Security & Privacy Research at Illinois (SPRAI)
Professor Adam Bates Fall 2018
Web Privacy Professor Adam Bates Fall 2018 Security & Privacy - - PowerPoint PPT Presentation
CS 563 - Advanced Computer Security: Web Privacy Professor Adam Bates Fall 2018 Security & Privacy Research at Illinois (SPRAI) Administrative Learning Objectives : Consider the difference between security and privacy Discuss work
Security & Privacy Research at Illinois (SPRAI)
Professor Adam Bates Fall 2018
CS423: Operating Systems Design
2
Learning Objectives:
Announcements:
Reminder: Please put away (backlit) devices at the start of class
2
Security & Privacy Research at Illinois (SPRAI)
3
Security & Privacy Research at Illinois (SPRAI)
4
downplay the importance of individual security.
privacy problems can be found in all sections of the triad.
privacy security
Security & Privacy Research at Illinois (SPRAI)
5
explicitly disclose be used to make sensitive inferences about me?
parties affect that data?
authorized partied when I need it?
privacy security
Security & Privacy Research at Illinois (SPRAI)
6
activities at different times and on different websites.
that is stored in the browser.
cookie’s use in browser tracking.
can be used to track browsers across multiple website.
Security & Privacy Research at Illinois (SPRAI)
7
usatoday.com) can identify us on subsequent visits?
Websites: Expectation…
Security & Privacy Research at Illinois (SPRAI)
8
usatoday.com) can identify us on subsequent visits?
Websites: Reality!
Security & Privacy Research at Illinois (SPRAI)
9
browser tracking problem…
If we eradicated cookies from the Internet, would that solve the browser tracking problem?
Security & Privacy Research at Illinois (SPRAI)
10
hardware and devices. You can basically fingerprint anything, and use anything to fingerprint:
Security & Privacy Research at Illinois (SPRAI)
11
albeit with varying levels of difficulty, including:
harder?
Security & Privacy Research at Illinois (SPRAI)
12
browser fingerprinting was.
determine severity of the problem.
Security & Privacy Research at Illinois (SPRAI)
13
Note: Plenty of unharvested info, such as ActiveX, Silverlight, etc.
Security & Privacy Research at Illinois (SPRAI)
14
Self-Information / Surprisal / Entropy (related ideas)
its random variable(s) is sampled?
that the variables won’t all be independent.
(logarithm of) the number of browsers in “the world”
Security & Privacy Research at Illinois (SPRAI)
15
Of ~470,000 fingerprint instances collected…
Security & Privacy Research at Illinois (SPRAI) 16
Of ~470,000 fingerprint instances collected…
8 3 . 6 % o f fingerprints are entirely unique! 8.1% of fingerprints had some semblance
Security & Privacy Research at Illinois (SPRAI) 17
Where did Panoptoclick struggle?
Security & Privacy Research at Illinois (SPRAI) 18
Where did Panoptoclick struggle? iPhones Androids
Trolls using lynx
Security & Privacy Research at Illinois (SPRAI)
19
Are browser fingerprints consistent?
between two fingerprints 65% of the time (w/ 0.9% FP).
Security & Privacy Research at Illinois (SPRAI)
20
anonymity plug-ins) often decreased anonymity set!!
fingerprinting.
fingerprinting (e.g., fine-grained version numbers)
difficulty of fingerprinting (e.g., font orders)
Security & Privacy Research at Illinois (SPRAI)
21
(LBS), e.g., …
about our identity, of even harm us in the real world!
Security & Privacy Research at Illinois (SPRAI)
22
“User is equally likely to be anywhere within radius r of the Eiffel Tower”
noise to user’s location before sharing with LBS.
indistinguishability within a given area
differential privacy for an arbitrary distance function.
Security & Privacy Research at Illinois (SPRAI)
23
How does GI work?
Security & Privacy Research at Illinois (SPRAI) 24
region specified by ε is equally likely to be returned
Properties of GI
Security & Privacy Research at Illinois (SPRAI)
compare to Differential Privacy (DP)?
25
, GI is independent from side information
two points
Security & Privacy Research at Illinois (SPRAI)
26
distribution, yielding a probability density function from which we choose a random point.
the nearest point in discrete domain (i.e., Lat, Long)
Continuous Discretize Truncate
Security & Privacy Research at Illinois (SPRAI)
inadequate, instead specify larger area of retrieval based on z:
27
User’s approximate location z Location info for z User’s approximate location z Area of Retrieval A POI Info within A
Security & Privacy Research at Illinois (SPRAI)
28
Security & Privacy Research at Illinois (SPRAI)
29
Security & Privacy Research at Illinois (SPRAI)
30
Security & Privacy Research at Illinois (SPRAI)
31
Security & Privacy Research at Illinois (SPRAI)
32
Security & Privacy Research at Illinois (SPRAI)
33
according to specified values of l and r
Security & Privacy Research at Illinois (SPRAI)
34
Security & Privacy Research at Illinois (SPRAI)
35
Endpoint Privacy Zones…
Security & Privacy Research at Illinois (SPRAI)
36
Endpoint Privacy Zones…
Security & Privacy Research at Illinois (SPRAI)
37
Endpoint Privacy Zones…
Security & Privacy Research at Illinois (SPRAI)
38
Endpoint Privacy Zones…
21 Million Activities 3 Million Athletes
Security & Privacy Research at Illinois (SPRAI)
39
Endpoint Privacy Zones…
21 Million Activities 3 Million Athletes
15% of Athletes use Privacy Zones
Security & Privacy Research at Illinois (SPRAI)
40
Endpoint Privacy Zones…
21 Million Activities 3 Million Athletes
15% of Athletes use Privacy Zones
Security & Privacy Research at Illinois (SPRAI)
41
Endpoint Privacy Zones…
21 Million Activities 3 Million Athletes
15% of Athletes use Privacy Zones
Security & Privacy Research at Illinois (SPRAI)
42
Endpoint Privacy Zones…
d
θ Use GI-st yle enhancement to dramatically reduces privacy leakage!!
Security & Privacy Research at Illinois (SPRAI)
43
conferences (IEEE S&P a.k.a. Oakland, USENIX Security, CCS, NDSS), prestigious privacy-focused conferences (i.e., PETS).