• Home
  • Search
  • Scalable Approximation of Quantitative Information Flow in Programs
  • Cite Icon37
  • https://doi.org/10.1007/978-3-319-73721-8_4Copy DOI Icon

Scalable Approximation of Quantitative Information Flow in Programs

  • Dec 29, 2017
  • Fabrizio Biondi +5 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Quantitative information flow measurement techniques have been proven to be successful in detecting leakage of confidential information from programs. Modern approaches are based on formal methods, relying on program analysis to produce a SAT formula representing the program’s behavior, and model counting to measure the possible information flow. However, while program analysis scales to large codebases like the OpenSSL project, the formulas produced are too complex for analysis with precise model counting. In this paper we use the approximate model counter ApproxMC2 to quantify information flow. We show that ApproxMC2 is able to provide a large performance increase for a very small loss of precision, allowing the analysis of SAT formulas produced from complex code. We call the resulting technique ApproxFlow and test it on a large set of benchmarks against the state of the art. Finally, we show that ApproxFlow can evaluate the leakage incurred by the Heartbleed OpenSSL bug, contrarily to the state of the art.

Similar Papers
  • Research Article

SAT를 이용한 정보흐름의 안전성 분석

  • Jun 28, 2016
  • Journal of Digital Convergence
  • Je-Min Kim +1
  • PDF
  • Research Article
  • Citations4

Refinement Orders for Quantitative Information Flow and Differential Privacy

  • Dec 12, 2020
  • Journal of Cybersecurity and Privacy
  • Konstantinos Chatzikokolakis +2
  • Book Chapter
  • Citations61

On the Relation between Differential Privacy and Quantitative Information Flow

  • Jan 01, 2011
  • Mário S Alvim +3
  • Research Article
  • Citations143

Quantitative Information Flow, Relations and Polymorphic Types

  • Apr 01, 2005
  • Journal of Logic and Computation
  • D Clark
  • Book Chapter
  • Citations195

Termination-Insensitive Noninterference Leaks More Than Just a Bit

  • Jan 01, 2008
  • Aslan Askarov +3
  • Research Article
  • Citations50

Measuring the strength of information flows in programs

  • Oct 01, 2009
  • ACM Transactions on Software Engineering and Methodology
  • Wes Masri +1
  • Book Chapter

Slice-Based Information Flow Graph

  • Jan 01, 2004
  • Wan-Kyoo Choi +1
  • Conference Article
  • Citations2

QQIF: Quantum Quantitative Information Flow (invited paper)

  • Sep 01, 2020
  • Arthur Americo +1
  • Research Article
  • Citations23

Approximate counting in SMT and value estimation for probabilistic programs

  • Apr 12, 2017
  • Acta Informatica
  • Dmitry Chistikov +2
  • Research Article
  • Citations10

A multi-flow information flow tracking approach for proving quantitative hardware security properties

  • Jul 20, 2020
  • Tsinghua Science and Technology
  • Yu Tai +4
  • Research Article
  • Citations8

Instruction-level security typing by abstract interpretation

  • Feb 13, 2007
  • International Journal of Information Security
  • Nicoletta De Francesco +1
  • Conference Article
  • Citations184

Quantitative information flow as network flow capacity

  • Jun 07, 2008
  • Stephen Mccamant +1
  • Conference Article
  • Citations37

Hypercollecting semantics and its application to static analysis of information flow

  • Jan 01, 2017
  • Mounir Assaf +4
  • Research Article
  • Citations5

Privacy in elections: How small is “small”?

  • Aug 30, 2017
  • Journal of Information Security and Applications
  • Annabelle Mciver +3
  • Conference Article
  • Citations23

All-Solution Satisfiability Modulo Theories: Applications, Algorithms and Benchmarks

  • Aug 01, 2015
  • Quoc-Sang Phan +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.