Title :
Are e-commerce users defenceless?
Author :
M. Trampus;M. Ciglaric;M. Pancur;T. Vidmar
Author_Institution :
Fac. of Comput. & Inf. Sci., Ljubljana Univ., Slovenia
fDate :
6/25/1905 12:00:00 AM
Abstract :
We are interested in new ways of threats and attack on the e-commerce. The server side of e-commerce platform is usually very well protected and secured. Unfortunately, this is not true for the client side. End users are usually undereducated in the field of computer security. They use Internet clients such as Web browsers and e-mail programs to do their e-commerce business. Their platform that is used to run these programs can hardly be trusted. This paper focuses on the attacks on system and application infrastructure. The main idea of our approach is to take advantage of existing applications and attack them while they are executing. We analyze the steps that need to be taken in such attacks and point out the properties of the applications and execution environments that can be exploited. To demonstrate the findings, we present two case studies of such attacks. The first exploits a Web browser which uses SSL (Secure Sockets Layer) and the second an e-mail client which uses digital signatures. In both cases we are able to successfully perform the attack which escapes the end user´s notice. In the final part of the paper we present a possible defence against such attack together with our work on a security enforcement system.
Keywords :
"Application software","Information science","Protection","Computer security","Internet","Computer crime","Web server","Electronic mail","Sockets","Digital signatures"
Conference_Titel :
Parallel and Distributed Processing Symposium, 2003. Proceedings. International
Print_ISBN :
0-7695-1926-1
DOI :
10.1109/IPDPS.2003.1213442