{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T07:54:42Z","timestamp":1761983682462,"version":"build-2065373602"},"reference-count":92,"publisher":"Cambridge University Press (CUP)","issue":"2","license":[{"start":{"date-parts":[[2014,11,10]],"date-time":"2014-11-10T00:00:00Z","timestamp":1415577600000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/www.cambridge.org\/core\/terms"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Math. Struct. Comp. Sci."],"published-print":{"date-parts":[[2015,2]]},"abstract":"<jats:p>Three integrity measures are introduced: contamination, channel suppression and program suppression. Contamination is a measure of how much untrusted information reaches trusted outputs; it is the dual of leakage, which is a measure of information-flow confidentiality. Channel suppression is a measure of how much information about inputs to a noisy channel is missing from the channel outputs. And program suppression is a measure of how much information about the correct output of a program is lost because of attacker influence and implementation errors. Program and channel suppression do not have interesting confidentiality duals. As a case study, a quantitative relationship between integrity, confidentiality and database privacy is examined.<\/jats:p>","DOI":"10.1017\/s0960129513000595","type":"journal-article","created":{"date-parts":[[2014,11,10]],"date-time":"2014-11-10T17:58:11Z","timestamp":1415642291000},"page":"207-258","source":"Crossref","is-referenced-by-count":12,"title":["Quantification of integrity"],"prefix":"10.1017","volume":"25","author":[{"given":"MICHAEL R.","family":"CLARKSON","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"FRED B.","family":"SCHNEIDER","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"56","published-online":{"date-parts":[[2014,11,10]]},"reference":[{"key":"S0960129513000595_ref68","unstructured":"Newsome J. and Song D. (2005) Dynamic taint analysis for automatic detection, analysis and signature generation of exploits on commodity software. In: Proceedings Symposium on Network and Distributed System Security. Available from http:\/\/www.isoc.org\/isoc\/conferences\/ndss\/05\/proceedings\/papers\/taintcheck.pdf."},{"key":"S0960129513000595_ref65","doi-asserted-by":"publisher","DOI":"10.1145\/292540.292561"},{"key":"S0960129513000595_ref63","doi-asserted-by":"crossref","unstructured":"Millen J. (1987) Covert channel capacity. In: Proceedings IEEE Symposium on Security and Privacy 60\u201366.","DOI":"10.1109\/SP.1987.10013"},{"key":"S0960129513000595_ref60","unstructured":"McCullough D. (1987) Specifications for multi-level security and a hook-up property. In: Proceedings IEEE Symposium on Security and Privacy 161\u2013166."},{"key":"S0960129513000595_ref72","unstructured":"Roy I. , Setty S. T. V. , Kilzer A. , Shmatikov V. and Witchel E. (2010) Airavat: Security and privacy for MapReduce. In: Proceedings USENIX Symposium on Networked Systems Design and Implementation 297\u2013312."},{"key":"S0960129513000595_ref42","unstructured":"International Organization for Standardization (1989) Information processing systems: Open systems interconnection \u2013 basic reference model, Part 2: Security architecture, ISO 7498-2."},{"key":"S0960129513000595_ref40","unstructured":"Heusser J. and Malacaria P. (2009) Applied quantitative information flow and statistical databases. In: Workshop on Formal Aspects in Security and Trust 96\u2013110."},{"key":"S0960129513000595_ref52","unstructured":"Li P. , Mao Y. and Zdancewic S. (2003) Information integrity policies. In: Workshop on Formal Aspects in Security and Trust 53\u201370."