Research, technical design notes & publications.
In-depth architectural analysis of boundary controls, NIST access models, session security mechanics, and peer-reviewed computational publications.
Threat Models & Boundary Control Specifications
Deep technical analyses exploring how formal models translate into defensible web application runtimes.
Threat Model: Kestrel Relief Field Ingress & Beneficiary Privacy
Summary & Attack Context
Threat modeling of an emergency relief platform handling aid allocation across 12 simulated zones. Examined volunteer mobile endpoints, donor webhooks, and administrative records.
Database-level column redaction and cryptographically verified webhook signatures mitigate both insider curiosity and webhook forgery.
Architectural Verification Points
- Identified Spoofing risks on payment callbacks: enforced HMAC-SHA256 signature validation with replay timestamp checks on Stripe webhooks.
- Addressed Information Disclosure of vulnerable civilians: separated public fundraising registries from beneficiary records, enforcing UNHCR field redaction rules.
- Mitigated Tampering risks in volunteer inventory tracking: all state mutations require authenticated server actions with parameterized Drizzle ORM queries.
Hierarchical RBAC Design Under NIST (ANSI INCITS 359)
Summary & Attack Context
Design note on structuring an 8-tier role hierarchy without privilege creep or brittle ad-hoc conditional logic across frontend and backend boundaries.
Hierarchical inheritance must be monotonic: rights descend strictly from higher roles, while mutations require explicit permission checks rather than string-matching role names.
Architectural Verification Points
- Modeled core NIST RBAC entities: Users, Roles, Permissions, and Session Constraints.
- Created an explicit permission matrix enforced via Next.js Server Components and API middleware before page hydration.
- Prevented horizontal privilege escalation by validating record ownership at the query compilation layer rather than relying on URL parameters.
Mitigating Token Theft: Pragmatic Defense Against Session Hijacking
Summary & Attack Context
Technical evaluation of session token storage in single-page and server-rendered web applications, comparing localStorage against HTTP-only SameSite cookies.
HTTP-only cookies reduce token theft via XSS by blocking JavaScript access, but do not eliminate XSS. Complete defense requires CSP, input sanitization, and anti-CSRF measures.
Architectural Verification Points
- Tokens stored in localStorage are trivial to exfiltrate with a single injected script tag. HTTP-only cookies prevent document.cookie reading.
- However, XSS execution can still issue authenticated requests from within the victim's browser session. HTTP-only cookies reduce token exfiltration, not XSS itself.
- Implemented defense-in-depth: strict CSP headers to prevent script injection, 15-minute JWT expiration with server-side rotation, and SameSite=Strict cookies to stop CSRF.
Security Terminal Sandbox
Test simulated system audits, inspect live header grades, and evaluate STRIDE model invariants directly in the browser.
TMI Security Core v2.4.0 (Islamabad, PK)
Type help to list available security commands or click a chip below.
Peer-Reviewed Publications (2023)
Quantitative dataset validation, regression modeling, and statistical evaluation published in high-impact medical and scientific journals.
Epidemiological Evaluation and Antimicrobial Resistance Dynamics in Clinical Cohorts
Oxford University Press / Infectious Diseases Society of America (IDSA) • Clin Infect Dis. 2023. DOI: 10.1093/cid/ciad (Peer-Reviewed)
Contributed to data cleaning, computational dataset validation, and statistical analysis of large clinical cohorts evaluating infectious disease dynamics.
Comparative Antimicrobial Regimen Profiling and Clinical Outcome Modeling
Taylor & Francis • Expert Rev Anti Infect Ther. 2023. DOI: 10.1080/14787210.2023 (Peer-Reviewed)
Synthesized clinical trial datasets and evaluated treatment protocols through quantitative data modeling and regression analyses.