Securing Live Music Festival Broadcast Streams Against Hijacking.
Many large-scale music festivals now provide a live streaming package that is available for those unable to attend because the event is sold out, or they are based overseas. Whist some of these are offered as a free to use service, other organisers may charge a nominal fee for access. What can organisers do to protect their live streaming broadcasts from being hijacked.
A live stream broadcast from a music festival provides additional engagement with online audiences, and in some cases provides a valuable revenue stream too. Criminal networks do sometimes target these live streams, so it can present a significant cybersecurity risk for organisers as well as resulting in reputational damage.
Common Occurrences.
A criminal network that hacks into a live stream may be able to replace the broadcast with other content or simply interrupt the feed. Other common incidents may involve redirecting viewers or redistributing the festival's content as an unauthorised (stolen) feed. Attackers usually focus on obtaining the broadcaster credentials, stream keys, encoder access or distribution tokens for example. The weakest security aspect of any live stream broadcast is usually staff credentials or unauthorised access to production or contractor laptops where these assets can be stolen without the need for an external hack.
Robust Set Up.
Festival organisers commonly use external contractors to manage any live broadcasting stream, but they should ensure that a supplier can be trusted to deliver a secure solution. Typical checks may include numerous technical aspects that should be confirmed before appointing them. The contractor should be able to demonstrate a resilient broadcast architecture with built in redundancy using secondary encoders, secure internet connections with secondary streaming provider capability, for example. There should be secure connections between the festival production environment and the streaming platform with unique credentials for each event. Encoder access should only be given to trusted authorised personnel with unused or expired encoder access being deleted. Some streams can be given short-lived signed tokens which help to restrict access by user, duration and other relevant conditions. The server that provides the content should always be protected by a secure distribution layer typically consisting of the production encoder, a secure ingest environment plus a CDN/security layer, for example. Organisers should be wary of contractors who need to integrate APIs with the festival ticketing and CRM platforms for payment or authentication systems with the streaming platform because these can present significant security risks.
Monitoring.
Once the live stream broadcast has been set up with all the necessary security protocols, it needs to be monitored in real time during the event. This cybersecurity monitoring can be automated to check the broadcast and the IT infrastructure for unexpected changes to the stream source. Other factors that can be set up to be monitored can include encoder disconnections, sudden changes in bitrate, abnormal viewer spikes, unexpected administrator logins, repeated failed authentication or simultaneous sessions using the same token, for example. Should any of these incidents occur, the broadcasting contractor and festival production management team should be alerted immediately so that they can take the appropriate actions.
Operational Live Streaming Hijacking Protocols.
Organisers and broadcast contractors should have a documented emergency procedure for any hijacking incidents that may occur. A practical plan should clearly identify and verify a hijacking incident and proceed to isolate the occurrence. The verification process should identify if it is a genuine hijacking attempt or just a technical glitch, and during this phase it may be necessary to disconnect the compromised encoder or account until the incident has been investigated. If it is established that an attack has taken place, then any affected tokens and credentials should be immediately revoked. Organisers can consider switching the broadcast stream to a backup encoder or distribution gateway with a pre-prepared holding message for all viewers. If necessary, it may help to preserve any logs as evidence should there be a follow up criminal investigation. After any incident it will be prudent to thoroughly investigate how any compromise occurred so that future broadcasts can have improved protection.
For festival organisers planning their next event using a software management platform like Festival Pro gives them all the functionality they need manage every aspect of their event logistics. The guys who are responsible for this software have been in the front line of event management for many years and the features are built from that experience and are performance artists themselves. The Festival Pro platform is easy to use and has comprehensive features with specific modules for managing artists, contractors, venues/stages, vendors, volunteers, sponsors, guestlists, ticketing, site planning, cashless payments and contactless ordering.
Image by Max Ravier via Pexals
<< Back to articles
Contact us
Get in touch to discuss your requirements.
US: +1 424 485 0220 (USA)
UK: +44 207 060 2666 (United Kingdom)
AU: +61 (2) 8357 0793 (Australia)
NZ: +64 (0)9887 8005 (New Zealand)