IT225 Computer Security and Cyber Law

Computer Security and Cyber LawUnit 716 min read

Secure Electronic Transactions & E-Commerce Security: SET Protocol, EFT, PCI-DSS, Fraud & Risk Management

Unit 7 of Computer Security and Cyber Law explores the cryptographic foundations of secure online payments (SET protocol), electronic funds transfer (EFT), Payment Card Industry Data Security Standard (PCI-DSS), fraud detection techniques, and risk management strategies in e-commerce—with real-world examples from eSewa

TAKEAWAYS:

  • SET Protocol ensures end-to-end encryption between buyer, merchant, and bank using dual signatures and digital certificates to prevent fraud.
  • PCI-DSS mandates 12 security controls (e.g., encryption, access logs) for any business handling card payments—violation fines can exceed $500,000/year.
  • EFT (Electronic Funds Transfer) uses ACH (Automated Clearing House) for domestic transfers (e.g., Ncell’s bill payments) and SWIFT for international (e.g., Daraz’s supplier payments).
  • Fraud detection relies on anomaly detection (e.g., sudden high-value transactions) and behavioral biometrics (typing speed, mouse movements).
  • Risk management in e-commerce includes multi-factor authentication (MFA), tokenization (replacing card numbers with tokens), and chargeback policies.
  • Legal compliance requires GDPR (EU), Nepal’s Electronic Transaction Act 2063, and tax laws (e.g., VAT on digital transactions).

1. Secure Electronic Transactions (SET) Protocol: How Online Payments Stay Secure

The SET protocol (developed by Visa/Mastercard) is the gold standard for securing credit card transactions over the internet. It uses dual signatures and digital certificates to ensure:

  • Confidentiality: Data is encrypted end-to-end.
  • Integrity: No tampering with transaction details.
  • Authentication: All parties (buyer, merchant, bank) are verified.
  • Non-repudiation: No party can deny participation.
Digital Certificate (from CA)Encrypted Order + Payment InfoBuyer (Cardholder)Digital Certificate (from CA)Order ConfirmationMerchantRoutes Encrypted DataNever Stores Raw Card DataPayment GatewayReceives FundsForwards to Issuer BankAcquirer Bank (Merchant’s Bank)Authorizes/Declines PaymentSends ResponseIssuer Bank (Buyer’s Bank)Issues Digital CertificatesValidates PartiesCertificate Authority (CA)SET Protocol Participants
Hierarchy of SET protocol participants and their roles in securing transactions.

How SET Works: Step-by-Step Flow

sequenceDiagram
    participant Buyer
    participant Merchant
    participant PaymentGateway
    participant AcquirerBank
    participant IssuerBank

    Buyer->>Merchant: 1. Order (item details)
    Merchant->>Buyer: 2. Order confirmation + digital certificate
    Buyer->>PaymentGateway: 3. SET request (encrypted order + payment info)
    PaymentGateway->>AcquirerBank: 4. Forward to bank (merchant’s account)
    AcquirerBank->>IssuerBank: 5. Authorize payment (buyer’s bank)
    IssuerBank-->>AcquirerBank: 6. Approval/Rejection
    AcquirerBank-->>PaymentGateway: 7. Response to merchant
    Merchant-->>Buyer: 8. Confirmation (no raw card data shared)

Key Participants in SET

Role Responsibility Example in Nepal
Buyer (Cardholder) Initiates transaction, provides encrypted payment details. You using eSewa to pay a Daraz seller.
Merchant Sends order to buyer, processes encrypted payment request. Daraz, Swoyambu Books.
Payment Gateway Routes encrypted data between merchant and bank (never sees raw card details). Khalti’s payment processor.
Acquirer Bank Merchant’s bank (receives funds). Global IME Bank (for Daraz merchants).
Issuer Bank Buyer’s bank (authorizes/declines payment). NMB Bank (for eSewa users).
Certificate Authority Issues digital certificates to validate parties. DigiCert, GlobalSign.

Why SET is Rare Today (But Still Important)

  • Complexity: Requires dual signatures (separate for order and payment), which increases processing time.
  • Replaced by Tokens: Modern systems (e.g., Apple Pay, Google Pay) use tokenization instead.
  • Still Used in: High-security sectors like government payments (e.g., NTC bill payments) and cross-border transactions.

2. Electronic Funds Transfer (EFT): How Money Moves Digitally

EFT enables real-time or batch transfers between accounts. Two key systems:

  1. Automated Clearing House (ACH): Used for domestic transfers (e.g., salary deposits, bill payments).
  2. SWIFT (Society for Worldwide Interbank Financial Telecommunication): Used for international transfers (e.g., Daraz suppliers paying overseas vendors).

