TY - JOUR
T1 - PEBA
T2 - Enhancing User Privacy and Coverage of Safe Browsing Services
AU - Du, Yuefeng
AU - Duan, Huayi
AU - Xu, Lei
AU - Cui, Helei
AU - Wang, Cong
AU - Wang, Qian
N1 - Publisher Copyright:
© 2004-2012 IEEE.
PY - 2023/9/1
Y1 - 2023/9/1
N2 - To keep web users away from unsafe websites, modern web browsers enable the embedded feature of safe browsing (SB) by default. In this work, through theoretical analysis and empirical evidence, we reveal two major shortcomings in the current SB infrastructure. First, we derive a feasible tracking technique for industry best practice. We show that the current mitigation techniques cannot eliminate the threat of de-anonymization permanently. Second, we gauge the effectiveness of blacklists provided by major vendors. Our discovery indicates the urge for blacklist integration in order to boost service quality. In light of this, we propose a new three-party paradigm PEBA with an intermediate third party decoupling the direct interaction of users and proprietary blacklist vendors. To satisfy practical usage requirements, we instantiate our design with trusted hardware, detailing how it can be leveraged to fulfill the requirements of privacy enhancement and broader content coverage at the same time. We also tackle numerous implementation challenges that emerged from this proxy-based and hardware-enabled solution. Extensive evaluation confirms that PEBA can balance well among desirable goals of security, usability, performance, and elasticity, making it suitable for deployment in practice.
AB - To keep web users away from unsafe websites, modern web browsers enable the embedded feature of safe browsing (SB) by default. In this work, through theoretical analysis and empirical evidence, we reveal two major shortcomings in the current SB infrastructure. First, we derive a feasible tracking technique for industry best practice. We show that the current mitigation techniques cannot eliminate the threat of de-anonymization permanently. Second, we gauge the effectiveness of blacklists provided by major vendors. Our discovery indicates the urge for blacklist integration in order to boost service quality. In light of this, we propose a new three-party paradigm PEBA with an intermediate third party decoupling the direct interaction of users and proprietary blacklist vendors. To satisfy practical usage requirements, we instantiate our design with trusted hardware, detailing how it can be leveraged to fulfill the requirements of privacy enhancement and broader content coverage at the same time. We also tackle numerous implementation challenges that emerged from this proxy-based and hardware-enabled solution. Extensive evaluation confirms that PEBA can balance well among desirable goals of security, usability, performance, and elasticity, making it suitable for deployment in practice.
KW - blacklist query service
KW - integrated service
KW - malware
KW - phishing
KW - privacy drawback
KW - privacy preserving
KW - Safe browsing
UR - http://www.scopus.com/inward/record.url?scp=85137935305&partnerID=8YFLogxK
U2 - 10.1109/TDSC.2022.3204767
DO - 10.1109/TDSC.2022.3204767
M3 - 文章
AN - SCOPUS:85137935305
SN - 1545-5971
VL - 20
SP - 4343
EP - 4358
JO - IEEE Transactions on Dependable and Secure Computing
JF - IEEE Transactions on Dependable and Secure Computing
IS - 5
ER -