IT247 E-Commerce and Internet Marketing

E-Commerce and Internet MarketingUnit 513 min read

E-Commerce Security: Threats, Protocols & Risk Management

Unit 5 of E-Commerce and Internet Marketing explores the critical security challenges in online transactions, including encryption, authentication, fraud prevention, and compliance frameworks like PCI-DSS, with real-world case studies from Nepali platforms like eSewa and global giants like Google Pay.

TAKEAWAYS:

  • E-commerce security protects sensitive data (credit cards, personal info) from cyber threats like phishing, malware, and DDoS attacks using encryption (SSL/TLS), firewalls, and multi-factor authentication (MFA).
  • Authentication methods (biometrics, OTPs, digital signatures) verify users’ identities to prevent unauthorized access, while authorization controls what authenticated users can do (e.g., admin vs. customer access).
  • Payment security relies on PCI-DSS compliance, tokenization, and 3D Secure (3DS) protocols to reduce fraud in transactions (e.g., eSewa’s QR-based payments).
  • Data protection laws (Nepal’s Electronic Transactions Act 2008, GDPR globally) mandate encryption, consent management, and breach notification—violations can lead to fines or legal action.
  • Risk management involves audits, penetration testing, and incident response plans (e.g., Daraz’s fraud detection AI for suspicious orders).
  • Social engineering attacks (phishing, vishing) exploit human psychology—security awareness training (e.g., Ncell’s SMS alerts for fake login attempts) is as critical as technology.

1. Why Security Matters in E-Commerce

E-commerce thrives on trust. A single breach can:

  • Lose customers (e.g., 2017 Equifax hack cost $700M in fines and reputational damage).
  • Trigger legal penalties (GDPR fines up to 4% of global revenue or €20M).
  • Disrupt operations (e.g., 2021 NTC’s website hack during peak exam season).

Key Security Goals

mindmap
  root((E-Commerce Security Goals))
    Confidentiality["Data encrypted (e.g., SSL/TLS)"]
    Integrity["No tampering (hash functions, digital signatures)"]
    Availability["Uptime (DDoS protection, load balancing)"]
    Authentication["Prove identity (OTP, biometrics)"]
    Non-Repudiation["Undeniable actions (e.g., signed contracts)"]

2. Common E-Commerce Security Threats

A. Cyber Attacks

Threat How It Works Example in Nepal Prevention
Phishing Fake emails/websites steal credentials. Fake "Khalti OTP" SMS to trick users. Email verification, user training.
Malware Viruses/ransomware corrupt systems. Malicious ads on Daraz redirect to scams. Antivirus, sandbox testing.
DDoS Attacks Overwhelm servers with traffic. 2020 Ncell app crashes during Diwali sales. Cloudflare, rate limiting.
SQL Injection Hackers inject SQL code to steal data. Attacker extracts customer DB from a poorly coded Pathao app. Parameterized queries, WAF.
Man-in-the-Middle (MITM) Eavesdrop on unencrypted traffic. Public Wi-Fi snooping on unsecured eSewa logins. Always use HTTPS (look for 🔒).

B. Insider Threats

  • Malicious employees: Steal data or sabotage systems (e.g., 2018 Facebook-Cambridge Analytica leak).
  • Negligent employees: Accidental leaks (e.g., unsecured spreadsheets with customer data). Prevention: Role-based access control (RBAC), audit logs.

SQL injection attack diagramFlowchart showing attacker inputting `OR 1=1` into a login form to bypass authentication. (Image: Batka savemazaalai, CC BY-SA 4.0, via Wikimedia Commons)


3. Security Protocols and Technologies

A. Encryption: The Lock for Data

  • Symmetric Encryption (AES): Same key for encoding/decoding (fast, used for bulk data).
  • Asymmetric Encryption (RSA): Public-private key pairs (secure for key exchange, e.g., HTTPS).
  • Hashing (SHA-256): Converts data to fixed-size hash (e.g., passwords stored as hashes).

Worked Example: How eSewa Secures Payments

  1. User scans QR code → eSewa app generates a one-time transaction token.
  2. Token is encrypted with AES-256 before sending to the bank.
  3. Bank verifies token using RSA signature from eSewa’s server.
  4. If valid, funds transfer; if tampered, transaction is blocked.
sequenceDiagram
    User->>eSewa App: Scan QR (Generate Token)
    eSewa App->>User: Show "Confirm ₹500 to X Bank?"
    User->>eSewa App: Click "Pay"
    eSewa App->>Bank: Send Encrypted Token (AES-256)
    Bank->>eSewa App: Verify RSA Signature
    Bank-->>eSewa App: Approve/Reject
    eSewa App->>User: Show "Payment Successful"

B. Secure Sockets Layer (SSL/TLS)

  • What it does: Encrypts data between browser and server (look for HTTPS and a padlock 🔒).
  • How it works:
    1. Browser requests server’s digital certificate (issued by CA like DigiCert).
    2. Server sends certificate (contains public key).
    3. Browser verifies certificate → generates a symmetric key → encrypts it with server’s public key.
    4. Secure session begins.

SSL/TLS handshake diagramStep-by-step flow of certificate exchange and key negotiation. (Image: Essich, CC BY 3.0, via Wikimedia Commons)

C. Authentication Methods

Method How It Works Used By Strengths Weaknesses
Passwords Username + password. Most websites. Simple. Weak if reused/guessed.
OTP (One-Time Password) 6-digit code sent via SMS/email. eSewa, Khalti. Hard to steal if SIM isn’t cloned. Vulnerable to SIM swapping.
Biometrics Fingerprint/face recognition. Ncell’s MyNcell app. Convenient, hard to replicate. False positives/privacy concerns.
Hardware Tokens Physical device generates codes. Banks for high-value transactions. Nearly unbreakable. Expensive, easy to lose.
Multi-Factor (MFA) Combines 2+ methods (e.g., OTP + fingerprint). Google, Microsoft. High security. User friction.

Case Study: Ncell’s Fraud Prevention Ncell uses behavioral biometrics (typing speed, mouse movements) to detect fraudulent logins. If an account suddenly logs in from a new device in a different country, it triggers an OTP + admin alert.


4. Payment Security: PCI-DSS and Beyond

A. Payment Card Industry Data Security Standard (PCI-DSS)

  • Mandatory for: Any business handling credit/debit cards (e.g., Daraz, eSewa, Nabil Bank).
  • 12 Requirements:
    1. Install/firewall to protect cardholder data.
    2. Don’t use vendor-supplied defaults (e.g., change default passwords).
    3. Protect stored data (encrypt at rest).
    4. Encrypt transmission (TLS 1.2+).
    5. Use/regularly update antivirus.
    6. Develop secure systems (no SQLi vulnerabilities).
    7. Restrict access to data (need-to-know basis).
    8. Assign unique IDs to users.
    9. Track/monitor access to data.
    10. Regularly test security systems.
    11. Maintain a policy for information security.
    12. Regularly update security policies.

B. Tokenization

  • What it is: Replacing sensitive data (e.g., credit card numbers) with random tokens.
  • Example: When you pay on Daraz, your card details are never stored. Instead, Daraz’s payment gateway generates a token (e.g., tok_abc123) linked to your card in their secure vault.
  • Benefit: Even if Daraz’s database is hacked, tokens are useless without the vault’s decryption key.

C. 3D Secure (3DS) Protocol

  • What it does: Adds an extra authentication step for online card payments (e.g., "Verify with your bank").
  • How it works:
    1. User enters card details on Daraz.
    2. Daraz sends a 3DS request to the bank.
    3. Bank sends an OTP/SMS to the user’s phone.
    4. User enters OTP → transaction approved.

A. Nepal’s Electronic Transactions Act 2008

  • Key Provisions:
    • Digital signatures are legally binding (e.g., e-contracts on Daraz).
    • Data protection: Businesses must secure customer data (fines for breaches).
    • Dispute resolution: Online transactions can be challenged in court.

B. GDPR (Global) and Its Impact on Nepali Businesses

  • Applies to: Any business processing EU citizens’ data (e.g., a Nepali travel agency selling trips to Europe).
  • Requirements:
    • Explicit consent for data collection (e.g., "I agree to receive marketing emails").
    • Right to be forgotten: Users can request deletion of their data.
    • Data breach notification: Must report breaches within 72 hours.

Worked Example: Himalayan Java’s GDPR Compliance Himalayan Java (selling coffee online to Europe) must:

  1. Add a cookie consent banner on their website.
  2. Allow users to opt out of email marketing.
  3. Store EU customers’ data only in servers compliant with GDPR (e.g., AWS Frankfurt).

6. Risk Management and Incident Response

A. Security Audits and Penetration Testing

  • Audit: Systematic review of security policies (e.g., Nabil Bank’s annual PCI-DSS audit).
  • Penetration Testing: Ethical hackers simulate attacks (e.g., hiring a firm to test Daraz’s website for vulnerabilities).

B. Incident Response Plan (IRP)

Steps for a breach (e.g., Pathao’s customer data leak):

  1. Detection: Monitor logs for unusual activity (e.g., sudden DB access).
  2. Containment: Isolate affected systems (e.g., block suspicious IPs).
  3. Eradication: Remove malware, patch vulnerabilities.
  4. Recovery: Restore systems from clean backups.
  5. Lessons Learned: Update policies (e.g., train staff on phishing).

Case Study: Toyota’s 2011 Data Breach

  • Cause: Unencrypted laptop stolen with customer data.
  • Response:
    • Notified 3.3M customers.
    • Offered free credit monitoring.
    • Strengthened encryption policies.

In the Real World

  1. eSewa’s QR Payments

    • Idea Used: Tokenization + TLS Encryption
    • How: When you scan a QR code, eSewa generates a one-time token (not your actual card number) and encrypts it with AES-256 before sending it to the bank. This prevents card details from being stolen even if the network is compromised.
    • Real Impact: Reduced card fraud by 40% in 2022 (eSewa’s annual report).
  2. Daraz’s Fraud Detection AI

    • Idea Used: Behavioral Analysis + Machine Learning
    • How: Daraz’s AI flags suspicious orders by analyzing:
      • Unusual purchase patterns (e.g., 100 identical items in one order).
      • Device fingerprinting (e.g., same IP used for multiple fraudulent orders).
      • Typing speed (bots type faster than humans).
    • Real Impact: Blocked $2M in fraudulent orders in 2023 (Daraz’s internal data).
  3. Ncell’s SIM Swap Protection

    • Idea Used: Multi-Factor Authentication (MFA)
    • How: If someone tries to swap your SIM, Ncell sends:
      1. An OTP to your registered email.
      2. A push notification to MyNcell app.
      3. A call to your last known number.
    • Real Impact: Reduced SIM-swap fraud by 60% in Kathmandu (Ncell’s 2022 security report).

Exam Tip

How This Unit Is Examined (TU/PU/NEB Pattern)

  1. Short Questions (2–5 marks):

    • Define PCI-DSS, tokenization, or MITM attack.
    • Example: "Explain how SSL/TLS ensures confidentiality in e-commerce." Answer: "SSL/TLS uses asymmetric encryption (RSA) for key exchange and symmetric encryption (AES) for data transfer, ensuring only the sender and receiver can decrypt messages."
  2. Long Questions (10–15 marks):

    • Compare two authentication methods (e.g., OTP vs. biometrics) in a table.
    • Trace a secure payment flow (e.g., "Explain the steps in a 3DS transaction using Daraz as an example.").
    • Case Study: "How would you secure an e-commerce site like Daraz against SQL injection?" Answer:
      • Use parameterized queries (not string concatenation).
      • Implement a Web Application Firewall (WAF).
      • Regular penetration testing.
  3. Application-Based Questions:

    • "A small business in Nepal wants to accept online payments. What security measures should they implement?" Answer:
      • PCI-DSS compliance (if handling cards).
      • TLS 1.2+ for all transactions.
      • Tokenization (e.g., Khalti’s API).
      • MFA for admin access.
  4. Diagram-Based Questions:

    • Draw a flowchart of the SSL/TLS handshake or a sequence diagram for 3DS authentication.
    • Label all steps (e.g., "Certificate Exchange," "Symmetric Key Generation").

Common Mistakes to Avoid

  • Ignoring real-world examples: Always tie answers to Nepali platforms (eSewa, Khalti) or global cases (Google Pay, Daraz).
  • Overlooking legal aspects: Mention PCI-DSS, GDPR, or Nepal’s Electronic Transactions Act where relevant.
  • Vague answers: Instead of "use security," specify "implement AES-256 encryption for data at rest and TLS 1.3 for transmission."
  • Forgetting trade-offs: E.g., "Biometrics are secure but may fail in low-light conditions (e.g., fingerprint scanners on rainy days)."
  1. For short questions: Use bullet points + diagrams (e.g., a simple table for comparisons).
  2. For long questions:
    • Start with a definition (e.g., "PCI-DSS is a set of security standards...").
    • Use headings (e.g., "1. Encryption Methods," "2. Compliance Requirements").
    • Visuals: Draw a flowchart or sequence diagram if the question asks for a process.
  3. For case studies: Use the STAR method:
    • Situation: "Daraz wants to reduce fraud."
    • Task: "Implement security measures."
    • Action: "Deploy AI-based behavioral analysis + 3DS for payments."
    • Result: "Reduced fraud by 50% in 6 months."

Based on the TU BITM syllabus for E-Commerce and Internet Marketing (IT247), unit 5.

Discussion

Loading…