pith. sign in

arxiv: 1704.03138 · v1 · pith:GSLSG65Dnew · submitted 2017-04-11 · 💻 cs.CR

Semantic Identification of Web Browsing Sessions

classification 💻 cs.CR
keywords browsingidentificationsemanticsessionsadversaryfingerprintidentifymethods
0
0 comments X
read the original abstract

We introduce a semantic identification attack, in which an adversary uses semantic signals about the pages visited in one browsing session to identify other browsing sessions launched by the same user. Current user fingerprinting methods fail when a single machine is used by multiple users (e.g., in cybercafes or spaces with public computers) as these methods fingerprint devices, not individuals. We demonstrate how an adversary can employ a SIA to successfully fingerprint users on public or shared machines and identify them across browsing sessions. We additionally describe and evaluate possible countermeasures to prevent identification.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.