HyLeak: Hybrid Analysis Tool for Information Leakage - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2017

HyLeak: Hybrid Analysis Tool for Information Leakage

Résumé

We present HyLeak, a tool for reasoning about the quantity of information leakage in programs. The tool takes as input the source code of a program and analyzes it to estimate the amount of leaked information measured by mutual information. The leakage estimation is mainly based on a hybrid method that combines precise program analysis with statistical analysis using stochastic program simulation. This way, the tool combines the best of both symbolic and randomized techniques to provide more accurate estimates with cheaper analysis, in comparison with the previous tools using one of the analysis methods alone. HyLeak is publicly available and is able to evaluate the information leakage of randomized programs, even when the secret domain is large. We demonstrate with examples that HyLeaks has the best performance among the tools that are able to analyze randomized programs with similarly high precision of estimates.
Fichier principal
Vignette du fichier
main.pdf (392.38 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01546817 , version 1 (26-06-2017)

Identifiants

  • HAL Id : hal-01546817 , version 1

Citer

Fabrizio Biondi, Yusuke Kawamoto, Axel Legay, Louis-Marie Traonouez. HyLeak: Hybrid Analysis Tool for Information Leakage. ATVA 2017 - Fifteenth International Symposium on Automated Technology for Verification and Analysis, Oct 2017, Pune, India. pp.14. ⟨hal-01546817⟩
392 Consultations
195 Téléchargements

Partager

Gmail Facebook X LinkedIn More