Tuesday, 10 November 2015

E-Commerce Series: Risk Management for the Internet

E-Commerce Series: Risk Management for the Internet

Summary: A discussion of risk management issues for e-commerce insurance products. At the conclusion of the session, the audience should have an increased knowledge of basic risk management skills and methods required for e-commerce insurance programs, as well as a better understanding of risk management for non-e-commerce insurance programs.

This session is valuable to persons with or without prior knowledge of risk management concepts.

I'm going to make a short introductory presentation.

The E-commerce Security Environment: 


Dimensions of E-commerce Security-


  • Integrity: ability to ensure that information being displayed on a Web site or transmitted/received over the Internet has not been altered in any way by an unauthorized party
  • Non-repudiation: ability to ensure that e-commerce participants do not deny (repudiate) online actions
  • Authenticity: ability to identify the identity of a person or entity with whom you are dealing on the Internet
  • Confidentiality: ability to ensure that messages and data are available only to those authorized to view them 
  • Privacy: ability to control use of information a customer provides about himself or herself to merchant 
  • Availability: ability to ensure that an e-commerce site continues to function as intended



  • Different Dimensions of E-commerce Security



    The Tension Between Security and Other Values


  • Security vs. ease of use: the more security measures that are added, the more difficult a site is to use, and the slower it becomes
  • Security vs. desire of individuals to act anonymously                                                                                                                                                                                                                                                         

  • Security Threats in the E-commerce Environment

    Three key points of vulnerability:
         Client
         Server
         Communications channel
    Most common threats:
         Malicious code
         Hacking and cyber-vandalism
         Credit card fraud/theft
         Spoofing
         Denial of service attacks
         Sniffing
         Insider jobs

    A Logical Design for a Simple Web Site




    A Physical Design for a Simple Web Site





    A Typical E-commerce Transaction




    Vulnerable Points in an E-commerce Environment


    Malicious Code
    • Viruses: computer program that as ability to replicate and spread to other files; most also deliver a “payload” of some sort (may be destructive or benign); include macro viruses, file-infecting viruses and script viruses
    • Worms: designed to spread from computer to computer
    • Trojan horse: appears to be benign, but then does something other than expected
    • Bad applets (malicious mobile code): malicious Java applets or ActiveX controls that may be downloaded onto client and activated merely by surfing to a Web site
    Examples of Malicious Code



    Hacking and Cyber-vandalism

    • Hacker: Individual who intends to gain unauthorized access to a computer systems
    • Cracker: Used to denote hacker with criminal intent (two terms often used interchangeably)
    • Cyber-vandalism: Intentionally disrupting, defacing or destroying a Web site
    • Types of hackers include:                                                                                                                        White hats – Members of “tiger teams” used by corporate security departments to test their own security measures                                                                                                                      Black hats – Act with the intention of causing harm                                                                    Grey hats – Believe they are pursuing some greater good by breaking in and revealing system flaws

    Credit Card Fraud
    • Fear that credit card information will be stolen deters online purchases 
    • Hackers target credit card files and other customer information files on merchant servers; use stolen data to establish credit under false identity  
    • One solution: New identity verification mechanisms   
    Spoofing, DoS and dDoS Attacks, Sniffing, Insider Jobs             

    • Spoofing: Misrepresenting oneself by using fake e-mail addresses or masquerading as someone else
    • Denial of service (DoS) attack: Hackers flood Web site with useless traffic to inundate and overwhelm network 
    • Distributed denial of service (dDoS) attack: hackers use numerous computers to attack target network from numerous launch points 
    • Sniffing: type of eavesdropping program that monitors information traveling over a network; enables hackers to steal proprietary information from anywhere on a network 
    • Insider jobs:single largest financial threat                                                                                                                                                                                                                                                
    Technology Solutions
    • Protecting Internet communications (encryption)
    • Securing channels of communication (SSL (secure sockets layer), S-HTTP, VPNs) URL
    • changes from HTTP to HTTPS
    • SSL: Protocol that provides secure communications between client and server
    • Protecting networks (firewalls)
    • Protecting servers and clients    

    Tools Available to Achieve Site Security     


    Protecting Internet Communications: Encryption
    • Encryption: The process of transforming plain text or data into cipher text that cannot be read by anyone other than the sender and receiver
    • Purpose:    Secure stored information                                                                                                               Secure information transmission
    • Provides:   Message integrity:                                                                                                                           Non-repudiation                                                                                                                             Authentication                                                                                                                                 Confidentiality
    Encryption ensures:
    • Message integrity: provides assurance that message has been altered
    • Non-repudiation: prevents the user from denying he or she sent the message
    • Authentication: provides verification of the identity of the person or machine sending the message
    • Confidentiality: gives assurance that the message was not read by others

    Public Key Encryption
    • Public key cryptography solves symmetric key encryption problem of having to exchange secret key
    • Uses two mathematically related digital keys – public key (widely disseminated) and private key (kept secret by owner)
    • Both keys are used to encrypt and decry-pt message
    • Once key is used to encrypt message, same key cannot be used to decry-pt message
    • For example, sender uses recipient’s public key to encrypt message; recipient uses his/her private key to decrypt it Slide 5-22 Public Key Cryptography
    Public Key Cryptography – A Simple Case


    Public Key Encryption using Digital Signatures and Hash Digests


  • Application of hash function (mathematical algorithm) by sender prior to encryption produces hash digest that recipient can use to verify integrity of data


  • Double encryption with sender’s private key (digital signature) helps ensure authenticity and non-repudiation

  • Public Key Cryptography with Digital Signatures


    Public Key Cryptography: Creating a Digital Envelope

    Secure Negotiated Sessions Using SSL




    Protecting Networks: Firewalls and Proxy Servers
    • Firewall: Software application that acts as a filter between a company’s private network and the Internet
    • Firewall methods include:                                                                                                                        Packet filters                                                                                                                                  Application gateways
    • Proxy servers: Software servers that handle all communications originating from for being sent to the Internet (act as “spokesperson” or “bodyguard” for the organization)                                                     
    Firewalls and Proxy Servers

                         


    Protecting Servers and Clients



  • Operating system controls: Authentication and access control mechanisms.
  • Anti-virus software: Easiest and least expensive way to prevent threats to system integrity.


  •   Research Limitation

    One of the limitations in research includes lack of adequate information on a particular subject.
    Research equipment's are very hard or expensive to acquire leading to formulation mere assumptions. Another hindrance is poor or inaccessibility to the region of study.
    Some of the limitations of doing a research include access of information, availability of enough resources and time management. The availability of experts in editing and guidance may also be minimal where support from friends or organisation may not be enough.

    DATA ANALYSIS AND INTERPRETATION AND FINDINGS

    CONCLUSIONS:-

    • community consensus on essential details to improve quality of products and services based on real requirements of end-users.
    • successful implementation among early adopters which then results in a faster and broader adoption process. 
    • greater flexibility for innovation and increased revenues. 
    • the differentiation by cost, availability, speed, reach and flexibility when the product becomes a commodity, as profit margins decrease.






                                                                                                                               

    No comments:

    Post a Comment