Information Leakage by Trace Analysis in QUAIL

Fabrizio Biondi 1 Jean Quilbeuf 1 Axel Legay 1
1 ESTASYS - Efficient STAtistical methods in SYstems of systems
Inria Rennes – Bretagne Atlantique , IRISA-D4 - LANGAGE ET GÉNIE LOGICIEL
Abstract : Quantitative security techniques have been proven effective to measure the security of systems against various types of attackers. However, such tech-niques are based on computing exponentially large channel matrices or Markov chains, making them impractical for large programs. We propose a different ap-proach based on abstract trace analysis. By analyzing directly sets of execution traces of the program and computing security measures on the results, we are able to scale down the exponential cost of the problem. Also, we are able to appy statistical simulation techniques, allowing us to obtain significant results even without exploring the full space of traces. We have implemented the resulting algorithms in the QUAIL tool. We compare their effectiveness against the state of the art LeakWatch tool on two case studies: privacy of user consumption in smart grid systems and anonymity of voters in different voting schemes.
Liste complète des métadonnées

Littérature citée [21 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01088208
Contributeur : Fabrizio Biondi <>
Soumis le : jeudi 27 novembre 2014 - 16:03:30
Dernière modification le : mercredi 11 avril 2018 - 02:00:48
Document(s) archivé(s) le : vendredi 14 avril 2017 - 21:59:23

Fichier

main.pdf
Fichiers produits par l'(les) auteur(s)

Identifiants

  • HAL Id : hal-01088208, version 1

Citation

Fabrizio Biondi, Jean Quilbeuf, Axel Legay. Information Leakage by Trace Analysis in QUAIL. 2014. 〈hal-01088208〉

Partager

Métriques

Consultations de la notice

330

Téléchargements de fichiers

92