TY - GEN
T1 - The chain of implicit trust
T2 - The Web Conference 2019, WWW 2019
AU - Ikram, Muhammad
AU - Masood, Rahat
AU - Tyson, Gareth
AU - Kaafar, Mohamed Ali
AU - Loizon, Noha
AU - Ensafi, Roya
PY - 2019
Y1 - 2019
N2 - The Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. The latter can also load resources hosted on other domains. For each website, this creates a dependency chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This paper performs a large-scale study of dependency chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short dependency chains (below 3 levels), we find websites with dependency chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious - although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem.
AB - The Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. The latter can also load resources hosted on other domains. For each website, this creates a dependency chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This paper performs a large-scale study of dependency chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short dependency chains (below 3 levels), we find websites with dependency chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious - although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem.
UR - http://www.scopus.com/inward/record.url?scp=85066901372&partnerID=8YFLogxK
U2 - 10.1145/3308558.3313521
DO - 10.1145/3308558.3313521
M3 - Conference proceeding contribution
SP - 2851
EP - 2857
BT - Proceeding WWW '19 The World Wide Web Conference
PB - Association for Computing Machinery (ACM)
CY - New York
Y2 - 13 May 2019 through 17 May 2019
ER -