
FP-Inconsistent: Measurement and Analysis of Fingerprint Inconsistencies in Evasive Bot Traic
of the 2015 Internet Measurement Conference. 1–12.
[36]
Jing Jin, Je Outt, Nan Zheng, Feng Mao, Aaron Koehl, and Haining
Wang. 2013. Evasive Bots Masquerading as Human Beings on the Web.
In 2013 43rd Annual IEEE/IFIP International Conference on Dependable
Systems and Networks (DSN). IEEE, New York, NY, USA, 1–12. https:
//doi.org/10.1109/DSN.2013.6575366
[37]
Jordan Jueckstock, Shaown Sarker, Peter Snyder, Aidan Beggs, Pana-
giotis Papadopoulos, Matteo Varvello, Benjamin Livshits, and Alexan-
dros Kapravelos. 2021. Towards Realistic and ReproducibleWeb Crawl
Measurements (WWW ’21). Association for Computing Machinery,
New York, NY, USA, 80–91. https://doi.org/10.1145/3442381.3450050
[38] Faezeh Kalantari, Mehrnoosh Zaei, Yeganeh Safaei, Marzieh Bitaab,
Adam Oest, Gianluca Stringhini, Yan Shoshitaishvili, and Adam Doupé.
2024. Browser Polygraph: Ecient Deployment of Coarse-Grained
Browser Fingerprints for Web-Scale Detection of Fraud Browsers.
In Proceedings of the 2024 ACM on Internet Measurement Conference.
https://doi.org/10.1145/3646547.3688455
[39]
Tomer Laor, Naif Mehanna, Antonin Durey, Vitaly Dyadyuk, Pierre
Laperdrix, Clé mentine Maurice, Yossi Oren, Romain Rouvoy, Walter
Rudametkin, and Yuval Yarom. 2022. DRAWN APART : A Device
Identication Technique based on Remote GPU Fingerprinting. In
Proceedings 2022 Network and Distributed System Security Symposium.
Internet Society. https://doi.org/10.14722/ndss.2022.24093
[40]
Xigao Li, Babak Amin Azad, Amir Rahmati, and Nick Nikiforakis. 2021.
Good Bot, Bad Bot: Characterizing Automated Browsing Activity. In
2021 IEEE Symposium on Security and Privacy (SP). 1589–1605. https:
//doi.org/10.1109/SP40001.2021.00079
[41]
Zengrui Liu, Prakash Shrestha, and Nitesh Saxena. 2022. Gummy
browsers: targeted browser spoong against state-of-the-art nger-
printing techniques. In International Conference on Applied Cryptogra-
phy and Network Security. Springer, 147–169.
[42]
MaxMind. 2024. MaxMind GeoIP Databases. https://www.maxmind.
com/en/geoip-databases.
[43]
MaxMind. 2024. MaxMind minFraud Services. https://www.maxmind.
com/en/solutions/fraud-prevention/overview.
[44]
Mozilla. [n. d.]. Date.prototype.getTimezoneOset(). https://develper
.mozilla.org/enUS/docs/Web/JavaScript/Reference/Global_Objects
/Date/getTimezoneOset.
[45]
Shaoor Munir, Sandra Siby, Umar Iqbal, Steven Englehardt, Zubair
Shaq, and Carmela Troncoso. 2023. COOKIEGRAPH: Understanding
and Detecting First-Party Tracking Cookies. arXiv:2208.12370 [cs.CR]
[46]
Yoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd, and Gene
Tsudik. 2021. CACTI: Captcha Avoidance via Client-side TEE In-
tegration. In 30th USENIX Security Symposium (USENIX Security 21).
USENIX Association, 2561–2578. https://www.usenix.org/conferenc
e/usenixsecurity21/presentation/nakatsuka
[47]
Minh Hieu Nguyen Ba, Jacob Bennett, Michael Gallagher, and Suman
Bhunia. 2021. A Case Study of Credential Stung Attack: Canva Data
Breach. In 2021 International Conference on Computational Science and
Computational Intelligence (CSCI). 735–740. https://doi.org/10.1109/
CSCI54926.2021.00187
[48]
OpenWPM. [n. d.]. A web privacy measurement framework. https:
//github.com/openwpm/OpenWPM.
