Sommario in IngleseAccess control mechanisms are defined by means of XACML policies in many application domains. Model-driven approaches: i)allow to overcome difficulties in the XACML policy definition; ii)can hide inaccuracies and weaknesses of security mechanisms. Testing is a key activity for assessing compliance of a XACML policy with the initial model. We propose a Toolchain for supporting users in testing access control policies modeled with UWE.

A toolchain for designing and testing XACML policies

Bertolino A;Daoudagh S;Lonetti F;Marchetti E
2013

Abstract

Sommario in IngleseAccess control mechanisms are defined by means of XACML policies in many application domains. Model-driven approaches: i)allow to overcome difficulties in the XACML policy definition; ii)can hide inaccuracies and weaknesses of security mechanisms. Testing is a key activity for assessing compliance of a XACML policy with the initial model. We propose a Toolchain for supporting users in testing access control policies modeled with UWE.
2013
Istituto di Scienza e Tecnologie dell'Informazione "Alessandro Faedo" - ISTI
XACML policies
UML-based Web Engineering
Test cases generation
Model compliance
D.2 SOFTWARE ENGINEERING
D.2.5 Testing and Debugging
D.2.6 Security and Protection. Access controls
File in questo prodotto:
File Dimensione Formato  
prod_277636-doc_78244.pdf

solo utenti autorizzati

Descrizione: A Toolchain for Designing and Testing XACML Policies
Tipologia: Versione Editoriale (PDF)
Dimensione 482.48 kB
Formato Adobe PDF
482.48 kB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/252580
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 3
  • ???jsp.display-item.citation.isi??? 2
social impact