Sorry, you do not have access to this eBook
A subscription is required to access the full text content of this book.
As software systems become more and more complex, and are deployed to manage a large amount of sensitive information and resources, specifying and managing correct access control policies is critical and yet challenging. Policy testing is an important means to increasing confidence in the correctness of specified policies and their implementations for access control. There are two types of policy testing. In the first type, the artifacts under test are policy specifications and the main testing goal is to assure the correctness of the policy specifications. In the second type, the artifacts under test are policy implementations and the main testing goal is to assure the conformance between the policy specifications and implementations. Both types of policy testing supply typical test inputs (requests) to the artifacts under test and subsequently check test outputs (responses) against expected ones. This entry presents recent approaches on policy testing in five main categories: fault models, testing criteria, test generation, test oracles, and model‐based testing.
A subscription is required to access the full text content of this book.
Other ways to access this content: