Hisham M. Haddad

dblp:h/HishamHaddad · also Hisham Al-Haddad, Hisham Haddad · DBLP profile ↗
← Back
23ranked-venue papers
1as first author
4since 2021 · last 2023
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 11 · 3 since 2021Software engineering, systems software and programming languages · 8 · 2 since 2021Security and privacy · 6 · 1 since 2021Databases, data management, data science and information retrieval · 4 · 1 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-authorComputer networks · 2
YearPublicationVenuePosition
2023 Blockchain Technology in Higher Education Ecosystem: Unraveling the Good, Bad, and Ugly
Sharaban Tahora, Bilash Saha, Hossain Shahriar, Hisham M. Haddad
COMPSAC5
2022 Predicting Mortality Rate based on Comprehensive Features of Intensive Care Unit Patients
abstract
Predictive analytics is gaining momentum in health-care since the adoption of electronic health record (EHR) system in hospitals. In particular, machine learning models are built using the critical care EHR data and the information provided during the ICU admissions to predict the mortality of patients admitted in ICU. As per the MIMIC-IV dataset, the survival rate of patients admitted in ICU is found to be 89.76%. This paper proposes a hybrid prediction technique that uses Random Forest and XGBoost for predicting the mortality rate. The proposed techniques performed well in predicting mortality rate despite the class imbalance problem of the dataset. The experiments conducted on MIMIC-IV dataset yields prediction accuracy of 89.72%.
Jagan Moahan Reddy Danda, Kumar Priyansh, Hossain Shahriar, Hisham M. Haddad, Alfredo Cuzzocrea
COMPSAC4
2021 Bayesian Hyperparameter Optimization for Deep Neural Network-Based Network Intrusion Detection
abstract
Traditional network intrusion detection approaches encounter feasibility and sustainability issues to combat modern, sophisticated, and unpredictable security attacks. Deep neural networks (DNN) have been successfully applied for intrusion detection problems. The optimal use of DNN-based classifiers requires careful tuning of the hyper-parameters. Manually tuning the hyperparameters is tedious, time-consuming, and computationally expensive. Hence, there is a need for an automatic technique to find optimal hyperparameters for the best use of DNN in intrusion detection. This paper proposes a novel Bayesian optimization-based framework for the automatic optimization of hyperparameters, ensuring the best DNN architecture. We evaluated the performance of the proposed framework on NSL-KDD, a benchmark dataset for network intrusion detection. The experimental results show the framework’s effectiveness as the resultant DNN architecture demonstrates significantly higher intrusion detection performance than the random search optimization-based approach in terms of accuracy, precision, recall, and f1-score.
Mohammad Masum, Hossain Shahriar, Hisham M. Haddad, Md. Jobair Hossain Faruk, Maria Valero, Md Abdullah Khan, Mohammad Ashiqur Rahman, Muhaiminul I. Adnan, Alfredo Cuzzocrea, Fan Wu 0013
IEEE BigData3
2021 Assessing HIPAA Compliance of Open Source Electronic Health Record Applications
abstract
Electronic health record (EHR) applications are digital versions of paper-based patient health information. EHR applications are increasingly being adopted in many countries. They have resulted in improved quality in healthcare, convenient access to histories of patient medication and clinic visits, easier follow up of patient treatment plans, and precise medical decision-making process. The goal of this paper is to identify HIPAA technical requirements, evaluate two open source EHR applications (OpenEMR and OpenClinic) for security vulnerabilities using two open-source scanner tools (RIPS and PHP VulnHunter), and map the identified vulnerabilities to HIPAA technical requirements.
Hossain Shahriar, Hisham M. Haddad, Maryam Farhadi
Int. J. Inf. Secur. Priv.2
2020 r-LSTM: Time Series Forecasting for COVID-19 Confirmed Cases with LSTMbased Framework
abstract
The coronavirus disease 2019 (COVID-19) caused a pandemic outbreak with affecting 213 nations worldwide. Global policymakers are imposing many measures to slow and reduce the rapid growth of the infections. On the other hand, the healthcare system is encountering significant challenges for a massive number of COVID-19 confirmed or suspected individuals seeking treatment. Therefore, estimating the number of confirmed cases is necessary to provide valuable insights into the growth of the outbreak and facilitate policy making process. In this study, we apply ARIMA models as well as LSTM-based recurrent neural network to forecast the daily cumulative confirmed cases. The LSTM architecture generates more precise forecasting by leveraging both short- and long-term temporal dependencies from the pandemic time series data. Due to the stochastic nature in optimization and random initialization of weights in neural network, the LSTM based model produce less reproducible outcome. In this paper, we propose a reproducible-LSTM (r-LSTM) framework that produces a reproducible and robust results leveraging z-score outlier detection method. We performed five round of nested cross validation to show the consistency in evaluating model performance. The experimental results demonstrate that r-LSTM outperformed the ARIMA model producing minimum MAPE, RMSE, and MAE.
