首页> 外文会议>International symposium on foundations and practice of security >A Formal Approach to Automatic Testing of Security Policies Specified in XACML
【24h】

A Formal Approach to Automatic Testing of Security Policies Specified in XACML

机译:XACML中指定的自动测试安全策略的正式方法

获取原文

摘要

Nowadays, security policies are the key point of every modern infrastructure. The specification and testing of such policies axe the fundamental steps in the development of a secure system. To address both challenges, we propose a framework that automatically generates test sequences to validate the conformance of a security policy. The functional behavior of the system is specified using a formal description technique based on Extended Finite-State Machines (EFSMs), while security requirements are specified using XACML. We develop specific algorithms to integrate the security rules into the functioned system specification. In this way, we obtain a complete specification of the secured system. Then, automatic test generation is performed using a dedicated tool called TestGen-IF which was developed in our laboratory. This generation is based on the security properties as test objectives. Finally, a case study is presented to demonstrate the reliability of our framework.
机译:如今,安全策略是每个现代基础架构的关键。此类策略的规范和测试是安全系统开发中的基本步骤。为了解决这两个挑战,我们提出了一个框架,该框架可自动生成测试序列以验证安全策略的一致性。使用基于扩展有限状态机(EFSM)的形式描述技术来指定系统的功能行为,同时使用XACML来指定安全性要求。我们开发特定的算法以将安全规则集成到功能系统规范中。通过这种方式,我们获得了安全系统的完整规范。然后,使用我们实验室开发的专用工具TestGen-IF执行自动测试生成。此生成基于作为测试目标的安全属性。最后,提出了一个案例研究来证明我们框架的可靠性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号