Unleash the Simulacrum: Shifting Browser Realities for Robust Extension-Fingerprinting Prevention

Unleash the Simulacrum: Shifting Browser Realities for Robust Extension-Fingerprinting Prevention
复制标题

DOI:
--
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Soroush Karami;Faezeh Kalantari;Mehrnoosh Zaeifi;Xavier J. Maso;Erik Trickel;Panagiotis Ilia;Yan Shoshitaishvili;Adam Doupé;Jason Polakis
Soroush Karami;Faezeh Kalantari;Mehrnoosh Zaeifi;Xavier J. Maso;Erik Trickel;Panagiotis Ilia;Yan Shoshitaishvili;Adam Doupé;Jason Polakis
中科院分区:
其他
文献类型:
--
作者:
Soroush Karami;Faezeh Kalantari;Mehrnoosh Zaeifi;Xavier J. Maso;Erik Trickel;Panagiotis Ilia;Yan Shoshitaishvili;Adam Doupé;Jason Polakis

文献摘要

被引文献

相似文献

在线跟踪由于给用户带来隐私风险而引起了极大的关注。在各种方法中,识别浏览器中安装了哪些扩展的技术可用于识别浏览器和跟踪用户,但也可用于推断个人和敏感的用户数据。虽然防止某些指纹识别技术相对简单,但减轻基于行为的扩展指纹识别带来了重大挑战,因为它依赖于隐藏源自扩展功能的操作。为此,我们引入了DOM RealityShifting的概念,将用户在浏览时体验到的现实与网页可以观察到的现实分离开来。为了演示我们的方法,我们开发了Simulacrum,这是一个原型扩展,通过核心Web API接口的目标工具实现了我们的防御。尽管在概念上很简单,但我们的实现突出了web应用程序、现代浏览器和JavaScript语言的复杂且通常特殊的性质和行为所带来的技术挑战。我们用最先进的基于dom的扩展指纹系统对我们的系统进行了实验评估,发现Simulacrum可以很容易地保护95.37%的敏感扩展。然后,我们确定扩展的琐碎修改,使我们能够对大多数剩余的扩展进行防御。为了方便更多的研究和保护用户免受侵犯隐私的行为,我们将开放我们的系统。
Online tracking has garnered significant attention due to the privacy risk it poses to users. Among the various approaches, techniques that identify which extensions are installed in a browser can be used for fingerprinting browsers and tracking users, but also for inferring personal and sensitive user data. While preventing certain fingerprinting techniques is relatively simple, mitigating behavior-based extension-fingerprinting poses a significant challenge as it relies on hiding actions that stem from an extension’s functionality. To that end, we introduce the conceptof DOM RealityShifting ,wherebywe splitthe reality users experience while browsing from the reality that webpages can observe. To demonstrate our approach we de-velop Simulacrum, a prototype extension that implements our defense through a targeted instrumentation of core Web API interfaces. Despite being conceptually straightforward, our implementation highlights the technical challenges posed by the complex and often idiosyncratic nature and behavior of web applications, modern browsers, and the JavaScript language. We experimentally evaluate our system against a state-of-the-art DOM-based extension fingerprinting system and find that Simulacrum readily protects 95.37% of susceptible extensions. We then identify trivial modifications to extensions that enable our defense for the majority of the remaining extensions. To facilitate additional research and protect users from privacy-invasive behaviors we will open-source our system.