• DocumentCode
    2845235
  • Title

    A Precise Information Flow Measure from Imprecise Probabilities

  • Author

    Hussein, Sari Haj

  • Author_Institution
    Dept. of Comput. Sci., Aalborg Univ., Aalborg, Denmark
  • fYear
    2012
  • fDate
    20-22 June 2012
  • Firstpage
    128
  • Lastpage
    137
  • Abstract
    Dempster-Shafer theory of imprecise probabilities has proved useful to incorporate both nonspecificity and conflict uncertainties in an inference mechanism. The traditional Bayesian approach cannot differentiate between the two, and is unable to handle non-specific, ambiguous, and conflicting information without making strong assumptions. This paper presents a generalization of a recent Bayesian-based method of quantifying information flow in Dempster-Shafer theory. The generalization concretely enhances the original method removing all its weaknesses that are highlighted in this paper. In so many words, our generalized method can handle any number of secret inputs to a program, it enables the capturing of an attacker´s beliefs in all kinds of sets (singleton or not), and it supports a new and precise quantitative information flow measure whose reported flow results are plausible in that they are bounded by the size of a program´s secret input, and can be easily associated with the exhaustive search effort needed to uncover a program´s secret information, unlike the results reported by the original metric.
  • Keywords
    belief networks; inference mechanisms; probability; security of data; Bayesian-based method; Dempster-Shafer theory; attacker belief; computer security; imprecise probabilities; inference mechanism; program secret information; quantitative information flow measure; Aggregates; Bayesian methods; Joints; Measurement uncertainty; Probability distribution; Uncertainty; Dempster-Shafer theory; computer security; imprecise probabilities; inference; information theory; program analysis; quantitative information flow; uncertainty;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Security and Reliability (SERE), 2012 IEEE Sixth International Conference on
  • Conference_Location
    Gaithersburg, MD
  • Print_ISBN
    978-1-4673-2067-2
  • Type

    conf

  • DOI
    10.1109/SERE.2012.25
  • Filename
    6258302