Navigating Murky Waters: Automated Browser Feature Testing for Uncovering Tracking Vectors
Mir Masood Ali, Binoy Chitale, Mohammad Ghasemisharif, Chris Kanich, Nick Nikiforakis, Jason Polakis
摘要
—Modern web browsers constitute complex applica- tion platforms with a wide range of APIs and features. Critically, this includes a multitude of heterogeneous mechanisms that allow sites to store information that explicitly or implicitly alters client-side state or functionality. This behavior implicates any browser storage , cache , access control , and policy mechanism as a potential tracking vector. As demonstrated by prior work, tracking vectors can manifest through elaborate behaviors and exhibit varying characteristics that differ vastly across different browsing contexts. In this paper we develop CanITrack, an automated, mechanism-agnostic framework for testing browser features and uncovering novel tracking vectors. Our system is designed for facilitating browser vendors and researchers by streamlining the systematic testing of browser mechanisms. It accepts methods to read and write entries for a mechanism and calls these methods across different browsing contexts to determine any potential tracking vulnerabilities that the mechanism may expose. To demonstrate our system’s capabilities we test 21 browser mechanisms and uncover a slew of tracking vectors, including 13 that enable third-party tracking and two that bypass the isolation offered by private browsing modes. Importantly, we show how two separate mechanisms from Google’s highly-publicized and widely-discussed Privacy Sandbox initiative can be leveraged for tracking. Our experimental findings have resulted in 20 disclosure reports across seven major browsers, which have set remediation efforts in motion. Overall, our study highlights the complex and formidable challenge that browsers currently face when trying to balance the adoption of new features and protecting the privacy of their users, as well as the potential benefit of incorporating CanITrack into their internal testing pipeline.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Fledging Will Continue Until Privacy Improves: Empirical Analysis of Google's Privacy-Preserving Targeted AdvertisingGiuseppe Calderonio, Mir Masood Ali, Jason PolakisUSENIX Security 2024 · 被引用 8 次
- Rise of Inspectron: Automated Black-box Auditing of Cross-platform Electron AppsMir Masood Ali, Mohammad Ghasemisharif, Chris Kanich, Jason PolakisUSENIX Security 2024 · 被引用 2 次
- You Can Rand but You Can't Hide: A Holistic Security Analysis of Google Fuchsia's (and gVisor's) Network StackInon Kaplan, Ron Even, Amit KleinNDSS 2025
- HyTrack: Resurrectable and Persistent Tracking Across Android Apps and the WebMalte Wessels, Simon Koch, Jan Drescher, Louis Bettels 等USENIX Security 2025
- Exploiting the Shared Storage APIAlexandra Nisenoff, Deian Stefan, Nicolas ChristinCCS 2025
它引用的顶会 Paper12
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 被引用 798 次
- Internet Jones and the Raiders of the Lost Trackers: An Archaeological Study of Web Tracking from 1996 to 2016Ada Lerner, Anna Kornfeld Simpson, Tadayoshi Kohno, Franziska RoesnerUSENIX Security 2016 · 被引用 273 次
- XHOUND: Quantifying the Fingerprintability of Browser ExtensionsOleksii Starov, Nick NikiforakisS&P 2017 · 被引用 104 次
- Same-Origin Policy: Evaluation in Modern BrowsersJörg Schwenk, Marcus Niemietz, Christian MainkaUSENIX Security 2017 · 被引用 52 次
- Hindsight: Understanding the Evolution of UI Vulnerabilities in Mobile BrowsersMeng Luo, Oleksii Starov, Nima Honarmand, Nick NikiforakisCCS 2017 · 被引用 43 次
相关 Paper
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 被引用 39 次
- Browser Permission Mechanisms DemystifiedKazuki Nomoto, Takuya Watanabe, Eitaro Shioji, Mitsuaki Akiyama 等NDSS 2023
- Privacy Settings and Ad Perception: The Shift from Third-Party Cookies to the Privacy SandboxAbir Benzaamia, Oana GogaCHI 2026 · 被引用 1 次
- Tales of Favicons and Caches: Persistent Tracking in Modern BrowsersKonstantinos Solomos, John Kristoff, Chris Kanich, Jason PolakisNDSS 2021
- Web Platform Threats: Automated Detection of Web Security Issues With WPTPedro Bernardo, Lorenzo Veronese, Valentino Dalla Valle, Stefano Calzavara 等USENIX Security 2024 · 被引用 6 次
