Mohamad Gharib

dblp:131/3581 · DBLP profile ↗
← Back
16ranked-venue papers
14as first author
8since 2021 · last 2024
0000-0003-2286-2819ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 7 · 6 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 first-author · 3 since 2021Security and privacy · 2 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 US4USec: A User Story Model for Usable Security
Mohamad Gharib
RCIS (1)1
2024 Dealing with Emotional Requirements for Software Ecosystems: Findings and Lessons Learned in the PHArA-ON Project
Mohamad Gharib, Mariana Falco, Femke Nijboer, Angelica M. Tinga, Stefania D'Agostini, Erika Rovini, Laura Fiorini 0001, Filippo Cavallo, Kuldar Taveter
RCIS (1)1
2023 Emotions in Requirements Engineering: A Systematic Mapping Study
abstract
The purpose of requirements engineering (RE) is to make sure that the expectations and needs of the stakeholders of a software system are met. Emotional needs can be captured as emotional requirements that represent how the end user should feel when using the system. Differently from functional and quality (non-functional) requirements, emotional requirements have received relatively less attention from the RE community. This study is motivated by the need to explore and map the literature on emotional requirements. The study applies the systematic mapping study technique for surveying and analyzing the available literature to identify the most relevant publications on emotional requirements. We identified 34 publications that address a wide spectrum of practices concerned with engineering emotional requirements. The identified publications were analyzed with respect to the application domains, instruments used for eliciting and artefacts used for representing emotional requirements, and the state of the practice in emotion-related requirements engineering. This analysis serves to identify research gaps and research directions in engineering emotional requirements. To the best of the knowledge by the authors, no other similar study has been conducted on emotional requirements.
Tahira Iqbal, Hina Anwar, Syazwanie Filzah, Mohamad Gharib, Kerli Mooses, Kuldar Taveter
CHASE4
2022 Toward an architecture to improve privacy and informational self-determination through informed consent
abstract
Purpose Most developed countries have enacted privacy laws to govern the collection and use of personal information (PI) as a response to the increased misuse of PI. Yet, these laws rely heavily on the concept of informational self-determination through the “notice” and “consent” models, which is deeply flawed. This study aims at tackling these flaws achieve the full potential of these privacy laws. Design/methodology/approach The author critically reviews the concept of informational self-determination through the “notice” and “consent” model identifying its main flaws and how they can be tackled. Findings Existing approaches present interesting ideas and useful techniques that focus on tackling some specific problems of informational self-determination but fail short in proposing a comprehensive solution that tackles the essence of the overall problem. Originality/value This study introduces a model for informed consent, a proposed architecture that aims at empowering individuals (data subjects) to take an active role in the protection of their PI by simplifying the informed consent transaction without reducing its effectiveness, and an ontology that can partially realize the proposed architecture.
Mohamad Gharib
Inf. Comput. Secur.1
2022 A cyber-physical-social approach for engineering Functional Safety Requirements for automotive systems
Mohamad Gharib, Andrea Ceccarelli, Paolo Lollini, Andrea Bondavalli
J. Syst. Softw.1
2021 COPri v.2 - A core ontology for privacy requirements
Mohamad Gharib, Paolo Giorgini, John Mylopoulos
Data Knowl. Eng.1
2021 A model to discipline autonomy in cyber-physical systems-of-systems and its application
abstract
Abstract A cyber‐physical system‐of‐systems (CPSoS) can be defined as a system‐of‐systems (SoS), composed of several operable and autonomous constituent systems (CSs) that are themselves cyber‐physical systems (CPSs). A main challenge in integrating CPSoS to function as a single integrated system is the autonomy of its components, which may result in undesirable, unsecure, or even unsafe situations. In this paper, we advocate that in order to facilitate the integration of CPSs within the overall context of their CPSoS, we may need to adjust their level of autonomy in a way that enables them to perform their activities and avoid undesirable, unsecure , and unsafe situations. Reducing such situations surely contributes to the dependability of the CPSoS. In particular, we propose a novel model‐based approach for modeling and analyzing the autonomy levels of CPSs based on their awareness concerning their operational environment as well as their capability to react in a timely, secure, and safe manner while performing their activities. The model is further described in a UML profile and applied to represent activities for autonomous driving scenarios. Using a driving simulator, we implement such models on a target vehicle, and we show the resulting safety improvement, especially in terms of reduced collisions.
