Paper published in a book (Scientific congresses, symposiums and conference proceedings)
Access Control Enforcement Testing
El Kateb, Donia; Elrakaiby, Yehia; Mouelhi, Tejeddine et al.
2012In 8th International Workshop on Automation of Software Test (AST), 2013
Peer reviewed
 

Files


Full Text
ast-2013-localisation-pep-final.pdf
Publisher postprint (790.58 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
authorisation; program diagnostics; program testing
Abstract :
[en] A policy-based access control architecture com- prises Policy Enforcement Points (PEPs), which are modules that intercept subjects access requests and enforce the access decision reached by a Policy Decision Point (PDP), the module implementing the access decision logic. In applications, PEPs are generally implemented manually, which can introduce errors in policy enforcement and lead to security vulnerabilities. In this paper, we propose an approach to systematically test and validate the correct enforcement of access control policies in a given target application. More specifically, we rely on a two folded approach where a static analysis of the target application is first made to identify the sensitive accesses that could be regulated by the policy. The dynamic analysis of the application is then conducted using mutation to verify for every sensitive access whether the policy is correctly enforced. The dynamic analysis of the application also gives the exact location of the PEP to enable fixing enforcement errors detected by the analysis. The approach has been validated using a case study implementing an access control policy.
Disciplines :
Computer science
Author, co-author :
El Kateb, Donia ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) ; University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Elrakaiby, Yehia
Mouelhi, Tejeddine ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Le Traon, Yves ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
Language :
English
Title :
Access Control Enforcement Testing
Publication date :
May 2012
Event name :
8th International Workshop on Automation of Software Test (AST), 2013
Event place :
San Francisco, United States
Event date :
from 18-05-2013 to 19-05-2013
Audience :
International
Main work title :
8th International Workshop on Automation of Software Test (AST), 2013
Pages :
64-70
Peer reviewed :
Peer reviewed
Available on ORBilu :
since 09 March 2014

Statistics


Number of views
121 (7 by Unilu)
Number of downloads
182 (4 by Unilu)

WoS citations
 
1

Bibliography


Similar publications



Contact ORBilu