Skip to main content
QUICK REVIEW

[论文解读] Compositional closure for Bayes Risk in probabilistic noninterference

Annabelle McIver, Larissa Meinicke|arXiv (Cornell University)|Jul 7, 2010
Security and Verification in Computing参考文献 17被引用 5
一句话总结

本文提出了一种基于贝叶斯风险的随机非干扰安全的组合式细化顺序,通过分层规格说明与实现支持安全系统开发。证明了该细化顺序是基于贝叶斯风险的原始测试顺序的组合闭包,确保组合下的安全规格仍保持安全,通过三名裁判协议的应用,展示了正确性证明的实用简化。

ABSTRACT

We give a sequential model for noninterference security including probability (but not demonic choice), thus supporting reasoning about the likelihood that high-security values might be revealed by observations of low-security activity. Our novel methodological contribution is the definition of a refinement order and its use to compare security measures between specifications and (their supposed) implementations. This contrasts with the more common practice of evaluating the security of individual programs in isolation. The appropriateness of our model and order is supported by our showing that our refinement order is the greatest compositional relation --the compositional closure-- with respect to our semantics and an "elementary" order based on Bayes Risk --- a security measure already in widespread use. We also relate refinement to other measures such as Shannon Entropy. By applying the approach to a non-trivial example, the anonymous-majority Three-Judges protocol, we demonstrate by example that correctness arguments can be simplified by the sort of layered developments --through levels of increasing detail-- that are allowed and encouraged by compositional semantics.

研究动机与目标

  • 开发一种形式化细化关系,支持在具有安全敏感数据的系统中对随机非干扰进行组合式推理。
  • 基于贝叶斯风险定义一种安全度量,实现对规格说明与实现的定量比较。
  • 建立所提出的细化顺序是基于贝叶斯风险的原始测试顺序的最大的组合关系。
  • 通过一个非平凡的案例研究——匿名多数三名裁判协议,展示该框架的实际效用。
  • 通过支持分层、模块化的验证,弥合理论安全度量与实际程序开发之间的差距。

提出的方法

  • 为无非难选择的程序提出一种顺序的随机语义,通过高变量与低变量上的分布来建模状态演化。
  • 基于贝叶斯风险定义一种原始测试顺序,衡量从低观察中正确推断高变量的概率。
  • 引入一个细化顺序 $\mathrel{\sqsubseteq}$,用于比较规格说明与实现,确保若 $S \mathrel{\sqsubseteq} I$,则 $I$ 在贝叶斯风险下至少与 $S$ 一样安全。
  • 证明 $\mathrel{\sqsubseteq}$ 是基于贝叶斯风险的原始顺序 $\mathrel{\preceq}$ 的组合闭包,意味着其在程序组合下保持安全性。
  • 使用分布和超分布的矩阵表示,形式化定义并推理细化关系及其闭包性质。
  • 将该框架应用于三名裁判协议,表明通过分层细化可显著简化正确性论证。

实验结果

研究问题

  • RQ1能否定义一种细化顺序,使得在使用贝叶斯风险作为安全度量时,组合下的安全性得以保证?
  • RQ2所提出的细化顺序是否是基于贝叶斯风险的原始测试顺序的最大组合关系?
  • RQ3如何通过此细化框架在随机非干扰中支持分层、模块化的验证?
  • RQ4该方法在如三名裁判系统等非平凡协议中,能在多大程度上简化正确性证明?
  • RQ5该细化顺序与其他信息度量(如香农熵)有何关联?

主要发现

  • 证明了细化顺序 $\mathrel{\sqsubseteq}$ 是基于贝叶斯风险的原始测试顺序 $\mathrel{\preceq}$ 的组合闭包,确保安全性在组合下得以保持。
  • 该框架通过允许在规格说明层面检查安全属性,并通过细化传递给实现,支持模块化验证。
  • 三名裁判协议的案例研究表明,基于该细化顺序的分层开发可使正确性论证显著简化。
  • 该方法将贝叶斯风险与其他度量(如香农熵)关联起来,表明基于贝叶斯风险的细化意味着在其他不确定性度量下也具备安全性。
  • 该方法通过允许从更简单、抽象的规格说明推断复杂实现的安全性,支持高效分析,减少冗余计算。
  • 使用分布和超分布的矩阵表示,为推理细化关系及其性质提供了构造性且形式化的基础。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。