VLDB 2026 Research / reviewers in the wild / expert
Amani S. Ibrahim
dblp:05/10279
· DBLP profile ↗
24ranked-venue papers
5as first author
9since 2021 · last 2022
0000-0001-8747-1419ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 17 · 1 first-author · 9 since 2021Security and privacy · 3 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | RCM-extractor: an automated NLP-based approach for extracting a semi formal representation model from natural language requirements
Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
Autom. Softw. Eng. | 5 |
| 2021 | SRCM: A Semi Formal Requirements Representation Model Enabling System Visualisation and Quality CheckingabstractSRCM: A semi formal requirements representation model enabling system visualisation and quality checking Mohamed Osama, Aya Zaki-Ismail, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
MODELSWARD | 5 |
| 2021 | RCM: Requirement Capturing Model for Automated Requirements FormalisationabstractMost existing automated requirements formalisation techniques require system engineers to (re)write their requirements using a set of predefined requirement templates with a fixed structure and known semantics to simplify the formalisation process. However, these techniques require understanding and memorising requirement templates, which are usually fixed format, limit requirements captured, and do not allow capture of more diverse requirements. To address these limitations, we need a reference model that captures key requirement details regardless of their structure, format or order. Then, using NLP techniques we can transform textual requirements into the reference model. Finally, using a suite of transformation rules we can then convert these requirements into formal notations. In this paper, we introduce the first and key step in this process, a Requirement Capturing Model (RCM) - as a reference model - to model the key elements of a system requirement regardless of their format, or order. We evaluated the robustness of the RCM model compared to 15 existing requirements representation approaches and a benchmark of 162 requirements. Our evaluation shows that RCM breakdowns support a wider range of requirements formats compared to the existing approaches. We also implemented a suite of transformation rules that transforms RCM-based requirements into temporal logic(s). In the future, we will develop NLP-based RCM extraction technique to provide end-to-end solution. Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
MODELSWARD | 5 |
| 2021 | RCM-Extractor: Automated Extraction of a Semi Formal Representation Model from Natural Language RequirementsabstractRCM-Extractor: Automated Extraction of a Semi Formal Representation Model from Natural Language Requirements Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
MODELSWARD | 5 |
| 2021 | DBRG: Description-Based Non-Quality Requirements GeneratorabstractRequirements quality checking is a key process in requirements engineering. For complex and large scale systems, it is recommended to use automated requirements quality checking tools because of the size and complexity of requirements. However, such tools are typically evaluated on a small set of manually curated requirements. This limitation affects the comprehensiveness and reliability of the evaluation and leaves several possible quality issues undetected. In this paper, we de-scribe a novel quality-checking-oriented synthesised requirements generator. We provide an input description language so that several quality checking issues and scenarios can be defined. The generator utilises an input dictionary of nouns and verb frames, and generates requirements sentences complying to a user-defined description of a quality affected requirement. Mohamed Osama, Aya Zaki-Ismail, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
RE | 5 |
| 2021 | Enhancing NL Requirements Formalisation Using a Quality Checking ModelabstractThe formalisation of natural language (NL) requirements is a challenging problem because NL is inherently vague and imprecise. Existing formalisation approaches only support requirements adhering to specific boilerplates or templates, and are affected by the requirements quality issues. Several quality models are developed to assess the quality of NL requirements. However, they do not focus on the quality issues affecting the formalisability of requirements. Such issues can greatly compromise the operation of complex systems and even lead to catastrophic consequences or loss of life (in case of critical systems). In this paper, we propose a requirements quality checking approach utilising natural language processing (NLP) analysis. The approach assesses the quality of the requirements against a quality model that we developed to enhance the formalisability of NL requirements. We evaluate the effectiveness of our approach by comparing the formalisation efficiency of a recent automatic formalisation technique before and after utilising our approach. The results show an increase of approximately 15% in the F-measure (from 83.8% to 98%). Mohamed Osama, Aya Zaki-Ismail, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
RE | 5 |
| 2021 | ARF: Automatic Requirements Formalisation ToolabstractFormal verification techniques enable the detection of complex quality issues within system specifications. However, the majority of system requirements are usually specified in natural language (NL). Manual formalisation of NL requirements is an error-prone and labour-intensive process requiring strong mathematical expertise, and can be infeasible for large numbers of requirements. Existing automatic formalisation techniques usually support heavily constrained natural language relying on requirement boilerplates or templates. In this paper, we introduce ARF: Automatic Requirements Formalisation Tool. ARF can automatically transform free-format natural language requirements into temporal logic based formal notations. This is achieved through two steps: 1) extraction of key requirement attributes into an intermediate representation (RCM: Requirement Capturing Model), and 2) transformation rules that convert requirements from the RCM format to formal notations. Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
