Skip to main navigation Skip to search Skip to main content

HTTP security headers analysis of top one million websites

  • NATO CCD COE
  • Spanish Joint Cyber Defence Command

Research output: Chapter in Book/Report/Conference proceedingConference paperResearchpeer-review

35 Citations (Scopus)

Abstract

We present research on the security of the most popular websites, ranked according to Alexa's top one million list, based on an HTTP response headers analysis. For each of the domains included in the list, we made four different requests: an HTTP/1.1 request to the domain itself and to its "www" subdomain and two more equivalent HTTPS requests. Redirections were always followed. A detailed discussion of the request process and main outcomes is presented, including X.509 certificate issues and comparison of results with equivalent HTTP/2 requests. The body of the responses was discarded, and the HTTP response header fields were stored in a database. We analysed the prevalence of the most important response headers related to web security aspects. In particular, we took into account Strict- Transport-Security, Content-Security-Policy, X-XSS-Protection, X-Frame-Options, Set-Cookie (for session cookies) and X-Content-Type. We also reviewed the contents of response HTTP headers that potentially could reveal unwanted information, like Server (and related headers), Date and Referrer-Policy. This research offers an up-to-date survey of current prevalence of web security policies implemented through HTTP response headers and concludes that most popular sites tend to implement it noticeably more often than less popular ones. Equally, HTTPS sites seem to be far more eager to implement those policies than HTTP only websites. A comparison with previous works show that web security policies based on HTTP response headers are continuously growing, but still far from satisfactory widespread adoption.

Original languageEnglish
Title of host publication2018 10th International Conference on Cyber Conflict
Subtitle of host publicationCyCon X: Maximising Effects, CyCon 2018
EditorsTomas Minarik, Lauri Lindstrom, Raik Jakschis
PublisherNATO CCD COE Publications
Pages345-370
Number of pages26
ISBN (Electronic)9789949990429
DOIs
Publication statusPublished - 5 Jul 2018
Externally publishedYes
Event10th International Conference on Cyber Conflict: CyCon X: Maximising Effects, CyCon 2018 - Tallinn, Estonia
Duration: 30 May 20181 Jun 2018

Publication series

NameInternational Conference on Cyber Conflict, CYCON
Volume2018-May
ISSN (Print)2325-5366
ISSN (Electronic)2325-5374

Conference

Conference10th International Conference on Cyber Conflict: CyCon X: Maximising Effects, CyCon 2018
Country/TerritoryEstonia
CityTallinn
Period30/05/181/06/18

Keywords

  • Content Security Policy
  • HTTP headers
  • HTTP Strict Transport Security
  • HTTP/2
  • HTTPS
  • top one million websites survey
  • web security
  • X.509 certificate

Fingerprint

Dive into the research topics of 'HTTP security headers analysis of top one million websites'. Together they form a unique fingerprint.

Cite this