An approach to protect credit card information against threat agents

Kilaru, Trinil Kumar

Small companies handle product sales using a custom e-commerce website. The web server uses the Linux, Apache, MySQL and PHP/Python/Perl (LAMP) solution stack and components are hosted on a single rack-mounted server co-located at a data center. Each customer transaction record has a credit card associated with it that is stored in the MySQL database. At the company office, a third-party solution is used for accounting. The third-party solution includes a server, owned and maintained by the vendor, which accepts transaction records in standard unencrypted formats, such as CSV or XML files. Once the transaction records are submitted to the server they are encrypted and stored in a database on the vendor server. The security of that data becomes the responsibility of the vendor. At regular intervals a batch job on the LAMP server pulls new transactions from the database and sends them via FTP to the accounting server. The e-commerce company has identified a number of threat agents from whom they want to protect the credit card numbers. Some of the expected threats that results in the loss of data or some secure information include database administrator, data center and internet attackers. This thesis include implements an algorithm in order to keep the data transaction more secure so that no unauthorized person can access credit card information or related data. The data that pass between the server and the related client would be in an encrypted form. A single secure architecture solution that provides protection for credit card numbers would be described against threat agents.

Read the paper · More papers on PaperTik