A session is a period of time linked to a user, which is initiated when he/she arrives at a web application and it ends when his/her browser is closed or after a certain time of inactivity. Attackers can hijack a user's session by exploiting session management vulnerabilities by means of session fixation and cross-site request forgery attacks.
Very often, session IDs are not only identification tokens, but also authenticators. This means that upon login, users are authenticated based on their credentials (e.g., usernames/passwords or digital certificates) and issued session IDs that will effectively serve as temporary static passwords for accessing their sessions. This makes session IDs a very appealing target for attackers. In many cases, an attacker who manages to obtain a valid ID of user’s session can use it to directly enter that session – often without arising user’s suspicion. A secure session management must be implemented in the development phase of web applications because it is the responsibility of the web application, and not the underlying web server.
Threat modeling is a systematic process that is used to identify threats and vulnerabilities in software and has become popular technique to help system designers think about the security threats that their system might face.
In this paper we design the threat modeling for session’s ID threat by using SeaMonster security modeling software, and then propose a secure session management that avoids the vulnerabilities. The proposed secure session management is designed to give trust authentication between the client and the server to avoid session hijacing attack by using both: server session’s ID and MAC address of the client.Visual Studio. Net 2008 is used in implementing the proposed system
This research aims to analyse the problem of organizations in general and universities in particular, in dealing with �quality subjects� in a world where these organizations face the risks of becoming side lined and possibly vanished without looking for solutions that allow them to move in an open arena where change becomes the key to those solutions. Change here must be strategic and planning must adopts a way for organizations to develop mechanisms to manage change itself. Management leaders play a central role in achieving the principle required to chart new trends for universities in dealing with quality as a strategy that allows excellence and competition in light of the success of the processes of change. Change through reengineer
... Show MorePublic private partnership PPP is a method to procure public projects in order to achieve additional value for money in terms of efficiency and quality of services. This thesis studies the concepts of PPP, advantages and disadvantages of PPP. In addition, current Iraq infrastructure projects situations and needs, as well as, some aspects relating to the Iraq’s construction market, legal and contract systems were discussed. A financial model was carried out and applied to a real-life case study project. Finally, a survey targeted researchers; public and private- sectors were applied.
The research aims to identify and diagnose the public relations strategies in its digital online communications by the United Nations High Commissioner for Refugees (UNHCR) in managing the crisis of Iraqi refugees in Turkey. A content analysis form was designed for the digital content of the UNHCR's website dedicated to topics and issues concerning Iraqi refugees that were covered by the site, adopting a comprehensive enumeration approach. The study covered the period from 01/03/2022, to 30/06/2022. The research yielded several key findings, including the predominant use of media, advertising, and education strategies in managing the crisis of Iraqi refugees in Turkey. News and reports ranked first among the media
... Show MoreThis research seeks to study the role of proactive leadership as an essential element that helps all federations that lead the wheel of sports, including the Iraqi Handball Federation, so that it builds a correct environment that helps manage the organizational errors that the Handball Federation may fall into, and this in turn helps in early detection of errors and obstacles that may occur. It is likely that the Federation will fall into the process of managing and organizing the Iraqi Handball League, in addition to increasing the clubs’ ability to assist the Iraqi Handball Federation by being proactive so as not to make mistakes. The research community included the administrative bodies of the clubs participating in the Iraqi E
... Show MoreThe current research aims to analyze the role of participatory budgeting in improving performance, especially during crises such as the Covid-19 crisis. The research used the descriptive analytical method to reach the results by distributing 100 questionnaires to a number of employees in Iraqi joint stock companies and at multiple administrative levels. The research came to several important conclusions, the most important of which is that the bottom-up approach to budgeting produces more achievable budgets than the top-down approach, which is imposed on the company by senior management with much less employee participation. Additionally, there is a better information flow from the lower levels of the organization to the upper management
... Show MoreCommunication represents the essence of language learning. Since the unspecified evolution of conveying information, human beings have been employing the main constituents of language with short pauses. Although the punctuation marks necessitate short expressions among thought group of words in writing, human language demand for understanding how and when to pause orally. This paper presents the pause technique in the classroom. It signifies the relation between pausing and lecturing in the class and determines its sufficient time-management to interact with college learners of different specializations. The conduct study reviewed teaching pause technique in the empirical studies at Special Education and Communication Disorders of Pennsylva
... Show MoreIn this paper we will investigate some Heuristic methods to solve travelling salesman problem. The discussed methods are Minimizing Distance Method (MDM), Branch and Bound Method (BABM), Tree Type Heuristic Method (TTHM) and Greedy Method (GRM).
The weak points of MDM are manipulated in this paper. The Improved MDM (IMDM) gives better results than classical MDM, and other discussed methods, while the GRM gives best time for 5≤ n ≤500, where n is the number of visited cities.
With the proliferation of both Internet access and data traffic, recent breaches have brought into sharp focus the need for Network Intrusion Detection Systems (NIDS) to protect networks from more complex cyberattacks. To differentiate between normal network processes and possible attacks, Intrusion Detection Systems (IDS) often employ pattern recognition and data mining techniques. Network and host system intrusions, assaults, and policy violations can be automatically detected and classified by an Intrusion Detection System (IDS). Using Python Scikit-Learn the results of this study show that Machine Learning (ML) techniques like Decision Tree (DT), Naïve Bayes (NB), and K-Nearest Neighbor (KNN) can enhance the effectiveness of an Intrusi
... Show MoreNuclear medicine is important for both diagnosis and treatment. The most common treatment for diseases is radiation therapy used against cancer. The radiation intensity of the treatment is often less than its ability to cause damage, so radiation must be carefully controlled. The interactions of alpha particle with matter were studied and the stopping powers of alpha particle with ovary tissue were calculated using Beth-Bloch equation, Zeigler’s formula and SRIM Software also the range and Liner Energy Transfer (LET) and ovary thickness as well as dose and dose equivalent for this particle were calculated by using Matlab language for (0.01-200) MeV alpha energy.
In the current digitalized world, cloud computing becomes a feasible solution for the virtualization of cloud computing resources. Though cloud computing has many advantages to outsourcing an organization’s information, but the strong security is the main aspect of cloud computing. Identity authentication theft becomes a vital part of the protection of cloud computing data. In this process, the intruders violate the security protocols and perform attacks on the organizations or user’s data. The situation of cloud data disclosure leads to the cloud user feeling insecure while using the cloud platform. The different traditional cryptographic techniques are not able to stop such kinds of attacks. BB84 protocol is the first quantum cry
... Show More