=== PASS A — corpus shape (denominator for everything in pass A) ===
papers with a structured extraction record: 5859
population all 5859
population crawled 1120
population measuredFrom 3908
population webCrawled 857
population legal 402
population empirical 5118
=== PASS A — corpus papers whose TITLE names server-side tracking ===
2024 PETS The Devil is in the Details: Detection, Measurement and Lawfulness of Server-Side Tracking on the Web
2024 PETS Client-side and Server-side Tracking on Meta: Effectiveness and Accuracy
=== PASS A — detection tuples of those papers (phenomenon | technique | metric | prevalence) ===
-- PETS 2024: The Devil is in the Details: Detection, Measurement and Lawfulness of Server-Side Tracking on the Web
IP cloaking | Compared A/AAAA/CNAME organizations with visited-site organization. | share of visited websites | 996 cloaked subdomains on 767 websites (10.41%)
identifier-cookie tracking | Compared cookie values across two user-specific crawls. | share of cloaked domains | 474 of 996 cloaked domains (47.59%)
server-side tracking | Matched emerging cloaked trackers and shifted parameters/cookies across 2020–2022 crawls. | websites with SST | 28 of 7,367 visited websites
Same-Origin Policy bypass | Identified cloaked trackers receiving IDs set by distinct third-party domains. | cloaked trackers receiving cross-origin IDs | 119 cloaked trackers and 91 distinct third-party cookie-setting domains
browser-feature sharing | Searched SST request URLs, POST data, and script calls for fingerprinting features. | share of SST domains | 6 of 32 SST domains (18.75%)
tracker blocking evasion | Checked shifted trackers against combined dated Disconnect lists. | shifted trackers listed by Disconnect | 40 of 69 trackers (57.97%)
cookie-purpose distribution | Looked up cookie names in Cookiepedia. | classified SST cookies categorized as targeting/advertising | 35%
crawlConfig: {"statefulness":"stateless","browsers":["Firefox"],"headless":"not-stated","consentAction":"no-interaction","interactionDepth":"landing-page-only","subpagesPerSite":null,"authentication":"none","languages":[],"repeatVisits":null,"evidence":{"quote":"we visit the home page of the website X and keep the page open until all content is loaded to capture all cookies stored","section":"results"}}
population : [{"sourceList":"Alexa top 10,000","listVersion":"2021","n":10000,"unit":"websites","samplingMethod":"top-n","evidence":{"quote":"We used the OpenWPM platform [75] with the Firefox browser to perform three passive web measurement crawls of the Alexa top 10,000 websites [13]","section":"evaluation"}}]
legal : [{"law":"GDPR","jurisdiction":"EU","whatWasAssessed":"Lawfulness, consent, transparency, and personal-data processing","foundViolations":"yes","usedOrMentioned":"used","evidence":{"quote":"Together with a legal scholar, we also assessed the compliance of SST and noted that SST infringes both the GDPR and the ePD.","section":"conclusion"}},{"law":"ePrivacy Directive","jurisdiction":"EU","whatWasAssessed":"Consent for cookies and tracking technologies","foundViolations":"yes","usedOrMentioned":"used","evidence":{"quote":"websites including SST subdomains must ask user's consent for the deposit of cookies and other tracking technologies for advertising purposes.","section":"discussion"}}]
artifacts : {"links":[{"url":"https://github.com/mozilla/OpenWPM","kind":"source-code","what":"OpenWPM crawler platform","belongsToAuthors":false},{"url":"https://www.dropbox.com/scl/fo/s83a6mxo340ommat2asau/h?rlkey=svro2emp1fyv1d3pcrzwuqk75&dl=0","kind":"dataset","what":"Alexa top-10,000 websites","belongsToAuthors":false},{"url":"https://cookiepedia.co.uk/classify-cookies","kind":"other","what":"Cookie-purpose database","belongsToAuthors":false},{"url":"https://sitelookup.mcafee.com/","kind":"web-demo-or-service","what":"Website categorization service","belongsToAuthors":false},{"url":"https://disconnect.me/","kind":"other","what":"Disconnect tracker list","belongsToAuthors":false},{"url":"https://pypi.org/project/whois/","kind":"other","what":"WHOIS Python library","belongsToAuthors":false},{"url":"https://xlinux.nist.gov/dads/HTML/ratcliffObershelp.html","kind":"other","what":"Ratcliff-Obershelp algorithm","belongsToAuthors":false}],"codeUrl":null,"dataUrl":null,"availability":"none-mentioned","badge":null,"evidence":{"quote":"We used the OpenWPM platform [75] with the Firefox browser to perform three passive web measurement crawls","section":"evaluation"}}
-- PETS 2024: Client-side and Server-side Tracking on Meta: Effectiveness and Accuracy
Meta user-profile matching effectiveness | Measured Meta ad-campaign reach for tracker-specific remarketing audiences. | reach effectiveness | Conversions API matched 34%–51%; Meta Pixel matched 42%–61%
User-matching accuracy | Compared overlap between recruiting and tracking Facebook ad campaigns. | campaign-audience overlap | Pixel accuracy was 100%; CAPI accuracy was 60%–65%
Browser privacy restrictions | Compared Pixel and CAPI reach on Safari without third-party cookies. | reach effectiveness | Safari Pixel ranged from 0% to 51%; CAPI ranged from 0% to 19%
Filter-list blocking | Monitored blocked network calls and cookies across endpoint configurations. | blocked requests and cookie transmission | Pixel calls were blocked; CAPI requests were unaffected
VPN effects on server-side tracking | Replaced authentic participant IPs with known VPN-server IP addresses. | reach effectiveness | CAPI achieved 27% reach effectiveness with VPN-linked IP addresses
User-agent spoofing | Compared CAPI events containing authentic versus randomly generated historical user agents. | reach effectiveness | Authentic and spoofed user agents each achieved 44%
First-party cookie effects | Compared CAPI events with and without fbp or fbc values. | reach effectiveness and audience overlap | fbp did not improve effectiveness; fbc increased effectiveness from 20% to 23%
Shared tracking endpoints | Compared isolated versus common Meta event endpoints. | matching accuracy | Pixel accuracy decreased from 100% to 81% with a common endpoint
crawlConfig: null
