Security policy testing via automated program code generation

Ting Yu*, Dhivya Sivasubramanian, Tao Xie

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Citations (Scopus)

Abstract

In this paper, we have presented a new general framework for policy esting via automated program code generation. This framework allows to easily reuse existing software testing techniques and tools to ensure the correctness of security policies. We have demonstrated the effectiveness of the proposed approach by empirically comparing it with an existing policy testing tool specifically designed for XACML. In future work, we plan to further evaluate the effectiveness of our approach by applying it to other policy languages such as Ponder [2]. We also plan to adapt our approach to handel stateful policies such as those for managing roles in RBAC and stateful firewall policies.

Original languageEnglish
Title of host publicationCSIIRW09
Subtitle of host publicationFifth Annual Cyber Security and Information Intelligence Research Workshop: Cyber Security and Information Intelligence Challenges and Strategies
DOIs
Publication statusPublished - 2009
Externally publishedYes
EventCSIIRW 2009: 5th Annual Cyber Security and Information Intelligence Research Workshop: Cyber Security and Information Intelligence Challenges and Strategies - Oak Ridge, TN, United States
Duration: 13 Apr 200915 Apr 2009

Publication series

NameACM International Conference Proceeding Series

Conference

ConferenceCSIIRW 2009: 5th Annual Cyber Security and Information Intelligence Research Workshop: Cyber Security and Information Intelligence Challenges and Strategies
Country/TerritoryUnited States
CityOak Ridge, TN
Period13/04/0915/04/09

Fingerprint

Dive into the research topics of 'Security policy testing via automated program code generation'. Together they form a unique fingerprint.

Cite this