As an emerging service for in-browser content delivery, peer-assisted delivery network (PDN) is reported to offload up to 95\% of bandwidth consumption for video streaming, significantly reducing the cost incurred by traditional CDN services. With such benefits, PDN services significantly impact today's video streaming and content delivery model. However, their security implications have never been investigated. In this paper, we report the first effort to address this issue, which is made possible by a suite of methodologies, e.g., an automatic pipeline to discover PDN services and their customers, and a PDN analysis framework to test the potential security and privacy risks of these services. Our study has led to the discovery of 3 representative PDN providers, along with 134 websites and 38 mobile apps as their customers. Most of these PDN customers are prominent video streaming services with millions of monthly visits or app downloads (from Google Play). Also found in our study are another 9 top video/live streaming websites with each equipped with a proprietary PDN solution. Most importantly, our analysis on these PDN services has brought to light a series of security risks, which have never been reported before, including free riding of the public PDN services, video segment pollution, exposure of video viewers' IPs to other peers, and resource squatting. All such risks have been studied through controlled experiments and measurements, under the guidance of our institution's IRB. We have responsibly disclosed these security risks to relevant PDN providers, who have acknowledged our findings, and also discussed the avenues to mitigate these risks.
翻译:作为在浏览器中提供内容的一种新兴服务,据报告,同行协助交付网络(PDN)会卸载多达95 ⁇ 的带宽消耗,用于视频流用,大大减少了传统CDN服务的成本。有了这些好处,PDN服务对当今视频流和内容交付模式产生了重大影响。然而,它们的安全影响从未进行过调查。在本文中,我们报告了解决这一问题的首次努力,这是一套方法,例如发现PDN服务及其客户的自动管道,以及测试这些服务的潜在安全和隐私风险的PDN分析框架。我们的研究发现3个具有代表性的PDN供应商,以及134个网站和38个移动应用程序作为客户。这些PDN客户大多是引人注目的视频流服务,每月访问或下载数百万次(来自GooPlay)。我们的研究还发现,另外9个拥有公开PDN服务的高级视频流网站,每个网站都公开讨论PDN服务的途径。最重要的是,我们对这些PD服务的分析已经让公众了解一系列安全风险,这些风险在PD的视频上一直被披露。