A framework for testing and monitoring security policies: application to an electronic voting system - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue The Computer Journal Année : 2018

A framework for testing and monitoring security policies: application to an electronic voting system

Résumé

Testing and monitoring the effectiveness of security policies under pervasive system architectures is still a major challenging problem for the research community as well as industrials. The inherent characteristics of these systems such as the heterogeneous communicating devices and the multiple used technologies make the burden more overwhelming when dealing with security measures and policies. This paper aims to bridge this gap through the introduction of a formal design of security policies to make security monitoring operation more efficient. Hence, a formal framework is proposed to actively test web-based systems, as an example of these pervasive architectures. The goal of our technique is to check the compliance of the targeted web application to a set of generic security requirements such as confidentiality, integrity and availability as well as to a set of user-related security constraints. Our approach has been applied to a real industrial electronic voting application provided by the Scytl company. Several experiments show the merit of our technique in verifying the correctness of security measures of the targeted application. This framework is part of the INTER-TRUST solution intended to ensure secure inter-operation between communicating systems and provide solutions to test and monitor them
Fichier non déposé

Dates et versions

hal-02017364 , version 1 (13-02-2019)

Identifiants

Citer

Khalifa Toumi, Mohamed Aouadi, Ana Rosa Cavalli, Wissam Mallouli, Jordi Puiggali Allepuz, et al.. A framework for testing and monitoring security policies: application to an electronic voting system. The Computer Journal, 2018, 61 (8), pp.1109 - 1122. ⟨10.1093/comjnl/bxy018⟩. ⟨hal-02017364⟩
39 Consultations
0 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More