See buying choices for this item to see if it's one of the millions that are eligible for Amazon Prime.

52 used & new from $0.02

Have one to sell? Sell yours here
 
 
E-Commerce Security: Weak Links, Best Defenses
 
 
Tell the Publisher!
I’d like to read this book on Kindle

Don’t have a Kindle? Get yours here.
 
  

E-Commerce Security: Weak Links, Best Defenses (Paperback)

by Anup K. Ghosh (Author) "Electronic commerce, or e-commerce, is changing the way in which consumers, merchants, and businesses interact and transact..." (more)
Key Phrases: Internet Explorer, Netscape Navigator, Visa Cash (more...)
4.2 out of 5 stars See all reviews (4 customer reviews)


Available from these sellers.


14 new from $0.74 38 used from $0.02
Also Available in: List Price: Our Price: Other Offers:
Unknown Binding Order it used!

Customers Who Bought This Item Also Bought

Fraud Prevention Techniques for Credit Card Fraud

Fraud Prevention Techniques for Credit Card Fraud

by David A. Montague
2.5 out of 5 stars (2)  $23.95
Explore similar items

Editorial Reviews

Amazon.com Review
Online security investigator and research scientist Anup Ghosh takes a realistic look at the state of security for electronic commerce. He is neither a Pollyanna believing that all is fine, nor a doomsayer predicting catastrophe for transactions lacking virtual plate armor. In fact, he feels that some levels of security are excessive. But he emphasizes that any security system is only as strong as its weakest point. If you're going to trust your money to online transactions, you need to know where your weaknesses lie and how to correct them.

To that end, Ghosh discusses real-life security failures, how they occurred, and how recurrences can be prevented. He then takes a systematic look at the areas of risk. One chapter deals with potential problems in active Web content, such as Java applets, ActiveX controls, and push technology. He examines data protocols to secure transactions with the warning that the data can be vulnerable before and after the secure transmission. The weaknesses of server hardware and software come under scrutiny as well. Ghosh calls for greater attention to security as software is being developed and looks at what advances are likely to be coming down the road. --Elizabeth Lewis

Product Description
"This is a very important book . . . mandatory reading for anyone thinking about getting into e-commerce."-Peter G. Neumann Moderator of the Risks Forum and author of Computer Related Risks

The World Wide Web is changing the way the world engages in business. With this paradigm shift comes uncertainty about how secure e-commerce transactions are over an inherently insecure medium-the Internet. Businesses have learned the hard way that there is no "silver bullet" solution-not encryption, not firewalls, not even secure protocols. Like a chain, the security of e-commerce is only as strong as its weakest link.

Written by security expert Anup K. Ghosh, E-Commerce Security highlights the weak links and provides best defenses for individuals and enterprises connected to the Internet. This valuable guide addresses vulnerabilities in four essential components of electronic commerce-the data transport protocol, Web server, Web clients, and the network server operating system.

E-Commerce Security:
* Exposes the dangers of new Internet innovations in today's Web browsers, including push technology and desktop integration with the Internet
* Methodically explains the dangers of active content programs downloaded from Web sites, such as Java applets, ActiveX controls, and JavaScript
* Provides a comparison of different secure protocols for e-commerce, including digital cash protocols used in smart cards
* Presents security considerations for Web servers, online databases, and server-side application software
* Details shortcomings in firewall technology and other host security measures.

See all Editorial Reviews


Product Details

  • Paperback: 304 pages
  • Publisher: Wiley; 1 edition (January 21, 1998)
  • Language: English
  • ISBN-10: 0471192236
  • ISBN-13: 978-0471192237
  • Product Dimensions: 9.2 x 7.5 x 0.7 inches
  • Shipping Weight: 1.1 pounds
  • Average Customer Review: 4.2 out of 5 stars See all reviews (4 customer reviews)
  • Amazon.com Sales Rank: #1,482,570 in Books (See Bestsellers in Books)

Inside This Book (learn more)


Tag this product

 (What's this?)
Think of a tag as a keyword or label you consider is strongly related to this product.
Tags will help all customers organize and find favorite items.
Your tags: Add your first tag
 
Help others find this product — tag it for Amazon search
No one has tagged this product for Amazon search yet. Why not be the first to suggest a search for which it should appear?

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

 

Customer Reviews

4 Reviews
5 star:
 (1)
4 star:
 (3)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.2 out of 5 stars (4 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
29 of 30 people found the following review helpful:
4.0 out of 5 stars Good coverage of Web-related e-commerce security issues, November 27, 1998
By A Customer
The title is ever so slightly misleading in that the topic is not electronic commerce as a whole, but the (admittedly most popular) Web segment of it. However, within this limit, the book does provide solid coverage and good advice for a whole range of issues.

