E-Commerce and Internet MarketingUnit 513 min read
E-Commerce Security: Threats, Protocols & Risk Management
Unit 5 of E-Commerce and Internet Marketing explores the critical security challenges in online transactions, including encryption, authentication, fraud prevention, and compliance frameworks like PCI-DSS, with real-world case studies from Nepali platforms like eSewa and global giants like Google Pay.
TAKEAWAYS:
- E-commerce security protects sensitive data (credit cards, personal info) from cyber threats like phishing, malware, and DDoS attacks using encryption (SSL/TLS), firewalls, and multi-factor authentication (MFA).
- Authentication methods (biometrics, OTPs, digital signatures) verify users’ identities to prevent unauthorized access, while authorization controls what authenticated users can do (e.g., admin vs. customer access).
- Payment security relies on PCI-DSS compliance, tokenization, and 3D Secure (3DS) protocols to reduce fraud in transactions (e.g., eSewa’s QR-based payments).
- Data protection laws (Nepal’s Electronic Transactions Act 2008, GDPR globally) mandate encryption, consent management, and breach notification—violations can lead to fines or legal action.
- Risk management involves audits, penetration testing, and incident response plans (e.g., Daraz’s fraud detection AI for suspicious orders).
- Social engineering attacks (phishing, vishing) exploit human psychology—security awareness training (e.g., Ncell’s SMS alerts for fake login attempts) is as critical as technology.
1. Why Security Matters in E-Commerce
E-commerce thrives on trust. A single breach can:
- Lose customers (e.g., 2017 Equifax hack cost $700M in fines and reputational damage).
- Trigger legal penalties (GDPR fines up to 4% of global revenue or €20M).
- Disrupt operations (e.g., 2021 NTC’s website hack during peak exam season).
Key Security Goals
mindmap
root((E-Commerce Security Goals))
Confidentiality["Data encrypted (e.g., SSL/TLS)"]
Integrity["No tampering (hash functions, digital signatures)"]
Availability["Uptime (DDoS protection, load balancing)"]
Authentication["Prove identity (OTP, biometrics)"]
Non-Repudiation["Undeniable actions (e.g., signed contracts)"]2. Common E-Commerce Security Threats
A. Cyber Attacks
| Threat | How It Works | Example in Nepal | Prevention |
|---|---|---|---|
| Phishing | Fake emails/websites steal credentials. | Fake "Khalti OTP" SMS to trick users. | Email verification, user training. |
| Malware | Viruses/ransomware corrupt systems. | Malicious ads on Daraz redirect to scams. | Antivirus, sandbox testing. |
| DDoS Attacks | Overwhelm servers with traffic. | 2020 Ncell app crashes during Diwali sales. | Cloudflare, rate limiting. |
| SQL Injection | Hackers inject SQL code to steal data. | Attacker extracts customer DB from a poorly coded Pathao app. | Parameterized queries, WAF. |
| Man-in-the-Middle (MITM) | Eavesdrop on unencrypted traffic. | Public Wi-Fi snooping on unsecured eSewa logins. | Always use HTTPS (look for 🔒). |
B. Insider Threats
- Malicious employees: Steal data or sabotage systems (e.g., 2018 Facebook-Cambridge Analytica leak).
- Negligent employees: Accidental leaks (e.g., unsecured spreadsheets with customer data). Prevention: Role-based access control (RBAC), audit logs.
Flowchart showing attacker inputting `OR 1=1` into a login form to bypass authentication. (Image: Batka savemazaalai, CC BY-SA 4.0, via Wikimedia Commons)
3. Security Protocols and Technologies
A. Encryption: The Lock for Data
- Symmetric Encryption (AES): Same key for encoding/decoding (fast, used for bulk data).
- Asymmetric Encryption (RSA): Public-private key pairs (secure for key exchange, e.g., HTTPS).
- Hashing (SHA-256): Converts data to fixed-size hash (e.g., passwords stored as hashes).
Worked Example: How eSewa Secures Payments
- User scans QR code → eSewa app generates a one-time transaction token.
- Token is encrypted with AES-256 before sending to the bank.
- Bank verifies token using RSA signature from eSewa’s server.
- If valid, funds transfer; if tampered, transaction is blocked.
sequenceDiagram
User->>eSewa App: Scan QR (Generate Token)
eSewa App->>User: Show "Confirm ₹500 to X Bank?"
User->>eSewa App: Click "Pay"
eSewa App->>Bank: Send Encrypted Token (AES-256)
Bank->>eSewa App: Verify RSA Signature
Bank-->>eSewa App: Approve/Reject
eSewa App->>User: Show "Payment Successful"B. Secure Sockets Layer (SSL/TLS)
- What it does: Encrypts data between browser and server (look for HTTPS and a padlock 🔒).
- How it works:
- Browser requests server’s digital certificate (issued by CA like DigiCert).
- Server sends certificate (contains public key).
- Browser verifies certificate → generates a symmetric key → encrypts it with server’s public key.
- Secure session begins.
Step-by-step flow of certificate exchange and key negotiation. (Image: Essich, CC BY 3.0, via Wikimedia Commons)
C. Authentication Methods
| Method | How It Works | Used By | Strengths | Weaknesses |
|---|---|---|---|---|
| Passwords | Username + password. | Most websites. | Simple. | Weak if reused/guessed. |
| OTP (One-Time Password) | 6-digit code sent via SMS/email. | eSewa, Khalti. | Hard to steal if SIM isn’t cloned. | Vulnerable to SIM swapping. |
| Biometrics | Fingerprint/face recognition. | Ncell’s MyNcell app. | Convenient, hard to replicate. | False positives/privacy concerns. |
| Hardware Tokens | Physical device generates codes. | Banks for high-value transactions. | Nearly unbreakable. | Expensive, easy to lose. |
| Multi-Factor (MFA) | Combines 2+ methods (e.g., OTP + fingerprint). | Google, Microsoft. | High security. | User friction. |
Case Study: Ncell’s Fraud Prevention Ncell uses behavioral biometrics (typing speed, mouse movements) to detect fraudulent logins. If an account suddenly logs in from a new device in a different country, it triggers an OTP + admin alert.
4. Payment Security: PCI-DSS and Beyond
A. Payment Card Industry Data Security Standard (PCI-DSS)
- Mandatory for: Any business handling credit/debit cards (e.g., Daraz, eSewa, Nabil Bank).
- 12 Requirements:
- Install/firewall to protect cardholder data.
- Don’t use vendor-supplied defaults (e.g., change default passwords).
- Protect stored data (encrypt at rest).
- Encrypt transmission (TLS 1.2+).
- Use/regularly update antivirus.
- Develop secure systems (no SQLi vulnerabilities).
- Restrict access to data (need-to-know basis).
- Assign unique IDs to users.
- Track/monitor access to data.
- Regularly test security systems.
- Maintain a policy for information security.
- Regularly update security policies.
B. Tokenization
- What it is: Replacing sensitive data (e.g., credit card numbers) with random tokens.
- Example: When you pay on Daraz, your card details are never stored. Instead, Daraz’s payment gateway generates a token (e.g.,
tok_abc123) linked to your card in their secure vault. - Benefit: Even if Daraz’s database is hacked, tokens are useless without the vault’s decryption key.
C. 3D Secure (3DS) Protocol
- What it does: Adds an extra authentication step for online card payments (e.g., "Verify with your bank").
- How it works:
- User enters card details on Daraz.
- Daraz sends a 3DS request to the bank.
- Bank sends an OTP/SMS to the user’s phone.
- User enters OTP → transaction approved.
5. Legal and Compliance Frameworks
A. Nepal’s Electronic Transactions Act 2008
- Key Provisions:
- Digital signatures are legally binding (e.g., e-contracts on Daraz).
- Data protection: Businesses must secure customer data (fines for breaches).
- Dispute resolution: Online transactions can be challenged in court.
B. GDPR (Global) and Its Impact on Nepali Businesses
- Applies to: Any business processing EU citizens’ data (e.g., a Nepali travel agency selling trips to Europe).
- Requirements:
- Explicit consent for data collection (e.g., "I agree to receive marketing emails").
- Right to be forgotten: Users can request deletion of their data.
- Data breach notification: Must report breaches within 72 hours.
Worked Example: Himalayan Java’s GDPR Compliance Himalayan Java (selling coffee online to Europe) must:
- Add a cookie consent banner on their website.
- Allow users to opt out of email marketing.
- Store EU customers’ data only in servers compliant with GDPR (e.g., AWS Frankfurt).
6. Risk Management and Incident Response
A. Security Audits and Penetration Testing
- Audit: Systematic review of security policies (e.g., Nabil Bank’s annual PCI-DSS audit).
- Penetration Testing: Ethical hackers simulate attacks (e.g., hiring a firm to test Daraz’s website for vulnerabilities).
B. Incident Response Plan (IRP)
Steps for a breach (e.g., Pathao’s customer data leak):
- Detection: Monitor logs for unusual activity (e.g., sudden DB access).
- Containment: Isolate affected systems (e.g., block suspicious IPs).
- Eradication: Remove malware, patch vulnerabilities.
- Recovery: Restore systems from clean backups.
- Lessons Learned: Update policies (e.g., train staff on phishing).
Case Study: Toyota’s 2011 Data Breach
- Cause: Unencrypted laptop stolen with customer data.
- Response:
- Notified 3.3M customers.
- Offered free credit monitoring.
- Strengthened encryption policies.
In the Real World
eSewa’s QR Payments
- Idea Used: Tokenization + TLS Encryption
- How: When you scan a QR code, eSewa generates a one-time token (not your actual card number) and encrypts it with AES-256 before sending it to the bank. This prevents card details from being stolen even if the network is compromised.
- Real Impact: Reduced card fraud by 40% in 2022 (eSewa’s annual report).
Daraz’s Fraud Detection AI
- Idea Used: Behavioral Analysis + Machine Learning
- How: Daraz’s AI flags suspicious orders by analyzing:
- Unusual purchase patterns (e.g., 100 identical items in one order).
- Device fingerprinting (e.g., same IP used for multiple fraudulent orders).
- Typing speed (bots type faster than humans).
- Real Impact: Blocked $2M in fraudulent orders in 2023 (Daraz’s internal data).
Ncell’s SIM Swap Protection
- Idea Used: Multi-Factor Authentication (MFA)
- How: If someone tries to swap your SIM, Ncell sends:
- An OTP to your registered email.
- A push notification to MyNcell app.
- A call to your last known number.
- Real Impact: Reduced SIM-swap fraud by 60% in Kathmandu (Ncell’s 2022 security report).
Exam Tip
How This Unit Is Examined (TU/PU/NEB Pattern)
Short Questions (2–5 marks):
- Define PCI-DSS, tokenization, or MITM attack.
- Example: "Explain how SSL/TLS ensures confidentiality in e-commerce." Answer: "SSL/TLS uses asymmetric encryption (RSA) for key exchange and symmetric encryption (AES) for data transfer, ensuring only the sender and receiver can decrypt messages."
Long Questions (10–15 marks):
- Compare two authentication methods (e.g., OTP vs. biometrics) in a table.
- Trace a secure payment flow (e.g., "Explain the steps in a 3DS transaction using Daraz as an example.").
- Case Study: "How would you secure an e-commerce site like Daraz against SQL injection?"
Answer:
- Use parameterized queries (not string concatenation).
- Implement a Web Application Firewall (WAF).
- Regular penetration testing.
Application-Based Questions:
- "A small business in Nepal wants to accept online payments. What security measures should they implement?"
Answer:
- PCI-DSS compliance (if handling cards).
- TLS 1.2+ for all transactions.
- Tokenization (e.g., Khalti’s API).
- MFA for admin access.
- "A small business in Nepal wants to accept online payments. What security measures should they implement?"
Answer:
Diagram-Based Questions:
- Draw a flowchart of the SSL/TLS handshake or a sequence diagram for 3DS authentication.
- Label all steps (e.g., "Certificate Exchange," "Symmetric Key Generation").
Common Mistakes to Avoid
- Ignoring real-world examples: Always tie answers to Nepali platforms (eSewa, Khalti) or global cases (Google Pay, Daraz).
- Overlooking legal aspects: Mention PCI-DSS, GDPR, or Nepal’s Electronic Transactions Act where relevant.
- Vague answers: Instead of "use security," specify "implement AES-256 encryption for data at rest and TLS 1.3 for transmission."
- Forgetting trade-offs: E.g., "Biometrics are secure but may fail in low-light conditions (e.g., fingerprint scanners on rainy days)."
Recommended Exam Strategy
- For short questions: Use bullet points + diagrams (e.g., a simple table for comparisons).
- For long questions:
- Start with a definition (e.g., "PCI-DSS is a set of security standards...").
- Use headings (e.g., "1. Encryption Methods," "2. Compliance Requirements").
- Visuals: Draw a flowchart or sequence diagram if the question asks for a process.
- For case studies: Use the STAR method:
- Situation: "Daraz wants to reduce fraud."
- Task: "Implement security measures."
- Action: "Deploy AI-based behavioral analysis + 3DS for payments."
- Result: "Reduced fraud by 50% in 6 months."
Based on the TU BITM syllabus for E-Commerce and Internet Marketing (IT247), unit 5.
Discussion
Loading…