{"id":{"repo_id":"uic","oai_identifier":"oai:figshare.com:article/30426292"},"canonical_url":"https://search.dev.ndltd.org/etd/uic/oai:figshare.com:article/30426292","repository":{"repo_id":"uic","name":"University of Illinois - Chicago","base_url":"https://api.figshare.com/v2/oai"},"display":{"title":"Exploring Tracking Techniques and Other Privacy-Invasive Attacks on the Modern Web","abstract":"Modern web browsers are essential gateways to the Internet, providing users access to a wide range of services and information. To support the complexity of modern web applications, browsers continuously adopt new features and advanced functionalities to enhance the user experience. However, despite these benefits, they often introduce inherent privacy and security risks. This work investigates how core browser features and mechanisms are exploited for privacy-invasive attacks and evaluates the effectiveness of deployed protection mechanisms in real-world settings. We first explore the properties and functionality of favicons to detect design-level flaws that enable persistent user tracking. Leveraging these properties, we demonstrate a novel fingerprinting technique that allows websites to re-identify users across visits without relying on traditional client-side methods. We then focus on the browser extension ecosystem and propose extension-detection techniques, each targeting a distinct behavioral property that can be leveraged for user tracking: (i) modifications triggered by user interactions, (ii) behaviors during the extension life cycle, and (iii) variation introduced through personalization. Our analysis utilizes publicly available datasets from prior studies and a collection of extensions from the Google Chrome Web Store spanning multiple time periods, detecting a significant number of fingerprintable extensions that were overlooked by prior approaches. Finally, we assess browser-specific security defenses by analyzing the Content Security Policy (CSP), a widely adopted standard for restricting injection attacks and enforcing origin-based access control. Using large-scale data collected from publicly accessible websites, we identify misconfigurations and overly permissive policies that allow attackers to compromise the privacy and integrity of both websites and users.","abstract_html":"Modern web browsers are essential gateways to the Internet, providing users access to a wide range of services and information. To support the complexity of modern web applications, browsers continuously adopt new features and advanced functionalities to enhance the user experience. However, despite these benefits, they often introduce inherent privacy and security risks. This work investigates how core browser features and mechanisms are exploited for privacy-invasive attacks and evaluates the effectiveness of deployed protection mechanisms in real-world settings. We first explore the properties and functionality of favicons to detect design-level flaws that enable persistent user tracking. Leveraging these properties, we demonstrate a novel fingerprinting technique that allows websites to re-identify users across visits without relying on traditional client-side methods. We then focus on the browser extension ecosystem and propose extension-detection techniques, each targeting a distinct behavioral property that can be leveraged for user tracking: (i) modifications triggered by user interactions, (ii) behaviors during the extension life cycle, and (iii) variation introduced through personalization. Our analysis utilizes publicly available datasets from prior studies and a collection of extensions from the Google Chrome Web Store spanning multiple time periods, detecting a significant number of fingerprintable extensions that were overlooked by prior approaches. Finally, we assess browser-specific security defenses by analyzing the Content Security Policy (CSP), a widely adopted standard for restricting injection attacks and enforcing origin-based access control. Using large-scale data collected from publicly accessible websites, we identify misconfigurations and overly permissive policies that allow attackers to compromise the privacy and integrity of both websites and users.","abstract_has_math":false,"creators":["Konstantinos Solomos (13004522)"],"institution":null,"degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025-08-01T00:00:00Z","date_published":"2025-08-01T00:00:00Z","updated_at":"2026-07-27T21:34:55Z","subjects":["Online Tracking","Privacy Invasive Attacks"],"languages":[],"rights":["In Copyright","Open Access after 2027-09-01"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://doi.org/10.25417/uic.30426292.v1","outbound_label":"DOI","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:creator","label":"Author","values":["Konstantinos Solomos (13004522)"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2025-08-01T00:00:00Z"]},{"key":"dc:relation","label":"Dc