RE | 5 |
| 2021 | CORG: A Component-Oriented Synthetic Textual Requirements Generator
Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
REFSQ | 5 |
| 2021 | Requirements Formality Levels Analysis and Transformation of Formal Notations into Semi-formal and Informal Notations (S)abstractIt is pivotal to have well-specified requirements to eliminate errors at an early stage of the system development life cycle.Some quality standards recommend the use of formal methods -mandate requirements to be expressed in formal notations -to detect errors.However, formal notations are not suitable for non-experts and may not be understood by all the stakeholder.To fix this, bidirectional transformations among requirement representation levels are required to maintain traceability and facilitate the communication of requirements among all the involved parties.This paper reflects on the different formality levels of requirements specifications including: informal, semi-formal, and formal notations.In addition, an automated multi-layer transformation approach is proposed to enable bi-directional transformation among requirements levels. Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
SEKE | 5 |
| 2020 | Score-Based Automatic Detection and Resolution of Syntactic Ambiguity in Natural Language RequirementsabstractThe quality of a delivered product relies heavily upon the quality of its requirements. Across many disciplines and domains, system and software requirements are mostly specified in natural language (NL). However, natural language is inherently ambiguous and inconsistent. Such intrinsic challenges can lead to misinterpretations and errors that propagate to the subsequent phases of the system development. Pattern-based natural language processing (NLP) techniques have been proposed to detect the ambiguity in requirements specifications. However, such approaches typically address specific cases or patterns and lack the versatility essential to detecting different cases and forms of ambiguity. In this paper, we propose an efficient and versatile automatic syntactic ambiguity detection technique for NL requirements. The proposed technique relies on filtering the possible scored interpretations of a given sentence obtained via Stanford CoreNLP library. In addition, it provides feedback to the user with the possible correct interpretations to resolve the ambiguity. Our approach incorporates four filtering pipelines on the input NL-requirements working in conjunction with the CoreNLP library to provide the most likely possible correct interpretations of a requirement. We evaluated our approach on a suite of datasets of 126 requirements and achieved 65% precision and 99% recall on average. Mohamed Osama, Aya Zaki-Ismail, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ICSME | 5 |
| 2015 | Improving Tenants' Trust in SaaS Applications Using Dynamic Security MonitorsabstractIt is almost impossible to prove that a given software system achieves an absolute security level. This becomes more complicated when addressing multi-tenant cloud-based SaaS applications. Developing practical security properties and metrics to monitor, verify, and assess the behavior of such software systems is a feasible alternative to such problem. However, existing efforts focus either on verifying security properties or security metrics but not both. Moreover, they are either hard to adopt, in terms of usability, or require design-time preparation to support monitoring of such security metrics and properties which is not feasible for SaaS applications. In this paper, we introduce, to the best of our knowledge, the first unified monitoring platform that enables SaaS application tenants to specify, at run-time, security metrics and properties without design-time preparation and hence increases tenants' trust of their cloud-assets security. The platform automatically converts security metrics and properties specifications into security probes and integrates them with the target SaaS application at run-time. Probes-generated measurements are fed into an analysis component that verifies the specified properties and calculates security metrics' values using aggregation functions. This is then reported to SaaS tenants and cloud platform security engineers. We evaluated our platform expressiveness and usability, soundness, and performance overhead. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ICECCS | 3 |
| 2014 | Adaptable, model-driven security engineering for SaaS cloud-based applications
Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
Autom. Softw. Eng. | 3 |
