{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:55:19Z","timestamp":1783007719002,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/"}],"funder":[{"name":"Deutsche Forschungsgemeinschaft (DFG German Research Foundation) under Germany's Excellence Strategy - EXC 2092 CASA","award":["390781972"],"award-info":[{"award-number":["390781972"]}]},{"name":"Industrie 4.0 Recht-Testbed by Ministry of Economics and Technology (BMWi)","award":["13I40V002C"],"award-info":[{"award-number":["13I40V002C"]}]},{"name":"North-Rhine Westphalian Experts in Research on Digitalization (NERD II) by the state of North Rhine-Westfalia","award":["NERD II 005-2201-0014"],"award-info":[{"award-number":["NERD II 005-2201-0014"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3616598","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"2456-2470","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Finding All Cross-Site Needles in the DOM Stack: A Comprehensive Methodology for the Automatic XS-Leak Detection in Web Browsers"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2138-9989","authenticated-orcid":false,"given":"Dominik Trevor","family":"No\u00df","sequence":"first","affiliation":[{"name":"Ruhr University Bochum, Bochum, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-5676-5151","authenticated-orcid":false,"given":"Lukas","family":"Knittel","sequence":"additional","affiliation":[{"name":"Ruhr University Bo\u00adchum, Bochum, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4273-645X","authenticated-orcid":false,"given":"Christian","family":"Mainka","sequence":"additional","affiliation":[{"name":"Ruhr University Bochum, Bochum, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-1726-8099","authenticated-orcid":false,"given":"Marcus","family":"Niemietz","sequence":"additional","affiliation":[{"name":"Niederrhein University of Applied Sciences, Krefeld, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9315-7354","authenticated-orcid":false,"given":"J\u00f6rg","family":"Schwenk","sequence":"additional","affiliation":[{"name":"Ruhr University Bochum, Bochum, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2019. Attempt to plug an information leak represented by http status. https:\/\/github.com\/kohler\/hotcrp\/commit\/ 406a966aad00a762460fbc62cfb04a7532fc9fbd"},{"key":"e_1_3_2_1_2_1","unstructured":"2022. Fetch Standard CORS protocol and credentials. https:\/\/ fetch.spec.whatwg.org\/#cors-protocol-and-credentials"},{"key":"e_1_3_2_1_3_1","unstructured":"2022. The HTTP archive. https:\/\/httparchive.org\/"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4614-7163-9_315-1"},{"key":"e_1_3_2_1_5_1","volume-title":"Proceedings of the 18th Conference on USENIX Security Symposium","author":"Barth Adam","year":"2009","unstructured":"Adam Barth, Joel Weinberger, and Dawn Song. 2009. Cross-Origin Javascript Capability Leaks: Detection, Exploitation, and Defense. In Proceedings of the 18th Conference on USENIX Security Symposium (Montreal, Canada) (SSYM'09). USENIX Association, USA, 187--198."},{"key":"e_1_3_2_1_6_1","volume-title":"Proceedings of W2SP","author":"Bau Jason","year":"2013","unstructured":"Jason Bau, Jonathan Mayer, Hristo Paskov, and John C Mitchell. 2013. A promising direction for web tracking countermeasures. Proceedings of W2SP (2013)."},{"key":"e_1_3_2_1_7_1","volume-title":"Celery: Distributed task queue. https:\/\/github.com\/celery\/celery","year":"2023","unstructured":"Celery. 2023. Celery: Distributed task queue. https:\/\/github.com\/celery\/celery"},{"key":"e_1_3_2_1_8_1","unstructured":"Mongo DB. 2023. Mongo DB Website. https:\/\/www.mongodb.com\/"},{"key":"e_1_3_2_1_9_1","unstructured":"MDN Web Docs. 2022a. HTTP Headers: Cache-Control. https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/HTTP\/Headers\/Cache-Control."},{"key":"e_1_3_2_1_10_1","unstructured":"MDN Web Docs. 2022b. MDN Web Docs. https:\/\/developer.mozilla.org\/."},{"key":"e_1_3_2_1_11_1","unstructured":"MDN Web Docs. 2022c. PerformanceResourceTiming nextHopProtocol. https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/PerformanceResourceTiming\/nextHopProtocol."},{"key":"e_1_3_2_1_12_1","unstructured":"MDN Web Docs. 2023. State Partitioning. https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/Privacy\/State_Partitioning."},{"key":"e_1_3_2_1_13_1","volume-title":"Conference on Computer and Communications Security.","author":"Edward","unstructured":"Edward W. Felten and Michael A. Schneider. 2000. Timing attacks on Web privacy. In Conference on Computer and Communications Security."},{"key":"e_1_3_2_1_14_1","unstructured":"Ilya Grigorik and Charles Vazac. 2022. Server Timing. W3C Working Draft. W3C. https:\/\/www.w3.org\/TR\/server-timing\/#privacy-and-security."},{"key":"e_1_3_2_1_15_1","volume-title":"Proceedings of the 7th Python in Science Conference, Ga\u00ebl Varoquaux, Travis Vaught, and Jarrod Millman (Eds.). Pasadena, CA USA, 11--15","author":"Hagberg Aric A.","unstructured":"Aric A. Hagberg, Daniel A. Schult, and Pieter J. Swart. 2008. Exploring Network Structure, Dynamics, and Function using NetworkX. In Proceedings of the 7th Python in Science Conference, Ga\u00ebl Varoquaux, Travis Vaught, and Jarrod Millman (Eds.). Pasadena, CA USA, 11--15."},{"key":"e_1_3_2_1_16_1","unstructured":"Mario Heiderich. 2020. HTTPLeaks. https:\/\/github.com\/cure53\/HTTPLeaks."