Automated testing in DevOps represents a key factor for providing fast release of new software features assuring quality delivery. In this paper, we introduce DOXAT, an automated framework for continuous development and testing of access control mechanisms based on the XACML standard. It leverages mutation analysis for the selection and assessment of the test strategies and provides automated facilities for test oracle definition, test execution, and results analysis, in order to speedup and automate the Plan, Code, Build, and Test phases of DevOps process. We show the usage of the framework during the planning and testing phases of the software development cycle of a PDP example.

An automated framework for continuous development and testing of access control systems

Daoudagh S;Lonetti F;Marchetti E
2020

Abstract

Automated testing in DevOps represents a key factor for providing fast release of new software features assuring quality delivery. In this paper, we introduce DOXAT, an automated framework for continuous development and testing of access control mechanisms based on the XACML standard. It leverages mutation analysis for the selection and assessment of the test strategies and provides automated facilities for test oracle definition, test execution, and results analysis, in order to speedup and automate the Plan, Code, Build, and Test phases of DevOps process. We show the usage of the framework during the planning and testing phases of the software development cycle of a PDP example.
2020
Istituto di Scienza e Tecnologie dell'Informazione "Alessandro Faedo" - ISTI
Inglese
22
https://onlinelibrary.wiley.com/doi/abs/10.1002/smr.2306
Sì, ma tipo non specificato
Access control systems
Continuous development and testing
DevOps
Mutation analysis
XACML
Online Version of Record before inclusion in an issue e2306
Elettronico
No
3
info:eu-repo/semantics/article
262
Daoudagh, S; Lonetti, F; Marchetti, E
01 Contributo su Rivista::01.01 Articolo in rivista
restricted
   Cyber Security Network of Competence Centres for Europe
   CyberSec4Europe
   H2020
   830929
File in questo prodotto:
File Dimensione Formato  
prod_457676-doc_177782.pdf

solo utenti autorizzati

Descrizione: An automated framework for continuous development and testing of access control systems
Tipologia: Versione Editoriale (PDF)
Licenza: NON PUBBLICO - Accesso privato/ristretto
Dimensione 7.82 MB
Formato Adobe PDF
7.82 MB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/398073
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 2
  • ???jsp.display-item.citation.isi??? 2
social impact