Unbundle-Rewrite-Rebundle: Runtime Detection and Rewriting of Privacy-Harming Code in JavaScript Bundles
Mir Masood Ali, Peter Snyder, Chris Kanich, Hamed Haddadi
摘要
This work presents Unbundle-Rewrite-Rebundle (URR), a system for detecting privacy-harming portions of bundled JavaScript code and rewriting that code at runtime to remove the privacy-harming behavior without breaking the surrounding code or overall application. URR is a novel solution to the problem of JavaScript bundles, where websites pre-compile multiple code units into a single file, making it impossible for content filters and ad-blockers to differentiate between desired and unwanted resources. Where traditional content filtering tools rely on URLs, URR analyzes the code at the AST level, and replaces harmful AST sub-trees with privacy-andfunctionality maintaining alternatives. We present an open-sourced implementation of URR as a Firefox extension and evaluate it against JavaScript bundles generated by the most popular bundling system (Webpack) deployed on the Tranco 10k. We evaluate URR by precision (1.00), recall (0.95), and speed (0.43s per script) when detecting and rewriting three representative privacy-harming libraries often included in JavaScript bundles, and find URR to be an effective approach to a large-andgrowing blind spot unaddressed by current privacy tools. CCS CONCEPTS • Security and privacy → Web application security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Debun: Detecting Bundled JavaScript Libraries on Web using Property-Order GraphsSeojin Kim, Sungmin Park, Jihyeok ParkASE 2025
- Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the WebBen Swierzy, Marc Ohm, Michael MeierICSE 2026
它引用的顶会 Paper12
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- Fingerprinting the Fingerprinters: Learning to Detect Browser Fingerprinting BehaviorsUmar Iqbal, Steven Englehardt, Zubair ShafiqS&P 2021 · 被引用 143 次
- AdGraph: A Graph-Based Approach to Ad and Tracker BlockingUmar Iqbal, Peter Snyder, Shitong Zhu, Benjamin Livshits 等S&P 2020 · 被引用 112 次
- User Tracking in the Post-cookie Era: How Websites Bypass GDPR Consent to Track UsersEmmanouil Papadogiannakis, Panagiotis Papadopoulos, Nicolas Kourtellis, Evangelos P. MarkatosWWW 2021 · 被引用 99 次
- HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTsAurore Fass, Michael Backes, Ben StockCCS 2019 · 被引用 78 次
相关 Paper
- Detecting Filter List Evasion with Event-Loop-Turn Granularity JavaScript SignaturesQuan Chen, Peter Snyder, Ben Livshits, Alexandros KapravelosS&P 2021 · 被引用 33 次
- ASTrack: Automatic Detection and Removal of Web Tracking Code with Minimal Functionality LossIsmael Castell-Uroz, Kensuke Fukuda, Pere Barlet-RosINFOCOM 2023 · 被引用 8 次
- SugarCoat: Programmatically Generating Privacy-Preserving, Web-Compatible Resource Replacements for Content BlockingMichael Smith, Peter Snyder, Benjamin Livshits, Deian StefanCCS 2021 · 被引用 16 次
- Blocking Tracking JavaScript at the Function GranularityAbdul Haddi Amjad, Shaoor Munir, Zubair Shafiq, Muhammad Ali GulzarCCS 2024 · 被引用 3 次
- D-BUNDLR: Destructing JavaScript Bundles for Effective Static AnalysisWenyuan Xu, Alexi Turcotte, Cristian-Alexandru StaicuICSE 2026
