Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
On the Relationship between Confidentiality Measures: Entropy and Guesswork
Karlstads universitet, Fakulteten för ekonomi, kommunikation och IT, Avdelningen för datavetenskap. (PriSec)
Karlstads universitet, Fakulteten för ekonomi, kommunikation och IT, Avdelningen för datavetenskap. (PriSec)ORCID-id: 0000-0003-0778-4736
Karlstads universitet, Fakulteten för ekonomi, kommunikation och IT, Avdelningen för datavetenskap. (PriSec)ORCID-id: 0000-0003-0861-2813
2007 (engelsk)Inngår i: WOSIS / [ed] Mariemma Inmaculada Yagüe del Valle and Eduardo Fernández-Medina, INSTICC Press , 2007, s. 135-144Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

In this paper, we investigate in detail the relationship between entropy and guesswork. The aim of the study is to lay the ground for future efficiency comparison of guessing strategies. After a short discussion of the two measures, and the differences between them, the formal definitions are given. Then, a redefinition of guesswork is made, since the measure is not completely accurate. The change is a minor modification in the last term of the sum expressing guesswork. Finally, two theorems are stated. The first states that the redefined guesswork is equal to the concept of cross entropy, and the second states, as a consequence of the first theorem, that the redefined guesswork is equal to the sum of the entropy and the relative entropy.

sted, utgiver, år, opplag, sider
INSTICC Press , 2007. s. 135-144
HSV kategori
Forskningsprogram
Datavetenskap
Identifikatorer
URN: urn:nbn:se:kau:diva-1916ISBN: 978-972-8865-96-2 (tryckt)OAI: oai:DiVA.org:kau-1916DiVA, id: diva2:5015
Konferanse
Proceedings of the 5th International Workshop on Security in Information Systems (WOSIS 2007), In conjunction with ICEIS 2007, Funchal, Madeira, Portugal, June 2007
Tilgjengelig fra: 2007-10-09 Laget: 2007-10-09 Sist oppdatert: 2019-07-12bibliografisk kontrollert
Inngår i avhandling
1. Towards Measurable and Tunable Security
Åpne denne publikasjonen i ny fane eller vindu >>Towards Measurable and Tunable Security
2007 (engelsk)Licentiatavhandling, med artikler (Annet vitenskapelig)
Abstract [en]

Many security services today only provides one security configuration at run-time, and cannot then utilize the trade-off between performance and security. In order to make use of this trade-off, tunable security services providing several security configurations that can be selected at run-time are needed. To be able to make intelligent choices on which security configuration to use for different situations we need to know how good they are, i.e., we need to order the different security configurations with respect to each security attribute using measures for both security and performance.

However, a key issue with computer security is that it is due to its complex nature hard to measure.

As the title of this thesis indicates, it discusses both security measures and tunable security services. Thus, it can be seen to consist of two parts. In the first part, discussing security measures for tunable security services, an investigation on the security implications of selective encryption by using guesswork as a security measure is made. Built on this an investigation of the relationship between guesswork and entropy. The result shows that guesswork,

after a minor redefinition, is equal to the sum of the entropy and the relative entropy.

The second part contributes to the area of tunable security services, e.g., services that provides several security configurations at run-time. In particular, we present the mobile Crowds (mCrowds) system,

an anonymity technology for the mobile Internet developed at Karlstad University, and a tunable encryption service, that is based on a selective encryption paradigm and designed as a middleware. Finally, an investigation of the tunable features provided by Mix-Nets and Crowds are done, using a conceptual model for tunable security services.

sted, utgiver, år, opplag, sider
Fakulteten för ekonomi, kommunikation och IT, 2007
Serie
Karlstad University Studies, ISSN 1403-8099 ; 2007:39
Emneord
tunable security, security measures, metrics, entropy, guesswork, privacy, anonymity, selective encryption
HSV kategori
Forskningsprogram
Datavetenskap
Identifikatorer
urn:nbn:se:kau:diva-1200 (URN)978-91-7063-142-9 (ISBN)
Presentation
2007-10-23, Sjöströmsalen, 1B 309, Karlstads universitet, Karlstad, 10:00
Opponent
Veileder
Tilgjengelig fra: 2007-10-09 Laget: 2007-10-09 Sist oppdatert: 2018-01-12
2. Guesswork and Entropy as Security Measures for Selective Encryption
Åpne denne publikasjonen i ny fane eller vindu >>Guesswork and Entropy as Security Measures for Selective Encryption
2012 (engelsk)Doktoravhandling, med artikler (Annet vitenskapelig)
Abstract [en]

More and more effort is being spent on security improvements in today's computer environments, with the aim to achieve an appropriate level of security. However, for small computing devices it might be necessary to reduce the computational cost imposed by security in order to gain reasonable performance and/or energy consumption. To accomplish this selective encryption can be used, which provides confidentiality by only encrypting chosen parts of the information. Previous work on selective encryption has chiefly focused on how to reduce the computational cost while still making the information perceptually secure, but not on how computationally secure the selectively encrypted information is. 

Despite the efforts made and due to the harsh nature of computer security, good quantitative assessment methods for computer security are still lacking. Inventing new ways of measuring security are therefore needed in order to better understand, assess, and improve the security of computer environments. Two proposed probabilistic quantitative security measures are entropy and guesswork. Entropy gives the average number of guesses in an optimal binary search attack, and guesswork gives the average number of guesses in an optimal linear search attack. In information theory, a considerable amount of research has been carried out on entropy and on entropy-based metrics. However, the same does not hold for guesswork.

In this thesis, we evaluate the performance improvement when using the proposed generic selective encryption scheme. We also examine the confidentiality strength of selectively encrypted information by using and adopting entropy and guesswork. Moreover, since guesswork has been less theoretical investigated compared to entropy, we extend guesswork in several ways and investigate some of its behaviors.

sted, utgiver, år, opplag, sider
Karlstad: Karlstad University Press, 2012. s. 30
Serie
Karlstad University Studies, ISSN 1403-8099 ; 2012:36
Emneord
Computer security, security metrics, selective encryption, confidentiality, entropy, guesswork.
HSV kategori
Forskningsprogram
Datavetenskap
Identifikatorer
urn:nbn:se:kau:diva-14032 (URN)978-91-7063-443-7 (ISBN)
Disputas
2012-09-27, 9C 203, Karlstads universitet, 65187 Karlstad, 13:15 (engelsk)
Opponent
Veileder
Tilgjengelig fra: 2012-09-04 Laget: 2012-06-28 Sist oppdatert: 2018-06-25bibliografisk kontrollert

Open Access i DiVA

Fulltekst mangler i DiVA

Andre lenker

http://www.iceis.org/iceis2007/workshops/wosis/wosis2007-cfp.html

Personposter BETA

Lundin, ReineLindskog, StefanHolleboom, Thijs

Søk i DiVA

Av forfatter/redaktør
Lundin, ReineLindskog, StefanHolleboom, Thijs
Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar

isbn
urn-nbn

Altmetric

isbn
urn-nbn
Totalt: 752 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf