Detecting Filter List Evasion with Event-Loop-Turn Granularity JavaScript Signatures
Quan Chen, Peter Snyder, Ben Livshits, Alexandros Kapravelos
摘要
Content blocking is an important part of a performant, user-serving, privacy respecting web. Current content blockers work by building trust labels over URLs. While useful, this approach has many well understood shortcomings. Attackers may avoid detection by changing URLs or domains, bundling unwanted code with benign code, or inlining code in pages. The common flaw in existing approaches is that they evaluate code based on its delivery mechanism, not its behavior. In this work we address this problem by building a system for generating signatures of the privacy-and-security relevant behavior of executed JavaScript. Our system uses as the unit of analysis each script's behavior during each turn on the JavaScript event loop. Focusing on event loop turns allows us to build highly identifying signatures for JavaScript code that are robust against code obfuscation, code bundling, URL modification, and other common evasions, as well as handle unique aspects of web applications. This work makes the following contributions to the problem of measuring and improving content blocking on the web: First, we design and implement a novel system to build per-event-loop-turn signatures of JavaScript behavior through deep instrumentation of the Blink and V8 runtimes. Second, we apply these signatures to measure how much privacy-and-security harming code is missed by current content blockers, by using EasyList and EasyPrivacy as ground truth and finding scripts that have the same privacy and security harming patterns. We build 1,995,444 signatures of privacy-and-security relevant behaviors from 11,212 unique scripts blocked by filter lists, and find 3,589 unique scripts hosting known harmful code, but missed by filter lists, affecting 12.48% of websites measured. Third, we provide a taxonomy of ways scripts avoid detection and quantify the occurrence of each. Finally, we present defenses against these evasions, in the form of filter list additions where possible, and through a proposed, signature based system in other cases. As part of this work, we share the implementation of our signature-generation system, the data gathered by applying that system to the Alexa 100K, and 586 AdBlock Plus compatible filter list rules to block instances of currently blocked code being moved to new URLs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- SugarCoat: Programmatically Generating Privacy-Preserving, Web-Compatible Resource Replacements for Content BlockingMichael Smith, Peter Snyder, Benjamin Livshits, Deian StefanCCS 2021 · 被引用 16 次
- Measuring the Privacy vs. Compatibility Trade-off in Preventing Third-Party Stateful TrackingJordan Jueckstock, Peter Snyder, Shaown Sarker, Alexandros Kapravelos 等WWW 2022 · 被引用 15 次
- The More Things Change, the More They Stay the Same: Integrity of Modern JavaScriptJohnny So, Michael Ferdman, Nick NikiforakisWWW 2023 · 被引用 7 次
- AdCPG: Classifying JavaScript Code Property Graphs with Explanations for Ad and Tracker BlockingChangmin Lee, Sooel SonCCS 2023 · 被引用 7 次
- Investigating Advertisers' Domain-changing Behaviors and Their Impacts on Ad-blocker Filter ListsSu-Chin Lin, Kai-Hsiang Chou, Yen Chen, Hsu-Chun Hsiao 等WWW 2022 · 被引用 5 次
它引用的顶会 Paper6
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 被引用 798 次
- AdGraph: A Graph-Based Approach to Ad and Tracker BlockingUmar Iqbal, Peter Snyder, Shitong Zhu, Benjamin Livshits 等S&P 2020 · 被引用 112 次
- Cloak of Visibility: Detecting When Machines Browse a Different WebLuca Invernizzi, Kurt Thomas, Alexandros Kapravelos, Oxana Comanescu 等S&P 2016 · 被引用 93 次
- HideNoSeek: Camouflaging Malicious JavaScript in Benign ASTsAurore Fass, Michael Backes, Ben StockCCS 2019 · 被引用 78 次
- Most Websites Don't Need to Vibrate: A Cost-Benefit Approach to Improving Browser SecurityPeter Snyder, Cynthia Bagier Taylor, Chris KanichCCS 2017 · 被引用 75 次
相关 Paper
- Unbundle-Rewrite-Rebundle: Runtime Detection and Rewriting of Privacy-Harming Code in JavaScript BundlesMir Masood Ali, Peter Snyder, Chris Kanich, Hamed HaddadiCCS 2024 · 被引用 2 次
- Blocking Tracking JavaScript at the Function GranularityAbdul Haddi Amjad, Shaoor Munir, Zubair Shafiq, Muhammad Ali GulzarCCS 2024 · 被引用 3 次
- Byte by Byte: Unmasking Browser Fingerprinting at the Function Level using V8 Bytecode TransformersPouneh Nikkhah Bahrami, Dylan Cutler, Igor BilogrevicCCS 2025
- Measuring and Disrupting Anti-Adblockers Using Differential Execution AnalysisShitong Zhu, Xunchao Hu, Zhiyun Qian, Zubair Shafiq 等NDSS 2018 · 被引用 44 次
- ASTrack: Automatic Detection and Removal of Web Tracking Code with Minimal Functionality LossIsmael Castell-Uroz, Kensuke Fukuda, Pere Barlet-RosINFOCOM 2023 · 被引用 8 次
