A security analysis of paid subscription video-on-demand services for online learning

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Scopus citations

Abstract

A typical online learning service allows users to watch video lectures in web browsers at any time and any place. In many cases of such services, security solutions (e.g., user authentication and access control) have been deployed to secure access to their premium contents to authorized users only who have paid the subscription fee. In this paper, we demonstrate how security solutions in real-world services can be broken easily. We performed an empirical analysis on the effectiveness of the security solutions deployed in the five popular online learning services using a web proxy to analyze the packets transferred between streaming server and web browser for a streaming service. Our experimental results show that one service out of five was vulnerable to password stealing attacks; three services were vulnerable to URL guessing attacks; and two services were vulnerable to cookie cloning attacks. All the websites tested were vulnerable to at least one attack.

Original languageEnglish
Title of host publicationProceedings - 2016 International Conference on Software Security and Assurance, ICSSA 2016
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages43-48
Number of pages6
ISBN (Electronic)9781509043880
DOIs
StatePublished - 21 Feb 2017
Event2016 International Conference on Software Security and Assurance, ICSSA 2016 - St. Polten, Austria
Duration: 24 Aug 201625 Aug 2016

Publication series

NameProceedings - 2016 International Conference on Software Security and Assurance, ICSSA 2016

Conference

Conference2016 International Conference on Software Security and Assurance, ICSSA 2016
Country/TerritoryAustria
CitySt. Polten
Period24/08/1625/08/16

Keywords

  • Security analysis
  • Video-on-demand
  • Web security

Fingerprint

Dive into the research topics of 'A security analysis of paid subscription video-on-demand services for online learning'. Together they form a unique fingerprint.

Cite this