VLDB 2026 Research / reviewers in the wild / expert
Mohamed Almorsy
dblp:08/10279 · also Mohamed Abdelrazek 0001, Mohamed Almorsy Abdelrazek
· DBLP profile ↗
89ranked-venue papers
11as first author
45since 2021 · last 2025
0000-0003-3812-9785ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 49 · 6 first-author · 25 since 2021Systems, architecture and hardware · 9 · 6 since 2021Human-computer interaction and ubiquitous computing · 9 · 2 first-authorArtificial intelligence and machine learning · 8 · 7 since 2021Security and privacy · 6 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 1 since 2021Computer networks · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Safeguarding LLM-Applications: Specify or Train?abstractLarge Language Models (LLMs) are powerful tools used in several applications such as conversational AI, and code generation. However, significant robustness concerns arise with LLMs in production, such as hallucinations, prompt injection attacks, harmful content generation, and challenges in maintaining accurate domain-specific content moderation. Guardrails aim to mitigate these challenges by aligning LLM outputs with desired behaviors without modifying the underlying models. Nvidia NeMo Guardrails, for instance, rely on specifying acceptable/unacceptable behaviours. However, it is challenging to predict and address potential issues of LLMs in advance to create these guardrails. Also, manual updates from software engineers are often required to maintain and refine these guardrails. We introduce LLM-Guards, specialised machine learning (ML) models trained to function as protective guards. Additionally, we present an automation pipeline for training and continual fine-tuning of these guards using reinforcement learning from human feedback (RLHF). We evaluated several small LLMs, including Llama-3, Mistral, and Gemma, as LLM-Guards for challenges such as moderation and detecting off-topic queries, and compared their performance against NeMo Guardrails. The proposed Llama-3 LLM-Guard outperformed NeMo Guardrails in detecting offtopic queries, achieving an accuracy of 98.7% compared to 81%. Furthermore, the LLM-Guard detected 97.86% of harmful queries” surpassing NeMo Guardrails by 19.86%. Hala Abdelkader, Mohamed Almorsy, Sankhya Singh, Irini Logothetis, Priya Rani, Rajesh Vasa, Jean-Guy Schneider |
CAIN | 2 |
| 2025 | uBSaaS: A Unified Blockchain Service as a Service Framework for Streamlined Blockchain Services Integration
Huynh Thanh Thien Pham, Frank Jiang 0001, Lei Pan 0002, Alessio Bonti, Mohamed Almorsy |
ENASE | 5 |
| 2025 | An empirical study of automatic wildlife detection using drone-derived imagery and object detection
Tan Vuong, Miao Chang, Manas Palaparthi, Lachlan Howell, Alessio Bonti, Mohamed Almorsy, Duc Thanh Nguyen |
Multim. Tools Appl. | 6 |
| 2024 | POSTER: Addressing the Privacy by Use Challenges in Verifiable Credential based Digital WalletsabstractThe concept of Verifiable Credentials (VC) has emerged as a viable alternative to federated identity systems and can offer greater levels of control and ownership to users over their Digital Identity. However, the inability of users to make optimal decisions in relation to the use of VC results in privacy risks. To address this gap in VC technology, we present game-theoretic models for optimising the privacy of users and simultaneously ensuring minimum disclosure of PII in line with privacy safeguards around CDR and GDPR expectations around anonymity and unlinkability and demonstrate these properties through a digital credential wallet (DCW). The developed technology will deliver a novel DCW which embeds decision-making ability to quantify, benchmark and recommend the optimal usage of credentials that are held within the DCW. Jongkil Jeong, Lu-Xing Yang, Robin Doss, Praveen Gauravaram, Zoe Wang, Mohamed Almorsy, Ashish Nanda, Keerthivasan Viswanathan |
AsiaCCS | 6 |
| 2024 | ML-On-Rails: Safeguarding Machine Learning Models in Software Systems - A Case StudyabstractMachine learning (ML), especially with the emergence of large language models (LLMs), has significantly transformed various industries. However, the transition from ML model prototyping to production use within software systems presents several challenges. These challenges primarily revolve around ensuring safety, security, and transparency, subsequently influencing the overall robustness and trustworthiness of ML models. In this paper, we introduce ML-On-Rails, a protocol designed to safeguard ML models, establish a well-defined endpoint interface for different ML tasks, and clear communication between ML providers and ML consumers (software engineers). ML-On-Rails enhances the robustness of ML models via incorporating detection capabilities to identify unique challenges specific to production ML. We evaluated the ML-On-Rails protocol through a real-world case study of the MoveReminder application. Through this evaluation, we emphasize the importance of safeguarding ML models in production. Hala Abdelkader, Mohamed Almorsy, Scott Barnett, Jean-Guy Schneider, Priya Rani, Rajesh Vasa |
CAIN | 2 |
| 2024 | Seven Failure Points When Engineering a Retrieval Augmented Generation SystemabstractSoftware engineers are increasingly adding semantic search capabilities to applications using a strategy known as Retrieval Augmented Generation (RAG). A RAG system involves finding documents that semantically match a query and then passing the documents to a large language model (LLM) such as ChatGPT to extract the right answer using an LLM. RAG systems aim to: a) reduce the problem of hallucinated responses from LLMs, b) link sources/references to generated responses, and c) remove the need for annotating documents with meta-data. However, RAG systems suffer from limitations inherent to information retrieval systems and from reliance on LLMs. In this paper, we present an experience report on the failure points of RAG systems from three case studies from separate domains: research, education, and biomedical. We share the lessons learned and present 7 failure points to consider when designing a RAG system. The two key takeaways arising from our work are: 1) validation of a RAG system is only feasible during operation, and 2) the robustness of a RAG system evolves rather than designed in at the start. We conclude with a list of potential research directions on RAG systems for the software engineering community. Scott Barnett, Stefanus Kurniawan, Srikanth Thudumu, Zach Brannelly, Mohamed Almorsy |
CAIN | 5 |
| 2024 | LLMs for Test Input Generation for Semantic ApplicationsabstractLarge language models (LLMs) enable state-of-the-art semantic capabilities to be added to software systems such as semantic search of unstructured documents and text generation. However, these models are computationally expensive. At scale, the cost of serving thousands of users increases massively affecting also user experience. To address this problem, semantic caches are used to check for answers to similar queries (that may have been phrased differently) without hitting the LLM service. Due to the nature of these semantic cache techniques that rely on query embeddings, there is a high chance of errors impacting user confidence in the system. Adopting semantic cache techniques usually requires testing the effectiveness of a semantic cache (accurate cache hits and misses) which requires a labelled test set of similar queries and responses which is often unavailable. In this paper, we present VaryGen, an approach for using LLMs for test input generation that produces similar questions from unstructured text documents. Our novel approach uses the reasoning capabilities of LLMs to 1) adapt queries to the domain, 2) synthesise subtle variations to queries, and 3) evaluate the synthesised test dataset. We evaluated our approach in the domain of a student question and answer system by qualitatively analysing 100 generated queries and result pairs, and conducting an empirical case study with an open source semantic cache. Our results show that query pairs satisfy human expectations of similarity and our generated data demonstrates failure cases of a semantic cache. Additionally, we also evaluate our approach on Qasper dataset. This work is an important first step into test input generation for semantic applications and presents considerations for practitioners when calibrating a semantic cache. Zafaryab Rasool, Scott Barnett, David Willie, Stefanus Kurniawan, Sherwin Balugo, Srikanth Thudumu, Mohamed Almorsy |
CAIN | 7 |
| 2024 | 6DVF: A Framework for the Development and Evaluation of Mobile Data Visualisationsabstract6DVF: A Framework for the Development and Evaluation of Mobile Data Visualisations Yasmeen Anjeer Alshehhi, Khlood Ahmad, Mohamed Almorsy, Alessio Bonti |
ENASE | 3 |
| 2024 | An Analysis of Privacy Issues and Policies of eHealth AppsabstractAn Analysis of Privacy Issues and Policies of eHealth Apps Omar Haggag, John C. Grundy, Mohamed Almorsy |
ENASE | 3 |
| 2024 | Towards Robust ML-enabled Software Systems: Detecting Out-of-Distribution data using Gini CoefficientsabstractMachine learning (ML) models have become essential components in software systems across several domains, such as autonomous driving, healthcare, and finance. The robustness of these ML models is crucial for maintaining the software systems performance and reliability. A significant challenge arises when these systems encounter out-of-distribution (OOD) data, examples that differ from the training data distribution. OOD data can cause a degradation of the software systems performance. Therefore, an effective OOD detection mechanism is essential for maintaining software system performance and robustness. Such a mechanism should identify and reject OOD inputs and alert software engineers. Current OOD detection methods rely on hyperparameters tuned with in-distribution and OOD data. However, defining the OOD data that the system will encounter in production is often infeasible. Further, the performance of these methods degrades with OOD data that has similar characteristics to the in-distribution data. In this paper, we propose a novel OOD detection method using the Gini coefficient. Our method does not require prior knowledge of OOD data or hyperparameter tuning. On common benchmark datasets, we show that our method outperforms the existing maximum softmax probability (MSP) baseline. For a model trained on the MNIST dataset, we improve the OOD detection rate by 4% on the CIFAR10 dataset and by more than 50% for the EMNIST dataset. Hala Abdelkader, Jean-Guy Schneider, Mohamed Almorsy, Priya Rani, Rajesh Vasa |
ASE | 3 |
| 2024 | Deep cross-domain transfer for emotion recognition via joint learningabstractAbstract Deep learning has been applied to achieve significant progress in emotion recognition from multimedia data. Despite such substantial progress, existing approaches are hindered by insufficient training data, leading to weak generalisation under mismatched conditions. To address these challenges, we propose a learning strategy which jointly transfers emotional knowledge learnt from rich datasets to source-poor datasets. Our method is also able to learn cross-domain features, leading to improved recognition performance. To demonstrate the robustness of the proposed learning strategy, we conducted extensive experiments on several benchmark datasets including eNTERFACE, SAVEE, EMODB, and RAVDESS. Experimental results show that the proposed method surpassed existing transfer learning schemes by a significant margin. Dung Nguyen 0001, Duc Thanh Nguyen, Sridha Sridharan, Mohamed Almorsy, Simon Denman, Son N. Tran, Clinton Fookes |