Relation","values":["https://figshare.com/articles/thesis/Exploring_Tracking_Techniques_and_Other_Privacy-Invasive_Attacks_on_the_Modern_Web/30426292"]},{"key":"dc:type","label":"Dc Type","values":["Text","Thesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Online Tracking","Privacy Invasive Attacks"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["In Copyright","Open Access after 2027-09-01"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["10.25417/uic.30426292.v1"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Modern web browsers are essential gateways to the Internet, providing users access to a wide range of services and information. To support the complexity of modern web applications, browsers continuously adopt new features and advanced functionalities to enhance the user experience. However, despite these benefits, they often introduce inherent privacy and security risks. This work investigates how core browser features and mechanisms are exploited for privacy-invasive attacks and evaluates the effectiveness of deployed protection mechanisms in real-world settings. We first explore the properties and functionality of favicons to detect design-level flaws that enable persistent user tracking. Leveraging these properties, we demonstrate a novel fingerprinting technique that allows websites to re-identify users across visits without relying on traditional client-side methods. We then focus on the browser extension ecosystem and propose extension-detection techniques, each targeting a distinct behavioral property that can be leveraged for user tracking: (i) modifications triggered by user interactions, (ii) behaviors during the extension life cycle, and (iii) variation introduced through personalization. Our analysis utilizes publicly available datasets from prior studies and a collection of extensions from the Google Chrome Web Store spanning multiple time periods, detecting a significant number of fingerprintable extensions that were overlooked by prior approaches. Finally, we assess browser-specific security defenses by analyzing the Content Security Policy (CSP), a widely adopted standard for restricting injection attacks and enforcing origin-based access control. Using large-scale data collected from publicly accessible websites, we identify misconfigurations and overly permissive policies that allow attackers to compromise the privacy and integrity of both websites and users."]},{"key":"dc:title","label":"Title","values":["Exploring Tracking Techniques and Other Privacy-Invasive Attacks on the Modern Web"]}]}],"canonical_facts":{"dc:creator":["Konstantinos Solomos (13004522)"],"dc:date":["2025-08-01T00:00:00Z"],"dc:description":["Modern web browsers are essential gateways to the Internet, providing users access to a wide range of services and information. To support the complexity of modern web applications, browsers continuously adopt new features and advanced functionalities to enhance the user experience. However, despite these benefits, they often introduce inherent privacy and security risks. This work investigates how core browser features and mechanisms are exploited for privacy-invasive attacks and evaluates the effectiveness of deployed protection mechanisms in real-world settings. We first explore the properties and functionality of favicons to detect design-level flaws that enable persistent user tracking. Leveraging these properties, we demonstrate a novel fingerprinting technique that allows websites to re-identify users across visits without relying on traditional client-side methods. We then focus on the browser extension ecosystem and propose extension-detection techniques, each targeting a distinct behavioral property that can be leveraged for user tracking: (i) modifications triggered by user interactions, (ii) behaviors during the extension life cycle, and (iii) variation introduced through personalization. Our analysis utilizes publicly available datasets from prior studies and a collection of extensions from the Google Chrome Web Store spanning multiple time periods, detecting a significant number of fingerprintable extensions that were overlooked by prior approaches. Finally, we assess browser-specific security defenses by analyzing the Content Security Policy (CSP), a widely adopted standard for restricting injection attacks and enforcing origin-based access control. Using large-scale data collected from publicly accessible websites, we identify misconfigurations and overly permissive policies that allow attackers to compromise the privacy and integrity of both websites and users."],"dc:identifier":["10.25417/uic.30426292.v1"],"dc:relation":["https://figshare.com/articles/thesis/Exploring_Tracking_Techniques_and_Other_Privacy-Invasive_Attacks_on_the_Modern_Web/30426292"],"dc:rights":["In Copyright","Open Access after 2027-09-01"],"dc:subject":["Online Tracking","Privacy Invasive Attacks"],"dc:title":["Exploring Tracking Techniques and Other Privacy-Invasive Attacks on the Modern Web"],"dc:type":["Text","Thesis"]},"updated_at":"2026-07-27T21:34:55Z"}