{"title":"Improving The Security of E-Exam Systems","authors":"Fatema Alnasser, A. Elrashidi","doi":"10.1109/ITIKD56332.2023.10100104","DOIUrl":null,"url":null,"abstract":"Though e-exams have their advantages like accuracy and speed reduced human intervention, there are some flaws as well. These flaws are security threats, the same way as traditional exams are exposed to them such as cheating or unauthorized access. Furthermore, e-exams are also exposed to threats like impersonation and tampering or accessing exam related data and information on servers. As a result, there is a need to establish a strong security framework within the e-exam system that universities adopt, such that smooth and timely conduction of exams can take place. The present study deals with such security threats of e-exam systems and provides a solution by proposing a new security framework, to deal with these threats. Based on the primary data, a security framework of e-exam system was proposed at university levels. This security model aimed to mitigate the threats determined during the survey, along with the strategies and system requirements suggested by the survey respondents. The proposed framework provides security at two levels. Firstly, at the university level using biometric authentication and user login authentication. The second level was the cloud level, where four security methods (encryption, anti-X, security system access and SQL injection) were added to secure the data in the cloud (application server side). Further it is suggested in the model to use Infrastructure as a service (IaaS) for cloud computing because of its various advantages and security options which have been discussed in the model.","PeriodicalId":283631,"journal":{"name":"2023 International Conference on IT Innovation and Knowledge Discovery (ITIKD)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-03-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 International Conference on IT Innovation and Knowledge Discovery (ITIKD)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ITIKD56332.2023.10100104","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Though e-exams have their advantages like accuracy and speed reduced human intervention, there are some flaws as well. These flaws are security threats, the same way as traditional exams are exposed to them such as cheating or unauthorized access. Furthermore, e-exams are also exposed to threats like impersonation and tampering or accessing exam related data and information on servers. As a result, there is a need to establish a strong security framework within the e-exam system that universities adopt, such that smooth and timely conduction of exams can take place. The present study deals with such security threats of e-exam systems and provides a solution by proposing a new security framework, to deal with these threats. Based on the primary data, a security framework of e-exam system was proposed at university levels. This security model aimed to mitigate the threats determined during the survey, along with the strategies and system requirements suggested by the survey respondents. The proposed framework provides security at two levels. Firstly, at the university level using biometric authentication and user login authentication. The second level was the cloud level, where four security methods (encryption, anti-X, security system access and SQL injection) were added to secure the data in the cloud (application server side). Further it is suggested in the model to use Infrastructure as a service (IaaS) for cloud computing because of its various advantages and security options which have been discussed in the model.