Multim. Tools Appl. | 4 |
| 2024 | Reinforcement learning-based autonomous attacker to uncover computer network vulnerabilities
Ahmed Mohamed Ahmed, Mohamed Almorsy, Sunil Aryal |
Neural Comput. Appl. | 3 |
| 2023 | Program Characterization for Software Exploitation DetectionabstractSoftware exploitation is an ever-growing problem. Signature-based exploitation detection techniques have not been effective as malicious actors continuously develop circumvention techniques. Current ML-based (signature-less) exploitation detection research is limited in quantity and use cases. Key to the success of any ML model is the characteristics used to depict program behaviour (i.e., features). Current work on using ML for software exploitation is focused on novelty ML algorithms while neglecting program characterization and under-reporting the approach for data preparation. There are two main competing program characterization techniques, micro-architecture independent (MAI) and micro-architecture dependent (MAD) techniques. This study evaluates MAI program characterization techniques for use with ML-based exploitation detection. A publicly available runtime-based traces of 11 Windows applications under buffer-overflow exploitation is used to replicate the feature engineering work found in research that uses MAI for ML-based exploitation detection. The performance and feature importance are evaluated with two different ensemble ML models (Random Forests and XGBoost). The results demonstrate that, although 0% FPR has been achieved in all datasets, MAI features that are purely fine-grained in nature can achieve a maximum recall value of 100% and an average recall of 40%, respectively. While features that contain a higher coarse-grained to fine-grained features ratio can achieve a maximum recall of 100% with an average value of 62%. The study provides a detailed discussion of the feature importance and reveals that the most important features relate to memory traffic characteristics. Ayman Youssef, Mohamed Almorsy, Chandan K. Karmakar |
ARES | 2 |
| 2023 | Requirements Elicitation and Modelling of Artificial Intelligence Systems: An Empirical StudyabstractArtificial Intelligence (AI) systems have gained significant traction in the recent past, creating new challenges in requirements engineering (RE) when building AI software systems. RE for AI practices have not been studied much and have scarce empirical studies. Additionally, many AI software solutions tend to focus on the technical aspects and ignore human-centered values. In this paper, we report on a case study for eliciting and modeling requirements using our framework and a supporting tool for human-centred RE for AI systems. Our case study is a mobile health application for encouraging type-2 diabetic people to reduce their sedentary behavior. We conducted our study with three experts from the app team - a software engineer, a project manager and a data scientist. We found in our study that most human-centered aspects were not originally considered when developing the first version of the application. We also report on other insights and challenges faced in RE for the health application, e.g., frequently changing requirements. Khlood Ahmad, Mohamed Almorsy, Chetan Arora 0002, John C. Grundy, Muneera Bano |
ENASE | 2 |
| 2023 | mHealthSwarm: A Unified Platform for mHealth ApplicationsabstractMobile health (mHealth) applications are ubiquitous and offer several benefits such as easier access to one's health and wellness data through smartphones. However, their growth in popularity has also introduced several challenges for both end-users and developers. Users face challenges around the poor user experience (UX) introduced by the need to install several apps and limited customizability which is exacerbated by the limited control over app functionality. While features common across different apps may not directly affect individual developers, the fact that one app may provide a better implementation of features leads to wasted developer effort. A single platform that can satisfy all user needs does not currently exist, and given the diversity of the mHealth domain, a single app would be far too complex if it existed. In this paper, we present a new approach and a platform for mHealth apps - micro-mHealth apps, and we discuss them as an alternative to the current mHealth app development model, which we believe could improve the current state of mHealth app development and adoption. We are currently evaluating our prototype with several micro-mHealth apps built using common features in the mHealth apps available in commercial app stores. Ben Joseph Philip, Yasmeen Anjeer Alshehhi, Mohamed Almorsy, Scott Barnett, Alessio Bonti, John C. Grundy |
ENASE | 3 |
| 2023 | An overview of Eulerian video motion magnification methods
Ahmed Mohamed Ahmed, Mohamed Almorsy, Sunil Aryal |
Comput. Graph. | 2 |
| 2023 | Requirements engineering for artificial intelligence systems: A systematic mapping study
Khlood Ahmad, Mohamed Almorsy, Chetan Arora 0002, Muneera Bano, John C. Grundy |
Inf. Softw. Technol. | 2 |
| 2023 | Online User and Power Allocation in Dynamic NOMA-Based Mobile Edge ComputingabstractThis study tackles the online user allocation problem in mobile edge computing (MEC) systems powered by non-orthogonal multiple access. App vendors need to determine a proper wireless channel in a base station/edge server and sufficient transmit power for every user. We consider a stochastic MEC system where users arrive and depart over time. When an edge server runs out of computing resources, some users will have to wait until the resources become available again, which incurs an allocation delay cost. This cost is often not investigated in many studies, which also do not consider a multi-cell, multi-channel system as we do in this work, due to its complexity. We aim to minimize the allocation delay and transmit power costs, increasing the system’s energy efficiency. To achieve this objective while guaranteeing users’ data rate requirements over time, we adopt the Lyapunov framework to convert this long-term optimization problem into a series of subproblems to be solved in every time slot. To solve the aforementioned subproblems efficiently, we present a distributed game theory-based approach. The proposed algorithm is theoretically evaluated and experimentally demonstrated to outperform several baseline and state-of-the-art methods, highlighting the significance of systematic consideration for both computation and communication aspects of this problem. Phu Lai, Qiang He 0001, Feifei Chen 0001, Mohamed Almorsy, John G. Hosking, John C. Grundy, Yun Yang 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2023 | OL-MEDC: An Online Approach for Cost-Effective Data Caching in Mobile Edge Computing SystemsabstractMobile Edge Computing (MEC) has emerged to overcome the inability of cloud computing to offer low latency services. It allows popular data to be cached on edge servers deployed within users' geographic proximity. However, the storage resources on edge servers are constrained due to their limited physical sizes. Existing studies of edge caching have predominantly focused on maximizing caching performance from the mobile network operator's perspective, e.g., maximizing data retrieval success rate, minimizing system energy consumption, balancing the overall caching workload, etc. App vendors, as key stakeholders in MEC systems, need to maximize the caching revenue, considering the cost incurred and the benefit produced. We investigate this novel Mobile Edge Data Caching (MEDC) problem from the app vendor's perspective, and prove its NP-hardness. We then propose Online MEDC (OL-MEDC), an approach that formulates MEDC strategies for app vendors, without requiring future information about data demands. Its performance is theoretically analyzed and experimentally evaluated. The experimental results demonstrate that OL-MEDC outperforms state-of-the-art approaches by at least 20.41\% on average. Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, Guangming Cui, John C. Grundy, Mohamed Almorsy, Athman Bouguettaya, Hai Jin 0001 |
IEEE Trans. Mob. Comput. | 6 |
| 2022 | Formulating Interference-aware Data Delivery Strategies in Edge Storage SystemsabstractNetworked edge servers constitute an edge storage system in edge computing (EC). Upon users’ requests, data must be delivered from edge servers in the system or from the cloud to users. Existing studies of edge storage systems have unfortunately neglected the fact that an excessive number of users accessing the same edge server for data may impact users’ data rates seriously due to the wireless interference. Thus, users must first be allocated to edge servers properly for ensuring their data rates. After that, requested data can be delivered to users to minimize their average data delivery latency. In this paper, we formulate this Interference-aware Data Delivery at the network Edge (IDDE) problem, and demonstrate its NP-hardness. To tackle it effectively and efficiently, we propose IDDE-G, a novel approach that first finds a Nash equilibrium as the strategy for allocating users. Then, it finds an approximate strategy for delivering requested data to allocated users. We analyze the performance of IDDE-G theoretically and evaluate its performance experimentally to demonstrate the effectiveness and efficiency of IDDE-G on solving the IDDE problem. Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, Guangming Cui, John C. Grundy, Mohamed Almorsy, Fang Dong 0001 |
ICPP | 6 |
| 2022 | Dynamic User Allocation in Stochastic Mobile Edge Computing SystemsabstractMobile edge computing (MEC) is a new distributed computing paradigm where edge servers are deployed at, or near cellular base stations in close proximity to end-users. This offers computing resources at the edge of the network, facilitating a highly accessible platform for real-time, latency-sensitive services. A typical MEC environment is highly stochastic with random user arrivals and departures over time. Here, we address the user allocation problem from a service provider’s perspective, who needs to allocate its users to the cloud or edge servers in a specific area. A user, who has a multi-dimensional resource requirement, can be allocated to either the remote cloud, which incurs a high latency, or an edge server, which results in a low latency but might require the user to wait in a queue. This study aims to achieve a controllable trade-off between performance (throughput) and several associated costs such as queuing delay and latency costs. We model this problem as a stochastic optimization problem, propose SUAC (Stochastic User AlloCation) – an online Lyapunov optimization-based algorithm, and prove its performance bounds. The experimental results demonstrate that SUAC outperforms existing approaches, effectively allocating users with a desired trade-off while keeping the system strongly stable. Phu Lai, Qiang He 0001, Xiaoyu Xia 0001, Feifei Chen 0001, Mohamed Almorsy, John C. Grundy, John G. Hosking, Yun Yang 0001 |
SERVICES | 5 |
| 2022 | RCM-extractor: an automated NLP-based approach for extracting a semi formal representation model from natural language requirements
Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
