Selective Regression Test for Access Control System Employing RBAC

Chao Huang,Jianling Sun,Xinyu Wang,Yuanjie Si
DOI: https://doi.org/10.1007/978-3-642-02617-1_8
2009-01-01
Abstract:To provide a selective regression test method for the access control systems which employ role based access control (RBAC) policy. Access control regression test is always tedious and error-prone for financial systems involving complicated constraints, like separation of duty and cardinality constraints. We give the formal definition of RBAC policy change then we propose a test selection framework via policy change and change propagation analysis. Our method provides the confidence that it's only necessary to exercise the selected test cases to guarantee the access control of the system is not broken for the new release. We also describe SACRT, an access control regression test tool which realizes our framework. According to our practical application experience in the realistic financial systems, SACRT demonstrates the effectiveness in reducing the size of the access control regression test suite.
What problem does this paper attempt to address?