policy testing to probe the Policy Decision Point (PDP) with some typical test inputs (in the form of requests) and check test outputs (in the form of responses) against expected ones. Unfortunately, manual test generation is tedious and manually generated tests are often not sufficient to exercise various policy behaviors. In … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
60
0

Year Published

2012
2012
2020
2020

Publication Types

Select...
4
1
1

Relationship

0
6

Authors

Journals

citations
Cited by 48 publications
(60 citation statements)
references
References 8 publications
0
60
0
Order By: Relevance
“…2) X-CREATE tool: Among the available tools for test cases generation we refer in this paper to X-CREATE 3 [15], [3], [16] showed that the fault detection effectiveness of X-CREATE test suites is similar or higher than that of comparable tools (like for instance Targen [2]). …”
Section: B Experiments Setupmentioning
confidence: 99%
See 3 more Smart Citations
“…2) X-CREATE tool: Among the available tools for test cases generation we refer in this paper to X-CREATE 3 [15], [3], [16] showed that the fault detection effectiveness of X-CREATE test suites is similar or higher than that of comparable tools (like for instance Targen [2]). …”
Section: B Experiments Setupmentioning
confidence: 99%
“…The Targen tool [2] generates test inputs using combinatorial coverage of the truth values of independent clauses of XACML policy values. This approach has been proven to be more effective than random generation strategy in terms of structural coverage of the policy and fault detection capability [2].…”
Section: Related Workmentioning
confidence: 99%
See 2 more Smart Citations
“…The work is based on a fault model [13], a structural coverage measurement tool for defining policy coverage metrics [15] and a test generator [14], developed by two of the authors in their former work. In [16] De Angelis et al discuss access policy testing as a vital function of the trust network, in which users and service providers interact.…”
Section: Testingmentioning
confidence: 99%