Tracking users on the Internet with behavioral patterns: Evaluation of its practical feasibility

Link:
Autor/in:
Beteiligte Person:
  • Gritzalis , Dimitris
Verlag/Körperschaft:
Springer
Erscheinungsjahr:
2012
Medientyp:
Text
Schlagworte:
  • Authentication
  • Biometrics
  • Implicit authentication
  • Computer Crime
  • Network Security
  • Intrusion Detection
  • Authentication
  • Biometrics
  • Implicit authentication
  • Computer Crime
  • Network Security
  • Intrusion Detection
Beschreibung:
  • Traditionally, service providers, who want to track the activities of Internet users, rely on explicit tracking techniques like HTTP cookies. From a privacy perspective behavior-based tracking is even more dangerous, because it allows service providers to track users passively, i. e., without cookies. In this case multiple sessions of a user are linked by exploiting characteristic patterns mined from network traffic. In this paper we study the feasibility of behavior-based tracking in a real-world setting, which is unknown so far. In principle, behavior-based tracking can be carried out by any attacker that can observe the activities of users on the Internet. We design and implement a behavior-based tracking technique that consists of a Naive Bayes classifier supported by a cosine similarity decision engine. We evaluate our technique using a large-scale dataset that contains all queries received by a DNS resolver that is used by more than 2100 concurrent users on average per day. Our technique is able to correctly link 88.2 % of the surfing sessions on a day-to-day basis. We also discuss various countermeasures that reduce the effectiveness of our technique.
Lizenz:
  • info:eu-repo/semantics/restrictedAccess
Quellsystem:
Forschungsinformationssystem der UHH

Interne Metadaten
Quelldatensatz
oai:www.edit.fis.uni-hamburg.de:publications/b862da53-bc2b-4de9-87ce-f5198be72612