Mohammad Masum, Hossain Shahriar, Hisham M. Haddad, Md. Shafiul Alam
IEEE BigData3
2020 Actionable Knowledge Extraction Framework for COVID-19
abstract
In response to the COVID-19 pandemic, the White House and a coalition of leading research groups have prepared the COVID-19 Open Research Dataset (CORD-19) containing over 51,000 scholarly articles, including over 40,000 with full text, about COVID-19, SARS-CoV-2, and related coronaviruses. Medical professional including physicians frequently seek answers to specific questions to improve guidelines and decisions. The huge resource of medical literature is important sources to generate new insights that can help medical communities to provide relevant knowledge and overall fight against the infectious disease. There are ongoing attempts to develop intelligent systems to automatically extract relevant knowledge from many unstructured documents. In this paper, we propose an efficient question answering framework based on automatically analyzing thousands of articles to generate both long text answers (sections/ paragraphs) in response to the questions that are posed by medical communities. In the process of developing the framework, we explored natural language processing techniques like query expansion, data preprocessing, and vector space models early. We show the initial results of an example query answering for the incubation period.
Mohammad Masum, Hossain Shahriar, Hisham M. Haddad, Sheikh Iqbal Ahamed, Sweta Sneha, Mohammad Ashiqur Rahman, Alfredo Cuzzocrea
IEEE BigData3
2020 Analysis of Sampling Techniques Towards Epileptic Seizure Detection from Imbalanced Dataset
abstract
Epileptic Seizure is a neurological disorder that occurs due to abnormal activities of brain neurons. Epilepsy can affect patients' health and can lead to life-threatening emergencies. Predicting epilepsy before the initiation of the onset is highly effective to avoid the seizure by medication. machine learning algorithms have been implemented in classifying epilepsy from Electroencephalograms (EEG) data. Machine learning algorithms experience reduced performance when classes are imbalanced. The imbalance class problem can be handled by different sampling techniques including oversampling minority class, undersampling majority class, and combined of both. In this paper, both traditional and state-of-the-art sampling techniques have been experimented and evaluated for their capability of improving the imbalance ratio. A Deep Neural Network (DNN) based framework is also presented in this paper. The classification performance has been investigated by applying several ML approaches with the effect of different balancing ratio. We performed experiments on Epileptic Seizure Recognition dataset. The experimental results show that the sampling techniques improve the imbalance class ratio as well as the classification performance.
Mohammad Masum, Hossain Shahriar, Hisham M. Haddad
COMPSAC3
2020 Malicious URL Detection Using Supervised Machine Learning Techniques
abstract
short-paper Share on Malicious URL Detection Using Supervised Machine Learning Techniques Authors: Vara Vundavalli Kennesaw State University Kennesaw State UniversityView Profile , Farhat Barsha Military Institute of Science and Technology Military Institute of Science and TechnologyView Profile , Mohammad Masum KSU KSUView Profile , Hossain Shahriar Kennesaw State University Kennesaw State UniversityView Profile , Hisham Haddad KSU KSUView Profile Authors Info & Claims SIN 2020: 13th International Conference on Security of Information and NetworksNovember 2020 Article No.: 21Pages 1–6https://doi.org/10.1145/3433174.3433592Published:01 February 2021Publication History 2citation237DownloadsMetricsTotal Citations2Total Downloads237Last 12 Months139Last 6 weeks19 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my Alerts New Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access
Vara Vundavalli, Farhat Lamia Barsha, Mohammad Masum, Hossain Shahriar, Hisham M. Haddad
SIN5
2019 Supervised and Unsupervised-Based Analytics of Intensive Care Unit Data
abstract
Resources and personnel availability in Intensive Care Units (ICUs) of hospitals are scarce and challenging to manage, particularly certain group of patients are more likely to be dead than alive after released from ICUs. There has been availability of ICU data, opening the door for performing analytical approach to uncover the trends and patterns for better policy and resource allocation decision towards improved outcome of the patients. In this paper, we explored MIMIC III dataset and applied supervised and unsupervised learning approaches to shed some lights on the complex underlying relationships between the patient's Length of Stay (LOS) and a number of attributes available from data. Our results indicate that neural network-based approaches perform the best for predicting the mortality outcome compared to other supervised and unsupervised approaches.
