Security aspects in modern service component-oriented application logic for social e-commerce systems

被引:3
|
作者
Nabi, Faisal [1 ,2 ]
Tao, Xiaohui [1 ,2 ]
Yong, Jianming [1 ,2 ]
机构
[1] Univ Southern Queensland, Sch Business, Toowoomba, Qld, Australia
[2] Univ Southern Queensland, Sch Sci, Toowoomba, Qld, Australia
关键词
Design flaws; Subversion attack; Social media-based e-commerce system; Service component architecture; Assurance & security; UML-based modeling; Business logic attacks;
D O I
10.1007/s13278-020-00717-9
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Modern practices in social commerce are a subset of e-Commerce focusing on security framework protocols such as secure transactional protocols, cryptographic schemes, and sanitization criteria. It is assumed that these practices will ensure stable social media-based e-Commerce applications. The main concern in utilizing these practices focus on software component composition, and integration flaws, which are often overlooked in their business application logic. These problems can render the effect of modern information security concepts null and void. The weakest link in social media-based e-Commerce applications is the component's logic subversion on its server side, which is caused by developers overlooking the design process. This paper addresses a unique issue in aspects of information security in application logic vulnerability called subversion attack, which can be classified as a design flaw. This kind of security flaw cannot be prevented by many traditional security mechanisms commonly used in modern e-Commerce systems. To address this issue, we propose the use of security assurance methodologies in service component-oriented applications to be utilized through threat modeling and a novel technique component fault detection model. This idea is further extended to the modeling component and its applications using a UML secure design approach. To validate the technique, the methods applied in this paper are verification and validation for security by design testing to avoid the business logic design flaw problem in rapidly built component-based social media e-Commerce applications.
引用
收藏
页数:19
相关论文
共 50 条
  • [1] Security aspects in modern service component-oriented application logic for social e-commerce systems
    Faisal Nabi
    Xiaohui Tao
    Jianming Yong
    Social Network Analysis and Mining, 2021, 11
  • [2] Component-oriented middleware for commerce systems
    Sessions, R
    IEEE SOFTWARE, 1998, 15 (05) : 42 - 43
  • [3] Secure business application logic for e-commerce systems
    Nabi, F
    COMPUTERS & SECURITY, 2005, 24 (03) : 208 - 217
  • [4] Service Oriented Architecture to Integrate E-Commerce and Social Media in Indonesia
    Hutagaol, Junedi
    Dennis
    Oktaviandre, Frido
    Richard, Matius
    Valentinus
    Sfenrianto
    LECTURE NOTES IN ELECTRICAL, ELECTRONIC AND COMPUTER ENGINEERING, 2019, : 82 - 88
  • [5] DSP application in E-commerce security
    Hu, JK
    Xi, ZP
    Jennings, A
    Lee, HYJ
    Wahyudi, D
    2001 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, VOLS I-VI, PROCEEDINGS: VOL I: SPEECH PROCESSING 1; VOL II: SPEECH PROCESSING 2 IND TECHNOL TRACK DESIGN & IMPLEMENTATION OF SIGNAL PROCESSING SYSTEMS NEURALNETWORKS FOR SIGNAL PROCESSING; VOL III: IMAGE & MULTIDIMENSIONAL SIGNAL PROCESSING MULTIMEDIA SIGNAL PROCESSING - VOL IV: SIGNAL PROCESSING FOR COMMUNICATIONS; VOL V: SIGNAL PROCESSING EDUCATION SENSOR ARRAY & MULTICHANNEL SIGNAL PROCESSING AUDIO & ELECTROACOUSTICS; VOL VI: SIGNAL PROCESSING THEORY & METHODS STUDENT FORUM, 2001, : 1005 - 1008
  • [6] Security and Disturbances in e-Commerce Systems
    Vymetal, Dominik
    Suchanek, Petr
    LIBEREC ECONOMIC FORUM 2011, 2011, : 580 - 589
  • [7] Component-oriented development of application systems: A German report
    Ortner, Erich
    Lonthoff, Joerg
    WMSCI 2005: 9th World Multi-Conference on Systemics, Cybernetics and Informatics, Vol 4, 2005, : 386 - 391
  • [8] Implementing the Logical Security Framework for E-Commerce Based on Service-Oriented Architecture
    Luhach, Ashish Kr.
    Dwivedi, Sanjay K.
    Jha, Chandra K.
    PROCEEDINGS OF INTERNATIONAL CONFERENCE ON ICT FOR SUSTAINABLE DEVELOPMENT ICT4SD 2015, VOL 2, 2016, 409 : 1 - 13
  • [9] A framework for E-commerce oriented recommendation systems
    Weng, L.-T. (l.weng@student.qut.edu.au), IEEE Systems, Man, and Cybernetics Society; Information Processing Society of Japan; Kagawa University (Institute of Electrical and Electronics Engineers Computer Society):
  • [10] A framework for e-commerce oriented recommendation systems
    Weng, LT
    Xu, Y
    Li, YF
    PROCEEDINGS OF THE 2005 INTERNATIONAL CONFERENCE ON ACTIVE MEDIA TECHNOLOGY (AMT 2005), 2005, : 309 - 314