2010/09/20 by Ji Zhu, Zhu Ji, Zhu, Ji +2
Computer Science · Mathematics · #Advanced Malware Detection Techniques #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Information Theory (cs.IT) #Network Security and Intrusion Detection #Security and Verification in Computing #cs.CR #cs.IT #math.IT
paper · pdf · doi:10.48550/arxiv.1009.3951
14 pages, 1 figure. A shorter version of this paper is submitted to ICC 2011
arxiv created 2010/09/20 · openalex publication_date 2010/09/20 · arxiv updated 2010/09/22 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Information flow analysis is a powerful technique for reasoning about the sensitive information exposed by a program during its execution. While past work has proposed information theoretic metrics (e.g., Shannon entropy, min-entropy, guessing entropy, etc.) to quantify such information leakage, we argue that some of these measures not only result in counter-intuitive measures of leakage, but also are inherently prone to conflicts when comparing two programs P1 and P2 -- say Shannon entropy predicts higher leakage for program P1, while guessing entropy predicts higher leakage for program P2. This paper presents the first attempt towards addressing such conflicts and derives solutions for conflict-free comparison of finite order deterministic programs.