A Large-scale Empirical Analysis of Browser Fingerprints Properties for Web Authentication

06/16/2020
by   Nampoina Andriamilanto, et al.
0

Modern browsers give access to several attributes that can be collected to form a browser fingerprint. Although browser fingerprints have primarily been studied as a web tracking tool, they can contribute to improve the current state of web security by augmenting web authentication mechanisms. In this paper, we investigate the adequacy of browser fingerprints for web authentication. We make the link between the digital fingerprints that distinguish browsers, and the biological fingerprints that distinguish Humans, to evaluate browser fingerprints according to properties inspired by biometric authentication factors. These properties include their distinctiveness, their stability through time, their collection time, their size, and the accuracy of a simple verification mechanism. We assess these properties on a large-scale dataset of 4,145,408 fingerprints composed of 216 attributes, and collected from 1,989,365 browsers. We show that, by time-partitioning our dataset, more than 81.3 fingerprints are known to evolve, an average of 91 fingerprints stay identical between two observations, even when separated by nearly 6 months. About their performance, we show that our fingerprints weigh a dozen of kilobytes, and take a few seconds to collect. Finally, by processing a simple verification mechanism, we show that it achieves an equal error rate of 0.61 attributes, and of their contribution to the evaluated properties. We conclude that our browser fingerprints carry the promise to strengthen web authentication mechanisms.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/19/2020

"Guess Who ?" Large-Scale Data-Centric Study of the Adequacy of Browser Fingerprints for Web Authentication

Browser fingerprinting consists in collecting attributes from a web brow...
research
10/13/2020

FPSelect: Low-Cost Browser Fingerprints for Mitigating Dictionary Attacks against Web Authentication Mechanisms

Browser fingerprinting consists into collecting attributes from a web br...
research
04/19/2021

BrFAST: a Tool to Select Browser Fingerprinting Attributes for Web Authentication According to a Usability-Security Trade-off

In this demonstration, we put ourselves in the place of a website manage...
research
04/25/2020

Active Voice Authentication

Active authentication refers to a new mode of identity verification in w...
research
05/26/2023

Fast IDentity Online with Anonymous Credentials (FIDO-AC)

Web authentication is a critical component of today's Internet and the d...
research
09/09/2022

Defend Data Poisoning Attacks on Voice Authentication

With the advances in deep learning, speaker verification has achieved ve...
research
11/14/2022

Is FIDO2 Passwordless Authentication a Hype or for Real?: A Position Paper

Operating system and browser support that comes with the FIDO2 standard ...

Please sign up or login with your details

Forgot password? Click here to reset