E-Commerce Essentials (Laudon/Traver)

Instructor’s Manual: Chapter 5

E-commerce Security and Payment Systems

Teaching Objectives
 Explain the scope of e-commerce crime and security problems.
 Describe the key dimensions of e-commerce security.
 Identify the key security threats in the e-commerce environment.
 Describe how technology helps protect the security of messages sent over the
 Identify the tools used to establish secure Internet communications channels and
protect networks, servers, and clients.
 Identify the major e-commerce payment systems in use today.

Key Terms
integrity, p. 167
nonrepudiation, p. 168
authenticity, p. 168
confidentiality, p. 168
privacy, p. 168
availability, p. 169
malicious code (malware), p. 170
drive-by download, p. 171
virus, p. 171
worm, p. 171
Trojan horse, p. 171
backdoor, p.171
bot, p. 171
botnet, p 171
potentially unwarranted program (PUP), p. 172
adware, p. 172
browser parasite, p. 172
spyware, p. 172
social engineering, p. 172
phishing, p. 172
hacker, p. 174

cracker, p. 174
cybervandalism, p. 174
hactivism, p. 174
data breach, p. 174
spoofing, p. 175
Denial of Service (DoS) attack, p. 175
distributed Denial of Service (dDos) attack, p. 176
sniffer, p. 176
zero-day vulnerability, p. 177
encryption, p. 180
cipher text, p. 180
key (cipher), p. 181
substitution cipher, p. 181
transposition cipher, p. 181
symmetric key encryption (secret key encryption), p. 182
public key cryptography, p. 182
hash function, p. 183
digital signature (e-signature), p. 183
digital certificate, p. 186
certification authority (CA), p. 186
public key infrastructure (PKI), p. 186
secure negotiated session, p. 189
session key, p. 189
virtual private network (VPN), p. 190
firewall, p. 190
proxy server (proxy), p. 191
merchant account, p. 193
online stored value payment system, p. 194
near field communications (NFC), p. 195
digital cash, p. 195
virtual currency, p. 196
electronic billing presentment and payment (EBPP) system, p. 196

Brief Chapter Outline

Cyberwar: MAD 2.0
5.1 The E-commerce Security Environment
The Scope of the Problem
What Is Good E-commerce Security?
Dimensions of E-commerce Security

5.2 Security Threats in the E-commerce Environment

Malicious Code
Potentially Unwanted Programs
Phishing and Identity Theft
Hacking, Cybervandalism, Hacktivism, and Data Breaches
Credit Card Fraud/Theft

Spoofing (Pharming) and Spam (Junk) Web Sites

Denial of Service (DoS) and Distributed Denial of Service (dDoS) Attacks
Insider Attacks
Poorly Designed Server and Client Software
Social Network Security Issues
Mobile Platform Security Issues
Cloud Security Issues
Insight on Technology: Think Your Smartphone Is Secure?

5.3 Technology Solutions

Protecting Internet Communications
Insight on Society: Web Dogs and Anonymity: Identity 2.0
Securing Channels of Communication
Protecting Networks
Protecting Servers and Clients

5.4 E-commerce Payment Systems

Online Credit Card Transactions
Alternative Online Payment Systems
Mobile Payment Systems: Your Smartphone Wallet
Digital Cash and Virtual Currencies

5.5 Electronic Billing Presentment and Payment

Market Size and Growth
EBPP Business Models

5.6 Case Study: Online Payment Marketplace: Goat Rodeo

5.7 Review
Key Concepts

Figure 5.1 The E-commerce Security Environment, p. 168
Figure 5.2 Vulnerable Points in an E-commerce Transaction, p. 170
Figure 5.3 An Example of a Nigerian Letter E-mail Scam, p. 173
Figure 5.4 Tools Available to Achieve Site Security, p.181
Figure 5.5 Public Key Cryptography: A Simple Case, p. 184
Figure 5.6 Public Key Cryptography with Digital Signatures, p. 185
Figure 5.7 Digital Certificates and Certification Authorities, p. 187
Figure 5.8 Secure Negotiated Sessions Using SSL/TLS, p. 189
Figure 5.9 Online Payment Methods in the United States, p. 192
Figure 5.10 How an Online Credit Card Transaction Works, p. 193

Table 5.1 Customer and Merchant Perspectives on the Different Dimensions of
E-commerce Security, p. 169

Teaching Suggestions
This chapter first summarizes the security threats and solutions that managers of
e-commerce sites need to be aware of, and then reviews the different payment systems
available on the Web.

