IT204 E Commerce

E CommerceUnit 412 min read

E-Commerce Security & Risk Management: Threats, Safeguards & Real-World Cases

Unit 4 of E-Commerce explores cybersecurity risks in digital transactions, encryption methods, fraud prevention, and compliance frameworks—with Nepalese examples like eSewa hacks and Kathmandu traffic route optimization for delivery logistics.

TAKEAWAYS:

  • Security triad: Confidentiality, integrity, and availability (CIA) are the core pillars of e-commerce protection, enforced via encryption and access controls.
  • Payment risks: Fraud, data breaches, and chargebacks plague electronic payment systems (e.g., Khalti’s 2022 ₹1.2B loss to scams).
  • Technical safeguards: SSL/TLS, firewalls, and multi-factor authentication (MFA) are non-negotiable for secure transactions.
  • Legal frameworks: Laws like Nepal’s Electronic Transactions Act 2008 and GDPR (for global e-commerce) mandate data protection and liability clauses.
  • Supply chain threats: Logistics vulnerabilities (e.g., Daraz’s delayed deliveries due to cyberattacks on couriers) require end-to-end encryption and GPS tracking.
  • Human factor: Social engineering (phishing, vishing) accounts for 90% of breaches—training is as critical as tech.

1. Defining E-Commerce Security: Beyond Passwords

E-commerce security isn’t just about passwords or antivirus software. It’s a multi-layered defense system protecting:

  • Customer data (credit cards, addresses, browsing history).
  • Business operations (inventory systems, order processing).
  • Reputation (trust is the currency of e-commerce).
2008 BSElectronicTransactions Act (Nepa2015 BSPCI-DSS ComplianceMandate2022 BSNepal Rastra BankCybersecurity Guidelin
Key legal milestones in Nepal's e-commerce security framework

The CIA Triad: The Security Foundation

mindmap
  root((CIA Triad))
    Confidentiality
      "Data encryption (AES-256)"
      "Access controls (Role-Based)"
      "Example: eSewa’s end-to-end encryption"
    Integrity
      "Hashing (SHA-256)"
      "Digital signatures"
      "Example: Ncell’s SMS verification"
    Availability
      "DDoS protection"
      "Redundant servers"
      "Example: Daraz’s cloud backup during load spikes"

2. Key Dimensions of E-Commerce Security

The syllabus highlights five critical dimensions (pick 3 for exams):

Dimension What It Protects Real-World Example (Nepal) How It Works
Payment Security Financial transactions Khalti’s tokenization (replaces card numbers with tokens) PCI-DSS compliance, 3D Secure (3DS) authentication
Data Privacy Customer PII (Personally Identifiable Information) NTC’s collection of user location data for billing GDPR/Nepal’s Data Privacy Act 2018, anonymization
System Security Infrastructure (servers, networks) Pathao’s use of AWS Shield against DDoS attacks Firewalls, intrusion detection systems (IDS)
Supply Chain Security Logistics and inventory Daraz’s GPS-tracked deliveries with tamper-proof packaging Blockchain for provenance, RFID tags
Legal & Compliance Regulatory adherence NEPSE’s KYC (Know Your Customer) for online trading Electronic Transactions Act 2008, liability clauses

WORKED EXAMPLE: eSewa’s Security Model

  1. User logs in → MFA (OTP + fingerprint).
  2. Payment initiated → Token replaces card details (never stored).
  3. Transaction processed → AES-256 encrypts data in transit.
  4. Confirmation sent → Digital signature verifies sender (eSewa). Risk mitigated: Even if hackers breach the system, they get useless tokens and no raw data.

3. Threats to E-Commerce: A Nepalese Perspective

Not all risks are global—some are hyper-local. Here’s what keeps Nepalese e-commerce executives up at night:

A. Payment System Risks

Khalti Scams (2022)eSewa Phishing LinksFraudulent TransactionsDaraz Returns FraudChargebacksNcell Customer Data LeakData BreachesFake Merchant RegistrationIdentity TheftPayment System Risks in Nepal
Hierarchy of payment risks with Nepal-specific examples
  • Fraud: Fake merchant sites (e.g., "Daraz Clone" scams) or card-not-present (CNP) fraud.
  • Chargebacks: Customers disputing transactions (common in Nepal’s high-return culture).
  • Data Breaches: 2021 saw 1.5M Khalti users’ data leaked via a third-party vendor.

B. Supply Chain Vulnerabilities

Risk Example (Nepal) Mitigation
Theft/Damage Courier vans robbed in Kathmandu (2023) GPS tracking, tamper-evident seals
Counterfeit Goods Fake medicines on Daraz Blockchain verification (e.g., Medicines Board Nepal)
Delayed Deliveries Monsoon floods disrupting Pathao riders Dynamic routing algorithms, insurance

WORKED EXAMPLE: Daraz’s Anti-Counterfeit Strategy

  1. Seller verification: Requires PAN card + business license for high-value items.
  2. Blockchain ledger: Each product gets a unique QR code traceable to origin.
  3. Customer reporting: One-click flag for suspicious items → AI review. Result: 40% drop in fake electronics in 2023.

4. Technical Safeguards: Tools of the Trade

A. Encryption: The Invisible Shield

sequenceDiagram
    participant User
    participant Server
    participant Hacker
    User->>Server: Credit Card (Unencrypted)
    Server->>Server: TLS 1.3 Encryption
    Server-->>User: Success (Encrypted)
    Hacker->>Server: Attack Attempt
    Server-->>Hacker: Gibberish
    Note over Server,Hacker: AES-256 Encryption
    Note over User,Server: Real Example: Daraz Checkout
    Note right of Hacker: Sees: '5K§#j9L!p2Q...'
    Note right of Server: Prevents: Man-in-the-Middle Attacks
  • Symmetric encryption (AES): Fast, same key for sender/receiver.
  • Asymmetric encryption (RSA): Slower, but secure key exchange (e.g., HTTPS).
  • Hashing (SHA-256): Turns "password123" into a591a6d4... (irreversible).

Real-World Use:

  • eSewa: Uses TLS 1.3 for all transactions.
  • Ncell: RSA-2048 for secure login tokens.

B. Firewalls and IDS/IPS

  • Firewall: Blocks unauthorized access (e.g., NTC’s network firewall).
  • Intrusion Detection System (IDS): Monitors for attacks (e.g., Daraz’s SIEM tools).
  • Intrusion Prevention System (IPS): Actively blocks threats (e.g., Pathao’s real-time fraud detection).
Firewall RulesIntrusion DetectionNTC NetworksTraffic FilteringVPN RestrictionsLocal ISPsNepal's Cybersecurity Infrastructure
Technical safeguards implemented by Nepal's major networks

Nepal’s e-commerce landscape is governed by:

  1. Electronic Transactions Act 2008: Legal validity of digital contracts.
  2. Data Privacy Act 2018: Rules on data collection/storage.
  3. PCI-DSS: For payment processors (Khalti, eSewa).
  4. Nepal Rastra Bank (NRB) Guidelines: For fintech security.

COMPARISON TABLE: Nepal vs. Global Standards

Aspect Nepal (2024) Global (GDPR/PCI-DSS)
Data Retention 6 months (NRB rule) 2–5 years (GDPR)
Encryption TLS 1.2+ (mandatory for payments) TLS 1.3+ (recommended)
Breach Notification 72 hours (if >100 users affected) 72 hours (GDPR)
Liability Merchant bears risk (unless proven hack) Shared liability (PCI-DSS)

WORKED EXAMPLE: NEPSE’s Compliance

  • KYC: Requires citizenship + bank statement for online trading.
  • Two-Factor Auth (2FA): SMS + OTP for logins.
  • Audit Logs: All trades recorded for NRB inspections.

6. Risk Management Strategies

A. The Risk Assessment Matrix

023466992Fraudulent Transactions85Data Breach92Supply Chain Delay65Phishing Attacks88
Risk Severity Score (0-100) for Nepalese E-Commerce (2023)

B. Mitigation Techniques

Risk Mitigation Nepalese Example
Phishing Email filtering + user training NTC’s anti-phishing workshops
DDoS Attacks Cloudflare/AWS Shield Daraz’s protection during sales
Insider Threats Role-based access control (RBAC) Ncell’s HR access restrictions
Third-Party Risks Vendor security audits eSewa’s PCI-DSS audits for banks

## In the Real World

  1. eSewa’s Tokenization

    • Idea: Replaces raw credit card numbers with unique tokens (like a digital alias).
    • How it’s used: When you pay via eSewa, your card details are never stored—only a token linked to your account. Even if hackers breach eSewa’s database, they get useless tokens.
    • Nepalese impact: Reduced card fraud by 30% in 2023.
  2. Pathao’s Rider Safety App

    • Idea: GPS tracking + panic button for real-time security.
    • How it’s used: Riders can share their live location with family contacts and trigger alerts if they feel unsafe. The app also blocks routes with high crime rates (e.g., parts of Kathmandu at night).
    • Tech behind it: Google Maps API + Firebase for real-time data.
  3. Daraz’s Blockchain for Medicine Authenticity

    • Idea: Immutable ledger to track medicine from manufacturer to customer.
    • How it’s used: When you buy paracetamol from Daraz, scan the QR code to see:
      • Manufacturer details (e.g., Nepal Pharmaceuticals).
      • Batch number and expiry date.
      • Whether it’s been tampered with in transit.
    • Why it matters: Nepal’s fake medicine market is worth ₹1.2B annually.

## Exam Tip

How to Score Full Marks in TU/PU Exams on This Unit

  1. Structure Answers Like This:

    • Definition (1 mark) → Explanation (3 marks) → Nepalese Example (2 marks).
    • Example:

      "SSL (Secure Sockets Layer) is a protocol that encrypts data between a web browser and server using asymmetric encryption (RSA) for key exchange and symmetric encryption (AES) for data transfer. In Nepal, eSewa uses TLS 1.3 (SSL’s successor) to secure transactions, preventing man-in-the-middle attacks where hackers intercept card details."

  2. Memorize These Key Terms with Examples:

    • PCI-DSS: Khalti’s compliance with 12 security standards (e.g., no storage of CVV).
    • Multi-Factor Authentication (MFA): Ncell’s OTP + fingerprint for logins.
    • Digital Signature: NEPSE’s ESign for online share trading.
    • DDoS Attack: Daraz’s Black Friday 2023 crash due to bot traffic.
  3. Compare Tables Are Gold:

    • Always draw a 2×2 or 3×3 comparison table when asked to differentiate (e.g., traditional vs. e-commerce, SSL vs. SSH).
  4. Worked Examples = Easy Marks:

    • For questions like "Explain how encryption secures e-payments," trace a transaction step-by-step (like the eSewa example above).
  5. Avoid These Mistakes:

    • ❌ Saying "firewall" is the only security tool (mention IDS/IPS + encryption).
    • ❌ Ignoring Nepal-specific laws (always cite Electronic Transactions Act 2008).
    • ❌ Describing how a hacker attacks without explaining how to prevent it.

Final Visual Summary

Based on the TU BBM syllabus for E Commerce (IT204), unit 4.

Discussion

Loading…