Security policy testing via automated program code generation

Ting Yu, Dhivya Sivasubramanian, Tao Xie

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

In this paper, we have presented a new general framework for policy esting via automated program code generation. This framework allows to easily reuse existing software testing techniques and tools to ensure the correctness of security policies. We have demonstrated the effectiveness of the proposed approach by empirically comparing it with an existing policy testing tool specifically designed for XACML. In future work, we plan to further evaluate the effectiveness of our approach by applying it to other policy languages such as Ponder [2]. We also plan to adapt our approach to handel stateful policies such as those for managing roles in RBAC and stateful firewall policies.

Original languageEnglish (US)
Title of host publicationCSIIRW09
Subtitle of host publicationFifth Annual Cyber Security and Information Intelligence Research Workshop: Cyber Security and Information Intelligence Challenges and Strategies
DOIs
StatePublished - 2009
Externally publishedYes
EventCSIIRW 2009: 5th Annual Cyber Security and Information Intelligence Research Workshop: Cyber Security and Information Intelligence Challenges and Strategies - Oak Ridge, TN, United States
Duration: Apr 13 2009Apr 15 2009

Publication series

NameACM International Conference Proceeding Series

Other

OtherCSIIRW 2009: 5th Annual Cyber Security and Information Intelligence Research Workshop: Cyber Security and Information Intelligence Challenges and Strategies
Country/TerritoryUnited States
CityOak Ridge, TN
Period4/13/094/15/09

ASJC Scopus subject areas

  • Software
  • Human-Computer Interaction
  • Computer Vision and Pattern Recognition
  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Security policy testing via automated program code generation'. Together they form a unique fingerprint.

Cite this