DocumentCode
3399590
Title
Quantifying trust: data integrity metrics
Author
Kyle-Bowlsbey, E.M. ; Zaret, D.R.
Author_Institution
Appl. Phys. Lab., Johns Hopkins Univ., Laurel, MD, USA
fYear
2005
fDate
17-20 Oct. 2005
Firstpage
3142
Abstract
This paper presents a framework for characterizing the integrity of data in terms of the probability of a successful integrity compromise attack-an attack whose goal is to achieve the unauthorized and undetected modification of the data. The framework is based on an innovative methodology that combines two complementary approaches for assessing this probability. The first approach looks at specific, known attacks, and uses attack trees to analyze their probability of success. This approach provides a lower bound on the probability of a successful integrity compromise attack, for some fixed level of effort on the part of the attacker. It demonstrates that an attack can succeed with a particular probability, but does not rule out the possibility that some other, perhaps previously unknown attack might have a greater probability of success. Our second approach addresses this limitation by applying cryptographic "provable security" results. Such results provide an upper bound on the probability of success for any possible attack (for a fixed utilization of attacker resources). We use this probabilistic framework to develop quantitative measures of integrity within a sample scenario.
Keywords
cryptography; data integrity; probability; telecommunication security; cryptographic scheme; data integrity metrics; information security; probability; Availability; Cryptography; Data security; Information analysis; Information security; Information systems; Laboratories; Physics; Probability; Upper bound;
fLanguage
English
Publisher
ieee
Conference_Titel
Military Communications Conference, 2005. MILCOM 2005. IEEE
Conference_Location
Atlantic City, NJ
Print_ISBN
0-7803-9393-7
Type
conf
DOI
10.1109/MILCOM.2005.1606140
Filename
1606140
Link To Document