Home > Published Issues > 2026 > Volume 17, No. 7, 2026 >
JAIT 2026 Vol.17(7): 1345-1355
doi: 10.12720/jait.17.7.1345-1355

Modelling Security Threats of Live Streaming Monetization Pipelines

Emil Eminov 1 and Stephen Flowerday 2,*
1. School of Cyber Studies, University of Tulsa, Tulsa, USA
2. Department of Information Systems and Security, Augusta University, Augusta, USA
Email: eae5331@utulsa.edu (E.E.); sflowerday@augusta.edu (S.F.)
*Corresponding author

Manuscript received March 2, 2026; revised March 25, 2026; accepted May 18, 2026; published July 23, 2026.

Abstract—Live-streaming platforms increasingly turn real-time payments, including cheers, Bits, gifts, and highlighted chat, into public signals of status and support. This article examines anomalous cheering as a security problem across the full monetization pipeline, asking how unusual spikes in volume, value, timing, or attribution can be related to system assets, trust boundaries, and controls. We develop a reference data-flow model of a monetized cheering pipeline and apply Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE) to each system element across identity, payments, wallet and ledger services, event streaming, anomaly detection, and trust and safety operations. A simple ordinal Damage Potential, Reproducibility, Exploitability, Affected Users, and Discoverability (DREAD) rubric is used for prioritization, with a worked example showing how one spike can support several competing hypotheses. The analysis highlights five recurring risks: scalable identity abuse and account takeover, payment and ledger exploitation, replay or duplication of canonical events, latency-sensitive denial of service, and misuse of privileged detection or enforcement tools. The paper concludes that monetized cheering should be protected as an end-to-end pipeline, with safeguards placed at the relevant trust boundaries: server-side event generation, idempotency and replay resistance, adaptive throttling, graceful degradation, tamper-evident audit trails, privacy-aware measurement, and least-privilege operational access.
 
Keywords—threat modelling; Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE); Damage, Reproducibility, Exploitability, Affected Users, and Discoverability (DREAD); live streaming security; monetization fraud; anomaly detection; trust and safety

Cite: Emil Eminov and Stephen Flowerday, "Modelling Security Threats of Live Streaming Monetization Pipelines," Journal of Advances in Information Technology, Vol. 17, No. 7, pp. 1345-1355, 2026. doi: 10.12720/jait.17.7.1345-1355

Copyright © 2026 by the authors. This is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited (CC BY 4.0).

Article Metrics in Dimensions