<bibliography>
 <citation type="proceedings" key="DBLP:conf/csfw/2010">
  <year>2010</year>
  <title>Proceedings of the 23rd IEEE Computer Security Foundations Symposium, CSF 2010, Edinburgh, United Kingdom, July 17-19, 2010</title>
  <publisher>IEEE Computer Society</publisher>
 </citation>
 <citation type="article" key="DBLP:journals/apal/Abramsky91">
  <author>Samson <surname>Abramsky</surname></author>
  <year>1991</year>
  <title>Domain Theory in Logical Form</title>
  <journal>Ann. Pure Appl. Logic</journal>
  <volume>51</volume>
  <number>1-2</number>
  <pages>1&#8211;77</pages>
  <url>http://dx.doi.org/10.1016/0168-0072(91)90065-T</url>
 </citation>
 <citation type="inproceedings" key="DBLP:conf/ccs/SamaratiV10">
  <author>Michael <surname>Backes</surname></author>
  <author>Matthias <surname>Berg</surname></author>
  <author>Boris <surname>K&#246;pf</surname></author>
  <year>2011</year>
  <title>Non-uniform distributions in quantitative information-flow</title>
  <booktitle>Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security</booktitle>
  <series>ASIACCS '11</series>
  <publisher>ACM</publisher>
  <address>New York, NY, USA</address>
  <pages>367&#8211;375</pages>
  <url>http://doi.acm.org/10.1145/1966913.1966960</url>
 </citation>
 <citation type="inproceedings" key="DBLP:conf/sp/BackesKR09">
  <author>Michael <surname>Backes</surname></author>
  <author>Boris <surname>K&#246;pf</surname></author>
  <author>Andrey <surname>Rybalchenko</surname></author>
  <year>2009</year>
  <title>Automatic Discovery and Quantification of Information Leaks</title>
  <booktitle>IEEE Symposium on Security and Privacy</booktitle>
  <publisher>IEEE Computer Society</publisher>
  <pages>141&#8211;153</pages>
  <url>http://dx.doi.org/10.1109/SP.2009.18</url>
 </citation>
 <citation type="inproceedings" key="barthe:csfw04">
  <author>Gilles <surname>Barthe</surname></author>
  <author>Pedro R. <surname>D'Argenio</surname></author>
  <author>Tamara <surname>Rezk</surname></author>
  <year>2004</year>
  <title>Secure Information Flow by Self-Composition</title>
  <booktitle>CSFW</booktitle>
  <publisher>IEEE Computer Society</publisher>
  <pages>100&#8211;114</pages>
  <url>http://doi.ieeecomputersociety.org/10.1109/CSFW.2004.17</url>
 </citation>
 <citation type="article" key="DBLP:journals/entcs/BraunCP09">
  <author>Christelle <surname>Braun</surname></author>
  <author>Konstantinos <surname>Chatzikokolakis</surname></author>
  <author>Catuscia <surname>Palamidessi</surname></author>
  <year>2009</year>
  <title>Quantitative Notions of Leakage for One-try Attacks</title>
  <journal>Electr. Notes Theor. Comput. Sci.</journal>
  <volume>249</volume>
  <pages>75&#8211;91</pages>
  <url>http://dx.doi.org/10.1016/j.entcs.2009.07.085</url>
 </citation>
 <citation type="inproceedings" key="DBLP:conf/csfw/CernyCH11">
  <author>Pavol <surname>&#x010c;ern&#253;</surname></author>
  <author>Krishnendu <surname>Chatterjee</surname></author>
  <author>Thomas A. <surname>Henzinger</surname></author>
  <year>2011</year>
  <title>The Complexity of Quantitative Information Flow Problems</title>
  <booktitle>CSF</booktitle>
  <publisher>IEEE Computer Society</publisher>
  <pages>205&#8211;217</pages>
  <url>http://doi.ieeecomputersociety.org/10.1109/CSF.2011.21</url>
 </citation>
 <citation type="article" key="clark05">
