Introduction to HTTP security headers and implementation of HTTP strict transport security (HSTS) header for HTTPS enforcing
Title | Introduction to HTTP security headers and implementation of HTTP strict transport security (HSTS) header for HTTPS enforcing |
Publication Type | Conference Paper |
Year of Publication | 2017 |
Authors | Dolnák, I., Litvik, J. |
Conference Name | 2017 15th International Conference on Emerging eLearning Technologies and Applications (ICETA) |
Keywords | Browsers, communication security, Computer crime, HSTS, HTTP protocol, HTTP strict transport security header, HTTPS protocol, Human Behavior, hypermedia, Internet, Internet of Things, IoT, Metrics, Protocols, pubcrawl, Resiliency, security, security of data, security policies, SSL-TLS certificates, transport protocols, Web Browser Security, Web browsers, Web servers, Web sites |
Abstract | This article presents introduction to HTTP Security Headers - new security topic in communication over Internet. It is emphasized that HTTPS protocol and SSL/TLS certificates alone do not offer sufficient level of security for communication among people and devices. In the world of web applications and Internet of Things (IoT), it is vital to bring communication security at higher level, what could be realised via few simple steps. HTTP Response Headers used for different purposes in the past are now the effective way how to propagate security policies from servers to clients (from web servers to web browsers). First improvement is enforcing HTTPS protocol for communication everywhere it is possible and promote this protocol as first and only option for secure connection over the Internet. It is emphasized that HTTP protocol for communication is not suitable anymore. |
URL | https://ieeexplore.ieee.org/document/8102478/ |
DOI | 10.1109/ICETA.2017.8102478 |
Citation Key | dolnak_introduction_2017 |
- Metrics
- Web sites
- Web servers
- Web browsers
- Web Browser Security
- transport protocols
- SSL-TLS certificates
- security policies
- security of data
- security
- Resiliency
- pubcrawl
- Protocols
- Browsers
- IoT
- Internet of Things
- internet
- hypermedia
- Human behavior
- HTTPS protocol
- HTTP strict transport security header
- HTTP protocol
- HSTS
- Computer crime
- communication security