首页    期刊浏览 2024年10月05日 星期六
登录注册

文章基本信息

  • 标题:Process of Security Assurance Technique for Application Functional Logic in E-Commerce Systems
  • 本地全文:下载
  • 作者:Faisal Nabi ; Jianming Yong ; Xiaohui Tao
  • 期刊名称:Journal of Information Security
  • 印刷版ISSN:2153-1234
  • 电子版ISSN:2153-1242
  • 出版年度:2021
  • 卷号:12
  • 期号:3
  • 页码:189-211
  • DOI:10.4236/jis.2021.123010
  • 语种:English
  • 出版社:Scientific Research Publishing
  • 摘要:Security practices such as Audits that often focus on penetration testing are performed to find flaws in some types of vulnerability & use tools, which have been tailored to resolve certain risks based on code errors, code conceptual assumptions bugs, etc. Most existing security practices in e-Commerce are dealt with as an auditing activity. They may have policies of security, which are enforced by auditors who enable a particular set of items to be reviewed, but also fail to find vulnerabilities, which have been established in compliance with application logic. In this paper, we will investigate the problem of business logic vulnerability in the component-based rapid development of e-commerce applications while reusing design specification of component. We propose secure application functional processing Logic Security technique for component-based e-commerce application, based on security requirement of e-business process and security assurance logical component behaviour specification approach to formulize and design a solution for business logic vulnerability phenomena.
  • 关键词:Business Logic Design Flaws;Components Integration Flaws;E-Commerce System;Assurance ;Security;Model Based Design;Business Logic Attacks;Attack Pattern
国家哲学社会科学文献中心版权所有