Why file sharing networks are dangerous?
M. Eric Johnson, Dan McGuire, Nicholas D. Willey · Communications of the ACM · 2009
applications for many users. With millions of users world-wide sharing music, video, software, and pictures 1, file movement on these networks represent a significant percentage of internet traffic. Beyond the much discussed copyright infringement issues, P2P networks threaten both corporate and individual security. Our research shows that confidential and potentially damaging documents have made their way onto these networks and continue to do so. The research also shows that criminals trawl P2P networks and opportunistically exploit information that they find. P2P file sharing represents a growing security threat because of the evolution of these networks. Internet service providers (ISPs), firms, and copyright holders have responded to the rise of P2P both technically (site blocking, traffic filtering and content poisoning 2) and legally. These challenges have prompted P2P developers to create decentralized, encrypted, anonymous networks that are difficult to track, are designed to accommodate large numbers of clients, and are capable of transferring vast amounts of data. We analyze the P2P security issues, establishing the vulnerabilities these software clients represent. Then we present experimental evidence of the risk through honeypot experiments that expose both business and personal financial information and track the resulting consequences. This analysis and experimental results clearly show the security risk of P2P file sharing networks. * We are grateful for the assistance of Tiversa Inc and Scott Dynes of the Center for Digital Strategies at the Tuck School. Experiments described in this paper were conducted in collaboration with Tiversa who has developed a patent pending technology that, in real-time, monitors global P2P file sharing networks. This work was supported under Award number 2000-DT-CX-K001 from the Office for Domestic Preparedness, Department of Homeland Security. Points of view in this document are those of the authors and do not necessarily represent the official position of the U.S. Department of Homeland Security.