- 专利标题: Systematic Approach to Uncover GUI Logic Flaws
-
申请号: US11565426申请日: 2006-11-30
-
公开(公告)号: US20080134338A1公开(公告)日: 2008-06-05
- 发明人: Shuo Chen , Jose Meseguer , Ralf Sasse , Jiahe Helen Wang , Yi-Min Wang
- 申请人: Shuo Chen , Jose Meseguer , Ralf Sasse , Jiahe Helen Wang , Yi-Min Wang
- 申请人地址: US WA Redmond US IL Urbana
- 专利权人: Microsoft Corporation,University of Illinois
- 当前专利权人: Microsoft Corporation,University of Illinois
- 当前专利权人地址: US WA Redmond US IL Urbana
- 主分类号: G08B23/00
- IPC分类号: G08B23/00
摘要:
To achieve end-to-end security, traditional machine-to-machine security measures are insufficient if the integrity of the graphical user interface (GUI) is compromised. GUI logic flaws are a category of software vulnerabilities that result from logic flaws in GUI implementation. The invention described here is a technology for uncovering these flaws using a systematic reasoning approach. Major steps in the technology include: (1) mapping a visual invariant to a program invariant; (2) formally modeling the program logic, the user actions and the execution context, and systematically exploring the possibilities of violations of the program invariant; (3) finding real spoofing attacks based on the exploration.
公开/授权文献
- US08156559B2 Systematic approach to uncover GUI logic flaws 公开/授权日:2012-04-10
信息查询