Quantitative Information Flow, with a View

被引:0
|
作者
Boreale, Michele [1 ,2 ]
Pampaloni, Francesca [3 ]
Paolini, Michela [3 ]
机构
[1] Univ Florence, Dipartimento Sistemi & Informat, Viale Morgagni 65, I-50134 Florence, Italy
[2] Univ Florence, I-50134 Florence, Italy
[3] IMT Inst Adv Studies, Lucca, Italy
来源
关键词
quantitative information flow; statistical attacks; anonymity; privacy; information theory; LEAKAGE;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
We put forward a general model intended for assessment of system security against passive eavesdroppers, both quantitatively (how much information is leaked) and qualitatively (what properties are leaked). To this purpose, we extend information hiding systems (ins), a model where the secret-observable relation is represented as a noisy channel, with views: basically, partitions of the state-space. Given a view W and n independent observations of the system, one is interested in the probability that a Bayesian adversary wrongly predicts the class of W the underlying secret belongs to. We offer results that allow one to easily characterise the behaviour of this error probability as a function of the number of observations, in terms of the channel matrices defining the IHS and the view W. In particular, we provide expressions for the limit value as n -> infinity, show by tight bounds that convergence is exponential, and also characterise the rate of convergence to predefined error thresholds. We then show a few instances of statistical attacks that can be assessed by a direct application of our model: attacks against modular exponentiation that exploit timing leaks, against anonymity in mix-nets and against privacy in sparse datasets.
引用
收藏
页码:588 / +
页数:4
相关论文
共 50 条
  • [31] Redefining KPIs with Information Flow Visualisation - Practitioners' View
    Hyysalo, Jarkko
    Kelanti, Markus
    Markkula, Jouni
    THIRTEENTH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING ADVANCES (ICSEA 2018), 2018, : 114 - 121
  • [32] Quantitative Strongest Post A Calculus for Reasoning about the Flow of Quantitative Information
    Zhang, Linpeng
    Kaminski, Benjamin Lucien
    PROCEEDINGS OF THE ACM ON PROGRAMMING LANGUAGES-PACMPL, 2022, 6 (OOPSLA):
  • [33] An Automated Quantitative Information Flow Analysis for Concurrent Programs
    Khayyam, Salehi
    Noroozi, Ali A.
    Amir-Mohammadian, Sepehr
    Mohagheghi, Mohammadsadegh
    QUANTITATIVE EVALUATION OF SYSTEMS (QEST 2022), 2022, 13479 : 43 - 63
  • [34] A Better Composition Operator for Quantitative Information Flow Analyses
    Engelhardt, Kai
    COMPUTER SECURITY - ESORICS 2017, PT I, 2018, 10492 : 446 - 463
  • [35] Quantitative Information Flow for Hardware: Advancing the Attack Landscape
    Reimann, Lennart M.
    Erdoenmez, Sarp
    Sisejkovic, Dominik
    Leupers, Rainer
    2023 IEEE 14TH LATIN AMERICA SYMPOSIUM ON CIRCUITS AND SYSTEMS, LASCAS, 2023, : 21 - 24
  • [36] Image contrast enhancement and quantitative measuring of information flow
    Ye, Zhengmao
    Mohamadian, Habib
    Pang, Su-Seng
    Iyengar, Sitharama
    PROCEEDINGS OF THE 6TH WSEAS INTERNATIONAL CONFERENCE ON INFORMATION SECURITY AND PRIVACY (ISP '07): ADVANCED TOPICS IN INFORMATION SECURITY AND PRIVACY, 2007, : 172 - +
  • [37] Approximation and Randomization for Quantitative Information-Flow Analysis
    Kopf, Boris
    Rybalchenko, Andrey
    2010 23RD IEEE COMPUTER SECURITY FOUNDATIONS SYMPOSIUM (CSF), 2010, : 3 - 14
  • [38] On the Relation between Differential Privacy and Quantitative Information Flow
    Alvim, Mario S.
    Andres, Miguel E.
    Chatzikokolakis, Konstantinos
    Palamidessi, Catuscia
    AUTOMATA, LANGUAGES AND PROGRAMMING, ICALP, PT II, 2011, 6756 : 60 - 76
  • [39] Quantitative Information Flow for Scheduler-Dependent Systems
    Kawamoto, Yusuke
    Given-Wilson, Thomas
    ELECTRONIC PROCEEDINGS IN THEORETICAL COMPUTER SCIENCE, 2015, (194): : 48 - 62
  • [40] BRIDGING THE INFORMATION-FLOW - VIEW FROM THE PRIVATE SECTOR
    WARNER, AS
    LIBRARY JOURNAL, 1979, 104 (16) : 1791 - 1794