✔ Problem with 10 second, 1 page sessions
Completed by Morgan M.
- Assigned to
-
Harsh P.
Jitesh D.
Ryan K.
- Notes
-
Further to the problem we experienced previously: https://basecamp.com/2341283/projects/12196005/todos/271259648. We are starting to see accounts generate suspicious usage with 10 second, 1 page sessions (see examples below - many are the same accounts where we saw the problems appear before). Note as well that the frequency of these 10 second, 1 page sessions started occurring more frequently in September. Please ensure that the domain validations are still working, and that we're not compromising usage data going forward.
Examples of 10 second, 1 page sessions:- University of Oxford: https://www.investorstatelawguide.com/subscribers/ShowGroupSession?grpId=241
- Singapore Management University: https://www.investorstatelawguide.com/subscribers/ShowGroupSession?grpId=150
- National University of Singapore: https://www.investorstatelawguide.com/subscribers/ShowGroupSession?grpId=266
- University of Melbourne: https://www.investorstatelawguide.com/subscribers/ShowGroupSession?grpId=250
- McGill University: https://www.investorstatelawguide.com/subscribers/ShowGroupSession?grpId=289
- Université Laval: https://www.investorstatelawguide.com/subscribers/ShowGroupSession?grpId=403
- University of Chicago: https://www.investorstatelawguide.com/subscribers/ShowGroupSession?grpId=706
- University of Victoria: https://www.investorstatelawguide.com/subscribers/ShowGroupSession?grpId=196
Note that the domain URL is peacepalacelibrary.nl; however, we should add ppl.nl as well.
| Subscriber | Domain URLs
| Georgetown University | georgetown.edu
| Gujarat National Law University | gnlu.ac.in
| Peace Palace Library | peacepalacelibrary.nl
| Universidad de San Andrés | udesa.edu.ar/
| University of Vienna | univie.ac.at/en/
Thanks,
Morgan
For account Pace Palance Library, We had validated peacepalacelibrary.nl domain URL.
Today, We have also validated the ppl.nl domain URL. so, please monitoring the session usage of Pace Palance Library acount and let us know the feedback.
Thank you for adding the additional URL for the Peace Palace Library account. We will monitor usage, and let you know if there is any change.
In the meantime, is there anything we can do to test the validation system to ensure it is working properly, because the issue appears to be widespread across multiple accounts where there is no ambiguity about the domain URLs?
Thanks,
Morgan
Do you check the session usage of the Peace Palace Library account ?
We are not able to test the Proxy URLs session usage directly from our environment. We also don't have any login credentials in our local environment. we need remote session to check the issue.
Please suggest.
Below is the latest usage report from the Peace Palace account, which appears to have normalized somewhat. However, I'm still concerned about the usage for all other accounts above.
How do you suggest we resolve the problem.
Thanks,
Morgan
It seems that the problem is because of multiple URLs are used by users which are not validated by our system. Hence, it would be great if we can confirm with the above universities whether they are using other URLs too which are not registered in our system. If problem persists then we might need user credentials or need to take remote session of their environment to figure out the issue.
We'll confirm whether other domain URLs are necessary for the accounts above, and if that doesn't resolve the problem we'll setup sessions with the users.
Thanks,
Morgan
I sent out an email last week about this, I didn't hear back from any of the 5 you requested however. I will send followups today.
Liam
Morgan
Georgetown University provided us with the following URL for their EzProxy server: http://proxygt-law.wrlc.org/. How do you suggest we use this to validate the appropriate domaine URLs. Should we just use wrlc.org to ensure we cover any proxy server accessing the system via Washington Research Library Consortium proxy server? Perhaps you could explain a little more how this validation system works, so that we can ensure we're providing you with the appropriate information.
Thanks,
Morgan
We have checked Georgetown University's Proxy URL in our database and it was georgetown.edu which is totally different from above Proxy URL.so, We have also validated above Proxy URLs (wrlc.org) in our database.
Yes. We can ensure that we cover any proxy server accessing by validating the wrlc.org
We have stored all Proxy URLs in one table in our database. If Our database Proxy URLs will match the contains with entered Proxy URLs then it will be validated.
For Georgetown University case, Our Database Proxy URL is georgetown.edu. Hence, it was not validated with Proxy URL http://proxygt-law.wrlc.org/.
Attached is an updated list of proxy URLs. New URLs are highlighted in green. Please make the appropriate updates, and we'll continue to collect the additional URLs from the other clients. Note that I've added the wrlc.org URL to all the schools that are members of that consortium.
We'll continue to monitor these accounts with updated URLs, and see if this fixes the problem.
Thanks,
Morgan
We have added and Validated green Marked Proxy URLs in our www.islg database.
I'll continue to monitor usage to see if there is improvement. So far the accounts for the Peace Palace Library and Georgetown University appear to have normalized.
Thanks,
Morgan
Could you please follow-up again with the following:
Thanks,
Morgan
I've reactivated this to-do, because we have some accounts that have been showing persistent anomalous usage the last few months, and I'd like to get it resolved. The accounts with problems are the following:
However, this hasn't resolved the problem. Is there anything further we can do to resolve this issue on these accounts?
Thanks,
Morgan
We have tried to reproduce the above issue in our local environment with using above accounts IP address but it is working fine.
We have again validate above accounts with common word on www.islg
(for ex. If proxy URL is nujs.edu then we have checked word nujs and if word will be found then it will be valid.)
Hence, Please monitor above URLs for 2 to 3 days and still problem is running then we need to take remote session any of above account to find out the root of this problem.
Please Suggest.
Morgan
I've reviewed the usage on the accounts above, and here are the results:
Thanks,
Morgan
For Renmin University of China, I have updated Proxy URL with only "ruc". Hence, any of URL they used, If it contains "ruc" in URL then it will be validated.
Please monitor this account for 2 to 3 days.
In the meantime,
Morgan
Further to the comments above, there is a problem with significant anomalous usage on the Renmin University account: https://www.investorstatelawguide.com/subscribers/ShowGroupSession. Over the past few weeks there have been thousands of sessions from hundreds of different IP address ranges. This is very suspicious usage, so I have deactivated their accounts (their account expired today as well).
Assuming they decide to renew their account, we will need them to confirm their IP address ranges, and ensure that this only granting access to legitimate users from the University. The starting point is to establish direct contact with someone at the University. Looking through the correspondence, I don't see a record of any direct contact with someone at Renmin University. All correspondence has been with a subscription agent at CEPIEC (China Educational Publications Import & Export Corporation). In fact, looking at the SA signed last April, it appears it was signed by someone at CEPIEC, rather than by someone at Remnin University.
This is unacceptable. It needs to signed by someone at the University. Let's ensure all these issues get resolved before the account gets reactivated, and ensure that we are addressing these issues with other subscribers that were setup through a subscription agent (particularly in China).
Thanks,
Morgan
Marysia
With the exception of the Renmin University and West Bengal National University accounts, which were deactivated for other reasons, the usage for the other accounts appears to have normalized, so I'll close this to-do again for the time being.
Thanks,
Morgan