Fraud in E-Commerce Assignment
LaKaden Brown
Liberty University
ACCT:406
Prof. Sturgess
March 1, 2024
Introduction:
The textbook shows a definition of E-Commerce fraud. “Essentially, e-business Footnote
uses information technology (IT) and electronic communication networks to exchange business
information and conduct paperless transactions. Although most consumers primarily use Web
browsers to access the Internet, businesses routinely connect to one another over the Internet
through e-business calls, virtual private networks (VPNs), and other specialized lines.”
(Albrecht, Albrecht, Albrecht, & Zimbelman,2019, Chapter 17 introduction). This shows E-
commerce and what it is about. It uses information technology to exchange info. So E-commerce
based on this definition is an internet type of fraud. Three cases will be shown of this type of
fraud. Scott Adam's case study is the first. Then VPN short case will be after. Then Lastly eBay's
short case will be presented. First, I will give a brief explanation of the case. Then I will show
two methods for each case and explain the steps. After I explain I will report the results right
after I do the steps. To wrap up the results I will show the tables of information that was given to
me.
Scott Adams:
Scott Adams started a home-based business two years ago and saw rapid success selling
bespoke tables and chairs. He decided to start selling things online to profit from the holidays.
He is worried about fraud involving fraudulent internet transactions, though. The Article, “The
Psychology of Internet Fraud Victimization: a Systematic Review”, shows internet fraud victims.
“There are a number of reviews in the wider online/consumer fraud area, although the focus for
many is age as a risk factor. Jackson’s (2017) evaluation is predominantly aimed at
methodological and prevalence issues and suggests a lack of knowledge of risk factors in the
financial exploitation of older people increases propensity for fraud.” Norris, G., Brookes, A., &
Dowell, D. (2019). This would show who would be responsible for fraud to happen. It shows that
older people have an increased propensity for fraud. This means older people are more likely to
let fraud happen because they are not used to the internet. The first prevention method is the
Address Verification System (AVS). The 1st step is to enable AVS on the payment gateway. To
ensure that the billing address supplied by clients corresponds with the address on file with the
credit card issuer, Scott has to activate AVS on his payment gateway. The 2nd step is to set the
AVS threshold. Set AVS mismatch thresholds, such as rejecting transactions if there is a
substantial discrepancy between the billing address and the address on file. The 3rd step is to
educate customers. Advise customers that to prevent transaction denials, their billing address and
the address on file with their credit card issuer must match. The 4th step is to monitor AVS
results. Examine AVS findings often to see any trends or patterns in mismatches that could point
to fraud. The 5th step is to implement manual review. To confirm the legality of transactions with
AVS mismatches higher than the specified levels, a human review procedure should be
implemented. Now the results of doing these steps. Scott successfully enabled AVS on his
payment gateway, which allowed him to verify the billing address provided by customers. When
there was a substantial discrepancy between the billing address and the address on file, Scott
oversaw transactions and established thresholds for AVS mismatches. To prevent transaction
denials, Scott informed clients of the significance of having their billing address match the
address on file with their credit card issuer. Scott looked at AVS findings on a frequent basis,
looking for trends or patterns in mismatches that would point to fraud. In order to confirm the
validity of transactions containing AVS mismatches higher than the predetermined levels, Scott
instituted a manual review procedure method's efficacy will need ongoing monitoring and AVS
threshold adjustments. Overall, Scott's implementation of the AVS method was successful in
reducing the risk of fraud in his online retail venture. Now for the second method. The second
method is the Card Verification Value (CVV). The 1st step of this method is to require cvv at
checkout. Scott should require customers to enter the CVV code from the back of their credit
card during checkout to verify that the customer has the physical card in their possession. The
2nd step is to set cvv thresholds. Set up conditions for CVV mismatches, such as rejecting
transactions that have the wrong CVV code. The 3rd step is to educate customers. Remind
customers that their card information must be protected and that they need to submit the right
CVV number to finish their purchase. The 4th step is to monitor cvv results. Examine CVV data
regularly to spot any trends or patterns in mismatches that could point to fraud. The last step is to
implement manual review. Conduct a manual review procedure to confirm the authenticity of
transactions containing CVV discrepancies beyond the specified levels. By implementing these
steps, Scott can enhance the security of his online retail venture and reduce the risk of fraud. The
results of using these steps. Scott successfully required customers to enter the CVV code from
the back of their credit card during checkout, verifying that the customer had the physical card in
their possession. For CVV mismatches, Scott established criteria and rejected transactions with
an erroneous CVV code. Scott stressed to his customers the value of safeguarding their card
information and the significance of inputting the right CVV number to complete their purchase.