How ACH Works (Example: Ncell Bill Payment via eSewa)

flowchart TD
    A["You (eSewa User)"] -->|"1. Select Ncell Bill"| B["eSewa App"]
    B -->|"2. Enter Amount"| C["eSewa Server"]
    C -->|"3. Generate ACH Request"| D["Nepal Clearing House (NCHL)"]
    D -->|"4. Debit Your Bank"| E["Your Bank: NMB/NIC Asia"]
    D -->|"5. Credit Ncell"| F["Ncell Bank Account"]
    F -->|"6. Update Your Bill"| A

ACH vs. SWIFT: Key Differences

Feature ACH (Domestic) SWIFT (International)
Scope Within a country (e.g., Nepal). Global (e.g., Nepal → USA).
Speed 1–3 business days. 1–5 business days.
Cost Low (Rs. 50–200). High (1–3% of amount + bank fees).
Use Case Salary, bill payments, merchant settlements. Cross-border trade, remittances.
Example in Nepal eSewa → NTC bill payment. Daraz supplier paying Alibaba vendor.

3. Payment Card Industry Data Security Standard (PCI-DSS): The Law for Card Payments

If your business accepts credit/debit cards, you must comply with PCI-DSS. Non-compliance can lead to:

  • Fines: Up to $500,000/year.
  • Card brand penalties: Visa/Mastercard can suspend your merchant account.
  • Liability for fraud: You pay for all fraudulent charges.
022.54567.590Requirement 1: Firewalls85Requirement 3: Protect Stored CHD72Requirement 4: Encrypt Transmission90Requirement 6: Vulnerability Management68Requirement 8: Access Control79Requirement 12: Logs & Monitoring88
PCI-DSS compliance rates (2023) for Nepal-based e-commerce platforms handling card payments (sample: Daraz, Khalti, eSewa).

The 12 PCI-DSS Requirements

Requirement What It Means Example in Nepal
1. Install firewalls. Protect cardholder data (CHD) from unauthorized access. Daraz’s server firewall blocking brute-force attacks.
2. No vendor defaults. Change default passwords on systems. Khalti changing default admin passwords.
3. Protect stored CHD. Encrypt card numbers (never store raw data). eSewa using tokenization (stores tokens, not card numbers).
4. Encrypt transmission. Use TLS 1.2+ for all online transactions. HTTPS on all Daraz checkout pages.
5. Use antivirus. Scan systems for malware. Ncell’s servers running ClamAV.
6. Develop secure apps. No SQL injection, buffer overflows. Pathao’s app using input validation.
7. Restrict access. Only authorized staff can access CHD. Bank tellers needing MFA to access card data.
8. Assign unique IDs. No shared admin accounts. Each Daraz employee has a unique login.
9. Track access. Log all actions on CHD. NMB Bank’s audit logs for card transactions.
10. Test security. Quarterly penetration testing. Global IME hiring ethical hackers.
11. Policy compliance. Train employees on security. eSewa’s annual phishing simulation drills.
12. Regular scans. Quarterly vulnerability scans. Daraz’s PCI-compliant scanning by Trustwave.

4. Fraud Detection in E-Commerce: How Platforms Stop Scams

Fraud costs e-commerce $16 billion/year globally. Common types:

  • Card fraud: Stolen card details.
  • Account takeover: Hacked buyer accounts.
  • Chargeback fraud: Buyer disputes a legitimate transaction.
  • Merchant fraud: Fake sellers (e.g., Daraz scams).
stateDiagram-v2
    [*] --> FraudDetection
    FraudDetection --> AnomalyDetection: Sudden High-Value Transaction
    FraudDetection --> BehavioralBiometrics: Typing Speed/Mouse Movements
    FraudDetection --> MachineLearning: AI Flagging Patterns
    AnomalyDetection --> AlertAdmin: >50% Increase in Order Value
    BehavioralBiometrics --> AlertAdmin: 30% Deviation in Typing Rhythm
    MachineLearning --> BlockTransaction: >90% Fraud Probability
    AlertAdmin --> [*]
State diagram of fraud detection workflow in platforms like Khalti or eSewa.

Fraud Detection Techniques

Method How It Works Example in Nepal
Anomaly Detection AI flags unusual patterns (e.g., sudden high-value purchase from a new IP). eSewa blocking a Rs. 500,000 transfer from a new device.
Behavioral Biometrics Analyzes typing speed, mouse movements. Khalti detecting a bot filling forms too fast.
Velocity Checks Limits transactions per minute (e.g., 3 card payments/hour). Ncell blocking 10 SIM registrations from one IP.
Device Fingerprinting Tracks browser, OS, and hardware details. Daraz banning a VPN user for suspicious activity.
3D Secure (3DS) Adds OTP/SMS verification for card payments. eSewa sending a one-time code for online payments.

5. Risk Management in E-Commerce: Protecting Your Business

Key Strategies

  1. Multi-Factor Authentication (MFA)

    • Example: eSewa requires OTP + fingerprint for large transactions.
    • Why? Reduces account takeover risk by 99.9%.
  2. Tokenization

    • Replaces card numbers with unique tokens (e.g., tok_visa_12345).
    • Example: When you save a card in Khalti, it stores a token, not your actual number.
  3. Chargeback Policies

    • Define legitimate dispute rules (e.g., "30-day window for undelivered items").
    • Example: Daraz’s 7-day return policy reduces fraudulent chargebacks.
  4. Regular Audits

    • PCI-DSS Requirement 10: Log all access to cardholder data.
    • Example: Global IME Bank audits merchant transactions weekly.

