Similarity testing for role-based access control systems

Sociedade Brasileira de Computacao - SB - Tập 6 - Trang 1-37 - 2018
Carlos Diego N. Damasceno1,2, Paulo C. Masiero1,2, Adenilso Simao1,2
1Institute of Mathematics and Computer Science, University of Sao Paulo (ICMC-USP), Sao Carlos-SP, Brazil
2Software Engineering Laboratory – LabES, Sao Carlos-SP, Brazil

Tóm tắt

Access control systems demand rigorous verification and validation approaches, otherwise, they can end up with security breaches. Finite state machines based testing has been successfully applied to RBAC systems and enabled to obtain effective test cases, but very expensive. To deal with the cost of these test suites, test prioritization techniques can be applied to improve fault detection along test execution. Recent studies have shown that similarity functions can be very efficient at prioritizing test cases. This technique is named similarity testing and assumes the hypothesis that resembling test cases tend to have similar fault detection capabilities. Thus, there is no gain from similar test cases, and fault detection ratio can be improved if test diversity increases. In this paper, we propose a similarity testing approach for RBAC systems named RBAC similarity and compare to simple dissimilarity and random prioritization. RBAC similarity combines the dissimilarity degree of pairs of test cases with their relevance to the RBAC policy under test to maximize test diversity and the coverage of its constraints. Five RBAC policies and fifteen test suites were prioritized using each of the three test prioritization techniques and compared using the Average Percentage Faults Detected metric. Our results showed that the combination of the dissimilarity degree to the relevance of a test case to RBAC policies in the RBAC similarity can be more effective than random prioritization and simple dissimilarity, by itself, in most of the cases. The RBAC similarity criterion is suitable as a test prioritization criteria for test suites generated from finite state machine models specifying RBAC systems.

