UCognito: Private Browsing without Tears

UCognito: Private Browsing without Tears
复制标题

UCognito:无泪私密浏览

DOI:
10.1145/2810103.2813716
复制
发表时间:
2015
期刊:
Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Wenke Lee
Wenke Lee
中科院分区:
--
文献类型:
--
作者:
Meng Xu;Yeongjin Jang;Xinyu Xing;Taesoo Kim;Wenke Lee

文献摘要

被引文献

相似文献

虽然隐私浏览是一项标准功能,但其实现在各大浏览器之间并不一致。更严重的是,它往往不能提供足够的甚至是预期的隐私保护。例如,先前的研究表明,浏览器扩展和附加组件经常破坏隐私浏览的目标。本文首先对隐私浏览进行了系统的研究。我们开发了一种技术方法来识别私人浏览会话留下的浏览器痕迹,并表明Chrome和Firefox不能正确清除这些痕迹。我们分析了这些浏览器的源代码,发现当前的实现方法是根据当前的浏览模式(即私有或公共)来决定浏览器的行为;但是这样的决策点分散在整个代码库中。这种实现方法非常有问题,因为考虑到浏览器组件(包括扩展和附加组件)的复杂性,开发人员很容易犯错误。基于这一观察,我们提出了一种新的通用方法来实现隐私浏览。其主要思想是在浏览器处于私有浏览模式时,用沙盒文件系统覆盖实际的文件系统,这样就不会出现意外泄漏,也不会存储持久的修改。这种方法不需要更改浏览器和操作系统内核,因为分层沙箱文件系统是通过插入系统调用实现的。我们已经在Linux上实现了一个名为Ucognito的原型系统。我们的评估显示,将Ucognito应用于Chrome和Firefox时,可以阻止之前的工作和我们目前的研究发现的所有已知的隐私泄露。更重要的是,Ucognito产生的性能开销可以忽略不计:例如,在标准JavaScript和网页加载的基准测试中,其性能开销为0%-2.5%。
While private browsing is a standard feature, its implementation has been inconsistent among the major browsers. More seriously, it often fails to provide the adequate or even the intended privacy protection. For example, as shown in prior research, browser extensions and add-ons often undermine the goals of private browsing. In this paper, we first present our systematic study of private browsing. We developed a technical approach to identify browser traces left behind by a private browsing session, and showed that Chrome and Firefox do not correctly clear some of these traces. We analyzed the source code of these browsers and discovered that the current implementation approach is to decide the behaviors of a browser based on the current browsing mode (i.e., private or public); but such decision points are scattered throughout the code base. This implementation approach is very problematic because developers are prone to make mistakes given the complexities of browser components (including extensions and add-ons). Based on this observation, we propose a new and general approach to implement private browsing. The main idea is to overlay the actual filesystem with a sandbox filesystem when the browser is in private browsing mode, so that no unintended leakage is allowed and no persistent modification is stored. This approach requires no change to browsers and the OS kernel because the layered sandbox filesystem is implemented by interposing system calls. We have implemented a prototype system called Ucognito on Linux. Our evaluations show that Ucognito, when applied to Chrome and Firefox, stops all known privacy leaks identified by prior work and our current study. More importantly, Ucognito incurs only negligible performance overhead: e.g., 0%-2.5% in benchmarks for standard JavaScript and webpage loading.