  <author>David <surname>Clark</surname></author>
  <author>Sebastian <surname>Hunt</surname></author>
  <author>Pasquale <surname>Malacaria</surname></author>
  <year>2005</year>
  <title>Quantified Interference for a While Language</title>
  <journal>Electr. Notes Theor. Comput. Sci.</journal>
  <volume>112</volume>
  <pages>149&#8211;166</pages>
  <url>http://dx.doi.org/10.1016/j.entcs.2004.01.018</url>
 </citation>
 <citation type="article" key="clarkjcs2007">
  <author>David <surname>Clark</surname></author>
  <author>Sebastian <surname>Hunt</surname></author>
  <author>Pasquale <surname>Malacaria</surname></author>
  <year>2007</year>
  <title>A static analysis for quantifying information flow in a simple imperative language</title>
  <journal>J. Comput. Secur.</journal>
  <volume>15</volume>
  <pages>321&#8211;371</pages>
  <url>http://dl.acm.org/citation.cfm?id=1370628.1370629</url>
 </citation>
 <citation type="inproceedings" key="clarkson:csf2005">
  <author>Michael R. <surname>Clarkson</surname></author>
  <author>Andrew C. <surname>Myers</surname></author>
  <author>Fred B. <surname>Schneider</surname></author>
  <year>2005</year>
  <title>Belief in Information Flow</title>
  <booktitle>CSFW</booktitle>
  <publisher>IEEE Computer Society</publisher>
  <pages>31&#8211;45</pages>
  <url>http://dx.doi.org/10.1109/CSFW.2005.10</url>
 </citation>
 <citation type="article" key="DBLP:journals/jcs/ClarksonS10">
  <author>Michael R. <surname>Clarkson</surname></author>
  <author>Fred B. <surname>Schneider</surname></author>
  <year>2010</year>
  <title>Hyperproperties</title>
  <journal>Journal of Computer Security</journal>
  <volume>18</volume>
  <number>6</number>
  <pages>1157&#8211;1210</pages>
  <url>http://dx.doi.org/10.3233/JCS-2009-0393</url>
 </citation>
 <citation type="inproceedings" key="DBLP:conf/sosp/Cohen77">
  <author>Ellis S. <surname>Cohen</surname></author>
  <year>1977</year>
  <title>Information Transmission in Computational Systems</title>
  <booktitle>SOSP</booktitle>
  <pages>133&#8211;139</pages>
  <url>http://doi.acm.org/10.1145/800214.806556</url>
 </citation>
 <citation type="inproceedings" key="darvas:spc05">
  <author>&#193;d&#225;m <surname>Darvas</surname></author>
  <author>Reiner <surname>H&#228;hnle</surname></author>
  <author>David <surname>Sands</surname></author>
  <year>2005</year>
  <title>A Theorem Proving Approach to Analysis of Secure Information Flow</title>
  <editor>Dieter <surname>Hutter</surname></editor>
  <editor>Markus <surname>Ullmann</surname></editor>
  <booktitle>SPC</booktitle>
  <series>Lecture Notes in Computer Science</series>
  <volume>3450</volume>
  <publisher>Springer</publisher>
  <pages>193&#8211;209</pages>
  <url>http://dx.doi.org/10.1007/978-3-540-32004-3_20</url>
 </citation>
 <citation type="book" key="denning82">
  <author>Dorothy Elizabeth Robling <surname>Denning</surname></author>
  <year>1982</year>
  <title>Cryptography and data security</title>
  <publisher>Addison-Wesley Longman Publishing Co., Inc.</publisher>
  <address>Boston, MA, USA</address>
 </citation>
 <citation type="inproceedings" key="DBLP:conf/popl/FlanaganS01">
  <author>Cormac <surname>Flanagan</surname></author>
  <author>James B. <surname>Saxe</surname></author>
  <year>2001</year>
  <title>Avoiding exponential explosion: generating compact verification conditions</title>
