Skip to main content

2015 | OriginalPaper | Buchkapitel

FPGuard: Detection and Prevention of Browser Fingerprinting

verfasst von : Amin FaizKhademi, Mohammad Zulkernine, Komminist Weldemariam

Erschienen in: Data and Applications Security and Privacy XXIX

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Fingerprinting is an identification method used by enterprises to personalize services for their end-users and detect online fraud or by adversaries to launch targeted attacks. Various tools have been proposed to protect online users from undesired identification probes to enhance the privacy and security of the users. However, we have observed that new fingerprinting methods can easily evade the existing protection mechanisms. This paper presents a runtime fingerprinting detection and prevention approach, called FPGuard. FPGuard relies on the analysis of predefined metrics to identify fingerprinting attempts. While FPGuard’s detection capability is evaluated using the top 10,000 Alexa websites, its prevention mechanism is evaluated against four fingerprinting providers. Our evaluation results show that FPGuard can effectively recognize and mitigate fingerprinting-related activities and distinguish normal from abnormal webpages (or fingerprinters).

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Boda, K., Földes, Á.M., Gulyás, G.G., Imre, S.: User tracking on the web via cross-browser fingerprinting. In: Laud, P. (ed.) NordSec 2011. LNCS, vol. 7161, pp. 31–46. Springer, Heidelberg (2012) Boda, K., Földes, Á.M., Gulyás, G.G., Imre, S.: User tracking on the web via cross-browser fingerprinting. In: Laud, P. (ed.) NordSec 2011. LNCS, vol. 7161, pp. 31–46. Springer, Heidelberg (2012)
2.
Zurück zum Zitat Eckersley, P.: How unique is your web browser? In: Atallah, M.J., Hopper, N.J. (eds.) PETS 2010. LNCS, vol. 6205, pp. 1–18. Springer, Heidelberg (2010) Eckersley, P.: How unique is your web browser? In: Atallah, M.J., Hopper, N.J. (eds.) PETS 2010. LNCS, vol. 6205, pp. 1–18. Springer, Heidelberg (2010)
3.
Zurück zum Zitat Wondracek, G., Holz, T., Kirda, E., Kruegel, C.: A practical attack to de-anonymize social network users. In: Proceedings of the 2010 IEEE Symposium on Security and Privacy, SP 2010, pp. 223–238. IEEE Computer Society, Washington, DC, USA (2010) Wondracek, G., Holz, T., Kirda, E., Kruegel, C.: A practical attack to de-anonymize social network users. In: Proceedings of the 2010 IEEE Symposium on Security and Privacy, SP 2010, pp. 223–238. IEEE Computer Society, Washington, DC, USA (2010)
6.
Zurück zum Zitat Acar, G., Juarez, M., Nikiforakis, N., Diaz, C., Gürses, S., Piessens, F., Preneel, B.: Fpdetective: dusting the web for fingerprinters. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer & #38; Communications Security, CCS 2013, pp. 1129–1140. ACM, New York, NY, USA (2013) Acar, G., Juarez, M., Nikiforakis, N., Diaz, C., Gürses, S., Piessens, F., Preneel, B.: Fpdetective: dusting the web for fingerprinters. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer & #38; Communications Security, CCS 2013, pp. 1129–1140. ACM, New York, NY, USA (2013)
7.
Zurück zum Zitat Acar, G., Eubank, C., Englehardt, S., Juarez, M., Narayanan, A., Diaz, C.: The web never forgets: persistent tracking mechanisms in the wild. In: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, CCS 2014, pp. 674–689. ACM, New York, NY, USA (2014) Acar, G., Eubank, C., Englehardt, S., Juarez, M., Narayanan, A., Diaz, C.: The web never forgets: persistent tracking mechanisms in the wild. In: Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, CCS 2014, pp. 674–689. ACM, New York, NY, USA (2014)
8.
Zurück zum Zitat Hoofnagle, C.J., Urban, J.M., Li, S.: Privacy and modern advertising: most us internet users want’do not track’to stop collection of data about their online activities. In: Amsterdam Privacy Conference (2012) Hoofnagle, C.J., Urban, J.M., Li, S.: Privacy and modern advertising: most us internet users want’do not track’to stop collection of data about their online activities. In: Amsterdam Privacy Conference (2012)
9.