},{"key":"S0960129513000595_ref73","doi-asserted-by":"publisher","DOI":"10.1023\/A:1011553200337"},{"key":"S0960129513000595_ref51","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45309-1_6"},{"volume-title":"Elementary Information Theory","year":"1979","author":"Jones","key":"S0960129513000595_ref44"},{"key":"S0960129513000595_ref45","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-6423(99)00024-6"},{"key":"S0960129513000595_ref59","doi-asserted-by":"publisher","DOI":"10.1145\/1375581.1375606"},{"key":"S0960129513000595_ref3","doi-asserted-by":"crossref","unstructured":"Backes M. (2005) Quantifying probabilistic information flow in computational reactive systems. In: Proceedings European Symposium on Research in Computer Security 336\u2013354.","DOI":"10.1007\/11555827_20"},{"key":"S0960129513000595_ref36","doi-asserted-by":"crossref","unstructured":"Gray J. W. III , (1990) Probabilistic interference. In: Proceedings IEEE Symposium on Security and Privacy 170\u2013179.","DOI":"10.1109\/RISP.1990.63848"},{"volume-title":"Computers at Risk: Safe Computing in the Information Age","year":"1991","key":"S0960129513000595_ref66"},{"key":"S0960129513000595_ref34","doi-asserted-by":"crossref","unstructured":"Giacobazzi R. and Mastroeni I. (2004) Abstract non-interference. In: Proceedings ACM Symposium on Principles of Programming Languages 186\u2013197.","DOI":"10.1145\/964001.964017"},{"key":"S0960129513000595_ref33","doi-asserted-by":"publisher","DOI":"10.1145\/1749603.1749605"},{"key":"S0960129513000595_ref53","doi-asserted-by":"crossref","unstructured":"Liu J. , George M. D. , Vikram K. , Qi X. , Waye L. and Myers A. C. (2009) Fabric: A platform for secure distributed computation and storage. In: Proceedings ACM Symposium on Operating Systems Principles 321\u2013334.","DOI":"10.1145\/1629575.1629606"},{"key":"S0960129513000595_ref50","first-page":"19","article-title":"Basic concepts: Logical foundation","volume":"190","author":"Lamport","year":"1985","journal-title":"Springer Lecture Notes in Computer Science"},{"key":"S0960129513000595_ref31","doi-asserted-by":"publisher","DOI":"10.1145\/1806689.1806787"},{"key":"S0960129513000595_ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-17714-9_5"},{"key":"S0960129513000595_ref61","doi-asserted-by":"crossref","unstructured":"McLean J. (1990) Security models and information flow. In: Proceedings IEEE Symposium on Security and Privacy 180\u2013189.","DOI":"10.21236\/ADA462529"},{"key":"S0960129513000595_ref30","doi-asserted-by":"crossref","unstructured":"Dwork C. , McSherry F. , Nissim K. and Smith A. (2006) Calibrating noise to sensitivity in private data analysis. In: Proceedings Theory of Cryptography Conference 265\u2013284.","DOI":"10.1007\/11681878_14"},{"key":"S0960129513000595_ref27","unstructured":"Dean J. and Ghemawat S. (2004) MapReduce: Simplified data processing on large clusters. In: Proceedings USENIX Symposium on Operating System Design and Implementation 137\u2013150."},{"key":"S0960129513000595_ref25","unstructured":"Commission of the European Communities (1991) Information technology security evaluation criteria: Provisional harmonised criteria. Document COM(90) 314, Version 1.2."},{"key":"S0960129513000595_ref41","doi-asserted-by":"crossref","unstructured":"Heusser J. and Malacaria P. (2010) Quantifying information leaks in software. In: Annual Computer Security Applications Conference 261\u2013269.","DOI":"10.1145\/1920261.1920300"},{"key":"S0960129513000595_ref24","doi-asserted-by":"crossref","unstructured":"Clarkson M. R. and Schneider F. B. (2010) Quantification of integrity. In: Proceedings IEEE Computer Security Foundations Symposium 28\u201343.","DOI":"10.1109\/CSF.2010.10"},{"key":"S0960129513000595_ref23","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2009-0353"},{"key":"S0960129513000595_ref87","doi-asserted-by":"publisher","DOI":"10.1145\/356909.356913"},{"key":"S0960129513000595_ref6","doi-asserted-by":"crossref","unstructured":"Barthe G. and K\u00f6pf B. (2011) Information-theoretic bounds for differentially private mechanisms. In: Proceedings IEEE Computer Security Foundations Symposium 191\u2013204.","DOI":"10.1109\/CSF.2011.20"},{"key":"S0960129513000595_ref92","doi-asserted-by":"crossref","unstructured":"Zheng L. and Myers A. C. (2005) End-to-end availability policies and