Said Daoudagh

dblp:60/11428 · DBLP profile ↗
← Back
19ranked-venue papers
11as first author
8since 2021 · last 2026
0000-0002-3073-6217ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 11 · 6 first-author · 3 since 2021Security and privacy · 4 · 4 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 From User Stories to Movement Features: A Requirements-Driven Approach to Pose-Based Dance Movement Analysis
Said Daoudagh, Giacomo Ignesti, Davide Moroni, Laura Sebastiani, Paolo Paradisi
ICSOFT1
2024 Assessment of Dance Movement Therapy Outcomes: A Preliminary Proposal
Said Daoudagh, Giacomo Ignesti, Davide Moroni, Laura Sebastiani, Paolo Paradisi
CHIRA (2)1
2024 Human-Centric Dev-X-Ops Process for Trustworthiness in AI-Based Systems
Antonello Calabrò, Said Daoudagh, Eda Marchetti, Oum-El-Kheir Aktouf, Annabelle Mercier
WEBIST2
2023 An automated framework for continuous development and testing of access control systems
abstract
Abstract Automated testing in DevOps represents a key factor for providing fast release of new software features assuring quality delivery. In this paper, we introduce DOXAT, an automated framework for continuous development and testing of access control mechanisms based on the XACML standard. It leverages mutation analysis for the selection and assessment of the test strategies and provides automated facilities for test oracle definition, test execution, and results analysis, in order to speedup and automate the Plan, Code, Build, and Test phases of DevOps process. We show the usage of the framework during the planning and testing phases of the software development cycle of a PDP example.
Said Daoudagh, Francesca Lonetti, Eda Marchetti
J. Softw. Evol. Process.1
2022 The GDPR Compliance and Access Control Systems: Challenges and Research Opportunities
abstract
The General Data Protection Regulation (GDPR) is changing how Personal Data should be processed. Using Access Control Systems (ACSs) and their specific policies as practical means for assuring a by-design lawfully compliance with the privacy-preserving rules and provision is currently an increasingly researched topic. As a result, this newly born research field raises several research questions and paves the way for different solutions. This position paper would like to provide an overview of research challenges and questions concerning activities for analyzing, designing, implementing, and testing Access Control mechanisms (systems and policies) to guarantee compliance with the GDPR. Some possible answers to the open issues and future research directions and topics are also provided.
Said Daoudagh, Eda Marchetti
ICISSP1
2021 How to Improve the GDPR Compliance through Consent Management and Access Control
abstract
This paper presents a privacy-by-design solution based on Consent Manager (CM) and Access Control (AC) to aid organizations to comply with the GDPR. The idea is to start from the GDPR's text, transform it into a machine-readable format through a given CM, and then convert the obtained outcome to a set of enforceable Access Control Policies (ACPs). As a result, we have defined a layered architecture that makes any given system privacy-aware, i.e., systems that are compliant by-design with the GDPR. Furthermore, we have provided a proof-of-concept by integrating a Consent Manager coming from an industrial context and an AC Manager coming from academia.
Said Daoudagh, Eda Marchetti, Vincenzo Savarino, Roberto Di Bernardo, Marco Alessi
ICISSP1
2021 GROOT: A GDPR-Based Combinatorial Testing Approach
Said Daoudagh, Eda Marchetti
ICTSS1
2021 MENTORS: Monitoring Environment for System of Systems
abstract
Context: Systems Of Systems (SoSs) are becoming a widespread emerging architecture, and they are used in several daily life contexts. Therefore, when a new device is integrated into an existing SoS, facilities able to efficaciously assess and prevent anomalous and dangerous situations are necessary. Objective: The aim is to define a reference environment conceived for monitoring and assessing the behavior of SoS when a new device is added. Method: In this paper, we present MENTORS, a monitoring environment for SoS. MENTORS is based on semantic web technologies to formally represent SoS and Monitoring knowledge through a core ontology, called MONTOLOGY. Results and Conclusion: We defined the conceptual model of MENTORS, which is composed of two phases: Off-line and On-line, supported by a reference architecture that allows its (semi-)automation. Validation of the proposal with real use-cases is part of future activities.
Antonello Calabrò, Said Daoudagh, Eda Marchetti
WEBIST2
2020 Assessing Testing Strategies for Access Control Systems: A Controlled Experiment
abstract
This paper presents a Controlled Experiment (CE) for assessing testing strategies in the context of Access Control (AC); more precisely, the CE is performed by considering the AC Systems (ACSs) based on the XACML Standard. We formalized the goal of the CE, and we assessed two available test cases generation strategies in terms of three metrics: Effectiveness, Size and Average Percentage Faults Detected (APFD). The experiment operation is described and the main results are analyzed.
Said Daoudagh, Francesca Lonetti, Eda Marchetti
ICISSP1
2020 Defining Controlled Experiments Inside the Access Control Environment
abstract
In ICT systems and modern applications access control systems are important mechanisms for managing resources and data access. Their criticality requires high security levels and consequently, the application of effective and efficient testing approaches. In this paper we propose standardized guidelines for correctly and systematically performing the testing process in order to avoid errors and improve the effectiveness of the validation. We focus in particular on Controlled Experiments, and we provide here a characterization of the first three steps of the experiment process (i.e., Scoping, Planning and Operation) by the adoption of the Goal- Question-Metric template. The specialization of the three phases is provided through a concrete example.
