A Case Study of Cyber Subversion Attack based Design Flaw in Service Oriented Component Application Logic
Article
Article Title | A Case Study of Cyber Subversion Attack based Design Flaw in Service Oriented Component Application Logic |
---|---|
Article Category | Article |
Authors | Nabi, Faisal, Zhou, Xujuan, Iftikhar, Umna and Attaullah, Hafiz Muhammad |
Journal Title | Journal of Cyber Security Technology |
Journal Citation | 8 (3), pp. 204-228 |
Number of Pages | 25 |
Year | 2024 |
Publisher | Taylor & Francis |
Place of Publication | United Kingdom |
ISSN | 2374-2917 |
2374-2925 | |
Digital Object Identifier (DOI) | https://doi.org/10.1080/23742917.2023.2261169 |
Web Address (URL) | https://www.tandfonline.com/doi/full/10.1080/23742917.2023.2261169 |
Abstract | Modern e-commerce systems are more likely focused on mechanisms of security, such as secure transactional protocols, cryptographic schemes and parameter sanitization, and it is assumed that putting these in place will guarantee a secure e-commerce application. However, vulnerabilities in the business application logic itself are often ignored which can make the effect of these security mechanisms null and void. Essentially, the weakest link can be at the server rather than client because of business logic and insecure server-side business components, its security ignoring is another factor, which is done at developer’s peril. This paper focuses on the weakest link (component’s logic subversion) in the e-commerce system. We outline a logical attack (subversion attack, class Design Flaw) that would not be prevented by the deployment of the mechanisms commonly used in e-commerce systems. To further investigate this problem, we propose a security assurance methodology for service component-oriented application that will be practiced through threat modeling and component fault detection model with further modeling component and its application using unified modeling language secure-design approach with a valid technique (verification, validation model for security-by-design testing) for design flaw detection to avoid the business logic problem in component-based e-commerce applications from existing application logic. |
Keywords | Design flaws; subversion attack; e-commerce system; service component architecture assurance |
Contains Sensitive Content | Does not contain sensitive content |
ANZSRC Field of Research 2020 | 4604. Cybersecurity and privacy |
Public Notes | Files associated with this item cannot be displayed due to copyright restrictions. |
https://research.usq.edu.au/item/zqzyv/a-case-study-of-cyber-subversion-attack-based-design-flaw-in-service-oriented-component-application-logic
Download files
19
total views11
total downloads7
views this month6
downloads this month