pith. sign in

arxiv: 1608.02247 · v1 · pith:3D3WJF65new · submitted 2016-08-07 · 💻 cs.CR

Information Security as Strategic (In)effectivity

classification 💻 cs.CR
keywords informationsecuritysystemflowharmleakagepreventingability
0
0 comments X
read the original abstract

Security of information flow is commonly understood as preventing any information leakage, regardless of how grave or harmless consequences the leakage can have. In this work, we suggest that information security is not a goal in itself, but rather a means of preventing potential attackers from compromising the correct behavior of the system. To formalize this, we first show how two information flows can be compared by looking at the adversary's ability to harm the system. Then, we propose that the information flow in a system is effectively information-secure if it does not allow for more harm than its idealized variant based on the classical notion of noninterference.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.