  <booktitle>POPL</booktitle>
  <pages>193&#8211;205</pages>
  <url>http://doi.acm.org/10.1145/360204.360220</url>
 </citation>
 <citation type="inproceedings" key="goguen:sp1982">
  <author>Joseph A. <surname>Goguen</surname></author>
  <author>Jos&#233; <surname>Meseguer</surname></author>
  <year>1982</year>
  <title>Security Policies and Security Models</title>
  <booktitle>IEEE Symposium on Security and Privacy</booktitle>
  <pages>11&#8211;20</pages>
 </citation>
 <citation type="inproceedings" key="DBLP:conf/ifip1-7/HeusserM09">
  <author>Jonathan <surname>Heusser</surname></author>
  <author>Pasquale <surname>Malacaria</surname></author>
  <year>2009</year>
  <title>Applied Quantitative Information Flow and Statistical Databases</title>
  <editor>Pierpaolo <surname>Degano</surname></editor>
  <editor>Joshua D. <surname>Guttman</surname></editor>
  <booktitle>Formal Aspects in Security and Trust</booktitle>
  <series>Lecture Notes in Computer Science</series>
  <volume>5983</volume>
  <publisher>Springer</publisher>
  <pages>96&#8211;110</pages>
  <url>http://dx.doi.org/10.1007/978-3-642-12459-4_8</url>
 </citation>
 <citation type="inproceedings" key="kopf07">
  <author>Boris <surname>K&#246;pf</surname></author>
  <author>David A. <surname>Basin</surname></author>
  <year>2007</year>
  <title>An information-theoretic model for adaptive side-channel attacks</title>
  <editor>Peng <surname>Ning</surname></editor>
  <editor>Sabrina De Capitani <surname>di Vimercati</surname></editor>
  <editor>Paul F. <surname>Syverson</surname></editor>
  <booktitle>ACM Conference on Computer and Communications Security</booktitle>
  <publisher>ACM</publisher>
  <pages>286&#8211;296</pages>
  <url>http://doi.acm.org/10.1145/1315245.1315282</url>
 </citation>
 <citation type="inproceedings" key="DBLP:conf/csfw/KopfR10">
  <author>Boris <surname>K&#246;pf</surname></author>
  <author>Andrey <surname>Rybalchenko</surname></author>
  <year>2010</year>
  <title>Approximation and Randomization for Quantitative Information-Flow Analysis</title>
  <booktitle>CSF</booktitle>
  <pages>3&#8211;14</pages>
  <url>http://doi.ieeecomputersociety.org/10.1109/CSF.2010.8</url>
 </citation>
 <citation type="inproceedings" key="DBLP:conf/csfw/KopfS10">
  <author>Boris <surname>K&#246;pf</surname></author>
  <author>Geoffrey <surname>Smith</surname></author>
  <year>2010</year>
  <title>Vulnerability Bounds and Leakage Resilience of Blinded Cryptography under Timing Attacks</title>
  <booktitle>CSF</booktitle>
  <pages>44&#8211;56</pages>
  <url>http://doi.ieeecomputersociety.org/10.1109/CSF.2010.11</url>
 </citation>
 <citation type="article" key="DBLP:journals/ipl/Leino05">
  <author>K. Rustan M. <surname>Leino</surname></author>
  <year>2005</year>
  <title>Efficient weakest preconditions</title>
  <journal>Inf. Process. Lett.</journal>
  <volume>93</volume>
  <number>6</number>
  <pages>281&#8211;288</pages>
  <url>http://dx.doi.org/10.1016/j.ipl.2004.10.015</url>
 </citation>
 <citation type="inproceedings" key="malacaria:popl2007">
  <author>Pasquale <surname>Malacaria</surname></author>
  <year>2007</year>
  <title>Assessing security threats of looping constructs</title>
  <editor>Martin <surname>Hofmann</surname></editor>
  <editor>Matthias <surname>Felleisen</surname></editor>
  <booktitle>POPL</booktitle>
