VLDB 2026 Research / reviewers in the wild / expert
Mamdouh Alenezi
dblp:134/8933
· DBLP profile ↗
8ranked-venue papers
5as first author
3since 2021 · last 2026
0000-0001-6852-1206ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 4 · 3 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorSecurity and privacy · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Unified Meta Model for Converting Architecture Decisions Into DevOps PipelinesabstractABSTRACT Background DevOps pipelines have become the primary vehicle for operationalizing software architecture decisions; however, their design and evolution remain largely ad hoc and tool‐specific. This disconnect weakens traceability from architectural intent to runtime automation, complicates change impact analysis, and increases the risk of configuration errors. Although model‐driven engineering (MDE) has been proposed to support CI/CD adoption, existing approaches typically focus on individual tools or isolated pipeline fragments and lack a unified, reusable foundation for systematic transformation. Aims This paper aims to introduce a unified DevOps Pipeline Meta‐Model (DP2M) and an architecture‐to‐pipeline transformation framework that enables the derivation of executable DevOps pipelines directly from software architecture models, while ensuring traceability and supporting systematic reuse. Materials and Methods A mixed‐methods approach is employed, combining: (i) a systematic mapping of MDE‐for‐DevOps literature; (ii) a cross‐vendor analysis of industrial pipeline specification languages across Jenkins (Declarative and Scripted), GitHub Actions, GitLab CI, Azure Pipelines, CircleCI, Travis CI, Google Cloud Build, and AWS CodePipeline; and (iii) semi‐structured interviews with practitioners. From this, a taxonomy of pipeline artifacts and concerns—covering build, test, deployment, security, compliance, and observability—is derived, along with quality‐driven requirements for pipeline modeling. These are formalized into the DP2M meta‐model and a catalog of reusable transformation patterns with defined rules and constraints. Results The proposed DP2M captures a technology‐agnostic representation of DevOps pipelines with explicit traceability links to architectural elements and decisions. A prototype toolchain implements the framework and generates executable pipelines across multiple CI/CD platforms. Evaluation through realistic case studies demonstrates expressiveness across heterogeneous toolchains, preservation of architectural intent, reduction of duplication, and improved handling of DevSecOps concerns as first‐class modeling constructs. Discussions The findings highlight the limitations of existing tool‐centric approaches and demonstrate how a unified meta‐model combined with formal transformation patterns can bridge the gap between architecture and pipeline implementation. The approach supports traceability, facilitates change impact analysis, and enables controlled co‐evolution of architecture and pipeline models across diverse environments. Conclusions This work presents a practical and scalable path toward architecture‐centric, model‐driven DevOps pipelines. By enabling analyzable, evolvable, and reusable pipelines across projects and platforms, the proposed framework advances the integration of software architecture and DevOps practices while addressing key challenges in traceability, consistency, and automation. Mamdouh Alenezi, Mohammed Akour |
Softw. Pract. Exp. | 1 |
| 2022 | Synthesizing secure software development activities for linear and agile lifecycle modelsabstractAbstract Application security is an important concern, and security activities to support software development lifecycle processes, such as specification, design, implementation, and testing are increasingly in need. Despite the plethora of knowledge available for secure software development in online and books, software systems are seldom secure as developers lack security knowledge. The primary reason for this paradox is the diversity and overwhelming nature of the available security knowledge. In this article, we propose to synthesize the well‐known secure software development practices for both linear and agile lifecycle models. Using theMediaWikiplatform, we make this knowledge available to software developers and designers from a single source. Mamdouh Alenezi, Hamid Abdul Basit, Maham Anwar Beg, Muhammad Saad Shaukat |
Softw. Pract. Exp. | 1 |
| 2021 | A reference measurement framework of software security product quality (SPQNFSR)abstractAbstract Currently, the customer's demands have expressively amplified their expectations of getting software at a high‐quality level. However, the non‐functional requirements of the software products attention have been expanded in both the academic and the industrial fields; so, there is no framework for specifying and measuring such kinds of quality constraints for the security requirements of software product quality. This paper presents an integrated framework of the early specification and measurement of the functional and non‐functional software security requirements. Such a measurement framework would help software and systems engineers to improve product qualities whether the software has already been delivered or has yet to be built. The main steps that have been followed include: identify, specify and measure the software security requirements based on ISO/IEC SQuaRE series of international standards for software product quality. A standard measurement framework used to measure the functional size of the software product quality to develop a functional size measurement of the functional and non‐functional security requirements is described. As a result, a functional size measurement framework of the functional and non‐functional security requirements (SPQ NFSR ) using international standards is proposed. An automatic teller machine case study for the measurement of security requirements based on perspectives of a software functional user requirements is presented. Finally, it is concluded that it is essential to develop such a functional size measurement framework for functional and non‐functional security requirements to support developers to face the challenges derived from early dealing with such requirements. Khalid T. Al-Sarayreh, Mamdouh Alenezi, Mohammad Zarour, Kenza Meridji |
