Web Request Hooking for Tracking Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing privacy policies that block all known tracking domains from loading content into host web pages are ineffective in preventing tracking activities, as they can break functional web pages and fail to detect hidden tracking domains that perform tracking through code executed by permissible content providers.
Innovation Solution
A method involving a computing device with processors that identifies and removes tracking capabilities by hooking into web requests and API calls, inspecting header values, detecting identifiers, and obfuscating or altering requests and responses to prevent tracking activities without blocking content from external domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If all known tracking domains are blocked from loading content into host web pages, then user privacy is protected, but functional web pages break and functionality is lost
Solution Approach 1:
The patent segments tracking protection into two distinct approaches: (1) blocking tracking domains from loading content, and (2) allowing tracking domains to load content but preventing them from performing tracking activities through code inspection and execution blocking. This segmentation resolves the contradiction by providing granular control over different aspects of tracking domain behavior.
Solution Approach 2:
The patent applies local quality by treating different tracking domains differently based on their specific functions. Functional tracking domains that provide necessary services are allowed to load content but have their tracking code blocked, while purely malicious tracking domains are completely blocked. This localized approach maintains web page functionality where needed while protecting privacy where possible.
2Object-affected harmful factors
If privacy policies block all known tracking domains from loading content, then tracking activities are prevented, but the policies fail to detect hidden tracking domains that perform tracking through code executed by permissible content providers
Solution Approach 1:
The patent implements preliminary action by proactively inspecting and blocking tracking code before it can execute. The system scans content from permissible content providers for embedded tracking code, identifies tracking domains attempting to execute through these providers, and blocks the tracking activities before they can compromise user privacy. This preventive approach addresses hidden tracking domains that traditional blocking methods miss.
Solution Approach 2:
The patent uses an intermediary approach by monitoring and inspecting the code execution environment. Rather than directly blocking tracking domains, the system acts as an intermediary that allows permissible content providers to load content but intercepts and blocks tracking code attempts to execute. This intermediary layer reveals and blocks hidden tracking domains that operate through third-party content providers.
3Object-affected harmful factors
If tracking domains are completely blocked, then user privacy is protected, but external domains that provide functionality to host web pages can no longer operate
Solution Approach 1:
The patent applies local quality by differentiating between tracking functions and functional services provided by external domains. Content from external domains is allowed to load and provide necessary functionality, but tracking code within that content is identified and blocked. This localized differentiation preserves web page adaptability and functionality while maintaining privacy protection.
Solution Approach 2:
The patent segments the functionality of external domains into two parts: (1) legitimate content and services that are allowed to load and execute, and (2) tracking code that is blocked. This segmentation enables functional tracking domains to continue providing necessary services while preventing their tracking activities, thus maintaining both privacy protection and web page versatility.
Data Source
AI summary
Systems and methods for identifying and removing a tracking capability from an external domain that performs a tracking activity on a host web page. Tracking capabilities of an external domain may be removed by altering web requests and/or responses to API calls. Once these tracking capabilities of the external domain have been removed, the altered web requests and/or altered responses to API calls may be transmitted to a web browser and/or entity making the API call thereby protecting user privacy while allowing the external domain to interact with the host web page.


