2008 International Conference on Software Testing, Verification, and Validation
Model-Based Tests for Access Control Policies
April 09-April 11
ISBN: 978-0-7695-3127-4
We present a model-based approach to testing access control requirements. By using combinatorial testing, we first automatically generate test cases from and without access control policies—i.e., the model—and assess the effectiveness of the test suites by means of mutation testing. We also compare them to purely random tests. For some of the investigated strategies, non-random tests kill considerably more mutants thanthe same number of random tests. Since we rely on policies only, no information on the application is required at this stage. As a consequence, our methodology applies to arbitrary implementations of the policy decision points.
Index Terms:
Access Control, Model-Based Testing, Mutation Testing, Combinatorial Testing
Citation:
Alexander Pretschner, Tejeddine Mouelhi, Yves Le Traon, "Model-Based Tests for Access Control Policies," icst, pp.338-347, 2008 International Conference on Software Testing, Verification, and Validation, 2008