Tài liệu tham khảo

Andrews, JH, Briand LC, Labiche Y, Namin AS (2006) Using mutation analysis for assessing and comparing testing coverage criteria. IEEE Trans Softw Eng. 32(8):608–624. https://doi.org/10.1109/TSE.2006.83. ANSI (2004) Role based access control. Technical report, American National Standards Institute, Inc.ANSI/INCITS 359-2004. Arcuri, A, Briand L (2011) A practical guide for using statistical tests to assess randomized algorithms in software engineering In: Proceedings of the 33rd International Conference on Software Engineering. ICSE ’11, 1–10.. ACM, New York, NY, USA. https://doi.org/10.1145/1985793.1985795. http://doi.acm.org/10.1145/1985793.1985795. Ben Fadhel, A, Bianculli D, Briand L (2015) A comprehensive modeling framework for role-based access control policies. J Syst Softw. 107(C):110–126. https://doi.org/10.1016/j.jss.2015.05.015. Bertolino, A, Daoudagh S, Kateb DE, Henard C, Traon YL, Lonetti F, Marchetti E, Mouelhi T, Papadakis M (2015) Similarity testing for access control. Inf Softw Technol. 58:355–372. https://doi.org/10.1016/j.infsof.2014.07.003. Broy, M, Jonsson B, Katoen JP, Leucker M, Pretschner A (2005) Model-Based Testing of Reactive Systems: Advanced Lectures (Lecture Notes in Computer Science). Springer, Secaucus, NJ, USA. Cartaxo, EG, Machado PDL, Neto FGO (2011) On the use of a similarity function for test case selection in the context of model-based testing. Softw Test Verif Reliab. 21(2):75–100. https://doi.org/10.1002/stvr.413. Chow, TS (1978) Testing software design modeled by finite-state machines. IEEE Trans Softw Eng. 4(3):178–187. https://doi.org/10.1109/TSE.1978.231496. Cohen, J (1977) Statistical Power Analysis for the Behavioral Sciences. Revised edn.. Academic Press, New York. https://doi.org/10.1016/B978-0-12-179060-8.50001-3. https://www.sciencedirect.com/science/article/pii/B9780121790608500013. Cohen, J (1992) A power primer. Psychol Bull. 112(1):155–159. https://doi.org/10.1037/0033-2909.112.1.155. Coutinho, AEVB, Cartaxo EG, Machado PDdL (2014) Analysis of distance functions for similarity-based test suite reduction in the context of model-based testing. Softw Qual J.1–39. https://doi.org/10.1007/s11219-014-9265-z. Damasceno, CDN, Masiero PC, Simao A (2016) Evaluating test characteristics and effectiveness of fsm-based testing methods on rbac systems In: Proceedings of the 30th Brazilian Symposium on Software Engineering. SBES ’16, 83–92.. ACM, New York, NY, USA. https://doi.org/10.1145/2973839.2973849. http://doi.acm.org/10.1145/2973839.2973849. Elbaum, S, Malishevsky AG, Rothermel G (2000) Prioritizing test cases for regression testing. SIGSOFT Softw Eng Notes. 25(5):102–112. https://doi.org/10.1145/347636.348910. Elbaum, S, Malishevsky AG, Rothermel G (2002) Test case prioritization: A family of empirical studies. IEEE Trans Softw Eng. 28(2):159–182. https://doi.org/10.1109/32.988497. Endo, AT, Simao A (2013) Evaluating test suite characteristics, cost, and effectiveness of fsm-based testing methods. Inf Softw Technol. 55(6):1045–1062. https://doi.org/10.1016/j.infsof.2013.01.001. Fabbri, SCPF, Delamaro ME, Maldonado JC, Masiero PC (1994) Mutation analysis testing for finite state machines In: Software Reliability Engineering, 1994. Proceedings., 5th International Symposium On, 220–229. https://doi.org/10.1109/ISSRE.1994.341378. Felderer, M, Zech P, Breu R, Büchler M, Pretschner A (2015) Model-based security testing: a taxonomy and systematic classification. Softw Test Verif Reliab. https://doi.org/10.1002/stvr.1580. Ferraiolo, DF, Kuhn RD, Chandramouli R (2007) Role-Based Access Control. 2nd edn. Artech House, Inc., Norwood, MA, USA. Gill, A (1962) Introduction to the Theory of Finite State Machines. McGraw-Hill, New York. Gîză-Belciug, F, Pentiuc SG (2015) Parallelization of similarity matrix calculus in ontology mapping systems In: 2015 14th RoEduNet International Conference - Networking in Education and Research (RoEduNet NER), 50–55. https://doi.org/10.1109/RoEduNet.2015.7311827. Hedges, LV (1981) Distribution theory for glass’s estimator of effect size and related estimators. J Educ Stat. 6(2):107–128. https://doi.org/10.3102/10769986006002107. https://doi.org/10.3102/10769986006002107. Henard, C, Papadakis M, Perrouin G, Klein J, Heymans P, Traon YL (2014) Bypassing the combinatorial explosion: Using similarity to generate and prioritize t-wise test configurations for software product lines. IEEE Trans Softw Eng. 40(7):650–670. https://doi.org/10.1109/TSE.2014.2327020. arXiv:1211.5451v1. Jang-Jaccard, J, Nepal S (2014) A survey of emerging threats in cybersecurity. J Comput Syst Sci 80(5):973–993. https://doi.org/10.1016/j.jcss.2014.02.005. Special Issue on Dependable and Secure Computing. Jia, Y, Harman M (2011) An analysis and survey of the development of mutation testing. Softw Eng IEEE Trans. 