Modeling and Analyzing Logic Vulnerabilities of E-Commerce Systems at the Design Phase
Journal article
Authors | Wangyang Yu, Lu Liu, Xiaoming Wang, Ovidiu Bagdasar and John Panneerselvam |
---|---|
Abstract | E-commerce systems have become tremendously popular and important for modern business processes in the world of the digital economy. E-commerce business processes rely on the distributed and concurrent interaction process among Web applications of participants, such as clients, merchants, third-party payment platforms (TPPs), and bank systems. Such complex business interactions bridge the gap of trustiness among participants and introduce new security challenges in the form of logical vulnerabilities, which are prevalent in the business process at the application level. The most pressing challenge is to guarantee security throughout the checkout process at the conceptual design phase such that the logic errors can be detected before the actual implementation. Maintenance and repair of implemented e-commerce systems can be extremely costly. To this end, this article proposes a novel modeling and analyzing methodology for multiparticipants and multisessions e-commerce interaction processes based on colored Petri nets (CPNs). First, we define a novel model that can efficiently depict the key properties of e-commerce business interaction processes. Second, several modeling principles are formulated based on the design specification of e-commerce systems. Finally, the concept of Transaction-Logical Consistency is defined to analyze and verify the logical vulnerabilities of e-commerce systems. Through a discussed case study, we demonstrate the feasibility and applicability of the proposed methodology and its efficiency in detecting problems those can potentially lead to logical vulnerabilities. |
Keywords | Analytical models; Electric commerce ; Petri nets; Testing |
Year | 2023 |
Journal | IEEE Transactions on Systems, Man, and Cybernetics: Systems |
Publisher | IEEE Xplore |
ISSN | 2168-2232 |
Digital Object Identifier (DOI) | https://doi.org/10.1109/tsmc.2023.3299605 |
Web address (URL) | https://doi.org/10.1109/TSMC.2023.3299605 |
Accepted author manuscript | License All rights reserved File Access Level Open |
Output status | Published |
Publication dates | 22 Aug 2023 |
Publication process dates | |
Deposited | 30 Aug 2023 |
https://repository.derby.ac.uk/item/q0458/modeling-and-analyzing-logic-vulnerabilities-of-e-commerce-systems-at-the-design-phase
Download files
Accepted author manuscript
2023 - AAM - Modeling and Analyzing Logic Vulnerabilities of E-Commerce Systems at the Design Phase - bare_jrnl.pdf | ||
License: All rights reserved | ||
File access level: Open |
77
total views98
total downloads3
views this month6
downloads this month