What's the Over/Under? Probabilistic Bounds on Information Leakage

What's the Over/Under? Probabilistic Bounds on Information Leakage
复制标题

什么是大小盘?

DOI:
10.1007/978-3-319-89722-6_1
复制
发表时间:
2018
期刊:
ArXiv
影响因子:
--
通讯作者:
Stephen Magill
Stephen Magill
中科院分区:
--
文献类型:
--
作者:
Ian Sweet;José Manuel Calderón Trilla;Chad Scherrer;M. Hicks;Stephen Magill

文献摘要

被引文献

相似文献

定量信息流(QIF)关注的是测量有多少秘密被泄露给观察使用该秘密的计算结果的对手。前人的工作表明,基于概率多面体抽象解释的QIF技术可以用于在线分析查询的最坏情况的泄漏,以确定该查询是否可以安全地得到回答。虽然这种方法可以提供准确的估计,但它不能很好地扩展。本文展示了如何通过采样和符号执行增强基线技术来解决可伸缩性问题。我们证明了我们的方法永远不会低估查询的泄漏(它是合理的),详细的实验结果表明,我们可以达到基线技术的精度,但性能要高出一个数量级。
Quantitative information flow (QIF) is concerned with measuring how much of a secret is leaked to an adversary who observes the result of a computation that uses it. Prior work has shown that QIF techniques based on abstract interpretation with probabilistic polyhedra can be used to analyze the worst-case leakage of a query, on-line, to determine whether that query can be safely answered. While this approach can provide precise estimates, it does not scale well. This paper shows how to solve the scalability problem by augmenting the baseline technique with sampling and symbolic execution. We prove that our approach never underestimates a query’s leakage (it is sound), and detailed experimental results show that we can match the precision of the baseline technique but with orders of magnitude better performance.