Secure Web Application Technologies Implementation through Hardening Security Headers Using Automated Threat Modelling Techniques
- 1 NECTA, Dar es Salaam, Tanzania
- 2 Sokoine University of Agriculture, Morogoro, Tanzania
Abstract
This paper investigates whether security headers are enforced to mitigate cyb er-attacks in web-based systems in cyberspace. The security headers examined include X-Content-Type-Options, X-Frame-Options, Strict-Transport-Security, Referrer-Policy, Content-Security-Policy, and Permissions-Policy. The study employed a controlled experiment using a security header analysis tool. The web-based applications (websites) were analyzed to determine whether security headers have been correctly implemented. The experiment was iterated for 100 universities in Africa which are ranked high. The purposive sampling technique was employed to understand the status quo of the security headers implementations. The results revealed that 70% of the web-based applications in Africa have not enforced security headers in web-based applications. The study proposes a secure system architecture design for addressing web-based applications’ misconfiguration and insecure design. It presents security techniques for securing web-based applications through hardening security headers using automated threat modelling techniques. Furthermore, it recommends adopting the security headers in web-based applications using the proposed secure system architecture design.
- SANS (2022) Securing Web Application Technologies [SWAT] Checklist. https://www.sans.org/cloud-security/securing-web-application-technologies
- OWASP (2021) OWASP Secure Headers Project. https://owasp.org/www-project-secure-headers
- Mshangi, M., Nfuka, E.N. and Sanga, C. (2017) An Innovative Soft Design Science Methodology for Improving Development of a Secure Information System in Tanzania Using Multi-Layered Approach. Journal of Information Security, 8, 141-165. https://doi.org/10.4236/jis.2017.83010
- Mshangi, M., Sanga, C. and Ngemera Nfuka, E. (2016) Designing Secure Web and Mobile-Based Information System for Dissemination of Students’ Examination Results: The Suitability of Soft Design Science Methodology. International Journal of Computing and ICT Research, 10, 10-40. https://www.researchgate.net/publication/313469379
- CISA (2022) Weak Security Controls and Practices Routinely Exploited for Initial Access. https://www.cisa.gov/uscert/ncas/current-activity/2022/05/17/weak-security-controls-and-practices-routinely-exploited-initial
- Weamie, S.J.Y. (2022) Cross-Site Scripting Attacks and Defensive Techniques: A Comprehensive Survey. International Journal of Communications, Network and System Sciences, 15, 126-148. https://doi.org/10.4236/ijcns.2022.158010
- NIST (2020) National Institute of Standards and Technology Special Publication 800-53, Revision 5: Security and Privacy Controls for Information Systems and Organizations. NIST Special Publication, NIST-800-5 (Revision 5), 1-465.
- Buchanan, W.J., Helme, S. and Woodward, A. (2018) Analysis of the Adoption of Security Headers in HTTP. IET Information Security, 12, 118-126. https://doi.org/10.1049/iet-ifs.2016.0621
- Petkova, L. and Technologies, I. (2019) HTTP Security Headers. Knowledge— International Journal, 30, 701-706. https://doi.org/10.35120/kij3003701p
- Lavrenovs, A. and Melón, F.J.R. (2018) HTTP Security Headers Analysis of Top One Million Websites. International Conference on Cyber Conflict, CYCON, Tallinn, 29 May-1 June 2018, 345-370. https://doi.org/10.23919/CYCON.2018.8405025
- Mozilla (2021) Content Security Policy (CSP). https://developer.mozilla.org/en-US/docs/Web/ HTTP/CSP
- Braun, F. (2019) Chrome Switching the XSSAuditor to Filter Mode Re-Enables the Old Attack. https://frederik-braun.com/xssauditor-bad.html
- Dolnak, I. (2017) Content Security Policy (CSP) as Countermeasure to Cross-Site Scripting (XSS) Attacks. ICETA 2017—15th IEEE International Conference on Emerging eLearning Technologies and Applications, Proceedings, Stary Smokovec, 26-27 October 2017, 1-4. https://doi.org/10.1109/ICETA.2017.8102476