论文标题
隐形同行:了解基于WEBRTC的同行辅助视频流的安全风险
Stealthy Peers: Understanding Security Risks of WebRTC-Based Peer-Assisted Video Streaming
论文作者
论文摘要
据报道,作为用于浏览器内内容交付的新兴服务,据报道,同行辅助交付网络(PDN)可将视频流的带宽消费量的95%倒计时,从而大大降低了传统CDN服务的成本。有了这些好处,PDN服务会极大地影响当今的视频流和内容交付模型。但是,他们的安全含义从未得到调查。在本文中,我们报告了解决此问题的第一个努力,例如,一套方法可以通过一套自动管道来发现PDN服务及其客户,以及一个测试这些服务的潜在安全性和隐私风险的PDN分析框架。我们的研究导致发现了3个代表性PDN提供商,以及134个网站和38个移动应用程序作为客户。这些PDN客户中的大多数是著名的视频流服务,每月访问或应用程序下载(来自Google Play)。在我们的研究中还发现了另外9个顶级视频/直播网站,每个网站都配备了专有PDN解决方案。最重要的是,我们对这些PDN服务的分析已经揭示了一系列的安全风险,这些风险从未有过报道,包括免费骑行公共PDN服务,视频细分市场污染,视频观看者的IPS接触其他同行以及资源蹲下。在我们机构IRB的指导下,通过受控的实验和测量进行了所有这些风险。我们已经向相关的PDN提供商披露了这些安全风险,他们承认我们的发现,并讨论了减轻这些风险的途径。
As an emerging service for in-browser content delivery, peer-assisted delivery network (PDN) is reported to offload up to 95\% of bandwidth consumption for video streaming, significantly reducing the cost incurred by traditional CDN services. With such benefits, PDN services significantly impact today's video streaming and content delivery model. However, their security implications have never been investigated. In this paper, we report the first effort to address this issue, which is made possible by a suite of methodologies, e.g., an automatic pipeline to discover PDN services and their customers, and a PDN analysis framework to test the potential security and privacy risks of these services. Our study has led to the discovery of 3 representative PDN providers, along with 134 websites and 38 mobile apps as their customers. Most of these PDN customers are prominent video streaming services with millions of monthly visits or app downloads (from Google Play). Also found in our study are another 9 top video/live streaming websites with each equipped with a proprietary PDN solution. Most importantly, our analysis on these PDN services has brought to light a series of security risks, which have never been reported before, including free riding of the public PDN services, video segment pollution, exposure of video viewers' IPs to other peers, and resource squatting. All such risks have been studied through controlled experiments and measurements, under the guidance of our institution's IRB. We have responsibly disclosed these security risks to relevant PDN providers, who have acknowledged our findings, and also discussed the avenues to mitigate these risks.