ترجمه مقاله نقش ضروری ارتباطات 6G با چشم انداز صنعت 4.0
- مبلغ: ۸۶,۰۰۰ تومان
ترجمه مقاله پایداری توسعه شهری، تعدیل ساختار صنعتی و کارایی کاربری زمین
- مبلغ: ۹۱,۰۰۰ تومان
The rapid development of e-commerce worldwide, means more e-commerce business processes adopting the structure of multiple participants; these include shopper clients, merchant and third-party payment platforms (TPPs), banks, and so on. It is a distributed and complex system, where communications among these participants rely on the web services and Application Programming Interfaces (APIs) such as Cashier-as-a-Service or CaaS. This introduces new security challenges due to complex interactions among multiple participants, and any design flaws in procedure structures may result in serious security issues. We study the structural security issues based on Petri nets, and a framework for analyzing structural security in e-commerce business process is proposed. Petri net-based modeling and analysis methods are also provided. Given the specifications of e-commerce business processes, the proposed methods can help designers analyze structural security issues of an e-commerce business process.
1. Introduction
E-commerce has significantly developed in recent years, and more and more business is conducted over the Internet. The daily volume of e-commerce is sizable and continues to grow at a rapid pace. Many e-commerce platforms spring up to accelerate this new industry [1,2]. E-commerce systems with multiple participants, including third-party payment platforms (TPPs), e-commerce systems, banks, clients, and other applications, have become the new frontier for conducting business. As a distributed application on the web, e-commerce business processes are more complex and loosely coupled. The participants communicate with each other through web services and APIs such as Cashier-as-a-Service or CaaS [3,4]. The business processes of different participants construct the entire process structure. This integration introduces new security challenges due to complex interactions among the APIs of multiple interactive participants. These differ from traditional security issues, and the new security challenges do not refer to virus, Trojans or security protocols [5,6]. The complex structural linkage of control and data flows in e-commerce systems may produce very serious problems including the violation of the transaction properties, and losses of user funds. These issues can be defined as structural security. There are many structural security cases that have appeared over recent years. These include the vulnerability caused by a combination of open source online shopping system and TPP [3], ‘‘one yuan gate’’ event of Taobao in 2011 [7], and mongodb-based web applications [8].
7. Conclusions
The rapid development of e-commerce has led to arise structural security issues in business processes. Based on EBPN, this paper discusses the concept of structural security and proposed a modeling method that fuses control and data structures. We propose two analyzing methods to determine the structural security of e-commerce business processes. However, plenty of analyzing methods in this area is still largely open. Even with the deployment of the proposed methods, there is still ample opportunity to conduct further research using additional analytical methods in structural security. In the future, we will focus on more efficient analytical methods and deploy more technologies based on the original Petri nets.