GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Fachbereiche
  • Informatik in den Lebenswissenschaften (ILW)
  • it - Information Technology
  • it - Information Technology 59(2) - April 2017
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Fachbereiche
  • Informatik in den Lebenswissenschaften (ILW)
  • it - Information Technology
  • it - Information Technology 59(2) - April 2017
  • Dokumentanzeige

On the misuse of graphical user interface elements to implement security controls

Autor(en):
Mulliner, Collin [DBLP] ;
Robertson, William [DBLP] ;
Kirda, Engin [DBLP]
Zusammenfassung
GUIs are the predominant means by which users interact with modern programs. GUIs contain a number of common visual elements widgets such as buttons, textfields, and lists, and GUIs typically provide the ability to change attributes on these widgets to control their visibility and behavior. While these attributes are extremely useful to provide visual cues to users to guide them through an application's GUI, they can also be misused for purposes they were not intended. In particular, in the context of GUI-based applications that include multiple privilege levels within the application, GUI element attributes may be misused as a mechanism for enforcing access control policies. This work presents a method to detect misuse of user interface elements to implement access control, it is based on our earlier work1 that introduced the vulnerability class the we refer to as GEMs, or instances of GUI element misuse. Using our GEM detection method we discovered unknown vulnerabilities in several applications.
  • Vollständige Referenz
  • BibTeX
Mulliner, C., Robertson, W. & Kirda, E., (2017). On the misuse of graphical user interface elements to implement security controls.   it - Information Technology: Vol. 59, No. 5. Berlin: De Gruyter. (S. 59). DOI: 10.1515/itit-2016-0036
@article{mci/Mulliner2017,
author = {Mulliner, Collin AND Robertson, William AND Kirda, Engin},
title = {On the misuse of graphical user interface elements to implement security controls},
journal = {it - Information Technology},
volume = {59},
number = {5},
year = {2017},
,
pages = { 59 } ,
doi = { 10.1515/itit-2016-0036 }
}

Sollte hier kein Volltext (PDF) verlinkt sein, dann kann es sein, dass dieser aus verschiedenen Gruenden (z.B. Lizenzen oder Copyright) nur in einer anderen Digital Library verfuegbar ist. Versuchen Sie in diesem Fall einen Zugriff ueber die verlinkte DOI: 10.1515/itit-2016-0036

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

DOI: 10.1515/itit-2016-0036
ISSN: 1611-2776
Datum: 2017
Sprache: en (en)
Typ: Text/Journal Article

Keywords

  • Vulnerability analysis
  •  graphical user interfaces
  •  access control
Sammlungen
  • it - Information Technology 59(2) - April 2017 [7]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.