population : [{"sourceList":"Prolific","listVersion":null,"n":2400,"unit":"human-participants","samplingMethod":"convenience","evidence":{"quote":"We recruited 2400 users across four experiments performed between April and October 2023.","section":"evaluation"}},{"sourceList":"Prolific","listVersion":null,"n":725,"unit":"human-participants","samplingMethod":"convenience","evidence":{"quote":"We recruited 725 users across three experiments performed between April and October 2023.","section":"evaluation"}},{"sourceList":"Prolific","listVersion":null,"n":1350,"unit":"human-participants","samplingMethod":"convenience","evidence":{"quote":"We recruited 1350 users across four campaigns between March and October 2023.","section":"evaluation"}},{"sourceList":"Prolific","listVersion":null,"n":500,"unit":"human-participants","samplingMethod":"convenience","evidence":{"quote":"We recruited 500 users, and the experiment was performed in November 2023.","section":"evaluation"}},{"sourceList":"Prolific","listVersion":null,"n":250,"unit":"human-participants","samplingMethod":"convenience","evidence":{"quote":"We directed traffic from 250 users on Prolific.","section":"evaluation"}},{"sourceList":"Facebook advertising campaign","listVersion":null,"n":2791,"unit":"human-participants","samplingMethod":"convenience","evidence":{"quote":"A total of 2,791 users consented and took part in this experiment.","section":"methodology"}}]
legal : []
artifacts : {"links":[{"url":"https://developers.facebook.com/docs/business-sdk/getting-started/","kind":"other","what":"Meta Business SDK documentation","belongsToAuthors":false},{"url":"https://prolific.com/","kind":"other","what":"Participant crowdsourcing platform","belongsToAuthors":false},{"url":"https://ipinfo.io/","kind":"web-demo-or-service","what":"IP geolocation and VPN data service","belongsToAuthors":false},{"url":"https://vpnapi.io/","kind":"web-demo-or-service","what":"VPN and proxy detection service","belongsToAuthors":false},{"url":"https://easylist.to/","kind":"other","what":"EasyList filter lists","belongsToAuthors":false},{"url":"https://www.ip2location.io/","kind":"web-demo-or-service","what":"IP geolocation API","belongsToAuthors":false},{"url":"https://www.ipqualityscore.com","kind":"web-demo-or-service","what":"IP and VPN detection service","belongsToAuthors":false}],"codeUrl":null,"dataUrl":null,"availability":"none-mentioned","badge":null,"evidence":{"quote":"This method had the lowest incidence of false negatives among the approaches we tested.","section":"methodology"}}
=== PASS A — detection tuples anywhere in the corpus mentioning CNAME / server-side ===
papers matched by the wide sweep: 63 of 5859 with a structured extraction record
of which web-tracking relevant: 7
of which unrelated (the residue): 56
-- web-tracking relevant --
2012 NDSS Ghost Domain Names: Revoked Yet Still Resolvable
Resolver cache-lifetime behavior | Tracked TTL variations of the www.google.com CNAME record | distribution of resolver behavior types | over 65% stable; over 85% of failed resolvers were proxy or unstable
2021 PETS The CNAME of the Game: Large-scale Analysis of DNS-based Tracking Evasion
CNAME-based tracking prevalence | Filtered same-site non-origin requests using CNAME chains and signatures. | share of websites | 9.98% of the top 10,000 websites employed at least one CNAME-based tracker.
CNAME-tracking growth | Applied an iterative IP-and-signature method across monthly HTTP Archive data. | relative increase in publishers | 21% growth over 22 months, compared with −3% and −8% for comparison tracker groups.
Cookie leaks in HTTP headers | Excluded tracker-set, session, short, and non-identifying cookies; traced setters. | share of sites with leaks | 95% of sites with an identified CNAME tracker had one or more cookie leaks.
Insecure CNAME tracking requests | Inspected HTTP Archive request protocols and active content. | number of websites | 19 websites requested active content over HTTP; 72 sent analytics over HTTP from HTTPS pages.
2023 USENIX Cookie Crumbles: Breaking and Fixing Web Session Integrity
server-side cookie-parser inconsistencies | Reflector programs plus fuzzed Cookie-header variations. | parser behaviors and vulnerabilities | -
2024 PETS The Devil is in the Details: Detection, Measurement and Lawfulness of Server-Side Tracking on the Web
IP cloaking | Compared A/AAAA/CNAME organizations with visited-site organization. | share of visited websites | 996 cloaked subdomains on 767 websites (10.41%)
server-side tracking | Matched emerging cloaked trackers and shifted parameters/cookies across 2020–2022 crawls. | websites with SST | 28 of 7,367 visited websites
2024 PETS Client-side and Server-side Tracking on Meta: Effectiveness and Accuracy
VPN effects on server-side tracking | Replaced authentic participant IPs with known VPN-server IP addresses. | reach effectiveness | CAPI achieved 27% reach effectiveness with VPN-linked IP addresses
2024 PETS Opted Out, Yet Tracked: Are Regulations Enough to Protect Your Privacy?
Server-side data sharing | Analyzed bids from advertisers not directly receiving leaked interests. | mean bid CPM relative to control | Advertisers not explicitly leaked user interests often still bid higher than control.
2022 IEEE-SP Journey to the Center of the Cookie Ecosystem: Unraveling Actors' Roles and Relationships.
CNAME cloaking | Detected aliases and matched them against a tracker blocklist | domains re-attributed | -
-- residue: matched "server-side"/"CNAME" but not about web tracking --
2011 CCS WAPTEC: whitebox analysis of web applications for parameter tampering exploit construction.
negative parameter tampering | Analyze server-side branches and data/control dependencies for hidden parameters | confirmed exploits | A privilege-escalation exploit in dcpportal
2012 CCS Collaborative TCP sequence number inference attack: how to crack sequence number under a second.
Windows Live Messenger command injection | Server-side TCP injection using inferred sequence and ACK numbers | demonstrated command effects | Injected commands added or removed friends, changed statuses, and sent messages
2012 IMC Beyond friendship: modeling user activity graphs on social network-based gifting applications.
Facebook gifting application activity | Server-side collection of anonymized sender, receiver, and timestamp records. | number of activities | iHeart 2.2 billion; iSmile 1.5 billion; Hugged 1.6 billion activities
2012 IMC Content delivery and the natural evolution of DNS: remote dns trends, performance issues and alternative solutions.
CDN use by popular websites | Downloaded index pages and linked objects; inspected redirects and CNAMEs | share of top sites and pageviews | Over 70% of the top 1,000 sites and 89% of their pageviews
2014 CCS Security Analysis of the Estonian Internet Voting System.
server-side vote alteration | Tainted installation ISO and counting-server malware | fraction of votes altered | 100% of votes in the demonstration
2014 IEEE-SP When HTTPS Meets CDN: A Case of Authentication in Delegated Service.
DNS-CDN deployment | Probed Alexa domains for CNAME or NS chains to surveyed CDN providers. | number of DNS-CDN-enabled sites | 14,199 DNS-CDN-enabled sites; 10,721 reachable with HTTPS
2015 NDSS EKHUNTER: A Counter-Offensive Toolkit for Exploit Kit Infiltration
Server-side exploit-kit vulnerabilities | Combined AC-VD, SQLI-VD, and MTS-VD static analyses | number of vulnerabilities and vulnerable kits | Over 180 vulnerabilities across 16 of 30 exploit kits
2015 IMC From .academy to .zone: An Analysis of the New TLD Land Rush.
Defensive redirects | Detected CNAME, browser-level, and single-large-frame redirects | share of domains | 236,380 off-domain redirects, or 6.5%
2016 IMC Measuring the Adoption of DDoS Protection Services.
DDoS protection service adoption | Counted domains referencing provider ASNs, CNAMEs, or NS records daily. | relative adoption growth | 1.24× over 1.5 years
DNS traffic-diversion method | Compared DPS references in CNAME, NS, and IP-address ASN records. | share of DPS-using domains by method | CloudFlare authoritative name servers used by about 75% of CloudFlare-using domains
2016 IMC Performance Characterization of a Commercial Video Streaming Service.
Client download-stack buffering | Outlier detection using first-byte delay, instantaneous throughput, and server-side TCP estimates. | share of chunks and sessions | 0.32% of chunks and 3.1% of sessions had detected download-stack buffering.
2016 WWW No Honor Among Thieves: A Large-Scale Analysis of Malicious Web Shells.
Server-side homephoning | Packet-trace analysis after instrumented honeypot execution. | share of dynamic-analysis shells | 4.8% initiated connections to 34 remote IP addresses.
2018 IMC A Long Way to the Top: Significance, Structure, and Stability of Internet Top Lists.
IPv6 adoption | Count routed IPv6 addresses in AAAA records and CNAME chains | share of domains IPv6-enabled | top lists had 11–13% IPv6 enablement versus 4% generally
CDN prevalence | Resolve domains and match CNAMEs against CDN patterns | share of domains using CDNs | all Top 1M lists exceeded the general population by at least a factor of two
2019 CCS MalMax: Multi-Aspect Execution for Automated Dynamic Web Server Malware Analysis.
PHP server-side malware | MalMax dynamic multi-path execution with PhpMalScan heuristics | detected samples | 1,485 malware samples not detected by VirusTotal
2019 IEEE-SP Does Certificate Transparency Break the Web? Measuring Adoption and Error Rate.
Server-side SCT delivery | Compare SCT delivery sources in Chrome and website datasets. | share of SCTs or compliant websites using TLS extension | 47.97% of Chrome-observed SCTs came from TLS extensions; 50% of Alexa CT-compliant websites used them
2019 IEEE-SP PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing Blacklists.
cloaking effectiveness | Applied six server-side or JavaScript HTTP request filters. | reduction in blacklisting likelihood | Geolocation, device-type, and JavaScript cloaking reduced blacklisting likelihood by over 55% on average.
2019 IMC A First Look at the Crypto-Mining Malware Ecosystem: A Decade of Unrestricted Wealth.
domain aliases | DNS and historical DNS resolution of extracted domains | number of CNAMEs | 215 different CNAMEs
2019 IMC No More Chasing Waterfalls: A Measurement Study of the Header Bidding Ad-Ecosystem.
HB implementation facets | Inspect response parameters and browser events | share of HB websites by facet | 48% server-side, 34.7% hybrid, 17.3% client-side
Ad-slot bid prices | Extract transparent prices and infer server-side prices heuristically | CPM bid price | 300x250 median cost 0.031 CPM
2019 NDSS understanding-open-ports-in-android-applications-discovery-diagnosis-and-security-assessment
Android TCP/UDP open ports | On-device monitoring of /proc/net/tcp, tcp6, udp, and udp6; server-side clustering | share of monitored apps | 15.3% of 3,216 apps had TCP open ports
2019 USENIX Less is More: Quantifying the Security Benefits of Debloating Web Applications
server-side code execution | XDebug dynamic code-coverage profiling during stimulated requests | covered files, functions, and lines | -
2020 IMC Analyzing Third Party Service Dependencies in Modern Web Services: Have We Learned from the Mirai-Dyn Incident?
third-party CDN dependency | Rendered landing pages, extracted internal resources, queried CNAMEs, and matched CDN providers. | share of websites using CDNs | 97.6% of websites using CDNs use a third-party CDN
2020 IEEE-SP TextExerciser: Feedback-driven Text Input Exercising for Android Applications.
Client- versus server-side validation | Repeat app interaction with network connections enabled and disabled. | share of hints displayed offline | 86 of 649 hints were purely client-side; 563 required server support
2020 NDSS Deceptive Previews: A Study of the Link Preview Trustworthiness in Social Platforms
countermeasure bypass | Server-side and client-side redirections | successful bypasses | Twitter and LinkedIn defenses were bypassed
2020 USENIX PhishTime: Continuous Longitudinal Measurement of the Effectiveness of Anti-phishing Blacklists
Server-side cloaking | Compared cloud crawler requests with mobile-IP and anonymous-VPN requests. | share of evasive websites | at least 146 of 183 websites used server-side cloaking
2020 USENIX The Ballot is Busted Before the Blockchain: A Security Analysis of Voatz, the First Internet Voting Application Used in U.S. Federal Elections
vote alteration | Modified the client and analyzed server-side protocol capabilities. | - | Rooted-device and API-server attackers can alter votes.
