"Guess Who ?" Large-Scale Data-Centric Study of the Adequacy of Browser Fingerprints for Web Authentication - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2021

"Guess Who ?" Large-Scale Data-Centric Study of the Adequacy of Browser Fingerprints for Web Authentication

Résumé

Browser fingerprinting consists in collecting attributes from a web browser to build a browser fingerprint. In this work, we assess the adequacy of browser fingerprints as an authentication factor, on a dataset of 4,145,408 fingerprints composed of 216 attributes. It was collected throughout 6 months from a population of general browsers. We identify, formalize, and assess the properties for browser fingerprints to be usable and practical as an authentication factor. We notably evaluate their distinctiveness, their stability through time, their collection time, and their size in memory. We show that considering a large surface of 216 fingerprinting attributes leads to an 81.8% unicity rate on a population of 1,989,365 browsers. Moreover, browser fingerprints are known to evolve, but we observe that between consecutive fingerprints, more than 90% of attributes remains unchanged after nearly 6 months. Fingerprints are also affordable. On average, they weight a dozen of kilobytes, and are collected in a few seconds. We conclude that browser fingerprints are a promising additional web authentication factor.
Fichier principal
Vignette du fichier
Guess Who - Large-Scale Data-Centric Study of the Adequacy of Browser Fingerprints for Web Authentication - Final Postprint.pdf (1.75 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02611624 , version 1 (18-05-2020)
hal-02611624 , version 2 (10-06-2020)
hal-02611624 , version 3 (14-10-2020)
hal-02611624 , version 4 (22-06-2021)

Identifiants

Citer

Nampoina Andriamilanto, Tristan Allard, Gaetan Le Guelvouit. "Guess Who ?" Large-Scale Data-Centric Study of the Adequacy of Browser Fingerprints for Web Authentication. International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing (IMIS), Jul 2020, Lodz, Poland. pp.161-172, ⟨10.1007/978-3-030-50399-4_16⟩. ⟨hal-02611624v3⟩
369 Consultations
142 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More