#9unit 1online security and payment system

Security threats in e-commerce environment

The landscape of threats facing e-commerce systems.

5-mark Exam Answer

5-mark answer

From a technology perspective, e-commerce has three key points of vulnerability — the client, the server, and the communications pipeline. Laudon and Traver identify many common and damaging security threats at each of these points.

  • 1.Three vulnerability points: client, server, communications
  • 2.Malicious code and PUPs
  • 3.Phishing, hacking, cybervandalism
  • 4.Credit card fraud, spoofing, sniffing
  • 5.Insider attacks, DoS/DDoS, identity fraud

From a technology perspective, there are three key points of vulnerability when dealing with e-commerce: the client, the server, and the communications pipeline. A typical e-commerce transaction (a consumer using a credit card to purchase a product) can be compromised at any of these points.

Common security threats to e-commerce consumers and site operators include malicious code (viruses, worms, Trojans, ransomware, bots), potentially unwanted programs (PUPs such as adware and spyware), phishing, hacking and cybervandalism, credit card fraud/theft, spoofing and pharming, spam websites, identity fraud, Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, sniffing, and insider attacks.

Other threats include poorly designed server and client software (with vulnerabilities like SQL injection and zero-day exploits), social network security issues, mobile platform security issues, and cloud security issues.

Surveys of organizations show that the most prevalent attacks are viruses, worms, and Trojans (100% of surveyed companies), followed by malware, web-based attacks, botnets, phishing, and malicious code. The most costly cybercrimes were those caused by denial of service, malicious insiders, and malicious code.

In a credit-card purchase, a keylogger on the client captures the card number, a sniffer on the network intercepts it in transit, and a hacker breaches the server to steal stored cards — each threat at a different vulnerability point.

The e-commerce security environment is broad, with threats targeting three vulnerable points. Understanding this landscape is the first step toward defending e-commerce systems with appropriate technical and procedural controls.

vulnerability pointsmalicious codephishingspoofingsniffingDoS/DDoS

The exam interface follows the university paper pattern: Section A & B carry 5-mark questions; Section C carries objective questions.