An Empirical Analysis of HTTPS Configuration Security

11/01/2021
by   Camelia Simoiu, et al.
0

It is notoriously difficult to securely configure HTTPS, and poor server configurations have contributed to several attacks including the FREAK, Logjam, and POODLE attacks. In this work, we empirically evaluate the TLS security posture of popular websites and endeavor to understand the configuration decisions that operators make. We correlate several sources of influence on sites' security postures, including software defaults, cloud providers, and online recommendations. We find a fragmented web ecosystem: while most websites have secure configurations, this is largely due to major cloud providers that offer secure defaults. Individually configured servers are more often insecure than not. This may be in part because common resources available to individual operators – server software defaults and online configuration guides – are frequently insecure. Our findings highlight the importance of considering SaaS services separately from individually-configured sites in measurement studies, and the need for server software to ship with secure defaults.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/02/2018

A Comprehensive Approach to Abusing Locality in Shared Web Hosting Servers

With the growing of network technology along with the need of human for ...
research
09/24/2018

The Struggle is Real: Analyzing Ground Truth Data of TLS (Mis-)Configurations

As of today, TLS is the most commonly used protocol to protect communica...
research
05/11/2019

HSTS Preloading is Ineffective as a Long-Term, Wide-Scale MITM-Prevention Solution: Results from Analyzing the 2013 - 2017 HSTS Preload List

HSTS (HTTP Strict Transport Security) serves to protect websites from ce...
research
02/09/2018

Urban vs. rural divide in HTTPS implementation for hospital websites in Illinois

The Hypertext Transfer Protocol Secure (HTTPS) communications protocol i...
research
10/28/2021

A First Look at the Consolidation of DNS and Web Hosting Providers

Although the Internet continues to grow, it increasingly depends on a sm...
research
05/12/2021

Web Content Signing with Service Workers

Securing the communication between a web server and a browser is a funda...
research
03/27/2020

Assessing the Security of OPC UA Deployments

To address the increasing security demands of industrial deployments, OP...

Please sign up or login with your details

Forgot password? Click here to reset