An Integrated Vulnerability Assessment of Electronic Commerce Websites

Issah Baako, Sayibu Umar
{"title":"An Integrated Vulnerability Assessment of Electronic Commerce Websites","authors":"Issah Baako, Sayibu Umar","doi":"10.5815/ijieeb.2020.05.03","DOIUrl":null,"url":null,"abstract":": This paper examines the security issues on electronic commerce websites in Ghana using technical and nontechnical procedures. The study assessed e-commerce websites for the security tools employed to protect user data and other related privacy issues on the websites. It also analyzed e-commerce websites for encryption security tools that protect customer data and test e-commerce websites for the presence of security vulnerabilities that could threaten the security of the sites and their users using w3af. The study used a combination of three methods; web content analysis, information security audit and testing of the websites using w3af, a vulnerability assessment tool. Web application attack and audit framework (w3af) was used to test and identify possible vulnerabilities on the e-commerce websites that could be used by malicious users to steal customer data for fraudulent intent. The research focused to reveal the security vulnerabilities present on e-commerce websites that could affect the trust of clients, the satisfaction of clients, and patronage of e-commerce services by customers. The study found credit card number disclosures, full path disclosures vulnerabilities, cross-site request forgery vulnerabilities and social security number exposures of clients on the e-commerce websites. These security weaknesses in these e-commerce websites have been highlighted as findings in the study that would inform policy direction on electronic data collection, protection and use in the e-commerce industry in Ghana. The findings will also inform industry players in the e-commerce sector on the need to strengthen security on their websites and caution customers to be security conscious on all e-commerce websites. The major significance of the study is the fact that majority of the electronic commerce websites have a lot of vulnerabilities making them unsecure for customers to trust their private data into their care. This study as such informs the customer society and the electronic commerce industry of these security weaknesses and the urgent need to get them fixed. Some solutions have been suggested in the paper to assist in fixing these security vulnerabilities. These solutions have provided the best results. A diligent application of these methods in addressing the vulnerabilities would provide a more secure and less vulnerable e-commerce websites for users. The precautions suggested could assist protect customers and reduce cyber threats during online shopping. E-commerce Security, cyber security, cyber-insurance E-Learning technologies.","PeriodicalId":427770,"journal":{"name":"International Journal of Information Engineering and Electronic Business","volume":"25 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-10-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International Journal of Information Engineering and Electronic Business","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.5815/ijieeb.2020.05.03","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

Abstract

: This paper examines the security issues on electronic commerce websites in Ghana using technical and nontechnical procedures. The study assessed e-commerce websites for the security tools employed to protect user data and other related privacy issues on the websites. It also analyzed e-commerce websites for encryption security tools that protect customer data and test e-commerce websites for the presence of security vulnerabilities that could threaten the security of the sites and their users using w3af. The study used a combination of three methods; web content analysis, information security audit and testing of the websites using w3af, a vulnerability assessment tool. Web application attack and audit framework (w3af) was used to test and identify possible vulnerabilities on the e-commerce websites that could be used by malicious users to steal customer data for fraudulent intent. The research focused to reveal the security vulnerabilities present on e-commerce websites that could affect the trust of clients, the satisfaction of clients, and patronage of e-commerce services by customers. The study found credit card number disclosures, full path disclosures vulnerabilities, cross-site request forgery vulnerabilities and social security number exposures of clients on the e-commerce websites. These security weaknesses in these e-commerce websites have been highlighted as findings in the study that would inform policy direction on electronic data collection, protection and use in the e-commerce industry in Ghana. The findings will also inform industry players in the e-commerce sector on the need to strengthen security on their websites and caution customers to be security conscious on all e-commerce websites. The major significance of the study is the fact that majority of the electronic commerce websites have a lot of vulnerabilities making them unsecure for customers to trust their private data into their care. This study as such informs the customer society and the electronic commerce industry of these security weaknesses and the urgent need to get them fixed. Some solutions have been suggested in the paper to assist in fixing these security vulnerabilities. These solutions have provided the best results. A diligent application of these methods in addressing the vulnerabilities would provide a more secure and less vulnerable e-commerce websites for users. The precautions suggested could assist protect customers and reduce cyber threats during online shopping. E-commerce Security, cyber security, cyber-insurance E-Learning technologies.
电子商务网站的综合脆弱性评估
本文考察了加纳电子商务网站使用技术和非技术程序的安全问题。该研究评估了电子商务网站用于保护用户数据和网站上其他相关隐私问题的安全工具。它还分析了电子商务网站的加密安全工具,以保护客户数据,并测试电子商务网站是否存在可能威胁网站及其使用w3af的用户安全的安全漏洞。该研究使用了三种方法的组合;利用漏洞评估工具w3af对网站进行Web内容分析、信息安全审计和测试。Web应用程序攻击和审计框架(w3af)用于测试和识别电子商务网站上可能存在的漏洞,恶意用户可以利用这些漏洞窃取客户数据以达到欺诈目的。本研究的重点是揭示电子商务网站存在的安全漏洞,这些漏洞可能会影响客户的信任、客户的满意度和客户对电子商务服务的惠顾。该研究发现了电子商务网站上客户的信用卡号码泄露、全路径泄露漏洞、跨站点请求伪造漏洞和社会安全号码泄露漏洞。研究结果强调了这些电子商务网站的安全弱点,这些弱点将为加纳电子商务行业的电子数据收集、保护和使用的政策方向提供信息。调查结果亦会让电子商贸业界人士了解加强其网站保安的必要性,并提醒顾客在所有电子商贸网站都要加强保安意识。这项研究的主要意义在于,大多数电子商务网站都有很多漏洞,这使得客户无法将他们的私人数据托付给他们。这项研究通知客户社会和电子商务行业的这些安全弱点和迫切需要得到他们的修复。本文提出了一些解决方案来帮助修复这些安全漏洞。这些解决方案提供了最好的结果。认真应用这些方法来解决漏洞,将为用户提供一个更安全、更不易受攻击的电子商务网站。建议的预防措施可以帮助保护顾客,减少网上购物时的网络威胁。电子商务安全、网络安全、网络保险、电子学习技术。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信