Information Security as Strategic (In)effectivity
Wojciech Jamroga,Masoud Tabatabaei
DOI: https://doi.org/10.48550/arXiv.1608.02247
2016-08-08
Abstract:Security of information flow is commonly understood as preventing any information leakage, regardless of how grave or harmless consequences the leakage can have. In this work, we suggest that information security is not a goal in itself, but rather a means of preventing potential attackers from compromising the correct behavior of the system. To formalize this, we first show how two information flows can be compared by looking at the adversary's ability to harm the system. Then, we propose that the information flow in a system is effectively information-secure if it does not allow for more harm than its idealized variant based on the classical notion of noninterference.
Cryptography and Security
What problem does this paper attempt to address?