A Formal Equivalence Classes Based Method for Security Policy Conformance Checking - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2012

A Formal Equivalence Classes Based Method for Security Policy Conformance Checking

Eckehard Hermann
  • Fonction : Auteur
  • PersonId : 1010595
Udo Litschauer
  • Fonction : Auteur
  • PersonId : 1010596
Jürgen Fuss
  • Fonction : Auteur
  • PersonId : 1010597

Résumé

Different security policy models have been developed and published in the past. Proven security policy models, if correctly implemented, guarantee the protection of data objects from unauthorized access or usage or prevent an illegal information flow. To verify that a security policy model has been correctly implemented, it is important to define and execute an exhaustive list of test cases, which verify that the formal security policy neither has been over-constrained nor under-constrained. In this paper we present a method for defining an exhaustive list of test cases, based on formally described equivalence classes that are derived from the formal security policy description.
Fichier principal
Vignette du fichier
978-3-642-32498-7_12_Chapter.pdf (300.9 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01542451 , version 1 (19-06-2017)

Licence

Paternité

Identifiants

Citer

Eckehard Hermann, Udo Litschauer, Jürgen Fuss. A Formal Equivalence Classes Based Method for Security Policy Conformance Checking. International Cross-Domain Conference and Workshop on Availability, Reliability, and Security (CD-ARES), Aug 2012, Prague, Czech Republic. pp.146-160, ⟨10.1007/978-3-642-32498-7_12⟩. ⟨hal-01542451⟩
183 Consultations
107 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More