• DocumentCode
    2301589
  • Title

    A Multi-Tier, Multi-Role Security Framework for E-Commerce Systems

  • Author

    Cachia, Ernest ; Micallef, Mark

  • Author_Institution
    Dept. of Comput. Sci. & Artificial Intelligence, Malta Univ., Msida
  • fYear
    2007
  • fDate
    26-29 March 2007
  • Firstpage
    422
  • Lastpage
    432
  • Abstract
    As the use of the Internet for commercial purposes continues to grow, so do the number of security threats which attempt to disrupt online systems (Glisson and Welland, 2005); (Deloitte, 2005); and (Gordon et al., 2005). A number of these threats are in fact unintended (Mackey, 2003). For example, a careless employee might drop a cup of coffee onto essential equipment. However, when compared to the brick and mortar world, the Internet offers would-be attackers a more anonymous environment in which to operate. Also, the free availability of hacking tools makes it possible even for the curious teenager to carry out dangerous attacks. Despite this ever-present threat however, it is all too often the case that security is dealt with (if at all) after a Web application has been developed (Gaur, 2000). This is mainly due to our software development heritage whereby companies prefer to focus on the functionality of new systems because that provides and immediate return on investment. This paper proposes a framework for building security into Web applications as they are being developed. The core philosophy here is that security is too big an issue to leave up to one person/team after the product has been developed. The framework also provides a quality assurance process and a communication protocol to ensure that all security-related tasks have been carried out
  • Keywords
    Internet; computer crime; electronic commerce; software quality; Internet; Web applications; communication protocol; e-commerce systems; hacking tools; multirole security framework; multitier security framework; security threats; software quality assurance; Acoustical engineering; Application software; Communication system security; Computer science; Computer security; Internet; Investments; Mortar; Software engineering; System testing; E-Commerce; Security; Software Quality Assurance; Web Applications;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Engineering of Computer-Based Systems, 2007. ECBS '07. 14th Annual IEEE International Conference and Workshops on the
  • Conference_Location
    Tucson, AZ
  • Print_ISBN
    0-7695-2772-8
  • Type

    conf

  • DOI
    10.1109/ECBS.2007.8
  • Filename
    4148959