Autom. Softw. Eng. | 3 |
| 2022 | A large scale analysis of mHealth app user reviewsabstractThe global mHealth app market is rapidly expanding, especially since the COVID-19 pandemic. However, many of these mHealth apps have serious issues, as reported in their user reviews. Better understanding their key user concerns would help app developers improve their apps' quality and uptake. While app reviews have been used to study user feedback in many prior studies, many are limited in scope, size and/or analysis. In this paper, we introduce a very large-scale study and analysis of mHealth app reviews. We extracted and translated over 5 million user reviews for 278 mHealth apps. These reviews were then classified into 14 different aspects/categories of issues reported. Several mHealth app subcategories were examined to reveal differences in significant areas of user concerns, and to investigate the impact of different aspects of mhealth apps on their ratings. Based on our findings, women's health apps had the highest satisfaction ratings. Fitness activity tracking apps received the lowest and most unfavourable ratings from users. Over half of users who reported troubles leading them to uninstall mHealth apps gave a 1-star rating. Half of users gave the account and logging aspect only one star due to faults and issues encountered while registering or logging in. Over a third of users who expressed privacy concerns gave the app a 1-star rating. However, only 6% of users gave apps a one-star rating due to UI/UX concerns. 20% of users reported issues with handling of user requests and internationalisation concerns. We validated our findings by manually analysing a sample of 1,000 user reviews from each investigated aspect/category. We developed a list of recommendations for mHealth apps developers based on our user review analysis. Omar Haggag, John C. Grundy, Mohamed Almorsy, Sherif Haggag |
Empir. Softw. Eng. | 3 |
| 2022 | Advanced calibration of mortality prediction on cardiovascular disease using feature-based artificial neural network
Alessio Bonti, Lianhua Chi, Mohamed Almorsy, Yi-Ping Phoebe Chen |
Expert Syst. Appl. | 4 |
| 2022 | Survey and Analysis of Current End-User Data Analytics Tool SupportabstractThere has been a very large growth in interest in big data analytics to discover patterns and insights. A major challenge in this domain is the need to combine domain knowledge – what the data means (semantics) and what it is used for – with advanced data analytics and visualization techniques to mine and communicate important information from the huge volumes of raw data. Many data analytics tools have been developed for both research and practice to assist in specifying, integrating and deploying data analytics applications. However, delivering such big data analytics applications requires a capable team with different skillsets including data scientists, software engineers and domain experts. Such teams and skillsets usually take a long time to build and have high running costs. An alternative is to provide domain experts and data scientists – the end users – with tools they can use to create and deploy complex data analytics application solutions directly with less technical skills required. In this paper we present a survey and analysis of several current research and practice approaches to supporting data analytics for end-users, identifying key strengths, weaknesses and opportunities for future research. Hourieh Khalajzadeh, Mohamed Almorsy, John C. Grundy, John G. Hosking, Qiang He 0001 |
IEEE Trans. Big Data | 2 |
| 2022 | Cost-Effective App User Allocation in an Edge Computing EnvironmentabstractEdge computing is a new distributed computing paradigm extending the cloud computing paradigm, offering much lower end-to-end latency, as real-time, latency-sensitive applications can now be deployed on edge servers that are much closer to end-users than distant cloud servers. In edge computing, edge user allocation (EUA) is a critical problem for any app vendors, who need to determine which edge servers will serve which users. This is to satisfy application-specific optimization objectives, e.g., maximizing users’ overall quality of experience, minimizing system costs, and so on. In this article, we focus on the cost-effectiveness of user allocation solutions with two optimization objectives. The primary one is to maximize the number of users allocated to edge servers. The secondary one is to minimize the number of required edge servers, which subsequently reduces the operating costs for app vendors. We first model this problem as a bin packing problem and introduce an approach for finding optimal solutions. However, finding optimal solutions to the$\mathcal {NP}$-hard EUA problem in large-scale scenarios is intractable. Thus, we propose a heuristic to efficiently find sub-optimal solutions to large-scale EUA problems. Extensive experiments conducted on real-world data demonstrate that our heuristic can solve the EUA problem effectively and efficiently, outperforming the state-of-the-art and baseline approaches. Phu Lai, Qiang He 0001, John C. Grundy, Feifei Chen 0001, Mohamed Almorsy, John G. Hosking, Yun Yang 0001 |
IEEE Trans. Cloud Comput. | 5 |
| 2022 | Cost-Effective User Allocation in 5G NOMA-Based Mobile Edge Computing SystemsabstractMobile edge computing (MEC) allows edge servers to be placed at cellular base stations. App vendors like Uber and YouTube can rent computing resources and deploy latency-sensitive applications on edge servers for their users to access. Non-orthogonal multiple access (NOMA) is an emerging technique that facilitates the massive connectivity of 5G networks, further enhancing the capability of MEC. The edge user allocation (EUA) problem faces new challenges in 5G NOMA-based MEC systems. In this study, we investigate the EUA problem in a multi-cell multi-channel downlink power-domain NOMA-based MEC system. The main objective is to help mobile app vendors maximize their benefit by allocating maximum users to edge servers in a specific area at the lowest computing resource and transmit power costs. To this end, we introduce a decentralized game-theoretic approach to effectively select a channel and edge server for each user while fulfilling their resource and data rate requirements. We theoretically and experimentally evaluate our solution, which significantly outperforms various state-of-the-art and baseline approaches. Phu Lai, Qiang He 0001, Guangming Cui, Feifei Chen 0001, John C. Grundy, Mohamed Almorsy, John G. Hosking, Yun Yang 0001 |
IEEE Trans. Mob. Comput. | 6 |
| 2022 | Data, User and Power Allocations for Caching in Multi-Access Edge ComputingabstractIn the multi-access edge computing (MEC) environment, app vendors’ data can be cached on edge servers to ensure low-latency data retrieval. Massive users can simultaneously access edge servers with high data rates through flexible allocations of transmit power. The ability to manage networking resources offers unique opportunities to app vendors but also raises unprecedented challenges. To ensure fast data retrieval for users in the MEC environment, edge data caching must take into account the allocations of data, users, and transmit power jointly. We make the first attempt to study the Data, User, and Power Allocation (DUPA$^3$) problem, aiming to serve the most users and maximize their overall data rate. First, we formulate the DUPA$^3$problem and prove its$\mathcal {NP}$-completeness. Then, we model the DUPA$^3$problem as a potential DUPA$^3$game admitting at least one Nash equilibrium and propose a two-phase game-theoretic decentralized algorithm named DUPA$^3$Game to achieve the Nash equilibrium as the solution to the DUPA$^3$problem. To evaluate DUPA$^3$Game, we analyze its theoretical performance and conduct extensive experiments to demonstrate its effectiveness and efficiency. Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, Guangming Cui, John C. Grundy, Mohamed Almorsy, Xiaolong Xu 0001, Hai Jin 0001 |
IEEE Trans. Parallel Distributed Syst. | 6 |
| 2022 | Formulating Cost-Effective Data Distribution Strategies Online for Edge Cache SystemsabstractEdge Computing (EC) enables a new kind of caching system in close geographic proximity to end-users by allowing app vendors to cache popular data on edge servers deployed at base stations. This edge cache system can better support latency-sensitive applications. However, transmitting data from the centralized cloud to the edge servers without proper transmission strategies may cost app vendors dearly. Cost-effective data distribution strategies are of particular importance for applications, whose data to be cached at the edge often changes dynamically. In this paper, we study thisOnline Edge Data Distribution(OEDD) problem, aiming to minimize app vendors’ total transmission cost, while ensuring low transmission latency in the long term. We first model this problem and prove its$\mathcal {NP}$-hardness. We then combine Lyapunov optimization and game theory to propose a novel Latency-Aware Online (LAO) approach for solving this OEDD problem over time in a distributed manner with provable performance guarantees. The evaluation of LAO based on a real-world dataset demonstrates that it can help app vendors formulate cost-effective edge data distribution strategies in an online manner. Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, John C. Grundy, Mohamed Almorsy, Jun Shen 0001, Athman Bouguettaya, Hai Jin 0001 |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2022 | Dynamic User Allocation in Stochastic Mobile Edge Computing SystemsabstractMobile edge computing (MEC) is a new distributed computing paradigm where edge servers are deployed at, or near cellular base stations in close proximity to end-users. This offers computing resources at the edge of the network, facilitating a highly accessible platform for real-time, latency-sensitive services. A typical MEC environment is highly stochastic with random user arrivals and departures over time. Here, we address the user allocation problem from a service provider's perspective, who needs to allocate its users to the cloud or edge servers in a specific area. A user, who has a multi-dimensional resource requirement, can be allocated to either the remote cloud, which incurs a high latency, or an edge server, which results in a low latency but might require the user to wait in a queue. This article aims to achieve a controllable trade-off between performance (throughput) and several associated costs such as queuing delay and latency costs. We model this problem as a stochastic optimization problem, propose SUAC (Stochastic User AlloCation) – an online Lyapunov optimization-based algorithm, and prove its performance bounds. The experimental results demonstrate that SUAC outperforms existing approaches, effectively allocating users with a desired trade-off while keeping the system strongly stable. Phu Lai, Qiang He 0001, Xiaoyu Xia 0001, Feifei Chen 0001, Mohamed Almorsy, John C. Grundy, John G. Hosking, Yun Yang 0001 |
IEEE Trans. Serv. Comput. | 5 |
