Instrumentation & Measurement Magazine 23-9 - 51

Security and Privacy Implications of
Web Tracking

Measurements for the Detection and
Analysis of Web Tracking

Services such as the commented Facebook or other wellknown actors like Google, Amazon or Twitter are the main
examples of the commented third-party trackers. They
usually collect personal data to build the most exhaustive profile possible of their users for their own profit. This
is emphasized by the fact that they are at the same time
first-party and third-party trackers. As a result, they not
only collect data from multiple different places, but they
also have confidential personal data obtained during the
account creation process, such as real names, place of residence, telephone number or school graduation details. All
of that data is combined into a profile that will allow them
to personalize their websites and advertisements based on
the users' likes and opinions.
Besides the usual third-party trackers, the presence of
data brokers (i.e., companies focused on collecting data from
millions of users to resell it to other companies) is mostly
unknown to regular users but they are becoming more frequent on the Internet and present multiple security and
privacy concerns. Usually, the power reached by those companies, due to the amount of data they collect, and how
this power can alter everyday life, is not noticed. A practical example would be a political situation where a party has
access to the personal information of a widely used social
network, where political opinions and personal perspectives of millions of people are easily reachable. All of that
information can be used to catalog people into different
groups, depending on their ideological positions, and create
specific online marketing political campaigns to influence
users doubting their vote, and potentially favoring the election of a political party. This perverse use of the data already
happened in the past [3] and had consequences not only for
the people being tracked, but also for all the people living in
the same country.
Besides, having all of this information gathered silently
by an unknown company in a remote computer, where the
user has neither knowledge nor access at all, represents
a privacy problem by itself. Security breaches have been
present in the Internet since its foundation, and even big
companies that dedicate a lot of resources to secure their
data have suffered from security flaws that allowed information theft. On the other hand, there is no guarantee that
the collected information (and the conclusions drawn from
it) are correct, as the user cannot access nor review it. However, this information is already being used for multiple
purposes that affect our lives, such as financial assessment,
determination of insurance coverage, price discrimination
or background scanning.
Bujlow et al. presents in [1] a survey that includes a comprehensive description of the existing web tracking methods
as well as references to the literature explaining the facts contained in this section. In this paper, we focus instead on the
methods that have been proposed to analyze and detect web
tracking using network measurements.

Web tracking is a transparent and pervasive data collection
method that operates in the background, mainly at the application layer. As such, the only possibility to effectively detect
and analyze it is by using network measurements to observe
the information transmitted by the browser in the wild, either
at the network or the application layer. Among the different
network measurement techniques that can be applied, we can
differentiate three main categories: passive, active and clientside measurements.

December 2020	

Passive Measurements
These kinds of measurements base their methodology on
collecting all of the traffic seen inside a network (e.g., IP packets). The captured data is explored, looking for patterns and
characteristics that could be useful for the experiment. The
limited visibility of the traffic content at the application level
and the privacy concerns introduced by capturing all the personal data being transmitted over the network are factors to
consider.

Active Measurements
This methodology is based on performing measurements acting as the user. In web tracking experiments, this is done by
executing a longitudinal study over a selected website population, opening the website as a user would do. This method
allows a high number of very precise measurements to be obtained without the intervention of real users. However, this
type of measurement presents some ethical considerations.
By simulating a user, false visits are generated to the examined websites, a fact that if done in excess can affect their
functionality.

Client-side Measurements
Client-side measurements are based on performing the measurements directly on the clients and sending back the results
to a centralized place to explore them. In web tracking experiments, it is done mainly by using browser plugins installable
by the user. This approximation avoids the privacy concerns
introduced in passive measurements, as the user is previously
informed of the purpose of the experiment and the overall process. It also gives precise measurement results that are only
dependent on the client settings and specifications. The main
drawback is a potential lack of support by the user, usually representing a big challenge to get enough participation to obtain
a representative number of measurements.
Each presented methodology has its pros and cons and has
been used in the past for web tracking measurements, as discussed in the next section.

Taxonomy of Web Tracking Network
Measurements
Web tracking presents multiple security and privacy concerns,
and as such, it is a hot topic in the network measurement community at the time of this writing. Therefore, there have been

IEEE Instrumentation & Measurement Magazine	51



Instrumentation & Measurement Magazine 23-9

Table of Contents for the Digital Edition of Instrumentation & Measurement Magazine 23-9

