Italian Web Security Study (IWSS): Passive Security Measurement Dataset
收藏资源简介:
This dataset and codebase accompany the Italian Web Security Study (IWSS), a large-scale passive measurement study of the security configuration of the Italian web. It covers 10,022 `.it` domains sampled from the entire `.it` slice of the Tranco top-1M list (list date 2026-07-08), yielding 10,020 completed scans. Measurements were collected exclusively through standard, browser-equivalent HTTP, HTTPS and DNS requests, no exploitation, active vulnerability scanning, or brute-force techniques were used. The dataset covers HTTP security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy), Content-Security-Policy directive analysis, cookie security attributes (Secure/HttpOnly/SameSite), TLS configuration, DNS email authentication (SPF/DMARC/DKIM), well-known resources (robots.txt, sitemap.xml, security.txt), and CORS configuration. Domain identifiers in the published export are pseudonymized (unsalted SHA-256 of the domain name), not anonymized in the strict sense, since `.it` domain names are public information but the hash is dictionary-invertible. See the included `manifest.json` for the exact pseudonymization method. This record accompanies the paper "Measuring the Security Configuration of the Italian Web: A Large-Scale Passive Measurement Study" (see Related works). Interactive summary: https://f-hack.com/analisi-sicurezza-web-italiano-2026



