Data Protection and Security Issues With Network Error Logging

05/09/2023
by   Libor Polčák, et al.
0

Network Error Logging helps web server operators detect operational problems in real-time to provide fast and reliable services. This paper analyses Network Error Logging from two angles. Firstly, this paper overviews Network Error Logging from the data protection view. The ePrivacy Directive requires consent for non-essential access to the end devices. Nevertheless, the Network Error Logging design does not allow limiting the tracking to consenting users. Other issues lay in GDPR requirements for transparency and the obligations in the contract between controllers and processors of personal data. Secondly, this paper explains Network Error Logging exploitations to deploy long-time trackers to the victim devices. Even though users should be able to disable Network Error Logging, it is not clear how to do so. Web server operators can mitigate the attack by configuring servers to preventively remove policies that adversaries might have added.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/02/2023

Network Error Logging: HTTP Archive Analysis

Network Error Logging helps web server operators detect operational prob...
research
01/13/2019

Implementing DMZ in Improving Network Security of Web Testing in STMIK AKBA

The aims of this research are to design and to implement network securit...
research
07/10/2019

Increasing broadband reach withHybrid Access Networks

End-users and governments force network operators to deploy faster Inter...
research
02/24/2022

A Holistic View on Data Protection for Sharing, Communicating, and Computing Environments: Taxonomy and Future Directions

The data is an important asset of an organization and it is essential to...
research
01/21/2014

Increasing Server Availability for Overall System Security: A Preventive Maintenance Approach Based on Failure Prediction

Server Availability (SA) is an important measure of overall systems secu...
research
09/08/2020

Technical Report: Gone in 20 Seconds – Overview of a Password Vulnerability in Siemens HMIs

Siemens produce a range of industrial human machine interface (HMI) scre...
research
12/07/2021

Datensouveränität für Verbraucher:innen: Technische Ansätze durch KI-basierte Transparenz und Auskunft im Kontext der DSGVO

A sufficient level of data sovereignty is extremely difficult for consum...

Please sign up or login with your details

Forgot password? Click here to reset