{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:16:15Z","timestamp":1781104575691,"version":"3.54.1"},"reference-count":43,"publisher":"IGI Global Scientific Publishing","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016,10]]},"abstract":"<jats:p>Massive Open Online Courses (MOOCs) are commonly hosted as web servers for learners worldwide to access education and learning materials at low cost. Many of the well-known MOOCs have adopted open source software and database technologies and frequently operate within cloud environments. It is likely that the well-known software security vulnerabilities may manifest to MOOC-based applications. Unfortunately, few studies have identified a set of common vulnerabilities applicable to MOOC-based applications. This paper1 presents an exploratory study of potential security vulnerabilities and challenges for MOOC platforms, and it provide some guidelines and suggestions to mitigate these concerns. This study helps practitioners (educators and developers) to adopt MOOC applications while considering potential vulnerabilities and be prepared to deal with these risks.<\/jats:p>","DOI":"10.4018\/ijsse.2016100101","type":"journal-article","created":{"date-parts":[[2017,1,25]],"date-time":"2017-01-25T11:02:08Z","timestamp":1485342128000},"page":"1-18","source":"Crossref","is-referenced-by-count":1,"title":["Survey of Vulnerabilities and Mitigation Techniques for Mooc-Based Applications"],"prefix":"10.4018","volume":"7","author":[{"given":"Hossain","family":"Shahriar","sequence":"first","affiliation":[{"name":"Department of Information Technology, Kennesaw State University, Marietta, Georgia, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hisham M.","family":"Haddad","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Kennesaw State University, Marietta, Georgia, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"David","family":"Lebron","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Kennesaw State University, Marietta, Georgia, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rubana","family":"Lupu","sequence":"additional","affiliation":[{"name":"Department of Information Technology, Kennesaw State University, Marietta, Georgia, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"IJSSE.2016100101-0","unstructured":"Abrams, R. (2013). Microsoft Takes Scammers To CAMP. Retrieved from https:\/\/www.nsslabs.com\/sites\/default\/files\/public-report\/files\/Microsoft%20Takes%20Scammers%20To%20CAMP_0.pdf"},{"key":"IJSSE.2016100101-1","unstructured":"Abrams, R., Pathak, J., Barrera, O., & Ghimire, D. (2014). Browser Security Comparative Analysis. Retrieved from https:\/\/www.nsslabs.com\/sites\/default\/files\/public-report\/files\/Browser%20Security%20Comparative%20Analysis%20-%20Socially%20Engineered%20Malware.pdf"},{"key":"IJSSE.2016100101-2","unstructured":"Anti-Phishing Working Group (APWG). (2016). Accessed from http:\/\/www.antiphishing.org"},{"key":"IJSSE.2016100101-3","unstructured":"Apache.org. (2016). The Apache Cassandra Project. Retrieved from http:\/\/cassandra.apache.org"},{"key":"IJSSE.2016100101-4","unstructured":"Application Vulnerability Trends Report. (2014). Retrieved from https:\/\/www.info-point-security.com\/sites\/default\/files\/cenzic-vulnerability-report-2014.pdf"},{"key":"IJSSE.2016100101-5","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2016.2546228"},{"key":"IJSSE.2016100101-6","unstructured":"Cloud Security Alliance. (2013). The Notorious Nine Cloud Computing Top Threats in 2013. Retrieved from https:\/\/downloads.cloudsecurityalliance.org\/initiatives\/top threats\/The Notorious Nine Cloud Computing Top Threats_in_2013.pdf"},{"key":"IJSSE.2016100101-7","doi-asserted-by":"publisher","DOI":"10.1145\/2567574.2567586"},{"key":"IJSSE.2016100101-8","unstructured":"Coursera. (2016). Retrieved from https:\/\/www.coursera.org"},{"key":"IJSSE.2016100101-9","first-page":"1","author":"J.Daries","year":"2014","journal-title":"Privacy, Anonymity, and Big Data in the Social Sciences"},{"key":"IJSSE.2016100101-10","unstructured":"EdX. (2016). Retrieved from https:\/\/www.edx.org"},{"key":"IJSSE.2016100101-11","unstructured":"Emma, C., & Pro, P. (2014). Online education run amok? Private companies want to scoop up your child\u2019s data, Accessed from http:\/\/www.politico.com\/story\/2014\/11\/online-education-run-amok-113208.html"},{"key":"IJSSE.2016100101-12","unstructured":"Ferber, M. (2014). The Notorious Nine: Cloud Computing threats for 2014. Retrieved from http:\/\/www.meetup.com\/IGTCloud\/events\/160678562\/"},{"key":"IJSSE.2016100101-13","unstructured":"Fidelis Cybersecurity. (2014), Current Data Security Issues of NoSQL Databases. Retrieved from http:\/\/www.fidelissecurity.com\/files\/NDFInsightsWhitePaper.pdf"},{"key":"IJSSE.2016100101-14","unstructured":"Goodin, D. (2012). Virtual machine used to steal crypto keys from other VM on same server. Retrieved from