| 2022 | Constrained App Data Caching Over Edge Server Graphs in Edge Computing EnvironmentabstractIn recent years, edge computing, as an extension of cloud computing, has emerged as a promising paradigm for powering a variety of applications demanding low latency, e.g., virtual or augmented reality, interactive gaming, real-time navigation, etc. In the edge computing environment, edge servers are deployed at base stations to offer highly-accessible computing capacities to nearby end-users, e.g., CPU, RAM, storage, etc. From a service provider’s perspective, caching app data on edge servers can ensure low latency in its users’ data retrieval. Given constrained cache spaces on edge servers due to their physical sizes, the optimal data caching strategy must minimize overall user latency. In this article, we formulate this Constrained Edge Data Caching (CEDC) problem as a constrained optimization problem from the service provider’s perspective and prove its$\mathcal {NP}$-hardness. We propose an optimal approach named CEDC-IP to solve this CEDC problem with the Integer Programming technique. We also provide an approximation algorithm named CEDC-A for finding approximate solutions to large-scale CEDC problems efficiently and prove its approximation ratio. CEDC-IP and CEDC-A are evaluated on a real-world data set. The results demonstrate that they significantly outperform four representative approaches. Xiaoyu Xia 0001, Feifei Chen 0001, John C. Grundy, Mohamed Almorsy, Hai Jin 0001, Qiang He 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2022 | Requirements of API Documentation: A Case Study into Computer Vision ServicesabstractUsing cloud-based computer vision services is gaining traction, where developers access AI-powered components through familiar RESTful APIs, not needing to orchestrate large training and inference infrastructures or curate/label training datasets. However, while these APIsseemfamiliar to use, their non-deterministic run-time behaviour and evolution is not adequately communicated to developers. Therefore, improving these services’ API documentation is paramount—more extensive documentation facilitates the development process of intelligent software. In a prior study, we extracted 34 API documentation artefacts from 21 seminal works, devising a taxonomy of five key requirements to produce quality API documentation. We extend this study in two ways. First, by surveying 104 developers of varying experience to understand what API documentation artefacts are ofmost valueto practitioners. Second, identifying which of these highly-valued artefacts are or are not well-documented through a case study in the emerging computer vision service domain. We identify: (i) several gaps in the software engineering literature, where aspects of API documentation understanding is/is not extensively investigated; and (ii) where industry vendors (in contrast) document artefacts to better serve their end-developers. We provide a set of recommendations to enhance intelligent software documentation for both vendors and the wider research community. Alex Cummaudo, Rajesh Vasa, John C. Grundy, Mohamed Almorsy |
IEEE Trans. Software Eng. | 4 |
| 2021 | SRCM: A Semi Formal Requirements Representation Model Enabling System Visualisation and Quality CheckingabstractSRCM: A semi formal requirements representation model enabling system visualisation and quality checking Mohamed Osama, Aya Zaki-Ismail, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
MODELSWARD | 3 |
| 2021 | RCM: Requirement Capturing Model for Automated Requirements FormalisationabstractMost existing automated requirements formalisation techniques require system engineers to (re)write their requirements using a set of predefined requirement templates with a fixed structure and known semantics to simplify the formalisation process. However, these techniques require understanding and memorising requirement templates, which are usually fixed format, limit requirements captured, and do not allow capture of more diverse requirements. To address these limitations, we need a reference model that captures key requirement details regardless of their structure, format or order. Then, using NLP techniques we can transform textual requirements into the reference model. Finally, using a suite of transformation rules we can then convert these requirements into formal notations. In this paper, we introduce the first and key step in this process, a Requirement Capturing Model (RCM) - as a reference model - to model the key elements of a system requirement regardless of their format, or order. We evaluated the robustness of the RCM model compared to 15 existing requirements representation approaches and a benchmark of 162 requirements. Our evaluation shows that RCM breakdowns support a wider range of requirements formats compared to the existing approaches. We also implemented a suite of transformation rules that transforms RCM-based requirements into temporal logic(s). In the future, we will develop NLP-based RCM extraction technique to provide end-to-end solution. Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
MODELSWARD | 3 |
| 2021 | RCM-Extractor: Automated Extraction of a Semi Formal Representation Model from Natural Language RequirementsabstractRCM-Extractor: Automated Extraction of a Semi Formal Representation Model from Natural Language Requirements Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
MODELSWARD | 3 |
| 2021 | Tracing Software Exploitation
Ayman Youssef, Mohamed Almorsy, Chandan K. Karmakar, Zubair A. Baig |
NSS | 2 |
| 2021 | What's up with Requirements Engineering for Artificial Intelligence Systems?abstractIn traditional approaches to building software systems (that do not include an Artificial Intelligent (AI) or Machine Learning (ML) component), Requirements Engineering (RE) activities are well-established and researched. However, building software systems with one or more AI components may depend heavily on data with limited or no insight into the system’s workings. Therefore, engineering such systems poses significant new challenges to RE. Our search showed that literature has focused on using AI to manage RE activities, with limited research on RE for AI (RE4AI). Our study’s main objective was to investigate current approaches in writing requirements for AI/ML systems, identify available tools and techniques used to model requirements, and find existing challenges and limitations. We performed a Systematic Literature Review (SLR) of current RE4AI methods and identified 27 primary studies. Using these studies, we analysed the key tools and techniques used to specify and model requirements and found several challenges and limitations of existing RE4AI practices. We further provide recommendations for future research, based on our analysis of the primary studies and mapping to industry guidelines in Google PAIR). The SLR findings highlighted that present RE applications were not adaptive to manage most AI/ML systems and emphasised the need to provide new techniques and tools to support RE4AI. Khlood Ahmad, Muneera Bano, Mohamed Almorsy, Chetan Arora 0002, John C. Grundy |
RE | 3 |
| 2021 | DBRG: Description-Based Non-Quality Requirements GeneratorabstractRequirements quality checking is a key process in requirements engineering. For complex and large scale systems, it is recommended to use automated requirements quality checking tools because of the size and complexity of requirements. However, such tools are typically evaluated on a small set of manually curated requirements. This limitation affects the comprehensiveness and reliability of the evaluation and leaves several possible quality issues undetected. In this paper, we de-scribe a novel quality-checking-oriented synthesised requirements generator. We provide an input description language so that several quality checking issues and scenarios can be defined. The generator utilises an input dictionary of nouns and verb frames, and generates requirements sentences complying to a user-defined description of a quality affected requirement. Mohamed Osama, Aya Zaki-Ismail, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
RE | 3 |
| 2021 | Enhancing NL Requirements Formalisation Using a Quality Checking ModelabstractThe formalisation of natural language (NL) requirements is a challenging problem because NL is inherently vague and imprecise. Existing formalisation approaches only support requirements adhering to specific boilerplates or templates, and are affected by the requirements quality issues. Several quality models are developed to assess the quality of NL requirements. However, they do not focus on the quality issues affecting the formalisability of requirements. Such issues can greatly compromise the operation of complex systems and even lead to catastrophic consequences or loss of life (in case of critical systems). In this paper, we propose a requirements quality checking approach utilising natural language processing (NLP) analysis. The approach assesses the quality of the requirements against a quality model that we developed to enhance the formalisability of NL requirements. We evaluate the effectiveness of our approach by comparing the formalisation efficiency of a recent automatic formalisation technique before and after utilising our approach. The results show an increase of approximately 15% in the F-measure (from 83.8% to 98%). Mohamed Osama, Aya Zaki-Ismail, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
RE | 3 |
| 2021 | ARF: Automatic Requirements Formalisation ToolabstractFormal verification techniques enable the detection of complex quality issues within system specifications. However, the majority of system requirements are usually specified in natural language (NL). Manual formalisation of NL requirements is an error-prone and labour-intensive process requiring strong mathematical expertise, and can be infeasible for large numbers of requirements. Existing automatic formalisation techniques usually support heavily constrained natural language relying on requirement boilerplates or templates. In this paper, we introduce ARF: Automatic Requirements Formalisation Tool. ARF can automatically transform free-format natural language requirements into temporal logic based formal notations. This is achieved through two steps: 1) extraction of key requirement attributes into an intermediate representation (RCM: Requirement Capturing Model), and 2) transformation rules that convert requirements from the RCM format to formal notations. Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
RE | 3 |
| 2021 | CORG: A Component-Oriented Synthetic Textual Requirements Generator
Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
REFSQ | 3 |
| 2021 | Requirements Formality Levels Analysis and Transformation of Formal Notations into Semi-formal and Informal Notations (S)abstractIt is pivotal to have well-specified requirements to eliminate errors at an early stage of the system development life cycle.Some quality standards recommend the use of formal methods -mandate requirements to be expressed in formal notations -to detect errors.However, formal notations are not suitable for non-experts and may not be understood by all the stakeholder.To fix this, bidirectional transformations among requirement representation levels are required to maintain traceability and facilitate the communication of requirements among all the involved parties.This paper reflects on the different formality levels of requirements specifications including: informal, semi-formal, and formal notations.In addition, an automated multi-layer transformation approach is proposed to enable bi-directional transformation among requirements levels. Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
SEKE | 3 |
