VEB-ILOVALARDА XAVFSIZLIK SARLAVHALARINING NOTO‘G‘RI KONFIGURATSIYASI: ANIQLASH VA TAHLIL
Ключевые слова:
HTTP xavfsizlik sarlavhalari, noto‘g‘ri konfiguratsiya, Content-Security-Policy, soxta xavfsizlik, veb-ilovalar xavfsizligiАннотация
В исследовании оценивается внедрение HTTP-заголовков безопасности в
веб-приложениях домена .uz. Проверяемые заголовки включают Content-Security-Policy,
Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options и X-XSS-Protection.
Применены автоматизированное сканирование и ручная валидация. Проанализировано
15 веб-приложений из пяти секторов: электронная коммерция, финтех,
государственный, образовательный и медиа. Результаты показали, что в 40% веб-
приложений заголовки безопасности полностью отсутствуют. CSP присутствует на53% сайтов, однако 63% реализаций настроены неверно. Выявлен феномен «Security
Theater»: один портал имеет все заголовки безопасности и набрал 100 баллов при
автоматическом сканировании, но получил оценку F от securityheaders.com. В работе
разработана таксономия ошибок конфигурации.
Библиографические ссылки
OWASP Foundation. (2026). OWASP Secure Headers Project. Retrieved March 15, 2026, from https://owasp.org/www-project-secure-headers/
OWASP Foundation. (2025). OWASP Top 10: Web Application Security Risks. Retrieved March 15, 2026, from https://owasp.org/Top10/
Mlyatu, M. M., & Sanga, C. (2023). Secure web application technologies implementation through hardening security headers using automated threat modelling techniques. International Journal of Computer Applications, 185(10), 12–20.
Martins, S. L., Cruz, F. M., Araújo, R. P., & Silva, C. M. R. (2022). Systematic literature review on security misconfigurations in web applications. Journal of Systems and Software, 192, 111420.
Kumi, S., Lim, C. H., Lee, S., Oktian, Y., & Witanto, E. N. (2021). Head(er)s Up! Detecting security header inconsistencies in browsers. In Proceedings of the IEEE Conference on Computer Communications (pp. 1–10).
Rautenstrauch, J., Nguyen, T. T., Ramakrishnan, K., & Stock, B. (2023). Helping or hindering? How browser extensions undermine security. In Proceedings of the USENIX Security Symposium (pp. 245–262).
Agarwal, S. (2022). First, do no harm: Studying the manipulation of security headers in browser extensions (Master’s thesis). University of California.
Agarwal, S., & Chen, J. (2023). Browser extension security: Analysis of header manipulation patterns. In Proceedings of the Web Security Conference (pp. 78–92).
Weichselbaum, L., Spagnuolo, M., Garmany, S., & Janc, A. (2016). CSP is dead, long live CSP! On the insecurity of whitelists and the future of Content Security Policy. In Proceedings of the ACM Conference on Computer and Communications Security (pp. 1376–1387).
Mozilla Developer Network. (2024). HTTP Security Headers. Retrieved March 15, 2026, from https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers