Mapping and Analysis of Common Vulnerabilities in Popular Web Servers


연구 분야: Verification



학회: International Conference on Critical Information Infrastructures Security


초록

The digitalization of the modern society has made many organizations susceptible to cybercrime through exploitations of software vulnerabilities. The popular web servers Apache HTTP and Nginx make up around 65% of the market for web server software and power the majority of all websites on the internet. Vulnerabilities that occur in these two software programs therefore pose a significant risk to the millions of users. This paper maps the most common vulnerability types in these web servers by retrieving, filtering, and analyzing information related to around 195,000 reported vulnerabilities. The results not only show that 5 vulnerability types according to the NIST classification, namely CWE-20, CWE-200, CWE-22, CWE-79, and CWE-787, account for almost 25% of all reported vulnerabilities in Apache HTTP and Nginx, but also that these vulnerability types are commonly found in other web software as well. The outcomes of this study are useful for constructing proof-of-concept insecurity demonstrations and for applying in awareness exercises and cybersecurity education.


Author Profile
Simin Nadjm-Tehrani

Department of Computer and Information Science Linköping University Linköping Sweden

Andorra
Author Profile
Matyas Barocsai

Department of Cyber Defence and C2 Technology Swedish Defence Research Agency (FOI) Stockholm Sweden

Andorra
Author Profile
Johan Can

Department of Computer and Information Science Linköping University Linköping Sweden

Andorra

📄 논문 정보

발행 연도 2024년
인용수 0
출판 국가 Andorra
사이트 Springer
좋아요 수 0

연관 논문 목록 (84건)