{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2022,4,4]],"date-time":"2022-04-04T19:07:55Z","timestamp":1649099275267},"reference-count":0,"publisher":"Walter de Gruyter GmbH","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017,4,20]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>GUIs are the predominant means by which users interact with modern programs.\nGUIs contain a number of common visual elements widgets such as buttons, textfields,\nand lists, and GUIs typically provide the ability to change attributes on these widgets\nto control their visibility and behavior.\nWhile these attributes are extremely useful to provide visual cues to users to guide them\nthrough an application's GUI, they can also be misused for purposes they were\nnot intended.\nIn particular, in the context of GUI-based applications that\ninclude multiple privilege levels within the application, GUI element attributes\nmay be misused as a mechanism for enforcing access control policies.\nThis work presents a method to detect misuse of user interface elements to\nimplement access control, it is based on our earlier work<jats:fn symbol=\"1\" id=\"j_itit-2016-0036_fn_0001_w2aab3b7b5b1b6b1aab1c14b1b1Ab1\">\n                     <jats:p>C. Mulliner, W. Robertson, and E. Kirda,\n\u201cHidden GEMs: Automated Discovery of Access Control Vulnerabilities in Graphical User Interfaces\u201d, in\n<jats:italic>Proceedings of the IEEE Symposium on Security and Privacy<\/jats:italic>, 2014.<\/jats:p>\n                  <\/jats:fn> that\nintroduced the vulnerability class the we refer to as <jats:italic>GEMs<\/jats:italic>,\nor instances of <jats:italic>GUI element misuse<\/jats:italic>.\nUsing our GEM detection method we discovered unknown vulnerabilities in several applications.<\/jats:p>","DOI":"10.1515\/itit-2016-0036","type":"journal-article","created":{"date-parts":[[2017,3,16]],"date-time":"2017-03-16T15:33:04Z","timestamp":1489678384000},"page":"59-65","source":"Crossref","is-referenced-by-count":0,"title":["On the misuse of graphical user interface elements to implement security controls"],"prefix":"10.1515","volume":"59","author":[{"given":"Collin","family":"Mulliner","sequence":"first","affiliation":[{"name":"Secure Systems Lab, Northeastern University, 360 Huntington Ave, Boston, MA, 02115 United States of America"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"William","family":"Robertson","sequence":"additional","affiliation":[{"name":"Secure Systems Lab, Northeastern University, 360 Huntington Ave, Boston, MA, 02115 United States of America"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[{"name":"Secure Systems Lab, Northeastern University, 360 Huntington Ave, Boston, MA, 02115 United States of America"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"374","published-online":{"date-parts":[[2017,3,15]]},"container-title":["it - Information Technology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.degruyter.com\/view\/j\/itit.2017.59.issue-2\/itit-2016-0036\/itit-2016-0036.xml","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.degruyter.com\/document\/doi\/10.1515\/itit-2016-0036\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.degruyter.com\/document\/doi\/10.1515\/itit-2016-0036\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,6,23]],"date-time":"2021-06-23T11:44:36Z","timestamp":1624448676000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.degruyter.com\/document\/doi\/10.1515\/itit-2016-0036\/html"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,3,15]]},"references-count":0,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2017,3,28]]},"published-print":{"date-parts":[[2017,4,20]]}},"alternative-id":["10.1515\/itit-2016-0036"],"URL":"https:\/\/doi.org\/10.1515\/itit-2016-0036","relation":{},"ISSN":["2196-7032","1611-2776"],"issn-type":[{"value":"2196-7032","type":"electronic"},{"value":"1611-2776","type":"print"}],"subject":[],"published":{"date-parts":[[2017,3,15]]}}}