2020 WWW Apophanies or Epiphanies? How Crawlers Impact Our Understanding of the Web.
server-side blocking | Matched HTTP errors, CAPTCHAs, browser errors, geo-blocking, and IP-abuse block pages. | successful page-load fraction and block-category rates | Over 16% variation in successful page loads; over 160 sites showed blocking
2021 USENIX Blind In/On-Path Attacks and Applications to VPNs
Server-side DNS hijacking | UDP port inference followed by transaction-ID brute forcing | successful injection rate | 75.3% with 15-second timeout; 48.1% with 10-second; 11.6% with 5-second
2021 USENIX Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNS
DNS cache poisoning | Injected CNAME records and queried for poisoned cached records. | share and count of open resolvers | 8.0% (105,854) of open resolvers were vulnerable to cache poisoning via injection payloads.
2021 USENIX Security Analysis of the Democracy Live Online Voting System
Client-server data transmission | Reverse-engineered JavaScript and API calls using a compatible local server. | qualitative security and privacy analysis | Identity and ballot selections were sent to Democracy Live for server-side ballot generation.
2020 IEEE-SP Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwd.
authentication bypasses | Black-box tests of invalid scalars, invalid elements, and reflection handling | implementations affected | All tested client and server-side EAP-pwd implementations were vulnerable to the invalid-curve attack
2022 IMC ZDNS: a fast DNS toolkit for internet measurement.
CAA record deployment | Querying CAA records for 93M base domains and following CNAMEs | share of NOERROR domains returning CAA records | 1.08M domains (1.69%) respond to CAA queries
2022 PETS Setting the Bar Low: Are Websites Complying With the Minimum Requirements of the CCPA?
DNSMPI geofencing | Compare rendered snapshots and server responses from Boston and California. | share among 12,222 DNSMPI websites | 2,101 (17%) exhibit dynamic link visibility; 62% client-side and 38% server-side
2023 CCS Are we there yet? An Industrial Viewpoint on Provenance-based Endpoint Detection and Response Tools.
server-side P-EDR memory consumption | Ran HOLMES, ProvDetector, and UNICORN on five datasets. | MB per host | None of the three systems met the <20MB/host requirement.
2023 NDSS ReScan: A Middleware Framework for Realistic and Robust Black-box Web Application Scanning
server-side code coverage | Measured unique server-side lines executed using XDebug. | unique executed lines of code | Coverage improvement ranged from 3% to 935%, averaging 168%.
2023 PETS Heads in the Clouds? Measuring Universities’ Migration to Public Clouds: Implications for Privacy & Academic Freedom
University cloud infrastructure adoption | Matched A, AAAA, and CNAME records to cloud-provider IPs and hostnames | share of institutions | U.S. institutions using all three major operators rose from 30.38% to 87.31%
Cloud-hosted LMS | Matched CNAME targets against four LMS provider domains | share of institutions | 196 U.S. universities (75.38%) used cloud-hosted LMS in October 2022
2023 IMC Stale TLS Certificates: Investigating Precarious Third-Party Access to Valid TLS Keys.
managed-TLS departure | Compared consecutive daily Cloudflare NS and CNAME records. | stale certificates and effective second-level domains | 854K stale certificates representing 695K effective second-level domains over three months.
2024 CCS Collapse Like A House of Cards: Hacking Building Automation System Through Fuzzing.
BAS software and device vulnerabilities | BASE protocol-aware fuzzing with response and coverage monitoring | number of vulnerabilities discovered | 13 new vulnerabilities: 8 client-side and 5 server-side
Server crashes and denial of service | Monitoring device responses and liveness after fuzzing | number of server-side vulnerabilities | 5 server-side vulnerabilities
2024 NDSS dRR: A Decentralized, Scalable, and Auditable Architecture for RPKI Repository
CDN hosting of publication points | Analyzed DNS, CNAMEs, HTTPS headers, IPs, and geographic latency | share of independent PPs | 8 of 61 PPs were hosted in CDNs
2024 CCS Poster: Whether We Are Good Enough to Detect Server-Side Request Forgeries in PHP-native Applications?
Server-side request forgery vulnerabilities | Static call-graph construction and SSRF-specific taint analysis | number of detected vulnerabilities | 24 SSRF vulnerabilities in 13 applications: 20 known and 4 new
2024 NDSS Understanding the Implementation and Security Implications of Protective DNS Services
Dangling cloud DNS resources | Matched IPs to cloud ASNs/PTRs, tested reachability and ports, and checked CNAME registration. | affected PDNS resolvers | 7 obsolete cloud IPs affected 21 PDNSes; one seizable CNAME affected 5
DNS rewriting policy distribution | Categorized returned secure IPs, special-use IPs, CNAMEs, empty data, and error codes. | share of identified PDNSes | Secure IP rewriting used by 56.45% of PDNSes
2024 PETS A Black-Box Privacy Analysis of Messaging Service Providers' Chat Message Processing
server-side message analysis | Monitored requests to unique URLs embedded in chat messages. | share of messaging services | 34% of messaging services conducted server-side URL access
client-side token leakage | Scanned intercepted HTTP(S), WebSocket, and WebRTC traffic for token encodings. | share of analyzed messengers with CNAME chains | CNAME redirect chains were recognized for 60% of analyzed messengers
2024 USENIX A Mixed-Methods Study on User Experiences and Challenges of Recovery Codes for an End-to-End Encrypted Service
Recovery-code dialog interactions | Opt-in server-side logging of dialog button interactions. | number of users and interactions | 32,784 opened the code popup; 7,546 copied and 1,873 printed it
2024 USENIX Atropos: Effective Fuzzing of Web Applications for Server-Side Vulnerabilities
server-side PHP vulnerabilities | Eight instrumented sink-specific bug oracles with fuzzing feedback | true positives, false positives, precision, and true positive rate | Seven previously unknown vulnerabilities in real-world applications; 49 of 52 benchmark vulnerabilities in the 40-core configuration
2024 WWW Cold Start or Hot Start? Robust Slow Start in Congestion Control with A Priori Knowledge for Mobile Web Services.
