WebSocket
V4.4.1
Verify that WebSocket over TLS (WSS) is used for all WebSocket connections.
Required for Level 1, 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 102, 117, 383, 94
V4.4.2
Verify that, during the initial HTTP WebSocket handshake, the Origin header field is checked against a list of origins allowed for the application.
Required for Level 2 and 3
Related CAPEC™ Requirements
V4.4.3
Verify that, if the application's standard session management cannot be used, dedicated tokens are being used for this, which comply with the relevant Session Management security requirements.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 21, 383, 49, 633
V4.4.4
Verify that dedicated WebSocket session management tokens are initially obtained or validated through the previously authenticated HTTPS session when transitioning an existing HTTPS session to a WebSocket channel.
Required for Level 2 and 3
Related CAPEC™ Requirements
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.