Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability?
Nowadays, many users make money by publishing content on social media platforms. In order to attract users' attention, they often take measures to promote themselves. The security vulnerabilities in social media platforms may provide convenience for their user promotion work. We call this type...
Main Authors: | , , |
---|---|
Format: | Article |
Language: | English |
Published: |
IEEE
2020-01-01
|
Series: | IEEE Access |
Subjects: | |
Online Access: | https://ieeexplore.ieee.org/document/9018045/ |
_version_ | 1819171401307783168 |
---|---|
author | Hongzhou Yue Shuilong He Zhenghui Liu |
author_facet | Hongzhou Yue Shuilong He Zhenghui Liu |
author_sort | Hongzhou Yue |
collection | DOAJ |
description | Nowadays, many users make money by publishing content on social media platforms. In order to attract users' attention, they often take measures to promote themselves. The security vulnerabilities in social media platforms may provide convenience for their user promotion work. We call this type of vulnerability the user promotion security vulnerability (UPSV). UPSV may cause unfair competition and endanger the interests of legitimate users and the social media platforms. Therefore it has great research significance to find and fix this vulnerability. In this paper, we propose a UPSV which widely exists in the function of sending messages to strangers of in-app chatting of many social media platforms. We first analyzed this vulnerability in some apps, and then YY app (China's largest live streaming platform) was chosen as the research object to verify the actual effect of the vulnerability on illegitimate user promotion. We took the method of promoting a target YY streamer through sending promotional links to viewers, and to improve promotion effect, we used the method of user preference learning to select viewers for promotion. The experimental results show that among the promoted viewers, more than 44% entered the target streamers' channels to watch live streaming, more than 21% followed the target steamers, and more than 13% gave gifts to the target steamers. It fully proves that this UPSV is real, exploitable and harmful, and we also proposed some fix suggestions to help the platforms to fix it. |
first_indexed | 2024-12-22T19:50:42Z |
format | Article |
id | doaj.art-8d81815eff8148c3b7ff31a7d2e34c31 |
institution | Directory Open Access Journal |
issn | 2169-3536 |
language | English |
last_indexed | 2024-12-22T19:50:42Z |
publishDate | 2020-01-01 |
publisher | IEEE |
record_format | Article |
series | IEEE Access |
spelling | doaj.art-8d81815eff8148c3b7ff31a7d2e34c312022-12-21T18:14:34ZengIEEEIEEE Access2169-35362020-01-018417054171810.1109/ACCESS.2020.29771019018045Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability?Hongzhou Yue0https://orcid.org/0000-0002-2836-0927Shuilong He1https://orcid.org/0000-0001-5329-0919Zhenghui Liu2https://orcid.org/0000-0001-9460-8890School of Computer and Information Technology, Xinyang Normal University, Xinyang, ChinaSchool of Computer and Information Technology, Xinyang Normal University, Xinyang, ChinaHenan Key Laboratory of Analysis and Applications of Education Big Data, Xinyang Normal University, Xinyang, ChinaNowadays, many users make money by publishing content on social media platforms. In order to attract users' attention, they often take measures to promote themselves. The security vulnerabilities in social media platforms may provide convenience for their user promotion work. We call this type of vulnerability the user promotion security vulnerability (UPSV). UPSV may cause unfair competition and endanger the interests of legitimate users and the social media platforms. Therefore it has great research significance to find and fix this vulnerability. In this paper, we propose a UPSV which widely exists in the function of sending messages to strangers of in-app chatting of many social media platforms. We first analyzed this vulnerability in some apps, and then YY app (China's largest live streaming platform) was chosen as the research object to verify the actual effect of the vulnerability on illegitimate user promotion. We took the method of promoting a target YY streamer through sending promotional links to viewers, and to improve promotion effect, we used the method of user preference learning to select viewers for promotion. The experimental results show that among the promoted viewers, more than 44% entered the target streamers' channels to watch live streaming, more than 21% followed the target steamers, and more than 13% gave gifts to the target steamers. It fully proves that this UPSV is real, exploitable and harmful, and we also proposed some fix suggestions to help the platforms to fix it.https://ieeexplore.ieee.org/document/9018045/Social mediauser promotionsecurity vulnerabilityin-app~chattingpreference learning |
spellingShingle | Hongzhou Yue Shuilong He Zhenghui Liu Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability? IEEE Access Social media user promotion security vulnerability in-app~chatting preference learning |
title | Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability? |
title_full | Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability? |
title_fullStr | Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability? |
title_full_unstemmed | Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability? |
title_short | Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability? |
title_sort | social media users send promotional links to strangers legitimate promotion or security vulnerability |
topic | Social media user promotion security vulnerability in-app~chatting preference learning |
url | https://ieeexplore.ieee.org/document/9018045/ |
work_keys_str_mv | AT hongzhouyue socialmediauserssendpromotionallinkstostrangerslegitimatepromotionorsecurityvulnerability AT shuilonghe socialmediauserssendpromotionallinkstostrangerslegitimatepromotionorsecurityvulnerability AT zhenghuiliu socialmediauserssendpromotionallinkstostrangerslegitimatepromotionorsecurityvulnerability |