noninterference. In: Proceedings IEEE Computer Security Foundations Workshop 272\u2013286.","DOI":"10.1109\/CSFW.2005.16"},{"key":"S0960129513000595_ref49","doi-asserted-by":"publisher","DOI":"10.1145\/1323293.1294293"},{"key":"S0960129513000595_ref47","doi-asserted-by":"crossref","unstructured":"K\u00f6pf B. and Basin D. (2007) An information-theoretic model for adaptive side-channel attacks. In: Proceedings ACM Conference on Computer and Communications Security 286\u2013296.","DOI":"10.1145\/1315245.1315282"},{"key":"S0960129513000595_ref86","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-1999-72-305"},{"key":"S0960129513000595_ref4","unstructured":"Backes M. , K\u00f6pf B. and Rybalchenko A. (2009) Automated discovery and quantification of information leaks. In: Proceedings IEEE Symposium on Security and Privacy 141\u2013153."},{"key":"S0960129513000595_ref57","doi-asserted-by":"crossref","unstructured":"Malacaria P. (2007) Assessing security threats of looping constructs. In: Proceedings ACM Symposium on Principles of Programming Languages 225\u2013235.","DOI":"10.1145\/1190216.1190251"},{"key":"S0960129513000595_ref76","doi-asserted-by":"publisher","DOI":"10.1145\/353323.353382"},{"volume-title":"Cryptography and Data Security","year":"1982","author":"Denning","key":"S0960129513000595_ref28"},{"key":"S0960129513000595_ref69","doi-asserted-by":"publisher","DOI":"10.1016\/S0933-3657(98)00056-6"},{"key":"S0960129513000595_ref83","doi-asserted-by":"publisher","DOI":"10.1142\/S021848850200165X"},{"key":"S0960129513000595_ref62","doi-asserted-by":"publisher","DOI":"10.1109\/32.481534"},{"key":"S0960129513000595_ref26","doi-asserted-by":"publisher","DOI":"10.1002\/0471200611"},{"key":"S0960129513000595_ref21","doi-asserted-by":"crossref","unstructured":"Clark D. D. and Wilson D. R. (1987) A comparison of commercial and military computer security policies. In: Proceedings IEEE Symposium on Security and Privacy 184\u2013194.","DOI":"10.1109\/SP.1987.10001"},{"key":"S0960129513000595_ref70","doi-asserted-by":"publisher","DOI":"10.1145\/596980.596983"},{"key":"S0960129513000595_ref12","doi-asserted-by":"publisher","DOI":"10.1016\/j.ic.2007.07.003"},{"key":"S0960129513000595_ref82","doi-asserted-by":"crossref","unstructured":"Suh G. E. , Lee J. W. , Zhang D. and Devedas S. (2004) Secure program execution via dynamic information flow tracking. In: Proceedings ACM Conference on Architectural Support for Programming Languages and Systems 85\u201396.","DOI":"10.1145\/1024393.1024404"},{"key":"S0960129513000595_ref17","doi-asserted-by":"publisher","DOI":"10.1016\/S1571-0661(04)00290-7"},{"key":"S0960129513000595_ref1","doi-asserted-by":"publisher","DOI":"10.1002\/9781118033265"},{"key":"S0960129513000595_ref2","unstructured":"Alvim M. S. , Chatzikokolakis K. , Degano P. and Palamidessi C. (2010) Differential privacy versus quantitative information flow, Technical Report hal-00548214, INRIA. Available at http:\/\/hal.inria.fr\/hal-00548214\/en."},{"key":"S0960129513000595_ref71","unstructured":"Rinard M. , Cadar C. , Dumitran D. , Roy D. M. , Leu T. and Beebee W. S. Jr. (2004) Enhancing server availability and security through failure-oblivious computing. In: Proceedings USENIX Symposium on Operating System Design and Implementation 303\u2013316."},{"key":"S0960129513000595_ref29","doi-asserted-by":"crossref","unstructured":"Dwork C. (2006) Differential privacy. In: Proceedings International Colloquium on Automata, Languages and Programming 1\u201312.","DOI":"10.1007\/11787006_1"},{"key":"S0960129513000595_ref18","doi-asserted-by":"publisher","DOI":"10.1016\/j.entcs.2004.01.018"},{"key":"S0960129513000595_ref10","doi-asserted-by":"crossref","unstructured":"Braun C. , Chatzikokolakis K. and Palamidessi C. (2008) Compositional methods for information-hiding. In: Proceedings International Conference on Foundations of Software Science and Computation Structures 