Stealthy Peers: Understanding Security Risks of WebRTC-Based Peer-Assisted Video Streaming

12/06/2022
by   Siyuan Tang, et al.
0

As an emerging service for in-browser content delivery, peer-assisted delivery network (PDN) is reported to offload up to 95% of bandwidth consumption for video streaming, significantly reducing the cost incurred by traditional CDN services. With such benefits, PDN services significantly impact today's video streaming and content delivery model. However, their security implications have never been investigated. In this paper, we report the first effort to address this issue, which is made possible by a suite of methodologies, e.g., an automatic pipeline to discover PDN services and their customers, and a PDN analysis framework to test the potential security and privacy risks of these services. Our study has led to the discovery of 3 representative PDN providers, along with 134 websites and 38 mobile apps as their customers. Most of these PDN customers are prominent video streaming services with millions of monthly visits or app downloads (from Google Play). Also found in our study are another 9 top video/live streaming websites with each equipped with a proprietary PDN solution. Most importantly, our analysis on these PDN services has brought to light a series of security risks, which have never been reported before, including free riding of the public PDN services, video segment pollution, exposure of video viewers' IPs to other peers, and resource squatting. All such risks have been studied through controlled experiments and measurements, under the guidance of our institution's IRB. We have responsibly disclosed these security risks to relevant PDN providers, who have acknowledged our findings, and also discussed the avenues to mitigate these risks.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/22/2018

Insights from Analysis of Video Streaming Data to Improve Resource Management

Today a large portion of Internet traffic is video. Over The Top (OTT) s...
research
05/13/2023

Beyond the Safeguards: Exploring the Security Risks of ChatGPT

The increasing popularity of large language models (LLMs) such as ChatGP...
research
09/18/2018

Performance Analysis and Modeling of Video Transcoding Using Heterogeneous Cloud Services

High-quality video streaming, either in form of Video-On-Demand (VOD) or...
research
01/03/2019

The Price of Free Illegal Live Streaming Services

As Internet streaming of live content has gained on traditional cable TV...
research
04/04/2022

Clues in Tweets: Twitter-Guided Discovery and Analysis of SMS Spam

With its critical role in business and service delivery through mobile d...
research
03/30/2021

Looney Tunes: Exposing the Lack of DRM Protection in Indian Music Streaming Services

Numerous studies have shown that streaming is now the most preferred way...
research
09/13/2022

An Extensive Study of Residential Proxies in China

We carry out the first in-depth characterization of residential proxies ...

Please sign up or login with your details

Forgot password? Click here to reset