| 2021 | Constrained App Data Caching over Edge Server Graphs in Edge Computing EnvironmentabstractEdge computing has emerged as a promising paradigm for powering a huge number of applications requiring low latency, e.g., real-time navigation, interactive gaming, virtual or augmented reality, etc. Edge computing offers highly accessible computing and storage resources, including CPU, storage and bandwidth, by deploying edge servers at base stations. With more users accessing edge apps, a huge number of data will be transmitted via edge servers between users’ devices and remote cloud servers. A service provider can cache its app data on edge servers to ensure the low data retrieval latency of its users. Due to the physical size limits of edge servers, the optimal data caching strategy must minimize overall user latency with consideration of constrained cache spaces on edge servers. From the service provider’s perspective, we formulate this Constrained Edge Data Caching (CEDC) problem and prove the NP-hardness of this CEDC problem. After that, we propose CEDC-IP, an optimal approach solved by the Integer Programming technique, to find optimal solutions to this CEDC problem. We also propose CEDC-A, an approximation algorithm with theoretical guarantee, to find approximate solutions to large-scale CEDC problems efficiently. Finally, we conduct extensive experiments on a widely-used real-world data set, and the experimental results demonstrate that both CEDC-IP and CEDC-A significantly outperform the other four representative approaches. Xiaoyu Xia 0001, Feifei Chen 0001, John C. Grundy, Mohamed Almorsy, Hai Jin 0001, Qiang He 0001 |
SERVICES | 4 |
| 2021 | Online Collaborative Data Caching in Edge ComputingabstractIn the edge computing (EC) environment, edge servers are deployed at base stations to offer highly accessible computing and storage resources to nearby app users. From the app vendor's perspective, caching data on edge servers can ensure low latency in app users' retrieval of app data. However, an edge server normally owns limited resources due to its limited size. In this article, we investigate the collaborative caching problem in the EC environment with the aim to minimize the system cost including data caching cost, data migration cost, and quality-of-service (QoS) penalty. We model this collaborative edge data caching problem (CEDC) as a constrained optimization problem and prove that it is NP-complete. We propose an online algorithm, called CEDC-O, to solve this CEDC problem during all time slots. CEDC-O is developed based on Lyapunov optimization, works online without requiring future information, and achieves provable close-to-optimal performance. CEDC-O is evaluated on a real-world data set, and the results demonstrate that it significantly outperforms four representative approaches. Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, John C. Grundy, Mohamed Almorsy, Hai Jin 0001 |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2021 | Cost-Effective App Data Distribution in Edge ComputingabstractEdge computing, as an extension of cloud computing, distributes computing and storage resources from centralized cloud to distributed edge servers, to power a variety of applications demanding low latency, e.g., IoT services, virtual reality, real-time navigation, etc. From an app vendor's perspective, app data needs to be transferred from the cloud to specific edge servers in an area to serve the app users in the area. However, according to the pay-as-you-go business model, distributing a large amount of data from the cloud to edge servers can be expensive. The optimal data distribution strategy must minimize the cost incurred, which includes two major components, the cost of data transmission between the cloud to edge servers and the cost of data transmission between edge servers. In the meantime, the delay constraint must be fulfilled - the data distribution must not take too long. In this article, we make the first attempt to formulate this Edge Data Distribution (EDD) problem as a constrained optimization problem from the app vendor's perspective and prove its NP-hardness. We propose an optimal approach named EDD-IP to solve this problem exactly with the Integer Programming technique. Then, we propose an O(k)-approximation algorithm named EDD-A for finding approximate solutions to largescale EDD problems efficiently. EDD-IP and EDD-A are evaluated on a real-world dataset and the results demonstrate that they significantly outperform three representative approaches. Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, John C. Grundy, Mohamed Almorsy, Hai Jin 0001 |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2020 | Visual Languages for Supporting Big Data Analytics DevelopmentabstractWe present BiDaML (Big Data Analytics Modeling Languages), an integrated suite of visual languages and supporting tool to help end-users with the engineering of big data analytics solutions. BiDaML, our visual notations suite, comprises six diagrammatic notations: brainstorming diagram, process diagram, technique diagrams, data diagrams, output diagrams and deployment diagram. BiDaML tool provides a platform for efficiently producing BiDaML visual models and facilitating their design, creation, code generation and integration with other tools. To demonstrate the utility of BiDaML, we illustrate our approach with a realworld example of traffic data analysis. We evaluate BiDaML using two types of evaluations, the physics of notations and a cognitive walkthrough with several target end-users e.g. data scientists and software engineers. Hourieh Khalajzadeh, Anj Simmons, Mohamed Almorsy, John C. Grundy, John G. Hosking, Qiang He 0001 |
ENASE | 3 |
| 2020 | Quality of Experience-Aware User Allocation in Edge Computing Systems: A Potential GameabstractAs many applications and services are moving towards a more human-centered design, app vendors are taking the quality of experience (QoE) increasingly seriously. End-to-end latency is a key factor that determines the QoE experienced by users, especially for latency-sensitive applications such as online gaming, health care, critical warning systems and so on. Recently, edge computing has emerged as a promising solution to the high latency problem. In an edge computing environment, edge servers are deployed at cellular base stations, offering processing power and low network latency to users within their geographic proximity. In this paper, we tackle the user allocation problem in edge computing from an app vendor's perspective, where the vendor needs to decide which edge servers to serve which users in a specific area. Also, the vendor must consider the various levels of quality of service (QoS) for its users. Each QoS level results in a different QoE level; thus, the app vendor needs to decide the QoS level for each user so that the overall user experience is maximized. To tackle the NP-hardness of this problem, we formulate it as a potential game then propose QoEGame, an effective and efficient game-theoretic approach that admits a Nash equilibrium as a solution to the user allocation problem. Being a distributed algorithm, QoEGame is able to fully utilize the distributed nature of edge computing. Finally, we theoretically and empirically evaluate the performance of QoEGame, which is illustrated to be significantly better than the state of the art and other baseline approaches. Phu Lai, Qiang He 0001, Guangming Cui, Feifei Chen 0001, Mohamed Almorsy, John C. Grundy, John G. Hosking, Yun Yang 0001 |
ICDCS | 5 |
| 2020 | Interpreting cloud computer vision pain-points: a mining study of stack overflowabstractIntelligent services are becoming increasingly more pervasive; application developers want to leverage the latest advances in areas such as computer vision to provide new services and products to users, and large technology firms enable this via RESTful APIs. While such APIs promise an easy-to-integrate on-demand machine intelligence, their current design, documentation and developer interface hides much of the underlying machine learning techniques that power them. Such APIs look and feel like conventional APIs but abstract away data-driven probabilistic behaviour---the implications of a developer treating these APIs in the same way as other, traditional cloud services, such as cloud storage, is of concern. The objective of this study is to determine the various pain-points developers face when implementing systems that rely on the most mature of these intelligent services, specifically those that provide computer vision. We use Stack Overflow to mine indications of the frustrations that developers appear to face when using computer vision services, classifying their questions against two recent classification taxonomies (documentation-related and general questions). We find that, unlike mature fields like mobile development, there is a contrast in the types of questions asked by developers. These indicate a shallow understanding of the underlying technology that empower such systems. We discuss several implications of these findings via the lens of learning taxonomies to suggest how the software engineering community can improve these services and comment on the nature by which developers use them. Alex Cummaudo, Rajesh Vasa, Scott Barnett, John C. Grundy, Mohamed Almorsy |
ICSE | 5 |
| 2020 | Score-Based Automatic Detection and Resolution of Syntactic Ambiguity in Natural Language RequirementsabstractThe quality of a delivered product relies heavily upon the quality of its requirements. Across many disciplines and domains, system and software requirements are mostly specified in natural language (NL). However, natural language is inherently ambiguous and inconsistent. Such intrinsic challenges can lead to misinterpretations and errors that propagate to the subsequent phases of the system development. Pattern-based natural language processing (NLP) techniques have been proposed to detect the ambiguity in requirements specifications. However, such approaches typically address specific cases or patterns and lack the versatility essential to detecting different cases and forms of ambiguity. In this paper, we propose an efficient and versatile automatic syntactic ambiguity detection technique for NL requirements. The proposed technique relies on filtering the possible scored interpretations of a given sentence obtained via Stanford CoreNLP library. In addition, it provides feedback to the user with the possible correct interpretations to resolve the ambiguity. Our approach incorporates four filtering pipelines on the input NL-requirements working in conjunction with the CoreNLP library to provide the most likely possible correct interpretations of a requirement. We evaluated our approach on a suite of datasets of 126 requirements and achieved 65% precision and 99% recall on average. Mohamed Osama, Aya Zaki-Ismail, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ICSME | 3 |
| 2020 | Budgeted Data Caching based on k-Median in Mobile Edge ComputingabstractIn mobile edge computing (MEC), edge servers are deployed at base stations to provide highly accessible computational resources and storage capacities to nearby mobile devices. Caching data on edge servers can ensure the service quality and network latency for those mobile devices. However, an app vendor needs to ensure that the data caching cost does not exceed its data caching budget. In this paper, we present the budgeted edge data caching (BEDC) problem as a constrained optimization problem to maximize the overall reduction in data retrieval for all its app users within the budget, and prove that it is NP-hard. Then, we provide an approach named IP-BEDC for solving the BEDC problem optimally based on Integer Programming. We also provide an O(k) -approximation algorithm, namely α-BEDC, to find near-optimal solutions to the BEDC problems efficiently. Our proposed approaches are evaluated on a real-world data set and a synthesized data set. The results demonstrate that our approaches can solve the BEDC problem effectively and efficiently while significantly outperforming five representative approaches. Xiaoyu Xia 0001, Feifei Chen 0001, Guangming Cui, Mohamed Almorsy, John C. Grundy, Hai Jin 0001, Qiang He 0001 |
ICWS | 4 |
| 2020 | Literature Review on Visualization in Supply Chain & Decision MakingabstractRecent developments in information system have shown critical benefits that visualization can offer for supply chain and logistics. The present paper landscapes the current literature in the use of visualization in the supply chain and decision making. Using the PRISMA methodology the paper identifies the main theme and areas of development as well as propose the future directions for research. Using a dataset of top academic and industry publications, the paper contributes to the literature by providing a brief structural view of available directional developments and links them to practical applications. Catherine Xiaocui Lou, Alessio Bonti, Maria Prokofieva, Mohamed Almorsy, Sai Midhil Chowdary Kari |
IV | 4 |
| 2020 | Beware the evolving 'intelligent' web service! an integration architecture tactic to guard AI-first componentsabstractIntelligent services provide the power of AI to developers via simple RESTful API endpoints, abstracting away many complexities of machine learning. However, most of these intelligent services---such as computer vision---continually learn with time. When the internals within the abstracted 'black box' become hidden and evolve, pitfalls emerge in the robustness of applications that depend on these evolving services. Without adapting the way developers plan and construct projects reliant on intelligent services, significant gaps and risks result in both project planning and development. Therefore, how can software engineers best mitigate software evolution risk moving forward, thereby ensuring that their own applications maintain quality? Our proposal is an architectural tactic designed to improve intelligent service-dependent software robustness. The tactic involves creating an application-specific benchmark dataset baselined against an intelligent service, enabling evolutionary behaviour changes to be mitigated. A technical evaluation of our implementation of this architecture demonstrates how the tactic can identify 1,054 cases of substantial confidence evolution and 2,461 cases of substantial changes to response label sets using a dataset consisting of 331 images that evolve when sent to a service. Alex Cummaudo, Scott Barnett, Rajesh Vasa, John C. Grundy, Mohamed Almorsy |
ESEC/SIGSOFT FSE | 5 |
| 2020 | End-User-Oriented Tool Support for Modeling Data Analytics RequirementsabstractBig data and analytics are increasingly used in different domains to gain insights and to improve decision-making. Developing big data analytics solutions is a complex task involving multidisciplinary teams and users - with no data science and programming background - to professional data scientists and software engineers. Different stakeholders work with a variety of data types, tasks and concepts in different languages from high- level domain concepts to low level programming languages and technical concepts. In order to advance the level of abstraction beyond low-level data analysis technical details, we demonstrate our BiDaML tool. BiDaML brings all stakeholders around one tool to specify, model and document their big data applications using a novel set of domain-specific visual languages (DSVLs). Hourieh Khalajzadeh, Anj Simmons, Mohamed Almorsy, John C. Grundy, John G. Hosking, Qiang He 0001 |
VL/HCC | 3 |
| 2020 | The Effect of Narration on User Comprehension and Recall of Information VisualisationsabstractInformation visualisation researchers have posited that author-driven narratives will allow information to be conveyed efficiently and argue for the adoption of storytelling techniques in information visualisation. However, there is limited work describing the effects of author-driven narratives in users' comprehension and memorability of visualisations in relation to interactive visualisations. Recommendations for author-driven visualisation stories are largely based on anecdotal reports or research from the arts, and not on studies in information visualisation. To investigate these issues, we carried out a study that compared purely author-driven narratives with interactive visualisations devoid of author narratives, in terms of comprehension and short-term and long-term memorability. We found that the presence of narration in author-driven stories significantly aided the understanding of information but had no significant effect on the long-term recall of information from visualisations. Humphrey O. Obie, Caslon Chua, Iman Avazpour, Mohamed Almorsy, John C. Grundy, Tomasz Bednarz |
VL/HCC | 4 |
| 2020 | QoE-aware user allocation in edge computing systems with dynamic QoS
Phu Lai, Qiang He 0001, Guangming Cui, Xiaoyu Xia 0001, Mohamed Almorsy, Feifei Chen 0001, John G. Hosking, John C. Grundy, Yun Yang 0001 |
Future Gener. Comput. Syst. | 5 |
| 2020 | Graph-based data caching optimization for edge computing
Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, Guangming Cui, Phu Lai, Mohamed Almorsy, John C. Grundy, Hai Jin 0001 |
Future Gener. Comput. Syst. | 6 |
| 2019 | Footprints of fitness functions in search-based software testingabstractTesting is technically and economically crucial for ensuring software quality. One of the most challenging testing tasks is to create test suites that will reveal potential defects in software. However, as the size and complexity of software systems increase, the task becomes more labour-intensive and manual test data generation becomes infeasible. To address this issue, researchers have proposed different approaches to automate the process of generating test data using search techniques; an area that is known as Search-Based Software Testing (SBST). Carlos Oliveira 0005, Aldeida Aleti, Yuan-Fang Li, Mohamed Almorsy |
GECCO | 4 |
| 2019 | Losing Confidence in Quality: Unspoken Evolution of Computer Vision ServicesabstractThe following topics are dealt with: software maintenance; public domain software; program testing; source code (software); program debugging; software quality; program diagnostics; learning (artificial intelligence); mobile computing; data mining. Alex Cummaudo, Rajesh Vasa, John C. Grundy, Mohamed Almorsy, Andrew Cain |
ICSME | 4 |
| 2019 | Edge User Allocation with Dynamic Quality of Service
Phu Lai, Qiang He 0001, Guangming Cui, Xiaoyu Xia 0001, Mohamed Almorsy, Feifei Chen 0001, John G. Hosking, John C. Grundy, Yun Yang 0001 |
ICSOC | 5 |
| 2019 | Graph-Based Optimal Data Caching in Edge Computing
Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, Guangming Cui, Phu Lai, Mohamed Almorsy, John C. Grundy, Hai Jin 0001 |
ICSOC | 6 |
| 2019 | Merging Intelligent API Responses Using a Proportional Representation Approach
Tomohiro Ohtake, Alex Cummaudo, Mohamed Almorsy, Rajesh Vasa, John C. Grundy |
ICWE | 3 |
| 2019 | A Framework for Authoring Logically Ordered Visual Data StoriesabstractVisual data storytelling has gained widespread adoption as a means of communicating information visualisation. This is partly due to the increased interest in data journalism. Besides being engaging, it has been shown to foster better comprehension and memorability of information to target audiences. The visual data story authoring process involves several stages. However, current tools neither consolidate the visual data story creation process nor integrate the essential features, such as the recommendation of logically sequenced story pieces, for producing coherent narratives. This paper briefly demonstrates our approach and framework for supporting the creation of logically sequenced visual data stories. Humphrey O. Obie, Caslon Chua, Iman Avazpour, Mohamed Almorsy, John C. Grundy, Tomasz Bednarz |
VL/HCC | 4 |
| 2019 | Emotion-oriented requirements engineering: A case study in developing a smart home system for the elderly
Maheswaree Kissoon Curumsing, Niroshinie Fernando, Mohamed Almorsy, Rajesh Vasa, Kon Mouzakis, John C. Grundy |
J. Syst. Softw. | 3 |
| 2018 | Optimal Edge User Allocation in Edge Computing with Variable Sized Vector Bin Packing
Phu Lai, Qiang He 0001, Mohamed Almorsy, Feifei Chen 0001, John G. Hosking, John C. Grundy, Yun Yang 0001 |
ICSOC | 3 |
| 2018 | PedaViz: Visualising Hour-Level Pedestrian ActivityabstractEffective visualisation plays a vital role in generating insights from data. The selection of graph types however, is highly dependent on the analysis tasks and data types at hand. For example, spatio-temporal visualisations encode changes in data over time and space. Although they have the potential of revealing overall tendencies and movement patterns, building effective spatio-temporal visualisations is challenging because it requires encoding all three attributes of spatio-temporal data i.e. thematic (values of attributes), temporal and spatial in a single visualisation. In this application design study, we present PedaViz for representing hour-level spatio-temporal attributes within a single visualisation; a 24-hour radial visual metaphor that encodes hour-level temporal and daily temperature attributes while utilising a thematic map display to present spatial attributes. The design was applied on city planning domain using Melbourne's pedestrian count and temperature data. Results of our preliminary user evaluation suggest that our visualisation is easily understandable by users; and supports users in carrying out selected analysis tasks. Humphrey O. Obie, Caslon Chua, Iman Avazpour, Mohamed Almorsy, John C. Grundy, Tomasz Bednarz |
VINCI | 4 |
| 2017 | Testing Environment Emulation - A Model-based ApproachabstractModern enterprise software systems often need to interact with a large number of distributed and\nheterogeneous systems. As a result, integration testing has become a critical step in their software\ndevelopment lifecycle. Service virtualization is an emerging technique for creating testing environments with realistic executable models of server side production-like behaviours. However, building models in existing service virtualization approaches is very challenging, requiring either significant human effort or the availability of interactive tracing records. In this paper, we present a domain-specific modeling approach to generate complex, virtualized testing environments. Our approach allows domain experts to use a suite of domain-specific visual modeling languages to model key interface layers of applications at a high level of abstraction. These layered models are then transformed into a testing runtime environment for application integration testing. We have conducted a technical comparison with two other existing approaches and also carried out a user study. The user study demonstrated the acceptance of our new testing environment emulation approach from software testing experts and developers. John C. Grundy, Mohamed Almorsy, Iman Avazpour |
MODELSWARD | 3 |
