Déjà vu: Abusing Browser Cache Headers to Identify and Track Online Users

نویسندگان

چکیده

Abstract Many browser cache attacks have been proposed in the literature to sniff user’s browsing history. All of them rely on specific time measurements infer if a resource is or not. Unlike state-of-the-art, this paper reports novel cache-based attack that not timing but abuses HTTP cache-control and expires headers extract exact date when was cached by browser. The privacy implications are serious as information can only be utilized detect website visited user it also help build timeline visits. This goes beyond traditional history sniffing we observe patterns visit model behavior web. To evaluate impact our attack, tested all major browsers found them, except ones based WebKit, vulnerable it. Since requires present, crawled T ranco Top 100K websites identified 12, 970 detected with approach. Among 1, 910 deliver resources expiry dates greater than 100 days, enabling long-term tracking. Finally, discuss possible defenses at both standard levels prevent users from being tracked.

برای دانلود باید عضویت طلایی داشته باشید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

What is Déjà vu?

Déjà vu, pronounced day-zhaa voo, is French for “already seen.” It describes the fascinating and strange experience where you feel that something is very familiar but you also know that this feeling of familiarity should not be as strong as it is. For example, you might be walking to school when you suddenly feel like you have been in exactly this situation before. Of course, you have been in t...

متن کامل

Café Scientifique—Déjà Vu

Is the Café Scientifique a fashionable by-product of a comfortable age or an indicator of the changing relationship between science and society?

متن کامل

Recurrent commotio cordis: Déjà vu

Introduction Commotio cordis is defined as sudden cardiac death caused by a chest blow to the anterior chest. Events are predominantly reported in youth sports of baseball, lacrosse and hockey when the ball or puck strikes the chest. But commotio cordis can occur with other relatively innocent blows to the anterior chest wall, including fists, elbows and other objects. The mechanism of commotio...

متن کامل

Neuroimaging and cognitive changes during déjà vu.

OBJECTIVE The cause or the physiological role of déjà vu (DV) in healthy people is unknown. The pathophysiology of DV-type epileptic aura is also unresolved. Here we describe a 22-year-old woman treated with deep brain stimulation (DBS) of the left internal globus pallidus for hemidystonia. At certain stimulation settings, DBS elicited reproducible episodes of DV. METHODS Neuropsychological t...

متن کامل

Transcatheter aortic valve replacement failure: déjà vu ou jamais vu?

T he past half decade has seen transcatheter aortic valve replacement (TAVR) emerge as the standard of care for inoperable and high-risk patients with severe aortic stenosis: randomized data have demonstrated reduced mortality with TAVR compared with medical therapy or surgery in these respective situations. Accordingly, recent research efforts have reorientated from establishing the short-term...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: Proceedings on Privacy Enhancing Technologies

سال: 2021

ISSN: ['2299-0984']

DOI: https://doi.org/10.2478/popets-2021-0033