CASA: a comprehensive automatic web servers audit
| dc.contributor.author | Khurat A. | |
| dc.contributor.author | Gunatilaka D. | |
| dc.contributor.author | Kethom W. | |
| dc.contributor.correspondence | Khurat A. | |
| dc.contributor.other | Mahidol University | |
| dc.date.accessioned | 2026-02-06T18:29:05Z | |
| dc.date.available | 2026-02-06T18:29:05Z | |
| dc.date.issued | 2026-01-01 | |
| dc.description.abstract | Web servers play a crucial role in web technology. Insufficient protection can lead to serious risks, such as sensitive data exposure. To reduce risk of successful attacks, regular web server configuration audits are conducted. However, manual auditing is often tedious and error-prone, as it requires running commands to check configurations. To enhance this process, we introduce CASA, an automated audit tool designed for four widely used web servers: Nginx, Apache HTTP, Apache Tomcat, and Microsoft IIS. CASA evaluates configurations against industry standard CIS benchmarks, identifies non-compliant settings, and generates HTML audit reports. Our analysis shows that CASA significantly enhances automation in security auditing. We validate its effectiveness by comparing results with manual audits and analysing default and publicly available configurations from GitHub. The findings indicate low compliance with security benchmarks, with less than half of configurations meeting recommended standards, exposing critical risks in unmodified deployments. | |
| dc.identifier.citation | International Journal of Information and Computer Security Vol.29 No.1 (2026) , 87-111 | |
| dc.identifier.doi | 10.1504/IJICS.2026.150538 | |
| dc.identifier.eissn | 17441773 | |
| dc.identifier.issn | 17441765 | |
| dc.identifier.scopus | 2-s2.0-105025718489 | |
| dc.identifier.uri | https://repository.li.mahidol.ac.th/handle/123456789/114714 | |
| dc.rights.holder | SCOPUS | |
| dc.subject | Computer Science | |
| dc.subject | Engineering | |
| dc.title | CASA: a comprehensive automatic web servers audit | |
| dc.type | Article | |
| mu.datasource.scopus | https://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=105025718489&origin=inward | |
| oaire.citation.endPage | 111 | |
| oaire.citation.issue | 1 | |
| oaire.citation.startPage | 87 | |
| oaire.citation.title | International Journal of Information and Computer Security | |
| oaire.citation.volume | 29 | |
| oairecerif.author.affiliation | Mahidol University |
