RISS 학술연구정보서비스

검색
다국어 입력

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

변환된 중국어를 복사하여 사용하시면 됩니다.

예시)
  • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
  • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
닫기
    인기검색어 순위 펼치기

    RISS 인기검색어

      A security analysis of paid subscription video-on-demand services for online learning = 온라인 수업의 유료 주문형 비디오 서비스에 대한 보안 취약점 분석

      한글로보기

      https://www.riss.kr/link?id=T14574558

      • 0

        상세조회
      • 0

        다운로드
      서지정보 열기
      • 내보내기
      • 내책장담기
      • 공유하기
      • 오류접수

      부가정보

      다국어 초록 (Multilingual Abstract)

      A typical online learning service allows users to watch video lectures in web browsers at any time and any place. In many cases of such services, security solutions (e.g., user authentication and access control) have been deployed to secure access to their premium contents to authorized users only who have paid the subscription fee. In this paper, we demonstrate how security solutions in real-world services can be broken easily. We performed an empirical analysis on the effectiveness of the security solutions deployed in the five popular online learning services using a web proxy to analyze the packets transferred between streaming server and web browser for a streaming service. Our experimental results show that one service out of five was vulnerable to password stealing attacks; three services were vulnerable to URL guessing attacks; and two services were vulnerable to cookie cloning attacks. All the websites tested were vulnerable to at least one attack.
      번역하기

      A typical online learning service allows users to watch video lectures in web browsers at any time and any place. In many cases of such services, security solutions (e.g., user authentication and access control) have been deployed to secure access to ...

      A typical online learning service allows users to watch video lectures in web browsers at any time and any place. In many cases of such services, security solutions (e.g., user authentication and access control) have been deployed to secure access to their premium contents to authorized users only who have paid the subscription fee. In this paper, we demonstrate how security solutions in real-world services can be broken easily. We performed an empirical analysis on the effectiveness of the security solutions deployed in the five popular online learning services using a web proxy to analyze the packets transferred between streaming server and web browser for a streaming service. Our experimental results show that one service out of five was vulnerable to password stealing attacks; three services were vulnerable to URL guessing attacks; and two services were vulnerable to cookie cloning attacks. All the websites tested were vulnerable to at least one attack.

      더보기

      목차 (Table of Contents)

      • List of Tables ⅱ
      • List of Figures ⅱ
      • Abstract ⅲ
      • 1. Introduction 1
      • 2. Background 4
      • List of Tables ⅱ
      • List of Figures ⅱ
      • Abstract ⅲ
      • 1. Introduction 1
      • 2. Background 4
      • 2.1. Overview of video-on-demand services 4
      • 2.2. Security technologies for video-on-demand services 6
      • 3. Methodology 9
      • 3.1. Threat models 9
      • 3.2. Three attacks tested 11
      • 4. Experiments 14
      • 4.1. Security mechanisms of the websites tested 14
      • 4.2. Implementation 15
      • 4.3. Summary of results 20
      • 5. Countermeasures 21
      • 5.1. Encryption of web traffic 21
      • 5.2. Use of the best practices for capability URLs 21
      • 5.3. Expiration of capability URLs and cookies 23
      • 5.4. Preventing suspicious URL requests 23
      • 6. Conclusion 24
      • References 25
      • Korean Abstract 27
      더보기

      분석정보

      View

      상세정보조회

      0

      Usage

      원문다운로드

      0

      대출신청

      0

      복사신청

      0

      EDDS신청

      0

      동일 주제 내 활용도 TOP

      더보기

      주제

      연도별 연구동향

      연도별 활용동향

      연관논문

      연구자 네트워크맵

      공동연구자 (7)

      유사연구자 (20) 활용도상위20명

      이 자료와 함께 이용한 RISS 자료

      나만을 위한 추천자료

      해외이동버튼