This paper presents a study on the evolution of the use of HTTPS by the official websites of all (308) Portuguese municipalities. One year ago, we found a bad situation regarding HTTPS usage: only a small percentage of websites adopted HTTPS correctly. The results were communicated to the relevant entities so actions could be taken. After one year, we performed a new assessment to check for evolution. This pape...
This paper presents a study on the adoption of HTTPS in the official websites of all (308) Portuguese municipalities. Automated and, whenever needed, manual analysis were used to investigate its entry pages. Specifically, the pages were checked for the existence of an HTTPS site; the correctness of the certificates and their certification chain; coherence between contents of the HTTP and HTTPS sites; redirectio...
Cyberattacks are performed against all organizations including Higher Education Institutions (HEIs). When these attacks are successful, they can affect the regular operation of these institutions and may cause the leak of essential or sensitive data that can be misused or become inaccessible. Therefore, the adoption of current security services is important for devices and services exposed to the Internet that ...
Dissertação de mestrado em Engenharia de Redes e Serviços Telemáticos, Diretório de Informática; The Internet emerged in the late sixties in a scenario marked by the race of world hegemony between USA and USSR. Besides military applications, it was also initially used by researchers, academics, and college students, enabling file transfer between hosts. After the nineties the Internet reached the general public...
Tese de mestrado, Segurança Informática, Universidade de Lisboa, Faculdade de Ciências, 2022; Web applications are the building blocks of many services, from social networks to banks. Network security threats have remained a permanent concern since the advent of data communication. Not withstanding, security breaches are still a serious problem since web applications incorporate both company information and pri...
Submitted by Rosemary Magalhães (rosemary.magalhaes@ucsal.br) on 2020-04-15T17:24:53Z No. of bitstreams: 1 DOCUMENTÁRIOADALGISASALES.htm: 368380 bytes, checksum: 18764368390424fcda9ea5866d9eaca1 (MD5); Approved for entry into archive by Rosemary Magalhães (rosemary.magalhaes@ucsal.br) on 2020-04-15T17:25:49Z (GMT) No. of bitstreams: 1 DOCUMENTÁRIOADALGISASALES.htm: 368380 bytes, checksum: 18764368390424fcda9ea5...
Secure (HTTPS) in the entry pages of the official websites of all (308) Portuguese municipalities. This is relevant because such websites are typically used to provide transactional services to citizens, and citizens need to trust that websites are authentic and that confidentiality and integrity of the information exchanged is assured in the communication process. Automated and, whenever needed, manual analyse...
Currently, web and mobile-based systems exchange information with other services, mostly through APIs that extend the functionality and enable multipart interoperable information exchange. Most of this is accomplished through the usage of RESTful APIs and data exchange that is conducted using JSON over the HTTP or HTTPS protocol. In the case of the exchange requires some specific security requirements, SSL/TLS ...
The services supporting the websites, both public and private entities, may support security protocols such as HTTPS or DNSSEC. Public and private entities have a responsibility to ensure the security of their online platforms. Entities in the public domain such as city councils provide their services through their websites. However, each city council has its systems, configurations, and IT teams, and this mean...