http:\/\/arstechnica.com\/security\/2012\/11\/crypto-keys-stolen-from-virtual-machine"},{"key":"IJSSE.2016100101-15","doi-asserted-by":"publisher","DOI":"10.1145\/2556325.2566239"},{"key":"IJSSE.2016100101-16","doi-asserted-by":"crossref","unstructured":"Hodges, J., Jackson, C., & Barth, A. (2012). HTTP Strict Transport Security (HSTS). Retrieved from https:\/\/tools.ietf.org\/html\/rfc6797","DOI":"10.17487\/rfc6797"},{"key":"IJSSE.2016100101-17","unstructured":"Hogben, G., & Dekker, M. (2010). Information security risks, opportunities and recommendations for users, Enisa. Retrieved from https:\/\/www.enisa.europa.eu\/activities\/identity-and-trust\/risks-and-data-breaches\/smartphones-information-security-risks-opportunities-and-recommendations-for-users\/at_download\/fullReport"},{"key":"IJSSE.2016100101-18","first-page":"69","article-title":"Visual Analytics for MOOC data.","author":"Q.Hu","year":"2015","journal-title":"Proc. of IEEE Computer Graphics and Applications"},{"key":"IJSSE.2016100101-19","doi-asserted-by":"publisher","DOI":"10.1145\/2554850.2555010"},{"key":"IJSSE.2016100101-20","unstructured":"Kirkpatrick, D. (2013). Mongodb - Security Weaknesses in a typical NoSQL database, [Online] Available: https:\/\/www.trustwave.com\/Resources\/SpiderLabs-Blog\/Mongodb---Security-Weaknesses-in-a-typical-NoSQL-database\/"},{"key":"IJSSE.2016100101-21","doi-asserted-by":"crossref","unstructured":"Kumaraguru, P., Rhee, Y., Sheng, S., Hasan, S., Acquisti, A., Cranor, L., & Hong, J. (2007). Getting Users to Pay Attention to Anti-Phishing Education: Evaluation of Retention and Transfer. Proceedings of the APWG eCrime Researchers Summit, Pittsburgh, PA, USA (pp. 70-81).","DOI":"10.1145\/1299015.1299022"},{"key":"IJSSE.2016100101-22","doi-asserted-by":"publisher","DOI":"10.1109\/CTS.2015.7210417"},{"key":"IJSSE.2016100101-23","doi-asserted-by":"publisher","DOI":"10.1109\/ICITST.2015.7412075"},{"key":"IJSSE.2016100101-24","unstructured":"MongoDB. (2016). Retrieved from https:\/\/www.mongodborg"},{"key":"IJSSE.2016100101-25","unstructured":"MongoDB Security Concept. (2016). Retrieved from http:\/\/docs.mongodb.org\/master\/core\/security\/"},{"key":"IJSSE.2016100101-26","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom.2011.70"},{"key":"IJSSE.2016100101-27","unstructured":"OWASP Cross-site Scripting. (2016). Retrieved from https:\/\/www.owasp.org\/index.php\/Cross-site_Scripting_%28XSS%29"},{"key":"IJSSE.2016100101-28","unstructured":"Page, D. (2005). Partitioned Cache Architecture as a Side-Channel Defence Mechanism. IACR. Retrieved from http:\/\/eprint.iacr.org\/2005\/280"},{"key":"IJSSE.2016100101-29","unstructured":"Pass-Through Authentication. (2016). Retrieved from https:\/\/msdn.microsoft.com\/en-us\/library\/ms813076.aspx"},{"key":"IJSSE.2016100101-30","unstructured":"PHP Prepared Statement and Stored Procedure (2016). Retrieved from http:\/\/php.net\/manual\/en\/pdo.prepared-statements.php"},{"key":"IJSSE.2016100101-31","unstructured":"PHPCassa. (2016). Accessed from http:\/\/thobbs.github.io\/phpcassa\/tutorial.html"},{"key":"IJSSE.2016100101-32","doi-asserted-by":"publisher","DOI":"10.1109\/CICSyN.2012.50"},{"key":"IJSSE.2016100101-33","doi-asserted-by":"publisher","DOI":"10.1145\/2669711.2669914"},{"key":"IJSSE.2016100101-34","doi-asserted-by":"publisher","DOI":"10.1145\/2500876"},{"key":"IJSSE.2016100101-35","unstructured":"Seltzer, L. (2013). Spoofing Server-Server Communication How You can Prevent It. Retrieved from http:\/\/www.verisign.com\/ssl\/ssl-information-center\/ssl-resources\/whitepaper-ev-prevent-spoofing.pdf"},{"key":"IJSSE.2016100101-36","unstructured":"Soap UI. (2016). XML Bomb. Retrieved from https:\/\/www.soapui.org\/security-testing\/security-scans\/xml-bomb.html"},{"key":"IJSSE.2016100101-37","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2012.1"},{"key":"IJSSE.2016100101-38","unstructured":"Udacity (2016). Retrieved from https:\/\/www.udacity.com"},{"key":"IJSSE.2016100101-39","unstructured":"US Department of Education, Family Educational Rights and Privacy Act (FERPA). (2016). Retrieved from http:\/\/www2.ed.gov\/policy\/gen\/guid\/fpco\/ferpa\/index.html"},{"key":"IJSSE.2016100101-40","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382230"},{"key":"IJSSE.2016100101-41","doi-asserted-by":"crossref","DOI":"10.1145\/2382196.2382230","article-title":"CrosVM Side Channels and Their Use to Extract Private Keys.","author":"Y.Zhang","year":"2012","journal-title":"Proc. of ACM Computer and Communications Security (CCS)"},{"key":"IJSSE.2016100101-42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33469-6_30"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=176398","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,14]],"date-time":"2025-06-14T15:53:11Z","timestamp":1749916391000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJSSE.2016100101"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2016,10]]},"references-count":43,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.4018\/ijsse.2016100101","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,10]]}}}