Enhancing Security Testing for Identity Management Implementations: Introducing Micro-Id-Gym Language and Micro-Id-Gym Testing Tool
Description
This work presents MIG-L, a declarative language for specifying security and conformance tests, and MIG-T, an automated testing tool for Identity Management (IdM) implementations based on SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC). MIG-L enables the systematic description of protocol behaviors and security requirements, while MIG-T executes automated assessments to verify compliance with Best Current Practices, detect known vulnerabilities, and provide actionable mitigation strategies. The combined framework supports comprehensive testing of authentication and authorization flows in federated identity ecosystems. Experimental evaluations demonstrate the flexibility, scalability, and effectiveness of the approach for improving the security posture of real-world IdM deployments.
Files
2024-2.pdf
Files
(425.6 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:a938d7694d854cb1c8c6ec009095ecc1
|
425.6 kB | Preview Download |