QUAIL: A Quantitative Security Analyzer for Imperative Code
Biondi, Fabrizio;Legay, Axel;Traonouez, Louis-Marie;Wasowski, Andrzej
(2013) CAV 2013 - 25th International Conference on Computer Aided Verification (13.July.2013)
Files
No attached file found for this publication.
Details
Authors
Biondi, Fabrizio
Author
Legay, AxelUCLouvain
Author
Traonouez, Louis-Marie
Author
Wasowski, Andrzej
Author
Abstract
Quantitative security analysis evaluates and compares how effectively a system protects its secret data. We introduce QUAIL, the first tool able to perform an arbitrary-precision quantitative analysis of the security of a system depending on private information. QUAIL builds a Markov Chain model of the system's behavior as observed by an attacker, and computes the correlation between the system's observable output and the behavior depending on the private information, obtaining the expected amount of bits of the secret that the attacker will infer by observing the system. QUAIL is able to evaluate the safety of randomized protocols depending on secret data, allowing to verify a security protocol's effectiveness. We experiment with a few examples and show that QUAIL's security analysis is more accurate and revealing than results of other tools.
Citations
APA
Chicago
FWB
Biondi, F., Legay, A., Traonouez, L.-M., & Wasowski, A. (2013). QUAIL: A Quantitative Security Analyzer for Imperative Code. Computer Aided Verification Lecture Notes in Computer Science. CAV 2013 - 25th International Conference on Computer Aided Verification. https://doi.org/10.1007/978-3-642-39799-8_49