Résumé In this work, we investigate the use of test generation and controller synthesis techniques for the testing of security policies. We assume the existence of a model of the system and consider two kinds of properties : integrity properties and confidentiality properties. We first outline the methodology allowing to automatically compute access controls ensuring these two kinds of properties. We then show how to derive testers that not only test the security properties and the conformance of the implementation, but try to test the access controls that have been plugged with the implementation in order to ensure security properties.
Auteurs Jérémy Dubreil, Thierry Jéron, and Hervé Marchand
INRIA Rennes - Bretagne Atlantique