Skip to main content
QUICK REVIEW

[논문 리뷰] Web Tracking: Mechanisms, Implications, and Defenses

Tomasz Bujlow, Valentín Carela-Español|arXiv (Cornell University)|2015. 07. 28.
Privacy, Security, and Data ProtectionSocial Sciences참고 문헌 47인용 수 21
한 줄 요약

이 논문은 웹 추적 기법(예: 쿠키, 지문 분석, 장치 식별자)과 그 개인정보 침해 영향(가격 차별 및 감시 포함), 광고 차단기 및 추적 탐지 도구와 같은 방어 전략에 대한 종합적인 조사를 제공한다. 이는 더 침습적인 추적 기법으로의 전환을 규명하고, Google AdID 및 Microsoft Device Identifier와 같은 새로운 개인정보 보호 기반 식별자들이 제3자 쿠키의 대안으로 부상하고 있음을 강조한다.

ABSTRACT

This articles surveys the existing literature on the methods currently used by web services to track the user online as well as their purposes, implications, and possible user's defenses. A significant majority of reviewed articles and web resources are from years 2012-2014. Privacy seems to be the Achilles' heel of today's web. Web services make continuous efforts to obtain as much information as they can about the things we search, the sites we visit, the people with who we contact, and the products we buy. Tracking is usually performed for commercial purposes. We present 5 main groups of methods used for user tracking, which are based on sessions, client storage, client cache, fingerprinting, or yet other approaches. A special focus is placed on mechanisms that use web caches, operational caches, and fingerprinting, as they are usually very rich in terms of using various creative methodologies. We also show how the users can be identified on the web and associated with their real names, e-mail addresses, phone numbers, or even street addresses. We show why tracking is being used and its possible implications for the users (price discrimination, assessing financial credibility, determining insurance coverage, government surveillance, and identity theft). For each of the tracking methods, we present possible defenses. Apart from describing the methods and tools used for keeping the personal data away from being tracked, we also present several tools that were used for research purposes - their main goal is to discover how and by which entity the users are being tracked on their desktop computers or smartphones, provide this information to the users, and visualize it in an accessible and easy to follow way. Finally, we present the currently proposed future approaches to track the user and show that they can potentially pose significant threats to the users' privacy.

연구 동기 및 목표

  • 온라인 서비스에서 사용되는 기존 웹 추적 기법을 체계적으로 조사하고 분류하는 것.
  • 추적의 개인정보 침해 영향을 분석하는 것, 가격 차별, 신원 도용, 정부 감시를 포함하여.
  • 기존 및 제안된 추적 방어 전략을 평가하는 것, 기술적 도구와 사용자 인지 메커니즘을 포함하여.
  • 네트워크에 삽입된 및 클라우드 동기화된 식별자와 같은 새로운 추적 기술을 검토하는 것.
  • 추적 관행과 사용자에 대한 영향을 문서화하여 투명성을 제고하고 정책 개발을 지원하는 것.

제안 방법

  • 세션 기반, 클라이언트 스토리지, 클라이언트 캐시, 지문 분석, 기타 접근 방식의 다섯 가지 주요 그룹으로 추적 기법을 분류.
  • 지문 분석 및 장치 식별을 위해 장치, 브라우저, 운영체제, 네트워크 특성 기반의 추적 기법을 분석.
  • 특정 추적 방법에 맞춰진 방어 메커니즘 평가, 광고 차단기 및 개인정보 보호 기반 식별자를 포함.
  • 제3자 추적 탐지 및 시각화를 위한 도구를 검토, 桌정 및 모바일 기기에서의 추적 감지를 위해 사용된 도구들 포함.
  • 제안된 미래 추적 시스템을 검토, 장치 유추, 클라이언트 생성, 네트워크에 삽입된, 서버가 발급한, 클라우드 동기화된 식별자를 포함.
  • 2012~2014년 동안의 동료 심사 논문 및 웹 자료로부터의 통합적 분석을 통해 추적 생태계에 대한 종합적 시각을 제공.

실험 결과

연구 질문

  • RQ1웹에서 사용자를 추적하는 데 사용되는 주요 기술적 기법은 무엇이며, 침범성과 지속성 측면에서 어떻게 다릅니까?
  • RQ2장치, 브라우저 및 네트워크 속성을 사용하여 추적 기법이 사용자를 식별하는 방식은 무엇입니까?
  • RQ3웹 추적의 실제 영향은 재정적, 사회적, 정부적 결과를 포함하여 무엇이 있습니까?
  • RQ4현재의 방어 메커니즘은 다양한 추적 방법을 완화하는 데 얼마나 효과합니까?
  • RQ5제안된 미래의 추적 기술은 무엇이며, 어떤 개인정보 침해 위험이 있습니까?

주요 결과

  • 장치 및 브라우저 속성을 사용하는 지문 분석 기법은 쿠키 없이도 높은 정확도로 사용자를 고유하게 식별할 수 있다.
  • 제3자 쿠키는 점차 사용이 중단되고 있지만, 지문 분석 및 장치 식별자가 주요 추적 방법으로 부상하고 있다.
  • Google AdID 및 Microsoft Device Identifier는 사용자 제어 및 연간 리셋 기능을 갖춘 제3자 쿠키의 개인정보 보호 기반 대안으로 제안된다.
  • ISP나 CDN에서 삽입하는 네트워크 기반 식별자는 협업이 이루어질 경우 기기 및 네트워크를 초월해 사용자를 추적할 수 있다.
  • 추적 탐지 도구는 사용자가 데이터를 수집하는 엔티티를 시각화하고 정보를 제공함으로써 투명성을 높일 수 있다.
  • 더 침범적인 추적 기법으로의 전환은 사용자 개인정보 보호를 위협하며, 규제되지 않을 경우 광고 차단기의 광범위한 보급으로 이어질 수 있다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.