The previous chapter discussed threat inspection and intelligence. In this chapter, we will look into business fraud and service abuses. Cloud services introduce new types of security risks, such as transaction fraud, account abuses, and promotion code abuses. This online fraud and abuse may result in financial losses or gains, depending on which side of the fence you sit.
Therefore, the objective of this chapter is to provide guidelines and rules on how to detect these kinds of behaviors. We will also discuss typical technical frameworks and technical approaches needed to build a service abuse prevention or online fraud detection system.
In this chapter, we will cover the following topics:
- Business fraud and abuse scenarios
- Business risk detection framework
- PCI DSS compliance