Detecting Filter List Evasion with Event-Loop-Turn Granularity JavaScript Signatures
Quan Chen, Peter Snyder, Ben Livshits, Alexandros Kapravelos
Abstract
Content blocking is an important part of a performant, user-serving, privacy respecting web. Current content blockers work by building trust labels over URLs. While useful, this approach has many well understood shortcomings. Attackers may avoid detection by changing URLs or domains, bundling unwanted code with benign code, or inlining code in pages. The common flaw in existing approaches is that they evaluate code based on its delivery mechanism, not its behavior. In this work we address this problem by building a system for generating signatures of the privacy-and-security relevant behavior of executed JavaScript. Our system uses as the unit of analysis each script's behavior during each turn on the JavaScript event loop. Focusing on event loop turns allows us to build highly identifying signatures for JavaScript code that are robust against code obfuscation, code bundling, URL modification, and other common evasions, as well as handle unique aspects of web applications. This work makes the following contributions to the problem of measuring and improving content blocking on the web: First, we design and implement a novel system to build per-event-loop-turn signatures of JavaScript behavior through deep instrumentation of the Blink and V8 runtimes. Second, we apply these signatures to measure how much privacy-and-security harming code is missed by current content blockers, by using EasyList and EasyPrivacy as ground truth and finding scripts that have the same privacy and security harming patterns. We build 1,995,444 signatures of privacy-and-security relevant behaviors from 11,212 unique scripts blocked by filter lists, and find 3,589 unique scripts hosting known harmful code, but missed by filter lists, affecting 12.48% of websites measured. Third, we provide a taxonomy of ways scripts avoid detection and quantify the occurrence of each. Finally, we present defenses against these evasions, in the form of filter list additions where possible, and through a proposed, signature based system in other cases. As part of this work, we share the implementation of our signature-generation system, the data gathered by applying that system to the Alexa 100K, and 586 AdBlock Plus compatible filter list rules to block instances of currently blocked code being moved to new URLs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers17
- SugarCoat: Programmatically Generating Privacy-Preserving, Web-Compatible Resource Replacements for Content BlockingMichael Smith, Peter Snyder, Benjamin Livshits, Deian StefanCCS 2021 · 16 citations
- Measuring the Privacy vs. Compatibility Trade-off in Preventing Third-Party Stateful TrackingJordan Jueckstock, Peter Snyder, Shaown Sarker, Alexandros Kapravelos et al.WWW 2022 · 15 citations
- The More Things Change, the More They Stay the Same: Integrity of Modern JavaScriptJohnny So, Michael Ferdman, Nick NikiforakisWWW 2023 · 7 citations
- AdCPG: Classifying JavaScript Code Property Graphs with Explanations for Ad and Tracker BlockingChangmin Lee, Sooel SonCCS 2023 · 7 citations
- Investigating Advertisers' Domain-changing Behaviors and Their Impacts on Ad-blocker Filter ListsSu-Chin Lin, Kai-Hsiang Chou, Yen Chen, Hsu-Chun Hsiao et al.WWW 2022 · 5 citations
Builds on6
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 798 citations
- AdGraph: A Graph-Based Approach to Ad and Tracker BlockingUmar Iqbal, Peter Snyder, Shitong Zhu, Benjamin Livshits et al.S&P 2020 · 112 citations
- Cloak of Visibility: Detecting When Machines Browse a Different WebLuca Invernizzi, Kurt Thomas, Alexandros Kapravelos, Oxana Comanescu et al.S&P 2016 · 93 citations
- HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTsAurore Fass, Michael Backes, Ben StockCCS 2019 · 78 citations
- Most Websites Don't Need to Vibrate: A Cost-Benefit Approach to Improving Browser SecurityPeter Snyder, Cynthia Bagier Taylor, Chris KanichCCS 2017 · 75 citations
Related papers
- Unbundle-Rewrite-Rebundle: Runtime Detection and Rewriting of Privacy-Harming Code in JavaScript BundlesMir Masood Ali, Peter Snyder, Chris Kanich, Hamed HaddadiCCS 2024 · 2 citations
- Blocking Tracking JavaScript at the Function GranularityAbdul Haddi Amjad, Shaoor Munir, Zubair Shafiq, Muhammad Ali GulzarCCS 2024 · 3 citations
- Byte by Byte: Unmasking Browser Fingerprinting at the Function Level using V8 Bytecode TransformersPouneh Nikkhah Bahrami, Dylan Cutler, Igor BilogrevicCCS 2025
- Measuring and Disrupting Anti-Adblockers Using Differential Execution AnalysisShitong Zhu, Xunchao Hu, Zhiyun Qian, Zubair Shafiq et al.NDSS 2018 · 44 citations
- ASTrack: Automatic Detection and Removal of Web Tracking Code with Minimal Functionality LossIsmael Castell-Uroz, Kensuke Fukuda, Pere Barlet-RosINFOCOM 2023 · 8 citations
