Skip to main navigation Skip to search Skip to main content

Test-driven assessment of access control in legacy applications

  • Technopôle Brest-Iroise
  • ETH Zürich
  • IRISA

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

33 Scopus citations

Abstract

If access control policy decision points are not neatly separated from the business logic of a system, the evolution of a security policy likely leads to the necessity of changing the system's code base. This is often the case with legacy systems. We present a test-driven methodology to assess the flexibility of a system, a property that describes the degree of coupling between the access control logic and the business logic of a system. A low flexibility indicates that a modification of the policy will lead to substantial changes of the code. In this paper, we analyze the notion of flexibility which is related to the presence of hidden and implicit security mechanisms in the business logic. We detail how testing can be used for detecting such mechanisms and how it may drive the incremental evolution of a security policy. We use several case studies to illustrate and validate the methodology.

Original languageEnglish
Title of host publicationProceedings of the 1st International Conference on Software Testing, Verification and Validation, ICST 2008
Pages238-247
Number of pages10
DOIs
StatePublished - 2008
Externally publishedYes
Event1st International Conference on Software Testing, Verification and Validation, ICST 2008 - Lillehammer, Norway
Duration: 9 Apr 200811 Apr 2008

Publication series

NameProceedings of the 1st International Conference on Software Testing, Verification and Validation, ICST 2008

Conference

Conference1st International Conference on Software Testing, Verification and Validation, ICST 2008
Country/TerritoryNorway
CityLillehammer
Period9/04/0811/04/08

Fingerprint

Dive into the research topics of 'Test-driven assessment of access control in legacy applications'. Together they form a unique fingerprint.

Cite this