Reconciling Belief and Vulnerability in Information Flow

Sardaouna Hamadou 1 Vladimiro Sassone 1 Catuscia Palamidessi 2
2 COMETE - Concurrency, Mobility and Transactions
LIX - Laboratoire d'informatique de l'École polytechnique [Palaiseau], Inria Saclay - Ile de France, Polytechnique - X, CNRS - Centre National de la Recherche Scientifique : UMR7161
Abstract : Belief and vulnerability have been proposed recently to quantify information flow in security systems. Both concepts stand as alternatives to the traditional approaches founded on Shannon entropy and mutual information, which were shown to provide inadequate security guarantees. In this paper we unify the two concepts in one model so as to cope with (potentially inaccurate) attackers' extra knowledge. To this end we propose a new metric based on vulnerability that takes into account the adversary's beliefs.
Document type :
Conference papers
31st IEEE Symposium on Security and Privacy, May 2010, Berleley/Oakland, California, United States. IEEE Computer Society, pp.79-92, 2010, 〈10.1109/SP.2010.13〉
Liste complète des métadonnées

Cited literature [35 references]  Display  Hide  Download

https://hal.inria.fr/inria-00548007
Contributor : Catuscia Palamidessi <>
Submitted on : Sunday, December 19, 2010 - 7:47:31 PM
Last modification on : Thursday, February 9, 2017 - 3:10:49 PM
Document(s) archivé(s) le : Monday, November 5, 2012 - 2:35:44 PM

File

BANDV.pdf
Files produced by the author(s)

Identifiers

Collections

Citation

Sardaouna Hamadou, Vladimiro Sassone, Catuscia Palamidessi. Reconciling Belief and Vulnerability in Information Flow. 31st IEEE Symposium on Security and Privacy, May 2010, Berleley/Oakland, California, United States. IEEE Computer Society, pp.79-92, 2010, 〈10.1109/SP.2010.13〉. 〈inria-00548007〉

Share

Metrics

Record views

321

Document downloads

132