Return
A novel hybrid cybersecurity assessment methodology for HTTPS deployment
DOI:10.1016/j.hcc.2025.100344.png)
Abstract
En 中文
Implementing HTTPS is a complex process encompassing technical and human factors, with a significant reliance on the webmaster’s expertise. Although various evaluation methods have been proposed in the scientific literature to address HTTPS deployment challenges, including vulnerabilities related to X.509 certificate fields, cipher suites, mixed content, encryption libraries, and the behaviors of users and webmasters, there remains a lack of a comprehensive methodology that integrates these metrics into a unified framework. To address this gap, this paper introduces a novel hybrid assessment methodology that combines three main cybersecurity assessment techniques: examination, testing, and interviewing. The methodology is further enhanced by integrating K-Means clustering with Large Language Model (LLM) reasoning to interpret interview-based insights and uncover behavioral patterns. It evaluates 12 critical security measures and mechanisms essential for robust HTTPS deployment. The effectiveness of the proposed methodology is demonstrated through a case study analyzing the security posture of HTTPS-secured websites across five domains: e-commerce, e-finance, education, government, and e-newspapers. The obtained results prove the applicability of the methodology in real-world scenarios and offer actionable insights for practitioners and researchers. In addition, the generated dataset of findings provides a comprehensive overview of the analyzed HTTPS website’s security levels and establishes a valuable foundation for future research to improve HTTPS implementation.
Keywords:
HTTPS deployment
Cybersecurity assessment
GPT-4o
Human factors
Hybrid framework
HTTPS-secured websites
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
H
IF:
3
Papers:
239
Citations:
407