| 2013 | Automated software architecture security risk analysis using formalized signaturesabstractReviewing software system architecture to pinpoint potential security flaws before proceeding with system development is a critical milestone in secure software development lifecycles. This includes identifying possible attacks or threat scenarios that target the system and may result in breaching of system security. Additionally we may also assess the strength of the system and its security architecture using well-known security metrics such as system attack surface, Compartmentalization, least-privilege, etc. However, existing efforts are limited to specific, predefined security properties or scenarios that are checked either manually or using limited toolsets. We introduce a new approach to support architecture security analysis using security scenarios and metrics. Our approach is based on formalizing attack scenarios and security metrics signature specification using the Object Constraint Language (OCL). Using formal signatures we analyse a target system to locate signature matches (for attack scenarios), or to take measurements (for security metrics). New scenarios and metrics can be incorporated and calculated provided that a formal signature can be specified. Our approach supports defining security metrics and scenarios at architecture, design, and code levels. We have developed a prototype software system architecture security analysis tool. To the best of our knowledge this is the first extensible architecture security risk analysis tool that supports both metric-based and scenario-based architecture security analysis. We have validated our approach by using it to capture and evaluate signatures from the NIST security principals and attack scenarios defined in the CAPEC database. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ICSE | 3 |
| 2012 | TOSSMA: A Tenant-Oriented SaaS Security Management ArchitectureabstractMulti-tenancy helps service providers to save costs, improve resource utilization, and reduce service customization and maintenance time by sharing of resources and services. On the other hand, supporting multi-tenancy adds more complexity to the shared application's required capabilities. Security is a key requirement that must be addressed when engineering new SaaS applications or when re-engineering existing applications to support multi-tenancy. Traditional security (re)engineering approaches do not fit with the multi-tenancy application model where tenants and their security requirements emerge after the system was first developed. Enabling, runtime, adaptable and tenant-oriented application security customization on single service instance is a key challenging security goal in multi-tenant application engineering. In this paper we introduce TOSSMA, a Tenant-Oriented SaaS Security Management Architecture. TOSSMA allows service providers to enable their tenants in defining, customizing and enforcing their security requirements without having to go back to application developers for maintenance or security customizations. TOSSMA supports security management for both new and existing systems. Service providers are not required to write security integration code to use a specific security platform or mechanism. In this paper, we describe details of our approach and architecture, our prototype implementation of TOSSMA, give a usage example of securing a multi-tenant SaaS, and discuss our evaluation experiments of TOSSMA. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
IEEE CLOUD | 3 |
| 2012 | Supporting Virtualization-Aware Security Solutions Using a Systematic Approach to Overcome the Semantic GapabstractA prerequisite to implementing virtualization-aware security solutions is to solve the "semantic gap" problem. Current approaches require a deep knowledge of the kernel data to manually solve the semantic gap. However, kernel data is very complex; an Operating System (OS) kernel contains thousands of data structures that have direct and indirect (pointer) relations between each other with no explicit integrity constraints. This complexity makes it impractical to use manual methods. In this paper, we present a new solution to systematically and efficiently solve the semantic gap for any OS, without any prior knowledge of the OS. We present: (i) KDD, a tool that systematically builds a precise kernel data definition for any C-based OS such as Windows and Linux. KDD generates this definition by performing points-to analysis on the kernel's source code to disambiguate the pointer relations. (ii) SVA, a security appliance that solves the semantic gap based on the generated definition, to systematically and externally map the virtual machines' physical memory and extract the runtime dynamic objects. We have implemented prototypes for KDD and SVA, and have performed different experiments to prove their effectiveness. Amani S. Ibrahim, James H. Hamlyn-Harris, John C. Grundy, Mohamed Almorsy |
IEEE CLOUD | 1 |
| 2012 | SMURF: Supporting Multi-tenancy Using Re-aspects Framework
Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ICECCS | 3 |
| 2012 | Supporting automated vulnerability analysis using formalized vulnerability signaturesabstractAdopting publicly accessible platforms such as cloud computing model to host IT systems has become a leading trend. Although this helps to minimize cost and increase availability and reachability of applications, it has serious implications on applications’ security. Hackers can easily exploit vulnerabilities in such publically accessible services. In addition to, 75% of the total reported application vulnerabilities are web application specific. Identifying such known vulnerabilities as well as newly discovered vulnerabilities is a key challenging security requirement. However, existing vulnerability analysis tools cover no more than 47% of the known vulnerabilities. We introduce a new solution that supports automated vulnerability analysis using formalized vulnerability signatures. Instead of depending on formal methods to locate vulnerability instances where analyzers have to be developed to locate specific vulnerabilities, our approach incorporates a formal vulnerability signature described using OCL. Using this formal signature, we perform program analysis of the target system to locate signature matches (i.e. signs of possible vulnerabilities). A newly–discovered vulnerability can be easily identified in a target program provided that a formal signature for it exists. We have developed a prototype static vulnerability analysis tool based on our formalized vulnerability signatures specification approach. We have validated our approach in capturing signatures of the OWSAP Top10 vulnerabilities and applied these signatures in analyzing a set of seven benchmark applications. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ASE | 3 |
