CACS301 MIS And E-Business

MIS And E-BusinessUnit 611 min read

E-Commerce Security: Defense Strategies, Threats & Real-World Cases

Unit 6 of MIS And E-Business explores e-commerce security threats (malware, wireless vulnerabilities, phishing), defense strategies (firewalls, IDS/IPS, encryption), and real-world applications in Nepali platforms like eSewa and Daraz. Learn how authentication, authorization, and availability are enforced, with case st


Core Concepts: The CIA Triad in E-Commerce

E-commerce security revolves around three pillars: Confidentiality, Integrity, and Availability (CIA Triad). These are often called security requirements or security goals. Let’s break them down with real-world examples from Nepal and globally.

Encryption (SSL/TLS)Access controls (RBAC)Data maskingConfidentialityHashing (SHA-256)Digital signaturesChecksumsIntegrityLoad balancingRedundancyDDoS protectionAvailabilityCIA Triad
The CIA Triad applied to e-commerce security principles

1. Confidentiality

Definition: Ensuring that sensitive data (e.g., credit card numbers, personal details) is accessible only to authorized users. How it’s enforced in e-commerce:

  • Encryption (e.g., SSL/TLS for secure data transmission).
  • Access controls (e.g., role-based permissions in eSewa).
  • Data masking (e.g., hiding full credit card numbers in Daraz checkout).

SSL/TLS handshake diagram**How HTTPS secures data between your browser and a website (Image: Essich, CC BY 3.0, via Wikimedia Commons)

Worked Example: When you pay for a Daraz order using Khalti, your card details are encrypted using AES-256 before being sent to the server. Even if a hacker intercepts the data, they can’t read it without the decryption key.


In the Real World

  1. eSewa (Nepal):

    • Uses two-factor authentication (2FA) (OTP + PIN) to enforce authentication and authorization.
    • If a hacker steals your password, they still can’t access your account without the OTP sent to your phone.
    • Security threat it prevents: Brute-force attacks (repeated password guesses).
  2. Khalti (Digital Wallet):

    • Implements tokenization (replacing card details with a unique token) to protect confidentiality.
    • Example: When you pay ₹500 on Daraz, Khalti generates a one-time token instead of storing your actual card number.
    • Security threat it prevents: Credit card fraud (if Daraz’s database is hacked).
  3. NTC (Nepal Telecom):

    • Uses VPNs for remote employees to access internal systems securely.
    • Security threat it prevents: Man-in-the-middle (MITM) attacks (eavesdropping on unsecured Wi-Fi).

2. Integrity

Definition: Ensuring that data is accurate, consistent, and unaltered (e.g., no one changes your order details on Daraz). How it’s enforced:

  • Hash functions (e.g., SHA-256 for digital signatures).
  • Digital signatures (e.g., verifying a downloaded file hasn’t been tampered with).
  • Checksums (e.g., ensuring a software update isn’t corrupted).

Worked Example: When you download an Android app from Google Play, the app uses a digital signature to prove it hasn’t been modified by a hacker. If the signature doesn’t match, Google Play blocks the download.


3. Availability

Definition: Ensuring that e-commerce systems (websites, payment gateways) are accessible when needed. How it’s enforced:

  • Redundancy (backup servers, e.g., Daraz’s cloud hosting).
  • DDoS protection (e.g., Cloudflare for eSewa).
  • Load balancing (distributing traffic, e.g., during Dashain sales on Daraz).

Real-World Case: During Dashain 2023, Daraz faced a DDoS attack that slowed down its website. To maintain availability, Daraz used:

  • Cloudflare’s DDoS mitigation (blocked malicious traffic).
  • Auto-scaling servers (added more servers during peak traffic).

Security Threats in E-Commerce

E-commerce faces technical and non-technical threats. Below is a comparison table of common threats:

Threat Type Example Impact Prevention Method
Malware Viruses, Trojans, Ransomware Steals data, locks systems Antivirus, Firewalls, Employee training
Phishing Fake eSewa/Khalti login pages Tricks users into revealing credentials Multi-factor authentication (MFA)
Denial-of-Service (DoS/DDoS) Overloading Daraz’s servers Website crashes, lost sales Cloudflare, Load balancers
SQL Injection Hacking Daraz’s database via search box Steals customer data Input validation, Parameterized queries
Man-in-the-Middle (MITM) Hacking unsecured Wi-Fi in cafes Eavesdropping on transactions VPNs, HTTPS (not HTTP)
Non-Technical (Social Engineering) Calling customers pretending to be NTC support Tricks users into sharing passwords Security awareness training

Defense Strategies: How Companies Protect Themselves

2015SSL/TLS adoptionby 90% of Nepali e-com2018Introduction ofPCI-DSS compliance for2020Implementation of2FA in 70% of major Ne2023AI-based frauddetection systems depl
Key security milestones in Nepali e-commerce (2015-2023)

1. Firewalls

What it does: Acts as a barrier between trusted internal networks and untrusted external networks (e.g., the internet). Types:

  • Packet-filtering firewall (checks IP/port rules).
  • Stateful inspection firewall (tracks connections, e.g., used by banks).
  • Next-gen firewall (NGFW) (includes intrusion prevention, e.g., used by Daraz).

Real-World Use:

  • Nabil Bank uses stateful firewalls to block unauthorized access to its online banking system.
  • NTC uses NGFWs to prevent DDoS attacks on its customer portal.

