VEB-ILOVALARDА XAVFSIZLIK SARLAVHALARINING NOTO‘G‘RI KONFIGURATSIYASI: ANIQLASH VA TAHLIL

Nasrullayev Nurbek Baxtiyarovich, Azimova, Toshpo‘latov Sherzod Ortuqboy o‘g‘li

Management and Economics Scientific Research Journal · 2026-yil

Annotatsiya

This study investigates the implementation of HTTP security headers in webapplications under the .uz domain. The security headers examined include Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, and X-XSS-Protection.The study employed automated scanning tools and manual validation methods. 15 webapplications across five sectors — e-commerce, fintech, government, education, and media —were analyzed. The results revealed that 40% of web applications have not enforced any securityheaders. CSP is present on 53% of sites; however, 63% of implementations are misconfigured. A"Security Theater" phenomenon was identified: one portal possesses all security headers andscored 100 points in automated scanning, yet received an F grade from securityheaders.com. Thestudy develops a misconfiguration taxonomy for addressing security header configuration errors.

Maqola ma’lumotlari
MualliflarNasrullayev Nurbek Baxtiyarovich, Azimova, Toshpo‘latov Sherzod Ortuqboy o‘g‘li
JurnalManagement and Economics Scientific Research Journal
Nashr sanasi2026-04-01
Jild3
Son3
Betlar86-96
TilO‘zbek

Kalit so‘zlar

HTTP xavfsizlik sarlavhalari, noto‘g‘ri konfiguratsiya, Content-Security-Policy, soxta xavfsizlik, veb-ilovalar xavfsizligi

Ilmiy soha

Management and Economics Scientific Research Journal jurnalidan boshqa maqolalar

Management and Economics Scientific Research Journal — barcha maqolalar