This research presents a set of patterns appropriate for securing information in an online transaction processing system. The research also shows how security constraints can be added to the domain model by using mandatory access control (MAC). The system developed created three different access levels which include e-platform administrator, the payment gateway administrator and the customers. Each of the users on the platform has limited access areas and this was achieved by applying mandatory access control technique. Security constraints were added to each of the component patterns to produce a domain model for secure e-commerce. The research utilized a security feature called Role-Based Access Control (RBAC). In the RBAC pattern, users are assigned to the roles according to their tasks or jobs and rights are assigned to the roles. In this way, a need-to-know policy can be applied, where roles get only the rights they need to perform their tasks. The software developed utilized the mandatory access control (MAC) as a security mechanism for the online transaction processing which involves product ordering, payment using credit card, and product information management. The system is very robust and MySQL database was used at the back-end.
Administrator, Cybersecurity, Subsystem, Domain Model
International Journal of Trend in Scientific Research and Development - IJTSRD having
online ISSN 2456-6470. IJTSRD is a leading Open Access, Peer-Reviewed International
Journal which provides rapid publication of your research articles and aims to promote
the theory and practice along with knowledge sharing between researchers, developers,
engineers, students, and practitioners working in and around the world in many areas
like Sciences, Technology, Innovation, Engineering, Agriculture, Management and
many more and it is recommended by all Universities, review articles and short communications
in all subjects. IJTSRD running an International Journal who are proving quality
publication of peer reviewed and refereed international journals from diverse fields
that emphasizes new research, development and their applications. IJTSRD provides
an online access to exchange your research work, technical notes & surveying results
among professionals throughout the world in e-journals. IJTSRD is a fastest growing
and dynamic professional organization. The aim of this organization is to provide
access not only to world class research resources, but through its professionals
aim to bring in a significant transformation in the real of open access journals
and online publishing.