• Home
  • Search
  • Online Transaction Security Risk Management for E-commerce Web Applications
  • Cite Icon1
  • https://doi.org/10.11648/j.ajomis.20170201.12Copy DOI Icon

Online Transaction Security Risk Management for E-commerce Web Applications

  • Abstract
  • Literature Map
  • Citations
  • Similar Papers
Abstract

Over the past decade, e-commerce creates exciting new opportunities for business but also brings new web application vulnerabilities and transaction security risks. A stream of news of phishing attacks, website spoofing, payment card skimming (credit /debit cards), fraud in online transactions, malware attack (malicious code attack of viruses, worms, Trojans, and bots), hacker/cracker infiltration, vandalism, identity theft and data breaches of payment card or bank details are increasingly reported. Web application security risk management, therefore, is essential for secure e-commerce online transactions, including order processing, payment transaction, banking and clearing processing. Therefore, the main purpose of this study was to propose a web application security risk management methodology to perform e-commerce web application security risk management, helping organizations understand and improve their e-commerce web application security risks. In order to achieve this purpose, the goal of this study has been two-fold: (1) How will organizations measure threat likelihood, impact consequence and severity of their e-commerce web application security risk? (2) What management methodology is required to prompt the e-commerce web application security vulnerabilities measurement and improvement? Using OWASP Top Ten Vulnerabilities as target items, the proposed management methodology is disciplined in a PDCA based ISO/IEC 27005 iterative process activities, integrating Common Criteria attack potential ratings as threat likelihood scales and the FIPS 199 impact categories as impact consequence scales to categorize severity of every e-commerce web application vulnerabilities. Following the proposed management procedure, all the critical e-commerce web application vulnerabilities can be reviewed, analyzed, prioritized and remedied effectively and efficiently, moving on again in a continuous cycle.

Similar Papers
  • Research Article

Secure Development - Web Application Security.

  • Jan 01, 2013
  • IOSR Journal of Computer Engineering
  • Sayyad Arif Ulla
  • Research Article
  • Citations14

Web Application Security through Comprehensive Vulnerability Assessment

  • Jan 01, 2023
  • Procedia Computer Science
  • Prasanth Satya Sai Kiran Gandikota +4
  • Conference Article
  • Citations3

Web application reconnaissance scan detection using LSTM network based deep learning

  • Mar 10, 2022
  • Bronjon Gogoi +2
  • Research Article
  • Citations20

Web Application Security Tools Analysis

  • Nov 08, 2017
  • Studies in Media and Communication
  • Abdulrahman Alzahrani +4
  • Research Article
  • Citations1

Hybrid Method on Clickjacking Detection and Prevention in Modern Advertisements

  • Nov 28, 2019
  • International Journal of Innovative Computing
  • Kirit Shashank Dhurandhar +1
  • Book Chapter
  • Citations1

Vulnerability Detection and Sanitization Synthesis

  • Jan 01, 2017
  • Tevfik Bultan +3
  • Research Article
  • Citations8

Nscanner: Vulnerabilities Detection Tool for Web Application

  • Dec 01, 2020
  • Journal of Physics: Conference Series
  • R Utaya Surian +2
  • Research Article

Autopen Test: Leveraging Automation for Real-Time Web Vulnerability Scanning

  • Apr 23, 2025
  • INTERNATIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT
  • Snehlata Mishra
  • Book Chapter
  • Citations1

Dynamic Web View Materialization

  • Aug 14, 2020
  • Akshay Kumar +1
  • Conference Article

Research on Web application injection vulnerabilities detection method based on pattern matching

  • May 06, 2022
  • Qican Ma +3
  • Book Chapter
  • Citations7

Automated Security Testing Framework for Detecting SQL Injection Vulnerability in Web Application

  • Jan 01, 2015
  • Nor Fatimah Awang +1
  • Research Article
  • Citations1

Improving Malicious Web Code Classification with Sequence by Machine Learning

  • Oct 31, 2014
  • IEIE Transactions on Smart Processing and Computing
  • Incheon Paik
  • Conference Article
  • Citations11

A Search-Based Testing Approach for XML Injection Vulnerabilities in Web Applications

  • Mar 01, 2017
  • Sadeeq Jan +3
  • Supplementary Content

Layout Investigation of GUI Navigational Interactions of Android Applications

  • Nov 27, 2019
  • Figshare
  • Joylyn Alexander Lewis
  • Research Article
  • Citations55

Defending against Web Application Vulnerabilities

  • Feb 01, 2012
  • Computer
  • Nuno Antunes +1
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.