A Systematic Approach to Uncover Security Flaws in GUI Logic

 

Website spoofing, or phishing, is a serious problem targeting online user information. It can be used to steal usernames and passwords from important websites such as bank websites. Dr. Meseguer from the University of Illinois, jointly with Microsoft Research, developed a method for uncovering GUI logic flaws in software implementations. The systems specifically address status-bar spoofing and address bar spoofing scenarios but could also address a variety of other classes of problems.