Application-limit state | Measured unsent server-side bytes during replayed application traffic. | share of time without application data | 14.46% of the time there was no application data waiting to be sent
2025 NDSS EvoCrawl: Exploring Web Application Code and State using Evolutionary Search
server-side code coverage | Coverage instrumentation for PHP and Rails applications | lines of code covered | 59% average increase over the next-best scanner
2025 USENIX Big Help or Big Brother? Auditing Tracking, Profiling, and Personalization in Generative AI Assistants
server-side response generation | Network traffic analysis identified response-generation architecture. | share of assistants | 8 out of 9 extensions operated server-side.
2025 WWW Beyond Visual Confusion: Understanding How Inconsistencies in ENS Normalization Facilitate Homoglyph Attacks.
Server-side normalization behavior | Uses four to thirteen library-probing requests and latency-based remote API identification. | minimum requests required | server-side libraries identified with as few as 4 and up to 13 requests
2026 USENIX DaLens: Charting DNS Self-Amplification Threats at Large
amplification primitive thresholds | Bounded binary search over controlled DNS resolution configurations | threshold for NS fetch, NS chain, CNAME chain, and DDLG | Most resolvers tolerated deep or wide configurations
2026 PETS Waterfall: A Capsule-Based Framework for Evaluating Traffic Watermarking in Anonymity Systems
watermark removal | Constant 20 ms server-side pacing of buffered RTP packets. | TPR, FPR1, FPR2 | Detection converged to near-chance performance under the pacing defense.
mixed-background false positives | Detectors ran over concurrent browsing, downloads, and uploads routed through Tor. | FPR1 | Server-side proxy FPR1 reached 1.28% for 0.5 s intervals among viable flows.
2026 NDSS NetRadar: Enabling Robust Carpet Bombing DDoS Detection
carpet bombing DDoS | Gateway analysis of traffic and server-side features using NetRadar | packet-level Accuracy, Precision, and Recall | NetRadar achieves over 94% accuracy in all carpet bombing detection scenarios
runtime feature mismatch | Randomly erasing server-side features during training and testing | F1-score and recall | F1-score over 0.9 across tested victim-server counts
2025 CCS Exploiting the Shared Storage API.
network timing covert channel | Delayed worklet execution and server-side request timing | bits leaked per page | 33-bit identifiers feasible with delays of 0.36–1.82 seconds
2025 USENIX XSSky: Detecting XSS Vulnerabilities through Local Path-Persistent Fuzzing
reflected server-side XSS | Static source-sink analysis followed by path-persistent fuzzing and browser-popup oracle | confirmed vulnerabilities | 60 previously unknown vulnerabilities across 20 PHP applications
2017 IEEE-SP SoK: Exploiting Network Printers.
PostScript website information disclosure | Malicious PostScript files listing server-side files | share of evaluated websites | 8 of 12 websites
2025 NDSS Automatic Insecurity: Exploring Email Auto-configuration in the Wild
Server-side security defects | Parsed configuration files and checked redirects, parameters, priorities, and consistency. | share of supported domains | 49,013 domains had security defects; 43,566 Type-I and 11,824 Type-II defects.
2026 PETS Dead Domains, Living Data: A Privacy Risk Analysis of Domain Lifecycle in Android Apps
dangling CNAMEs | Automated dangling-resource detection during DNS analysis | share of late-renewed domains with dangling CNAMEs | 218 of 861 late-renewed domains (25.3%)
2024 IEEE-SP Where Are the Red Lines? Towards Ethical Server-Side Scans in Security and Privacy Research.
Legal and ethical boundaries of server-side scanning | Semi-structured interviews using five scenario vignettes. | qualitative themes and assessments | -
Operator comfort with server-side scans | Online survey using five-point Likert-scale scenario assessments. | percentage of 119 respondents | 57.9% were comfortable or somewhat comfortable with 3S generally
2021 IEEE-SP Black Widow: Blackbox Data-driven Web Scanning.
server-side code coverage | Xdebug records executed PHP lines for each request | number of unique executed lines | Black Widow had the highest coverage on 9 out of 10 applications
=== PASS B — full-text probe: pattern definitions ===
sst_term /server[- ]?side (?:tracking|tagging)/i
sgtm /\bsGTM\b|server[- ]?side (?:google )?tag manager|server[- ]?side google analytics|\bsGA\b/i
capi /conversions? api|\bCAPI\b|events api/i
capi_product /Conversions? API/
moved_server /(?:moved?|shift(?:ed|ing)?|relocat\w+|migrat\w+|rout\w+|forward\w+|proxy|proxied|proxying)[^.]{0,60}(?:to|on|onto|via|through) the server[- ]?side|server[- ]?to[- ]?server (?:tracking|reporting|communication|data shar)/i
cname_cloak /CNAME[- ]?(?:cloak\w*|based|tracking|redirection|redirect\w*|delegation)/i
cname_any /\bCNAME\b/i
first_party_proxy /reverse[- ]?prox\w+|first[- ]?party (?:prox\w+|cloak\w*)/i
measurement_protocol /measurement protocol/i
tag_manager_any /\b(?:google )?tag manager\b|\bGTM\b|gtag\.js/i
=== PASS B — hits per probe, denominator = papers with a readable paper.cols.txt ===
papers scanned: 5869
sst_term 11 0.2%
sgtm 2 0.0%
capi 16 0.3%
capi_product 4 0.1%
moved_server 18 0.3%
cname_cloak 46 0.8%
cname_any 151 2.6%
