Sciweavers

IEEEARES
2010
IEEE

Supporting Authorization Policy Modification in Agile Development of Web Applications

13 years 9 months ago
Supporting Authorization Policy Modification in Agile Development of Web Applications
Web applications are increasingly developed in Agile development processes. Business-centric Web applications need complex authorization policies to securely implement business processes. As part of the Agile process, integrating domain experts into the development of RBAC authorization policies improves the policies, but remains difficult. For policy modifications, high numbers of options need to be considered. To ease the management task and integrate domain experts, we propose an algorithm and prototype tool. The AI-based changesupport algorithm helps to find the suitable modification actions according to desired changes that are given in policy test cases. We also present a prototype GUI for domain experts to employ the algorithm and report on early results of nonsecurity experts using the tool in a real-world business Web application. Keywords-Agile Development; Authorization Policy Development; Policy Change Management; Change-Impact Analysis
Steffen Bartsch
Added 02 Aug 2010
Updated 02 Aug 2010
Type Conference
Year 2010
Where IEEEARES
Authors Steffen Bartsch
Comments (0)