IT247 E-Commerce and Internet Marketing

E-Commerce and Internet MarketingUnit 58 min read

E-Commerce Security: Threats, Protocols & Best Practices

Unit 5 of E-Commerce and Internet Marketing covers the critical security measures protecting online transactions, data integrity, and customer trust—including encryption, authentication, fraud prevention, and compliance with global standards like PCI-DSS and GDPR.

TAKEAWAYS:

  • E-commerce security protects sensitive data (credit cards, personal info) using encryption (SSL/TLS), authentication (OAuth, multi-factor), and secure protocols (HTTPS).
  • Common threats include phishing, malware, DDoS attacks, and man-in-the-middle (MITM) attacks—each requiring specific countermeasures.
  • Payment security relies on PCI-DSS compliance, tokenization, and 3D Secure (3DS) for fraud prevention in real-time.
  • Legal frameworks like GDPR (EU) and Nepal’s Electronic Transactions Act (2008) mandate data protection and breach notifications.
  • Best practices include regular audits, employee training, and zero-trust architecture to minimize breaches.
  • Case studies (e.g., Nabil Bank’s digital fraud detection, Daraz’s PCI-compliant checkout) show how security directly impacts trust and revenue.

1. Why E-Commerce Security Matters

E-commerce security ensures:

  • Confidentiality: Only authorized parties (e.g., banks, merchants) access sensitive data.
  • Integrity: Data (e.g., order details, payment info) isn’t altered in transit.
  • Availability: Systems (e.g., eSewa’s payment gateway) remain operational during attacks.
  • Non-repudiation: Buyers/sellers can’t deny transactions (critical for NEPSE’s online trading).

Why it matters: 90% of data breaches in e-commerce involve stolen credentials or unencrypted payment data (Verizon DBIR 2023).


2. Key Security Threats & How They Work

A. Authentication Attacks

  1. Phishing

    • How it works: Fake emails (e.g., "Your Khalti account is locked!") trick users into revealing credentials.
    • Real-world example: 2022 Daraz phishing scam where attackers mimicked order confirmation emails to steal payment details.
    • Countermeasure: Multi-Factor Authentication (MFA) (SMS/OTP + biometrics).
    flowchart TD
      A["User clicks malicious link"] --> B["Redirects to fake login page"]
      B --> C["Credentials stolen"] --> D["Fraudulent transaction"]
      D --> E["MFA blocks access"]
  2. Brute Force Attacks

    • Example: Attackers guess Pathao driver passwords to hijack accounts.
    • Solution: Account lockout after 5 failed attempts + CAPTCHA.

B. Data Interception Attacks

  1. Man-in-the-Middle (MITM)

    • How it works: Hackers intercept HTTPS traffic (e.g., on public Wi-Fi) to steal Ncell e-commerce login data.
    • Fix: SSL/TLS encryption (look for the 🔒 padlock in URLs).
    sequenceDiagram
      User->>Server: Sends credit card data (unencrypted)
      Hacker->>User: Intercepts data
      Hacker->>Server: Alters data (e.g., changes amount)
      Server-->>User: Confirms fraudulent transaction
  2. Session Hijacking

    • Example: Stealing eSewa session cookies to make unauthorized payments.
    • Prevention: Short-lived session tokens + HTTP-only cookies.

C. Malware & Ransomware

  • Example: 2021 NTC website hack via malware-infected plugins.
  • Solutions:
    • Endpoint protection (e.g., Kaspersky for servers).
    • Regular software updates (e.g., WordPress plugins for Daraz’s blog).

D. Denial-of-Service (DoS/DDoS)

  • Example: Nepal’s 2020 COVID-19 info sites crashed due to DDoS.
  • Mitigation: Cloudflare CDN + rate limiting.

3. Security Protocols & Standards

A. Encryption

Protocol Purpose Example Use Case
SSL/TLS Encrypts data in transit (HTTPS) Daraz checkout page
PGP/GPG Encrypts emails (e.g., Nabil Bank internal communications) Secure email for loan agreements
AES-256 Encrypts stored data (e.g., Khalti databases) Credit card numbers in DBs

B. Authentication Protocols

  1. OAuth 2.0

    • How it works: Lets users log in via Google/Facebook without sharing passwords.
    • Example: Pathao’s "Login with Facebook" feature.
    flowchart LR
      User["User"] -->|"Click 'Login with Google'"| Google["Google OAuth"]
      Google -->|"Verifies identity"| Pathao["Pathao App"]
      Pathao -->|"Grants access"| User["User Dashboard"]
  2. Multi-Factor Authentication (MFA)

    • Example: Nepal Rastra Bank’s online banking requires OTP + fingerprint.