2. Intrusion Detection System (IDS) vs. Intrusion Prevention System (IPS)

Both monitor network traffic, but IDS detects while IPS prevents.

Feature Intrusion Detection System (IDS) Intrusion Prevention System (IPS)
Primary Role Monitors and alerts Monitors and blocks
Deployment Passive (doesn’t stop attacks) Active (can stop attacks)
Example Snort (open-source IDS) Cisco Firepower (IPS)
Response to Attack Sends email/alert to admin Drops malicious packets automatically

Mermaid Diagram: IDS vs. IPS in Action

Snort (open-source)Alerts via emailPassive monitoringIntrusion Detection System (IDS)Cisco FirepowerDrops malicious packetsActive blockingIntrusion Prevention System (IPS)Security Systems
Hierarchy of IDS vs. IPS deployment and functionality

Worked Example:

  • Daraz uses Snort (IDS) to detect SQL injection attempts in its search box.
  • If an attack is detected, Cisco IPS automatically blocks the IP address.

3. Encryption

What it does: Converts data into unreadable ciphertext to prevent theft. Types:

  • Symmetric encryption (same key for encryption/decryption, e.g., AES).
  • Asymmetric encryption (public/private keys, e.g., RSA for SSL).

Real-World Use:

  • eSewa uses AES-256 to encrypt transaction data.
  • Khalti uses RSA for secure key exchange during payments.

4. Secure Coding Practices

Common vulnerabilities in e-commerce websites:

  1. Cross-Site Scripting (XSS): Injecting malicious scripts (e.g., stealing cookies).
    • Fix: Input validation, Content Security Policy (CSP).
  2. Cross-Site Request Forgery (CSRF): Tricking users into executing actions (e.g., transferring money).
    • Fix: CSRF tokens in forms.
  3. Broken Authentication: Weak password policies.
    • Fix: Enforce strong passwords + MFA.

Case Study: Facebook’s Security Breach (2019)

  • Attack: View As bug allowed hackers to steal 50M+ user access tokens.
  • Impact: Unauthorized logins, data theft.
  • Fix: Facebook implemented strict OAuth 2.0 validation and biometric login options.

Wireless Security Challenges

Wireless networks (Wi-Fi, Bluetooth) are easier to hack than wired ones. Key threats:

  1. Eavesdropping: Hackers intercept data on public Wi-Fi (e.g., in Thamel cafes).
    • Solution: Use VPNs (e.g., NordVPN, ProtonVPN).
  2. Rogue Access Points: Fake Wi-Fi hotspots (e.g., "Free_NTC_WiFi" in Kathmandu).
    • Solution: Only connect to verified networks.
  3. Bluejacking/Bluesnarfing: Exploiting Bluetooth vulnerabilities.
    • Solution: Disable Bluetooth when not in use.

Real-World Example:

  • NTC’s "Ncell WiFi" uses WPA3 encryption to prevent eavesdropping.
  • Pathao drivers are trained to avoid public Wi-Fi for transactions.

Security in Mobile Commerce (M-Commerce)

Mobile apps (e.g., Khalti, eSewa, Daraz) face unique risks:

  1. Insecure APIs: Poorly coded backend services.
    • Fix: Use OAuth 2.0 for API security.
  2. Jailbroken/Rooted Devices: Malware installed via sideloading.
    • Fix: App signing (e.g., Google Play Protect).
  3. SMS Phishing (Smishing): Fake OTP messages.
    • Fix: App-based OTPs (e.g., eSewa’s in-app notifications).

Case Study: WhatsApp Payment Scam (India/Nepal)

  • Attack: Hackers sent fake WhatsApp payment links to users.
  • Impact: Users lost money thinking it was a legitimate transaction.
  • Solution: WhatsApp now shows payment warnings and requires biometric verification.

Exam Tip: How to Score Full Marks

  1. Define + Explain + Example:

    • Always start with clear definitions (e.g., "IDS is a system that monitors network traffic for suspicious activity").
    • Follow with how it works (e.g., "It uses signature-based detection to match known attack patterns").
    • End with a real-world example (e.g., "Daraz uses Snort IDS to detect SQL injection attempts").
  2. Diagrams = Extra Marks:

    • Draw IDS vs. IPS (as shown above).
    • Show firewall layers (e.g., DMZ, internal network).
    • Use flowcharts for processes (e.g., how SSL/TLS works).
  3. Compare and Contrast:

    • Questions often ask to differentiate (e.g., "H2C vs. H2R").
    • Use tables (like the IDS vs. IPS one above).
  4. Case Studies:

    • Mention Nepali companies (eSewa, Khalti, Daraz) or global examples (Facebook, WhatsApp).
    • Explain what went wrong and how it was fixed.
  5. Security Requirements (CIA + Others):

    • Always link back to Confidentiality, Integrity, Availability.
    • Example: "To ensure availability during Dashain sales, Daraz uses Cloudflare DDoS protection."

Final Checklist Before Exam

✅ Can you define IDS, IPS, firewall, encryption? ✅ Can you explain how they work with diagrams? ✅ Can you compare IDS vs. IPS, symmetric vs. asymmetric encryption? ✅ Can you give 2 Nepali examples (eSewa, Khalti, Daraz, NTC) for each security concept? ✅ Can you describe a real breach (e.g., Facebook, WhatsApp) and its solution?

Based on the TU BCA syllabus for MIS And E-Business (CACS301), unit 6.

Discussion

Loading…