作者
Tom Chothia, Yusuke Kawamoto, Chris Novakovic
发表日期
2014
研讨会论文
Computer Security-ESORICS 2014: 19th European Symposium on Research in Computer Security, Wroclaw, Poland, September 7-11, 2014. Proceedings, Part II 19
页码范围
219-236
出版商
Springer International Publishing
简介
Programs that process secret data may inadvertently reveal information about those secrets in their publicly-observable output. This paper presents LeakWatch, a quantitative information leakage analysis tool for the Java programming language; it is based on a flexible “point-to-point” information leakage model, where secret and publicly-observable data may occur at any time during a program’s execution. LeakWatch repeatedly executes a Java program containing both secret and publicly-observable data and uses robust statistical techniques to provide estimates, with confidence intervals, for min-entropy leakage (using a new theoretical result presented in this paper) and mutual information.We demonstrate how LeakWatch can be used to estimate the size of information leaks in a range of real-world Java programs.
引用总数
201420152016201720182019202020212022202320245667612761042
学术搜索中的文章
T Chothia, Y Kawamoto, C Novakovic - Computer Security-ESORICS 2014: 19th European …, 2014
T Chothia, Y Kawamoto, C Novakovic