Test Case Generation for Access Control Based on UML Activity Diagram

Ao Fan, Li Liao, Lulu Wang, Bixin Li · 2024

Access control is a vital component of information system security, ensuring that resources are only accessible to authorized users with specific permissions. However, traditional testing methods still face challenges when solving complex access control scenarios, such as third-party login and authorization/authentication. To address these challenges, this paper presents a method for generating access control test cases based on UML activity diagrams. The method focuses on two key scenarios in access control: third-party login and authorization/authentication. For the third-party login scenario, the method incorporates the OAuth 2.0 protocol and conducts a detailed analysis of security issues associated with third-party login processes. For the authorization and authentication scenario, the method models the permission control workflow and performs a comprehensive parse and traversal of the activity diagram structure. Lastly, an empirical study utilizing seven distinct combinations of third-party login and two widely used authentication frameworks provides successful validation of the proposed method. This validation demonstrates the significant impact of the method in uncovering seven specific security issues. Furthermore, the method exhibits efficient problem identification capabilities for potential vulnerabilities within the authorization authentication system. It effectively exposes three types of security flaws that are commonly difficult to detect.

Read the paper · More papers on PaperTik