首页> 外文会议>International Conference on Cyber Conflict >HTTP security headers analysis of top one million websites
【24h】

HTTP security headers analysis of top one million websites

机译:前一百万个网站的HTTP安全标头分析

获取原文

摘要

We present research on the security of the most popular websites, ranked according to Alexa's top one million list, based on an HTTP response headers analysis. For each of the domains included in the list, we made four different requests: an HTTP/1.1 request to the domain itself and to its "www" subdomain and two more equivalent HTTPS requests. Redirections were always followed. A detailed discussion of the request process and main outcomes is presented, including X.509 certificate issues and comparison of results with equivalent HTTP/2 requests. The body of the responses was discarded, and the HTTP response header fields were stored in a database. We analysed the prevalence of the most important response headers related to web security aspects. In particular, we took into account Strict- Transport-Security, Content-Security-Policy, X-XSS-Protection, X-Frame-Options, Set-Cookie (for session cookies) and X-Content-Type. We also reviewed the contents of response HTTP headers that potentially could reveal unwanted information, like Server (and related headers), Date and Referrer-Policy. This research offers an up-to-date survey of current prevalence of web security policies implemented through HTTP response headers and concludes that most popular sites tend to implement it noticeably more often than less popular ones. Equally, HTTPS sites seem to be far more eager to implement those policies than HTTP only websites. A comparison with previous works show that web security policies based on HTTP response headers are continuously growing, but still far from satisfactory widespread adoption.
机译:我们根据HTTP响应标头分析,对最受欢迎的网站的安全性进行了研究,并根据Alexa的排名前100万的列表进行了排名。对于列表中包括的每个域,我们提出了四个不同的请求:对该域本身及其“ www”子域的HTTP / 1.1请求,以及另外两个等效的HTTPS请求。始终遵循重定向。提出了对请求过程和主要结果的详细讨论,包括X.509证书问题以及与等效HTTP / 2请求的结果比较。响应的主体被丢弃,并且HTTP响应标头字段存储在数据库中。我们分析了与Web安全方面相关的最重要的响应标头的普遍性。特别是,我们考虑了严格的传输安全性,内容安全性策略,X-XSS保护,X-Frame-Options,Set-Cookie(用于会话cookie)和X-Content-Type。我们还检查了响应HTTP标头的内容,这些标头可能会泄露不需要的信息,例如Server(和相关标头),Date和Referrer-Policy。这项研究提供了对通过HTTP响应标头实施的Web安全策略的当前流行程度的最新调查,并得出结论,与不那么受欢迎的站点相比,最流行的站点倾向于更频繁地实施它。同样,HTTPS网站似乎比仅HTTP网站更渴望实施这些策略。与以前的工作进行比较表明,基于HTTP响应标头的Web安全策略正在不断发展,但仍远未令人满意地被广泛采用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号