Said Daoudagh, Eda Marchetti
MODELSWARD1
2020 XACMET: XACML Testing & Modeling
Said Daoudagh, Francesca Lonetti, Eda Marchetti
Softw. Qual. J.1
2019 A Decentralized Solution for Combinatorial Testing of Access Control Engine
abstract
In distributed environments, information security is a key factor and access control is an important means to guarantee confidentiality of sensitive and valuable data. In this paper, we introduce a new decentralized framework for testing of XACML-based access control engines. The proposed framework is composed of different web services and provides the following functionalities: I) generation of test cases based on combinatorial testing strategies; ii) decentralized oracle that associates the expected result to a given test case, i.e. an XACML request; and finally, iii) a GUI for interacting with the framework and providing some analysis about the expected results. A first validation confirms the efficiency of the proposed approach.
Said Daoudagh, Francesca Lonetti, Eda Marchetti
ICISSP1
2019 Towards a Lawful Authorized Access: A Preliminary GDPR-based Authorized Access
abstract
The General Data Protection Regulation (GDPR)'s sixth principle, Integrity and Confidentiality, dictates that personal data must be protected from unauthorised or unlawful processing. To this aim, we propose a systematic approach for authoring access control policies that are by-design aligned with the provisions of the GDPR. We exemplify it by considering realistic use cases.
Cesare Bartolini, Said Daoudagh, Gabriele Lenzini, Eda Marchetti
ICSOFT2
2015 A Toolchain for Model-based Design and Testing of Access Control Systems
abstract
In access control systems, aimed at regulating the accesses to protected data and resources, a critical component is the Policy Decision Point (PDP), which grants or denies the access according to the defined policies. Due to the complexity of the standard languag-e, it is recommended to rely on model-driven approaches which allow to overcome difficulties in the XACML policy definition. We provide in this paper a toolchain that involves a model-driven approach to specify and generate XACML policies and also enables automated testing of the PDP component. We use XACML-based testing strategies for generating appropriate test cases which are able to validate the functional aspects, constraints, permissions and prohibitions of the PDP. An experimental assessment of the toolchain and its use on a realistic case study are also presented.
Said Daoudagh, Donia El Kateb, Francesca Lonetti, Eda Marchetti, Tejeddine Mouelhi
MODELSWARD1
2015 Similarity testing for access control
Antonia Bertolino, Said Daoudagh, Donia El Kateb, Christopher Henard, Yves Le Traon, Francesca Lonetti, Eda Marchetti, Tejeddine Mouelhi, Mike Papadakis
Inf. Softw. Technol.2
2014 Testing of PolPA-based usage control systems
Antonia Bertolino, Said Daoudagh, Francesca Lonetti, Eda Marchetti, Fabio Martinelli, Paolo Mori
Softw. Qual. J.2
2013 A Toolchain for Designing and Testing XACML Policies
abstract
In modern pervasive application domains, such as Service Oriented Architectures (SOAs) and Peer-to-Peer (P2P) systems, security aspects are critical. Justified confidence in the security mechanisms that are implemented for assuring proper data access is a key point. In the last years XACML has become the de facto standard for specifying policies for access control decisions in many application domains. Briefly, an XACML policy defines the constraints and conditions that a subject needs to comply with for accessing a resource and doing an action in a given environment. Due to the complexity of the language, XACML policy specification is a difficult and error prone process that requires specific knowledge and a high effort to be properly managed.
Antonia Bertolino, Marianne Busch, Said Daoudagh, Nora Koch, Francesca Lonetti, Eda Marchetti
ICST3
2012 Automatic XACML Requests Generation for Policy Testing
abstract
Access control policies are usually specified by the XACML language. However, policy definition could be an error prone process, because of the many constraints and rules that have to be specified. In order to increase the confidence on defined XACML policies, an accurate testing activity could be a valid solution. The typical policy testing is performed by deriving specific test cases, i.e. XACML requests, that are executed by means of a PDP implementation, so to evidence possible security lacks or problems. Thus the fault detection effectiveness of derived test suite is a fundamental property. To evaluate the performance of the applied test strategy and consequently of the test suite, a commonly adopted methodology is using mutation testing. In this paper, we propose two different methodologies for deriving XACML requests, that are defined independently from the policy under test. The proposals exploit the values of the XACML policy for better customizing the generated requests and providing a more effective test suite. The proposed methodologies have been compared in terms of their fault detection effectiveness by the application of mutation testing on a set of real policies.
Antonia Bertolino, Said Daoudagh, Francesca Lonetti, Eda Marchetti
ICST2
2012 The X-CREATE Framework - A Comparison of XACML Policy Testing Strategies
Antonia Bertolino, Said Daoudagh, Francesca Lonetti, Eda Marchetti
WEBIST2