U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.


Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Conference Proceedings

Pseudo-Exhaustive Testing of Attribute Based Access Control Rules

Published: April 11, 2016


Richard Kuhn (NIST), Vincent Hu (NIST), David Ferraiolo (NIST), Raghu Kacker (NIST), Yu Lei (UTSA)


Name: Fifth International Workshop on Combinatorial Testing (IWCT 2016)
Dates: April 11-15, 2016
Location: Chicago, Illinois, United States
Citation: Proceedings of the 2016 IEEE International Conference on Software Testing, Verification and Validation Workshops (ICSTW), pp. 51-58


Access control typically requires translating policies or rules given in natural language into a form such as a programming language or decision table, which can be processed by an access control system. Once rules have been described in machine-processable form, testing is necessary to ensure that the rules are implemented correctly. This paper describes an approach based on combinatorial test methods for efficiently testing access control rules, using the structure of attribute based access control (ABAC) to detect a large class of faults without a conventional test oracle.



test automation; access control; attribute based access control; combinatorial testing; t-way testing
Control Families

Access Control


Conference Proceedings (DOI)

Supplemental Material:
Preprint (pdf)

Document History:
04/11/16: Conference Proceedings (Final)