The key point students should take away from this chapter, with respect to security, is
that security is a complex, multi-layered phenomenon that involves a diverse set of risks
and a balanced approach. It requires three main elements: special technology,
organizational rules and procedures, and laws and industry standards. A good place to
start a lecture is with Figure 5.1, which illustrates the interaction and supportive nature of
these three elements. No single “magic bullet” solution exists for Internet security any
more than for general societal security. With respect to payment systems, the key point
for students is that the Web has not created completely new methods of payment,
although it has changed how methods of payment are implemented. Web consumers in
the United States predominantly use credit cards for purchases, and efforts to wean
consumers away from their credit cards have generally failed. The primary exception to
this is PayPal, which still relies on the stored value provided by credit cards or checking

Key Points
The opening case, Cyberwar: MAD 2.0, highlights the increasing vulnerability of the
Web to large-scale attacks. Ask students to discuss how their daily life might be affected
as a result. Indeed, at times it appears that the Internet itself has become a battlefield
involving not just rogue groups of terrorists attacking the systems of developed countries
but also involving large nation states such as the United States as an active participant in
conducting its own cyberwar for its own purposes.

Additional questions for class discussion might include the following:

 What is the difference between hacking and cyberwar?
 Why has cyberwar become more potentially devastating in the past decade?
 Why has Google been the target of so many cyberattacks?
 Will a political solution to MAD 2.0 be effective enough?

The Scope of the Problem. This section is likely to be of particular interest to students.
Ask students to discuss whether they themselves or anyone they know has ever been a
victim of a computer crime. Do they think computer crime is being overplayed or
underplayed in the popular press, given the statistics available and discussed in this

Defining Good Security. Good security has many elements. Table 5.1 lists the six key
ingredients required for e-commerce sites and how the key stakeholders (consumers and

merchants) view the issue. You may want to walk students through this table so they
understand the nature of the problem as well as the different perspectives.

E-Commerce Security Threats. The e-commerce environment holds threats for both
consumers and merchants. Figure 5.2 provides an illustration of vulnerable points in the
transaction process. Malicious code, potentially unwanted programs (PUPs), phishing and
identity theft, hacking, cybervandalism and data breaches, DoS/dDos attacks, and
spoofing/pharming are uniquely technical threats to security. Credit card fraud/theft,
although it appears frequently in the news, does not impact consumers as much as
students might think because of federal laws that limit liability to $50 for the consumer.
However, this leaves the merchant open to much higher losses. Ask students whether
they have any personal experience with any of these types of e-commerce security

Many students will not necessarily realize the relationship between poorly designed
server and client software and security issues, or the security issues posed by social
networks or smartphones, so this is something worth pointing out. The Insight on
Technology case, Think Your Smartphone is Secure? highlights the latter issue. Class
discussion questions might include the following:
 What types of threats do smartphones face?
 Are there any particular vulnerabilities to this type of device?
 Are apps more or less likely to be subject to threats than traditional PC software

Technology Solutions. Some types of security threats can be ameliorated through

technological means, but not all. A variety of encryption techniques, in particular public
key encryption, are useful for protecting Internet communications; they address issues of
integrity, authenticity, and confidentiality of messages. It is useful to slowly and carefully
walk students through Figures 5.5 and 5.6 to illustrate public key encryption and digital
signatures. Figure 5.7 is useful for discussing the elements of public key infrastructure.
Figure 5.8 shows how SSL/TLS—the most common form of encryption used in
e-commerce transactions—works.

There are limitations to technical security measures, and they often presume a secure
organizational environment before they can work. Encryption of any kind is susceptible
to disloyal or disgruntled employees and poor client side security (such as keeping your
passwords on an insecure PC directory). Encryption also slows processors and the entire
transaction process; the better the security, the worse the performance.

The Insight on Society case, Web Dogs and Anonymity: Identity 2.0, discusses a federal
government initiative called “voluntary trusted identity,” an effort to create a new Web
security environment by forcing all who use the Internet to positively identify
themselves, and thereby eliminate anonymity on the Internet. In security circles, and a
larger community of philosophers and social commentators, anonymity is the opposite of
accountability. When people can post comments online, or send you e-mail and don’t
positively identify who they are, they can escape all efforts to hold themselves

Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall

