Uniform Resource Locator Protection Scheme for the Mitigation of Man-In-The-Middle Stripping Attacks Duaa Sameer Zhraw, Mohammed Abdulridha Hussain, Zaid Ameen Abduljabbar, Vincent Omollo Nyangaresi, Ali Hasan Ali, et al. Mesopotamian Journal of Big Data, 2025 Man-in-the-Middle (MITM) attacks reduce Hypertext Transfer Protocol Secure (HTTPS) to Hypertext Transfer Protocol (HTTP), compromising network communications to potential exploitation. Attackers exploit application-layer vulnerabilities, and the attack often occurs on LAN. This study addresses the problem by introducing a Uniform Resource Locator (URL) protection mechanism that combines encryption with secure key exchange. A browser built with Python and PyQt5 encrypts URLs before transmission. The router decrypts, processes, re-encrypts, and returns data securely. The Diffie–Hellman algorithm generates a new session key for each connection, and the Advanced Encryption Standard with Galois Counter Mode (AES-GCM) technique to encrypt. The system was tested in a VMware host-only environment under four scenarios: normal use, active attacker, system-only, and active attacker with the system enabled. Packet capture and timing analysis evaluated security and performance. The scheme achieved a 100% prevention rate against HTTPS downgrades. Intercepted traffic appeared as unreadable ciphertext. Average execution time increased from 0.05 seconds to 0.11 seconds due to encryption, but it did not affect stability. This research improves application-layer security independently and offers a concrete defense against MITM stripping attacks. In conclusion, the proposed methodology provides a pragmatic and effective strategy for protecting URL traffic in vulnerable local network environments.
Implementing Blockchain for Enhancing Security and Authentication in Iraqi E-Government Services Huda Kamil Abdali, Mohammed Abdulridha Hussain, Zaid Ameen Abduljabbar, Vincent Omollo Nyangaresi Engineering Technology and Applied Science Research, 2024 E-Government is used to provide various services to citizens via an online portal and is currently available in many countries. Current e-government technology is supported by an extensive, centrally controlled database and a collection of applications linked to it through web interfaces. However, e-government depends too much on centralization. E-government services store sensitive data about citizens, making them particularly vulnerable to cyberattacks, data breaches, and access control. Therefore, alternative techniques should be developed to protect sensitive data and ensure secure storage in e-government platforms. This study proposes a safe and distributed electronic system for e-government based on blockchain technology to protect sensitive data from breaches. This system uses advanced encryption methods, including Lightweight Encryption Device (LED) and Elliptic-Curve Cryptography (ECC), to protect transmitted data. The proposed system employs a two-layer encryption approach to secure user data. The first layer utilizes the LED algorithm with a randomly generated key, and the second employs the ECC algorithm with a public key obtained from the blockchain server to enhance user data security and privacy. The proposed system allows data to be disseminated across many networks, retrieves and synchronizes data in case of unauthorized changes, and restores them to their original form. Experimental results showed that the proposed system takes an average of 0.05 seconds to complete the login process for five successful login attempts, confirming the effectiveness of the proposed approach in the execution of login procedures. The effectiveness of this system in resisting different attack types was verified through formal and informal security analyses and simulations based on the Scyther tool.
Secure and Fast Remote Application-Based Authentication Dragonfly Using an LED Algorithm in Smart Buildings Batool Mohammed Radhi, Mohammed Abdulridha Hussain, Zaid Ameen Abduljabbar, Vincent Omollo Nyangaresi 6th International Conference on Artificial Intelligence in Information and Communication Icaiic 2024, 2024 The proliferation of the internet of things (IoT) has led to the emergence of a wide range of intelligent devices, creating a broad domain with significant security concerns. These concerns impose a high level of security; unfortunately, IoT devices usually have limited resources in terms of little memory, low computing power, and a short battery life. Therefore, IoT application developers must use lightweight cryptographic tools to achieve a trade-off between performance and security. The storage and high computation capacity of cloud computing is often exploited to manage the vast amount of data produced by such gadgets. Some methods still suffer from attacks, and others cannot achieve low complexity. We propose a secure and low-complexity system for smart buildings in transferring data between the local server, the cloud, and users authorized by the owner. The LED encryption algorithm, which is lightweight and requires limited resources and less energy, was used to create a mobile application system characterized by confidentiality, authentication, and privacy. For further security, the owner's biometrics were used and derived as the key to decrypt data from the cloud. We have leveraged Dragonfly authentication technology to transfer data from the local server to the users. The owner can add authorized persons in the cloud database and local server to enjoy using the application. Moreover, we successfully balance security complexity and performance in our work. As a result, we achieve good results with a computation cost of 0.281 s and a communication cost of 1472 $bit$.
Comprehensive Challenges to E-government in Iraq Huda Kamil Abdali, Mohammed Abdulridha Hussain, Zaid Ameen Abduljabbar, Vincent Omollo Nyangaresi, Abdulla J. Y. Aldarwish Lecture Notes in Networks and Systems, 2024
An Effective Approach to Detect and Prevent ARP Spoofing Attacks on WLAN Hiba Nasser, Mohammed Hussain Iraqi Journal for Electrical and Electronic Engineering, 2023 Address Resolution Protocol (ARP) is used to resolve a host’s MAC address, given its IP address. ARP is stateless, as there is no authentication when exchanging a MAC address between the hosts. Hacking tactics using ARP spoofing are constantly being abused differently; many previous studies have prevented such attacks. However, prevention requires modification of the underlying network protocol or additional expensive equipment, so applying these methods to the existing network can be challenging. In this paper, we examine the limitations of previous research in preventing ARP spoofing. In addition, we propose a defense mechanism that does not require network protocol changes or expensive equipment. Before sending or receiving a packet to or from any device on the network, our method checks the MAC and IP addresses to ensure they are correct. It protects users from ARP spoofing. The findings demonstrate that the proposed method is secure, efficient, and very efficient against various threat scenarios. It also makes authentication safe and easy and ensures data and users’ privacy, integrity, and anonymity through strong encryption techniques.
Content-Based Image Retrieval using Hard Voting Ensemble Method of Inception, Xception, and Mobilenet Architectures Meqdam Mohammed, Zakariya Oraibi, Mohammed Hussain Iraqi Journal for Electrical and Electronic Engineering, 2023 Advancements in internet accessibility and the affordability of digital picture sensors have led to the proliferation of extensive image databases utilized across a multitude of applications. Addressing the semantic gap between low-level attributes and human visual perception has become pivotal in refining Content-Based Image Retrieval (CBIR) methodologies, especially within this context. As this field is intensely researched, numerous efficient algorithms for CBIR systems have surfaced, precipitating significant progress in the artificial intelligence field. In this study, we propose employing a hard voting ensemble approach on features derived from three robust deep learning architectures: Inception, Exception, and Mobilenet. This is aimed at bridging the divide between low-level image features and human visual perception. The Euclidean method is adopted to determine the similarity metric between the query image and the features database. The outcome was a noticeable improvement in image retrieval accuracy. We applied our approach to a practical dataset named CBIR 50, which encompasses categories such as mobile phones, cars, cameras, and cats. The effectiveness of our method was thereby validated. Our approach outshone existing CBIR algorithms with superior accuracy (ACC), precision (PREC), recall (REC), and F1-score (F1-S), proving to be a noteworthy addition to the field of CBIR. Our proposed methodology could be potentially extended to various other sectors, including medical imaging and surveillance systems, where image retrieval accuracy is of paramount importance.
Content based Image Retrieval using Fine-tuned Deep Features with Transfer Learning Meqdam A. Mohammed, Zakariya A. Oraibi, Mohammed Abdulridha Hussain Proceeding 2023 2nd International Conference on Computer System Information Technology and Electrical Engineering Sustainable Development for Smart Innovation System Cosite 2023, 2023
Uniform Resource Locator Protection Scheme for the Mitigation of Man-In-The-Middle Stripping Attacks DS Zhraw, MA Hussain, ZA Abduljabbar, VO Nyangaresi, AH Ali, ... Mesopotamian Journal of Big Data 2025, 329-349 , 2025 2025
Vehicular ad hoc networks verification scheme based on bilinear pairings and networks reverse fuzzy extraction ZA Abduljabbar, VO Nyangaresi, AA Ahmed, J Ma, MA Al Sibahee, ... Scientific Reports 15 (1), 29225 , 2025 2025 Citations: 7
Chronological Review of MITM Attacks: Challenges, Solutions and Recommendations DS Zhraw, MA Hussain, ZA Abduljabbar, VO Nyangaresi, AJY Aldarwish Computer Science On-line Conference, 202-220 , 2025 2025 Citations: 3
Implementing Blockchain for Enhancing Security and Authentication in Iraqi E-Government Services HK Abdali, MA Hussain, ZA Abduljabbar, VO Nyangaresi Engineering, Technology & Applied Science Research 14 (6), 18222-18233 , 2024 2024 Citations: 9
A Review on IoTs Applications and Security Threats via Data Transfer over Networks BM Radhi, MA Hussain, ZA Abduljabbar, VO Nyangaresi, AJY Aldarwish Computer Science On-line Conference, 562-579 , 2024 2024 Citations: 3
Comprehensive Challenges to E-government in Iraq HK Abdali, MA Hussain, ZA Abduljabbar, VO Nyangaresi, AJY Aldarwish Computer Science On-line Conference, 639-657 , 2024 2024 Citations: 7
Secure and Fast Remote Application–Based Authentication Dragonfly Using an LED Algorithm in Smart Buildings BM Radhi, MA Hussain, ZA Abduljabbar, VO Nyangaresi 2024 International Conference on Artificial Intelligence in Information and … , 2024 2024 Citations: 6
Secure content based image retrieval system using deep learning MA Mohammed, MA Hussain, ZA Oraibi, ZA Abduljabbar, VO Nyangaresi Journal of Basrah Research Sciences 49 (2), 94-111 , 2023 2023 Citations: 17
Smart Building Security using ESP32 based AES One Bio-key and Owner's Biometrics Encryption Technology BM Radhi, MA Hussain Journal of Basrah Research Sciences 49 (2), 30-47 , 2023 2023 Citations: 5
content-based image retrieval using hard voting ensemble method of inception, Xception, and Mobilenet architectures MA Mohammed, ZA Oraibi, MA Hussain Iraqi Journal for Electrical and Electronic Engineering 19 (2), 145-157 , 2023 2023 Citations: 2
Content based Image Retrieval using Fine-tuned Deep Features with Transfer Learning MA Mohammed, ZA Oraibi, MA Hussain 2023 2nd International Conference on Computer System, Information Technology … , 2023 2023 Citations: 5
Elliptic curve cryptography-based scheme for secure signaling and data exchanges in precision agriculture ZA Abduljabbar, VO Nyangaresi, HM Jasim, J Ma, MA Hussain, ... Sustainability 15 (13), 10264 , 2023 2023 Citations: 50
An effective approach to detect and prevent ARP spoofing attacks on WLAN HI Nasser, MA Hussain Iraqi Journal for Electrical and Electronic Engineering 19 (2), 8-17 , 2023 2023 Citations: 5
Lightweight Integrity Preserving Scheme for Secure Data Exchange in Cloud-Based IoT Systems ZA Hussien, HA Abdulmalik, MA Hussain, VO Nyangaresi, J Ma, ... Applied Sciences 13 (2), 691 , 2023 2023 Citations: 57
Defending a wireless LAN against ARP spoofing attacks using a Raspberry Pi HI Nasser, MA Hussain Journal of Basrah Research Sciences 48 (2), 123-135 , 2022 2022 Citations: 2
Provably throttling SQLI using an enciphering query and secure matching MA Hussain, ZA Hussien, ZA Abduljabbar, J Ma, MA Al Sibahee, ... Egyptian Informatics Journal 23 (4), 145-162 , 2022 2022 Citations: 27
Forward and Backward Key Secrecy VO Nyangaresi, ZA Abduljabbar, KAA Mutlaq, MA Hussain Human-Centric Smart Computing: Proceedings of ICHCSC 2022, 15 , 2022 2022
Forward and Backward Key Secrecy Preservation Scheme for Medical Internet of Things VO Nyangaresi, ZA Abduljabbar, KAA Mutlaq, MA Hussain, ZA Hussien Human-Centric Smart Computing: Proceedings of ICHCSC 2022, 15-29 , 2022 2022 Citations: 7
Provably curb man-in-the-middle attack-based ARP spoofing in a local network HI Nasser, MA Hussain Bulletin of Electrical Engineering and Informatics 11 (4), 2280-2291 , 2022 2022 Citations: 30
Provably Secure Session Key Agreement Protocol for Unmanned Aerial Vehicles Packet Exchanges VO Nyangaresi, A Ibrahim, ZA Abduljabbar, MA Hussain, MA Al Sibahee, ... 2021 International Conference on Electrical, Computer and Energy … , 2021 2021 Citations: 34
MOST CITED SCHOLAR PUBLICATIONS
Lightweight Integrity Preserving Scheme for Secure Data Exchange in Cloud-Based IoT Systems ZA Hussien, HA Abdulmalik, MA Hussain, VO Nyangaresi, J Ma, ... Applied Sciences 13 (2), 691 , 2023 2023 Citations: 57
Elliptic curve cryptography-based scheme for secure signaling and data exchanges in precision agriculture ZA Abduljabbar, VO Nyangaresi, HM Jasim, J Ma, MA Hussain, ... Sustainability 15 (13), 10264 , 2023 2023 Citations: 50
Efficient encrypted image retrieval in IoT-cloud with multi-user authentication MA Al Sibahee, S Lu, ZA Abduljabbar, A Ibrahim, ZA Hussien, KAA Mutlaq, ... International Journal of Distributed Sensor Networks 14 (2), 1550147718761814 , 2018 2018 Citations: 42
DNS Protection against Spoofing and Poisoning Attacks MA Hussain, H Jin, ZA Hussien, ZA Abduljabbar, SH Abbdal, A Ibrahim 2016 3rd International Conference on Information Science and Control … , 2016 2016 Citations: 39
Lightweight Secure Message Delivery for E2E S2S Communication in the IoT-Cloud System MA Al Sibahee, S Lu, ZA Abduljabbar, X Liu, HB Abdalla, MA Hussain, ... IEEE Access 8, 218331-218347 , 2020 2020 Citations: 36
LEACH-T: LEACH Clustering Protocol Based on Three Layers MA Al Sibahee, S Lu, MZ Masoud, ZA Hussien, MA Hussain, ... 2016 International Conference on Network and Information Systems for … , 2016 2016 Citations: 35
Provably Secure Session Key Agreement Protocol for Unmanned Aerial Vehicles Packet Exchanges VO Nyangaresi, A Ibrahim, ZA Abduljabbar, MA Hussain, MA Al Sibahee, ... 2021 International Conference on Electrical, Computer and Energy … , 2021 2021 Citations: 34
Provably curb man-in-the-middle attack-based ARP spoofing in a local network HI Nasser, MA Hussain Bulletin of Electrical Engineering and Informatics 11 (4), 2280-2291 , 2022 2022 Citations: 30
The Best Performance Evaluation of Encryption Algorithms to Reduce Power Consumption in WSN MA Al Sibahee, S Lu, ZA Hussien, MA Hussain, KAA Mutlaq, ... 2017 International Conference on Computing Intelligence and Information … , 2017 2017 Citations: 30
Privacy-preserving image retrieval in IoT-cloud ZA Abduljabbar, H Jin, A Ibrahim, ZA Hussien, MA Hussain, SH Abbdal, ... 2016 IEEE Trustcom/BigDataSE/ISPA, 799-806 , 2016 2016 Citations: 29
Secure and efficient e-health scheme based on the Internet of Things ZA Hussien, H Jin, ZA Abduljabbar, MA Hussain, AA Yassin, SH Abbdal, ... 2016 IEEE International Conference on Signal Processing, Communications and … , 2016 2016 Citations: 29
Provably throttling SQLI using an enciphering query and secure matching MA Hussain, ZA Hussien, ZA Abduljabbar, J Ma, MA Al Sibahee, ... Egyptian Informatics Journal 23 (4), 145-162 , 2022 2022 Citations: 27
SEPIM: Secure and Efficient Private Image Matching ZA Abduljabbar, H Jin, A Ibrahim, ZA Hussien, MA Hussain, SH Abbdal, ... Applied Sciences 6 (8), 213 , 2016 2016 Citations: 27
EEIRI: Efficient Encrypted Image Retrieval in IoT-Cloud ZA Abduljabbar, A Ibrahim, MA Hussain, ZA Hussien, MA Al Sibahee, ... KSII Transactions on Internet and Information Systems (TIIS) 13 (11), 5692-5716 , 2019 2019 Citations: 23
Secure biometric image retrieval in IoT-cloud ZA Abduljabbar, H Jin, A Ibrahim, ZA Hussien, MA Hussain, SH Abbdal, ... 2016 IEEE International Conference on Signal Processing, Communications and … , 2016 2016 Citations: 23
Server side method to detect and prevent stored XSS attack IF Khazal, MA Hussain Iraqi Journal for Electrical and Electronic Engineering 17 (2), 58-65 , 2021 2021 Citations: 20
Public auditing for secure data storage in cloud through a third party auditor using modern ciphertext ZA Hussien, H Jin, ZA Abduljabbar, AA Yassin, MA Hussain, SH Abbdal, ... 2015 11th International Conference on Information Assurance and Security … , 2015 2015 Citations: 18
Secure content based image retrieval system using deep learning MA Mohammed, MA Hussain, ZA Oraibi, ZA Abduljabbar, VO Nyangaresi Journal of Basrah Research Sciences 49 (2), 94-111 , 2023 2023 Citations: 17
Securing audio transmission based on encoding and steganography EW Abood, ZA Abduljabbar, MA Al Sibahee, MA Hussain, ZA Hussien Indonesian Journal of Electrical Engineering and Computer Science 22 (3 … , 2021 2021 Citations: 17
Scheme for ensuring data security on cloud data storage in a semi-trusted third party auditor ZA Hussien, H Jin, ZA Abduljabbar, MA Hussain, SH Abbdal, D Zou 2015 4th International Conference on Computer Science and Network Technology … , 2015 2015 Citations: 13