Scott looked at CVV findings regularly, looking for trends or patterns in mismatches that would
point to fraud. To confirm the legality of transactions with CVV mismatches greater than the
predetermined levels, Scott instituted a manual review procedure. Overall, Scott's
implementation of the CVV method was successful in reducing the risk of fraud in his online
retail venture. This is the investigation results for this case. There is no table or extra information
for this case so now it’s time for the next one.
VPN
In Case 4, a business is having problems with network security and is thinking about
using a virtual private network (VPN) to strengthen security. The firm employs people who work
remotely and has offices in several places. They are worried about the security and privacy of
data, particularly when staff members use business resources from a location outside than the
office network. The Article, “Common Vulnerabilities Exposed in VPN – A Survey”, it shows
what a VPN is and what it is used for. “A virtual private network (VPN) has been used variously.
Security experts use VPN for sharing the Intranet services on a public network with
authentication and Authorization. However, Cyber Criminals use it for Anonymity and spoofed
identity. Now it’s the right time to revamp the Infrastructure Security Policies and prepare all the
security checks on every stage of the data filtration, data Preservation, Authentication, and
Authorization with the Notifications and preventions using Intrusion detection and prevention
systems. However, the VPN is playing a vital role in the updated security systems.” Bansode, R.,
& Girdhar, A. (2021). This shows what a VPN is and how important it is in the updated security
systems. It is used for good and bad. It can protect you from harm but if you're committing the
crime, it keeps you hidden from any trouble. The 1st method for this case is behavioral analytics.
The 1st step of this method is data collection. Gather information on user activity, including
locations, times of login, and access patterns. The 2nd step is profile creation. Based on their
usual activities, create user profiles that include their locations, login times, and access habits.
The 3rd step is anomaly detection. To identify variations from the pre-established user profiles,
such as odd login times or places, apply machine learning algorithms. The 4th step is alert
generation. Generate alerts for detected anomalies, which can be further investigated by security
analysts. The last step is the feedback loop. To increase detection accuracy and lower false
positives, update the user profiles and anomaly detection algorithms on a regular basis based on
fresh data and security analyst input. This shows the steps of this method. Now here are the
investigation results. Information was gathered from many sources, encompassing user locations,
login times, and access behaviors. User profiles based on normal behavior were created using
historical data. User profiles were created based on their typical behavior, including login times,
locations, and access patterns. Profiles were updated regularly to account for changes in user
behavior. The constructed user profiles were scrutinized for any abnormalities using machine
learning methods. Unusual login times or locations were among the anomalies that were marked
for additional examination. Alerts were generated for detected anomalies, which were reviewed
by security analysts. Alerts included details such as the user, the type of anomaly, and the
severity. The system was modified regularly in response to security experts' input and fresh data.
To decrease false positives and increase detection accuracy, user profiles and anomaly detection
algorithms were improved. This is the investigation results for this method. Now for the second
method. The second method is the Intrusion Detection System (IDS). The 1st step of this method
is data collection. Gather network traffic data, including packet headers and payloads, from
various sources such as firewalls, routers, and intrusion detection sensors. The 2nd step is
signature creation. Based on past data and known vulnerabilities, create signatures for known
attack patterns. The 3rd step is anomaly detection. To identify variations in the standard network
traffic patterns, such as odd packet sizes or frequencies, apply machine learning methods. The 4th
step is alert generation. Create notifications for abnormalities that are found so that security
experts may investigate them more. The last step is the feedback loop. To increase detection
accuracy and lower false positives, regularly update the signatures and anomaly detection
algorithms based on fresh information and input from security analysts. In the context of network
security, these stages offer a broad framework for putting behavioral analytics and intrusion
detection systems into practice for fraud detection. Depending on the security needs, the type of
company, and the data that is accessible, the implementation specifics may change. Now the
investigation results for this method. Network traffic data, including packet headers and
payloads, was collected from various sources such as firewalls, routers, and intrusion detection
sensors. Based on known vulnerabilities and historical data, signatures for well-known attack
patterns were produced. Network traffic patterns were monitored for deviations using machine
learning methods. Unusual packet sizes or frequencies were among the anomalies that were
marked for additional examination. Security experts examined the alerts that were issued for
abnormalities that were found. Information about the kind of abnormality, the system it affected,
and its severity were all included in the alerts. The system was modified regularly in response to
security experts' input and fresh data. To decrease false positives and increase detection
accuracy, algorithms for anomaly detection and signatures were improved. That is the
investigation results from the steps. There is no extra information or tables provided so now it's
time for the last case.
eBay
The "bait and switch" fraud is one that frequently occurs on eBay. This scam involves a
seller listing an item at a tempting price, but upon a buyer's purchase, the seller substitutes an
item—often inferior—for the original one. The most popular products for this scam to target are
luxury goods, collectibles, and technology. Potential customers should carefully review the item
description, photographs, and seller's feedback and ratings to avoid or identify this fraud.
