清华大学学报(自然科学版)  2021, Vol. 61 Issue (11): 1254-1259    DOI: 10.16511/j.cnki.qhdxxb.2021.25.003
宋宇波1,2, 吴天琦1,2, 胡爱群2,3, 高尚4
1. 东南大学 网络空间安全学院, 江苏省计算机网络技术重点实验室, 南京 211189;
2. 网络通信与安全紫金山实验室, 南京 211189;
3. 东南大学 信息科学与工程学院, 移动通信国家重点实验室, 南京 211189;
4. 香港理工大学 电子计算学系, 香港 999077
Browser user tracking based on cross-domain resource access
SONG Yubo1,2, WU Tianqi1,2, HU Aiqun2,3, GAO Shang4
1. Jiangsu Key Laboratory of Computer Networking Technology, School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China;
2. Purple Mountain Laboratories, Nanjing 211189, China;
3. National Mobile Communications Research Laboratory, School of Information Science and Engineering, Southeast University, Nanjing 211189, China;
4. Computing Department, Hong Kong Polytheistic University, Hong Kong 999077, China
摘要 近年来,点击欺诈给广告商造成了巨大的经济损失,迫使广告商支付高额费用。为了应对点击欺诈,广告商通常使用用户配置文件来识别用户身份。但是,攻击者可以轻松构建独特的虚拟操作环境,干扰身份的识别。该文提出了PingLoc机制,一种基于跨域资源访问的定位方案,可检测点击欺诈来源。该方案从ping响应延迟序列提取特征构建用户指纹。测试表明,PingLoc所收集的延迟特征是稳定的,用户定位指纹的准确性高达98%。
关键词 点击欺诈多点ping用户身份识别攻击者定位    
Abstract:In recent years, click fraud has caused huge economic losses to advertisers. Many advertisers have then used "user profiles" to identify users to eliminate click fraud. However, attackers can easily construct unique virtual operating environments to confuse the identification algorithms. This paper introduces a localization scheme to detect click fraud sources based on cross-domain resource access. This scheme extracts features from a ping response delay series to fingerprint users. Tests show that the delay features collected by this method are stable with a fingerprint localization accuracy of up to 98%.
Key wordsclick fraud    multilocalization pings    user identification    attacker localization
收稿日期: 2020-11-15      出版日期: 2021-10-19
宋宇波, 吴天琦, 胡爱群, 高尚. 基于跨域资源访问的浏览器用户追踪[J]. 清华大学学报(自然科学版), 2021, 61(11): 1254-1259.
SONG Yubo, WU Tianqi, HU Aiqun, GAO Shang. Browser user tracking based on cross-domain resource access. Journal of Tsinghua University(Science and Technology), 2021, 61(11): 1254-1259.
