Abstract
The Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. The latter can also load resources hosted on other domains. For each website, this creates a dependency chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The chain can only be loosely controlled as first-party websites often have little, if any, visibility on where these resources are loaded from. This paper performs a large-scale study of dependency chains in the Web, to find that around 50% of first-party websites render content that they did not directly load. Although the majority (84.91%) of websites have short dependency chains (below 3 levels), we find websites with dependency chains exceeding 30. Using VirusTotal, we show that 1.2% of these third-parties are classified as suspicious - although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem.
| Original language | English |
|---|---|
| Title of host publication | Proceeding WWW '19 The World Wide Web Conference |
| Place of Publication | New York |
| Publisher | Association for Computing Machinery (ACM) |
| Pages | 2851-2857 |
| Number of pages | 7 |
| ISBN (Electronic) | 9781450366748 |
| DOIs | |
| Publication status | Published - 2019 |
| Event | The Web Conference 2019, WWW 2019: 30th World Wide Web Conference - San Francisco, United States Duration: 13 May 2019 → 17 May 2019 |
Conference
| Conference | The Web Conference 2019, WWW 2019 |
|---|---|
| Country/Territory | United States |
| City | San Francisco |
| Period | 13/05/19 → 17/05/19 |
Fingerprint
Dive into the research topics of 'The chain of implicit trust: an analysis of the Web third-party resources loading'. Together they form a unique fingerprint.-
An empirical assessment of security and privacy risks of web-based chatbots
Waheed, N., Ikram, M., Hashmi, S. S., He, X. & Nanda, P., 2022, Web Information Systems Engineering – WISE 2022: 23rd International Conference, Biarritz, France, November 1-3, 2022 : proceedings. Chbeir, R., Huang, H., Silvestri, F., Manolopoulos, Y., Zhang, Y. & Zhang, Y. (eds.). Cham, Switzerland: Springer, Springer Nature, p. 325-339 15 p. (Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics); vol. 13724 LNCS).Research output: Chapter in Book/Report/Conference proceeding › Conference proceeding contribution › peer-review
11 Link opens in a new tab Citations (Scopus) -
Measuring and analysing the chain of implicit trust: a study of third-party resources loading
Ikram, M., Masood, R., Tyson, G., Kaafar, M. A., Loizon, N. & Ensafi, R., Apr 2020, In: ACM Transactions on Privacy and Security (TOPS). 23, 2, p. 1-27 27 p., 8.Research output: Contribution to journal › Article › peer-review
Open Access
Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver