#9unit 1online security and payment system

Security threats in e-commerce environment

The landscape of threats facing e-commerce systems.

Learning Objectives

  • Identify the three key points of vulnerability in e-commerce.
  • List the major categories of security threats to e-commerce.
  • Explain why each vulnerability point matters.
  • Outline the basic landscape of e-commerce security threats.

Explanation

E-commerce faces threats at three vulnerable points: the client (your device), the server (the merchant's site), and the communications pipeline (the network in between). Threats include malicious code, unwanted programs, phishing, hacking, fraud, spoofing, sniffing, insider attacks, and denial-of-service attacks.

From a technology perspective, there are three key points of vulnerability when dealing with e-commerce: the client, the server, and the communications pipeline. Each of these points can be attacked, and a typical e-commerce transaction (a consumer using a credit card to purchase a product) can be compromised at any of the three.

Common and damaging security threats to e-commerce consumers and site operators include: malicious code (viruses, worms, Trojans, ransomware, bots), potentially unwanted programs (PUPs) such as adware and spyware, phishing, hacking and cybervandalism, credit card fraud/theft, spoofing and pharming, spam (junk) websites, identity fraud, Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks, sniffing, insider attacks, poorly designed server and client software, social network security issues, mobile platform security issues, and cloud security issues.

Surveys of organizations show that the most prevalent types of attacks are viruses, worms, and Trojans (100% of surveyed companies), followed by malware, web-based attacks, botnets, phishing and social engineering attacks, and malicious code. The most costly cybercrimes were those caused by denial of service, malicious insiders, and malicious code.

Understanding this landscape is the first step toward defending e-commerce sites. The threats target different vulnerability points and require different defensive tools — from anti-virus software on clients, to firewalls on servers, to encryption on the communications pipeline. The following topics examine each major threat in more detail.

Key Points & Important Terms

Key Points

  • Three vulnerability points: client, server, communications pipeline.
  • Major threat categories: malicious code, PUPs, phishing, hacking, fraud, spoofing, sniffing, insider attacks, DoS/DDoS.
  • Most prevalent attacks: viruses, worms, Trojans, malware, botnets.
  • Most costly cybercrimes: denial of service, malicious insiders, malicious code.
  • Different threat types require different defenses (anti-virus, firewalls, encryption).
  • Threats target consumers, merchants, and the network between them.

Important Terms

Vulnerability point
A location in an e-commerce transaction where a security threat can strike — client, server, or communications pipeline.
Malicious code
Malware including viruses, worms, Trojan horses, ransomware, and bots.
PUP
Potentially unwanted program — installs itself on a computer, typically without the user's informed consent.
Phishing
Deceptive online attempt by a third party to obtain confidential information for financial gain.
Spoofing
Hiding a true identity by using someone else's e-mail or IP address.
DoS/DDoS
Denial of Service / Distributed Denial of Service attacks that flood a website with useless traffic to shut it down.