A verification framework for access control in dynamic web applications

Manar H. Alalfi, James R. Cordy, Thomas Roy Dean · 2009

This paper proposes a security analysis framework for dynamic web applications. A reverse engineering process is performed over a dynamic web application to extract a role-based access control security model. A formal analysis is applied on the recovered model to check access control security properties. This framework can be used to verify that a dynamic web application conforms to access control polices specified by a security engineer.

Read the paper · More papers on PaperTik