A Taxonomy of Logic Attack Vulnerabilities in Component-based e-Commerce System
Faisal Nabi, Jianming Yong, Xiaohui Tao · International Journal for Information Security Research · 2019
This paper addresses the problem associated with a lack of clear web application related vulnerabilities taxonomies identifying and classifying two different types of vulnerability classes in the ecommerce CSB based web applications. The paper has done this by organizing the significant classification ,which proposes the Classification of logical Vulnerabilities based on Design Flaws vs. Technical Vulnerabilities based on Implementation level Faults and Bugs in the e-commerce web application (Application component based software that resides in the mid-tier of the system) from the security assessment perspective for CBS based e-Commerce application. The most important point is to integrate the knowledge contained in the attack patterns with boundary knowledge related to vulnerability of the target CBS based web Application e-commerce system and the potential threats. Taxonomies (Technical Vulnerability based) and the identified logical vulnerabilities attack Taxonomy).