Conformity Analysis of HTTP Strict Transport Security (HSTS) Configuration and Implementation Using Bettercap Tools

Amiruddin Amiruddin, Daffa Akbar Putra Yusa, Rizky Ainur Rofiq · 2021

Currently, HTTPS is commonly used because it offers more protection when compared to HTTP. However, it does not rule out the possibility of attacks being carried out against HTTPS. One of the features that can improve HTTPS security is configuring HTTP strict transport security (HSTS). Unfortunately, not all HSTS is successfully configured and implemented correctly due to administrator ignorance. The purpose of this study is to provide an overview of what configurations need to be done to run HSTS properly to increase the functionality of existing features and improve security. Configuration conformity testing is done using three parameters, i.e., max-age, includeSubDomains, and preload. The attack attempts carried out in this exploratory study used Bettercap, which allows multiple types of attacks to be carried out simultaneously. The results obtained from this study include a list of parameters that need to be met as a condition of an adequately configured HSTS on a website, such as the max-age value, which has a minimum value of 31536000.

Read the paper · More papers on PaperTik