VEB-ILOVALARDА XAVFSIZLIK SARLAVHALARINING NOTO‘G‘RI KONFIGURATSIYASI: ANIQLASH VA TAHLIL

VEB-ILOVALARDА XAVFSIZLIK SARLAVHALARINING NOTO‘G‘RI KONFIGURATSIYASI: ANIQLASH VA TAHLIL

Authors

  • Nasrullayev Nurbek Baxtiyarovich TATU “kiberxavfsizlik” kafedrasi dekani DSc., dotsent
  • Toshpo‘latov Sherzod Ortuqboy o‘g‘li Azimova TATU “Axborot xavfsizligi” yo‘nalishi magistranti

Keywords:

HTTP xavfsizlik sarlavhalari, noto‘g‘ri konfiguratsiya, Content-Security-Policy, soxta xavfsizlik, veb-ilovalar xavfsizligi

Abstract

This study investigates the implementation of HTTP security headers in web
applications under the .uz domain. The security headers examined include Content-Security-
Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, and X-XSS-Protection.
The study employed automated scanning tools and manual validation methods. 15 web
applications across five sectors — e-commerce, fintech, government, education, and media —
were analyzed. The results revealed that 40% of web applications have not enforced any security
headers. CSP is present on 53% of sites; however, 63% of implementations are misconfigured. A
"Security Theater" phenomenon was identified: one portal possesses all security headers and
scored 100 points in automated scanning, yet received an F grade from securityheaders.com. The
study develops a misconfiguration taxonomy for addressing security header configuration errors.

References

OWASP Foundation. (2026). OWASP Secure Headers Project. Retrieved March 15, 2026, from https://owasp.org/www-project-secure-headers/

OWASP Foundation. (2025). OWASP Top 10: Web Application Security Risks. Retrieved March 15, 2026, from https://owasp.org/Top10/

Mlyatu, M. M., & Sanga, C. (2023). Secure web application technologies implementation through hardening security headers using automated threat modelling techniques. International Journal of Computer Applications, 185(10), 12–20.

Martins, S. L., Cruz, F. M., Araújo, R. P., & Silva, C. M. R. (2022). Systematic literature review on security misconfigurations in web applications. Journal of Systems and Software, 192, 111420.

Kumi, S., Lim, C. H., Lee, S., Oktian, Y., & Witanto, E. N. (2021). Head(er)s Up! Detecting security header inconsistencies in browsers. In Proceedings of the IEEE Conference on Computer Communications (pp. 1–10).

Rautenstrauch, J., Nguyen, T. T., Ramakrishnan, K., & Stock, B. (2023). Helping or hindering? How browser extensions undermine security. In Proceedings of the USENIX Security Symposium (pp. 245–262).

Agarwal, S. (2022). First, do no harm: Studying the manipulation of security headers in browser extensions (Master’s thesis). University of California.

Agarwal, S., & Chen, J. (2023). Browser extension security: Analysis of header manipulation patterns. In Proceedings of the Web Security Conference (pp. 78–92).

Weichselbaum, L., Spagnuolo, M., Garmany, S., & Janc, A. (2016). CSP is dead, long live CSP! On the insecurity of whitelists and the future of Content Security Policy. In Proceedings of the ACM Conference on Computer and Communications Security (pp. 1376–1387).

Mozilla Developer Network. (2024). HTTP Security Headers. Retrieved March 15, 2026, from https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers

Downloads

Published

2026-04-01

How to Cite

Nasrullayev Nurbek Baxtiyarovich, & Azimova, T. S. O. o‘g‘li. (2026). VEB-ILOVALARDА XAVFSIZLIK SARLAVHALARINING NOTO‘G‘RI KONFIGURATSIYASI: ANIQLASH VA TAHLIL. MANAGEMENT AND ECONOMICS SCIENTIFIC RESEARCH JOURNAL, 3(1), 86–96. Retrieved from https://journals.timeedu.uz/index.php/mesr/article/view/98

Issue

Section

Articles
Loading...