Authors
Donia El Kateb, Yehia El Rakaiby, Tejeddine Mouelhi, Yves Le Traon
Publication date
2013/5/18
Conference
2013 8th International Workshop on Automation of Software Test (AST)
Pages
64-70
Publisher
Ieee
Description
A policy-based access control architecture comprises Policy Enforcement Points (PEPs), which are modules that intercept subjects access requests and enforce the access decision reached by a Policy Decision Point (PDP), the module implementing the access decision logic. In applications, PEPs are generally implemented manually, which can introduce errors in policy enforcement and lead to security vulnerabilities. In this paper, we propose an approach to systematically test and validate the correct enforcement of access control policies in a given target application. More specifically, we rely on a two folded approach where a static analysis of the target application is first made to identify the sensitive accesses that could be regulated by the policy. The dynamic analysis of the application is then conducted using mutation to verify for every sensitive access whether the policy is correctly enforced. The dynamic …
Total citations
2015201620172018201920201112
Scholar articles
D El Kateb, Y El Rakaiby, T Mouelhi, Y Le Traon - 2013 8th International Workshop on Automation of …, 2013