arrow
Return

CASA: a comprehensive automatic web servers audit

delete2026-01-01
delete0
PRE
AI
K
Khurat, Assadarat *
G
Gunatilaka, Dolvara
K
Kethom, Wasutum
DOI:10.1504/IJICS.2026.150538delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Web servers play a crucial role in web technology. Insufficient protection can lead to serious risks, such as sensitive data exposure. To reduce risk of successful attacks, regular web server configuration audits are conducted. However, manual auditing is often tedious and error-prone, as it requires running commands to check configurations. To enhance this process, we introduce CASA, an automated audit tool designed for four widely used web servers: Nginx, Apache HTTP, Apache Tomcat, and Microsoft IIS. CASA evaluates configurations against industry standard CIS benchmarks, identifies non-compliant settings, and generates HTML audit reports. Our analysis shows that CASA significantly enhances automation in security auditing. We validate its effectiveness by comparing results with manual audits and analysing default and publicly available configurations from GitHub. The findings indicate low compliance with security benchmarks, with less than half of configurations meeting recommended standards, exposing critical risks in unmodified deployments.
Keywords:
automatic audit
web server audit
CIS benchmarks
audit tool
security analysis

Journal

I
International Journal of Information and Computer Security
IF:
0.6
Papers:
18
Citations:
0

Organization

M
mahidol university
Scholars:
2.3W
Papers: 1.5W
Citations: 19