MIS And E-BusinessUnit 611 min read
E-Commerce Security: Defense Strategies, Threats & Real-World Cases
Unit 6 of MIS And E-Business explores e-commerce security threats (malware, wireless vulnerabilities, phishing), defense strategies (firewalls, IDS/IPS, encryption), and real-world applications in Nepali platforms like eSewa and Daraz. Learn how authentication, authorization, and availability are enforced, with case st
Core Concepts: The CIA Triad in E-Commerce
E-commerce security revolves around three pillars: Confidentiality, Integrity, and Availability (CIA Triad). These are often called security requirements or security goals. Let’s break them down with real-world examples from Nepal and globally.
1. Confidentiality
Definition: Ensuring that sensitive data (e.g., credit card numbers, personal details) is accessible only to authorized users. How it’s enforced in e-commerce:
- Encryption (e.g., SSL/TLS for secure data transmission).
- Access controls (e.g., role-based permissions in eSewa).
- Data masking (e.g., hiding full credit card numbers in Daraz checkout).
How HTTPS secures data between your browser and a website (Image: Essich, CC BY 3.0, via Wikimedia Commons)
Worked Example: When you pay for a Daraz order using Khalti, your card details are encrypted using AES-256 before being sent to the server. Even if a hacker intercepts the data, they can’t read it without the decryption key.
In the Real World
eSewa (Nepal):
- Uses two-factor authentication (2FA) (OTP + PIN) to enforce authentication and authorization.
- If a hacker steals your password, they still can’t access your account without the OTP sent to your phone.
- Security threat it prevents: Brute-force attacks (repeated password guesses).
Khalti (Digital Wallet):
- Implements tokenization (replacing card details with a unique token) to protect confidentiality.
- Example: When you pay ₹500 on Daraz, Khalti generates a one-time token instead of storing your actual card number.
- Security threat it prevents: Credit card fraud (if Daraz’s database is hacked).
NTC (Nepal Telecom):
- Uses VPNs for remote employees to access internal systems securely.
- Security threat it prevents: Man-in-the-middle (MITM) attacks (eavesdropping on unsecured Wi-Fi).
2. Integrity
Definition: Ensuring that data is accurate, consistent, and unaltered (e.g., no one changes your order details on Daraz). How it’s enforced:
- Hash functions (e.g., SHA-256 for digital signatures).
- Digital signatures (e.g., verifying a downloaded file hasn’t been tampered with).
- Checksums (e.g., ensuring a software update isn’t corrupted).
Worked Example: When you download an Android app from Google Play, the app uses a digital signature to prove it hasn’t been modified by a hacker. If the signature doesn’t match, Google Play blocks the download.
3. Availability
Definition: Ensuring that e-commerce systems (websites, payment gateways) are accessible when needed. How it’s enforced:
- Redundancy (backup servers, e.g., Daraz’s cloud hosting).
- DDoS protection (e.g., Cloudflare for eSewa).
- Load balancing (distributing traffic, e.g., during Dashain sales on Daraz).
Real-World Case: During Dashain 2023, Daraz faced a DDoS attack that slowed down its website. To maintain availability, Daraz used:
- Cloudflare’s DDoS mitigation (blocked malicious traffic).
- Auto-scaling servers (added more servers during peak traffic).
Security Threats in E-Commerce
E-commerce faces technical and non-technical threats. Below is a comparison table of common threats:
| Threat Type | Example | Impact | Prevention Method |
|---|---|---|---|
| Malware | Viruses, Trojans, Ransomware | Steals data, locks systems | Antivirus, Firewalls, Employee training |
| Phishing | Fake eSewa/Khalti login pages | Tricks users into revealing credentials | Multi-factor authentication (MFA) |
| Denial-of-Service (DoS/DDoS) | Overloading Daraz’s servers | Website crashes, lost sales | Cloudflare, Load balancers |
| SQL Injection | Hacking Daraz’s database via search box | Steals customer data | Input validation, Parameterized queries |
| Man-in-the-Middle (MITM) | Hacking unsecured Wi-Fi in cafes | Eavesdropping on transactions | VPNs, HTTPS (not HTTP) |
| Non-Technical (Social Engineering) | Calling customers pretending to be NTC support | Tricks users into sharing passwords | Security awareness training |
Defense Strategies: How Companies Protect Themselves
1. Firewalls
What it does: Acts as a barrier between trusted internal networks and untrusted external networks (e.g., the internet). Types:
- Packet-filtering firewall (checks IP/port rules).
- Stateful inspection firewall (tracks connections, e.g., used by banks).
- Next-gen firewall (NGFW) (includes intrusion prevention, e.g., used by Daraz).
Real-World Use:
- Nabil Bank uses stateful firewalls to block unauthorized access to its online banking system.
- NTC uses NGFWs to prevent DDoS attacks on its customer portal.
2. Intrusion Detection System (IDS) vs. Intrusion Prevention System (IPS)
Both monitor network traffic, but IDS detects while IPS prevents.
| Feature | Intrusion Detection System (IDS) | Intrusion Prevention System (IPS) |
|---|---|---|
| Primary Role | Monitors and alerts | Monitors and blocks |
| Deployment | Passive (doesn’t stop attacks) | Active (can stop attacks) |
| Example | Snort (open-source IDS) | Cisco Firepower (IPS) |
| Response to Attack | Sends email/alert to admin | Drops malicious packets automatically |
Mermaid Diagram: IDS vs. IPS in Action
Worked Example:
- Daraz uses Snort (IDS) to detect SQL injection attempts in its search box.
- If an attack is detected, Cisco IPS automatically blocks the IP address.
3. Encryption
What it does: Converts data into unreadable ciphertext to prevent theft. Types:
- Symmetric encryption (same key for encryption/decryption, e.g., AES).
- Asymmetric encryption (public/private keys, e.g., RSA for SSL).
Real-World Use:
- eSewa uses AES-256 to encrypt transaction data.
- Khalti uses RSA for secure key exchange during payments.
4. Secure Coding Practices
Common vulnerabilities in e-commerce websites:
- Cross-Site Scripting (XSS): Injecting malicious scripts (e.g., stealing cookies).
- Fix: Input validation, Content Security Policy (CSP).
- Cross-Site Request Forgery (CSRF): Tricking users into executing actions (e.g., transferring money).
- Fix: CSRF tokens in forms.
- Broken Authentication: Weak password policies.
- Fix: Enforce strong passwords + MFA.
Case Study: Facebook’s Security Breach (2019)
- Attack: View As bug allowed hackers to steal 50M+ user access tokens.
- Impact: Unauthorized logins, data theft.
- Fix: Facebook implemented strict OAuth 2.0 validation and biometric login options.
Wireless Security Challenges
Wireless networks (Wi-Fi, Bluetooth) are easier to hack than wired ones. Key threats:
- Eavesdropping: Hackers intercept data on public Wi-Fi (e.g., in Thamel cafes).
- Solution: Use VPNs (e.g., NordVPN, ProtonVPN).
- Rogue Access Points: Fake Wi-Fi hotspots (e.g., "Free_NTC_WiFi" in Kathmandu).
- Solution: Only connect to verified networks.
- Bluejacking/Bluesnarfing: Exploiting Bluetooth vulnerabilities.
- Solution: Disable Bluetooth when not in use.
Real-World Example:
- NTC’s "Ncell WiFi" uses WPA3 encryption to prevent eavesdropping.
- Pathao drivers are trained to avoid public Wi-Fi for transactions.
Security in Mobile Commerce (M-Commerce)
Mobile apps (e.g., Khalti, eSewa, Daraz) face unique risks:
- Insecure APIs: Poorly coded backend services.
- Fix: Use OAuth 2.0 for API security.
- Jailbroken/Rooted Devices: Malware installed via sideloading.
- Fix: App signing (e.g., Google Play Protect).
- SMS Phishing (Smishing): Fake OTP messages.
- Fix: App-based OTPs (e.g., eSewa’s in-app notifications).
Case Study: WhatsApp Payment Scam (India/Nepal)
- Attack: Hackers sent fake WhatsApp payment links to users.
- Impact: Users lost money thinking it was a legitimate transaction.
- Solution: WhatsApp now shows payment warnings and requires biometric verification.
Exam Tip: How to Score Full Marks
Define + Explain + Example:
- Always start with clear definitions (e.g., "IDS is a system that monitors network traffic for suspicious activity").
- Follow with how it works (e.g., "It uses signature-based detection to match known attack patterns").
- End with a real-world example (e.g., "Daraz uses Snort IDS to detect SQL injection attempts").
Diagrams = Extra Marks:
- Draw IDS vs. IPS (as shown above).
- Show firewall layers (e.g., DMZ, internal network).
- Use flowcharts for processes (e.g., how SSL/TLS works).
Compare and Contrast:
- Questions often ask to differentiate (e.g., "H2C vs. H2R").
- Use tables (like the IDS vs. IPS one above).
Case Studies:
- Mention Nepali companies (eSewa, Khalti, Daraz) or global examples (Facebook, WhatsApp).
- Explain what went wrong and how it was fixed.
Security Requirements (CIA + Others):
- Always link back to Confidentiality, Integrity, Availability.
- Example: "To ensure availability during Dashain sales, Daraz uses Cloudflare DDoS protection."
Final Checklist Before Exam
✅ Can you define IDS, IPS, firewall, encryption? ✅ Can you explain how they work with diagrams? ✅ Can you compare IDS vs. IPS, symmetric vs. asymmetric encryption? ✅ Can you give 2 Nepali examples (eSewa, Khalti, Daraz, NTC) for each security concept? ✅ Can you describe a real breach (e.g., Facebook, WhatsApp) and its solution?
Based on the TU BCA syllabus for MIS And E-Business (CACS301), unit 6.
Discussion
Loading…