VEB-ILOVALARDA HTTP XAVFSIZLIK SARLAVHALARINI JORIY ETISHNING DOLZARB MUAMMOLARI

VEB-ILOVALARDA HTTP XAVFSIZLIK SARLAVHALARINI JORIY ETISHNING DOLZARB MUAMMOLARI

Авторы

  • Toshpo‘latov Sh Muhammad Al-Xorazmiy nomidagi Toshkent axborot texnologiyalari universiteti

Ключевые слова:

HTTP xavfsizlik sarlavhalari, veb-xavfsizlik, Content- Security-Policy, HSTS, noto‘g‘ri konfiguratsiya, OWASP, kiberxavfsizlik.

Аннотация

В статье анализируется роль HTTP-заголовков
безопасности как первой линии защиты веб-приложений, а также
практические проблемы их внедрения. Рассматриваются основные
заголовки — Content-Security-Policy, Strict-Transport-Security, X-Frame-
Options, X-Content-Type-Options и Referrer-Policy, трудности их корректной
настройки и риски безопасности, возникающие при их неправильной
конфигурации. Результаты исследования позволяют выявить текущее
состояние развёртывания заголовков безопасности и наиболее
распространённые шаблоны их некорректной настройки.

Библиографические ссылки

OWASP Foundation. (2021). OWASP Top 10: Web Application Security Risks. Retrieved May 13, 2026, from https://owasp.org/Top10/

Mozilla Developer Network. (2026). HTTP Security Headers. Retrieved January 15, 2026, from https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers

Mlyatu, M. M., & Sanga, C. (2023). Secure web application technologies implementation through hardening security headers using automated threat modelling techniques. International Journal of Computer Applications, 185(10), 12–20.

Martins, S. L., Cruz, F. M., Araújo, R. P., & Silva, C. M. R. (2022). Systematic literature review on security misconfigurations in web applications. Journal of Systems and Software, 192, Article 111420.

Kumi, S., Lim, C. H., Lee, S., Oktian, Y., & Witanto, E. N. (2021). Head(er)s Up! Detecting security header inconsistencies in browsers. In Proceedings of the IEEE Conference on Computer Communications (pp. 1–10).

Rautenstrauch, J., Nguyen, T. T., Ramakrishnan, K., & Stock, B. (2023). Helping or hindering? How browser extensions undermine security. In Proceedings of the USENIX Security Symposium (pp. 245–262).

Weichselbaum, L., Spagnuolo, M., Garmany, S., & Janc, A. (2016). CSP is dead, long live CSP! On the insecurity of whitelists and the future of Content Security Policy. In Proceedings of the ACM Conference on Computer and Communications Security (pp. 1376–1387).

Agarwal, S. (2022). First, Do No Harm: Studying the Manipulation of Security Headers in Browser Extensions (Master’s thesis).

OWASP Foundation. (2026). OWASP Secure Headers Project. Retrieved May 13, 2026, from https://owasp.org/www-project-secure-headers/

Загрузки

Опубликован

2026-05-21

Как цитировать

Toshpo‘latov Sh. (2026). VEB-ILOVALARDA HTTP XAVFSIZLIK SARLAVHALARINI JORIY ETISHNING DOLZARB MUAMMOLARI. MANAGEMENT AND ECONOMICS SCIENTIFIC RESEARCH JOURNAL, 3(2), 209–214. извлечено от https://journals.timeedu.uz/index.php/mesr/article/view/135

Выпуск

Раздел

article
Loading...