A Security Framework for Addressing Privacy Issues in the Zoom Conference System

Samer H. Atawneh, Ziad Alshammari, Mousa AL- Akhras, Bayan Abu Shawar
{"title":"A Security Framework for Addressing Privacy Issues in the Zoom Conference System","authors":"Samer H. Atawneh, Ziad Alshammari, Mousa AL- Akhras, Bayan Abu Shawar","doi":"10.58346/jisis.2024.i1.016","DOIUrl":null,"url":null,"abstract":"The COVID-19 pandemic had a significant impact on many facets of human behavior. Most significantly, it required significant changes to how daily activities were conducted. The majority of individuals were forced to work and communicate from home due to social distancing, which opened the door for more virtual meetings. Since most organizations started allowing their employees to work from home, the majority of online meeting platforms—like Zoom and Microsoft Teams—have become more and more popular. Online meetings were not only used by businesses but also by educational institutes to carry out online learning, hospitals to conduct meetings and certain surgeries, and many other industries. The online meetings are practical and simple to organize, but their information security is not as high as that of conventional meetings. Security and privacy issues resulted from this. The safety of personal information such as names, contacts, and locations, the security of online recordings since sensitive information was discussed in most meetings, the security of data while it was in transit, and the potential for competitors to intercept your business were among the many security issues that were raised. Zoom, as one of the famous online conference systems, faced many global concerns, such as sharing private information with third parties, exposing users to unauthorized bullying calls, and adopting questionable end-to-end encryption processes. Additionally, companies have had virtual meetings hacked, leading to privacy issues since hackers can obtain data illegally. Therefore, this research proposes a security framework to address the privacy issues in the Zoom system by applying a set of governance and technical controls. The governance controls provide a strategic view of how an organization controls its security while implementing the technical controls avoids privacy issues in online conference systems. The proposed framework implements a set of technical controls such as encryption, auditing, authentication, and role-based access control. The results were promising and significantly addressed Zoom's privacy issues.","PeriodicalId":36718,"journal":{"name":"Journal of Internet Services and Information Security","volume":"16 18","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-03-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Internet Services and Information Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.58346/jisis.2024.i1.016","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"Computer Science","Score":null,"Total":0}
引用次数: 0

Abstract

The COVID-19 pandemic had a significant impact on many facets of human behavior. Most significantly, it required significant changes to how daily activities were conducted. The majority of individuals were forced to work and communicate from home due to social distancing, which opened the door for more virtual meetings. Since most organizations started allowing their employees to work from home, the majority of online meeting platforms—like Zoom and Microsoft Teams—have become more and more popular. Online meetings were not only used by businesses but also by educational institutes to carry out online learning, hospitals to conduct meetings and certain surgeries, and many other industries. The online meetings are practical and simple to organize, but their information security is not as high as that of conventional meetings. Security and privacy issues resulted from this. The safety of personal information such as names, contacts, and locations, the security of online recordings since sensitive information was discussed in most meetings, the security of data while it was in transit, and the potential for competitors to intercept your business were among the many security issues that were raised. Zoom, as one of the famous online conference systems, faced many global concerns, such as sharing private information with third parties, exposing users to unauthorized bullying calls, and adopting questionable end-to-end encryption processes. Additionally, companies have had virtual meetings hacked, leading to privacy issues since hackers can obtain data illegally. Therefore, this research proposes a security framework to address the privacy issues in the Zoom system by applying a set of governance and technical controls. The governance controls provide a strategic view of how an organization controls its security while implementing the technical controls avoids privacy issues in online conference systems. The proposed framework implements a set of technical controls such as encryption, auditing, authentication, and role-based access control. The results were promising and significantly addressed Zoom's privacy issues.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
解决 Zoom 会议系统隐私问题的安全框架
COVID-19 大流行对人类行为的许多方面产生了重大影响。最重要的是,它要求人们对日常活动的方式做出重大改变。由于社会关系的疏远,大多数人被迫在家工作和交流,这为更多的虚拟会议打开了大门。自从大多数企业开始允许员工在家办公以来,大多数在线会议平台(如 Zoom 和 Microsoft Teams)变得越来越流行。在线会议不仅被企业使用,还被教育机构用于开展在线学习、医院用于举行会议和某些手术,以及许多其他行业。在线会议实用性强,组织简单,但其信息安全性不如传统会议高。安全和隐私问题由此产生。姓名、联系人和地点等个人信息的安全问题,由于大多数会议都讨论敏感信息,在线录音的安全问题,数据在传输过程中的安全问题,以及竞争对手拦截业务的可能性等,都是人们提出的诸多安全问题。作为著名的在线会议系统之一,Zoom 面临着许多全球性的问题,如与第三方共享私人信息、使用户面临未经授权的霸王电话、采用可疑的端到端加密流程等。此外,还有公司的虚拟会议遭到黑客攻击,导致隐私问题,因为黑客可以非法获取数据。因此,本研究提出了一个安全框架,通过应用一套治理和技术控制措施来解决 Zoom 系统中的隐私问题。管理控制提供了一个组织如何控制其安全的战略视角,而技术控制的实施则避免了在线会议系统中的隐私问题。建议的框架实施了一套技术控制,如加密、审计、身份验证和基于角色的访问控制。结果很有希望,极大地解决了 Zoom 的隐私问题。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
Journal of Internet Services and Information Security
Journal of Internet Services and Information Security Computer Science-Computer Science (miscellaneous)
CiteScore
3.90
自引率
0.00%
发文量
0
审稿时长
8 weeks
期刊最新文献
Evaluating the Effectiveness of a Gan Fingerprint Removal Approach in Fooling Deepfake Face Detection CSA-Forecaster: Stacked Model for Forecasting Child Sexual Abuse A Nonredundant SVD-based Precoding Matrix for Blind Channel Estimation in CP-OFDM Systems Over Channels with Memory An Intelligent Health Surveillance System: Predictive Modeling of Cardiovascular Parameters through Machine Learning Algorithms Using LoRa Communication and Internet of Medical Things (IoMT) Identifying Large Young Hacker Concentration in Indonesia
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1