Authors
Yehia Elrakaiby, Tejeddine Mouelhi, Yves Le Traon
Publication date
2012/4/17
Conference
2012 IEEE Fifth International Conference on Software Testing, Verification and Validation
Pages
673-680
Publisher
IEEE
Description
The support of obligations with access control policies allows the expression of more sophisticated requirements such as usage control, availability and privacy. In order to enable the use of these policies, it is crucial to ensure their correct enforcement and management in the system. For this reason, this paper introduces a set of mutation operators for obligation policies. The paper first identifies key elements in obligation policy management, then presents mutation operators which injects minimal errors which affect these aspects. Test cases are qualified w.r.t. their ability in detecting problems, simulated by mutation, in the interactions between policy management and the application code. The use of policy mutants as substitutes for real flaws enables a first investigation of testing obligation policies in a system. We validate our work by providing an implementation of the mutation process: the experiments conducted …
Total citations
20132014201520162017201820192020202120222023202441511142141
Scholar articles
Y Elrakaiby, T Mouelhi, Y Le Traon - 2012 IEEE Fifth International Conference on Software …, 2012