Abstract
Classical quantitative information flow analysis often considers a system as an information-theoretic channel, where private data are the only inputs and public data are the outputs. However, for systems where an attacker is able to influence the initial values of public data, these should also be considered as inputs of the channel. This paper adapts the classical view of information-theoretic channels in order to quantify information flow of programs that contain both private and public inputs.
Additionally, we show that our measure also can be used to reason about the case where a system operator on purpose adds noise to the output, instead of always producing the correct output. The noisy outcome is used to reduce the correlation between the output and the input, and thus to increase the remaining uncertainty. However, even though adding noise to the output enhances the security, it reduces the reliability of the program. We show how given a certain noisy output policy, the increase in security and the decrease in reliability can be quantified.
Original language | Undefined |
---|---|
Title of host publication | Proceedings of the 6th International Symposium on Engineering Secure Software and Systems, ESSoS 2014 |
Place of Publication | London |
Publisher | Springer |
Pages | 77-94 |
Number of pages | 18 |
ISBN (Print) | 978-3-319-04896-3 |
DOIs | |
Publication status | Published - Feb 2014 |
Event | 6th International Symposium on Engineering Secure Software and Systems, ESSoS 2014 - Technische Universität München, Munich, Germany Duration: 26 Feb 2014 → 28 Feb 2014 Conference number: 6 https://distrinet.cs.kuleuven.be/events/essos/2014/ |
Publication series
Name | Lecture Notes in Computer Science |
---|---|
Publisher | Springer Verlag |
Volume | 8364 |
Conference
Conference | 6th International Symposium on Engineering Secure Software and Systems, ESSoS 2014 |
---|---|
Abbreviated title | ESSoS |
Country/Territory | Germany |
City | Munich |
Period | 26/02/14 → 28/02/14 |
Internet address |
Keywords
- EWI-24027
- METIS-303973
- IR-88367