Laws Governing E-Commerce in Nepal

Law Key Provisions
Electronic Transaction Act 2063 Validates digital contracts (e.g., online orders).
Payment Systems Act 2064 Regulates e-wallets (eSewa, Khalti) and banks.
Consumer Protection Act 2075 Right to dispute fraudulent transactions.
Income Tax Act 2058 VAT on digital transactions (e.g., 13% on Daraz sales).
Cyber Security Act 2075 Penalties for data breaches (up to Rs. 10 million fine).

Ethical Issues in E-Commerce

  • Privacy: Collecting more data than needed (e.g., Daraz asking for PAN details for small purchases).
  • Transparency: Hiding shipping costs until checkout (banned in Nepal under Consumer Protection Act).
  • Accessibility: Not supporting Nepali language or mobile payments for rural users.

In the Real World

  1. eSewa’s SET-Like Security

    • When you pay a NTC bill via eSewa, the system uses tokenization (similar to SET’s dual signatures) to ensure your card details never reach NTC directly. Instead, eSewa generates a one-time token for the transaction.
    • Why it matters: Even if NTC’s database is hacked, attackers only get tokens, not real card numbers.
  2. Daraz’s PCI-DSS Compliance

    • Daraz merchants must use PCI-compliant payment gateways (e.g., Khalti, eSewa). If a seller stores raw card data, they risk fines and account suspension.
    • Real example: In 2022, a Daraz seller in Kathmandu was banned for 6 months after a data breach exposed 5,000 customer card details.
  3. Pathao’s Fraud Detection

    • Pathao uses behavioral biometrics to detect fake accounts. If a new user:
      • Books 10 rides in 5 minutes from the same location.
      • Uses automated mouse movements (like a bot).
      • The system flags the account for manual review.
    • Result: Pathao blocks ~20% of fraudulent sign-ups before they cause harm.

Exam Tip

What Examiners Want to See

  1. For SET Protocol:

    • Draw the sequence diagram (buyer → merchant → payment gateway → banks).
    • Explain dual signatures and digital certificates (not just "it’s secure").
    • Worked Example: "If a buyer orders a laptop from Daraz, trace how SET ensures the merchant never sees the card number."
  2. For PCI-DSS:

    • List 3 requirements and give Nepali examples (e.g., "Requirement 4: Daraz uses TLS 1.3 for checkout").
    • Calculate fines: "A merchant in Pokhara stores 10,000 card numbers without encryption. What’s the minimum penalty?" → $500,000/year.
  3. For Fraud Detection:

    • Compare 2 methods (e.g., "Anomaly detection vs. behavioral biometrics").
    • Case Study: "How would eSewa detect a fraudster trying to transfer Rs. 1 million from a new device in India?" → Velocity check + behavioral analysis.
  4. For Legal Questions:

    • Match laws to scenarios:
      • "A buyer disputes a Daraz order after 35 days. Which law applies?" → Consumer Protection Act 2075 (30-day limit).
      • "Khalti leaks user data. What’s the penalty?" → Cyber Security Act 2075 (up to Rs. 10M fine).

Common Mistakes to Avoid

  • ❌ Saying "SET is obsolete" without explaining why it’s still used in government payments.
  • ❌ Confusing ACH and SWIFT (remember: ACH = domestic, SWIFT = international).
  • ❌ Ignoring Nepali laws—always relate answers to eSewa, Daraz, or NTC.
  • ❌ Describing tokenization as encryption (they’re different!).

Practice Question (Solve Like an Exam)

Question: "As a security consultant for a Nepalese e-commerce startup, explain how you would implement PCI-DSS Requirement 3 (Protect Stored Cardholder Data) using real-world examples from Khalti and eSewa."

Model Answer:

  1. Never store raw card data:
    • Like eSewa, use tokenization (store tok_visa_abc123 instead of 4111-1111-1111-1111).
  2. Encrypt stored tokens:
    • Use AES-256 encryption (like Khalti does for its database).
  3. Limit access:
    • Only 2 employees (CFO + Security Lead) can decrypt tokens, with MFA required.
  4. Regular audits:
    • Quarterly scans (like Daraz’s PCI-compliant audits) to ensure no tokens are exposed.
  5. Legal compliance:
    • Train staff on Nepal’s Cyber Security Act 2075 (fines for data leaks).

Why this scores full marks:

  • Technical depth (AES-256, MFA, tokenization).
  • Nepali examples (eSewa, Khalti, Daraz).
  • Legal tie-in (Cyber Security Act).
  • Process-oriented (not just "use encryption").

Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 7.

Discussion

Loading…