Preferred Language
Articles
/
ijs-12444
A Secure Session Management Based on Threat Modeling

A session is a period of time linked to a user, which is initiated when he/she arrives at a web application and it ends when his/her browser is closed or after a certain time of inactivity. Attackers can hijack a user's session by exploiting session management vulnerabilities by means of session fixation and cross-site request forgery attacks.
Very often, session IDs are not only identification tokens, but also authenticators. This means that upon login, users are authenticated based on their credentials (e.g., usernames/passwords or digital certificates) and issued session IDs that will effectively serve as temporary static passwords for accessing their sessions. This makes session IDs a very appealing target for attackers. In many cases, an attacker who manages to obtain a valid ID of user’s session can use it to directly enter that session – often without arising user’s suspicion. A secure session management must be implemented in the development phase of web applications because it is the responsibility of the web application, and not the underlying web server.
Threat modeling is a systematic process that is used to identify threats and vulnerabilities in software and has become popular technique to help system designers think about the security threats that their system might face.
In this paper we design the threat modeling for session’s ID threat by using SeaMonster security modeling software, and then propose a secure session management that avoids the vulnerabilities. The proposed secure session management is designed to give trust authentication between the client and the server to avoid session hijacing attack by using both: server session’s ID and MAC address of the client.Visual Studio. Net 2008 is used in implementing the proposed system

View Publication Preview PDF
Quick Preview PDF
Publication Date
Tue Jun 15 2021
Journal Name
Al-academy
The concept of freedom in the texts of Yashar Kamal play "The play (The Plate) as a model": عامر صباح نوري المرزوك

This research is concerned with studying (the concept of freedom in the texts of Yaşar Kamal the play), as the Turkish playwright (Kamal Yasar) is one of the contemporary playwrights who have been interested in and criticize society, and perhaps the concept of freedom in his texts took a different form, through his ability to renew and present his attempts to create A theatrical form different from his earlier writers in dealing with the life of the peasants and the oppression that went through them, as the researcher identified the problem of his research with the following question: What is the concept of freedom in the texts of Yashar Kamal? The research aims to define the concept of freedom in the texts of Yashar Kamal of the play,

... Show More
Crossref
View Publication Preview PDF
Publication Date
Fri Apr 01 2016
Journal Name
Journal Of Economics And Administrative Sciences
The Committed of the Auditors for the Procedures of Environmental audits (An Exploratory Study of a sample of auditing offices in Iraq)

At the beginning of the nineties increased responsibility of the auditor to the community as the demand for auditing the environmental performance for the economic units in addition to audit the financial performance. With the aim of preserving the environment and reducing the damagse as  aresult of the negative effects of the activities of these units.

The researh deal with two sides the first one identifies the theoretical framework of the concept of environmental audits, requirements, methods, types of procedures, and duties of  the auditor in conducting  environmental audits. It also deals with the concept of the enviro

... Show More
Crossref
View Publication Preview PDF
Publication Date
Wed May 25 2022
Journal Name
Iraqi Journal Of Science
Reducing the Purification Period of Congo Red Dye Solution By Using Co-Exposure to Ultraviolet and Green Laser as A Photocatalysit Source

      Attempts were made over the years to achieve economic and easy methods for water purification. This could well save time, cost, and earn a good process quality for many countries. This study aims to enhance the purification process parameters for Congo red dye polluted water  and introduce a developed methodology with an impact on many associated parameters such as the time for water purification process.  The research  proposes  a method to achieve this time reduction by mixing gold nanoparticle (AuNPs) (prepared by chemical reduction method) with Titanium dioxide nanoparticles (TiO2NPs) (prepared by sol-gel techniques). The resulting mixture is incorporated into PVA host to synthesize a hard disk used as a purification d

... Show More
Scopus (3)
Scopus Crossref
View Publication Preview PDF
Publication Date
Fri Aug 28 2020
Journal Name
Iraqi Journal Of Science
A Comparison Between Different Susceptibility Test Methods to Evaluate the Antibacterial Activity of Olibanum and Alum Against the "Red Complex" Periodontal Pathogens

Testing the sensitivity of periodontal pathogens requires the selection of an easier and more reliable method to be used with such anaerobic bacteria that need a long period of time for growth. Natural materials are a new era of antibacterial agents to control periodontal infections. The aims of the current study were to test the antibacterial activity of two natural agents, namely olibanum and alum, against three types of red complex periodontal pathogens and compare the application of agar diffusion and microdilution methods for testing the susceptibility. Gingival crevicular fluid from pockets with chronic infections was sampled as a source for the three types of bacteria, Porphyromonas gingivalis, Tannerella forsythia

... Show More
Scopus (3)
Crossref (1)
Scopus Crossref
View Publication Preview PDF
Publication Date
Sun Oct 01 2023
Journal Name
Baghdad Science Journal
Synthesis, characterization, molecular docking, ADMET prediction, and anti-inflammatory activity of some Schiff bases derived from salicylaldehyde as a potential cyclooxygenase inhibitor

A series of Schiff base-bearing salicylaldehyde moiety compounds (1-4) had been designed, synthesized, subjected to insilico ADMET prediction, molecular docking, characterization by FT-IR, and CHNS analysis techniques, and finally to their Anti-inflammatory profile using cyclooxygenase fluorescence inhibitor screening assay methods along with standard drugs, celecoxib, and diclofenac. The ADMET studies were used to predict which compounds would be suitable for oral administration, as well as absorption sites, bioavailability, TPSA, and drug likeness. According to the results of ADME data, all of the produced chemicals can be absorbed through the GIT and have passed Lipinski’s rule of five. Through molecular docking with PyRx 0.8, these

... Show More
Scopus (4)
Crossref (2)
Scopus Crossref
View Publication Preview PDF
Publication Date
Mon Aug 01 2022
Journal Name
Engineering, Technology & Applied Science Research
Castellated Beams with Fiber-Reinforced Lightweight Concrete Deck Slab as a Modified Choice for Composite Steel-Concrete Beams Affected by Harmonic Load

The behavior investigation of castellated beams with fiber-reinforced lightweight concrete deck slab as a modified choice for composite steel-concrete beams affected by harmonic load is presented in this study. The experimental program involved six fixed-supported castellated beams of 2140mm size. Three types of concrete were included: Normal Weight Concrete (NWC), Lightweight Aggregate Concrete (LWAC), and Lightweight Fiber-Reinforced Aggregate Concrete (LWACF). The specimens were divided into two groups: the first comprised three specimens tested under harmonic load effect of 30Hz operation frequency for 3 days, then the residual strength was determined through static load application. The second group included three specimens ide

... Show More
Crossref (8)
Crossref
Publication Date
Thu Nov 03 2022
Journal Name
Sensors
A Novel Application of Deep Learning (Convolutional Neural Network) for Traumatic Spinal Cord Injury Classification Using Automatically Learned Features of EMG Signal

In this study, a traumatic spinal cord injury (TSCI) classification system is proposed using a convolutional neural network (CNN) technique with automatically learned features from electromyography (EMG) signals for a non-human primate (NHP) model. A comparison between the proposed classification system and a classical classification method (k-nearest neighbors, kNN) is also presented. Developing such an NHP model with a suitable assessment tool (i.e., classifier) is a crucial step in detecting the effect of TSCI using EMG, which is expected to be essential in the evaluation of the efficacy of new TSCI treatments. Intramuscular EMG data were collected from an agonist/antagonist tail muscle pair for the pre- and post-spinal cord lesi

... Show More
Scopus (2)
Crossref (3)
Scopus Clarivate Crossref
View Publication
Publication Date
Thu Dec 01 2022
Journal Name
Environmental Nanotechnology Monitoring & Management
Scopus (14)
Crossref (1)
Scopus Crossref
Publication Date
Tue Nov 19 2024
Journal Name
Journal Of Baghdad College Of Dentistry
A Comparative Study of Clinicopathological and Immunohistochemical Expression of CD1a, RANK and RANKL in Langerhans Cell Histiocytosis of Jaw and Skull Lesions

Background: Langerhans' cell histiocytosis (LCH) is a group of conditions affecting the reticuloendothelial system. It includes Letterer-Siwe disease, Hand-Schuller-Christian disease and eosinophilic granuloma and most often presents in childhood. Materials and methods: Twenty-five cases of LCH were diagnosed histologically and confirmed by CD1a antibody and assessed immunohistochemically using anti-RANKL and anti-RANK antibodies to evaluate osteoclastogenic mechanism. Results: Regarding jaw cases, there was a significant correlation between CD1a and RANK (P=0.016). While in the skull, highly significant correlation existed between RANK and RANKL (p=0.001). Among the sites, there was no statistically significant difference found for each

... Show More
Crossref
View Publication Preview PDF
Publication Date
Fri Mar 01 2019
Journal Name
Journal Of Accounting And Financial Studies ( Jafs )
The Relationship Between Competitive Intelligence and Entrepreneurial Performance By Centralizing Strategic Vigilance: Field study of a sample of National colleges in Iraq

The aim of this study is to highlight the relationship between competitive intelligence and Entrepreneurial Performance by centralizing the strategic vigilance of a sample of civil faculties in Baghdad. The sample of the study was targeted at 10 Iraqi civil colleges, which consisted of (133) members of the faculty council of the faculties, the search data was collected using the questionnaire form as the main research tool. The results showed that the correlation and influence of competitive intelligence and strategic vigilance in the Entrepreneurial Performance, as well as the role of strategic vigilance as an intermediate variable between competitive intelligence and Entrepreneurial Performance.

Crossref (1)
Crossref
View Publication Preview PDF