Automatic Testing of Access Control for Security Properties - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2009

Automatic Testing of Access Control for Security Properties

Résumé

In this work, we investigate the combination of controller synthesis and test generation techniques for the testing of open, partially observable systems with respect to security policies. We consider two kinds of properties: integrity properties and confidentiality properties. We assume that the behavior of the system is modeled by a labeled transition system and assume the existence of a black-box implementation. We first outline a method allowing to automatically compute an ideal access control ensuring these two kinds of properties. Then, we show how to derive testers that test the conformance of the implementation with respect to its specification, the correctness of the real access control that has been composed with the implementation in order to ensure a security property, and the security property itself.
Fichier principal
Vignette du fichier
testcom-paper-13.pdf (227.9 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

inria-00420424 , version 1 (23-04-2010)

Identifiants

Citer

Hervé Marchand, Jérémy Dubreil, Thierry Jéron. Automatic Testing of Access Control for Security Properties. TESTCOM/FATES 2009, Nov 2009, Eindhoven, Netherlands. pp.113-128, ⟨10.1007/978-3-642-05031-2⟩. ⟨inria-00420424⟩
76 Consultations
94 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More