论文标题
追踪器反弹:测量野外划分存储的逃避
Trackers Bounce Back: Measuring Evasion of Partitioned Storage in the Wild
论文作者
论文摘要
这项工作提出了一项系统的导航跟踪研究,这是浏览器和在线跟踪器之间猫与鼠标游戏的最新发展。导航跟踪允许跟踪器通过修改其导航请求来“汇总用户的活动和行为。该技术尤其重要,因为它规避了浏览器对分区或阻止第三方存储的日益增长的努力,这对于大多数跨网站跟踪是必需的。虽然先前的工作已经研究了特定的导航跟踪技术(即“弹跳跟踪”),但我们的工作是系统地研究和测量整个导航跟踪技术类别的第一个工作。我们描述并测量网络上两种不同的导航跟踪技术的频率,并发现在我们进行的所有导航的百分之十以上存在导航跟踪。我们的贡献包括确定属于至少104个组织的214个域,通过使用直接或间接导航流进行链接装饰技术跟踪用户。我们确定了属于至少16个组织通过反弹跟踪跟踪用户的23个域(即通过无关的第三方弹跳用户以生成用户配置文件)。我们还改进了将用户标识符与非敏感信息不同的先前技术,这对于检测一类导航跟踪是必不可少的。我们讨论我们的发现如何用于保护用户免受导航跟踪的影响,并致力于发布我们的完整数据集和测量管道
This work presents a systematic study of navigational tracking, the latest development in the cat-and-mouse game between browsers and online trackers. Navigational tracking allows trackers to 'aggregate users' activities and behaviors across sites by modifying their navigation requests. This technique is particularly important because it circumvents the increasing efforts by browsers to partition or block third-party storage, which was previously necessary for most cross-website tracking. While previous work has studied specific navigational tracking techniques (i.e. "bounce tracking"), our work is the first effort to systematically study and measure the entire category of navigational tracking techniques. We describe and measure the frequency of two different navigational tracking techniques on the Web, and find that navigational tracking is present on slightly more than ten percent of all navigations that we made. Our contributions include identifying 214 domains belonging to at least 104 organizations tracking users across sites through link decoration techniques using direct or indirect navigation flows. We identify a further 23 domains belonging to at least 16 organizations tracking users through bounce tracking (i.e. bouncing users through unrelated third parties to generate user profiles). We also improve on prior techniques for differenting user identifiers from non-sensitive information, which is necessary to detect one class of navigational tracking. We discuss how our findings can used to protect users from navigational tracking, and commit to releasing both our complete dataset and our measurement pipeline