2020
DOI: 10.1007/978-3-030-50399-4_16
|View full text |Cite
|
Sign up to set email alerts
|

“Guess Who?” Large-Scale Data-Centric Study of the Adequacy of Browser Fingerprints for Web Authentication

Abstract: Browser fingerprinting consists in collecting attributes from a web browser to build a browser fingerprint. In this work, we assess the adequacy of browser fingerprints as an authentication factor, on a dataset of 4, 145, 408 fingerprints composed of 216 attributes. It was collected throughout 6 months from a population of general browsers. We identify, formalize, and assess the properties for browser fingerprints to be usable and practical as an authentication factor. We notably evaluate their distinctiveness… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
20
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
3
2
1

Relationship

2
4

Authors

Journals

citations
Cited by 11 publications
(20 citation statements)
references
References 14 publications
0
20
0
Order By: Relevance
“…If the collected fingerprint matches with the one stored, the user is given access to the account, and the stored fingerprint is updated to the newly collected one. The comparison is done using a matching function (i.e., a similarity function between two fingerprints that authorizes differences), as fingerprints are known to evolve [4,13,59]. Any matching function can be used provided that it is monotonic (i.e., if two fingerprints match 7 for an attribute set C, they also match for any subset of C).…”
Section: Authentication Mechanismmentioning
confidence: 99%
See 3 more Smart Citations
“…If the collected fingerprint matches with the one stored, the user is given access to the account, and the stored fingerprint is updated to the newly collected one. The comparison is done using a matching function (i.e., a similarity function between two fingerprints that authorizes differences), as fingerprints are known to evolve [4,13,59]. Any matching function can be used provided that it is monotonic (i.e., if two fingerprints match 7 for an attribute set C, they also match for any subset of C).…”
Section: Authentication Mechanismmentioning
confidence: 99%
“…It was collected from December 7, 2016, to June 7, 2017, during a real-life experiment in which the authors integrated a fingerprinting probe to two pages of one of the 15 most visited websites in France. We refer to their studies [4,5] that provide an in-depth analysis of this dataset, a comprehensive description of the fingerprint collection, a precise description of the preprocessing steps that include a cookie resynchronization process similar to [13], and an exhaustive list of the attributes with their properties. In a nutshell, the preprocessed dataset contains 5, 714, 738 entries (comprising identical fingerprints for a given browser if interleaved 18 ) and 4, 145, 408 fingerprints (no identical fingerprint counted for the same browser), that are collected from 1, 989, 366 browsers.…”
Section: Fingerprint Datasetmentioning
confidence: 99%
See 2 more Smart Citations
“…(4) We enrich our results with (1) a precise analysis of the contribution of each attribute (a) to the distinctiveness, and show that 10% of the attributes provide a normalized entropy higher than 0.25, (b) to the stability, and show that 85% of the attributes stay identical for 99% of the consecutive fingerprints coming from the same browser, (c) to the collection time, and show that only 33 attributes take more than 5ms to collect, (d) to the fingerprint size, and show that only 20 attributes weigh more than 100 bytes, (2) a discussion about the correlation of the attributes, and show that only 49 attributes can completely be inferred when knowing another attribute, (3) a focus on the properties of the nine dynamic attributes. (5) We provide an in-depth description of our methodology and our dataset with the goal of making our results reproducible. In particular, we include an exhaustive list of the collected attributes together with their properties, and a detailed description of the preprocessing of the fingerprints.…”
Section: Introductionmentioning
confidence: 99%