  <publisher>ACM</publisher>
  <pages>225&#8211;235</pages>
  <url>http://doi.acm.org/10.1145/1190216.1190251</url>
 </citation>
 <citation type="inproceedings" key="malacaria08">
  <author>Pasquale <surname>Malacaria</surname></author>
  <author>Han <surname>Chen</surname></author>
  <year>2008</year>
  <title>Lagrange multipliers and maximum information leakage in different observational models</title>
  <editor>&#218;lfar <surname>Erlingsson</surname></editor>
  <editor>Marco <surname>Pistoia</surname></editor>
  <booktitle>PLAS</booktitle>
  <publisher>ACM</publisher>
  <pages>135&#8211;146</pages>
  <url>http://doi.acm.org/10.1145/1375696.1375713</url>
 </citation>
 <citation type="inproceedings" key="Massey94">
  <author>James L. <surname>Massey</surname></author>
  <year>1994</year>
  <title>Guessing and Entropy</title>
  <booktitle>ISIT '94: Proceedings of the 1994 IEEE International Symposium on Information Theory</booktitle>
  <pages>204</pages>
  <url>http://dx.doi.org/10.1109/ISIT.1994.394764</url>
 </citation>
 <citation type="inproceedings" key="mccamant:pldi2008">
  <author>Stephen <surname>McCamant</surname></author>
  <author>Michael D. <surname>Ernst</surname></author>
  <year>2008</year>
  <title>Quantitative information flow as network flow capacity</title>
  <editor>Rajiv <surname>Gupta</surname></editor>
  <editor>Saman P. <surname>Amarasinghe</surname></editor>
  <booktitle>PLDI</booktitle>
  <publisher>ACM</publisher>
  <pages>193&#8211;205</pages>
  <url>http://doi.acm.org/10.1145/1375581.1375606</url>
 </citation>
 <citation type="inproceedings" key="naumann:esorics06">
  <author>David A. <surname>Naumann</surname></author>
  <year>2006</year>
  <title>From Coupling Relations to Mated Invariants for Checking Information Flow</title>
  <editor>Dieter <surname>Gollmann</surname></editor>
  <editor>Jan <surname>Meier</surname></editor>
  <editor>Andrei <surname>Sabelfeld</surname></editor>
  <booktitle>ESORICS</booktitle>
  <series>Lecture Notes in Computer Science</series>
  <volume>4189</volume>
  <publisher>Springer</publisher>
  <pages>279&#8211;296</pages>
  <url>http://dx.doi.org/10.1007/11863908_18</url>
 </citation>
 <citation type="inproceedings" key="NMS2009">
  <author>James <surname>Newsome</surname></author>
  <author>Stephen <surname>McCamant</surname></author>
  <author>Dawn <surname>Song</surname></author>
  <year>2009</year>
  <title>Measuring channel capacity to distinguish undue influence</title>
  <editor>Stephen <surname>Chong</surname></editor>
  <editor>David A. <surname>Naumann</surname></editor>
  <booktitle>PLAS</booktitle>
  <publisher>ACM</publisher>
  <pages>73&#8211;85</pages>
  <url>http://doi.acm.org/10.1145/1554339.1554349</url>
 </citation>
 <citation type="article" key="shannon48">
  <author>Claude <surname>Shannon</surname></author>
  <year>1948</year>
  <title>A Mathematical Theory of Communication</title>
  <journal>Bell System Technical Journal</journal>
  <volume>27</volume>
  <pages>379&#8211;423, 623&#8211;656</pages>
  <url>http://doi.acm.org/10.1145/584091.584093</url>
 </citation>
 <citation type="inproceedings" key="smith09">
  <author>Geoffrey <surname>Smith</surname></author>
  <year>2009</year>
  <title>On the Foundations of Quantitative Information Flow</title>
  <editor>Luca <surname>de Alfaro</surname></editor>
