Assessing the NGINX Server's Configuration Security Based on CIS Benchmarks

dc.contributor.authorLekcharuthas G.
dc.contributor.authorKhurat A.
dc.contributor.authorChoetkiertikul M.
dc.contributor.authorRagkhitwetsagul C.
dc.contributor.correspondenceLekcharuthas G.
dc.contributor.otherMahidol University
dc.date.accessioned2026-03-20T18:25:43Z
dc.date.available2026-03-20T18:25:43Z
dc.date.issued2025-01-01
dc.description.abstractWebsites and applications commonly rely on web server software such as NGINX to handle server-side tasks. Administrators often copy configuration files of these servers from online sources (e.g., GitHub) and adapt them, but these files can be misconfigured and introduce security vulnerabilities. This paper presents an automated tool that assesses NGINX configuration files against the CIS Benchmark for NGINX by the Center for Internet Security (CIS). We categorized benchmark recommendations applicable to configuration files, implemented the tool, and evaluated it on 23 popular NGINXbased GitHub repositories. On average, only about 4.01% of scannable recommendations were implemented; configurations for logging and encryption were absent from defaults. These findings raise concerns for developers adopting such files without thorough review. Our evaluation shows that the tool can be used to identify insecure or missing configurations in online-sourced configurations and promotes best practices of having secure configurations for a stronger security posture.
dc.identifier.citationIcsec 2025 29th International Computer Science and Engineering Conference 2025 (2025) , 459-464
dc.identifier.doi10.1109/ICSEC67360.2025.11298035
dc.identifier.scopus2-s2.0-105032724655
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/123456789/115802
dc.rights.holderSCOPUS
dc.subjectComputer Science
dc.subjectDecision Sciences
dc.titleAssessing the NGINX Server's Configuration Security Based on CIS Benchmarks
dc.typeConference Paper
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=105032724655&origin=inward
oaire.citation.endPage464
oaire.citation.startPage459
oaire.citation.titleIcsec 2025 29th International Computer Science and Engineering Conference 2025
oairecerif.author.affiliationMahidol University

Files

Collections