On‐line tracing of XACML‐based policy coverage criteria.

Saved in:
Bibliographic Details
Title: On‐line tracing of XACML‐based policy coverage criteria.
Authors: Lonetti, Francesca1 (AUTHOR) francesca.lonetti@isti.cnr.it, Marchetti, Eda1 (AUTHOR)
Source: IET Software (Wiley-Blackwell). Dec2018, Vol. 12 Issue 6, p480-488. 9p.
Abstract: Currently, eXtensible Access Control Markup Language (XACML) has becoming the standard for implementing access control policies and consequently more attention is dedicated to testing the correctness of XACML policies. In particular, coverage measures can be adopted for assessing test strategy effectiveness in exercising the policy elements. This study introduces a set of XACML coverage criteria and describes the access control infrastructure, based on a monitor engine, enabling the coverage criterion selection and the on‐line tracing of the testing activity. Examples of infrastructure usage and of assessment of different test strategies are provided. [ABSTRACT FROM AUTHOR]
Copyright of IET Software (Wiley-Blackwell) is the property of Wiley-Blackwell and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Description
Abstract:Currently, eXtensible Access Control Markup Language (XACML) has becoming the standard for implementing access control policies and consequently more attention is dedicated to testing the correctness of XACML policies. In particular, coverage measures can be adopted for assessing test strategy effectiveness in exercising the policy elements. This study introduces a set of XACML coverage criteria and describes the access control infrastructure, based on a monitor engine, enabling the coverage criterion selection and the on‐line tracing of the testing activity. Examples of infrastructure usage and of assessment of different test strategies are provided. [ABSTRACT FROM AUTHOR]
ISSN:17518806
DOI:10.1049/iet-sen.2017.0351