面向组件接口的XACML变异测试策略

Component Interface -Oriented XACMLMutation Testing Policies

  • 摘要: XACML是一种适用于各种信息资源保护的访问控制语言。由于其严格的语法规范,且具有多种平台之间的可移植性,非常适用于各种组件交互的安全管理。借助该访问控制语言提出的一种面向组件的三层访问控制方法,组件交互、接口调用和参数访问都能实现安全控制。在该基础上设计了相应的变异测试策略,规则变异可以导致策略变异,策略变异可以导致整个策略集的变异;反之亦然。通过测试具体实例与验证其语义模型,该测试策略为组件访问及交互提供了安全保障。

     

    Abstract: A kind of three level access control policy towards component is presented by extensible access control markup language (XACML) for the protection of component interaction, interface invocation, and parameters access. Based on this policy, the mutation test strategies are designed: policy mutations follow policy mutations, policyset mutations follow policy mutations, and vice versa. Both the case study and semantical verification shows that the access control of component interface and interactions can be tested by XACML mutation policies.

     

/

返回文章
返回