English

Semantic Identification of Web Browsing Sessions

Cryptography and Security 2017-04-12 v1

Abstract

We introduce a semantic identification attack, in which an adversary uses semantic signals about the pages visited in one browsing session to identify other browsing sessions launched by the same user. Current user fingerprinting methods fail when a single machine is used by multiple users (e.g., in cybercafes or spaces with public computers) as these methods fingerprint devices, not individuals. We demonstrate how an adversary can employ a SIA to successfully fingerprint users on public or shared machines and identify them across browsing sessions. We additionally describe and evaluate possible countermeasures to prevent identification.

Keywords

Cite

@article{arxiv.1704.03138,
  title  = {Semantic Identification of Web Browsing Sessions},
  author = {Neel Guha},
  journal= {arXiv preprint arXiv:1704.03138},
  year   = {2017}
}

Comments

10 pages and Appendix. arXiv admin note: substantial text overlap with arXiv:1610.09417

R2 v1 2026-06-22T19:13:42.434Z