Skip to main content
Back

Link decoration

5 results across all content

Publications (1)

2024ConferenceTop-Tier

PURL: Safe and Effective Sanitization of Link Decoration

USENIX Security Symposium(USENIX Security) · 17% acceptance

Shaoor Munir, Patrick Lee, Umar Iqbal, Zubair Shafiq, Sandra Siby

TL;DR:PURL uses ML to sanitize tracking information from URL parameters while preserving website functionality.

While privacy-focused browsers have taken steps to block third-party cookies and browser fingerprinting, novel tracking methods that bypass existing defenses continue to emerge. Since trackers need to exfiltrate information from the client- to server-side through link decoration regardless of the tracking technique they employ, a promising orthogonal approach is to detect and sanitize tracking information in decorated links. We present PURL, a machine-learning approach that leverages a cross-layer graph representation of webpage execution to safely and effectively sanitize link decoration. Our evaluation shows that PURL significantly outperforms existing countermeasures in terms of accuracy and reducing website breakage while being robust to common evasion techniques. We use PURL to perform a measurement study on top-million websites. We find that link decorations are widely abused by well-known advertisers and trackers to exfiltrate user information collected from browser storage, email addresses, and scripts involved in fingerprinting.

Talks (3)

PURL: Safe and Effective Sanitization of Link Decoration

USENIX Security 2024 · August 2024

Presenting a machine-learning approach that uses cross-layer graph representation of webpage execution to safely and effectively sanitize tracking information in decorated links.

Watch/Listen →

Beyond Third-Party Cookies: Safeguarding User Data from Storage and Exfiltration with CookieGraph and PURL

IMDEA Networks · November 2023

A comprehensive talk covering two complementary approaches to combat emerging tracking techniques: CookieGraph for first-party cookie tracking and PURL for link decoration tracking.

Watch/Listen →

What you don't remove can track you: Measuring and detecting tracking decorations

Ad-Filtering Dev Summit 2023 · October 2023

Discussing how link decorations are abused by advertisers and trackers to exfiltrate user information, and how PURL can detect and sanitize these tracking decorations.

Watch/Listen →

Media Coverage (1)

Link decoration Research & Content | Shaoor Munir