Skip to main content
QUICK REVIEW

[论文解读] Web Tracking: Mechanisms, Implications, and Defenses

Tomasz Bujlow, Valentín Carela-Español|arXiv (Cornell University)|Jul 28, 2015
Privacy, Security, and Data ProtectionSocial Sciences参考文献 47被引用 21
一句话总结

本文全面综述了网络跟踪机制(例如,Cookie、指纹识别、设备标识符)、其对隐私的影响(包括价格歧视和监控),以及防御策略,如广告拦截器和跟踪发现工具。研究指出,跟踪技术正向更具侵入性的方向发展,并强调了谷歌AdID和微软设备标识符等新兴隐私保护型标识符,作为第三方Cookie的潜在替代方案。

ABSTRACT

This articles surveys the existing literature on the methods currently used by web services to track the user online as well as their purposes, implications, and possible user's defenses. A significant majority of reviewed articles and web resources are from years 2012-2014. Privacy seems to be the Achilles' heel of today's web. Web services make continuous efforts to obtain as much information as they can about the things we search, the sites we visit, the people with who we contact, and the products we buy. Tracking is usually performed for commercial purposes. We present 5 main groups of methods used for user tracking, which are based on sessions, client storage, client cache, fingerprinting, or yet other approaches. A special focus is placed on mechanisms that use web caches, operational caches, and fingerprinting, as they are usually very rich in terms of using various creative methodologies. We also show how the users can be identified on the web and associated with their real names, e-mail addresses, phone numbers, or even street addresses. We show why tracking is being used and its possible implications for the users (price discrimination, assessing financial credibility, determining insurance coverage, government surveillance, and identity theft). For each of the tracking methods, we present possible defenses. Apart from describing the methods and tools used for keeping the personal data away from being tracked, we also present several tools that were used for research purposes - their main goal is to discover how and by which entity the users are being tracked on their desktop computers or smartphones, provide this information to the users, and visualize it in an accessible and easy to follow way. Finally, we present the currently proposed future approaches to track the user and show that they can potentially pose significant threats to the users' privacy.

研究动机与目标

  • 系统性地调查并分类在线服务所使用的现有网络跟踪机制。
  • 分析跟踪的隐私影响,包括价格歧视、身份盗窃和政府监控。
  • 评估现有及提出的防御措施,包括技术工具和用户意识机制。
  • 研究新兴的跟踪技术,如网络插入式和云同步标识符。
  • 通过记录跟踪实践及其对用户的影响,促进透明度并推动政策制定。

提出的方法

  • 将跟踪机制分为五大类:基于会话的、客户端存储的、客户端缓存的、指纹识别的以及其他方法。
  • 基于设备、浏览器、操作系统和网络特征,分析指纹识别和设备识别的跟踪技术。
  • 评估针对特定跟踪方法量身定制的防御机制,包括广告拦截器和隐私保护型标识符。
  • 审查用于跟踪发现和可视化的工具,例如用于检测桌面和移动设备上第三方跟踪的工具。
  • 研究提出的未来跟踪系统,包括设备推断型、客户端生成型、网络插入型、服务器颁发型以及云同步型标识符。
  • 综合同行评审文献和网络资源(2012–2014年)的研究成果,提供对跟踪生态系统整体性的视角。

实验结果

研究问题

  • RQ1网络上用于跟踪用户的主要技术机制是什么?它们在侵入性和持久性方面有何差异?
  • RQ2跟踪技术如何利用设备、浏览器和网络属性实现用户识别?
  • RQ3网络跟踪在现实世界中的影响是什么,包括经济、社会和政府层面的后果?
  • RQ4当前的防御机制在缓解各种跟踪方法方面的有效性如何?
  • RQ5正在提出的未来跟踪技术有哪些?它们带来了哪些隐私风险?

主要发现

  • 指纹识别技术通过利用设备和浏览器属性,即使在无Cookie的情况下,也能以高精度唯一标识用户。
  • 第三方Cookie正在逐步被淘汰,但指纹识别和设备标识符正成为主导的跟踪方法。
  • 谷歌AdID和微软设备标识符被提议作为第三方Cookie的隐私保护型替代方案,具备用户控制权和年度重置功能。
  • 若协调一致,网络插入型标识符(如来自ISP或CDN的标识符)可跨设备和网络跟踪用户。
  • 跟踪发现工具可可视化并告知用户哪些实体正在收集其数据,从而提升透明度。
  • 向更具侵入性的跟踪方法转变威胁用户隐私,若不加监管,可能导致广告拦截器的广泛采用。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。