Selection of regression system tests for security policy evolution

  • Authors:
  • JeeHyun Hwang;Tao Xie;Donia El Kateb;Tejeddine Mouelhi;Yves Le Traon

  • Affiliations:
  • North Carolina State University, USA;North Carolina State University, USA;University of Luxembourg, Luxembourg;University of Luxembourg, Luxembourg;University of Luxembourg, Luxembourg

  • Venue:
  • Proceedings of the 27th IEEE/ACM International Conference on Automated Software Engineering
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

As security requirements of software often change, developers may modify security policies such as access control policies (policies in short) according to evolving requirements. To increase confidence that the modification of policies is correct, developers conduct regression testing. However, rerunning all of existing system test cases could be costly and time-consuming. To address this issue, we develop a regression-test-selection approach, which selects every system test case that may reveal regression faults caused by policy changes. Our evaluation results show that our test-selection approach reduces a substantial number of system test cases efficiently.