Towards a Theory on Testing XACML Policies

Towards a Theory on Testing XACML Policies
复制标题

DOI:
10.1145/3532105.3535031
复制
发表时间:
2022-06
期刊:
Proceedings of the 27th ACM on Symposium on Access Control Models and Technologies
影响因子:
--
通讯作者:
Dianxiang Xu;Roshan Shrestha;Ning Shen;Yunpeng Zhang
Dianxiang Xu;Roshan Shrestha;Ning Shen;Yunpeng Zhang
中科院分区:
其他
文献类型:
--
作者:
Dianxiang Xu;Roshan Shrestha;Ning Shen;Yunpeng Zhang

文献摘要

相似文献

策略测试是保证访问控制策略质量的重要手段。对XACML策略测试方法的实验研究表明了它们不同程度的有效性。然而,对于为什么它们无法检测到某些类型的故障缺乏解释。目前还不清楚什么是故障检测能力的基本要素。为了解决这个问题,我们提出了一个理论,通过形式化的故障检测条件方面的全面故障模型的XACML政策的政策测试。由可达性、必要性和传播约束组成的策略故障检测条件是揭示故障的充分必要条件。形式化的故障检测条件可以量化测试方法的内在优势和局限性。我们已经应用了形式化的定性评估的五个测试方法的当前版本的XACML标准。结果表明,对于每种方法,有一定类型的故障,可以总是或永远不会被发现,而其他故障的检测可能取决于特定的策略结构。
Policy testing is an important means for quality assurance of access control policies. Experimental studies on the testing methods of XACML policies have shown their varying levels of effectiveness. However, there is a lack of explanation for why they are unable to detect certain types of faults. It is unclear what is essential to the fault detection capability. To address this issue, we propose a theory on policy testing by formalizing the fault detection conditions with respect to a comprehensive fault model of XACML policies. The detection condition of a policy fault, composed of the reachability, necessity, and propagation constraints, is sufficient and necessary for revealing the fault. The formalized fault detection conditions can qualify the inherent strengths and limitations of testing methods. We have applied the formalization to the qualitative evaluations of five testing methods for the current version of the XACML standard. The results show that, for each method, there are certain types of faults that can always or never be revealed, while the detection of other faults may depend on the particular policy structure.