Authors: Aleksandra Mileva, Dushan Bikov, Bojana Tasheva, Aleksandra Brashnarova
Keywords: Websites security, HTTP security headers, Mozil\-la Observatory, XSS, clickjacking.
Abstract
The present research focuses on the security of Macedonian websites. It involves the analysis of HTTP Security header responses for 756 websites in the country, of which 246 are the most popular. This analysis is conducted across 13 different categories of websites, including government bodies and institutions, public institutions and enterprises, educational, commercial, news and media, entertainment, sports, etc. We intend to create a comprehensive security profile for the country's websites, which will help raise their overall security level. It is critical to understand and implement proper HTTP security headers to prevent or limit the dangers that can cause website attacks such as Denial of Service (DoS), Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), SQL Injection, clickjacking, etc. Our analysis was performed with the help of the Mozilla Observatory tool. We have discovered a significant lack of implementation and/or misconfiguration of HTTP security headers in all categories. Almost half of the websites (n=375; 49.60\%) have an F grade, while more than a quarter of all websites (n=214; 28.31\%) have a minimal security score of 0.
Aleksandra Mileva
ORCID:
https://orcid.org/0000-0003-0706-6355
Goce Delcev University, Faculty of Computer Science
str. Krste Misirkov No. 10-A P.O box 201, Stip, 2000, Macedonia
E-mail:
Dushan Bikov
ORCID:
https://orcid.org/0000-0002-5145-5297
Goce Delcev University, Faculty of Computer Science
str. Krste Misirkov No. 10-A P.O box 201, Stip, 2000, Macedonia
E-mail:
Bojana Tasheva
Goce Delcev University, Faculty of Computer Science
str. Krste Misirkov No. 10-A P.O box 201, Stip, 2000, Macedonia
E-mail:
Aleksandra Brashnarova
Goce Delcev University, Faculty of Computer Science
str. Krste Misirkov No. 10-A P.O box 201, Stip, 2000, Macedonia
E-mail:
DOI
https://doi.org/10.56415/csjm.v33.01
Fulltext

–
0.72 Mb