首页> 外文会议>Information and Communications Security; Lecture Notes in Computer Science; 4307 >Defining and Measuring Policy Coverage in Testing Access Control Policies
【24h】

Defining and Measuring Policy Coverage in Testing Access Control Policies

机译:在测试访问控制策略中定义和衡量策略覆盖率

获取原文
获取原文并翻译 | 示例

摘要

To facilitate managing access control in a system, security officers increasingly write access control policies in specification languages such as XACML, and use a dedicated software component called a Policy Decision Point (PDP). To increase confidence on written policies, certain types of policy testing (often in an ad hoc way) are usually conducted, which probe the PDP with some typical requests and check PDP's responses against expected ones. This paper develops a first step toward systematic policy testing by defining and measuring policy coverage when testing policies. We have developed a coverage-measurement tool to measure policy coverage given a set of XACML policies and a set of requests. We have developed a tool for request generation, which randomly generates requests for a given set of policies, and a tool for request reduction, which greedily selects a nearly minimal set of requests for achieving the same coverage as the originally generated requests. To evaluate coverage-based request reduction and its effect on fault detection, we have conducted an experiment with mutation testing on a set of real policies. Our experimental results show that the coverage-based test reduction can substantially reduce the size of generated requests and incur only relatively low loss on fault detection. We also conduct a study on the policy coverage achieved by manually generated requests.
机译:为了便于管理系统中的访问控制,安全人员越来越多地使用诸如XACML的规范语言编写访问控制策略,并使用称为策略决策点(PDP)的专用软件组件。为了提高对书面政策的信心,通常会进行某些类型的政策测试(通常是临时性的),这些测试会测试PDP的一些典型请求,并对照预期的请求检查PDP的响应。本文通过在测试策略时定义和衡量策略覆盖范围,朝着系统策略测试迈出了第一步。我们已经开发了一种覆盖率测量工具,可以根据一组XACML策略和一组请求来测量策略覆盖率。我们已经开发了一种用于请求生成的工具,该工具可以随机生成针对给定策略集的请求,以及一种用于减少请求的工具,该工具可以贪婪地选择一组几乎最少的请求,以实现与原始生成的请求相同的覆盖率。为了评估基于覆盖的请求减少及其对故障检测的影响,我们对一组实际策略进行了变异测试实验。我们的实验结果表明,基于覆盖率的测试减少可以大大减少所生成请求的大小,并且在故障检测方面仅造成相对较低的损失。我们还对通过手动生成的请求实现的策略覆盖范围进行了研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号