论文标题

无处可隐藏:检测混淆的指纹脚本

Nowhere to Hide: Detecting Obfuscated Fingerprinting Scripts

论文作者

Ngan, Ray, Konkimalla, Surya, Shafiq, Zubair

论文摘要

随着网络远离状态跟踪,浏览器指纹越来越普遍。不幸的是,现有的检测浏览器指纹识别的方法没有考虑到诸如代码混淆之类的潜在逃避策略。为了解决这一差距,我们研究了针对各种现成的混淆工具的最先进的指纹检测方法的鲁棒性。总体而言,我们发现静态分析和动态分析的组合与不同类型的混淆相结合。尽管某些混淆器能够在静态分析中诱导错误的负面因素,但动态分析仍然能够检测到这些情况。由于混淆不会引起明显的误报,因此静态分析和动态分析的组合仍然能够准确检测到混淆的指纹脚本。

As the web moves away from stateful tracking, browser fingerprinting is becoming more prevalent. Unfortunately, existing approaches to detect browser fingerprinting do not take into account potential evasion tactics such as code obfuscation. To address this gap, we investigate the robustness of a state-of-the-art fingerprinting detection approach against various off-the-shelf obfuscation tools. Overall, we find that the combination of static and dynamic analysis is robust against different types of obfuscation. While some obfuscators are able to induce false negatives in static analysis, dynamic analysis is still able detect these cases. Since obfuscation does not induce significant false positives, the combination of static and dynamic analysis is still able to accurately detect obfuscated fingerprinting scripts.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源