first_party_proxy 64 1.1%
measurement_protocol 7 0.1%
tag_manager_any 48 0.8%
=== PASS B — sst_term OR sgtm OR capi, by year (2026 is provisional: see literature:corpus) ===
2010 1 of 118 scanned 0.8%
2011 0 of 116 scanned 0.0%
2012 1 of 151 scanned 0.7%
2013 0 of 125 scanned 0.0%
2014 0 of 165 scanned 0.0%
2015 0 of 190 scanned 0.0%
2016 1 of 182 scanned 0.5%
2017 0 of 232 scanned 0.0%
2018 0 of 254 scanned 0.0%
2019 1 of 402 scanned 0.2%
2020 1 of 402 scanned 0.2%
2021 2 of 380 scanned 0.5%
2022 3 of 546 scanned 0.5%
2023 4 of 720 scanned 0.6%
2024 3 of 701 scanned 0.4%
2025 4 of 770 scanned 0.5%
2026 4 of 415 scanned 1.0%
=== PASS B — unions of the probes, because the page quotes them and they are not sums ===
sst_term alone : 11
sst_term OR sgtm OR capi : 25
moved_server total / adds new to that union : 18 / 16
sst_term OR sgtm OR capi OR moved_server : 41
The probes overlap, so these are unions and never sums. Denominator: 5869
=== PASS B — the capi probe split by width, because the wide one is mostly noise ===
wide /conversions? api|\bCAPI\b|events api/i : 16 papers
narrow /Conversions? API/ : 4 papers
-- narrow hits (the advertising product) --
2024 PETS client-side-and-server-side-tracking-on-meta-effectiveness-and-accuracy
2026 PETS a-year-under-the-dsa-ad-transparencys-uneven-landscape
2026 PETS clicking-into-exposure-uncovering-privacy-risks-of-google-click-identifier-in-yo
2026 USENIX bridges-to-self-silent-web-to-app-tracking-on-mobile-via-localhost
-- wide-only hits (the residue: GitHub/Android Events APIs, CryptoAPI, "social capi-talists") --
2012 WWW understanding-and-combating-link-farming-in-the-twitter-social-network
2016 USENIX the-million-key-question-investigating-the-origins-of-rsa-public-keys
2019 NDSS how-bad-can-it-git-characterizing-secret-leakage-in-public-github-repositories
2021 NDSS preventing-and-detecting-state-inference-attacks-on-android
2021 USENIX understanding-malicious-cross-library-data-harvesting-on-android
2022 USENIX characterizing-the-security-of-github-ci-workflows
2023 USENIX bilingual-problems-studying-the-security-risks-incurred-by-native-extensions-in
2023 USENIX differential-testing-of-cross-deep-learning-framework-apis-revealing-inconsisten
2023 USENIX pool-party-exploiting-browser-resource-pools-for-web-tracking
2024 USENIX ihunter-hunting-privacy-violations-at-scale-in-the-software-supply-chain-on-ios
2025 PETS why-am-i-seeing-double-an-investigation-of-device-management-flaws-in-voice-assi
2025 USENIX prsa-prompt-stealing-attacks-against-real-world-prompt-services
=== PASS B — the sst_term papers, listed in full (this is the whole population) ===
2010 USENIX an-analysis-of-private-browsing-modes-in-modern-browsers
2020 PETS inferring-tracker-advertiser-relationships-in-the-online-advertising-ecosystem-u
2022 PETS atom-ad-network-tomography
2022 PETS on-dark-patterns-and-manipulation-of-website-publishers-by-cmps
2024 PETS client-side-and-server-side-tracking-on-meta-effectiveness-and-accuracy
2024 PETS the-devil-is-in-the-details-detection-measurement-and-lawfulness-of-server-side
2025 CCS piixel-leaks-passive-identification-of-personally-identifiable-information-leaka
2025 IMC cookieguard-characterizing-and-isolating-the-first-party-cookie-jar
2026 PETS clicking-into-exposure-uncovering-privacy-risks-of-google-click-identifier-in-yo
2026 USENIX bridges-to-self-silent-web-to-app-tracking-on-mobile-via-localhost
2026 WWW tgnn-enhancing-pixel-tracking-detection-via-llm-driven-annotation-and-gat-powere
=== PASS B — the cname_cloak papers, listed in full (the neighbouring technique) ===
2013 WWW the-anatomy-of-ldns-clusters-findings-and-implications-for-web-content-delivery
2014 IEEE-SP when-https-meets-cdn-a-case-of-authentication-in-delegated-service
2016 IMC measuring-the-adoption-of-ddos-protection-services
2017 CCS poster-x-ray-your-dns
2018 IMC dissecting-apples-meta-cdn-during-an-ios-update
2018 USENIX end-users-get-maneuvered-empirical-analysis-of-redirection-hijacking-in-content
2019 IMC a-look-at-the-ecs-behavior-of-dns-resolvers
2019 WWW pythia-a-framework-for-the-automated-analysis-of-web-hosting-environments
2020 CCS dns-cache-poisoning-attack-reloaded-revolutions-with-side-channels
2020 IMC analyzing-third-party-service-dependencies-in-modern-web-services-have-we-learne
2021 IMC trackersift-untangling-mixed-tracking-and-functional-web-resources
2021 NDSS cv-inspector-towards-automating-detection-of-adblock-circumvention
2021 PETS privacy-preference-signals-past-present-and-future
2021 PETS the-cname-of-the-game-large-scale-analysis-of-dns-based-tracking-evasion
2021 USENIX injection-attacks-reloaded-tunnelling-malicious-payloads-over-dns
2022 IEEE-SP journey-to-the-center-of-the-cookie-ecosystem-unraveling-actors-roles-and-relati
2022 IEEE-SP towards-automated-auditing-for-account-and-session-management-flaws-in-single-si
2022 IMC measuring-uid-smuggling-in-the-wild
2022 PETS on-dark-patterns-and-manipulation-of-website-publishers-by-cmps
2022 USENIX khaleesi-breaker-of-advertising-and-tracking-request-chains
2022 USENIX leaky-forms-a-study-of-email-and-password-exfiltration-before-form-submission
2022 USENIX webgraph-capturing-advertising-and-tracking-information-flows-for-robust-blockin
2022 WWW investigating-advertisers-domain-changing-behaviors-and-their-impacts-on-ad-bloc
