A Detection and Correction Approach for Overflow Vulnerabilities in Graphical User Interfaces

dc.contributor.advisor Tuğlular, Tuğkan
dc.contributor.author Müftüoğlu, Can Arda
dc.date.accessioned 2014-07-22T13:50:42Z
dc.date.available 2014-07-22T13:50:42Z
dc.date.issued 2009
dc.description Thesis (Master)--Izmir Institute of Technology, Computer Engineering, Izmir, 2009 en_US
dc.description Includes bibliographical references (leaves: 36-40) en_US
dc.description Text in English; Abstract: Turkish and English en_US
dc.description ix, 40 leaves en_US
dc.description.abstract The objective of this thesis is to propose an approach for detecting overflow vulnerabilities such as buffer and boundary overflows by using static analysis and correcting these vulnerabilities by applying a correction mechanism which uses static code insertion. GUI is tested by specifying user interface requirements and converting this specification into an event-sequence model. Decision table notion is used for modeling the dependencies and boundary restrictions on input data and generating test cases. The test cases are applied to the GUI as inputs manually in real environment. The faults are observed. Then, the overflow vulnerability analysis tool is used to analyze the source code of the program. The deficiencies related to overflow vulnerabilities are found by static analysis. After that, the correction mechanism is applied to the deficient parts of the source code. The software is tested in real environment again. The proposed approach is observed to be successful for detecting and correcting overflow vulnerabilities in GUIs. en_US
dc.identifier.uri https://hdl.handle.net/11147/3013
dc.language.iso en en_US
dc.publisher Izmir Institute of Technology en_US
dc.rights info:eu-repo/semantics/openAccess en_US
dc.subject.lcc QA76.9.U83 .M94 2009 en
dc.subject.lcsh Graphical user interfaces (Computer systems) en
dc.title A Detection and Correction Approach for Overflow Vulnerabilities in Graphical User Interfaces en_US
dc.type Master Thesis en_US
dspace.entity.type Publication
gdc.author.institutional Müftüoğlu, Can Arda
gdc.coar.access open access
gdc.coar.type text::thesis::master thesis
gdc.description.department Thesis (Master)--İzmir Institute of Technology, Computer Engineering en_US
gdc.description.publicationcategory Tez en_US
gdc.description.scopusquality N/A
gdc.description.wosquality N/A
relation.isAuthorOfPublication.latestForDiscovery 7f52fb71-3121-46a6-a461-2ff1b28d9fa1
relation.isOrgUnitOfPublication.latestForDiscovery 9af2b05f-28ac-4014-8abe-a4dfe192da5e

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Name:
T000181.pdf
Size:
725.33 KB
Format:
Adobe Portable Document Format
Description:
MasterThesis

License bundle

Now showing 1 - 1 of 1
Loading...
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: