Web Security Glossary

Comprehensive definitions of web security terms and concepts

Filter by Category

Search Security Terms

Content Security Policy (CSP)

Security Headers

A security standard that helps prevent cross-site scripting (XSS) attacks by allowing website owners to control which resources can be loaded and executed on their pages.

Related terms:

XSSSecurity HeadersCSP Directives

TLS (Transport Layer Security)

Transport Security

A cryptographic protocol that provides secure communication over a computer network, commonly used to secure HTTPS connections.

Related terms:

SSLHTTPSCertificateEncryption

CORS (Cross-Origin Resource Sharing)

Cross-Origin Security

A security feature that allows web pages to make requests to a different domain than the one serving the web page, while maintaining security.

Related terms:

Same-Origin PolicyPreflight RequestAccess-Control-Allow-Origin

HSTS (HTTP Strict Transport Security)

Security Headers

A web security policy mechanism that helps protect websites against protocol downgrade attacks and cookie hijacking by forcing HTTPS connections.

Related terms:

HTTPSTLSSecurity Headers

XSS (Cross-Site Scripting)

Web Vulnerabilities

A type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.

Related terms:

CSPInput ValidationOutput Encoding

CSRF (Cross-Site Request Forgery)

Web Vulnerabilities

An attack that tricks a user into performing unwanted actions on a web application in which they're currently authenticated.

Related terms:

Anti-CSRF TokenSameSite CookieOrigin Header

SPF (Sender Policy Framework)

Email Security

An email authentication method that helps prevent email spoofing by specifying which mail servers are authorized to send emails for a domain.

Related terms:

DKIMDMARCEmail Authentication

DKIM (DomainKeys Identified Mail)

Email Security

An email authentication method that uses digital signatures to verify that an email message was sent by an authorized sender.

Related terms:

SPFDMARCEmail Authentication

DMARC (Domain-based Message Authentication, Reporting and Conformance)

Email Security

An email authentication protocol that builds on SPF and DKIM to provide domain-level protection against email spoofing.

Related terms:

SPFDKIMEmail Authentication

Clickjacking

Web Vulnerabilities

A malicious technique where an attacker tricks a user into clicking on something different from what the user perceives, potentially revealing confidential information.

Related terms:

X-Frame-OptionsCSP frame-ancestorsFrame Security

Mixed Content

Transport Security

A security issue where a web page served over HTTPS contains resources (images, scripts, stylesheets) loaded over HTTP, which can compromise security.

Related terms:

HTTPSTLSSecurity Headers

Subdomain Takeover

Network Security

A vulnerability where an attacker can take control of a subdomain by exploiting misconfigured DNS records or abandoned services.

Related terms:

DNSCNAMEDomain Security
Barrion logo iconBarrion

Barrion delivers automated security scans and real-time monitoring to keep your applications secure.

Contact Us

Have questions or need assistance? Reach out to our team for support.

© 2025 Barrion - All Rights Reserved.