E-Commerce and Internet MarketingUnit 58 min read
E-Commerce Security: Threats, Protocols & Best Practices
Unit 5 of E-Commerce and Internet Marketing covers the critical security measures protecting online transactions, data integrity, and customer trust—including encryption, authentication, fraud prevention, and compliance with global standards like PCI-DSS and GDPR.
TAKEAWAYS:
- E-commerce security protects sensitive data (credit cards, personal info) using encryption (SSL/TLS), authentication (OAuth, multi-factor), and secure protocols (HTTPS).
- Common threats include phishing, malware, DDoS attacks, and man-in-the-middle (MITM) attacks—each requiring specific countermeasures.
- Payment security relies on PCI-DSS compliance, tokenization, and 3D Secure (3DS) for fraud prevention in real-time.
- Legal frameworks like GDPR (EU) and Nepal’s Electronic Transactions Act (2008) mandate data protection and breach notifications.
- Best practices include regular audits, employee training, and zero-trust architecture to minimize breaches.
- Case studies (e.g., Nabil Bank’s digital fraud detection, Daraz’s PCI-compliant checkout) show how security directly impacts trust and revenue.
1. Why E-Commerce Security Matters
E-commerce security ensures:
- Confidentiality: Only authorized parties (e.g., banks, merchants) access sensitive data.
- Integrity: Data (e.g., order details, payment info) isn’t altered in transit.
- Availability: Systems (e.g., eSewa’s payment gateway) remain operational during attacks.
- Non-repudiation: Buyers/sellers can’t deny transactions (critical for NEPSE’s online trading).
Why it matters: 90% of data breaches in e-commerce involve stolen credentials or unencrypted payment data (Verizon DBIR 2023).
2. Key Security Threats & How They Work
A. Authentication Attacks
Phishing
- How it works: Fake emails (e.g., "Your Khalti account is locked!") trick users into revealing credentials.
- Real-world example: 2022 Daraz phishing scam where attackers mimicked order confirmation emails to steal payment details.
- Countermeasure: Multi-Factor Authentication (MFA) (SMS/OTP + biometrics).
flowchart TD A["User clicks malicious link"] --> B["Redirects to fake login page"] B --> C["Credentials stolen"] --> D["Fraudulent transaction"] D --> E["MFA blocks access"]
Brute Force Attacks
- Example: Attackers guess Pathao driver passwords to hijack accounts.
- Solution: Account lockout after 5 failed attempts + CAPTCHA.
B. Data Interception Attacks
Man-in-the-Middle (MITM)
- How it works: Hackers intercept HTTPS traffic (e.g., on public Wi-Fi) to steal Ncell e-commerce login data.
- Fix: SSL/TLS encryption (look for the 🔒 padlock in URLs).
sequenceDiagram User->>Server: Sends credit card data (unencrypted) Hacker->>User: Intercepts data Hacker->>Server: Alters data (e.g., changes amount) Server-->>User: Confirms fraudulent transaction
Session Hijacking
- Example: Stealing eSewa session cookies to make unauthorized payments.
- Prevention: Short-lived session tokens + HTTP-only cookies.
C. Malware & Ransomware
- Example: 2021 NTC website hack via malware-infected plugins.
- Solutions:
- Endpoint protection (e.g., Kaspersky for servers).
- Regular software updates (e.g., WordPress plugins for Daraz’s blog).
D. Denial-of-Service (DoS/DDoS)
- Example: Nepal’s 2020 COVID-19 info sites crashed due to DDoS.
- Mitigation: Cloudflare CDN + rate limiting.
3. Security Protocols & Standards
A. Encryption
| Protocol | Purpose | Example Use Case |
|---|---|---|
| SSL/TLS | Encrypts data in transit (HTTPS) | Daraz checkout page |
| PGP/GPG | Encrypts emails (e.g., Nabil Bank internal communications) | Secure email for loan agreements |
| AES-256 | Encrypts stored data (e.g., Khalti databases) | Credit card numbers in DBs |
B. Authentication Protocols
OAuth 2.0
- How it works: Lets users log in via Google/Facebook without sharing passwords.
- Example: Pathao’s "Login with Facebook" feature.
flowchart LR User["User"] -->|"Click 'Login with Google'"| Google["Google OAuth"] Google -->|"Verifies identity"| Pathao["Pathao App"] Pathao -->|"Grants access"| User["User Dashboard"]
Multi-Factor Authentication (MFA)
- Example: Nepal Rastra Bank’s online banking requires OTP + fingerprint.
C. Payment Security Standards
PCI-DSS (Payment Card Industry Data Security Standard)
- 12 requirements (e.g., "Do not store CVV codes").
- Example: Nabil Bank’s PCI-compliant POS terminals.
mindmap root((PCI-DSS Compliance)) root --> Build and Maintain a Secure Network root --> Protect Cardholder Data root --> Maintain a Vulnerability Management Program root --> Implement Strong Access Control Measures root --> Regularly Monitor and Test Networks root --> Maintain an Information Security Policy
3D Secure (3DS)
- How it works: Adds a second verification step (e.g., Khalti’s OTP for high-value transactions).
- Benefit: Reduces chargeback fraud by 70% (Mastercard data).
4. Legal & Ethical Frameworks
A. Global Laws
| Law | Key Requirement | Applies to Nepal? |
|---|---|---|
| GDPR (EU) | User consent for data collection | Yes (for EU customers) |
| PCI-DSS | Secure credit card handling | Yes (for banks/e-commerce) |
| California CCPA | Right to delete personal data | No (but best practice) |
B. Nepal’s Laws
- Electronic Transactions Act (2008)
- Mandates digital signatures for legal contracts (e.g., NEPSE online trades).
- Data Privacy Guidelines (2018)
- Requires data breach notifications within 72 hours (like GDPR).
5. Real-World Case Study: Nabil Bank’s Fraud Prevention
Problem: High credit card fraud on their e-commerce platform. Solution:
- Tokenization: Replaced card numbers with random tokens (e.g.,
tok_123abc). - AI-Based Fraud Detection: Flagged unusual transactions (e.g., sudden large orders from a new device).
- PCI-DSS Level 1 Certification: Ensured end-to-end encryption.
Result: 40% drop in fraudulent transactions in 2023.
6. Best Practices for E-Commerce Security
| Best Practice | How to Implement | Example |
|---|---|---|
| Regular Security Audits | Use OWASP ZAP to scan for vulnerabilities | Daraz’s quarterly audits |
| Employee Training | Simulate phishing attacks | NTC’s cybersecurity workshops |
| Zero-Trust Architecture | Verify every access request | Google Cloud’s BeyondCorp |
| Backup & Disaster Recovery | Automated cloud backups (AWS S3) | eSewa’s daily DB snapshots |
## In the Real World
Khalti’s 3D Secure Integration
- Idea: 3D Secure (3DS) adds an extra OTP step for high-value transactions (e.g., >Rs. 50,000).
- Why it works: Reduces chargeback fraud by verifying the user’s device/browser.
Daraz’s PCI-DSS Compliance
- Idea: Tokenization replaces credit card numbers with unique tokens during checkout.
- Impact: Even if hackers breach Daraz’s database, they get useless token strings instead of real card details.
Nepal Rastra Bank’s Biometric Login
- Idea: Fingerprint + OTP for online banking (beyond just passwords).
- Real-world use: Nabil Bank’s mobile app uses this to prevent SIM-swap fraud.
## Exam Tip
How this unit is tested (TU/PU/NEB style):
Short Questions (2–5 marks)
- Define SSL vs. TLS, phishing vs. spear-phishing, or PCI-DSS vs. GDPR.
- Example: "Explain how tokenization works in e-commerce with an example."
Long Questions (10–15 marks)
- Compare two security protocols (e.g., OAuth 2.0 vs. SAML).
- Case study: "How would you secure eSewa’s payment gateway against MITM attacks?"
- Expected answer: SSL/TLS + HSTS + regular key rotation.
Practical Scenarios (5–10 marks)
- "A customer reports unauthorized transactions on Pathao’s app. Suggest 3 security fixes."
- Answers: MFA, transaction alerts, device fingerprinting.
- "A customer reports unauthorized transactions on Pathao’s app. Suggest 3 security fixes."
Pro Tip:
- Memorize acronyms: PCI-DSS, 3DS, MFA, SSL/TLS.
- Link theories to Nepal: Always relate GDPR to Nepal’s Data Privacy Guidelines or PCI-DSS to Nabil Bank’s policies.
- Draw diagrams: For MITM attacks, OAuth flow, or PCI-DSS requirements—examiners love visual answers!
Based on the TU BIM syllabus for E-Commerce and Internet Marketing (IT247), unit 5.
Discussion
Loading…