Invention Grant
- Patent Title: Systematic approach to uncover GUI logic flaws
- Patent Title (中): 发现GUI逻辑缺陷的系统方法
-
Application No.: US11772085Application Date: 2007-06-29
-
Publication No.: US08125669B2Publication Date: 2012-02-28
- Inventor: Shuo Chen , Yi-Min Wang , Jiahe Helen Wang
- Applicant: Shuo Chen , Yi-Min Wang , Jiahe Helen Wang
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Agency: Lee & Hayes, PLLC
- Main IPC: G06F15/00
- IPC: G06F15/00 ; G06F11/00

Abstract:
To achieve end-to-end security, traditional machine-to-machine security measures are insufficient if the integrity of the graphical user interface (GUI) is compromised. GUI logic flaws are a category of software vulnerabilities that result from logic flaws in GUI implementation. The invention described here is a technology for uncovering these flaws using a systematic reasoning approach. Major steps in the technology include: (1) mapping a visual invariant to a program invariant; (2) formally modeling the program logic, the user actions and the execution context, and systematically exploring the possibilities of violations of the program invariant; (3) finding real spoofing attacks based on the exploration.
Public/Granted literature
- US20080127341A1 Systematic Approach to Uncover GUI Logic Flaws Public/Granted day:2008-05-29
Information query