HyLeak: Hybrid Analysis Tool for Information Leakage

Abstract : We present HyLeak, a tool for reasoning about the quantity of information leakage in programs. The tool takes as input the source code of a program and analyzes it to estimate the amount of leaked information measured by mutual information. The leakage estimation is mainly based on a hybrid method that combines precise program analysis with statistical analysis using stochastic program simulation. This way, the tool combines the best of both symbolic and randomized techniques to provide more accurate estimates with cheaper analysis, in comparison with the previous tools using one of the analysis methods alone. HyLeak is publicly available and is able to evaluate the information leakage of randomized programs, even when the secret domain is large. We demonstrate with examples that HyLeaks has the best performance among the tools that are able to analyze randomized programs with similarly high precision of estimates.
Type de document :
Communication dans un congrès
ATVA 2017 - Fifteenth International Symposium on Automated Technology for Verification and Analysis, Oct 2017, Pune, India. pp.14
Liste complète des métadonnées

Littérature citée [18 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01546817
Contributeur : Fabrizio Biondi <>
Soumis le : lundi 26 juin 2017 - 10:10:12
Dernière modification le : mercredi 11 avril 2018 - 02:01:11
Document(s) archivé(s) le : mercredi 17 janvier 2018 - 16:21:06

Fichier

main.pdf
Fichiers produits par l'(les) auteur(s)

Identifiants

  • HAL Id : hal-01546817, version 1

Citation

Fabrizio Biondi, Yusuke Kawamoto, Axel Legay, Louis-Marie Traonouez. HyLeak: Hybrid Analysis Tool for Information Leakage. ATVA 2017 - Fifteenth International Symposium on Automated Technology for Verification and Analysis, Oct 2017, Pune, India. pp.14. 〈hal-01546817〉

Partager

Métriques

Consultations de la notice

297

Téléchargements de fichiers

69