Payment Gateway


Published on

an introduction to how payment gateway works, with some security issues.

Published in: Technology
No Downloads
Total views
On SlideShare
From Embeds
Number of Embeds
Embeds 0
No embeds

No notes for slide
  • First I want to thank you all for taking the time to be here. We have
  • Payment Gateway

    1. 1. Payment Gateway
    2. 2. Agenda <ul><li>Terminology </li></ul><ul><li>Payment Gateway life cycle </li></ul><ul><li>Types of Payment Gateways </li></ul><ul><li>Advantages and Disadvantages </li></ul><ul><li>Security Issues </li></ul><ul><ul><li>Vulnerabilities </li></ul></ul><ul><ul><li>Related Vulnerabilities </li></ul></ul><ul><ul><li>“ Must Do” list </li></ul></ul><ul><li>Payment Gateway Implementation over SSL </li></ul><ul><li>What to ask in third payment gateways parties ? </li></ul><ul><li>Example …. </li></ul><ul><li>Most famous payment gateways </li></ul><ul><li>Questions </li></ul>
    3. 3. Some Terminologies : <ul><li>Individuals </li></ul><ul><ul><li>Merchant – seller of goods </li></ul></ul><ul><ul><li>Customer – buyer of goods </li></ul></ul><ul><li>Institutions </li></ul><ul><ul><li>Customer’s Issuing Bank – provides customer’s credit card information and verification </li></ul></ul><ul><ul><li>Merchant’s Acquiring Bank – provides internet merchant account </li></ul></ul><ul><ul><li>Processor – authorizes credit card transactions and settles funds for merchants </li></ul></ul>
    4. 4. Basic Elements Interactions : <ul><li>Processes </li></ul><ul><ul><li>Authorization – the process of verifying a customer’s credit card </li></ul></ul><ul><ul><li>Settlement – the process of collecting funds from the customer’s account </li></ul></ul><ul><li>Services </li></ul><ul><ul><li>Payment Processing Service – connects merchants, customers, and banks through secure online transactions. </li></ul></ul><ul><ul><li>Gateway – the secure pipe between the banks and the processor </li></ul></ul>
    5. 5. Authorization Process <ul><li>Customer decides to make an online purchase and inputs credit card information </li></ul><ul><li>Merchant ’s website receives customer information and sends it to a payment processing service </li></ul><ul><li>Payment processing service routes information to processor </li></ul><ul><li>Processor routes information to bank that issued customer’s credit card (issuing bank) </li></ul><ul><li>Issuing bank sends authorization (or declination) to processor </li></ul><ul><li>Processor routes transaction results to payment processing service </li></ul><ul><li>Payment processing service sends results to merchant </li></ul>2 Payment Processing Service 7 6 5 Customer Merchant 1 Processor 3 Customer’s issuing bank 4 <ul><li>Merchant decides to accept or reject purchase </li></ul>8
    6. 6. Settlement Process <ul><li>Merchant informs the payment processing service to settle transactions </li></ul><ul><li>Payment processing service sends transaction information to the processor </li></ul><ul><li>Processor checks the information and forwards settled transaction information to the issuing bank </li></ul><ul><li>Issuing bank transfers funds to the processor </li></ul><ul><li>Processor routes funds to the acquiring bank </li></ul><ul><li>Acquiring bank credits merchant’s bank account </li></ul><ul><li>Issuing bank includes merchant’s charge on customer’s credit card account </li></ul>7 2 Payment Processing Service Processor 6 4 Merchant’s acquiring bank 5 Merchant Customer 1 Customer’s issuing bank 3
    7. 7. PayPal (As an example) All-in-One Solution Customer’s issuing bank Merchant’s acquiring bank Customer Merchant Processor Payment Processing Service
    8. 8. Payment Gateways Types <ul><li>COM based Gateways </li></ul><ul><ul><li>requires that you install software called a DLL provided by the gateway company on your web hosting server. </li></ul></ul><ul><ul><li>requires that you have your own dedicated SSL certificate </li></ul></ul><ul><li>XML transport Gateways </li></ul><ul><ul><li>do NOT require a DLL install. They use a facility already installed on most Windows servers. </li></ul></ul><ul><ul><li>requires SSL certificate. </li></ul></ul><ul><li>FORM based Gateways </li></ul><ul><ul><li>do not require any extra software to be installed on your web hosting server. </li></ul></ul><ul><ul><li>some, but not all, require that you have your own SSL certificate. </li></ul></ul>