| 2017 | Visualising melbourne pedestrian countabstractWe present a visualisation of Melbourne pedestrian count data and a visual metaphor for representing hour-level temporal dimension in this context. The pedestrian count data is captured from sensors located around the city. A visualisation web application is implemented that incorporates a thematic map of these sensor locations with a 24-hour clocklike polygon that shows pedestrian counts at every hour, and alongside a display of daily temperature. Our visualisation allows users to analyse how the city is used by pedestrians. Moreover, the design of our visualisation was driven by the type of analysis tasks carried out by city planners. The visualisation would help city planners better understand the dynamics of pedestrian activity within the city and aid them in urban management and design policy recommendation. Humphrey O. Obie, Caslon Chua, Iman Avazpour, Mohamed Almorsy, John C. Grundy |
VL/HCC | 4 |
| 2016 | TeeVML: tool support for semi-automatic integration testing environment emulationabstractSoftware environment emulation provides a means for simulating an operational environment of a system. This process involves approximation of systems’ external behaviors and their communications with a system to be tested in the environment. Development of such an environment is a tedious task and involves complex low level coding. Model driven engineering is an avenue to raise the level of abstraction beyond programming by specifying solution directly using problem domain concepts. In this paper we propose a novel domain-specific modeling tool to generate complex testing environments. Our tool employs a suite of domain-specific visual modeling languages for modeling emulation environment at a high level of abstraction. These high level specifications are then automatically transformed to runtime environment for application integration testing, boosting development productivity and ease of use. The tool demonstration video can be accessed here: https://youtu.be/H3Vg20Juq80. John C. Grundy, Iman Avazpour, Mohamed Almorsy |
ASE | 4 |
| 2016 | A domain-specific visual modeling language for testing environment emulationabstractSoftware integration testing plays an increasingly important role as the software industry has experienced a major change from isolated applications to highly distributed computing environments. Conducting integration testing is a challenging task because it is often very difficult to replicate a real enterprise environment. Emulating testing environment is one of the key solutions to this problem. However, existing specification-based emulation techniques require manual coding of their message processing engines, therefore incurring high development cost. In this paper, we present a suite of domain-specific visual modeling languages to describe emulated testing enviroements at a high abstraction level. Our solution allows domain experts to model a testing environment from abstract interface layers. These layer models are then transformed to runtime environment for application testing. Our user study shows that our visual languages are easy to use, yet with sufficient expressive power to model complex testing applications. John C. Grundy, Iman Avazpour, Mohamed Almorsy |
VL/HCC | 4 |
| 2016 | Ontology-based automated support for goal-use case model analysis
Tuong Huan Nguyen, John C. Grundy, Mohamed Almorsy |
Softw. Qual. J. | 3 |
| 2015 | Improving Tenants' Trust in SaaS Applications Using Dynamic Security MonitorsabstractIt is almost impossible to prove that a given software system achieves an absolute security level. This becomes more complicated when addressing multi-tenant cloud-based SaaS applications. Developing practical security properties and metrics to monitor, verify, and assess the behavior of such software systems is a feasible alternative to such problem. However, existing efforts focus either on verifying security properties or security metrics but not both. Moreover, they are either hard to adopt, in terms of usability, or require design-time preparation to support monitoring of such security metrics and properties which is not feasible for SaaS applications. In this paper, we introduce, to the best of our knowledge, the first unified monitoring platform that enables SaaS application tenants to specify, at run-time, security metrics and properties without design-time preparation and hence increases tenants' trust of their cloud-assets security. The platform automatically converts security metrics and properties specifications into security probes and integrates them with the target SaaS application at run-time. Probes-generated measurements are fed into an analysis component that verifies the specified properties and calculates security metrics' values using aggregation functions. This is then reported to SaaS tenants and cloud platform security engineers. We evaluated our platform expressiveness and usability, soundness, and performance overhead. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ICECCS | 1 |
| 2015 | Integrating goal-oriented and use case-based requirements engineering: The missing linkabstractCombining goal-oriented and use case modeling has been shown as an effective method of requirements engineering. To ensure the quality of such modeled artifacts, a conceptual foundation is needed to govern the process of determining what types of artifacts to be modeled, and how they should be specified and analyzed for 3Cs problems (completeness, consistency and correctness). However, such a foundation is missing in current goal-use case integration approaches. In this paper, we present GUIMeta, a meta-model, to address this problem. GUIMeta consists of three layers. The artifact layer defines the semantics and classification of artifacts and their relationships. The specification layer offers specification rules for each artifact class. The ontology layer allows semantics to be integrated into the entire model. Our promising evaluation shows the suitability of GUIMeta in modeling goals and use cases. Tuong Huan Nguyen, John C. Grundy, Mohamed Almorsy |
MoDELS | 3 |
| 2015 | Rule-based extraction of goal-use case models from textabstractGoal and use case modeling has been recognized as a key approach for understanding and analyzing requirements. However, in practice, goals and use cases are often buried among other content in requirements specifications documents and written in unstructured styles. It is thus a time-consuming and error-prone process to identify such goals and use cases. In addition, having them embedded in natural language documents greatly limits the possibility of formally analyzing the requirements for problems. To address these issues, we have developed a novel rule-based approach to automatically extract goal and use case models from natural language requirements documents. Our approach is able to automatically categorize goals and ensure they are properly specified. We also provide automated semantic parameterization of artifact textual specifications to promote further analysis on the extracted goal-use case models. Our approach achieves 85% precision and 82% recall rates on average for model extraction and 88% accuracy for the automated parameterization. Tuong Huan Nguyen, John C. Grundy, Mohamed Almorsy |
ESEC/SIGSOFT FSE | 3 |
| 2014 | GUITAR: An ontology-based automated requirements analysis toolabstractCombining goal-oriented and use case modeling has been proven to be an effective method in requirements elicitation and elaboration. However, current requirements engineering approaches generally lack reliable support for automated analysis of such modeled artifacts. To address this problem, we have developed GUITAR, a tool which delivers automated detection of incorrectness, incompleteness and inconsistency between artifacts. GUITAR is based on our goal-use case integration meta-model and ontologies of domain knowledge and semantics. GUITAR also provides comprehensive explanations for detected problems and can suggest resolution alternatives. Tuong Huan Nguyen, John C. Grundy, Mohamed Almorsy |
RE | 3 |
| 2014 | HorusCML: Context-aware domain-specific visual languages designerabstractThe objective behind building domain-specific visual languages (DSVLs) is to provide users with the most appropriate concepts and notations that best fit with their domain and experience. However, the existing DSVL designers do not support integrating environment and user context information when modeling, editing or viewing DSVL models at different locations, permissions, devices, etc. In this paper, we introduce HorusCML, a context-aware DSVL designer, which supports DSVL experts in integrating necessary context details within their DSVLs. The resultant DSVLs can reflect different facets, layouts, and behaviours according to context it is used in. We show a case study on developing a context-aware data flow diagram DSVL tool using HorusCML. Mohamed Almorsy, John C. Grundy, Ulf Rüegg |
VL/HCC | 1 |
| 2014 | Adaptable, model-driven security engineering for SaaS cloud-based applications
Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
Autom. Softw. Eng. | 1 |
| 2013 | Automated software architecture security risk analysis using formalized signaturesabstractReviewing software system architecture to pinpoint potential security flaws before proceeding with system development is a critical milestone in secure software development lifecycles. This includes identifying possible attacks or threat scenarios that target the system and may result in breaching of system security. Additionally we may also assess the strength of the system and its security architecture using well-known security metrics such as system attack surface, Compartmentalization, least-privilege, etc. However, existing efforts are limited to specific, predefined security properties or scenarios that are checked either manually or using limited toolsets. We introduce a new approach to support architecture security analysis using security scenarios and metrics. Our approach is based on formalizing attack scenarios and security metrics signature specification using the Object Constraint Language (OCL). Using formal signatures we analyse a target system to locate signature matches (for attack scenarios), or to take measurements (for security metrics). New scenarios and metrics can be incorporated and calculated provided that a formal signature can be specified. Our approach supports defining security metrics and scenarios at architecture, design, and code levels. We have developed a prototype software system architecture security analysis tool. To the best of our knowledge this is the first extensible architecture security risk analysis tool that supports both metric-based and scenario-based architecture security analysis. We have validated our approach by using it to capture and evaluate signatures from the NIST security principals and attack scenarios defined in the CAPEC database. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ICSE | 1 |
