What's the Over/Under? Probabilistic Bounds on Information Leakage

02/22/2018
by   Ian Sweet, et al.
0

Quantitative information flow (QIF) is concerned with measuring how much of a secret is leaked to an adversary who observes the result of a computation that uses it. Prior work has shown that QIF techniques based on abstract interpretation with probabilistic polyhedra can be used to analyze the worst-case leakage of a query, on-line, to determine whether that query can be safely answered. While this approach can provide precise estimates, it does not scale well. This paper shows how to solve the scalability problem by augmenting the baseline technique with sampling and symbolic execution. We prove that our approach never underestimates a query's leakage (it is sound), and detailed experimental results show that we can match the precision of the baseline technique but with orders of magnitude better performance.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/23/2020

Measuring Information Leakage in Non-stochastic Brute-Force Guessing

We propose an operational measure of information leakage in a non-stocha...
research
09/02/2019

KLEESPECTRE: Detecting Information Leakage through Speculative Cache Attacks via Symbolic Execution

Spectre attacks disclosed in early 2018 expose data leakage scenarios vi...
research
03/09/2019

Quantifying Dynamic Leakage: Complexity Analysis and Model Counting-based Calculation

A program is non-interferent if it leaks no secret information to an obs...
research
01/18/2023

Sound Symbolic Execution via Abstract Interpretation and its Application to Security

Symbolic execution is a program analysis technique commonly utilized to ...
research
02/27/2018

Leakage and Protocol Composition in a Game-Theoretic Perspective

In the inference attacks studied in Quantitative Information Flow (QIF),...
research
05/11/2019

On the Compositionality of Dynamic Leakage and Its Application to the Quantification Problem

Quantitative information flow (QIF) is traditionally defined as the expe...
research
09/28/2018

Caulking the Leakage Effect in MEEG Source Connectivity Analysis

Simplistic estimation of neural connectivity in MEEG sensor space is imp...

Please sign up or login with your details

Forgot password? Click here to reset