Please use this identifier to cite or link to this item: https://hdl.handle.net/11147/3013
Title: A detection and correction approach for overflow vulnerabilities in graphical user interfaces
Authors: Müftüoğlu, Can Arda
Advisors: Tuğlular, Tuğkan
Publisher: Izmir Institute of Technology
Abstract: The objective of this thesis is to propose an approach for detecting overflow vulnerabilities such as buffer and boundary overflows by using static analysis and correcting these vulnerabilities by applying a correction mechanism which uses static code insertion. GUI is tested by specifying user interface requirements and converting this specification into an event-sequence model. Decision table notion is used for modeling the dependencies and boundary restrictions on input data and generating test cases. The test cases are applied to the GUI as inputs manually in real environment. The faults are observed. Then, the overflow vulnerability analysis tool is used to analyze the source code of the program. The deficiencies related to overflow vulnerabilities are found by static analysis. After that, the correction mechanism is applied to the deficient parts of the source code. The software is tested in real environment again. The proposed approach is observed to be successful for detecting and correcting overflow vulnerabilities in GUIs.
Description: Thesis (Master)--Izmir Institute of Technology, Computer Engineering, Izmir, 2009
Includes bibliographical references (leaves: 36-40)
Text in English; Abstract: Turkish and English
ix, 40 leaves
URI: http://hdl.handle.net/11147/3013
Appears in Collections:Master Degree / Yüksek Lisans Tezleri
Sürdürülebilir Yeşil Kampüs Koleksiyonu / Sustainable Green Campus Collection

Files in This Item:
File Description SizeFormat 
T000181.pdfMasterThesis725.33 kBAdobe PDFThumbnail
View/Open
Show full item record



CORE Recommender

Page view(s)

216
checked on Nov 18, 2024

Download(s)

68
checked on Nov 18, 2024

Google ScholarTM

Check





Items in GCRIS Repository are protected by copyright, with all rights reserved, unless otherwise indicated.