| 2013 | A suite of domain-specific visual languages for scientific software application modellingabstractMany advances in science now require sophisticated scientific software applications that facilitate data and computationally intensive experiments. However, the effective utilization of existing computational power e.g., grid and cloud platforms depends on the capabilities of scientists to implement parallel, scalable code for such experiments. Currently, tools aimed at supporting scientists are either very limited to specific domains, or require significant development using low-level code. We describe our work towards a more end user-friendly scientific applications development process, notations and toolset. We introduce a scientific application designer intended for use primarily by scientists to enable them in describing workflow, processes, entities, formulae, computation and ultimately realization code for different computing platforms. This is achieved via a set of integrated, domain-specific visual and textual languages (DSVLs). A Web-based modeling tool supports definition of new DSVLs and modeling of these applications. We are currently extending our tool to support generation of multi-core and GPU implementations, and visualization of results. Mohamed Almorsy, John C. Grundy, Richard J. Sadus, Willem van Straten, David G. Barnes, Owen Kaluza |
VL/HCC | 1 |
| 2012 | TOSSMA: A Tenant-Oriented SaaS Security Management ArchitectureabstractMulti-tenancy helps service providers to save costs, improve resource utilization, and reduce service customization and maintenance time by sharing of resources and services. On the other hand, supporting multi-tenancy adds more complexity to the shared application's required capabilities. Security is a key requirement that must be addressed when engineering new SaaS applications or when re-engineering existing applications to support multi-tenancy. Traditional security (re)engineering approaches do not fit with the multi-tenancy application model where tenants and their security requirements emerge after the system was first developed. Enabling, runtime, adaptable and tenant-oriented application security customization on single service instance is a key challenging security goal in multi-tenant application engineering. In this paper we introduce TOSSMA, a Tenant-Oriented SaaS Security Management Architecture. TOSSMA allows service providers to enable their tenants in defining, customizing and enforcing their security requirements without having to go back to application developers for maintenance or security customizations. TOSSMA supports security management for both new and existing systems. Service providers are not required to write security integration code to use a specific security platform or mechanism. In this paper, we describe details of our approach and architecture, our prototype implementation of TOSSMA, give a usage example of securing a multi-tenant SaaS, and discuss our evaluation experiments of TOSSMA. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
IEEE CLOUD | 1 |
| 2012 | Supporting Virtualization-Aware Security Solutions Using a Systematic Approach to Overcome the Semantic GapabstractA prerequisite to implementing virtualization-aware security solutions is to solve the "semantic gap" problem. Current approaches require a deep knowledge of the kernel data to manually solve the semantic gap. However, kernel data is very complex; an Operating System (OS) kernel contains thousands of data structures that have direct and indirect (pointer) relations between each other with no explicit integrity constraints. This complexity makes it impractical to use manual methods. In this paper, we present a new solution to systematically and efficiently solve the semantic gap for any OS, without any prior knowledge of the OS. We present: (i) KDD, a tool that systematically builds a precise kernel data definition for any C-based OS such as Windows and Linux. KDD generates this definition by performing points-to analysis on the kernel's source code to disambiguate the pointer relations. (ii) SVA, a security appliance that solves the semantic gap based on the generated definition, to systematically and externally map the virtual machines' physical memory and extract the runtime dynamic objects. We have implemented prototypes for KDD and SVA, and have performed different experiments to prove their effectiveness. Amani S. Ibrahim, James H. Hamlyn-Harris, John C. Grundy, Mohamed Almorsy |
IEEE CLOUD | 4 |
| 2012 | SMURF: Supporting Multi-tenancy Using Re-aspects Framework
Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ICECCS | 1 |
| 2012 | Supporting automated vulnerability analysis using formalized vulnerability signaturesabstractAdopting publicly accessible platforms such as cloud computing model to host IT systems has become a leading trend. Although this helps to minimize cost and increase availability and reachability of applications, it has serious implications on applications’ security. Hackers can easily exploit vulnerabilities in such publically accessible services. In addition to, 75% of the total reported application vulnerabilities are web application specific. Identifying such known vulnerabilities as well as newly discovered vulnerabilities is a key challenging security requirement. However, existing vulnerability analysis tools cover no more than 47% of the known vulnerabilities. We introduce a new solution that supports automated vulnerability analysis using formalized vulnerability signatures. Instead of depending on formal methods to locate vulnerability instances where analyzers have to be developed to locate specific vulnerabilities, our approach incorporates a formal vulnerability signature described using OCL. Using this formal signature, we perform program analysis of the target system to locate signature matches (i.e. signs of possible vulnerabilities). A newly–discovered vulnerability can be easily identified in a target program provided that a formal signature for it exists. We have developed a prototype static vulnerability analysis tool based on our formalized vulnerability signatures specification approach. We have validated our approach in capturing signatures of the OWSAP Top10 vulnerabilities and applied these signatures in analyzing a set of seven benchmark applications. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ASE | 1 |
| 2012 | Supporting automated software re-engineering using re-aspectsabstractSystem maintenance, including omitting an existing system feature e.g. buggy or vulnerable code, or modifying existing features, e.g. replacing them, is still very challenging. To address this problem we introduce the “re-aspect” (re-engineering aspect), inspired from traditional AOP. A re-aspect captures system modification details including signatures of entities to be updated; actions to apply including remove, modify, replace, or inject new code; and code to apply. Re-aspects locate entities to update, entities that will be impacted by the given update, and finally propagate changes on the system source code. We have applied our re-aspects technique to the security re-engineering problem and evaluated it on a set of open source .NET applications to demonstrate its usefulness. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ASE | 1 |
| 2012 | Supporting operating system kernel data disambiguation using points-to analysisabstractGeneric pointers scattered around operating system (OS) kernels make the kernel data layout ambiguous. This limits current kernel integrity checking research to covering a small fraction of kernel data. Hence, there is a great need to obtain an accurate kernel data definition that resolves generic pointer ambiguities, in order to formulate a set of constraints between structures to support precise integrity checking. In this paper, we present KDD, a new tool for systematically generating a sound kernel data definition for any C-based OS e.g. Windows and Linux, without any prior knowledge of the kernel data layout. KDD performs static points-to analysis on the kernel’s source code to infer the appropriate candidate types for generic pointers. We implemented a prototype of KDD and evaluated it to prove its scalability and effectiveness. Amani S. Ibrahim, John C. Grundy, James H. Hamlyn-Harris, Mohamed Almorsy |
ASE | 4 |
| 2012 | Operating System Kernel Data Disambiguation to Support Security Analysis
Amani S. Ibrahim, John C. Grundy, James H. Hamlyn-Harris, Mohamed Almorsy |
NSS | 4 |
| 2012 | Identifying OS Kernel Objects for Run-Time Security Analysis
Amani S. Ibrahim, James H. Hamlyn-Harris, John C. Grundy, Mohamed Almorsy |
NSS | 4 |
| 2012 | VAM-aaS: Online Cloud Services Security Vulnerability Analysis and Mitigation-as-a-Service
Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
WISE | 1 |
| 2011 | Collaboration-Based Cloud Computing Security Management FrameworkabstractAlthough the cloud computing model is considered to be a very promising internet-based computing platform, it results in a loss of security control over the cloud-hosted assets. This is due to the outsourcing of enterprise IT assets hosted on third-party cloud computing platforms. Moreover, the lack of security constraints in the Service Level Agreements between the cloud providers and consumers results in a loss of trust as well. Obtaining a security certificate such as ISO 27000 or NIST-FISMA would help cloud providers improve consumers trust in their cloud platforms' security. However, such standards are still far from covering the full complexity of the cloud computing model. We introduce a new cloud security management framework based on aligning the FISMA standard to fit with the cloud computing model, enabling cloud providers and consumers to be security certified. Our framework is based on improving collaboration between cloud providers, service providers and service consumers in managing the security of the cloud platform and the hosted services. It is built on top of a number of security standards that assist in automating the security management process. We have developed a proof of concept of our framework using. NET and deployed it on a test bed cloud platform. We evaluated the framework by managing the security of a multi-tenant SaaS application exemplar. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
IEEE CLOUD | 1 |
| 2011 | CloudSec: A security monitoring appliance for Virtual Machines in the IaaS cloud modelabstractThe Infrastructure-as-a-Service (IaaS) cloud computing model has become a compelling computing solution with a proven ability to reduce costs and improve resource efficiency. Virtualization has a key role in supporting the IaaS model. However, virtualization also makes it a target for potent rootkits because of the loss of control problem over the hosted Virtual Machines (VMs). This makes traditional in-guest security solutions, relying on operating system kernel trustworthiness, no longer an effective solution to secure the virtual infrastructure of the IaaS model. In this paper, we explore briefly the security problem of the IaaS cloud computing model, and present CloudSec, a new virtualization-aware monitoring appliance that provides active, transparent and real-time security monitoring for hosted VMs in the IaaS model. CloudSec utilizes virtual machine introspection techniques to provide fine-grained inspection of VM's physical memory without installing any monitoring code inside the VM. It actively reconstructs and monitors the dynamically changing kernel data structures instances, as a prior step to enable providing protection for kernel data structures. We have implemented a proof-of-concept prototype using VMsafe libraries on a VMware ESX platform. We have evaluated the system monitoring accuracy and the performance overhead of CloudSec. Amani S. Ibrahim, James H. Hamlyn-Harris, John C. Grundy, Mohamed Almorsy |
NSS | 4 |