[49]
Iskander Sanchez-Rola, Igor Santos, and Davide Balzarotti. 2018. Clock
Around the Clock: Time-Based Device Fingerprinting. In Proceed-
ings of the 2018 ACM SIGSAC Conference on Computer and Com-
munications Security (Toronto, Canada) (CCS ’18). Association for
Computing Machinery, New York, NY, USA, 1502–1514. https:
//doi.org/10.1145/3243734.3243796
[50]
Andre Schaller, Wenjie Xiong, Nikolaos Athanasios Anagnostopoulos,
Muhammad Umair Saleem, Sebastian Gabmeyer, Stefan Katzenbeisser,
and Jakub Szefer. 2017. Intrinsic Rowhammer PUFs: Leveraging the
Rowhammer eect for improved security. In 2017 IEEE International
Symposium on Hardware Oriented Security and Trust (HOST). IEEE.
https://doi.org/10.1109/hst.2017.7951729
[51]
Andrew Searles, Yoshimichi Nakatsuka, Ercan Ozturk, Andrew Paverd,
Gene Tsudik, and Ai Enkoji. 2023. An Empirical Study & Evaluation
of Modern CAPTCHAs. In 32nd USENIX Security Symposium (USENIX
Security 23). USENIX Association, Anaheim, CA, 3081–3097. https:
//www.usenix.org/conference/usenixsecurity23/presentation/searles
[52]
seoclerks. [n. d.]. SEO Marketplace for backlinks, web design, website
trac, and online marketing. https://www.seoclerks.com/.
[53]
SHapley Additive exPlanations. [n. d.]. Welcome to the SHAP docu-
mentation. https://shap.readthedocs.io/en/latest/.
[54]
Sandra Siby, Umar Iqbal, Steven Englehardt, Zubair Shaq, and
Carmela Troncoso. 2022. WebGraph: Capturing Advertising and Track-
ing Information Flows for Robust Blocking. In 31st USENIX Security
Symposium (USENIX Security 22). USENIX Association, Boston, MA,
2875–2892. https://www.usenix.org/conference/usenixsecurity22/p
resentation/siby
[55]
Spark Trac. [n. d.]. Comprehensive Marketing Suite for better SEO
ranking. https://www.sparktrac.com/.
[56]
Kevin Springborn and Paul Barford. 2013. Impression Fraud in On-
line Advertising via Pay-Per-View Networks. In 22nd USENIX Security
Symposium (USENIX Security 13). USENIX Association, Washington,
D.C., 211–226. https://www.usenix.org/conference/usenixsecurity13
/technical-sessions/paper/springborn
[57]
StatCounter. 2024. Browser Market Share Worldwide. https://gs.statc
ounter.com/browser-market-share.
[58]
TechReport. [n. d.]. Most Important Brave Market Share Statistics in
2024. https://techreport.com/statistics/software-web/brave-market-
share-statistics/.
[59]
Tor. [n. d.]. A website I am trying to reach is blocking access over Tor.
https://support.torproject.org/tbb/website-blocking-tor/.
[60]
Tor. [n. d.]. You have a right to BROWSE without being watched.
https://www.torproject.org/download/languages/.
[61]
U.S. Department of Health and Human Services. 2018. Decision Charts:
2018 Requirements (Common Rule). https://www.hhs.gov/ohrp/reg
ulations-and-policy/decision-charts-2018/index.html#c1
[62]
Antoine Vastel, Pierre Laperdrix, Walter Rudametkin, and Romain
Rouvoy. 2018. FP-STALKER: Tracking Browser Fingerprint Evolutions.
In 2018 IEEE Symposium on Security and Privacy (SP). 728–741. https:
//doi.org/10.1109/SP.2018.00008
[63]
Antoine Vastel, Walter Rudametkin, Romain Rouvoy, and Xavier Blanc.
2020. FP-Crawlers: Studying the Resilience of Browser Fingerprint-
ing to Block Crawlers. In MADWeb’20 - NDSS Workshop on Measure-
ments, Attacks, and Defenses for the Web, Oleksii Starov, Alexandros
Kapravelos, and Nick Nikiforakis (Eds.). San Diego, United States.
https://doi.org/10.14722/ndss.2020.23xxx
[64]
Hari Venugopalan, Kaustav Goswami, Zainul Abi Din, Jason Lowe-
Power, Samuel T. King, and Zubair Shaq. 2023. Centauri: Practical
Rowhammer Fingerprinting. arXiv:2307.00143 [cs.CR]
[65]
Chrome Webstore. 2024. Adblock Plus. https://chromewebstore.googl
e.com/detail/adblock-plus-free-ad-bloc/cfhdojbkjhnklbpkdaibdccdd
ilifddb.
[66]
Chrome Webstore. 2024. uBlock Origin. https://chromewebstore.goo
gle.com/detail/ublock-origin/cjpalhdlnbpafiamejdnhcphjbkeiagm.
[67]
Shujiang Wu, Pengfei Sun, Yao Zhao, and Yinzhi Cao. 2023. Him
of Many Faces: Characterizing Billion-scale Adversarial and Benign
Browser Fingerprints on Commercial Websites. In 30th Annual Net-
work and Distributed System Security Symposium, NDSS 2023, San Diego,
California, USA, February 27 - March 3, 2023. The Internet Society.
[68]
XGBoost. [n. d.]. XGBoost Documentation. https://xgboost.readthed
ocs.io/en/stable/.