Context-Aware Software Vulnerability Testing via Dynamic UI Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional software security analysis (SSA) tools are limited in their ability to dynamically analyze software applications, failing to consider transient security issues and user interactions, and are not context-aware, leading to incomplete vulnerability detection.

Innovation Solution

A method and system that launch a subject application, identify and analyze user interactive (UI) elements within the application, generate examination challenges based on context indicators, and test for vulnerabilities by simulating user interactions, monitoring communication with external sources, and recording results to detect unauthorized actions and privilege exceedances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional SSA tools perform static scanning from a fixed point in time, then the analysis process is simple and quick, but the tools cannot detect transient security issues that arise during dynamic user interactions

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidtesting system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static security scanning into dynamic context-aware testing by implementing a system that automatically implements UI resource functionality, identifies context indicators during runtime, and generates examination challenges based on dynamic application state. This allows the system to detect transient security issues that only appear during user interactions while maintaining manageable complexity through automated context analysis.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-service by automatically implementing UI resource functionality and identifying context indicators without requiring manual configuration. The automated implementation engine executes UI resources, captures context indicators, and generates appropriate examination challenges autonomously, reducing the need for complex manual setup while improving vulnerability detection reliability.

Inventive Principle:
Principle #25Self-service

2Reliability

If conventional SSA tools analyze application state at a single point in time, then the analysis is straightforward, but the tools miss security issues that occur temporarily during runtime operations

Engineering Contradiction:
Improvesecurity issue detectionVSAvoidtesting duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically implementing UI resources and capturing context indicators before security vulnerabilities manifest. The automated implementation engine proactively executes UI functionality and records context indicators during normal operation, enabling the system to detect transient security issues as they occur rather than requiring extended monitoring periods.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring application state, capturing context indicators, and using this information to generate targeted examination challenges. This feedback loop allows the system to efficiently detect transient security issues during runtime without requiring excessive testing time, as the system adapts its testing based on observed application behavior.

Inventive Principle:
Principle #23Feedback

3Reliability

If conventional SSA tools use random data input for fuzz testing, then the testing process is simple to implement, but the tools cannot identify context-specific vulnerabilities related to UI element purpose and usage

Engineering Contradiction:
Improvecontext-aware vulnerability detectionVSAvoidcontext analysis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by capturing context indicators specific to each UI resource and generating examination challenges tailored to that particular context. The system identifies descriptive information, purpose statements, and usage instructions for each UI element, then generates context-specific challenges rather than applying uniform random input, improving detection accuracy while managing complexity through targeted analysis.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes parameters by transforming generic fuzz testing into context-aware testing through the use of captured context indicators. The automated implementation engine modifies testing parameters based on identified UI resource context, such as adjusting input data types, validation rules, and challenge generation strategies to match the specific purpose and usage of each UI element, thereby improving vulnerability detection without excessive complexity.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If conventional SSA tools require manual configuration for fuzz testing, then the tool structure remains simple, but the testing process becomes time-consuming and less adaptable to different applications

Engineering Contradiction:
Improveapplication-specific testing adaptabilityVSAvoidsetup complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system implements self-service by automatically capturing context indicators from UI resources and using this information to configure context-aware examination challenges. The automated implementation engine extracts purpose, usage instructions, and descriptive information directly from the application under test, eliminating the need for manual configuration while maintaining simplicity through automated adaptation to different applications.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies universality by creating a multi-functional automated implementation engine that can handle various UI resource types across different applications. The system captures context indicators from diverse UI elements, generates appropriate examination challenges for each context, and adapts to different application architectures without requiring application-specific configuration, thereby improving versatility while maintaining ease of operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11294798B2Method and system for context based testing of software application vulnerabilities
Publication Date: 2022.04.05 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US11294798B2 patent drawing
  • US11294798B2 patent drawing
  • US11294798B2 patent drawing

AI summary

Methods, systems and program products are provided for controlling one or more processors configured with executable instructions to launch a subject application and implement functionality of user interactive (UI) resources defined by the subject application. The methods, systems and program products identify a UI element provided on a first UI resource from the UI resources and a context indicator associated with the UI element. The methods, systems and program products generate one or more examination challenges for the UI element based on the context indicator, tests for vulnerabilities related to the UI element by applying the examination challenges to the UI elements.