Skip to main navigation Skip to search Skip to main content

Assessing the NGINX Server's Configuration Security Based on CIS Benchmarks

  • Mahidol University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Websites and applications commonly rely on web server software such as NGINX to handle server-side tasks. Administrators often copy configuration files of these servers from online sources (e.g., GitHub) and adapt them, but these files can be misconfigured and introduce security vulnerabilities. This paper presents an automated tool that assesses NGINX configuration files against the CIS Benchmark for NGINX by the Center for Internet Security (CIS). We categorized benchmark recommendations applicable to configuration files, implemented the tool, and evaluated it on 23 popular NGINXbased GitHub repositories. On average, only about 4.01% of scannable recommendations were implemented; configurations for logging and encryption were absent from defaults. These findings raise concerns for developers adopting such files without thorough review. Our evaluation shows that the tool can be used to identify insecure or missing configurations in online-sourced configurations and promotes best practices of having secure configurations for a stronger security posture.

Original languageEnglish
Title of host publicationICSEC 2025 - 29th International Computer Science and Engineering Conference 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages459-464
Number of pages6
ISBN (Electronic)9798331573836
DOIs
Publication statusPublished - 2025
Event29th International Computer Science and Engineering Conference, ICSEC 2025 - Chiang Mai, Thailand
Duration: 2 Nov 20255 Nov 2025

Publication series

NameICSEC 2025 - 29th International Computer Science and Engineering Conference 2025

Conference

Conference29th International Computer Science and Engineering Conference, ICSEC 2025
Country/TerritoryThailand
CityChiang Mai
Period2/11/255/11/25

Keywords

  • CIS benchmarks
  • configuration security
  • web server auditing
  • web server security

Fingerprint

Dive into the research topics of 'Assessing the NGINX Server's Configuration Security Based on CIS Benchmarks'. Together they form a unique fingerprint.

Cite this