Wednesday, January 8, 2025
Homecyber securityPriveShield - Advanced Privacy Protection with Browser Profile Isolation

PriveShield – Advanced Privacy Protection with Browser Profile Isolation

Published on

A browser extension named PRIVESHIELD automatically creates isolated profiles to group websites based on browsing history and user interaction, which disrupts cross-website tracking practices by preventing cookie-matching methods used for targeted advertising. 

The evaluation results show that PRIVESHIELD is more than 90% effective in preventing ad exchanges from sharing user information.

In Real-time Bidding (RTB), ad exchanges act as intermediaries between Supply-side Platforms (SSPs) and Demand-side Platforms (DSPs). 

SSPs manage ad inventory for publishers and DSPs manage ad campaigns for advertisers. During an RTB auction, DSPs place bids on ad impressions based on user information collected through cookies. 

Cookie syncing allows SSPs and DSPs to synchronize their cookies and share user data, which enables DSPs to learn about users’ interests and demographics and deliver targeted ads. 

Cookie syncing process between the user, SSP, and
the DSP.

It is essential for retargeted advertising as it allows advertisers to identify users across different websites, as third-party cookies are used for cookie syncing, but browsers can block third-party cookies, which limits the effectiveness of cookie syncing.

PRIVESHIELD is a browser extension that uses automatic profiles to store and manage data from different clusters of websites in isolated profiles to disrupt the cross-origin tracking cycle and prevent ad exchanges from using cookie-matching methods to implement retargeting practices on Internet users. 

It achieves this by creating separate profiles for regular visited websites, websites where users spend a long time, websites where users interact with and websites that fall into specific categories. 

The extension uses a combination of browsing history, time on website and user interaction with the website to determine which profile to use for a particular website.

When switching between profiles, PRIVESHIELD ensures that the cookies of each profile are stored separately in isolated storage. 

PRIVESHIELD impacting the browsing process

It is a browser extension that protects users from retargeted ads by creating isolated profiles for different websites and achieves this by using event listeners to track user interactions and storing cookies in separate profiles. 

The evaluation methods include testing on real-world scenarios and analyzing third-party cookie behavior, where the results show that PRIVESHIELD is effective in reducing retargeted ads and the performance overhead is minimal.

According to the research, the project implemented PRIVESHIELD, a privacy tool that disrupts cookie-syncing for retargeted ads and reuses existing browser functions to isolate cookies, minimizing performance impact and user experience disruption. 

It achieves this by creating dedicated profiles for websites, hindering cross-site data sharing while allowing ads within a website category, which increases the difficulty of cookie-matching for advertisers, reducing the effectiveness of retargeting. 

The evaluation demonstrated a significant reduction in retargeted ads based on cookie matching, although other tracking methods like fingerprinting remain a challenge, while future work will explore incorporating fingerprinting avoidance techniques while maintaining the tool’s lightweight design and minimal user impact.

ANY.RUN Threat Intelligence Lookup - Extract Millions of IOC's for Interactive Malware Analysis: Try for Free

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Gravy Analytics Hit by Cyberattack, Hackers Allegedly Stole data

Gravy Analytics, a prominent player in location intelligence, has reportedly fallen victim to a...

Chrome Security Update – Patch for Multiple Security Vulnerabilities

Google has released an update for its Chrome web browser, advancing to version 131.0.6778.264/.265...

How Nation-State Actors and Organised Hackers Involving in Their Ways of Cyber Attacks

The distinction between nation-state actors and organized cybercriminals is becoming increasingly blurred.Both groups...

Washington State Filed Lawsuit Against T-Mobile Massive Data Breach

Washington State Attorney General Bob Ferguson filed a consumer protection lawsuit against T-Mobile for...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Gravy Analytics Hit by Cyberattack, Hackers Allegedly Stole data

Gravy Analytics, a prominent player in location intelligence, has reportedly fallen victim to a...

Chrome Security Update – Patch for Multiple Security Vulnerabilities

Google has released an update for its Chrome web browser, advancing to version 131.0.6778.264/.265...

How Nation-State Actors and Organised Hackers Involving in Their Ways of Cyber Attacks

The distinction between nation-state actors and organized cybercriminals is becoming increasingly blurred.Both groups...