Mohamad Gharib, Leandro Dias da Silva, Andrea Ceccarelli
J. Softw. Evol. Process.1
2021 Meta-Learning to Improve Unsupervised Intrusion Detection in Cyber-Physical Systems
abstract
Artificial Intelligence (AI)- based classifiers rely on Machine Learning (ML) algorithms to provide functionalities that system architects are often willing to integrate into critical Cyber-Physical Systems (CPSs) . However, such algorithms may misclassify observations, with potential detrimental effects on the system itself or on the health of people and of the environment. In addition, CPSs may be subject to threats that were not previously known, motivating the need for building Intrusion Detectors (IDs) that can effectively deal with zero-day attacks. Different studies were directed to compare misclassifications of various algorithms to identify the most suitable one for a given system. Unfortunately, even the most suitable algorithm may still show an unsatisfactory number of misclassifications when system requirements are strict. A possible solution may rely on the adoption of meta-learners, which build ensembles of base-learners to reduce misclassifications and that are widely used for supervised learning. Meta-learners have the potential to reduce misclassifications with respect to non-meta learners: however, misleading base-learners may let the meta-learner leaning towards misclassifications and therefore their behavior needs to be carefully assessed through empirical evaluation. To such extent, in this paper we investigate, expand, empirically evaluate, and discuss meta-learning approaches that rely on ensembles of unsupervised algorithms to detect (zero-day) intrusions in CPSs. Our experimental comparison is conducted by means of public datasets belonging to network intrusion detection and biometric authentication systems, which are common IDSs for CPSs. Overall, we selected 21 datasets, 15 unsupervised algorithms and 9 different meta-learning approaches. Results allow discussing the applicability and suitability of meta-learning for unsupervised anomaly detection, comparing metric scores achieved by base algorithms and meta-learners. Analyses and discussion end up showing how the adoption of meta-learners significantly reduces misclassifications when detecting (zero-day) intrusions in CPSs.
Tommaso Zoppi, Mohamad Gharib, Muhammad Atif 0001, Andrea Bondavalli
ACM Trans. Cyber Phys. Syst.2
2020 COPri - A Core Ontology for Privacy Requirements Engineering
Mohamad Gharib, John Mylopoulos, Paolo Giorgini
RCIS1
2019 Information quality requirements engineering with STS-IQ
Mohamad Gharib, Paolo Giorgini
Inf. Softw. Technol.1
2018 Analysis of information quality requirements in business processes, revisited
Mohamad Gharib, Paolo Giorgini, John Mylopoulos
Requir. Eng.1
2017 Dealing with Functional Safety Requirements for Automotive Systems: A Cyber-Physical-Social Approach
Mohamad Gharib, Paolo Lollini, Andrea Ceccarelli, Andrea Bondavalli
CRITIS1
2017 Towards an Ontology for Privacy Requirements via a Systematic Literature Review
Mohamad Gharib, Paolo Giorgini, John Mylopoulos
ER1
2016 Privacy Requirements: Findings and Lessons Learned in Developing a Privacy Platform
abstract
Information practices and systems that make use of personal and health-related information are governed by European laws and regulations to prevent unauthorized use and disclosure. Failure to comply with these laws and regulations results in huge monetary sanctions, which both private companies and public administrations want to avoid. How to comply with these laws, requires understanding the privacy requirements imposed on information systems. A holistic approach to privacy requirements specification calls for understanding not only the requirements derived from law, but also citizens' needs with respect to privacy. In this paper, we report on our experience in conducting privacy requirements engineering as part of a H2020 European Project, namely VisiOn (Visual Privacy Management in User Centric Open Requirements) for the development of a privacy platform to improve the interaction between Public Administrations (PA) and citizens, while guarding the privacy of the latter. Specifically, we present the process for eliciting, classifying, prioritizing, and validating privacy requirements for the two types of users, namely PA and citizen. The process is applied to different cases spanning from healthcare to other e-governmental initiatives, with the active involvement of the corresponding PAs. We report on findings and lessons learned from this experience.
Mohamad Gharib, Mattia Salnitri, Elda Paja, Paolo Giorgini, Haralambos Mouratidis, Michalis Pavlidis, José Fran. Ruiz, Sandra Fernandez, Andrea Della Siria
RE1
2015 A goal-based approach for automated specification of Information Quality policies
abstract
Organizational and social aspects are key factors for the analysis of Information Quality (IQ) requirements. This is particularly true in the case of complex socio-technical systems where computerized components coexist with humans and social structures and effective IQ policies can be defined only as a combination of all these factors. Although, several policy-based approaches have been proposed in the literature, none of them offer an adequate conceptual support to combine the technical and organizational perspective in the analysis of IQ requirements. In this paper, we propose a goal-based approach based on an extended version of Secure Tropos to model and analyze IQ requirements from a socio-technical perspective. Our approach provides mechanisms for an automatic derivation of IQ policies, which are specified in terms of permitted, forbidden and obligated activities. Verification of correctness and consistency of the derived policies are supported by automated analysis techniques. We illustrated our approach with an example concerning the stock market system.
Mohamad Gharib, Paolo Giorgini
RCIS1
2015 Modeling and Reasoning About Information Quality Requirements
Mohamad Gharib, Paolo Giorgini
REFSQ1