Inferring Secrets by Guided Experiments.

Quoc Huy Do,Richard Bubel, Reiner Hähnle

Lecture Notes in Computer Science(2017)

引用 1|浏览29
暂无评分
摘要
A program has secure information flow if it does not leak any secret information to publicly observable output. A large number of static and dynamic analyses have been devised to check programs for secure information flow. In this paper, we present an algorithm that can carry out a systematic and efficient attack to automatically extract secrets from an insecure program. The algorithm combines static analysis and dynamic execution. The attacker strategy learns from past experiments and chooses as its next attack one that promises maximal knowledge gain about the secret. The idea is to provide the software developer with concrete information about the severity of an information leakage.
更多
查看译文
关键词
Information flow,Symbolic execution,Static analysis
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要