TRANCO: A Research-Oriented Top Sites Ranking Hardened Against Manipulation

Conference Paper (2019)
Author(s)

Victor Le Pochat (Katholieke Universiteit Leuven)

Tom Van Goethem (Katholieke Universiteit Leuven)

S. Tajalizadehkhoob (TU Delft - Organisation & Governance)

Wouter Joosen (Grenoble Alps University/CNRS/IRD)

Research Group
Organisation & Governance
Copyright
© 2019 Victor Le Pochat, Tom Van Goethem, S. Tajalizadehkhoob, Wouter Joosen
DOI related publication
https://doi.org/10.14722/ndss.2019.23386
More Info
expand_more
Publication Year
2019
Language
English
Copyright
© 2019 Victor Le Pochat, Tom Van Goethem, S. Tajalizadehkhoob, Wouter Joosen
Research Group
Organisation & Governance
ISBN (print)
1-891562-55-X
ISBN (electronic)
['189156255X', '9781891562556']
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

In order to evaluate the prevalence of security and privacy practices on a representative sample of the Web, researchers rely on website popularity rankings such as the Alexa list. While the validity and representativeness of these rankings are rarely questioned, our findings show the contrary: we show for four main rankings how their inherent properties (similarity, stability, representativeness, responsiveness and benignness) affect their composition and therefore potentially skew the conclusions made in studies. Moreover, we find that it is trivial for an adversary to manipulate the composition of these lists. We are the first to empirically validate that the ranks of domains in each of the lists are easily altered, in the case of Alexa through as little as a single HTTP request. This allows adversaries to manipulate rankings on a large scale and insert malicious domains into whitelists or bend the outcome of research studies to their will. To overcome the limitations of such rankings, we propose improvements to reduce the fluctuations in list composition and guarantee better defenses against manipulation. To allow the research community to work with reliable and reproducible rankings, we provide TRANCO, an improved ranking that we offer through an online service available at https://tranco-list.eu.

Files

Ndss2019_01B_3.pdf
(pdf | 0.785 Mb)
License info not available