ECOM 190B Topics
Home Up

 

Security and Risk Management

TEXTS:

Electronic Commerce: Security, Riak Management and Control; Greenstein, Mariyln & Feinman, Todd M.; Irwin McGraw-Hill;2000

Purchase books at the Wave Internet eStore

I.             Risks of Insecure Systems

bullet

A.     Learning Objectives

bullet

B.    What is risk, in the context of electronic commerce?

bullet

C.    Risks to Customers

bullet

D.    Malicious web

bullet

E.     Man in the Middle Attacks

bullet

F.     Privacy

bullet

G.    Cookies

bullet

H.    Party Line Connections

bullet

I.       Risks to Selling Agents - Customer Impersonation

bullet

J.     Denial of Service Attacks

bullet

K.    File Upload Attacks

bullet

L.     Sabotage by Employees

bullet

M.   Sniffers

bullet

N.    Downloading of Data

bullet

O.    E-mail Spoofing

bullet

P.     Social Engineering

bullet

Q.    Intranet vs. Extranets

bullet

R.    Intranet - internal telecommunications links within a company to allow employees to share data.  Typically placed behind a firewall.

bullet

S.     Extranet - limited outside access is made possible to data in the Intranet, typically with identified business partners

bullet

T.     Uses of Extranets

bullet

U.    Important Techniques used to prevent/detect data interception

bullet

V.    Archival Stored Data...

bullet

W.   Hoaxes...

II.          Risk Management

bullet

A.     Learning Objectives

bullet

B.    Risk Management Defined

bullet

C.    Risk Analysis...

bullet

D.    Control Weakness & Risk

bullet

E.     Security Gap

bullet

F.     Paradox: Excessively Tight Controls can result in problems

bullet

G.    What Disaster Recovery Plans should include

bullet

H.    Second-Site Backup Alternatives

bullet

I.       Dress Rehearsals

bullet

J.     Internal Controls

bullet

K.    Five Internal Control Elements

bullet

L.     External Enterprise Level Risks

bullet

M.   Internal Enterprise Level Risks

III.        Internet Standards, Protocols, and Languages

bullet

A.     Learning Objectives

·         To understand the necessity of standards.

·         To understand the impact that the global environment has on standard setting processes.

·         To identify the seven layers in the Open Systems Interconnections Model.

·         To identify common Internet protocols and languages.

bullet

B.    Standards...What is a “standard” and why are they necessary?

bullet

C.    Interoperability

bullet

D.    EDI - 2 competing standards

bullet

E.     ASC X12 Alignment Task Force

bullet

F.     ISO

bullet

G.    NIST

bullet

H.    ISOC

bullet

I.       Request For Comments (RFC)

bullet

J.     Internet Corporation for Assigned Names and Numbers ICANN

bullet

K.    Domain Names

bullet

L.     World Wide Consortium (W3C)

bullet

M.   Open Buying on the Internet (OBI)

bullet

N.    Global Information Infrastructure Commission (GIIF)

bullet

O.    Computer Emergency Response Team Coordination Center (CERT)

bullet

P.     Open Systems Interconnections (OSI) Model

bullet

Q.    IP addresses

bullet

R.    FTP and Telnet

bullet

S.     HTTP and HTTP-NG

bullet

T.     Secure-HTTP (S-HTTP)

bullet

U.    Secure Sockets Layer (SSL)

bullet

V.    DOMs Document Object Model

bullet

W.   Web-based EDI/XML is popular alternative

bullet

X.    eXtensible Markup Language - XML

bullet

Y.     European XML/EDI Pilot Project

bullet

Z.     Java

bullet

AA.      Basic Mail Protocols

bullet

BB.     Internet secure mail

bullet

CC.     SET: Secure Electronic Transmission

IV.       Cryptography and Authentication

bullet

A.     Learning Objectives

bullet

B.    Encryption….

bullet

C.    Industry Solution

bullet

D.    Symmetric Key Challenge

bullet

E.     Key Pairs

bullet

F.     Integrity Check Values.

bullet

G.    Digital Signatures

bullet

H.    Attacks against encryption

bullet

I.       Digital Wrapper or Envelope

bullet

J.     Compressed Files

bullet

K.    Elliptic Curve Cryptography

bullet

L.     Key Management

bullet

M.   Public Key Infrastructure

bullet

N.    Public Certification Authority

bullet

O.    Certification Authority

bullet

P.     Private or Enterprise CAs

bullet

Q.    Private Certification Authority

bullet

R.    Hybrid Certification Authority

bullet

S.     What tasks are involved in Key Management systems?

bullet

T.     Additional Authentication Methods

bullet

U.    Additional Non-Repudiation Techniques

V.          Firewalls

bullet

A.     Learning Objectives

bullet

B.    What is a firewall?

bullet

C.    Characteristics of Good Firewalls

bullet

D.    Transmission Control Protocol/ Internet Protocol - TCP/IP

bullet

E.      4 Basic Layers of TCP/IP

bullet

F.     Open Systems Interconnect (OSI)

bullet

G.    Firewall Filtering

bullet

H.    Static Firewalls

bullet

I.       Dynamic Firewalls

bullet

J.     Components of Firewalls

bullet

K.    Firewall Functions

bullet

L.     Packet-Filtering

bullet

M.   Packet Filtering Routers

bullet

N.    Proxies

bullet

O.    IP Spoofing

bullet

P.     Real-Time Monitoring

bullet

Q.    Demilitarized Zone

bullet

R.    Securing the Firewall - Policy

bullet

S.     Securing the Firewall - Administration

bullet

T.     Securing the Firewall - Services

bullet

U.    Securing the Firewall - Internal Firewalls

bullet

V.    Securing the Firewall - Operating System Controls

bullet

W.   Firewall Design Factors

bullet

X.    Choosing a Firewall Vendor

bullet

Y.     Limitations of Security Provided by Firewalls

VI.       Electronic Commerce Payment Mechanisms

bullet

A.     Chapter 10 Objectives

bullet

B.    Secure Sockets Layer (SSL)

bullet

C.    Secure Electronic Transaction (SET)

bullet

D.    Set Version 1.0 Features

bullet

E.     Set vs. SSL

bullet

F.      

bullet

G.    Four SET Components

bullet

H.    Key Management

bullet

I.       What tasks are involved in Key Management systems?

bullet

J.     Certificate Trust Chain

bullet

K.    Dual Signatures

bullet

L.     SET Compliance Testing

bullet

M.   Version 2.0 and other Update  Planned Enhancements

bullet

N.    Food for Thought...

bullet

O.    Magnetic Strip Cards

bullet

P.     Smart Cards

bullet

Q.    Electronic Checks

bullet

R.    Biller Presentment Systems

bullet

S.     FSTC’s Electronic Check

bullet

T.     FSTC’s BIPS Specification

bullet

U.    Electronic or Digital Cash

 

These Topic Outlines cover the content of one 5 week Module in the ECOM Program.

Email for more information:

mmeyer@hawaii.edu

 

 
 
©Wave Internet LLC 2001-2003