Chapter one is a general introduction to the factors involved, looking at some recent "attacks" of various types, and then reviewing the client, transport, server, and operating system components to be examined in the remainder of the book. Client (generally browser) flaws are covered thoroughly in chapter two. The breadth of coverage even includes mention of topics such as the concern for privacy considerations with cookies. Active content is the major concern, with an excellent discussion of ActiveX (entitled "ActiveX [In]security"), a reasonably detailed review of the Java security model, and a look at JavaScript. Unfortunately, very little of this touches directly on e-commerce as such, except insofar as insecure client technology is going to make e-commerce a harder sell to the general public. While covering the transport of transaction information, in chapter three, Ghosh makes an interesting distinction between stored account systems (where you want to secure the transmission of identification data) and stored value systems (where the data, once transmitted, is useless to an eavesdropper). Many books concentrate on either channel security or electronic cash systems, so this comparison is instructive.

A server involves multiple programs, and may involve multiple machines. Server security can quickly become complex, and this is quite evident in chapter four. While a great deal of useful and thought-provoking information is presented, the complicated nature of the undertaking works against this chapter. Not all topics are dealt with thoroughly, or as well as the previous material was. Oddly, one issue not covered in depth is the firewall, which is handled very well in chapter five, with operating system problems. Ghosh sets up a classification scheme for OS attacks, illustrated by specific weaknesses in Windows NT and UNIX.

The book ends in chapter six with a call for certification of software, greater attention to security in all forms of software, and, interestingly, for greater use of component software. (From the jacket material, it appears that Ghosh is currently involved in the promotion of component software systems.)

Each chapter ends with a set of references. Unlike all too many books with bibliographies stuff with obscure citations from esoteric journals, the bulk of the material listed is available on the Internet. A separate section lists Web sites used in the text.

The various issues dealt with in the book are explained clearly, and generally present counsel on the best practices for secure online commerce. A compact but comprehensive guide to the current state of electronic transaction security.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
22 of 24 people found the following review helpful:
5.0 out of 5 stars great overview of the security issues for internet commerce, March 15, 1999
By A Customer
This book is an excellent overview of the fundamental problems that need to be solved in order to build a secure internet-commerce system. It covers client-, server-, protocol-, and OS- related security holes and pitfalls. The author did a very good job of both painting the broad picture as well as giving concrete, real-world examples. I'm new to the e-commerce domain and this book did an excellent job of introducing me to the manifold pitfalls awaiting the unaware. I also very much liked how the author recommended concrete but general steps to take in order to avoid or minimize each category of vulnerability which he identified. A fascinating book on a fascinating topic.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
1 of 1 people found the following review helpful:
4.0 out of 5 stars well organized and well written, March 27, 2001
By Derek R. Mahlitz (Troy, NY United States) - See all my reviews
(REAL NAME)   
This is an outstanding book--well organized and well written, it serves as an introduction as well as review.

Highly recommended for beginners because it is very easy to understand and a brilliant introduction to e-commerce security issues. Also highly recommended for experienced users, as it provides a good overview in a concise manner.

Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

4.0 out of 5 stars An overall
A very good starting book to understand the security aspects of e-commence. Correct views(e.g. The auther emphasized the importantance of the security of two communication ends)... Read more
Published on December 21, 1998

Only search this product's reviews



Customer Discussions

 Beta (What's this?)
New! See all customer communities, and bookmark your communities to keep track of them.
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]

   


Product Information from the Amapedia Community

Beta (What's this?)


So You'd Like to...

Create a guide

Look for Similar Items by Category


Let Toro Clear the Snow

Let Toro Clear the Snow
Rely on Toro for top-quality snow throwers and power shovels to make snow removal a breeze.

Shop all Toro

 

Best Books of 2008

Best of 2008
Find our top 100 editors' picks as well as customers' favorites in dozens of categories in our Best Books of 2008 Store.
 

Summer Reading for Kids & Teens

Summer Reading for Kids and Teens
Discover everything from beach reads and board books to teen romance and action-adventure series in Summer Reading for Kids & Teens. And, check off the kids' required reading lists in our Summer School Reading Store.
 

Have the Best Lawn on the Block

Shop for lawn mowers
Shop a selection of electric, gas, and reel lawn mowers in the Home Improvement Store.

Shop for lawn mowers now

 

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.



Where's My Stuff?

Shipping & Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue shopping: Top Sellers

Conditions of Use | Privacy Notice © 1996-2009, Amazon.com, Inc. or its affiliates