Security Certification in Payment Card Industry: Testbeds, Measurements, and Recommendations
Sazzadur Rahaman, Gang Wang, Danfeng Daphne Yao
Abstract
The massive payment card industry (PCI) involves various entities such as merchants, issuer banks, acquirer banks, and card brands. Ensuring security for all entities that process payment card information is a challenging task. The PCI Security Standards Council requires all entities to be compliant with the PCI Data Security Standard (DSS), which specifies a series of security requirements. However, little is known regarding how well PCI DSS is enforced in practice. In this paper, we take a measurement approach to systematically evaluate the PCI DSS certification process for e-commerce websites. We develop an e-commerce web application testbed, Bug-gyCart, which can flexibly add or remove 35 PCI DSS related vulnerabilities. Then we use the testbed to examine the capability and limitations of PCI scanners and the rigor of the certification process. We find that there is an alarming gap between the security standard and its real-world enforcement. None of the 6 PCI scanners we tested are fully compliant with the PCI scanning guidelines, issuing certificates to merchants that still have major vulnerabilities. To further examine the compliance status of real-world e-commerce websites, we build a new lightweight scanning tool named Pci-CheckerLite and scan 1,203 e-commerce websites across various business sectors. The results confirm that 86% of the websites have at least one PCI DSS violation that should have disqualified them as non-compliant. Our in-depth accuracy analysis also shows that PciCheckerLite's output is more precise than w3af. We reached out to the PCI Security Council to share our research results to improve the enforcement in practice. CCS Concepts • Security and privacy → Web application security; Web protocol security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 520da96a-a073-45b1-b1d1-328a11127de5Cited by top-tier papers10
- Continuous ComplianceMartin Kellogg, Martin Schäf, Serdar Tasiran, Michael D. ErnstASE 2020 · 16 citations
- Measuring Secure Coding Practice and Culture: A Finger Pointing at the Moon is not the MoonIta Ryan, Utz Roedig, Klaas-Jan StolICSE 2023 · 13 citations
- Unhelpful Assumptions in Software Security ResearchIta Ryan, Utz Roedig, Klaas-Jan StolCCS 2023 · 9 citations
- Spinner: Automated Dynamic Command Subsystem PerturbationMeng Wang, Chijung Jung, Ali Ahad, Yonghwi KwonCCS 2021 · 6 citations
- Cardpliance: PCI DSS Compliance of Android ApplicationsSamin Yaseer Mahmud, Akhil Acharya, Benjamin Andow, William Enck et al.USENIX Security 2020
Builds on8
- PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing BlacklistsAdam Oest, Yeganeh Safaei, Adam Doupé, Gail-Joon Ahn et al.S&P 2019 · 129 citations
- PhishEye: Live Monitoring of Sandboxed Phishing KitsXiao Han, Nizar Kheir, Davide BalzarottiCCS 2016 · 118 citations
- Don't Trust The Locals: Investigating the Prevalence of Persistent Client-Side Cross-Site Scripting in the WildMarius Steffens, Christian Rossow, Martin Johns, Ben StockNDSS 2019 · 84 citations
- Deemon: Detecting CSRF with Dynamic Analysis and Property GraphsGiancarlo Pellegrino, Martin Johns, Simon Koch, Michael Backes et al.CCS 2017 · 74 citations
- Fear the Reaper: Characterization and Fast Detection of Card SkimmersNolen Scaife, Christian Peeters, Patrick TraynorUSENIX Security 2018 · 34 citations
Related papers
- All Your Shops Are Belong to Us: Security Weaknesses in E-commerce PlatformsRohan Pagey, Mohammad Mannan, Amr M. YoussefWWW 2023 · 10 citations
- A Formal Security Analysis of the W3C Web Payment APIs: Attacks and VerificationQuoc Huy Do, Pedram Hosseyni, Ralf Küsters, Guido Schmitz et al.S&P 2022 · 6 citations
- SCAMMAGNIFIER: Piercing the Veil of Fraudulent Shopping Website CampaignsMarzieh Bitaab, Alireza Karimi, Zhuoer Lyu, Adam Oest et al.NDSS 2025
- "We can't Change it Overnight": Understanding Industry Perspectives on IoT Product Security Compliance and CertificationPrianka Mandal, Adwait NadkarniS&P 2025
- Compliance Cautions: Investigating Security Issues Associated with U.S. Digital-Security StandardsRock Stevens, Josiah Dykstra, Wendy Knox Everette, James Chapman et al.NDSS 2020
