Towards model-driven development of access control policies for web applications

  • Authors:
  • Marianne Busch;Nora Koch;Massimiliano Masi;Rosario Pugliese;Francesco Tiezzi

  • Affiliations:
  • LMU München, Munich, Germany;LMU München, Munich, Germany;Tiani "Spirit" GmbH, Vienna, Austria;Università di Firenze, Firenze, Italy;IMT Advanced Studies Lucca, Lucca, Italy

  • Venue:
  • Proceedings of the Workshop on Model-Driven Security
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

We introduce a UML-based notation for graphically modeling systems' security aspects in a simple and intuitive way and a model-driven process that transforms graphical specifications of access control policies in XACML. These XACML policies are then translated in FACPL, a policy language with a formal semantics, and the resulting policies are evaluated by means of a Java-based software tool.