Paper published in a journal (Scientific congresses, symposiums and conference proceedings)
Testing Obligation Policy Enforcement using Mutation Analysis
El Rakaiby, Yehia; Mouelhi, Tejeddine; Le Traon, Yves
2012In Proceedings of the 7th International Workshop on Mutation Analysis (associated to the Fifth International Conference on Software Testing, Verification, and Validation, ICST 2012), p. 100-110
Peer reviewed
 

Files


Full Text
Obligations-Mutation12.pdf
Author postprint (712.06 kB)
Download

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Access control policies; Application codes; Java program; Key elements; Minimal errors; Mutation analysis; Mutation operators; Mutation process; Policy enforcement; Policy management; Test case; Test selection; Usage control
Abstract :
[en] The support of obligations with access control policies allows the expression of more sophisticated requirements such as usage control, availability and privacy. In order to enable the use of these policies, it is crucial to ensure their correct enforcement and management in the system. For this reason, this paper introduces a set of mutation operators for obligation policies. The paper first identifies key elements in obligation policy management, then presents mutation operators which injects minimal errors which affect these aspects. Test cases are qualified w.r.t. their ability in detecting problems, simulated by mutation, in the interactions between policy management and the application code. The use of policy mutants as substitutes for real flaws enables a first investigation of testing obligation policies in a system. We validate our work by providing an implementation of the mutation process: the experiments conducted on a Java program provide insights for improving test selection.
Disciplines :
Computer science
Identifiers :
UNILU:UL-CONFERENCE-2012-122
Author, co-author :
El Rakaiby, Yehia ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC) ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Mouelhi, Tejeddine ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Le Traon, Yves ;  University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC)
External co-authors :
yes
Language :
English
Title :
Testing Obligation Policy Enforcement using Mutation Analysis
Publication date :
2012
Event name :
MUTATION'12, 7th International workshop on mutation analysis
Event place :
Montreal, QC, Canada
Event date :
17 April 2012
Audience :
International
Journal title :
Proceedings of the 7th International Workshop on Mutation Analysis (associated to the Fifth International Conference on Software Testing, Verification, and Validation, ICST 2012)
Pages :
100-110
Peer reviewed :
Peer reviewed
Available on ORBilu :
since 03 April 2016

Statistics


Number of views
108 (0 by Unilu)
Number of downloads
93 (0 by Unilu)

Bibliography


Similar publications



Contact ORBilu