Quantitative Information Flow Metrics
نویسندگان
چکیده
Information flow analysis is a powerful technique for reasoning about sensitive information that may be exposed during program execution. One promising approach is to adopt a program as a communication channel model and leverage information theoretic metrics (e.g., mutual information between the sensitive input and the public output) to quantify such information flows. However, recent research has shown discrepancies in such information theoretic metrics: for example, Smith et. al. [5] showed examples wherein using the classical Shannon entropy measure for quantifying information flows may be counter-intuitive. Smith et. al. [5] proposed a vulnerability measure in an attempt to resolve this problem; this measure was subsequently enhanced by Hamadou et. al. [2] into a belief-vulnerability metric (in Oakland 2010). However, we point out that the vulnerability measure may also lead to counter-intuitive results on several other programs. In fact, we show that one can construct infinitely many programs wherein different information leakage measures (proposed in past work) are in conflict. This paper presents the first attempt towards addressing such conflicts and derives solutions for an optimal conflict-free comparison of programs over a class of entropy measures (called Renyi entropy − a well known generalization of the classical Shannon entropy).
منابع مشابه
Improving Clinical Work Flow through an AIM Database: A Sample Web-based Lesion Tracking Application1
Quantitative assessments on images are crucial to clinical decision making, especially in cancer patients, in whom measurements of lesions are tracked over time. However, the potential value of quantitative approaches to imaging is impeded by the difficulty and timeintensive nature of compiling this information from prior studies and reporting corresponding information on current studies. The a...
متن کاملQuantitative Information Flow for Security: A Survey
Information-flow security enforces limits on the use of information that cover both access and propagate in programs. Quantifying and measuring information flow in software has recently become an active research topic in computer security community. There has been a significant activity around the question of how to measure the amount of information flow caused by interference between variables...
متن کاملA New Classification of Information: A Step on the Road to Interpretability
Complex systems, such as manufacturing supply chains, are often modeled as a collection of interacting components with information flows between them. These components are frequently responsible for making a wide range of decisions that are implemented using an optimization, heuristic, or control technique. The traditional approach to system performance focuses on the performance of these compo...
متن کاملMetrics in SoC Verification Not just for coverage anymore
Process metrics provide a clear, quantitative and objective measure to assess process performance and progress towards a specific process goal. SoC functional verification involves integrating multiple IP blocks. So understanding how to define, measure, correlate, and analyze appropriate IP and system-level metrics is fundamental to improving performance and achieving quality goals. Yet, many o...
متن کاملAdversary Gain vs. Defender Loss in Quantified Information Flow
Metrics for quantifying information leakage assume that an adversary’s gain is the defender’s loss. We demonstrate that this assumption does not always hold via a class of scenarios. We describe how to extend quantification to account for a defender with goals distinct from adversary failure. We implement the extension and experimentally explore the impact on the measured information leakage of...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2011