C. Payment Security Standards

  1. PCI-DSS (Payment Card Industry Data Security Standard)

    • 12 requirements (e.g., "Do not store CVV codes").
    • Example: Nabil Bank’s PCI-compliant POS terminals.
    mindmap
      root((PCI-DSS Compliance))
      root --> Build and Maintain a Secure Network
      root --> Protect Cardholder Data
      root --> Maintain a Vulnerability Management Program
      root --> Implement Strong Access Control Measures
      root --> Regularly Monitor and Test Networks
      root --> Maintain an Information Security Policy
  2. 3D Secure (3DS)

    • How it works: Adds a second verification step (e.g., Khalti’s OTP for high-value transactions).
    • Benefit: Reduces chargeback fraud by 70% (Mastercard data).

A. Global Laws

Law Key Requirement Applies to Nepal?
GDPR (EU) User consent for data collection Yes (for EU customers)
PCI-DSS Secure credit card handling Yes (for banks/e-commerce)
California CCPA Right to delete personal data No (but best practice)

B. Nepal’s Laws

  1. Electronic Transactions Act (2008)
    • Mandates digital signatures for legal contracts (e.g., NEPSE online trades).
  2. Data Privacy Guidelines (2018)
    • Requires data breach notifications within 72 hours (like GDPR).

5. Real-World Case Study: Nabil Bank’s Fraud Prevention

Problem: High credit card fraud on their e-commerce platform. Solution:

  1. Tokenization: Replaced card numbers with random tokens (e.g., tok_123abc).
  2. AI-Based Fraud Detection: Flagged unusual transactions (e.g., sudden large orders from a new device).
  3. PCI-DSS Level 1 Certification: Ensured end-to-end encryption.

Result: 40% drop in fraudulent transactions in 2023.


6. Best Practices for E-Commerce Security

Best Practice How to Implement Example
Regular Security Audits Use OWASP ZAP to scan for vulnerabilities Daraz’s quarterly audits
Employee Training Simulate phishing attacks NTC’s cybersecurity workshops
Zero-Trust Architecture Verify every access request Google Cloud’s BeyondCorp
Backup & Disaster Recovery Automated cloud backups (AWS S3) eSewa’s daily DB snapshots

## In the Real World

  1. Khalti’s 3D Secure Integration

    • Idea: 3D Secure (3DS) adds an extra OTP step for high-value transactions (e.g., >Rs. 50,000).
    • Why it works: Reduces chargeback fraud by verifying the user’s device/browser.
  2. Daraz’s PCI-DSS Compliance

    • Idea: Tokenization replaces credit card numbers with unique tokens during checkout.
    • Impact: Even if hackers breach Daraz’s database, they get useless token strings instead of real card details.
  3. Nepal Rastra Bank’s Biometric Login

    • Idea: Fingerprint + OTP for online banking (beyond just passwords).
    • Real-world use: Nabil Bank’s mobile app uses this to prevent SIM-swap fraud.

## Exam Tip

How this unit is tested (TU/PU/NEB style):

  1. Short Questions (2–5 marks)

    • Define SSL vs. TLS, phishing vs. spear-phishing, or PCI-DSS vs. GDPR.
    • Example: "Explain how tokenization works in e-commerce with an example."
  2. Long Questions (10–15 marks)

    • Compare two security protocols (e.g., OAuth 2.0 vs. SAML).
    • Case study: "How would you secure eSewa’s payment gateway against MITM attacks?"
      • Expected answer: SSL/TLS + HSTS + regular key rotation.
  3. Practical Scenarios (5–10 marks)

    • "A customer reports unauthorized transactions on Pathao’s app. Suggest 3 security fixes."
      • Answers: MFA, transaction alerts, device fingerprinting.

Pro Tip:

  • Memorize acronyms: PCI-DSS, 3DS, MFA, SSL/TLS.
  • Link theories to Nepal: Always relate GDPR to Nepal’s Data Privacy Guidelines or PCI-DSS to Nabil Bank’s policies.
  • Draw diagrams: For MITM attacks, OAuth flow, or PCI-DSS requirements—examiners love visual answers!

Based on the TU BIM syllabus for E-Commerce and Internet Marketing (IT247), unit 5.

Discussion

Loading…