2021
DOI: 10.1007/978-3-030-72582-2_5
|View full text |Cite
|
Sign up to set email alerts
|

Our (in)Secure Web: Understanding Update Behavior of Websites and Its Impact on Security

Abstract: Software updates take an essential role in keeping IT environments secure. If service providers delay or do not install updates, it can cause unwanted security implications for their environments. This paper conducts a large-scale measurement study of the update behavior of websites and their utilized software stacks. Across 18 months, we analyze over 5.6M websites and 246 distinct client-and server-side software distributions. We found that almost all analyzed sites use outdated software. To understand the po… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1

Citation Types

0
4
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
3
2
2

Relationship

0
7

Authors

Journals

citations
Cited by 7 publications
(4 citation statements)
references
References 18 publications
0
4
0
Order By: Relevance
“…Sites and Pages. In this work, we use the term site to depict the registerable part of a given domain-often referred to as "extended Top Level Domain plus one" (eTLD+1) [6,10,23,42]. For example, given the URL https://www.bar.com/ the eTLD+1 is bar.com, or the URL https://foo.co.uk the eTLD+1 is foo.co.uk.…”
Section: Terminology and Backgroundmentioning
confidence: 99%
“…Sites and Pages. In this work, we use the term site to depict the registerable part of a given domain-often referred to as "extended Top Level Domain plus one" (eTLD+1) [6,10,23,42]. For example, given the URL https://www.bar.com/ the eTLD+1 is bar.com, or the URL https://foo.co.uk the eTLD+1 is foo.co.uk.…”
Section: Terminology and Backgroundmentioning
confidence: 99%
“…Online tracking. Several works analyzed the usage of cross-site tracking techniques in the wild [15]. Chen et al [13] propose a data flow tracking system to measure user tracking performed through first-party cookies that third-party JavaScript sets.…”
Section: Related Workmentioning
confidence: 99%
“…Reference [12] performed a survey to 548 governmental websites in Indonesia to see the technologies used, in particular: web server, web programming, CSS, content management system, web framework, and web 3.0. Reference [13] reviewed 5.6 million websites within the time span of 18 months from HTTPArchive, to see whether they are using outdated software. Their work is similar to our research and done on a much larger scale (our research was done on 1,500 websites and performed on one day).…”
Section: Related Workmentioning
confidence: 99%
“…However, there are several differences between the two. Reference [13] looked for software that does not use the latest minor or patch version as extracted from each application GitHub repository, while our research focuses more on the versions supported stated in the maintainer's website. We also used on-the-fly Wappalyzer detection, while reference [13] relied on Wapplayzer information detected earlier by HTTPArchive.…”
Section: Related Workmentioning
confidence: 99%