CRApr 11, 2017

Semantic Identification of Web Browsing Sessions

arXiv:1704.03138v11 citations
Originality Incremental advance
AI Analysis

This addresses privacy risks for users on public or shared computers, offering a novel attack method with incremental improvements over existing device-based fingerprinting.

The paper tackles the problem of user identification on shared devices by introducing a semantic identification attack that uses page visit signals to link browsing sessions, achieving successful fingerprinting across sessions.

We introduce a semantic identification attack, in which an adversary uses semantic signals about the pages visited in one browsing session to identify other browsing sessions launched by the same user. Current user fingerprinting methods fail when a single machine is used by multiple users (e.g., in cybercafes or spaces with public computers) as these methods fingerprint devices, not individuals. We demonstrate how an adversary can employ a SIA to successfully fingerprint users on public or shared machines and identify them across browsing sessions. We additionally describe and evaluate possible countermeasures to prevent identification.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes