[論文レビュー] Web Tracking: Mechanisms, Implications, and Defenses
本論文は、Webトラッキングメカニズム(例:クッキー、ファングプリント、デバイス識別子)の包括的サーベイを提供する。そのプライバシーへの影響(価格差別や監視を含む)と、広告ブロッカーおよびトラッキング発見ツールなどの防御戦略も検討する。本稿では、より侵入的なトラッキング技術への移行が顕著であると指摘し、Google AdID や Microsoft Device Identifier といったプライバシー保護型識別子が、第三者クッキーの代替としての可能性を示唆している。
This articles surveys the existing literature on the methods currently used by web services to track the user online as well as their purposes, implications, and possible user's defenses. A significant majority of reviewed articles and web resources are from years 2012-2014. Privacy seems to be the Achilles' heel of today's web. Web services make continuous efforts to obtain as much information as they can about the things we search, the sites we visit, the people with who we contact, and the products we buy. Tracking is usually performed for commercial purposes. We present 5 main groups of methods used for user tracking, which are based on sessions, client storage, client cache, fingerprinting, or yet other approaches. A special focus is placed on mechanisms that use web caches, operational caches, and fingerprinting, as they are usually very rich in terms of using various creative methodologies. We also show how the users can be identified on the web and associated with their real names, e-mail addresses, phone numbers, or even street addresses. We show why tracking is being used and its possible implications for the users (price discrimination, assessing financial credibility, determining insurance coverage, government surveillance, and identity theft). For each of the tracking methods, we present possible defenses. Apart from describing the methods and tools used for keeping the personal data away from being tracked, we also present several tools that were used for research purposes - their main goal is to discover how and by which entity the users are being tracked on their desktop computers or smartphones, provide this information to the users, and visualize it in an accessible and easy to follow way. Finally, we present the currently proposed future approaches to track the user and show that they can potentially pose significant threats to the users' privacy.
研究の動機と目的
- オンラインサービスが使用する既存のWebトラッキングメカニズムを体系的かつ分類的に調査すること。
- トラッキングのプライバシー的影響を分析すること。具体的には、価格差別、身元泥用、政府による監視を含む。
- 既存および提案中のトラッキング対策を評価すること。技術的ツールおよびユーザーの意識喚起メカニズムを含む。
- ネットワークに挿入された識別子やクラウド同期型識別子を含む、新たなトラッキング技術を検討すること。
- トラッキング実態とそのユーザーへの影響を文書化することで、透明性を高め、政策立案を支援すること。
提案手法
- トラッキングメカニズムを5つの主要なグループに分類:セッションベース、クライアントストレージ、クライアントキャッシュ、ファングプリント、その他のアプローチ。
- ファングプリントおよびデバイス識別に用いられる、デバイス、ブラウザ、OS、ネットワークの特性に基づくトラッキング技術を分析。
- 特定のトラッキング手法に特化した防御メカニズムを評価。広告ブロッカーおよびプライバシー保護型識別子を含む。
- 第三者トラッキングを検出するためのツールや可視化手法(デスクトップおよびモバイルデバイスでの検出に使用)をレビュー。
- 将来のトラッキングシステムの提案を検討。具体的には、デバイス推定型、クライント生成型、ネットワーク挿入型、サーバー発行型、クラウド同期型識別子。
- 2012年から2014年の間の査読付き論文およびWebリソースからの知見を統合し、トラッキングエコシステム全体の包括的視点を提供。
実験結果
リサーチクエスチョン
- RQ1Web上でユーザーをトラッキングするために使用される主な技術的メカニズムは何か。また、それらは侵入性や持続性においてどのように異なるか。
- RQ2トラッキング技術は、デバイス、ブラウザ、ネットワークの属性を用いて、どのようにユーザーを識別可能にするか。
- RQ3Webトラッキングの現実世界への影響は何か。具体的には、経済的、社会的、政府関連の結果を含む。
- RQ4現在の防御メカニズムは、さまざまなトラッキング手法に対してどれほど効果的か。
- RQ5今後提案されているトラッキング技術は何か。また、それらが引き起こすプライバシー上のリスクは何か。
主な発見
- デバイスおよびブラウザの属性を用いるファングプリント技術は、クッキーが存在しない状況でも、高い正確性でユーザーを一意に特定可能である。
- 第三者クッキーは段階的に廃止されつつあるが、ファングプリントおよびデバイス識別子が、トラッキングの主流となる傾向にある。
- Google AdID および Microsoft Device Identifier は、ユーザーの制御と年間リセット機能を備えた、第三者クッキーのプライバシー保護型代替手段として提案されている。
- ISP や CDN が挿入するネットワーク挿入型識別子は、連携されれば、複数のデバイスおよびネットワークにまたがるユーザーのトラッキングが可能になる。
- トラッキング発見ツールは、ユーザーのデータを収集している実体を可視化し、ユーザーに通知することで、透明性を高める。
- より侵入的なトラッキング手法への移行は、ユーザーのプライバシーを脅かすおそれがあり、規制がなければ、広告ブロッカーの広範な採用につながる可能性がある。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。