    9. 9. Advantages and Disadvantages (for user) <ul><li>Fixed fee per month </li></ul><ul><li>Percentage fee per amount spent </li></ul><ul><li>Fixed fee per transaction </li></ul><ul><li>User bank or the gateway's bank will charge a merchant fee for the privilege of allowing credit card purchases. This can range from 1-5% or more </li></ul><ul><li>Credit card validation and processing in real time </li></ul><ul><li>Money is normally deposited into bank account automatically (Transparency) </li></ul><ul><li>Reports are auto generated for users. </li></ul><ul><li>Doesn’t need special user deployment (a browser is adequate) </li></ul>Advantages Disadvantages
    10. 10. Some security Issues <ul><li>An estimated $2.8B USD was lost to online fraud in the U.S. and Canada in 2005 </li></ul><ul><li>The rate of credit card fraud for online sales is three to four times higher than the overall fraud rate </li></ul><ul><li>Authentication is a challenge </li></ul><ul><li>Hackers can break into a merchant’s network </li></ul><ul><li>Hackers can also steal customer identities </li></ul><ul><li>Recorded session attack </li></ul>Vulnerabilities … … leading to losses
    11. 11. Common Fraud-Related Risks Using stolen information to open new credit cards Issuing unauthorized credits or payments Identity theft Cash theft Accessing a payment network to complete fraud Accessing payment networks Using a stolen credit card to purchase goods and services Product theft Chargebacks A cardholder disputes a credit card purchase
    12. 12. How to Protect Your Business Against Fraud Transaction Level Ensure each transaction you accept and process is valid, and be careful in reviewing suspicious transactions because some may be valid. Account Level Make sure only authorized users have access to your payment gateway account, and be alert for suspicious account access patterns. Network Level Ensure your perimeter is defended against unauthorized access. 1 2 3
    13. 13. Your Disclosure Policy Tells Customers that You Are Honest and Dependable <ul><li>Business Description – Explains what the company does </li></ul><ul><li>Shipping Policy – Details shipping terms, shipping classes offered, & expected delivery timeframe </li></ul><ul><li>Privacy Policy – Describes how the company treats and protects customers’ information </li></ul><ul><li>Return Policy – Provides clear guidelines on how a return is handled </li></ul><ul><li>Contact Information – Makes it easy for customers to get in touch with the merchant via different communication channels </li></ul>
    14. 14. Security basics “must do” list Protect Cardholder Data Maintain a Vulnerability Management Program Implement Strong Access Control Measures Regularly Monitor and Test Networks Maintain an Information Security Policy <ul><ul><li>Protect stored cardholder data </li></ul></ul><ul><ul><li>Encrypt transmission of cardholder data across open, public networks </li></ul></ul><ul><li>Use and regularly update anti-virus software </li></ul><ul><li>Develop and maintain secure systems and applications </li></ul><ul><ul><li>Restrict access to cardholder data by business need-to-know </li></ul></ul><ul><ul><li>Assign a unique ID to each person with computer access </li></ul></ul><ul><ul><li>Restrict physical access to cardholder data </li></ul></ul><ul><li>Track and monitor all access to network resources and cardholder data </li></ul><ul><li>Regularly test security systems and processes </li></ul><ul><li>Maintain a policy that addresses information security </li></ul>Control Objective Requirement Build and Maintain a Secure Network <ul><ul><li>Install and maintain a firewall configuration to protect cardholder data </li></ul></ul><ul><ul><li>Do not use vendor-supplied defaults for system passwords and other security parameters </li></ul></ul>
    15. 15. Payment Gateway Implementation over SSL Refer to the attached PDF “ Payment Gateway Implementation.pdf”
    16. 16. What to ask in third payment gateways parties ? <ul><li>How long has this company been in service ? </li></ul><ul><li>What is the company history ? </li></ul><ul><li>How long has their particular software package been in use ? </li></ul><ul><li>Can you test a demo software ? </li></ul><ul><li>How much will the setup and service bundle cost ? </li></ul><ul><li>How much are processing costs and fees ? </li></ul><ul><li>Does the system needs special installation equipments ? </li></ul><ul><li>Does the system provides extra services ? </li></ul><ul><li>What is the level of support provided by this third party ? </li></ul><ul><li>Who are the customers that already exist and uses this system ? </li></ul><ul><li>What are provided system authentication and authorization ? </li></ul>
    17. 17. An example of applying to a payment gateway (WorldPay) Refer to the attached PPS “ worldpay application.pps”
    18. 18. Most famous Payment Gateways    
    19. 19. Questions Confidential and Proprietary