Quantitative Information Flow, with a View

被引:0
|
作者
Boreale, Michele [1 ,2 ]
Pampaloni, Francesca [3 ]
Paolini, Michela [3 ]
机构
[1] Univ Florence, Dipartimento Sistemi & Informat, Viale Morgagni 65, I-50134 Florence, Italy
[2] Univ Florence, I-50134 Florence, Italy
[3] IMT Inst Adv Studies, Lucca, Italy
来源
关键词
quantitative information flow; statistical attacks; anonymity; privacy; information theory; LEAKAGE;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
We put forward a general model intended for assessment of system security against passive eavesdroppers, both quantitatively (how much information is leaked) and qualitatively (what properties are leaked). To this purpose, we extend information hiding systems (ins), a model where the secret-observable relation is represented as a noisy channel, with views: basically, partitions of the state-space. Given a view W and n independent observations of the system, one is interested in the probability that a Bayesian adversary wrongly predicts the class of W the underlying secret belongs to. We offer results that allow one to easily characterise the behaviour of this error probability as a function of the number of observations, in terms of the channel matrices defining the IHS and the view W. In particular, we provide expressions for the limit value as n -> infinity, show by tight bounds that convergence is exponential, and also characterise the rate of convergence to predefined error thresholds. We then show a few instances of statistical attacks that can be assessed by a direct application of our model: attacks against modular exponentiation that exploit timing leaks, against anonymity in mix-nets and against privacy in sparse datasets.
引用
收藏
页码:588 / +
页数:4
相关论文
共 50 条
  • [1] Algebra for Quantitative Information Flow
    McIver, A. K.
    Morgan, C. C.
    Rabehaja, T.
    RELATIONAL AND ALGEBRAIC METHODS IN COMPUTER SCIENCE, RAMICS 2017, 2017, 10226 : 3 - 23
  • [2] ON THE COMPOSITIONALITY OF QUANTITATIVE INFORMATION FLOW
    Kawamoto, Yusuke
    Chatzikokolakis, Konstantinos
    Palamidessi, Catuscia
    LOGICAL METHODS IN COMPUTER SCIENCE, 2017, 13 (03)
  • [3] On the Foundations of Quantitative Information Flow
    Smith, Geoffrey
    FOUNDATIONS OF SOFTWARE SCIENCE AND COMPUTATIONAL STRUCTURES, PROCEEDINGS, 2009, 5504 : 288 - 302
  • [4] Information Theory and Security: Quantitative Information Flow
    Malacaria, Pasquale
    Heusser, Jonathan
    FORMAL METHODS FOR QUANTITATIVE ASPECTS OF PROGRAMMING LANGUAGES, 2010, 6154 : 87 - 134
  • [5] Quantitative information flow as network flow capacity
    McCamant, Stephen
    Ernst, Michael D.
    ACM SIGPLAN NOTICES, 2008, 43 (06) : 193 - 205
  • [6] Quantitative Information Flow as Network Flow Capacity
    McCamant, Stephen
    Ernst, Michael D.
    PLDI'08: PROCEEDINGS OF THE 2008 SIGPLAN CONFERENCE ON PROGRAMMING LANGUAGE DESIGN & IMPLEMENTATION, 2008, : 193 - 205
  • [7] Program algebra for quantitative information flow
    McIver, A. K.
    Morgan, C. C.
    Rabehaja, T.
    JOURNAL OF LOGICAL AND ALGEBRAIC METHODS IN PROGRAMMING, 2019, 106 : 55 - 77
  • [8] Correlated Secrets in Quantitative Information Flow
    Bordenabe, Nicolas E.
    Smith, Geoffrey
    2016 IEEE 29TH COMPUTER SECURITY FOUNDATIONS SYMPOSIUM (CSF 2016), 2016, : 93 - 104
  • [9] On Bounding Problems of Quantitative Information Flow
    Yasuoka, Hirotoshi
    Terauchi, Tachio
    COMPUTER SECURITY-ESORICS 2010, 2010, 6345 : 357 - 372
  • [10] QQIF: Quantum Quantitative Information Flow
    Americo, Arthur
    Malacaria, Pasquale
    2020 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2020), 2020, : 261 - 270