MyWebGuard: Toward a User-Oriented Tool for Security and Privacy Protection on the Web

被引:16
|
作者
Hiremath, Panchakshari N. [1 ]
Armentrout, Jack [1 ]
Son Vu [2 ]
Tu N Nguyen [3 ]
Quang Tran Minh [4 ]
Phu H Phung [1 ]
机构
[1] Univ Dayton, Dept Comp Sci, Intelligent Syst Secur Lab, Dayton, OH 45469 USA
[2] Truman State Univ, Kirksville, MO USA
[3] Purdue Univ, Ft Wayne, IN USA
[4] Ho Chi Minh City Univ Technol, VNU HCM, Ho Chi Minh City, Vietnam
关键词
Privacy; Web security; Online tracking;
D O I
10.1007/978-3-030-35653-8_33
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We introduce a novel approach to implementing a browser-based tool for web users to protect their privacy. We propose to monitor the behaviors of JavaScript code within a webpage, especially operations that can read data within a browser or can send data from a browser to outside. Our monitoring mechanism is to ensure that all potential information leakage channels are detected. The detected leakage is either automatically prevented by our context-aware policies or decided by the user if needed. Our method advances the conventional same-origin policy standard of the Web by enforcing different policies for each source of the code. Although we develop the tool as a browser extension, our approach is browser-agnostic as it is based on standard JavaScript. Also, our method stands from existing proposals in the industry and literature. In particular, it does not rely on network request interception and blocking mechanisms provided by browsers, which face various technical issues. We implement a proof-of-concept prototype and perform practical evaluations to demonstrate the effectiveness of our approach. Our experimental results evidence that the proposed method can detect and prevent data leakage channels not captured by the leading tools such as Ghostery and uBlock Origin. We show that our prototype is compatible with major browsers and popular real-world websites with promising runtime performance.
引用
收藏
页码:506 / 525
页数:20
相关论文
共 50 条
  • [1] A User-Oriented Approach and Tool for Security and Privacy Protection on the Web
    Phung P.H.
    Pham H.-D.
    Armentrout J.
    Hiremath P.N.
    Tran-Minh Q.
    [J]. SN Computer Science, 2020, 1 (4)
  • [2] Privacy Risk Assessment for Web Tracking A user-oriented approach toward privacy risk assessment for Web tracking
    Hamed, Asma
    Ben Ayed, Hella Kaffel
    [J]. 2016 IEEE CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING (CCECE), 2016,
  • [3] A user-oriented web retrieval summarization tool
    Vazhenin, Denis
    Ishikawa, Satoru
    Klyuev, Vitaly
    [J]. 2009 SECOND INTERNATIONAL CONFERENCE ON ADVANCES IN HUMAN-ORIENTED AND PERSONALIZED MECHANISM, TECHNOLOGIES, AND SERVICES, 2009, : 73 - 78
  • [4] A User-Oriented Trust Model for Web Services
    Li, Bixin
    Song, Rui
    Liao, Li
    Liu, Cuicui
    [J]. 2013 IEEE SEVENTH INTERNATIONAL SYMPOSIUM ON SERVICE-ORIENTED SYSTEM ENGINEERING (SOSE 2013), 2013, : 224 - 232
  • [5] A User-Oriented Web Service Reliability Model
    Li, Bixin
    Su, Zhiyong
    Zhou, Ying
    Gong, Xufang
    [J]. 2008 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN AND CYBERNETICS (SMC), VOLS 1-6, 2008, : 3611 - 3616
  • [6] User-oriented reliability modeling for a web system
    Wang, WL
    Tang, MH
    [J]. ISSRE 2003: 14TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING, PROCEEDINGS, 2003, : 293 - 304
  • [7] TOWARD ESTABLISHING USER-ORIENTED MATERIALITY STANDARDS
    OCONNOR, MC
    COLLINS, DW
    [J]. JOURNAL OF ACCOUNTANCY, 1974, 138 (06): : 67 - 75
  • [8] User-Oriented Preference Toward a Recommender System
    Lin, Pei-Chun
    Arbaiy, Nureize
    [J]. BAGHDAD SCIENCE JOURNAL, 2021, 18 (01) : 746 - 752
  • [9] A User-Oriented Approach to Assessing Web Service Trustworthiness
    Zhao, Weinan
    Sun, Hailong
    Huang, Zicheng
    Liu, Xudong
    Kang, Xitong
    [J]. AUTONOMIC AND TRUSTED COMPUTING, 2010, 6407 : 195 - 207
  • [10] An efficient user-oriented clustering of web search results
    Cai, K
    Bu, JJ
    Chen, C
    [J]. COMPUTATIONAL SCIENCE - ICCS 2005, PT 3, 2005, 3516 : 806 - 809