Understanding the Security of Free Content Websites by Analyzing their SSL Certificates: A Comparative Study

Abdulrahman Alabduljabbar, Runyu Ma, Soohyeon Choi, Rhongho Jang, Songqing Chen, David Mohaisen

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

10 Scopus citations

Abstract

Online services that provide books, music, movies, etc., for free have existed on the Internet for decades. While there are some common beliefs and warnings that such online services may contain hidden security risks, many ordinary users still visit such websites, making them a convenient vehicle for subsequent exploitation. In this paper, we investigate and quantify through measurements the potential vulnerability of such free content websites (FCWs). For this purpose, we curated 834 FCWs offering books, games, movies, music, and software. For a comparison purpose, we also sampled a comparable number of premium content websites, where users need to pay for using the service for the same type of content. For our modality of analysis, we use SSL certificates. Namely, we explore SSL certificates' structural and fundamental differences between free and premium content websites. Through our analysis, we unveil that 36% of the free websites' certificates have major issues, with 17% invalid certificates, 7% expired, and 12% with mismatched domain names. Moreover, although surprisingly, we uncover the usage of ECDSA predominantly among the free websites. Among other observations, we notice that 38% of the FCWs use ECDSA-256, compared to only 20% of their premium counterparts, which provides better security guarantees (and performance) than the common algorithm option and key size (RSA-2048) in premium websites. Our observations raise concerns regarding the safety of using such free services from a transport standpoint and call for in-depth analysis of their risks.

Original languageEnglish
Title of host publicationCySSS 2022 - Proceedings of the 1st Workshop on Cybersecurity and Social Sciences
PublisherAssociation for Computing Machinery, Inc
Pages19-25
Number of pages7
ISBN (Electronic)9781450391771
DOIs
StatePublished - 30 May 2022
Externally publishedYes
Event1st International Workshop on Cybersecurity and Social Sciences, CySSS 2022 - Virtual, Online, Japan
Duration: 30 May 2022 → …

Publication series

NameCySSS 2022 - Proceedings of the 1st Workshop on Cybersecurity and Social Sciences

Conference

Conference1st International Workshop on Cybersecurity and Social Sciences, CySSS 2022
Country/TerritoryJapan
CityVirtual, Online
Period30/05/22 → …

Keywords

  • free content websites
  • internet measurements
  • ssl certificates
  • web security

Fingerprint

Dive into the research topics of 'Understanding the Security of Free Content Websites by Analyzing their SSL Certificates: A Comparative Study'. Together they form a unique fingerprint.

Cite this