CookieGraph: Understanding and Detecting First-Party Tracking Cookies

被引:3
|
作者
Munir, Shaoor [1 ]
Siby, Sandra [2 ]
Iqbal, Umar [3 ]
Englehardt, Steven
Sha, Zubair [1 ]
Troncoso, Carmela [4 ]
机构
[1] Univ Calif Davis, Davis, CA 95616 USA
[2] Imperial Coll London, London, England
[3] Washington Univ St Louis, St Louis, MO USA
[4] Ecole Polytech Fed Lausanne, Lausanne, Switzerland
来源
PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023 | 2023年
基金
美国国家科学基金会;
关键词
cookies; machine learning; privacy; tracking; web security;
D O I
10.1145/3576915.3616586
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As third-party cookie blocking is becoming the norm in mainstream web browsers, advertisers and trackers have started to use first-party cookies for tracking. To understand this phenomenon, we conduct a differential measurement study with versus without third-party cookies. We find that first-party cookies are used to store and exfiltrate identifiers to known trackers even when third-party cookies are blocked. As opposed to third-party cookie blocking, first-party cookie blocking is not practical because it would result in major breakage of website functionality. We propose CookieGraph, a machine learning-based approach that can accurately and robustly detect and block first-party tracking cookies. CookieGraph detects first-party tracking cookies with 90.18% accuracy, outperforming the stateof-the-art CookieBlock by 17.31%. We show that CookieGraph is robust against cookie name manipulation, while CookieBlock's accuracy drops by 15.87%. While blocking all first-party cookies results in major breakage on 32% of the sites with SSO logins, and CookieBlock reduces it to 10%, we show that CookieGraph does not cause any major breakage on these sites. Our deployment of CookieGraph shows that first-party tracking cookies are used on 89.86% of the top-million websites. We find that 96.61% of these first-party tracking cookies are in fact ghostwritten by third-party scripts embedded in the first-party context. We also dind evidence of first-party tracking cookies being set by fingerprinting scripts. The most prevalent first-party tracking cookies are set by major advertising entities such as Google, Facebook, and TikTok.
引用
收藏
页码:3490 / 3504
页数:15
相关论文
共 48 条
  • [41] A system for detecting third-party tracking through the combination of dynamic analysis and static analysis
    Sun, Jingxue
    Huang, Zhiqiu
    Yang, Ting
    Wang, Wengjie
    Zhang, Yuqing
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (IEEE INFOCOM WKSHPS 2021), 2021,
  • [42] Realignment and party revival: Understanding American electoral politics at the turn of the twenty-first century
    Thurber, T
    HISTORIAN, 2002, 64 (3-4): : 771 - 772
  • [43] Watching TV with the Second-Party: A First Look at Automatic Content Recognition Tracking in Smart TVs
    Anselmi, Gianluca
    Vekaria, Yash
    D'Souza, Alexander
    Callejo, Patricia
    Mandalari, Anna Maria
    Shafiq, Zubair
    PROCEEDINGS OF THE 2024 ACM INTERNET MEASUREMENT CONFERENCE, IMC 2024, 2024, : 622 - 634
  • [44] Realignment and party revival: Understanding American electoral politics at the turn of the twenty-first century.
    Dunham, P
    AMERICAN POLITICAL SCIENCE REVIEW, 2001, 95 (03) : 736 - 737
  • [45] Detecting and Tracking Circulating Tumour DNA Copy Number Profiles during First Line Chemotherapy in Oesophagogastric Adenocarcinoma
    Davidson, Michael
    Barber, Louise J.
    Woolston, Andrew
    Cafferkey, Catherine
    Mansukhani, Sonia
    Griffiths, Beatrice
    Moorcraft, Sing-Yu
    Rana, Isma
    Begum, Ruwaida
    Assiotis, Ioannis
    Matthews, Nik
    Rao, Sheela
    Watkins, David
    Chau, Ian
    Cunningham, David
    Starling, Naureen
    Gerlinger, Marco
    CANCERS, 2019, 11 (05)
  • [46] Tourist movement patterns understanding from the perspective of travel party size using mobile tracking data: A case study of Xi'an, China
    Zhao, Xi
    Lu, Xiaoni
    Liu, Yuanyuan
    Lin, Jun
    An, Jun
    TOURISM MANAGEMENT, 2018, 69 : 368 - 383
  • [47] Deconstructing the "First Moment of Truth": Understanding Unplanned Consideration and Purchase Conversion Using In-Store Video Tracking
    Hui, Sam K.
    Huang, Yanliu
    Suher, Jacob
    Inman, J. Jeffrey
    JOURNAL OF MARKETING RESEARCH, 2013, 50 (04) : 445 - 462
  • [48] Tracking and understanding the first-order structural transition in Er5Si4 -: art. no. 144102
    Mozharivskyj, Y
    Pecharsky, AO
    Pecharsky, VK
    Miller, GJ
    Gschneidner, KA
    PHYSICAL REVIEW B, 2004, 69 (14) : 144102 - 1