Secure web application technologies implementation through hardening security headers using automated threat modelling techniques

dc.creatorMlyatu, Maduhu Mshangi
dc.creatorSanga, Camilius
dc.date.accessioned2022-12-13T06:19:54Z
dc.date.accessioned2025-08-05T07:43:02Z
dc.date.available2022-12-13T06:19:54Z
dc.date.created2022-12-13T06:19:54Z
dc.date.issued2022
dc.description.abstractThis paper investigates whether security headers are enforced to mitigate cyber- attacks in web-based systems in cyberspace. The security headers examined include X-Content-Type-Options, X-Frame-Options, Strict-Transport-Security, Referrer-Policy, Content-Security-Policy, and Permissions-Policy. The study employed a controlled experiment using a security header analysis tool. The web-based applications (websites) were analyzed to determine whether security headers have been correctly implemented. The experiment was iterated for 100 universities in Africa which are ranked high. The purposive sampling technique was employed to understand the status quo of the security headers implementations. The results revealed that 70% of the web-based applications in Africa have not enforced security headers in web-based applications. The study proposes a secure system architecture design for addressing web-based applications’ misconfiguration and insecure design. It presents security techniques for securing web-based applications through hardening security headers using automated threat modelling techniques. Furthermore, it recommends adopting the security headers in web-based applications using the proposed secure system architecture design.
dc.identifierHow to cite this paper: Mlyatu, M.M. and Sanga, C. (2023) Secure Web Application Technologies Implementation through Hardening Security Headers Using Automated Threat Modelling Techniques. Journal of Information Security , 14, 1-15. https://doi.org/10.4236/jis.2023.141001
dc.identifier2153-1242
dc.identifier2153-1234
dc.identifierhttp://www.suaire.sua.ac.tz/handle/123456789/4816
dc.identifier.urihttp://repository.costech.or.tz/handle/20.500.14732/99731
dc.languageen
dc.publisherScientific Research Publishing Inc.
dc.subjectSecure web applications
dc.subjectSecurity headers
dc.subjectSystems security
dc.subjectSecure web architecture design
dc.titleSecure web application technologies implementation through hardening security headers using automated threat modelling techniques
dc.typeArticle

Files