Pseudo-Exhaustive Testing of Attribute Based Access Control Rules
D. Richard Kuhn, Vincent C. Hu, David F. Ferraiolo, Raghu N. Kacker, Yu Lei · 2016
Access control typically requires translating policies or rules given in natural language into a form such as a programming language or decision table, which can be processed by an access control system. Once rules have been described in machine-processable form, testing is necessary to ensure that the rules are implemented correctly. This paper describes an approach based on combinatorial test methods for efficiently testing access control rules, using the structure of attribute based access control (ABAC) to detect a large class of faults without a conventional test oracle.