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382276"},{"key":"e_1_3_2_1_18_1","unstructured":"Luan Herrera. 2021. Guessing the URL a cross-origin iframe was redirected to by listening to the load event. https:\/\/crbug.com\/1248444."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","unstructured":"Umar Iqbal Peter Snyder Shitong Zhu Benjamin Livshits Zhiyun Qian and Zubair Shafiq. 2018. AdGraph: A Graph-Based Approach to Ad and Tracker Blocking. https:\/\/doi.org\/10.48550\/ARXIV.1805.09155","DOI":"10.48550\/ARXIV.1805.09155"},{"key":"e_1_3_2_1_20_1","unstructured":"Travi J. 2012. What does it mean global namespace would be polluted? https:\/\/stackoverflow.com\/questions\/8862665\/what-does-it-mean-global-namespace-would-be-polluted\/13352212."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW51379.2020.00096"},{"key":"e_1_3_2_1_22_1","volume-title":"Unleash the Simulacrum: Shifting Browser Realities for Robust Extension-Fingerprinting Prevention. In USENIX Security Symposium. USENIX Association.","author":"Karami Soroush","year":"2022","unstructured":"Soroush Karami, Faezeh Kalantari, Mehrnoosh Zaeifi, Xavier J. Maso, Erik Trickel, Panagiotis Ilia, Yan Shoshitaishvili, Adam Doup\u00e9, and Jason Polakis. 2022. Unleash the Simulacrum: Shifting Browser Realities for Robust Extension-Fingerprinting Prevention. In USENIX Security Symposium. USENIX Association."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833637"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179403"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484739"},{"key":"e_1_3_2_1_26_1","volume-title":"The Unexpected Dangers of Dynamic JavaScript. In USENIX Security Symposium","author":"Lekies Sebastian","year":"2015","unstructured":"Sebastian Lekies, Ben Stock, Martin Wentzel, and Martin Johns. 2015. The Unexpected Dangers of Dynamic JavaScript. In USENIX Security Symposium (2015). USENIX Association, 723. https:\/\/www.usenix.org\/conference\/usenixsecurity15\/technical-sessions\/presentation\/lekies"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23319"},{"key":"e_1_3_2_1_28_1","unstructured":"Milica Mihajlija. 2022. Cookies having independent partitioned state (CHIPS). https:\/\/developer.chrome.com\/docs\/privacy-sandbox\/chips\/"},{"key":"e_1_3_2_1_29_1","unstructured":"Mozilla. 2022. Firefox Source Code. https:\/\/hg.mozilla.org\/."},{"key":"e_1_3_2_1_30_1","volume-title":"The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the Web. In IEEE Symposium on Security and Privacy (S&P). IEEE Computer Society.","author":"Rautenstrauch Jannis","year":"2023","unstructured":"Jannis Rautenstrauch, Giancarlo Pellegrino, and Ben Stock. 2023. The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the Web. In IEEE Symposium on Security and Privacy (S&P). IEEE Computer Society."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.5555\/3241189.3241245"},{"key":"e_1_3_2_1_32_1","volume-title":"32th USENIX Security Symposium (USENIX Security 23)","author":"Snyder Peter","year":"2023","unstructured":"Peter Snyder, Soroush Karami, Benjamin Livshits, and Hamed Haddadi. 2023. Pool-Party: Exploiting Browser Resource Pools as Side-Channels for Web Tracking. In 32th USENIX Security Symposium (USENIX Security 23)."},{"key":"e_1_3_2_1_33_1","volume-title":"Leaky Images: Targeted Privacy Attacks in the Web. In USENIX Security Symposium. USENIX Association, 923--939","author":"Staicu Cristian-Alexandru","year":"2019","unstructured":"Cristian-Alexandru Staicu and Michael Pradel. 2019. Leaky Images: Targeted Privacy Attacks in the Web. In USENIX Security Symposium. USENIX Association, 923--939."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.18"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24278"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3517416"},{"key":"e_1_3_2_1_37_1","unstructured":"W3C. 2022. The web-platform-tests Project. https:\/\/wpt.fyi\/."},{"key":"e_1_3_2_1_38_1","unstructured":"Yoav Weiss and Noam Rosenthal. 2022. Resource Timing Level 2. W3C Working Draft. W3C. https:\/\/www.w3.org\/TR\/2022\/WD-resource-timing-2-20220706\/."},{"key":"e_1_3_2_1_39_1","unstructured":"Mike West. 2021. Content Security Policy: Embedded Enforcement. W3C Editor's Draft. W3C. https:\/\/w3c.github.io\/webappsec-cspee\/."},{"key":"e_1_3_2_1_40_1","unstructured":"John Wilander. 2019. Preventing Tracking Prevention Tracking. https:\/\/webkit.org\/blog\/9661\/preventing-tracking-prevention-tracking\/."},{"key":"e_1_3_2_1_41_1","unstructured":"Takashi Yoneuchi. 2019a. Issue 1038036: Security: Cross-Origin (Partial) Status Code Leakage. https:\/\/crbug.com\/1038036."},{"key":"e_1_3_2_1_42_1","unstructured":"Takashi Yoneuchi. 2019b. XS-Leak with Resource Timing API and CSP Embedded Enforcement. https:\/\/crbug.com\/1105875."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-90022-9_8"}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3616598","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3616598","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:58:55Z","timestamp":1755741535000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3616598"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":43,"alternative-id":["10.1145\/3576915.3616598","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3616598","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}