ACPT- Access Control Policy Testing SystemNational Institute .ppt
《ACPT- Access Control Policy Testing SystemNational Institute .ppt》由会员分享,可在线阅读,更多相关《ACPT- Access Control Policy Testing SystemNational Institute .ppt(25页珍藏版)》请在麦多课文档分享上搜索。
1、,ACPT: Access Control Policy Testing System National Institute of Standards and Technology Department of Computer Science North Carolina State University,Presenter: Prof. Tao Xie,ACPT Overview,Model Constructioncomposing and combining access control (AC) models (e.g., Multi-Level, RBAC )Model Verifi
2、cationverifying AC models against given propertiesImplementation Testing testing AC implementation,Model Construction,Composing and Combining AC models (e.g., Multi-Level and RBAC)Support mandatory AC models (e.g., Multi-Level and RBAC) popularly used in practice Ensure safety (i.e., absence of leak
3、age) and flexibility in composing and combining mandatory AC models and rules Allow to use combination algorithms such as first-applicable, deny-overrides, permit-overrides,Model Verification,Verifying AC models against given propertiesAC models can include a large number of attributes (e.g., roles,
4、 objects, clearance) Conflicts among entities and their complexity may lead to misconfigurationsDetect discrepancies between AC models and their intended function (specified as properties) Property verification is to check if AC models satisfy given properties (e.g., via model checking),Implementati
5、on Testing,Testing AC implementations for implementation faultsGenerate test suite (access requests) based on AC models and propertiesEvaluate generated test suite against AC implementations to find faultsGenerated test suites can be applied to any AC implementations in deployment,Model verification
6、,GUI,Implementation testing,AC Model Templates: Multi-Level, RBAC, Workflow, Chinese Wall, ,AC Models/Rules,Test Suite,ACPT System Architecture,Model construction,AC Properties,AC Implementations,GoalsModel verification- Model/rule correctnessImplementation testing- Implementation conformance,e.g.,
7、model checker,e.g., combinatorial tester,Model Construction,Allow to compose mandatory AC models (as well as AC rules) through pre-defined model templates Multi-Level, RBAC, Workflow, Chinese Wall modelsAllow to specify model details by assigning attribute values e.g., role subjects, resources, and
8、actions for RBACAllow to combine different AC models or rules specifying model (or rule) priority for combining models or rules, e.g., combine Multi-Level with RBAC models,Model Verification,Conduct model verification to assure AC safety in composed/combined models Convert composed/combined models a
9、nd user-specified properties to input models and properties of a verification tool (e.g., a model checker)Verify models against specified properties, and report detected property violations,Assure AC implementation conformance by evaluating generated access requests Test Generation: generate access
10、requests (based on models/properties) Test Execution: evaluate requests (against AC implementation) and produce their decisions Test-Result Evaluation: check if the decisions are consistent with expected decisions (from properties or manual inspection, etc.) If inconsistent, review implementation fa
11、ults,Implementation Testing,Expected Decisions,Decisions,Access Requests,AC Implementation,Combinatorial Test Generation,Exhaustive testing is impractical (esp. when manual effort needed for test-result inspection) Need to generate a small test suite with high fault-detection capabilityExploit NIST
12、Advanced Combinatorial Testing Suite (ACTS): collect domain variables in AC models and generate efficient test suite automatically to detect faults, with inputs: a domain of variables outputs: t-way covering arrays as tests,Combinatorial Test Generation Example,For example, domain of variables: 2 su
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
2000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ACPTACCESSCONTROLPOLICYTESTINGSYSTEMNATIONALINSTITUTEPPT

链接地址:http://www.mydoc123.com/p-377998.html