No label
Instrumentation & Measurement Magazine 23-9 - No label
Instrumentation & Measurement Magazine 23-9 - Cover2
Instrumentation & Measurement Magazine 23-9 - 1
Instrumentation & Measurement Magazine 23-9 - 2
Instrumentation & Measurement Magazine 23-9 - 3
Instrumentation & Measurement Magazine 23-9 - 4
Instrumentation & Measurement Magazine 23-9 - 5
Instrumentation & Measurement Magazine 23-9 - 6
Instrumentation & Measurement Magazine 23-9 - 7
Instrumentation & Measurement Magazine 23-9 - 8
Instrumentation & Measurement Magazine 23-9 - 9
Instrumentation & Measurement Magazine 23-9 - 10
Instrumentation & Measurement Magazine 23-9 - 11
Instrumentation & Measurement Magazine 23-9 - 12
Instrumentation & Measurement Magazine 23-9 - 13
Instrumentation & Measurement Magazine 23-9 - 14
Instrumentation & Measurement Magazine 23-9 - 15
Instrumentation & Measurement Magazine 23-9 - 16
Instrumentation & Measurement Magazine 23-9 - 17
Instrumentation & Measurement Magazine 23-9 - 18
Instrumentation & Measurement Magazine 23-9 - 19
Instrumentation & Measurement Magazine 23-9 - 20
Instrumentation & Measurement Magazine 23-9 - 21
Instrumentation & Measurement Magazine 23-9 - 22
Instrumentation & Measurement Magazine 23-9 - 23
Instrumentation & Measurement Magazine 23-9 - 24
Instrumentation & Measurement Magazine 23-9 - 25
Instrumentation & Measurement Magazine 23-9 - 26
Instrumentation & Measurement Magazine 23-9 - 27
Instrumentation & Measurement Magazine 23-9 - 28
Instrumentation & Measurement Magazine 23-9 - 29
Instrumentation & Measurement Magazine 23-9 - 30
Instrumentation & Measurement Magazine 23-9 - 31
Instrumentation & Measurement Magazine 23-9 - 32
Instrumentation & Measurement Magazine 23-9 - 33
Instrumentation & Measurement Magazine 23-9 - 34
Instrumentation & Measurement Magazine 23-9 - 35
Instrumentation & Measurement Magazine 23-9 - 36
Instrumentation & Measurement Magazine 23-9 - 37
Instrumentation & Measurement Magazine 23-9 - 38
Instrumentation & Measurement Magazine 23-9 - 39
Instrumentation & Measurement Magazine 23-9 - 40
Instrumentation & Measurement Magazine 23-9 - 41
Instrumentation & Measurement Magazine 23-9 - 42
Instrumentation & Measurement Magazine 23-9 - 43
Instrumentation & Measurement Magazine 23-9 - 44
Instrumentation & Measurement Magazine 23-9 - 45
Instrumentation & Measurement Magazine 23-9 - 46
Instrumentation & Measurement Magazine 23-9 - 47
Instrumentation & Measurement Magazine 23-9 - 48
Instrumentation & Measurement Magazine 23-9 - 49
Instrumentation & Measurement Magazine 23-9 - 50
Instrumentation & Measurement Magazine 23-9 - 51
Instrumentation & Measurement Magazine 23-9 - 52
Instrumentation & Measurement Magazine 23-9 - 53
Instrumentation & Measurement Magazine 23-9 - 54
Instrumentation & Measurement Magazine 23-9 - 55
Instrumentation & Measurement Magazine 23-9 - 56
Instrumentation & Measurement Magazine 23-9 - 57
Instrumentation & Measurement Magazine 23-9 - 58
Instrumentation & Measurement Magazine 23-9 - 59
Instrumentation & Measurement Magazine 23-9 - 60
Instrumentation & Measurement Magazine 23-9 - 61
Instrumentation & Measurement Magazine 23-9 - 62
Instrumentation & Measurement Magazine 23-9 - 63
Instrumentation & Measurement Magazine 23-9 - 64
Instrumentation & Measurement Magazine 23-9 - 65
Instrumentation & Measurement Magazine 23-9 - 66
Instrumentation & Measurement Magazine 23-9 - 67
Instrumentation & Measurement Magazine 23-9 - 68
Instrumentation & Measurement Magazine 23-9 - 69
Instrumentation & Measurement Magazine 23-9 - 70
Instrumentation & Measurement Magazine 23-9 - 71
Instrumentation & Measurement Magazine 23-9 - 72
Instrumentation & Measurement Magazine 23-9 - Cover3
Instrumentation & Measurement Magazine 23-9 - Cover4
https://www.nxtbook.com/allen/iamm/25-9
https://www.nxtbook.com/allen/iamm/25-8
https://www.nxtbook.com/allen/iamm/25-7
https://www.nxtbook.com/allen/iamm/25-6
https://www.nxtbook.com/allen/iamm/25-5
https://www.nxtbook.com/allen/iamm/25-4
https://www.nxtbook.com/allen/iamm/25-3
https://www.nxtbook.com/allen/iamm/instrumentation-measurement-magazine-25-2
https://www.nxtbook.com/allen/iamm/25-1
https://www.nxtbook.com/allen/iamm/24-9
https://www.nxtbook.com/allen/iamm/24-7
https://www.nxtbook.com/allen/iamm/24-8
https://www.nxtbook.com/allen/iamm/24-6
https://www.nxtbook.com/allen/iamm/24-5
https://www.nxtbook.com/allen/iamm/24-4
https://www.nxtbook.com/allen/iamm/24-3
https://www.nxtbook.com/allen/iamm/24-2
https://www.nxtbook.com/allen/iamm/24-1
https://www.nxtbook.com/allen/iamm/23-9
https://www.nxtbook.com/allen/iamm/23-8
https://www.nxtbook.com/allen/iamm/23-6
https://www.nxtbook.com/allen/iamm/23-5
https://www.nxtbook.com/allen/iamm/23-2
https://www.nxtbook.com/allen/iamm/23-3
https://www.nxtbook.com/allen/iamm/23-4
https://www.nxtbookmedia.com