TY - GEN
T1 - Assessing the NGINX Server's Configuration Security Based on CIS Benchmarks
AU - Lekcharuthas, Gewalee
AU - Khurat, Assadarat
AU - Choetkiertikul, Morakot
AU - Ragkhitwetsagul, Chaiyong
N1 - Publisher Copyright:
© 2025 IEEE.
PY - 2025
Y1 - 2025
N2 - Websites and applications commonly rely on web server software such as NGINX to handle server-side tasks. Administrators often copy configuration files of these servers from online sources (e.g., GitHub) and adapt them, but these files can be misconfigured and introduce security vulnerabilities. This paper presents an automated tool that assesses NGINX configuration files against the CIS Benchmark for NGINX by the Center for Internet Security (CIS). We categorized benchmark recommendations applicable to configuration files, implemented the tool, and evaluated it on 23 popular NGINXbased GitHub repositories. On average, only about 4.01% of scannable recommendations were implemented; configurations for logging and encryption were absent from defaults. These findings raise concerns for developers adopting such files without thorough review. Our evaluation shows that the tool can be used to identify insecure or missing configurations in online-sourced configurations and promotes best practices of having secure configurations for a stronger security posture.
AB - Websites and applications commonly rely on web server software such as NGINX to handle server-side tasks. Administrators often copy configuration files of these servers from online sources (e.g., GitHub) and adapt them, but these files can be misconfigured and introduce security vulnerabilities. This paper presents an automated tool that assesses NGINX configuration files against the CIS Benchmark for NGINX by the Center for Internet Security (CIS). We categorized benchmark recommendations applicable to configuration files, implemented the tool, and evaluated it on 23 popular NGINXbased GitHub repositories. On average, only about 4.01% of scannable recommendations were implemented; configurations for logging and encryption were absent from defaults. These findings raise concerns for developers adopting such files without thorough review. Our evaluation shows that the tool can be used to identify insecure or missing configurations in online-sourced configurations and promotes best practices of having secure configurations for a stronger security posture.
KW - CIS benchmarks
KW - configuration security
KW - web server auditing
KW - web server security
UR - https://www.scopus.com/pages/publications/105032724655
U2 - 10.1109/ICSEC67360.2025.11298035
DO - 10.1109/ICSEC67360.2025.11298035
M3 - Conference contribution
AN - SCOPUS:105032724655
T3 - ICSEC 2025 - 29th International Computer Science and Engineering Conference 2025
SP - 459
EP - 464
BT - ICSEC 2025 - 29th International Computer Science and Engineering Conference 2025
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 29th International Computer Science and Engineering Conference, ICSEC 2025
Y2 - 2 November 2025 through 5 November 2025
ER -