Pāriet uz galveno navigāciju Pāriet uz meklēšanu Pāriet uz galveno saturu

HTTP security headers analysis of top one million websites

  • NATO CCD COE
  • Spanish Joint Cyber Defence Command

Zinātniskās darbības rezultāts: Nodaļa grāmatā/enciklopēdijā/konferences krājumāKonferences zinātniskais rakstsPētniecībakoleģiāli recenzēts

35 Atsauces (Scopus)

Kopsavilkums

We present research on the security of the most popular websites, ranked according to Alexa's top one million list, based on an HTTP response headers analysis. For each of the domains included in the list, we made four different requests: an HTTP/1.1 request to the domain itself and to its "www" subdomain and two more equivalent HTTPS requests. Redirections were always followed. A detailed discussion of the request process and main outcomes is presented, including X.509 certificate issues and comparison of results with equivalent HTTP/2 requests. The body of the responses was discarded, and the HTTP response header fields were stored in a database. We analysed the prevalence of the most important response headers related to web security aspects. In particular, we took into account Strict- Transport-Security, Content-Security-Policy, X-XSS-Protection, X-Frame-Options, Set-Cookie (for session cookies) and X-Content-Type. We also reviewed the contents of response HTTP headers that potentially could reveal unwanted information, like Server (and related headers), Date and Referrer-Policy. This research offers an up-to-date survey of current prevalence of web security policies implemented through HTTP response headers and concludes that most popular sites tend to implement it noticeably more often than less popular ones. Equally, HTTPS sites seem to be far more eager to implement those policies than HTTP only websites. A comparison with previous works show that web security policies based on HTTP response headers are continuously growing, but still far from satisfactory widespread adoption.

OriģinālvalodaAngļu
Rīkotāja publikācijas nosaukums2018 10th International Conference on Cyber Conflict
Rīkotāja publikācijas apakšnosaukumsCyCon X: Maximising Effects, CyCon 2018
RedaktoriTomas Minarik, Lauri Lindstrom, Raik Jakschis
IzdevējsNATO CCD COE Publications
Lapas345-370
Lapu skaits26
ISBN (Elektroniski)9789949990429
DOIs
Publikācijas statussPublicēts - 5 jūl. 2018
Ārēji publicēts
Pasākums10th International Conference on Cyber Conflict: CyCon X: Maximising Effects, CyCon 2018 - Tallinn, Igaunija
Ilgums: 30 maijs 20181 jūn. 2018

Publikāciju sērijas

NosaukumsInternational Conference on Cyber Conflict, CYCON
Sējums2018-May
ISSN (Drukātā versija)2325-5366
ISSN (Elektroniskā versija)2325-5374

Konference

Konference10th International Conference on Cyber Conflict: CyCon X: Maximising Effects, CyCon 2018
Valsts/TeritorijaIgaunija
PilsētaTallinn
Periods30/05/181/06/18

Nospiedums

Uzziniet vairāk par pētniecības tēmām “HTTP security headers analysis of top one million websites”. Kopā tie veido unikālu nospiedumu.

Citēt šo