Zurück zum Zitat McDonald, A.M., Cranor, L.F.: Beliefs and behaviors: internet users? understanding of behavioral advertising. In: Proceedings of the 2010 Research Conference on Communication, Information and Internet Policy. Carnegie Mellon University, Pittsburgh (2010) McDonald, A.M., Cranor, L.F.: Beliefs and behaviors: internet users? understanding of behavioral advertising. In: Proceedings of the 2010 Research Conference on Communication, Information and Internet Policy. Carnegie Mellon University, Pittsburgh (2010)
10.
Zurück zum Zitat Turow, J., King, J., Hoofnagle, C.J., Bleakley, A., Hennessy, M.: Americans reject tailored advertising and three activities that enable it (2009). (SSRN 1478214) Turow, J., King, J., Hoofnagle, C.J., Bleakley, A., Hennessy, M.: Americans reject tailored advertising and three activities that enable it (2009). (SSRN 1478214)
14.
Zurück zum Zitat Nikiforakis, N., Kapravelos, A., Joosen, W., Kruegel, C., Piessens, F., Vigna, G.: Cookieless monster: exploring the ecosystem of web-based device fingerprinting. In: Proceedings of the 2013 IEEE Symposium on Security and Privacy, SP 2013, pp. 541–555. IEEE Computer Society, Washington, DC, USA (2013) Nikiforakis, N., Kapravelos, A., Joosen, W., Kruegel, C., Piessens, F., Vigna, G.: Cookieless monster: exploring the ecosystem of web-based device fingerprinting. In: Proceedings of the 2013 IEEE Symposium on Security and Privacy, SP 2013, pp. 541–555. IEEE Computer Society, Washington, DC, USA (2013)
18.
Zurück zum Zitat Mayer, J.R.: Any person... a aamphleteer?: Internet anonymity in the age of web 2.0. Undergraduate Senior Thesis, Princeton University (2009) Mayer, J.R.: Any person... a aamphleteer?: Internet anonymity in the age of web 2.0. Undergraduate Senior Thesis, Princeton University (2009)
19.
Zurück zum Zitat Mowery, K., Bogenreif, D., Yilek, S., Shacham, H.: Fingerprinting information in javascript implementations. In: Proceedings of W2SP (2011) Mowery, K., Bogenreif, D., Yilek, S., Shacham, H.: Fingerprinting information in javascript implementations. In: Proceedings of W2SP (2011)
20.
Zurück zum Zitat Olejnik, L., Castelluccia, C., Janc, A., et al.: Why johnny can’t browse in peace: on the uniqueness of web browsing history patterns. In: 5th Workshop on Hot Topics in Privacy Enhancing Technologies (HotPETs 2012) (2012) Olejnik, L., Castelluccia, C., Janc, A., et al.: Why johnny can’t browse in peace: on the uniqueness of web browsing history patterns. In: 5th Workshop on Hot Topics in Privacy Enhancing Technologies (HotPETs 2012) (2012)
21.
Zurück zum Zitat Mulazzani, M., Reschl, P., Huber, M., Leithner, M., Schrittwieser, S., Weippl, E., Wien, F.H.C.: Fast and reliable browser identification with javascript engine fingerprinting. In: Web 2.0 Workshop on Security and Privacy (W2SP), vol. 5 (2013) Mulazzani, M., Reschl, P., Huber, M., Leithner, M., Schrittwieser, S., Weippl, E., Wien, F.H.C.: Fast and reliable browser identification with javascript engine fingerprinting. In: Web 2.0 Workshop on Security and Privacy (W2SP), vol. 5 (2013)
22.
Zurück zum Zitat Yen, T.-F., Xie, Y., Fang, Y., Yu, R.P., Abadi, M.: Privacy and security implications. In: NDSS, Host fingerprinting and tracking on the web (2012) Yen, T.-F., Xie, Y., Fang, Y., Yu, R.P., Abadi, M.: Privacy and security implications. In: NDSS, Host fingerprinting and tracking on the web (2012)
25.
Zurück zum Zitat Khademi, A.F., Zulkernine, M., Weldemariam, K.: Empirical evaluation of web-based fingerprinting (to appear in ieee software, 2015). IEEE Software’s SWSI: Security & Privacy on the Web (2015) Khademi, A.F., Zulkernine, M., Weldemariam, K.: Empirical evaluation of web-based fingerprinting (to appear in ieee software, 2015). IEEE Software’s SWSI: Security & Privacy on the Web (2015)
36.
Zurück zum Zitat Kamkar, S.: Evercookie-never forget. New York Times (2010) Kamkar, S.: Evercookie-never forget. New York Times (2010)
Metadaten
Titel
FPGuard: Detection and Prevention of Browser Fingerprinting
verfasst von
Amin FaizKhademi
Mohammad Zulkernine
Komminist Weldemariam
Copyright-Jahr
2015
DOI
https://doi.org/10.1007/978-3-319-20810-7_21

Premium Partner