CookieGraph: Understanding and Detecting First-Party Tracking Cookies

被引:3
|
作者
Munir, Shaoor [1 ]
Siby, Sandra [2 ]
Iqbal, Umar [3 ]
Englehardt, Steven
Sha, Zubair [1 ]
Troncoso, Carmela [4 ]
机构
[1] Univ Calif Davis, Davis, CA 95616 USA
[2] Imperial Coll London, London, England
[3] Washington Univ St Louis, St Louis, MO USA
[4] Ecole Polytech Fed Lausanne, Lausanne, Switzerland
来源
PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023 | 2023年
基金
美国国家科学基金会;
关键词
cookies; machine learning; privacy; tracking; web security;
D O I
10.1145/3576915.3616586
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As third-party cookie blocking is becoming the norm in mainstream web browsers, advertisers and trackers have started to use first-party cookies for tracking. To understand this phenomenon, we conduct a differential measurement study with versus without third-party cookies. We find that first-party cookies are used to store and exfiltrate identifiers to known trackers even when third-party cookies are blocked. As opposed to third-party cookie blocking, first-party cookie blocking is not practical because it would result in major breakage of website functionality. We propose CookieGraph, a machine learning-based approach that can accurately and robustly detect and block first-party tracking cookies. CookieGraph detects first-party tracking cookies with 90.18% accuracy, outperforming the stateof-the-art CookieBlock by 17.31%. We show that CookieGraph is robust against cookie name manipulation, while CookieBlock's accuracy drops by 15.87%. While blocking all first-party cookies results in major breakage on 32% of the sites with SSO logins, and CookieBlock reduces it to 10%, we show that CookieGraph does not cause any major breakage on these sites. Our deployment of CookieGraph shows that first-party tracking cookies are used on 89.86% of the top-million websites. We find that 96.61% of these first-party tracking cookies are in fact ghostwritten by third-party scripts embedded in the first-party context. We also dind evidence of first-party tracking cookies being set by fingerprinting scripts. The most prevalent first-party tracking cookies are set by major advertising entities such as Google, Facebook, and TikTok.
引用
收藏
页码:3490 / 3504
页数:15
相关论文
共 48 条
  • [31] First-party content decision under competitive hardware/software platforms: Free vs. charge
    Tang, Hua
    Chen, Jing
    Ai, Xingzheng
    Li, Xiaojing
    He, Haojia
    EUROPEAN JOURNAL OF OPERATIONAL RESEARCH, 2023, 311 (03) : 1068 - 1083
  • [32] An evaluation of intravenous medication preparation times before and after implementation of first-party digital image capture functionality
    Hsia, Bernard M.
    Shelton, A. Travis
    Mara, Kristin C.
    Lim, Dennison
    Mistri, Amish
    Ong, Kyle
    Draper, Evan W.
    AMERICAN JOURNAL OF HEALTH-SYSTEM PHARMACY, 2023, 80 (11) : 663 - 669
  • [33] Toward a new history of American accident law: Classical tort law and the cooperative first-party insurance movement
    Witt, JF
    HARVARD LAW REVIEW, 2001, 114 (03) : 690 - 841
  • [34] APPLICANTS' AND EMPLOYEES' REACTIONS TO CORPORATE SOCIAL RESPONSIBILITY: THE MODERATING EFFECTS OF FIRST-PARTY JUSTICE PERCEPTIONS AND MORAL IDENTITY
    Rupp, Deborah E.
    Shao, Ruodan
    Thornton, Meghan A.
    Skarlicki, Daniel P.
    PERSONNEL PSYCHOLOGY, 2013, 66 (04) : 895 - 933
  • [35] Alternative to third-party cookies: Investigating persistent PII leakage-based web tracking
    Dao, Ha
    Fukuda, Kensuke
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON EMERGING NETWORKING EXPERIMENTS AND TECHNOLOGIES, CONEXT 2021, 2021, : 223 - 229
  • [36] Substitutive First-party Content as a Strategic Decision for Platform Growth - Evidence from a B2B Platform
    Wei, Jianjiong
    Zhang, Dawei
    Liu, Jie
    Wei, Xueqi
    AMCIS 2020 PROCEEDINGS, 2020,
  • [37] How and when do employees identify with their organization? Perceived CSR, first-party (in)justice, and organizational (mis)trust at workplace
    Ghosh, Koustab
    PERSONNEL REVIEW, 2018, 47 (05) : 1157 - 1175
  • [38] First-party content and market concentration on a B2B E-commerce platform-Theory and empirical evidence
    Wei, Jianjiong
    Wei, Xueqi
    Zhang, Dawei
    Liu, Jie
    DECISION SUPPORT SYSTEMS, 2023, 170
  • [39] Cookie Swap Party: Abusing First-PartyCookies for Web Tracking
    Chen, Quan
    Ilia, Panagiotis
    Polychronakis, Michalis
    Kapravelos, Alexandros
    PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE 2021 (WWW 2021), 2021, : 2117 - 2129
  • [40] A system for detecting third-party tracking through the combination of dynamic analysis and static analysis
    Xidian University, School of Cyber Engineering, Xi'an, China
    不详
    不详
    IEEE INFOCOM - IEEE Conf. Comput. Commun. Workshops, INFOCOM WKSHPS, 1600,