443\u2013457.","DOI":"10.1007\/978-3-540-78499-9_31"},{"key":"S0960129513000595_ref32","doi-asserted-by":"publisher","DOI":"10.1145\/773153.773174"},{"key":"S0960129513000595_ref11","doi-asserted-by":"crossref","unstructured":"Braun C. , Chatzikokolakis K. and Palamidessi C. (2009) Quantitative notions of leakage for one-try attacks. In: Proceedings Conference on Mathematical Foundations of Programming Semantics 75\u201391.","DOI":"10.1016\/j.entcs.2009.07.085"},{"key":"S0960129513000595_ref14","doi-asserted-by":"publisher","DOI":"10.1145\/1533057.1533087"},{"key":"S0960129513000595_ref56","doi-asserted-by":"publisher","DOI":"10.1145\/1217299.1217302"},{"key":"S0960129513000595_ref54","unstructured":"Livshits V. B. and Lam M. S. (2005) Finding security vulnerabilities in Java applications with static analysis. In: Proceedings USENIX Security Symposium 271\u2013286."},{"key":"S0960129513000595_ref15","doi-asserted-by":"crossref","unstructured":"Chong S. , Liu J. , Myers A. C. , Qi X. , Vikram K. , Zheng L. and Zheng X. (2007a) Secure web applications via automatic partitioning. In: Proceedings ACM Symposium on Operating Systems Principles 31\u201344.","DOI":"10.1145\/1294261.1294265"},{"key":"S0960129513000595_ref16","unstructured":"Chong S. , Vikram K. and Myers A. C. (2007b) SIF: Enforcing confidentiality and integrity in web applications. In: Proceedings USENIX Security Symposium 1\u201316."},{"key":"S0960129513000595_ref19","doi-asserted-by":"publisher","DOI":"10.1093\/logcom\/exi009"},{"key":"S0960129513000595_ref13","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2008-0333"},{"key":"S0960129513000595_ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CSFW.2005.10"},{"volume-title":"Programming Perl","year":"1996","author":"Wall","key":"S0960129513000595_ref88"},{"key":"S0960129513000595_ref74","doi-asserted-by":"publisher","DOI":"10.1109\/69.971193"},{"key":"S0960129513000595_ref75","unstructured":"Samarati P. and Sweeney L. (1998) Protecting privacy when disclosing information: k-anonymity and its enforcement through generalization and suppression, Technical Report SRI-CSL-98-04, Computer Science Laboratory, SRI International. Available from http:\/\/www.csl.sri.com\/papers\/sritr-98-04."},{"key":"S0960129513000595_ref77","article-title":"The need of psychological training.","volume":"19","author":"Scripture","year":"1892","journal-title":"Science"},{"key":"S0960129513000595_ref78","doi-asserted-by":"crossref","DOI":"10.1515\/9780691214696","volume-title":"A Mathematical Theory of Evidence","author":"Shafer","year":"1976"},{"key":"S0960129513000595_ref7","unstructured":"Bell D. E. and LaPadula L. J. (1973) Secure computer systems: Mathematical foundations, Technical Report 2547, Volume I, MITRE Corporation."},{"key":"S0960129513000595_ref79","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1948.tb01338.x"},{"key":"S0960129513000595_ref64","unstructured":"Murphy R. (1996) An analysis of the distribution of birthdays in a calendar year. Available at http:\/\/www.panix.com\/~murphy\/bday.html, accessed Dec. 29, 2009."},{"key":"S0960129513000595_ref80","doi-asserted-by":"crossref","unstructured":"Smith G. (2009) On the foundations of quantitative information flow. In: Proceedings Conference on Foundations of Software Science and Computation Structures 288\u2013302.","DOI":"10.1007\/978-3-642-00596-1_21"},{"key":"S0960129513000595_ref58","doi-asserted-by":"publisher","DOI":"10.1109\/CSFW.2000.856936"},{"key":"S0960129513000595_ref81","doi-asserted-by":"crossref","unstructured":"Smith G. and Volpano D. (1998) Secure information flow in a multi-threaded imperative language. In Proceedings ACM Symposium on Principles of Programming Languages 355\u2013364.","DOI":"10.1145\/268946.268975"},{"key":"S0960129513000595_ref84","doi-asserted-by":"publisher","DOI":"10.1142\/S0218488502001648"},{"key":"S0960129513000595_ref85","doi-asserted-by":"crossref","unstructured":"Volpano D. (2000) Secure introduction of one-way functions. In: Proceedings IEEE Computer Security Foundations Workshop 246\u2013254.","DOI":"10.1109\/CSFW.2000.856941"},{"key":"S0960129513000595_ref89","unstructured":"Xu W. , Bhatkar S. and Sekar R. (2006) Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks. In: Proceedings USENIX Security Symposium 121\u2013136."