Rehnuma Afrin, Hisham M. Haddad, Hossain Shahriar
COMPSAC (2)2
2019 Compliance Checking of Open Source EHR Applications for HIPAA and ONC Security and Privacy Requirements
abstract
Electronic Health Record (EHR) applications are digital versions of paper-based patient's health information. They are increasingly adopted to improved quality in healthcare, such as convenient access to histories of patient medication and clinic visits, easier follow up of patient treatment plans, and precise medical decision-making process. EHR applications are guided by measures of the Health Insurance Portability and Accountability Act (HIPAA) to ensure confidentiality, integrity, and availability. Furthermore, Office of the National Coordinator (ONC) for Health Information Technology (HIT) certification criteria for usability of EHRs. A compliance checking approach attempts to identify whether or not an adopted EHR application meets the security and privacy criteria. There is no study in the literature to understand whether traditional static code analysis-based vulnerability discovered can assist in compliance checking of regulatory requirements of HIPAA and ONC. This paper attempts to address this issue. We identify security and privacy requirements for HIPAA technical requirements, and identify a subset of ONC criteria related to security and privacy, and then evaluate EHR applications for security vulnerabilities. Finally propose mitigation of security issues towards better compliance and to help practitioners reuse open source tools towards certification compliance.
Maryam Farhadi, Hisham M. Haddad, Hossain Shahriar
COMPSAC (1)2
2018 Static Analysis of HIPPA Security Requirements in Electronic Health Record Applications
abstract
Electronic Health Records (EHRs) are digital versions of paper-based patient's health information. EHR applications are increasingly being adopted in many countries. They have resulted in improved quality in healthcare, convenient access to histories of patient medication and clinic visits, easier follow up of patient treatment plans, and precise medical decision-making process. EHR applications are guided by measures of the Health Insurance Portability and Accountability Act (HIPAA) to ensure confidentiality, integrity, and availability. However, there have been reported breaches of Protected Health Identifier (PHI) data stored by EHR applications. In many reported breaches, improper use of EHRs has resulted in disclosure of patient's PHI data. Inefficient application design threatens the integrity of EHRs, which leads to fraud and endangering patient's health. The goal of this paper is to identify HIPAA technical requirements, evaluate an open source EHR application (OpenEMR) for security vulnerabilities using an open-source scanner tool (RIPS), and map identified vulnerabilities to HIPAA technical requirements.
Maryam Farhadi, Hisham M. Haddad, Hossain Shahriar
COMPSAC (2)2
2017 An Iris-Based Authentication Framework to Prevent Presentation Attacks
abstract
Attacks on authentication services are major security concerns. Password-based authentication systems can be compromised using known techniques, such as brute force and dictionary-based attacks. Biometric-based authentication systems are becoming the preferred choice to replace password-based authentication systems. Among several variations of biometrics (e.g., face, eye, fingerprint), iris-based authentication is commonly used in various applications. In iris-based authentication systems, iris images from legitimate users are captured and certain features are extracted to be used for matching during the authentication process. Literature works suggest that iris-based authentication systems can be subject to presentation attacks where an attacker obtains printed copy of the victim's eye image and displays it in front of an authentication system to gain unauthorized access. Such attacks can be performed by displaying static eye images on mobile devices or ipads (known as screen attacks). Since human iris features so not changed, once the iris image is compromised, it is hard to avoid this type of attack. To address this challenge, this paper proposes a framework for iris code generation by considering the changes of the area between the pupil and the sclera due to light density level. The proposed approach relies on capturing iris images using near infrared light. We train HaarCascade and LBP classifiers to capture the area between the pupil and the cornea. The image of iris is then stored in the database. This approach also generates a QR code from the iris. The code acts as a password and the user is required to provide it during authentication. A prototype is built using OpenCV platform tool. The prototype has been tested using samples obtained from publicly available iris database. The initial results show that the proposed approach has lower false positive and false negative rates.
