Paper published in a book (Scientific congresses, symposiums and conference proceedings)
Testing Delegation Policy Enforcement via Mutation Analysis
Nguyen, Phu Hong; Papadakis, Mike; Rubab, Iram
2013In 7th International Workshop on Mutation Analysis
Peer reviewed
 

Files


Full Text
TestingDelegationPolicyViaMutationAnalysis-CamReady.pdf
Publisher postprint (1.23 MB)
Request a copy

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Access Control; Delegation; Mutation Analysis; Security Testing; Model-Driven Security
Abstract :
[en] Delegation is an important dimension of security that plays a crucial role in the administration mechanism of access control policies. Delegation may be viewed as an exception made to an access control policy in which a user gets right to act on behalf of other users. This meta-level characteristic together with the complexity of delegation itself make it crucial to ensure the correct enforcement and management of delegation policy in a system via testing. To this end, we adopt mutation analysis for delegation policies. In order to achieve this, a set of mutant operators specially designed for introducing mutants into the key components (features) of delegation is proposed. Our approach consists of analyzing the representation of the key components of delegation, based on which we derive the suggested set of mutant operators. These operators can then be used to introduce mutants into delegation policies and thus, enable mutation testing. A demonstration of the proposed approach on a model-driven adaptive delegation implementation of a library management system is also provided.
Research center :
Interdisciplinary Centre for Security, Reliability and Trust (SnT)
Disciplines :
Computer science
Author, co-author :
Nguyen, Phu Hong ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Papadakis, Mike ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Rubab, Iram ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > Computer Science and Communications Research Unit (CSC)
Language :
English
Title :
Testing Delegation Policy Enforcement via Mutation Analysis
Publication date :
March 2013
Event name :
IEEE Sixth International Conference on Software Testing, Verification and Validation Workshops (ICSTW), 2013
Event organizer :
ICST
Event place :
Luxembourg, Luxembourg
Event date :
from 18-03-2013 to 22-03-2013
Audience :
International
Main work title :
7th International Workshop on Mutation Analysis
Publisher :
IEEE
ISBN/EAN :
978-1-4799-1324-4
Pages :
34-42
Peer reviewed :
Peer reviewed
Name of the research project :
MITER
Funders :
The National Research Fund of Luxembourg (FNR)
Available on ORBilu :
since 07 November 2013

Statistics


Number of views
136 (10 by Unilu)
Number of downloads
1 (1 by Unilu)

Scopus citations®
 
6
Scopus citations®
without self-citations
3
WoS citations
 
3

Bibliography


Similar publications



Contact ORBilu