},{"key":"S0960129513000595_ref90","doi-asserted-by":"publisher","DOI":"10.1109\/CSFW.2001.930133"},{"key":"S0960129513000595_ref5","doi-asserted-by":"crossref","unstructured":"Barthe G. , D'Argenio P. R. and Rezk T. (2004) Secure information flow by self-composition. In: Proceedings IEEE Computer Security Foundations Workshop 100\u2013114.","DOI":"10.1109\/CSFW.2004.1310735"},{"key":"S0960129513000595_ref91","doi-asserted-by":"publisher","DOI":"10.1145\/502034.502036"},{"key":"S0960129513000595_ref8","unstructured":"Biba K. (1977) Integrity considerations for secure computer systems, Technical Report MTR-3153, MITRE Corporation."},{"key":"S0960129513000595_ref35","doi-asserted-by":"crossref","unstructured":"Goguen J. A. and Meseguer J. (1982) Security policies and security models. In: Proceedings IEEE Symposium on Security and Privacy 11\u201320.","DOI":"10.1109\/SP.1982.10014"},{"key":"S0960129513000595_ref46","doi-asserted-by":"crossref","unstructured":"Kifer D. and Gehrke J. (2006) Injecting utility into anonymized datasets. In: Proceedings ACM Conference on Management of Data 217\u2013228.","DOI":"10.1145\/1142473.1142499"},{"key":"S0960129513000595_ref39","doi-asserted-by":"crossref","unstructured":"Hamadou S. , Sassone V. and Palamidessi C. (2010) Reconciling belief and vulnerability in information flow. In: Proceedings IEEE Symposium on Security and Privacy 79\u201392.","DOI":"10.1109\/SP.2010.13"},{"key":"S0960129513000595_ref20","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2007-15302"},{"key":"S0960129513000595_ref55","doi-asserted-by":"crossref","unstructured":"Lowe G. (2002) Quantifying information flow. In: Proceedings IEEE Computer Security Foundations Workshop 18\u201331.","DOI":"10.1109\/CSFW.2002.1021804"},{"key":"S0960129513000595_ref37","doi-asserted-by":"crossref","unstructured":"Gray J. W. III , (1991) Toward a mathematical foundation for information flow security. In: Proceedings IEEE Symposium on Security and Privacy 21\u201335.","DOI":"10.1109\/RISP.1991.130769"},{"volume-title":"Reasoning about Uncertainty","year":"2003","author":"Halpern","key":"S0960129513000595_ref38"},{"key":"S0960129513000595_ref43","unstructured":"International Organization for Standardization (2005) Common criteria for information technology security evaluation: Part 1: Introduction and general model, ISO 15408. CCMB-2006-09-001, Version 3.1, Revision 1. Available from http:\/\/www.commoncriteriaportal.org."},{"key":"S0960129513000595_ref48","doi-asserted-by":"publisher","DOI":"10.1016\/0022-0000(81)90036-2"},{"key":"S0960129513000595_ref67","doi-asserted-by":"crossref","unstructured":"Newsome J. , McCamant S. and Song D. (2009) Measuring channel capacity to distinguish undue influence. In: Proceedings ACM Workshop on Programming Languages and Analysis for Security. Available from http:\/\/doi.acm.org\/10.1145\/1554339.1554349.","DOI":"10.1145\/1554339.1554349"}],"container-title":["Mathematical Structures in Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.cambridge.org\/core\/services\/aop-cambridge-core\/content\/view\/S0960129513000595","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,21]],"date-time":"2022-04-21T22:10:23Z","timestamp":1650579023000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.cambridge.org\/core\/product\/identifier\/S0960129513000595\/type\/journal_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,11,10]]},"references-count":92,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2015,2]]}},"alternative-id":["S0960129513000595"],"URL":"https:\/\/doi.org\/10.1017\/s0960129513000595","relation":{},"ISSN":["0960-1295","1469-8072"],"issn-type":[{"type":"print","value":"0960-1295"},{"type":"electronic","value":"1469-8072"}],"subject":[],"published":{"date-parts":[[2014,11,10]]}}}