Invention Grant
- Patent Title: System and method for detecting sensitive user input leakages in software applications
-
Application No.: US14939366Application Date: 2015-11-12
-
Publication No.: US09870485B2Publication Date: 2018-01-16
- Inventor: Zhichun Li , Xusheng Xiao , Zhenyu Wu , Jianjun Huang , Guofei Jiang
- Applicant: NEC Laboratories America, Inc.
- Applicant Address: JP Tokyo
- Assignee: NEC Corporation
- Current Assignee: NEC Corporation
- Current Assignee Address: JP Tokyo
- Agent Joseph Kolodka
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F21/62

Abstract:
A system and method for detecting sensitive user input leakages in software applications, such as applications created for smartphone platforms. The system and method are configured to parse user interface layout files of the software application to identify input fields and obtain information concerning the input fields. Input fields that contain sensitive information are identified and a list of sensitive input fields, such as contextual IDs, is generated. The sensitive information fields are identified by reviewing the attributes, hints and/or text labels of the user interface layout file. A taint analysis is performed using the list of sensitive input fields and a sink dataset in order to detect information leaks in the sensitive input fields.
Public/Granted literature
- US20160132679A1 SYSTEM AND METHOD FOR DETECTING SENSITIVE USER INPUT LEAKAGES IN SOFTWARE APPLICATIONS Public/Granted day:2016-05-12
Information query