31
Views
0
CrossRef citations to date
0
Altmetric
Review article

A Case Study of Cyber Subversion Attack based Design Flaw in Service Oriented Component Application Logic

ORCID Icon, , &
Received 22 Aug 2023, Accepted 17 Sep 2023, Published online: 09 Oct 2023
 

ABSTRACT

Modern e-commerce systems are more likely focused on mechanisms of security, such as secure transactional protocols, cryptographic schemes and parameter sanitization, and it is assumed that putting these in place will guarantee a secure e-commerce application. However, vulnerabilities in the business application logic itself are often ignored which can make the effect of these security mechanisms null and void. Essentially, the weakest link can be at the server rather than client because of business logic and insecure server-side business components, its security ignoring is another factor, which is done at developer’s peril. This paper focuses on the weakest link (component’s logic subversion) in the e-commerce system. We outline a logical attack (subversion attack, class Design Flaw) that would not be prevented by the deployment of the mechanisms commonly used in e-commerce systems. To further investigate this problem, we propose a security assurance methodology for service component-oriented application that will be practiced through threat modeling and component fault detection model with further modeling component and its application using unified modeling language secure-design approach with a valid technique (verification, validation model for security-by-design testing) for design flaw detection to avoid the business logic problem in component-based e-commerce applications from existing application logic.

Acknowledgments

The authors would like to thank Prof. Jianming Yong for support and cooperation.

Disclosure statement

No potential conflict of interest was reported by the authors.

Availability of data and material

No data have been provided for that project as it is not allowed.

Additional information

Funding

No funding is granted for this particular project.

Log in via your institution

Log in to Taylor & Francis Online

PDF download + Online access

  • 48 hours access to article PDF & online version
  • Article PDF can be downloaded
  • Article PDF can be printed
USD 61.00 Add to cart

Issue Purchase

  • 30 days online access to complete issue
  • Article PDFs can be downloaded
  • Article PDFs can be printed
USD 207.00 Add to cart

* Local tax will be added as applicable

Related Research

People also read lists articles that other readers of this article have read.

Recommended articles lists articles that we recommend and is powered by our AI driven recommendation engine.

Cited by lists all citing articles based on Crossref citations.
Articles with the Crossref icon will open in a new tab.