The Chain of Implicit Trust: An Analysis of the Web Third-party Resources Loading

01/23/2019
by   Muhammad Ikram, et al.
0

The Web is a tangled mass of interconnected services, where websites import a range of external resources from various third-party domains. However, the latter can further load resources hosted on other domains. For each website, this creates a dependency chain underpinned by a form of implicit trust between the first-party and transitively connected third-parties. The chain can only be loosely controlled as first-party websites often have little, if any, visibility of where these resources are loaded from. This paper performs a large-scale study of dependency chains in the Web, to find that around 50 first-party websites render content that they did not directly load. Although the majority (84.91 levels), we find websites with dependency chains exceeding 30. Using VirusTotal, we show that 1.2 suspicious --- although seemingly small, this limited set of suspicious third-parties have remarkable reach into the wider ecosystem. By running sandboxed experiments, we observe a range of activities with the majority of suspicious JavaScript downloading malware; worryingly, we find this propensity is greater among implicitly trusted JavaScripts.

READ FULL TEXT

page 3

page 8

page 10

research
11/02/2018

Include Me Out: In-Browser Detection of Malicious Third-Party Content Inclusions

Modern websites include various types of third-party content such as Jav...
research
12/10/2018

JSSignature: Eliminating Third-Party-Hosted JavaScript Infection Threats Using Digital Signatures

Today, third-party JavaScript resources are indispensable part of the we...
research
02/15/2019

Who Watches the Watchmen: Exploring Complaints on the Web

Under increasing scrutiny, many web companies now offer bespoke mechanis...
research
12/06/2021

Topology and Geometry of the Third-Party Domains Ecosystem

Over the years, web content has evolved from simple text and static imag...
research
03/21/2022

Privacy Rarely Considered: Exploring Considerations in the Adoption of Third-Party Services by Websites

Modern websites frequently use and embed third-party services to facilit...
research
01/28/2020

Beyond the Front Page: Measuring Third Party Dynamics in the Field

In the modern Web, service providers often rely heavily on third parties...
research
04/08/2018

Movie Pirates of the Caribbean: Exploring Illegal Streaming Cyberlockers

Online video piracy (OVP) is a contentious topic, with strong proponents...

Please sign up or login with your details

Forgot password? Click here to reset