THREAT MODEL FOR USER SECURITY IN E-LEARNING SYSTEMS

This paper suggest a generic threat model for the processes in e-learning systems. After a breaf discussion of the particularities of e-learning systems from the security point of view, the role of threat models in system security is explained. Then a characterization of the attackers is made, together with the assets and entry points identification and threats identification and classification. The most probable attacks for e-learning system are described regardless of the specific implementation, to help the e-learning system developers to eliminate or mitigate these attacks if possible in the design stage not waiting for actual attacks to occur.