Security Header Fields in HTTP Clients

11/05/2021
by   Pascal Gadient, et al.
0

HTTP headers are commonly used to establish web communications, and some of them are relevant for security. However, we have only little information about the usage and support of security-relevant headers in mobile applications. We explored the adoption of such headers in mobile app communication by querying 9,714 distinct URLs that were used in 3,376 apps and collected each server's response information. We discovered that support for secure HTTP header fields is absent in all major HTTP clients, and it is barely provided with any server response. Based on these results, we discuss opportunities for improvement particularly to reduce the likelihood of data leaks and arbitrary code execution. We advocate more comprehensive use of existing HTTP headers and timely development of relevant web browser security features in HTTP client libraries.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/16/2021

Security Smells Pervade Mobile App Servers

[Background] Web communication is universal in cyberspace, and security ...
research
04/04/2018

Co Hijacking Monitor: Collaborative Detecting and Locating Mechanism for HTTP Spectral Hijacking

With the rapid growth of mobile internet, mobile application, like websi...
research
04/12/2021

Exploring the Attack Surface of WebSocket

Over the years, with the advancement of technology, Web technology has m...
research
10/12/2018

Is the Web ready for HTTP/2 Server Push?

HTTP/2 supersedes HTTP/1.1 to tackle the performance challenges of the m...
research
07/20/2020

Towards an ontology of HTTP interactions

Enterprise information systems have adopted Web-based foundations for ex...
research
01/01/2020

Web APIs in Android through the Lens of Security

Web communication has become an indispensable characteristic of mobile a...
research
08/13/2019

Enhanced Performance and Privacy via Resolver-Less DNS

The domain name resolution into IP addresses can significantly delay con...

Please sign up or login with your details

Forgot password? Click here to reset