  <booktitle>FOSSACS</booktitle>
  <series>Lecture Notes in Computer Science</series>
  <volume>5504</volume>
  <publisher>Springer</publisher>
  <pages>288&#8211;302</pages>
  <url>http://dx.doi.org/10.1007/978-3-642-00596-1_21</url>
 </citation>
 <citation type="inproceedings" key="terauchi:sas05">
  <author>Tachio <surname>Terauchi</surname></author>
  <author>Alexander <surname>Aiken</surname></author>
  <year>2005</year>
  <title>Secure Information Flow as a Safety Problem</title>
  <editor>Chris <surname>Hankin</surname></editor>
  <editor>Igor <surname>Siveroni</surname></editor>
  <booktitle>SAS</booktitle>
  <series>Lecture Notes in Computer Science</series>
  <volume>3672</volume>
  <publisher>Springer</publisher>
  <pages>352&#8211;367</pages>
  <url>http://dx.doi.org/10.1007/11547662_24</url>
 </citation>
 <citation type="inproceedings" key="unno:plas2006">
  <author>Hiroshi <surname>Unno</surname></author>
  <author>Naoki <surname>Kobayashi</surname></author>
  <author>Akinori <surname>Yonezawa</surname></author>
  <year>2006</year>
  <title>Combining type-based analysis and model checking for finding counterexamples against non-interference</title>
  <editor>Vugranam C. <surname>Sreedhar</surname></editor>
  <editor>Steve <surname>Zdancewic</surname></editor>
  <booktitle>PLAS</booktitle>
  <publisher>ACM</publisher>
  <pages>17&#8211;26</pages>
  <url>http://doi.acm.org/10.1145/1134744.1134750</url>
 </citation>
 <citation type="inproceedings" key="DBLP:conf/esorics/YasuokaT10">
  <author>Hirotoshi <surname>Yasuoka</surname></author>
  <author>Tachio <surname>Terauchi</surname></author>
  <year>2010</year>
  <title>On Bounding Problems of Quantitative Information Flow</title>
  <editor>Dimitris <surname>Gritzalis</surname></editor>
  <editor>Bart <surname>Preneel</surname></editor>
  <editor>Marianthi <surname>Theoharidou</surname></editor>
  <booktitle>ESORICS</booktitle>
  <series>Lecture Notes in Computer Science</series>
  <volume>6345</volume>
  <publisher>Springer</publisher>
  <pages>357&#8211;372</pages>
  <url>http://dx.doi.org/10.1007/978-3-642-15497-3_22</url>
 </citation>
 <citation type="inproceedings" key="DBLP:conf/csfw/YasuokaT10">
  <author>Hirotoshi <surname>Yasuoka</surname></author>
  <author>Tachio <surname>Terauchi</surname></author>
  <year>2010</year>
  <title>Quantitative Information Flow - Verification Hardness and Possibilities</title>
  <booktitle>CSF</booktitle>
  <pages>15&#8211;27</pages>
  <url>http://doi.ieeecomputersociety.org/10.1109/CSF.2010.9</url>
 </citation>
 <citation type="article" key="yasuoka:jocssubmit">
  <author>Hirotoshi <surname>Yasuoka</surname></author>
  <author>Tachio <surname>Terauchi</surname></author>
  <year>2011</year>
  <title>On Bounding Problems of Quantitative Information Flow (Extended version)</title>
  <journal>Journal of Computer Security</journal>
  <volume>19</volume>
  <number>6</number>
  <pages>1029&#8211;1082</pages>
  <url>http://dx.doi.org/10.3233/JCS-2011-0437</url>
 </citation>
 <citation type="misc" key="longversion">
  <author>Hirotoshi <surname>Yasuoka</surname></author>
  <author>Tachio <surname>Terauchi</surname></author>
  <year>2011</year>
  <title>Quantitative Information Flow as Safety and Liveness Hyperproperties</title>
  <url>http://www.kb.ecei.tohoku.ac.jp/~yasuoka</url>
 </citation>
</bibliography>