| 2012 | Supporting automated software re-engineering using re-aspectsabstractSystem maintenance, including omitting an existing system feature e.g. buggy or vulnerable code, or modifying existing features, e.g. replacing them, is still very challenging. To address this problem we introduce the “re-aspect” (re-engineering aspect), inspired from traditional AOP. A re-aspect captures system modification details including signatures of entities to be updated; actions to apply including remove, modify, replace, or inject new code; and code to apply. Re-aspects locate entities to update, entities that will be impacted by the given update, and finally propagate changes on the system source code. We have applied our re-aspects technique to the security re-engineering problem and evaluated it on a set of open source .NET applications to demonstrate its usefulness. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ASE | 3 |
| 2012 | Supporting operating system kernel data disambiguation using points-to analysisabstractGeneric pointers scattered around operating system (OS) kernels make the kernel data layout ambiguous. This limits current kernel integrity checking research to covering a small fraction of kernel data. Hence, there is a great need to obtain an accurate kernel data definition that resolves generic pointer ambiguities, in order to formulate a set of constraints between structures to support precise integrity checking. In this paper, we present KDD, a new tool for systematically generating a sound kernel data definition for any C-based OS e.g. Windows and Linux, without any prior knowledge of the kernel data layout. KDD performs static points-to analysis on the kernel’s source code to infer the appropriate candidate types for generic pointers. We implemented a prototype of KDD and evaluated it to prove its scalability and effectiveness. Amani S. Ibrahim, John C. Grundy, James H. Hamlyn-Harris, Mohamed Almorsy |
ASE | 1 |
| 2012 | Operating System Kernel Data Disambiguation to Support Security Analysis
Amani S. Ibrahim, John C. Grundy, James H. Hamlyn-Harris, Mohamed Almorsy |
NSS | 1 |
| 2012 | Identifying OS Kernel Objects for Run-Time Security Analysis
Amani S. Ibrahim, James H. Hamlyn-Harris, John C. Grundy, Mohamed Almorsy |
NSS | 1 |
| 2012 | VAM-aaS: Online Cloud Services Security Vulnerability Analysis and Mitigation-as-a-Service
Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
WISE | 3 |
| 2011 | Collaboration-Based Cloud Computing Security Management FrameworkabstractAlthough the cloud computing model is considered to be a very promising internet-based computing platform, it results in a loss of security control over the cloud-hosted assets. This is due to the outsourcing of enterprise IT assets hosted on third-party cloud computing platforms. Moreover, the lack of security constraints in the Service Level Agreements between the cloud providers and consumers results in a loss of trust as well. Obtaining a security certificate such as ISO 27000 or NIST-FISMA would help cloud providers improve consumers trust in their cloud platforms' security. However, such standards are still far from covering the full complexity of the cloud computing model. We introduce a new cloud security management framework based on aligning the FISMA standard to fit with the cloud computing model, enabling cloud providers and consumers to be security certified. Our framework is based on improving collaboration between cloud providers, service providers and service consumers in managing the security of the cloud platform and the hosted services. It is built on top of a number of security standards that assist in automating the security management process. We have developed a proof of concept of our framework using. NET and deployed it on a test bed cloud platform. We evaluated the framework by managing the security of a multi-tenant SaaS application exemplar. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
IEEE CLOUD | 3 |
| 2011 | CloudSec: A security monitoring appliance for Virtual Machines in the IaaS cloud modelabstractThe Infrastructure-as-a-Service (IaaS) cloud computing model has become a compelling computing solution with a proven ability to reduce costs and improve resource efficiency. Virtualization has a key role in supporting the IaaS model. However, virtualization also makes it a target for potent rootkits because of the loss of control problem over the hosted Virtual Machines (VMs). This makes traditional in-guest security solutions, relying on operating system kernel trustworthiness, no longer an effective solution to secure the virtual infrastructure of the IaaS model. In this paper, we explore briefly the security problem of the IaaS cloud computing model, and present CloudSec, a new virtualization-aware monitoring appliance that provides active, transparent and real-time security monitoring for hosted VMs in the IaaS model. CloudSec utilizes virtual machine introspection techniques to provide fine-grained inspection of VM's physical memory without installing any monitoring code inside the VM. It actively reconstructs and monitors the dynamically changing kernel data structures instances, as a prior step to enable providing protection for kernel data structures. We have implemented a proof-of-concept prototype using VMsafe libraries on a VMware ESX platform. We have evaluated the system monitoring accuracy and the performance overhead of CloudSec. Amani S. Ibrahim, James H. Hamlyn-Harris, John C. Grundy, Mohamed Almorsy |
NSS | 1 |