E-Commerce

UBAI 3013 E-Commerce

Nowadays, people rely on the Internet to do their daily work. Although Internet has brought a lot of advantages to the users, but no doubt, there is also threat of online security increasing day to day.

There are few categories of threat:

1. Accidental actions
This category encompasses problems arising from basic lack of knowledge about online security concepts and includes issues such as poor password choices, accidental or erroneous business transactions, accidental disclosure, and erroneous or outdated software.
Related problems occur as a result of misconfigured security products and information leakage resulting from insecure information transfers.


2.Malicious attacks

  • Attack that specifically aims harm computers.
  • Types of Malicious attacks:

a.Computer Virus:

-It is the most common form of malicious code.
-It is a program that attaches itself to other program.
-Major types of virus:
i. File Infectors
ii. System or boot-record infectors
iii. Macro Viruses
iv. Multi-part

-Example of computer virus:
I.

Melissa” virus/worm - It will cause computer show down and face frequent failure.
II.

I Love You” virus - A small piece of code attached to electronic mail which will cause an e-mail send to everyone in an address book, then damaging victims' machines.

III.Trojan horse - Personal information will be stolen as Trojan track into the computer.


b.Denial of Service Attacks (DoS)

  • It is an attack on a web site that uses specialized software to send a flood of data packets to the target computer with the intention of overloading its resources and cause the network shut down.

c.Distributed denial-of-service attack (DDoS)

  • A DoS attacks that gains illegal administrative access to as many computers on the internet as possible and uses these multiple computers to send a flood of data pockets to the target computer.


3.Online fraud

  • It is a broad term covering Internet transactions that involve falsified information.
  • Types of Online fraud:

a.Identity Theft

-Electronic commerce information can be intercepted as a result of vulnerabilities in computer security. Thieves can then take information such as credit card numbers and misuse on it.

b.Data Theft

-A term used to describe not only the theft of information but also unauthorized perusal or manipulation of private data.


Ways to help prevent Threats of online security:

  • Use and update anti-virus software, anti spyware software and firewall frequently.
  • Be aware of email attachments from unknown sources.
  • Develop a strong password and change them frequently.
  • Do not download free software unless you have verified that it is legitimate.
  • Stay away from 'questionable' websites.
  • Be cautious of pop-ups.
  • Back up your data frequently.
  • Always delete cookies in the computer to prevent track on the history/password.

In conclusion, we should prepare well before online to secure us being threat of online security.

Related Links: http://www.bsagovernment.com/downloads/MajorOnlineThreats.pdf http://www.vermontpcsolutions.com/articles/10-free-ways-to-help-prevent-malware-threats.html

Phishing is a new word produced from ‘fishing’, it refers to a new type of network attack where the attacker creates a replica of an existing Web page to fool users (e.g., by using specially designed e-mails or instant messages) into submitting personal, financial, or password by masquerading as a trustworthy person or business in an electronic communication. This information then can be used for future target advertisements or even identity theft attacks (e.g., transfer money from victims’ bank account).

Example 1: Phishing email / Phishing website


A frequently used attack method is to send phishing e-mails to potential victims, which seemed to be sent by banks, online organizations, or ISPs. In these e-mails, they will makeup some causes such as password of your credit card had been mis-entered for many times, or they are providing upgrading services, to allure you visit their Web site to conform or modify your account number and password through the hyperlink provided in the e-mail. You will then be linked to a counterfeited Web site after clicking those links. Legitimate organizations would never request this information of you via email.



Example 2: JavaScript Obfuscation

There is a trend in phishing today to make an attempt to further fooling a victim in believing he/she is on a trusted page, at say, Netbank. Unmodified, a copied Netbank site will look like this on the phisher’s hosting server:



The location bar, which takes up approximately 2% of the screen height, accounts for virtually that all of the indication that a Web site is genuine. This is easily circumvented with a well known JavaScript vulnerability posted on the Bugtraq security mailing list in May of 2004, which uses a floating pop-up frame to change the address bar to the familiar:



The ability to produce “chromeless” frames outside the browser window using the window open JavaScript function continues to be available to Web developers, but thankfully, are now blocked by recent versions of Internet Explorer’s and Mozilla Firefox’s built-in “pop-up blockers,”.

Here is a quick checklist to bear in mind during our surfing, we should alert to the risks of phishing:
1. If you receive a mail that asks you to take immediate action, such as "to restore access to your bank account…." please don't click the link. Never has the bank will ask you to give them your user ID and password online. If in suspect something, speak with the bank directly to find out the truth.
2. Be alert in all Internet activities. Therefore be aware that there are unscrupulous elements out there trying to extract your personal details for their nefarious uses.
3. Check whether anything all right by log in to your account regularly.
4. Ensure your web browser is the latest version with all security patches updated to help you to detect and block the phishing. Web sites by using various spam filters to enhance the security of the web sites.
5. Do not filling out forms in email messages, especially if the form requires you to fill in personal detail information.
6. Never leave personal accounts unattended for long period of time (even for a month). Make it a habit to check your debit/credit of account and if you notice anything unusual, get clarification immediately.

7. Never reveal your personal information to anyone; however although genuine or trustful requester may sound. Personal details should only know by you and is your personal asset. It is better to be careful a bite.

Related links:
http://internet.suite101.com/article.cfm/avoid_phishing_attempts

http://research.microsoft.com/en-us/um/people/chguo/phishing.pdf

http://y2u.co.uk/Knowledge_Information/Technology/RN_Computer_Phishing_Scam.htm

http://www.phishtank.com/what_is_phishing.php

http://www.planbsecurity.net/wp/503167001_PhishingDetectionandPrevention.pdf


Are you taking steps to protect your personal and financial information? How do you safeguard? Nowadays, we will rely on computer to save our personal data and doing financial transactions such as e-banking by using computer in order to save our time. After all, if the information falls into person with bad intention, it can lead to fraud or identity theft. Therefore, do you think that safeguards that you done are sufficient enough to protect your personal and financial information?

There are some ways to safeguard our personal and financial data:


1. User ID
Avoid identifying information in user IDs, such as first initial and full last name. We should use a substitute name that avoids any reference to your name, job or other personal attributes can make tracking more difficult. Besides, we shall not use the same ID across multiple services.

2. Encryption and password security
Whenever we are transmitting data over private or public networks, we should assume that somebody could be eavesdropping on the packet data that we sent and receive. Therefore, when we transmitting sensitive data, we should use some form of encryption to protect our data. Besides, we should use stronger password to protect our access data. For example, use longer password or a combination of numeric and alphabet passwords. By using encryption and password security, we can ensure that no unauthorized people can view our data if they can physically access it.

3. Install and update antivirus and antispyware programs
Make sure antivirus and antispyware programs are well installed to protect our computer against viruses and Trojan horse from stealing or modifying our data on computer. In addition, we also need to keep our virus definitions up to date. Besides, we should regularly scan our computer system for spyware because spyware may affect performance of our computer.

4. Avoid accessing financial information in public
We should not access financial information and do any financial transaction in public such as coffee shop or cyber café that offers wireless access. It is because we do not know whether there have been installed spyware in their computer and hacker can easily get our information if there is no a strong firewall.


Related Links:
http://technorati.com/tag/personal-data
http://www.msisac.org/awareness/news/2007-03.cfm

3rd party certification program is used to ensure that the original content of an electronic document is safeguarded from being changed by unauthorized person. Certificate Authorities (CAs) are third parties that issue digital certificates which used to authenticate websites, individuals and software companies.



MSC Trustgate is a licensed Certification Authority (CA) in Malaysia since 1999. They offer security solutions that are needed by individuals, enterprises, government, and e-commerce service providers using digital certificates, digital signatures, encryption and decryption.

It’s very important for an organization to ensure the security of their confidential data. Therefore, they can use certificates to secure their data and manage identification credentials from users and computers within and outside your organization. Examples of the certificates are:

Public Key Infrastructure (PKI)
PKI is a combination of software, encryption technologies, processes and services which safeguard communications and business transaction. It is done by exchanging digital certificates between authenticated users and trusted resources. By using PKI, an organization can achieve its objective of Confidentiality, Integrity, Authenticity and Non-repudiation of data.

Digital ID
Everyday, there are millions of transactions being carried out over the unsecured network. These transactions normally contain information such as customer’s details, company’s pricing decision and other highly confidential information. Such information can be easily altered if not properly encrypted. Examples of Digital ID are CryptoSuite and Secured E-mail.

Therefore, Digital ID provides protection to this information so that such information remains private in its transferring process by signing and encrypting transaction. It uses private key and public key performs following operations that supplement PKI:

Authentication
  • Verification of real identity of an individual, computer, computer program & E-Commerce websites.
Privacy
  • Assurance of confidential data remains private

Authorization

  • Assurance that only authorized users have rights access to private data

Integrity

  • Assurance that stored data have not been amended without authorization

Non-repudiation

  • Assurance that online users cannot falsely deny or repudiate their transaction

VeriSign



Furthermore, VeriSign is also one of the programs used by organization in Malaysia. MSC Trustgate is the first company in Asia which appointed as VeriSign Authorized Training Centre. VeriSign provides various types of security products such as digital certificates, payment processing, managed firewalls to mobile call roaming, toll free call database queries and downloadable digital content for mobile devices.


MyKey




Besides Organization, Malaysian Government is also applying 3rd party certification program in National Identity Card (MyKad) of every citizen. MyKey is the PKI solution that works with our MyKad which allows us to conduct several Internet activities such as online submission of tax return, online banking and digitally sign documents.

Members of www.wowwowecommerce.blogspot.com

Members of www.wowwowecommerce.blogspot.com