Assessing the NGINX Server's Configuration Security Based on CIS Benchmarks
| dc.contributor.author | Lekcharuthas G. | |
| dc.contributor.author | Khurat A. | |
| dc.contributor.author | Choetkiertikul M. | |
| dc.contributor.author | Ragkhitwetsagul C. | |
| dc.contributor.correspondence | Lekcharuthas G. | |
| dc.contributor.other | Mahidol University | |
| dc.date.accessioned | 2026-03-20T18:25:43Z | |
| dc.date.available | 2026-03-20T18:25:43Z | |
| dc.date.issued | 2025-01-01 | |
| dc.description.abstract | Websites and applications commonly rely on web server software such as NGINX to handle server-side tasks. Administrators often copy configuration files of these servers from online sources (e.g., GitHub) and adapt them, but these files can be misconfigured and introduce security vulnerabilities. This paper presents an automated tool that assesses NGINX configuration files against the CIS Benchmark for NGINX by the Center for Internet Security (CIS). We categorized benchmark recommendations applicable to configuration files, implemented the tool, and evaluated it on 23 popular NGINXbased GitHub repositories. On average, only about 4.01% of scannable recommendations were implemented; configurations for logging and encryption were absent from defaults. These findings raise concerns for developers adopting such files without thorough review. Our evaluation shows that the tool can be used to identify insecure or missing configurations in online-sourced configurations and promotes best practices of having secure configurations for a stronger security posture. | |
| dc.identifier.citation | Icsec 2025 29th International Computer Science and Engineering Conference 2025 (2025) , 459-464 | |
| dc.identifier.doi | 10.1109/ICSEC67360.2025.11298035 | |
| dc.identifier.scopus | 2-s2.0-105032724655 | |
| dc.identifier.uri | https://repository.li.mahidol.ac.th/handle/123456789/115802 | |
| dc.rights.holder | SCOPUS | |
| dc.subject | Computer Science | |
| dc.subject | Decision Sciences | |
| dc.title | Assessing the NGINX Server's Configuration Security Based on CIS Benchmarks | |
| dc.type | Conference Paper | |
| mu.datasource.scopus | https://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=105032724655&origin=inward | |
| oaire.citation.endPage | 464 | |
| oaire.citation.startPage | 459 | |
| oaire.citation.title | Icsec 2025 29th International Computer Science and Engineering Conference 2025 | |
| oairecerif.author.affiliation | Mahidol University |