Additionally, purchasers should always utilize eBay's approved payment methods, such as
PayPal, which guarantees buyer protection, and be cautious of bargains that appear too good to
be true. The Article, “Mineshafts on Treasure Island: A Relief Map of the eBay Fraud
Landscape”, shows more about eBay fraud. “As explorers once opened up new trade passages,
thus attracting hordes of both honest traders and dishonest pirates, so too has the Internet opened
new lanes of commerce and attracted the modem versions of the same. One of the widest of these
lanes undoubtedly runs through eBay, located at http://www.ebay.com. From its humble
beginnings as a little-known auction site hawking PEZ candy dispensers, broken laser pointers
and other garage-sale pickings, eBay has transformed itself into a reputable public sales
powerhouse where a Gulfstream II jet, million-dollar sports artifacts, and Madonna's wedding
tiara might easily change hands.” Calkins, M. M., Nikitkov, A., & Richardson, V. (2008). This
shows eBay fraud and gives a background about eBay by relaying some valuable information.
Two methods can be used to detect fraud in this case. The first method is image reverse search.
Use reverse image search tools such as Google Images or Tin Eye to verify the authenticity of
the product photos. The 1st step is to download the product photos from the eBay listing. The 2nd
step is to go to Google Images or Tin Eye and upload the photos. Then Review the search results
to see if the same photos appear on other websites or listings. If the photos are widely used or
appear on multiple listings, it could be a sign of a scam. Then the last step. If the photos are
unique to the eBay listing, it may indicate that the seller is using genuine product images. So the
results of using these steps. The product photos from the eBay listing have been downloaded. he
photos have been uploaded to both Google Images and Tin Eye for reverse image search. The
search results show that the product photos do not appear on any other websites or listings. This
suggests that the seller is using unique and genuine product images. There are no indications that
the photos are widely used or appear on multiple listings, which is a positive sign. Based on the
image reverse search results, it can be concluded that the product photos used in the eBay listing
are likely authentic and not copied from other sources. This would show the results of the first
method. Now the second method. The Second method is seller verification. Verify the seller's
identity and legitimacy by checking their eBay profile and conducting additional research. The
1st step is to visit the seller's eBay profile and review their feedback and ratings. The 2nd step is to
check the seller's history of transactions and see if they have a track record of selling similar
items. The 3rd step is to conduct a web search using the seller's username or email address to see
if they have a presence on other online platforms or forums. The 4th step is, if possible, contact
the seller directly and ask for additional information or clarification about the item. The last step
follows. If you have any doubts about the seller's legitimacy, report it to eBay immediately. Now
for the results of using these steps. The seller's eBay profile has been visited and reviewed. The
seller has a high positive feedback rating, with the majority of buyers leaving positive reviews.
The seller has a history of selling similar items, which suggests that they are experienced in the
type of product being sold. A web search using the seller's username and email address did not
yield any concerning results. The seller was contacted directly to ask for additional information
about the item. The seller responded promptly and provided detailed information, which further
reassured the buyer. This is the investigation results and this concludes this case.
BIBLICAL WORLDBIEW/CONCLUSION
In e-commerce, a biblical worldview condemns fraud as dishonest and unfair. The
command to "love your neighbor as yourself" (Mark 12:31, NIV) emphasizes treating others
with respect and honesty. Fraud goes against this principle and misuses resources entrusted by
God. Biblical values call for accountability, repentance, and restitution to promote justice and
integrity in e-commerce.
REFRENCES:
Albrecht W., Albrecht C., Albrecht C., & Zimbelman M., (2019). Fraud Examination Cengage
Learning, Inc.
Bansode, R., & Girdhar, A. (2021). Common Vulnerabilities Exposed in VPN – A Survey.
Journal of Physics: Conference Series, 1714(1)https://doi.org/10.1088/1742-6596/1714/1/012045
Calkins, M. M., Nikitkov, A., & Richardson, V. (2008). Mineshafts on Treasure
Island: A Relief Map of the eBay Fraud Landscape.(Pittsburgh Journal of
Technology Law & Policy : TL & P.,(8. https://doi.org/10.5195/TLP.2008.42
Mark 12:31. New International Version. Bible Gateway. Mark 12:31 NIV - The second is this: ‘Love
your - Bible Gateway
Norris, G., Brookes, A., & Dowell, D. (2019). The Psychology of Internet Fraud Victimisation: a
Systematic Review. Journal of Police and Criminal Psychology, 34(3), 231-245.
https://doi.org/10.1007/s11896-019-09334-5