Invention Application
US20160132679A1 SYSTEM AND METHOD FOR DETECTING SENSITIVE USER INPUT LEAKAGES IN SOFTWARE APPLICATIONS
有权
用于检测软件应用中敏感用户输入漏洞的系统和方法
- Patent Title: SYSTEM AND METHOD FOR DETECTING SENSITIVE USER INPUT LEAKAGES IN SOFTWARE APPLICATIONS
- Patent Title (中): 用于检测软件应用中敏感用户输入漏洞的系统和方法
-
Application No.: US14939366Application Date: 2015-11-12
-
Publication No.: US20160132679A1Publication Date: 2016-05-12
- Inventor: Zhichun Li , Xusheng Xiao , Zhenyu Wu , Jianjun Huang , Guofei Jiang
- Applicant: NEC Laboratories America, Inc.
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06F17/27

Abstract:
A system and method for detecting sensitive user input leakages in software applications, such as applications created for smartphone platforms. The system and method are configured to parse user interface layout files of the software application to identify input fields and obtain information concerning the input fields. Input fields that contain sensitive information are identified and a list of sensitive input fields, such as contextual IDs, is generated. The sensitive information fields are identified by reviewing the attributes, hints and/or text labels of the user interface layout file. A taint analysis is performed using the list of sensitive input fields and a sink dataset in order to detect information leaks in the sensitive input fields.
Public/Granted literature
- US09870485B2 System and method for detecting sensitive user input leakages in software applications Public/Granted day:2018-01-16
Information query