• DocumentCode
    2426505
  • Title

    Quantifying Information Leakage in Finite Order Deterministic Programs

  • Author

    Zhu, Ji ; Srivatsa, Mudhakar

  • Author_Institution
    Dept of Electr. & Comput. Engg, Univ. of Illinois at Urbana-Champaign, Urbana, IL, USA
  • fYear
    2011
  • fDate
    5-9 June 2011
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Information flow analysis is a powerful technique for reasoning about the sensitive information exposed by a program during its execution. While past work has proposed information theoretic metrics (e.g., Shannon entropy, min-entropy, guessing entropy, etc.) to quantify such information leakage, we argue that some of these measures not only result in counter-intuitive measures of leakage, but also are inherently prone to conflicts when comparing two programs P1 and P2 - say Shannon entropy predicts higher leakage for program P1, while guessing entropy predicts higher leakage for program P2. This paper presents the first attempt towards addressing such conflicts and derives solutions for conflict-free comparison of finite order deterministic programs.
  • Keywords
    data flow analysis; deterministic algorithms; information theory; reasoning about programs; security of data; Shannon entropy; counter-intuitive measures; finite order deterministic programs; information flow analysis; information leakage quantification; information theoretic metrics; reasoning; sensitive information; Analytical models; Entropy; Equations; IEEE Communications Society; Measurement; Mutual information; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications (ICC), 2011 IEEE International Conference on
  • Conference_Location
    Kyoto
  • ISSN
    1550-3607
  • Print_ISBN
    978-1-61284-232-5
  • Electronic_ISBN
    1550-3607
  • Type

    conf

  • DOI
    10.1109/icc.2011.5963509
  • Filename
    5963509