2022 WWW measuring-the-privacy-vs-compatibility-trade-off-in-preventing-third-party-state
2023 CCS cookiegraph-understanding-and-detecting-first-party-tracking-cookies
2023 CCS read-between-the-lines-detecting-tracking-javascript-with-bytecode-classificatio
2023 IMC stale-tls-certificates-investigating-precarious-third-party-access-to-valid-tls
2023 NDSS navigating-murky-waters-automated-browser-feature-testing-for-uncovering-tracking-vectors
2023 USENIX defining-broken-user-experiences-and-remediation-tactics-when-ad-blocking-or-tra
2024 CCS blocking-tracking-javascript-at-the-function-granularity
2024 IMC of-choices-and-control-a-comparative-analysis-of-government-hosting
2024 PETS a-black-box-privacy-analysis-of-messaging-service-providers-chat-message-process
2024 PETS opted-out-yet-tracked-are-regulations-enough-to-protect-your-privacy
2024 PETS the-devil-is-in-the-details-detection-measurement-and-lawfulness-of-server-side
2024 USENIX purl-safe-and-effective-sanitization-of-link-decoration
2025 CCS byte-by-byte-unmasking-browser-fingerprinting-at-the-function-level-using-v8-byt
2025 CCS piixel-leaks-passive-identification-of-personally-identifiable-information-leaka
2025 IEEE-SP only-as-strong-as-the-weakest-link-on-the-security-of-brokered-single-sign-on-on
2025 IMC canvassing-the-fingerprinters-characterizing-canvas-fingerprinting-use-across-th
2025 IMC cookieguard-characterizing-and-isolating-the-first-party-cookie-jar
2025 PETS beyond-the-request-harnessing-http-response-headers-for-cross-browser-web-tracke
2025 PETS tracking-without-borders-studying-the-role-of-webviews-in-bridging-mobile-and-we
2026 NDSS crack-in-the-armor-underlying-infrastructure-threats-to-rpki-publication-point-reachability
2026 PETS clicking-into-exposure-uncovering-privacy-risks-of-google-click-identifier-in-yo
2026 PETS cryptographically-secured-domain-validation
2026 WWW tracking-the-stray-sheep-understanding-dns-response-manipulation-in-the-wild
=== PASS B — cname_cloak by year ===
2010 0 of 118
2011 0 of 116
2012 0 of 151
2013 1 of 125
2014 1 of 165
2015 0 of 190
2016 1 of 182
2017 1 of 232
2018 2 of 254
2019 2 of 402
2020 2 of 402
2021 5 of 380
2022 9 of 546
2023 5 of 720
2024 6 of 701
2025 7 of 770
2026 4 of 415
=== PASS B — residue: probe hits that are NOT about web tracking ===
cname_any minus cname_cloak is printed here so the part this page does not classify stays visible.
papers: 105
2010 IMC comparing-dns-resolvers-in-the-wild
2010 IMC improving-content-delivery-using-provider-aided-distance-information
2010 IMC netalyzr-illuminating-the-edge-network
2010 IMC youtube-traffic-dynamics-and-its-interplay-with-a-tier-1-isp-an-isp-perspective
2011 IEEE-SP click-trajectories-end-to-end-analysis-of-the-spam-value-chain
2011 IMC web-content-cartography
2012 IMC content-delivery-and-the-natural-evolution-of-dns-remote-dns-trends-performance
2012 NDSS ghost-domain-names-revoked-yet-still-resolvable
2013 NDSS the-core-of-the-matter-analyzing-malicious-traffic-in-cellular-carriers
2013 USENIX practical-comprehensive-bounds-on-surreptitious-communication-over-dns
2014 CCS poster-blind-separation-of-benign-and-malicious-events-to-enable-accurate-malwar
2014 IMC dnssec-and-its-potential-for-ddos-attacks-a-comprehensive-measurement-study
2014 USENIX brahmastra-driving-apps-to-test-the-security-of-third-party-components
2014 USENIX on-the-feasibility-of-large-scale-infections-of-ios-devices
2014 USENIX the-long-taile-of-typosquatting-domain-names
2014 USENIX understanding-the-dark-side-of-domain-parking
2015 IMC from-academy-to-zone-an-analysis-of-the-new-tld-land-rush
2016 IMC zone-poisoning-the-how-and-where-of-non-secure-dns-dynamic-updates
2017 IMC millions-of-targets-under-attack-a-macroscopic-characterization-of-the-dos-ecosy
2017 USENIX global-measurement-of-dns-manipulation
2017 WWW who-controls-the-internet-analyzing-global-threats-using-property-graph-traversa
2018 CCS domain-validation-for-mitm-resilient-pki
2018 IMC a-long-way-to-the-top-significance-structure-and-stability-of-internet-top-lists
2018 IMC is-the-web-ready-for-ocsp-must-staple
2018 IMC ldplayer-dns-experimentation-at-scale
2018 IMC the-rise-of-certificate-transparency-and-its-implications-on-the-internet-ecosys
2018 USENIX who-is-answering-my-queries-understanding-and-characterizing-interception-of-the
2018 WWW panning-for-gold-com-understanding-the-dynamics-of-domain-dropcatching
2019 IEEE-SP phishfarm-a-scalable-framework-for-measuring-the-effectiveness-of-evasion-techni
2019 IMC a-first-look-at-the-crypto-mining-malware-ecosystem-a-decade-of-unrestricted-wea
2019 IMC cache-me-if-you-can-effects-of-dns-time-to-live
2019 IMC dns-observatory-the-big-picture-of-the-dns
2019 NDSS cracking-the-wall-of-confinement-understanding-and-analyzing-malicious-domain-take-downs
2019 NDSS dns-cache-based-user-tracking
2020 CCS zombie-awakening-stealthy-hijacking-of-active-domains-through-dns-hosting-referr
2020 IEEE-SP iclab-a-global-longitudinal-internet-censorship-measurement-platform
2020 IMC a-haystack-full-of-needles-scalable-detection-of-iot-devices-in-the-wild
2020 IMC out-of-sight-not-out-of-mind-a-user-view-on-the-criticality-of-the-submarine-cab
2020 NDSS a-practical-approach-for-taking-down-avalanche-botnets-under-real-world-constraints
2020 USENIX nxnsattack-recursive-dns-inefficiencies-and-vulnerabilities