37(5):649–678. https://doi.org/10.1109/TSE.2010.62. Kampenes, VB, Dyb T, Hannay JE, Sjberg DIK (2007) A systematic review of effect size in software engineering experiments. Inf Softw Technol. 49(11):1073–1086. https://doi.org/10.1016/j.infsof.2007.02.015. Masood, A, Bhatti R, Ghafoor A, Mathur AP (2009) Scalable and effective test generation for role-based access control systems. IEEE Trans Softw Eng. 35(5):654–668. https://doi.org/10.1109/TSE.2009.35. Masood, A, Ghafoor A, Mathur AP (2010) Fault coverage of constrained random test selection for access control: A formal analysis. J Syst Softw. 83(12):2607–2617. TAIC PART 2009 - Testing: Academic & Industrial Conference - Practice And Research Techniques. McMinn, P (2004) Search-based software test data generation: A survey: Research articles. Softw Test Verif Reliab. 14(2):105–156. https://doi.org/10.1002/stvr.v14:2. Mouelhi, T, Kateb DE, Traon YL (2015) Chapter five - inroads in testing access control, Advances in Computers, vol. 99. Elsevier. https://doi.org/10.1016/bs.adcom.2015.04.003. http://www.sciencedirect.com/science/article/pii/S0065245815000327. OASIS (2013) eXtensible Access Control Markup Language (XACML) Version 3.0. Technical report, Organization for the Advancement of Structured Information Standards (OASIS). http://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.pdf. OASIS (2014) XACML v3.0 Core and Hierarchical Role Based Access Control (RBAC) Profile Version 1.0. http://docs.oasis-open.org/xacml/3.0/rbac/v1.0/cs02/xacml-3.0-rbac-v1.0-cs02.pdf. Ouriques, JaFS (2015) Strategies for prioritizing test cases generated through model-based testing approaches In: Proceedings of the 37th International Conference on Software Engineering - Volume 2. ICSE ’15, 879–882.. IEEE Press, Piscataway, NJ, USA. http://dl.acm.org/citation.cfm?id=2819009.2819204. Petrenko, A, Bochmann GV (1995) Selecting test sequences for partially-specified nondeterministic finite state machines. In: Luo G (ed)7th IFIP WG 6.1 International Workshop on Protocol Test Systems. IWPTS ’94, 95–110.. Chapman and Hall, Ltd., London, UK. http://dl.acm.org/citation.cfm?id=236187.233118. Rawald, T, Sips M, Marwan N, Leser U (2015) Massively parallel analysis of similarity matrices on heterogeneous hardware In: Proceedings of the Workshops of the EDBT/ICDT 2015 Joint Conference (EDBT/ICDT), Brussels, Belgium, March 27th, 2015, 56–62.. CEUR-WS, Brussels. Samarati, P, de Vimercati SC (2001) Access Control: Policies, Models, and Mechanisms(Focardi R, Gorrieri R, eds.). Springer, Berlin, Heidelberg. http://dx.doi.org/10.1007/3-540-45608-2_3. Simão, A, Petrenko A, Yevtushenko N (2009) Generating Reduced Tests for FSMs with Extra States. In: Núñez M, Baker P, Merayo MG (eds), 129–145.. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-642-05031-2_9. http://dx.doi.org/10.1007/978-3-642-05031-2_9. Torchiano, M (2017) Effsize: Efficient Effect Size Computation (v. 0.7.1). CRAN package repository. https://cran.r-project.org/web/packages/effsize/effsize.pdf. CRAN package repository. [Online; accessed 20-November-2017]. Utting, M, Pretschner A, Legeard B (2012) A taxonomy of model-based testing approaches. Softw Test Verif Reliab. 22(5):297–312. https://doi.org/10.1002/stvr.456. Vargha, A, Delaney HD (2000) A critique and improvement of the cl common language effect size statistics of mcgraw and wong. J Educ Behav Stat. 25(2):101–132. https://doi.org/10.3102/10769986025002101. https://doi.org/10.3102/10769986025002101. Vasilevskii, MP (1973) Failure diagnosis of automata. Cybernetics 9(4):653–665. https://doi.org/10.1007/BF01068590. Wohlin, C, Runeson P, Höst M, Ohlsson MC, Regnell B, Wesslén A (2012) Measurement. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-642-29044-2_3. Yoo, S, Harman M (2012) Regression testing minimization, selection and prioritization: A survey. Softw Test Verif Reliab. 22(2):67–120. https://doi.org/10.1002/stv.430. Zhang, YF, Tian YC, Kelly W, Fidge C (2017) Scalable and efficient data distribution for distributed computing of all-to-all comparison problems. Futur Gener Comput Syst. 67:152–162.