The design and implementation of a security plug-in for Learning Management Systems is presented. The plug-in (called IBS) can help in protecting a Leaning Management System from a varied selection of threats, carried on by malicious users via internet. Nowadays it is quite likely that the installer and/or administrator of a system are interested teachers, rather than skilled technicians. This is not a problem from the point of view of user friendliness and ease of use of the systems functionalities; those are actually features that motivate the widespread adoption of both proprietary and open source web-based learning systems. Yet, as any other web application, learning systems are subject to seamless discovery and publication of security weaknesses buried into their code. Accordingly, such systems present their administrators with apparent needs for continuous system upgrade and patches installation, which may turn out to became quite a burden for teachers. The integration of IBS in a system allows easing the above mentioned needs and can help the teachers to focus their work more on the pedagogical issues than on the technical ones. We report on the present integration of IBS in two well established open source Learning Management Systems (Moodle and Docebo), allowing for a reasonably standing protection from the threats comprised in five well known classes of "attacks". Besides describing the plug-in definition and functionalities, we focus in particular on the specification of a whole protocol, devised to guide the adaptation and installation of IBS in any other php-based learning system, which makes the applicability of the plug-in sufficiently wide. © 2011 Springer-Verlag Berlin Heidelberg.

IBS: Intrusion block system a general security module for elearning systems / Alessio, Conti; Sterbini, Andrea; Temperini, Marco. - STAMPA. - 167 CCIS:PART 2(2011), pp. 494-503. (Intervento presentato al convegno International Conference on Digital Information and Communication Technology and Its Applications, DICTAP 2011 tenutosi a Dijon nel 21 June 2011 through 23 June 2011) [10.1007/978-3-642-22027-2_41].

IBS: Intrusion block system a general security module for elearning systems

STERBINI, Andrea;TEMPERINI, Marco
2011

Abstract

The design and implementation of a security plug-in for Learning Management Systems is presented. The plug-in (called IBS) can help in protecting a Leaning Management System from a varied selection of threats, carried on by malicious users via internet. Nowadays it is quite likely that the installer and/or administrator of a system are interested teachers, rather than skilled technicians. This is not a problem from the point of view of user friendliness and ease of use of the systems functionalities; those are actually features that motivate the widespread adoption of both proprietary and open source web-based learning systems. Yet, as any other web application, learning systems are subject to seamless discovery and publication of security weaknesses buried into their code. Accordingly, such systems present their administrators with apparent needs for continuous system upgrade and patches installation, which may turn out to became quite a burden for teachers. The integration of IBS in a system allows easing the above mentioned needs and can help the teachers to focus their work more on the pedagogical issues than on the technical ones. We report on the present integration of IBS in two well established open source Learning Management Systems (Moodle and Docebo), allowing for a reasonably standing protection from the threats comprised in five well known classes of "attacks". Besides describing the plug-in definition and functionalities, we focus in particular on the specification of a whole protocol, devised to guide the adaptation and installation of IBS in any other php-based learning system, which makes the applicability of the plug-in sufficiently wide. © 2011 Springer-Verlag Berlin Heidelberg.
2011
International Conference on Digital Information and Communication Technology and Its Applications, DICTAP 2011
docebo; lfi; lms; lms security; moodle; rce; rfi; sqli; xss
04 Pubblicazione in atti di convegno::04b Atto di convegno in volume
IBS: Intrusion block system a general security module for elearning systems / Alessio, Conti; Sterbini, Andrea; Temperini, Marco. - STAMPA. - 167 CCIS:PART 2(2011), pp. 494-503. (Intervento presentato al convegno International Conference on Digital Information and Communication Technology and Its Applications, DICTAP 2011 tenutosi a Dijon nel 21 June 2011 through 23 June 2011) [10.1007/978-3-642-22027-2_41].
File allegati a questo prodotto
File Dimensione Formato  
VE_2011_11573-411485.pdf

solo gestori archivio

Tipologia: Versione editoriale (versione pubblicata con il layout dell'editore)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 2.18 MB
Formato Adobe PDF
2.18 MB Adobe PDF   Contatta l'autore

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/411485
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 2
  • ???jsp.display-item.citation.isi??? 2
social impact