Assessing Quality of Policy Properties in Verification of Access Control Policies

Assessing Quality of Policy Properties in Verification of Access Control Policies
复制标题

评估访问控制策略验证中策略属性的质量

DOI:
--
复制
发表时间:
2008
期刊:
Asia-Pacific Computer Systems Architecture Conference
影响因子:
--
通讯作者:
Vincent C. Hu
Vincent C. Hu
中科院分区:
--
文献类型:
--
作者:
Evan Martin;JeeHyun Hwang;Tao Xie;Vincent C. Hu

文献摘要

被引文献

相似文献

访问控制策略通常用声明性语言来指定。在本文中,我们提出了一种新的方法,称为突变验证,以评估指定的政策,并在这样做,验证本身的质量的属性的质量。在我们的方法中,给定一个策略和一组属性,我们首先对策略进行变异以生成各种突变策略,每个策略都有一个种子错误。然后,我们验证属性是否适用于每个突变策略。如果属性对于给定的突变策略仍然成立,则这些属性的质量被确定为不足以防止种子故障,指示需要更多的属性来扩充现有的属性集合以提供策略正确性的更高置信度。我们已经实现了Mutaver,XACML的突变验证工具,并将其应用于现实世界的软件系统的政策和属性。
Access control policies are often specified in declarative languages. In this paper, we propose a novel approach, called mutation verification, to assess the quality of properties specified for a policy and, in doing so, the quality of the verification itself. In our approach, given a policy and a set of properties, we first mutate the policy to generate various mutant policies, each with a single seeded fault. We then verify whether the properties hold for each mutant policy. If the properties still hold for a given mutant policy, then the quality of these properties is determined to be insufficient in guarding against the seeded fault, indicating that more properties are needed to augment the existing set of properties to provide higher confidence of the policy correctness. We have implemented Mutaver, a mutation verification tool for XACML, and applied it to policies and properties from a real-world software system.