Hossain Shahriar, Hisham M. Haddad, Mahbubul Islam
COMPSAC (2)2
2017 Ontology to Profile User Models with Disabilities
Brunil Dalila Romero-Mariño, Vanesa Espín, María José Rodríguez-Fórtiz, María Visitación Hurtado, Luis Ramos, Hisham M. Haddad
MEDI6
2016 Internet-of-Things Based Smart Resource Management System: A Case Study Intelligent Chair System
abstract
Internet of Things (IoT) involves connecting physical objects to the Internet, to provide opportunities to build smart systems or applications by leveraging Radio-Frequency Identification (RFID), Near Field Communication (NFC), Wireless Sensor Network (WSN), and universal mobile accessibility advanced technologies. In this paper, we propose an Internet-of-Things Based Smart Resource Management System. To further prove the concept, we implement a case study of Intelligent Chair system, where the chairs are connected to the internet. To be specific, the Intelligent Chair system includes an assembled Arduino system, which is responsible for scanning user ID, obtaining chair occupancy status, and then sending that information to the cloud server. The collected data stored on the cloud can be retrieved at anytime anywhere, and can be displayed on an Android application with authorized user. Additionally, the analyzed data can be used in various commercial/educational systems such as students attendance checking, tutor time tracking management, and dynamic ticketing system. Finally, the energy consumption of the Intelligent Chair system is tested and analyzed in this work.
Selena He, Amir Atabekov, Hisham M. Haddad
ICCCN3
2016 A Signature-Based Intrusion Detection System for Web Applications based on Genetic Algorithm
abstract
Web application attacks are an extreme threat to the world's information technology infrastructure. A web application is generally defined as a client-server software application where the client uses a user interface within a web browser. Most users are familiar with web application attacks. For instance, a user may have received a link in an email that led the user to a malicious website. The most widely accepted solution to this threat is to deploy an Intrusion Detection System (IDS). Such a system currently relies on signatures of the predefined set of events matching with attacks. Issues still arise as all possible attack signatures may not be defined before deploying an IDS. Attack events may not fit with the pre-defined signatures. Thus, there is a need to detect new types of attacks with a mutated signature based detection approach. Most traditional literature works describe signature based IDSs for application layer attacks, but several works mention that not all attacks can be detected. It is well known that many security threats can be related to software or application development and design or implementation flaws. Given that fact, this work expands a new method for signature based web application layer attack detection. We apply a genetic algorithm to analyze web server and database logs and the log entries. The work contributes to the development of a mutated signature detection framework. The initial results show that the suggested approach can detect specific application layer attacks such as Cross-Site Scripting, SQL Injection and Remote File Inclusion attacks.
Robert Bronte, Hossain Shahriar, Hisham M. Haddad
SIN3
2015 Client-Side Detection of Clickjacking Attacks
abstract
Clickjacking attacks are emerging threat for web application users where click operations performed by victims lead to security breaches such as compromising webcams and posting unintended messages. Effective client-side defense technique could prevent the possible victims. This paper presents a client side approach to detect clickjacking attacks. The authors' approach examines web page requests and responses; the proposed approach is designed to detect advanced attack types such as cursorjacking, double click, and history object-based attacks. They evaluate the proposed approach with a set of legitimate and malicious websites. The results indicate that our approach has low false positive and false negative rates. The overhead imposed by the proposed approach is negligible.
Hossain Shahriar, Hisham M. Haddad
Int. J. Inf. Secur. Priv.2
2014 Content Provider Leakage Vulnerability Detection in Android Applications
abstract
Although much research effort has focused on Android malware detection, very little attention has been given to implementation-level vulnerabilities. This paper focuses on Content Provider Leakage vulnerability that can be exploited by viewing or editing sensitive data through malware. We present a new technique for detecting content provider leakage vulnerability. We propose Kullback-Leibler Divergence (KLD) as a measure to detect the content provider leakage vulnerability. In particular, our contribution includes the development of a set of elements and mapping the elements to programming principles for secure implementation of content provider classes. These elements are captured from the implementation to form the initial population set. The population set is used to measure the divergence of a newly implemented application with content provider to identify potential vulnerabilities. We also apply a back-off smoothing technique to compute the KLD value. We implement a java prototype tool to evaluate a set of content provider implementations to show the effectiveness of the proposed approach. The initial results show that by choosing an appropriate threshold level, KLD is an effective method for detecting content provider leakage vulnerability.
Hossain Shahriar, Hisham M. Haddad
SIN2
2013 Minimum-sized Positive Influential Node Set selection for social networks: Considering both positive and negative influences
abstract
Social networks are important mediums for spreading information, ideas, and influences among individuals. Most of existing research work focus on understanding the characteristics of social networks, investigating spreading information through the “word of mouth” effect of social networks, or exploring social influences among individuals and groups. However, most of existing work ignore negative influences among individuals or groups. Motivated by alleviating social problems, such as drinking, smoking, gambling, and influence spreading problems (e.g., promoting new products), we take both positive and negative influences into consideration and propose a new optimization problem, named the Minimumsized Positive Influential Node Set (MPINS) selection problem, to identify the minimum set of influential nodes, such that every node in the network can be positively influenced by these selected nodes no less than a threshold θ. Our contributions are threefold. First, we propose a new optimization problem MPINS, which is investigated under the independent cascade model considering both positive and negative influences. Moreover, we claim that MPIMS is NP-hard. Subsequently, we present a greedy approximation algorithm to address the MPINS selection problem. Finally, to validate the proposed greedy algorithm, extensive simulations are conducted on random Graphs representing small and large size networks.
Selena He, Shouling Ji, Xiaojing Liao, Hisham M. Haddad, Raheem A. Beyah
IPCCC4
2013 ProClick: a framework for testing clickjacking attacks in web applications
abstract
Clickjacking attacks are an emerging threat on the web. An attacker application presents a User Interface (UI) element of a target application out of context, such as hiding sensitive UI element by making it transparent to the end user. The user is tricked to click on the hidden element out of context. These attacks can cause severe damages such as compromising webcams and posting unintended messages. A large number of websites are still vulnerable to clickjacking and have no minimal protection at the server side (e.g., frame busting, X-Frame-Options header). Further, client-side defense techniques have been ineffective to deal with sophisticated clickjacking attack types and suffer from performance issues. This paper presents a proxy-level framework, ProClick, to detect clickjacking attacks. ProClick examines the content of requests and response pages at the proxy level to detect clickjacking attacks. We evaluate the proposed approach with a set of legitimate and malicious websites. The results indicate that our approach has low false positive and false negative rates. The overhead imposed by the proposed approach is also very negligible.
Hossain Shahriar, Vamshee Krishna Devendran, Hisham M. Haddad
SIN3
2009 A Methodological Tool for Asset Identification in Web Applications: Security Risk Assessment
abstract
Security risk assessment in Web Engineering is an emerging discipline, where security is given a special attention, allowing software engineers to develop high quality and secure Web based applications. A preliminary study revealed that asset identification (and evaluation) is an essential phase in risk assessment practices. This phase represents a degree of complexity and is the primary activity in the assessment process. This work focuses on asset identification and contributes to security risk assessment, which is essential part of software security. Specifically, the research goal is to design a methodological tool (instrument) for asset identification in web applications for the purpose of risk assessment. The proposed tool helps identify assets with security risks in Web applications. The tool involves direct observations and survey questionnaires as data collection techniques used for this work. The research methodology is based on qualitative and quantitative analysis of a case study that focused on Web based application for student opinion survey coordination (EOE) developed in Simoacuten Boliacutevar University, Venezuela. The data analysis required the use of cross case analysis supported by the software application MAXQDA2007, which helps identify assets according to categories, such as environment, software, hardware, information and networks. Under this work, students, faculty, staff, and software developers at Simoacuten Boliacutevar University have participated in this study.
Brunil Dalila Romero-Mariño, Hisham M. Haddad, Jorge E. Molero A.
ICSEA2
2000 Instrumentation: a multi-science integrated sequence
abstract
A new method of teaching traditional concepts of CS1-CS2 is discussed. The new method uses real-time data acquisition, teaming, and interdisciplinary courseware to illustrate basic computer science concepts. We present a series of experiments and the corresponding software engineering elements. These experiments have proved to be motivating for a broad spectrum of students.
Herbert Tesser, Hisham M. Haddad, Gary Anderson
SIGCSE2
1997 Megaprogramming education
abstract
In the computer science field, educators face several obstacles when attempting to introduce rigorous software engineering concepts and practices into the curriculum. This paper addresses the issue of software engineering education and the role of megaprogramming in introductory courses for high school and college students. We highlight the need for, and the initial effort in megaprogramming education. We provide a brief description of developed materials and a proposed approach to integrate megaprogramming into high school computer science curriculum.
Hisham M. Haddad, Herbert Tesser, Steven P. Wartik
SIGCSE1
1994 A practical approach for teaching reuse in a data structures course using Ada (abstract)
abstract
No abstract available.
Akhtar Lodgher, Hisham M. Haddad
SIGCSE2