Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability?

Nowadays, many users make money by publishing content on social media platforms. In order to attract users' attention, they often take measures to promote themselves. The security vulnerabilities in social media platforms may provide convenience for their user promotion work. We call this type...

Full description

Bibliographic Details
Main Authors: Hongzhou Yue, Shuilong He, Zhenghui Liu
Format: Article
Language:English
Published: IEEE 2020-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/9018045/
_version_ 1819171401307783168
author Hongzhou Yue
Shuilong He
Zhenghui Liu
author_facet Hongzhou Yue
Shuilong He
Zhenghui Liu
author_sort Hongzhou Yue
collection DOAJ
description Nowadays, many users make money by publishing content on social media platforms. In order to attract users' attention, they often take measures to promote themselves. The security vulnerabilities in social media platforms may provide convenience for their user promotion work. We call this type of vulnerability the user promotion security vulnerability (UPSV). UPSV may cause unfair competition and endanger the interests of legitimate users and the social media platforms. Therefore it has great research significance to find and fix this vulnerability. In this paper, we propose a UPSV which widely exists in the function of sending messages to strangers of in-app chatting of many social media platforms. We first analyzed this vulnerability in some apps, and then YY app (China's largest live streaming platform) was chosen as the research object to verify the actual effect of the vulnerability on illegitimate user promotion. We took the method of promoting a target YY streamer through sending promotional links to viewers, and to improve promotion effect, we used the method of user preference learning to select viewers for promotion. The experimental results show that among the promoted viewers, more than 44% entered the target streamers' channels to watch live streaming, more than 21% followed the target steamers, and more than 13% gave gifts to the target steamers. It fully proves that this UPSV is real, exploitable and harmful, and we also proposed some fix suggestions to help the platforms to fix it.
first_indexed 2024-12-22T19:50:42Z
format Article
id doaj.art-8d81815eff8148c3b7ff31a7d2e34c31
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-12-22T19:50:42Z
publishDate 2020-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-8d81815eff8148c3b7ff31a7d2e34c312022-12-21T18:14:34ZengIEEEIEEE Access2169-35362020-01-018417054171810.1109/ACCESS.2020.29771019018045Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability?Hongzhou Yue0https://orcid.org/0000-0002-2836-0927Shuilong He1https://orcid.org/0000-0001-5329-0919Zhenghui Liu2https://orcid.org/0000-0001-9460-8890School of Computer and Information Technology, Xinyang Normal University, Xinyang, ChinaSchool of Computer and Information Technology, Xinyang Normal University, Xinyang, ChinaHenan Key Laboratory of Analysis and Applications of Education Big Data, Xinyang Normal University, Xinyang, ChinaNowadays, many users make money by publishing content on social media platforms. In order to attract users' attention, they often take measures to promote themselves. The security vulnerabilities in social media platforms may provide convenience for their user promotion work. We call this type of vulnerability the user promotion security vulnerability (UPSV). UPSV may cause unfair competition and endanger the interests of legitimate users and the social media platforms. Therefore it has great research significance to find and fix this vulnerability. In this paper, we propose a UPSV which widely exists in the function of sending messages to strangers of in-app chatting of many social media platforms. We first analyzed this vulnerability in some apps, and then YY app (China's largest live streaming platform) was chosen as the research object to verify the actual effect of the vulnerability on illegitimate user promotion. We took the method of promoting a target YY streamer through sending promotional links to viewers, and to improve promotion effect, we used the method of user preference learning to select viewers for promotion. The experimental results show that among the promoted viewers, more than 44% entered the target streamers' channels to watch live streaming, more than 21% followed the target steamers, and more than 13% gave gifts to the target steamers. It fully proves that this UPSV is real, exploitable and harmful, and we also proposed some fix suggestions to help the platforms to fix it.https://ieeexplore.ieee.org/document/9018045/Social mediauser promotionsecurity vulnerabilityin-app~chattingpreference learning
spellingShingle Hongzhou Yue
Shuilong He
Zhenghui Liu
Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability?
IEEE Access
Social media
user promotion
security vulnerability
in-app~chatting
preference learning
title Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability?
title_full Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability?
title_fullStr Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability?
title_full_unstemmed Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability?
title_short Social Media Users Send Promotional Links to Strangers: Legitimate Promotion or Security Vulnerability?
title_sort social media users send promotional links to strangers legitimate promotion or security vulnerability
topic Social media
user promotion
security vulnerability
in-app~chatting
preference learning
url https://ieeexplore.ieee.org/document/9018045/
work_keys_str_mv AT hongzhouyue socialmediauserssendpromotionallinkstostrangerslegitimatepromotionorsecurityvulnerability
AT shuilonghe socialmediauserssendpromotionallinkstostrangerslegitimatepromotionorsecurityvulnerability
AT zhenghuiliu socialmediauserssendpromotionallinkstostrangerslegitimatepromotionorsecurityvulnerability