TWC: Small: Confidentiality Measurement of Complex Computations using Quantitative Information Flow
TWC: Small: Confidentiality Measurement of Complex Computations using Quantitative Information Flow
批准号:
1526319
负责人:
Stephen McCamant
金额:
$49.57万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2015
资助国家:
美国
项目状态:
已结题
起止时间:
2015-09-01 至 2019-08-31
中文摘要
对信息隐私的关切是用户采用新的信息技术应用的主要障碍,从智能手机应用到在最大的医疗保健和政府企业中部署自动化工作流程。该项目解决了由软件错误和恶意攻击引起的隐私问题。关于软件的一个主要安全问题围绕着计算机是否泄露了它们不应该泄露的信息。我们委托给计算机的许多信息可能被描述为秘密的、私人的或机密的,因为我们想限制谁可以访问它。然而,在计算机系统中,很多事情可能会出错,从而使信息在不应该泄露的时候被泄露出来。在这个项目中,重点是计算结果中出现的信息。计算可能从多个来源获取信息,并以复杂的方式将其组合以产生输出。这些输出通常不是一种容易被人们直接读取的格式,因此计算的输出可能会在我们不知情的情况下“泄露”信息。该项目使用一种叫做定量信息流分析的技术来解决这个问题,这种技术允许一个计算机程序自动确定另一个计算机程序揭示了多少信息。例如,这样的分析系统可能报告一个程序总是显示4位的秘密信息,而另一个程序在最近的执行中显示了1000位的秘密信息。通过将这些测量值与程序的预期行为进行比较,可以检测可能导致程序显示不应该显示的信息的情况。以前的定量信息流分析系统已经证明了基本方法是可靠的,但是它们在有效的程序的种类和规模上受到限制,并且它们需要软件开发人员的指导才能获得良好的结果。该项目将开发新的技术,消除这些限制,使定量信息流分析更广泛地适用。定量信息流技术测量由计算输出显示的关于秘密计算输入的信息位的数量,给出了可以单独评估的测量,而不参考计算结果的预期含义,也不需要对主题程序进行额外的注释或说明。通过将定量分析与来自污点分析和符号执行的技术相结合,这些工具可以以精确的方式跟踪秘密信息的流向,以及输入值和输出值之间的联系。定量信息流测量还没有看到实际应用,因为现有的方法开销太高,不能自然地支持多种秘密数据,在它们应用的软件中受到限制,并且/或者需要偶尔的开发人员注释。该项目旨在通过推广基础技术并提高其精度来克服先前方法的局限性,同时通过阶段优化和完全自动化来提高其性能和适用性。该研究将通过应用于计算机安全和隐私中的一些现实挑战问题来证明该方法。
英文摘要
Concern about information privacy is a major obstacle to user adoption of new information technology applications, from smart phone applications to the deployment of automated workflows in the largest health-care and government enterprises. This project addresses privacy concerns caused by software through errors and malicious attacks. A major security concern about software revolves around whether computers reveal information that they should not. Much of the information we entrust to computers might be described as secret, private, or confidential, because we want to limit who has access to it. However many things can go wrong in computer systems to allow information to be revealed when it should not. In this project the focus is on the information that is present in the results of a computation. A computation might take information from several sources and combine it in a complex way to produce output. These outputs are usually not in a format that can easily be read directly by people, thus the output from a computation may be undesirably "leaking" information without our knowledge. The project tackles this problem using techniques called quantitative information flow analysis, which allow one computer program to automatically determine how much information another computer program is revealing. For instance, such an analysis system might report that one program always reveals 4 bits of secret information, while another program revealed 1000 bits of secret information in its most recent execution. By comparing these measurements to the expected behavior of a program, one can detect situations that might be causing a program to reveal information that it should not. Previous quantitative information flow analysis systems have demonstrated that the basic approach is sound, but they have been limited in the kinds and sizes of programs where they are effective, and they require guidance from software developers to obtain good results. This project will develop new techniques that eliminate these restrictions to make quantitative information flow analysis more widely applicable. The quantitative information-flow techniques, which measure the number of bits of information about secret computation inputs that are revealed by computation outputs, give a measurement that can be evaluated separately without reference to the intended meaning of the computation results and without additional annotation or specification of the subject program. By combining a quantitative analysis with techniques from taint analysis and symbolic execution, the tools can track in a precise way where secret information flows, and the connection between input values and output values. Quantitative information-flow measurement has not yet seen practical adoption because existing approaches have too high overhead, do not naturally support multiple kinds of secret data, are limited in the software to which they apply, and/or require occasional developer annotations. The project seeks to overcome the limitations of previous approaches by generalizing the underlying techniques and improving their precision, while at the same time improving their performance and applicability via staged optimizations and complete automation. The research will demonstrate the approach by application to a number of realistic challenge problems in computer security and privacy.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
登录
查看更多内容
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:张祥忠
-
依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
-
批准号:32000033
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:林平
-
依托单位:
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
-
批准号:31972324
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:高学文
-
依托单位:
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
-
批准号:81900988
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2019
-
负责人:毛梦莹
-
依托单位:
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
-
批准号:31870821
-
项目类别:面上项目
-
资助金额:56.0万元
-
批准年份:2018
-
负责人:陈江宁
-
依托单位:
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
-
批准号:31802058
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2018
-
负责人:麻慧
-
依托单位:
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
-
批准号:31772128
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2017
-
负责人:吴建国
-
依托单位:
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
-
批准号:81704176
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2017
-
负责人:赵继梦
-
依托单位:
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
-
批准号:91640114
-
项目类别:重大研究计划
-
资助金额:85.0万元
-
批准年份:2016
-
负责人:何祖华
-
依托单位: