Designing a Secure Framework Method for Secure Business Application Logic Integrity in e-Commerce Systems.
Faisal Nabi · International journal of network security · 2011
Currently e-commerce system security focuses on mechanisms such as secure transactional protocols, cryptographic schemes, parameter sanitization and it is assumed that putting these in place will guarantee a secure eCommerce application. However, often vulnerabilities in the business application logic itself are often ignored that can make the efiect of these security mechanisms null and void. Essentially, the weakest link can be at the server rather the client and ignoring this is done at a developer’s peril. This paper focuses on this weakest link in ecommerce system. In particular, it considers componentbased middleware platforms where vulnerabilities may exist in the middleware itself or the components used to construct the e-Commerce application. We outline a logic attacks that would not be prevented by the deployment of the mechanisms commonly used in e-Commerce systems. To counter this problem, we present a secure framework method based on existing techniques that treats security as a flrst-class concept and considers its interaction with business logic.