Invention Grant
- Patent Title: Quantitative analysis of information leakage vulnerabilities
-
Application No.: US14661145Application Date: 2015-03-18
-
Publication No.: US09251352B2Publication Date: 2016-02-02
- Inventor: Marco Pistoia , Omer Tripp
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Harrington & Smith
- Main IPC: G06F21/74
- IPC: G06F21/74 ; G06F21/57 ; H04L29/08 ; H04L12/24 ; G06F21/54 ; G06F3/0481 ; G06F9/48

Abstract:
A method includes recording, during execution of a program and by a computing system, concrete values exhibited at source and sink statements in the program. The source statements read confidential information and the sink statements release the confidential information to an outside environment. The method includes determining, by the computing system, using at least the recorded concrete values and source-sink pairs whether information leakage meeting one or more quantitative criteria occurs by the program. Apparatus and program products are also disclosed.
Public/Granted literature
- US20150193623A1 Quantitative Analysis Of Information Leakage Vulnerabilities Public/Granted day:2015-07-09
Information query