Enhancing Web Privacy through Fine-Grained Program Analysis of Tracking JavaScript

dc.contributor.authorAmjad, Abdul Haddien
dc.contributor.committeechairGulzar, Muhammad Alien
dc.contributor.committeememberShafiq, Zubairen
dc.contributor.committeememberYao, Danfengen
dc.contributor.committeememberMeng, Naen
dc.contributor.committeememberJi, Boen
dc.contributor.departmentComputer Science and#38; Applicationsen
dc.date.accessioned2026-03-12T08:00:10Zen
dc.date.available2026-03-12T08:00:10Zen
dc.date.issued2026-03-11en
dc.description.abstractAdvertisers and tracking services (ATS) are pervasive on the modern web. To counter these practices, millions of users rely on privacy-enhancing technologies (PETs), such as ad-blockers, which primarily depend on filter lists composed of regex-based rules to block network requests associated with data exfiltration. However, this approach has become increasingly ineffective in the face of an ongoing arms race. Currently, PETs struggle to handle mixed JavaScript (JS) scripts that combine tracking behavior with legitimate website functionality. These tools operate at the network level and can only block entire script requests rather than specific behaviors within a script. As a result, once a mixed script executes, any subsequent data exfiltration carried out through encrypted URL requests becomes invisible to network-based defenses, rendering existing PETs ineffective. Mixed JS scripts create a fundamental dilemma for PETs: aggressively blocking them risks breaking websites, while allowing them undermines user privacy. This thesis addresses this challenge by asking: How can code-aware program analysis be leveraged to design privacy-enhancing technologies that effectively mitigate tracking while preserving essential web functionality? This thesis makes three primary contributions. First, we focus on identification of mixed JS by introducing TrackerSift, a large-scale measurement framework that reveals mixed behavior in a substantial fraction of web JS scripts. Second, we validate that mixed JS scripts can be effectively handled through program analysis, demonstrating that functions inside mixed JS scripts can clearly separate tracking code from functional code. Finally, we address mitigation by presenting NoT.JS, a code-aware, ML–based system that accurately identifies tracking JS functions inside mixed JS scripts and refactors them to selectively remove tracking logic while maintaining legitimate functionality. Together, these contributions advance privacy-enhancing technologies by enabling principled mitigation of mixed JS scripts through code-aware program analysis.en
dc.description.abstractgeneralOnline advertising and tracking services (ATS) are a fundamental part of today's web, but they also raise serious concerns about user privacy. To protect themselves, millions of people rely on privacy-enhancing technologies (PETs), such as ad-blockers. These tools typically depend on simple filter-rule lists to block outgoing tracking requests. However, as ATS adapt, they employ increasingly sophisticated techniques in which tracking is hidden within mixed website resources that also provide essential functionality. Blocking these mixed resources outright can break websites, while allowing them can expose users to unwanted tracking. This thesis explores how PETs can better navigate this trade-off. It asks how deeper code-level analysis can be used to identify and remove tracking behavior without disrupting how websites functionality. The thesis first measures how common these mixed web resources are, those that combine essential website functionality with hidden tracking, and shows that they are widespread across the web. It then demonstrates that analyzing website JavaScript code at a fine-grained, function-level granularity enables tracking behavior to be isolated from website functionality in mixed resources. Building on these insights, the thesis presents an automated machine-learning system that detects and removes tracking code from mixed resources while preserving legitimate website functionality. Overall, this thesis shows that understanding how ATS tracking is embedded within website code is essential for building more effective and reliable PETs, and highlights how code-aware analysis can help PETs keep pace with an evolving web.en
dc.description.degreeDoctor of Philosophyen
dc.format.mediumETDen
dc.identifier.othervt_gsexam:45672en
dc.identifier.urihttps://hdl.handle.net/10919/142225en
dc.language.isoenen
dc.publisherVirginia Techen
dc.rightsCreative Commons Attribution-ShareAlike 4.0 Internationalen
dc.rights.urihttp://creativecommons.org/licenses/by-sa/4.0/en
dc.subjectWeben
dc.subjectPrivacyen
dc.subjectSoftware Engineeringen
dc.titleEnhancing Web Privacy through Fine-Grained Program Analysis of Tracking JavaScripten
dc.typeDissertationen
thesis.degree.disciplineComputer Science & Applicationsen
thesis.degree.grantorVirginia Polytechnic Institute and State Universityen
thesis.degree.leveldoctoralen
thesis.degree.nameDoctor of Philosophyen

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Amjad_A_D_2026.pdf
Size:
5.96 MB
Format:
Adobe Portable Document Format