2020 USENIX poison-over-troubled-forwarders-a-cache-poisoning-attack-targeting-dns-forwardin
2021 CCS lets-downgrade-lets-encrypt
2021 IEEE-SP cross-layer-attacks-and-how-to-use-them-for-dns-cache-poisoning-device-tracking
2021 NDSS favocado-fuzzing-the-binding-code-of-javascript-engines-using-semantically-correct-test-cases
2021 NDSS understanding-worldwide-private-information-collection-on-android
2021 USENIX accurately-measuring-global-risk-of-amplification-attacks-using-ampmap
2021 USENIX can-i-take-your-subdomain-exploring-same-site-attacks-in-the-modern-web
2021 USENIX domain-shadowing-leveraging-content-delivery-networks-for-robust-blocking-resist
2021 USENIX how-great-is-the-great-firewall-measuring-chinas-dns-censorship
2021 USENIX the-hijackers-guide-to-the-galaxy-off-path-taking-over-internet-resources
2021 WWW demystifying-illegal-mobile-gambling-apps
2022 CCS exposing-the-rat-in-the-tunnel-using-traffic-analysis-for-tor-based-malware-dete
2022 IEEE-SP measuring-and-mitigating-the-risk-of-ip-reuse-on-public-clouds
2022 IMC zdns-a-fast-dns-toolkit-for-internet-measurement
2022 NDSS auto-draft-206
2022 NDSS auto-draft-209
2022 USENIX xdri-attacks-and-how-to-enhance-resilience-of-residential-routers
2023 CCS silence-is-not-golden-disrupting-the-load-balancing-of-authoritative-dns-servers
2023 CCS tsuking-coordinating-dns-resolvers-and-queries-into-potent-dos-amplifiers
2023 CCS under-the-dark-a-systematical-study-of-stealthy-mining-pools-ab-use-in-the-wild
2023 IEEE-SP fashion-faux-pas-implicit-stylistic-fingerprints-for-bypassing-browsers-anti-fin
2023 IEEE-SP webspec-towards-machine-checked-analysis-of-browser-security-mechanisms
2023 IMC ecn-with-quic-challenges-in-the-wild
2023 IMC the-cloud-strikes-back-investigating-the-decentralization-of-ipfs
2023 PETS heads-in-the-clouds-measuring-universities-migration-to-public-clouds-implicatio
2023 USENIX nrdelegationattack-complexity-ddos-attack-on-dns-recursive-resolvers
2023 USENIX temporal-cdn-convex-lens-a-cdn-assisted-practical-pulsing-ddos-attack
2023 USENIX the-maginot-line-attacking-the-boundary-of-dns-caching-protection
2024 IEEE-SP dnsbomb-a-new-practical-and-powerful-pulsing-dos-attack-exploiting-dns-queries-a
2024 IEEE-SP practical-attacks-against-dns-reputation-systems
2024 IEEE-SP tudoor-attack-systematically-exploring-and-exploiting-logic-vulnerabilities-in-d
2024 IMC exploring-the-ecosystem-of-dns-https-resource-records-an-end-to-end-perspective
2024 IMC the-wisdom-of-the-measurement-crowd-building-the-internet-yellow-pages-a-knowled
2024 NDSS drr-a-decentralized-scalable-and-auditable-architecture-for-rpki-repository
2024 NDSS reqsminer-automated-discovery-of-cdn-forwarding-request-inconsistencies-and-dos-attacks-with-grammar-based-fuzzing
2024 NDSS understanding-the-implementation-and-security-implications-of-protective-dns-services
2024 USENIX camp-compositional-amplification-attacks-against-dns
2024 USENIX fledging-will-continue-until-privacy-improves-empirical-analysis-of-googles-priv
2024 USENIX loopy-hell-ow-infinite-traffic-loops-at-the-application-layer
2024 USENIX resolverfuzz-automated-discovery-of-dns-resolver-vulnerabilities-with-query-resp
2024 USENIX spf-beyond-the-standard-management-and-operational-challenges-in-practice-and-pr
2024 USENIX web-platform-threats-automated-detection-of-web-security-issues-with-wpt
2024 WWW discovering-and-measuring-cdns-prone-to-domain-fronting
2024 WWW investigations-of-top-level-domain-name-collisions-in-blockchain-naming-services
2024 WWW unfiltered-measuring-cloud-based-email-filtering-bypasses
2025 CCS rebirthday-attack-reviving-dns-cache-poisoning-with-the-birthday-paradox
2025 IEEE-SP predator-directed-web-application-fuzzing-for-efficient-vulnerability-validation
2025 IEEE-SP resolution-without-dissent-in-path-per-query-sanitization-to-defeat-surreptitiou
2025 IMC decoding-dnssec-errors-at-scale-an-automated-dnssec-error-resolution-framework-u
2025 IMC dive-into-the-cloud-unveiling-the-ab-usage-of-serverless-cloud-function-in-the-w
2025 IMC how-i-learned-to-stop-worrying-and-love-ipv6-measuring-the-internets-readiness-f
2025 IMC sibling-prefixes-identifying-similarities-in-ipv4-and-ipv6-prefixes
2025 IMC towards-a-non-binary-view-of-ipv6-adoption
2025 IMC unraveling-the-complexities-of-mta-sts-deployment-and-management-in-securing-ema
2025 NDSS cross-origin-web-attacks-via-http-2-server-push-and-signed-http-exchange
2025 NDSS misdirection-of-trust-demystifying-the-abuse-of-dedicated-url-shortening-service
2025 USENIX dns-flare-a-flush-reload-attack-on-dns-forwarders
2025 USENIX double-edged-shield-on-the-fingerprintability-of-customized-ad-blockers
2025 USENIX lost-in-the-mists-of-time-expirations-in-dns-footprints-of-mobile-apps
2025 USENIX your-shield-is-my-sword-a-persistent-denial-of-service-attack-via-the-reuse-of-u
2026 NDSS coordmail-exploiting-smtp-timeout-and-command-interaction-to-coordinate-email-middleware-for-convergence-amplification-attack
2026 NDSS loki-proactively-discovering-online-scams-by-mining-toxic-search-queries
2026 NDSS should-i-trust-you-rethinking-the-principle-of-zone-based-isolation-dns-bailiwick-checking
2026 PETS dead-domains-living-data-a-privacy-risk-analysis-of-domain-lifecycle-in-android
2026 USENIX dalens-charting-dns-self-amplification-threats-at-large
(per-paper probe matrix written to /tmp/sst_probe.json)