V4.4.1: Verify that WebSocket over TLS (WSS) is used for all WebSocket connections.
ASVS Maturity
V4.4.2
V4.4.2: Verify that, during the initial HTTP WebSocket handshake, the Origin header field is checked against a list of origins allowed for the application.
ASVS Maturity
V4.4.3
V4.4.3: Verify that, if the application's standard session management cannot be used, dedicated tokens are being used for this, which comply with the relevant Session Management security requirements.
ASVS Maturity
V4.4.4
V4.4.4: Verify that dedicated WebSocket session management tokens are initially obtained or validated through the previously authenticated HTTPS session when transitioning an existing HTTPS session to a WebSocket channel.