IET Inf. Secur. | 2 |
| 2020 | A Comparison Study of Available Sofware Security OntologiesabstractA rising number of software and services malfunctioning due to security flaws has increased the importance of software security and resulted in numerous knowledge sources of the domain. Building secure software systems require the understanding and extraction of the available knowledge, and a standard knowledge management platform is needed. Ontologies form an integral part of knowledge management platforms as they capture and structure the given knowledge. Various software security ontologies have been proposed previously, either stand-alone or as part of some bigger ontology like a computer or information security. However, these ontologies do not cover the entire domain and cannot be used as a standard ontology for software security in its current form. In this paper, we have identified and evaluated the existing ontologies that specifically capture software security knowledge, both qualitatively and quantitatively with the help of ontology evaluation tools, in order to select the best ontology that can be extended to prepare the standard ontology for the software security domain. Mamdouh Alenezi, Hamid Abdul Basit, Faraz Idris Khan, Maham Anwar Beg |
EASE | 1 |
| 2020 | Software Security Specifications and Design: How Software Engineers and Practitioners Are Mixing Things upabstractHuge numbers of worldwide-deployed software suffer from poor quality and possess vulnerabilities with serious impact. Meanwhile, people are using such software to save and manage their valuable information including their monetary data. This has increased the hackers' appetite to attack software. Henceforth, researchers and practitioners are convinced that software security is not an added value or a gold-plating need. Consequently, security requirements specification and implementation become vital during the software development process. Unfortunately, researchers and practitioners are doing so in a rush. This has made them mix concepts and practices up in a way that can terribly make the problem of delivering software overdue more chronic which will result in a security and technical debt. This research represents a corrective study that sheds light on what has been achieved in analyzing and designing secure software and what are the problems committed and how to handle them. Mohammad Zarour, Mamdouh Alenezi, Khalid Alsarayrah |
EASE | 2 |
| 2019 | An Efficient, Secure, and Queryable Encryption for NoSQL-Based Databases Hosted on Untrusted Cloud EnvironmentsabstractNoSQL-based databases are attractive to store and manage big data mainly due to high scalability and data modeling flexibility. However, security in NoSQL-based databases is weak which raises concerns for users. Specifically, security of data at rest is a high concern for the users deployed their NoSQL-based solutions on the cloud because unauthorized access to the servers will expose the data easily. There have been some efforts to enable encryption for data at rest for NoSQL databases. However, existing solutions do not support secure query processing, and data communication over the Internet and performance of the proposed solutions are also not good. In this article, the authors address NoSQL data at rest security concern by introducing a system which is capable to dynamically encrypt/decrypt data, support secure query processing, and seamlessly integrate with any NoSQL- based database. The proposed solution is based on a combination of chaotic encryption and Order Preserving Encryption (OPE). The experimental evaluation showed excellent results when integrated the solution with MongoDB and compared with the state-of-the-art existing work. Mamdouh Alenezi, Khaled Mohamad Almustafa, Waheed Iqbal, Muhammad Ali Raza, Tanveer Khan |
Int. J. Inf. Secur. Priv. | 1 |
| 2013 | Bug Reports Prioritization: Which Features and Classifier to Use?abstractLarge open source bug tracking systems receives large number of bug reports daily. Managing these huge numbers of incoming bug reports is a challenging task. Dealing with these reports manually consumes time and resources which leads to delaying the resolution of important bugs which are crucial and need to be identified and resolved earlier. Bug triaging is an important process in software maintenance. Some bugs are important and need to be fixed right away, whereas others are minor and their fixes could be postponed until resources are available. Most automatic bug assignment approaches do not take the priority of bug reports in their consideration. Assigning bug reports based on their priority may play an important role in enhancing the bug triaging process. In this paper, we present an approach to predict the priority of a reported bug using different machine learning algorithms namely Naive Bayes, Decision Trees, and Random Forest. We also investigate the effect of using two feature sets on the classification accuracy. We conduct experimental evaluation using open-source projects namely Eclipse and Fire fox. The experimental evaluation shows that the proposed approach is feasible in predicting the priority of bug reports. It also shows that feature-set-2 outperformsfeature-set-1. Moreover, both Random Forests and Decision Trees outperform Naive Bayes. Mamdouh Alenezi, Shadi Banitaan |
ICMLA (2) | 1 |
| 2013 | DECOBA: Utilizing Developers Communities in Bug AssignmentabstractBug Tracking System (BTS) is public ally accessible which enables geographically distributed developers to follow the work of each other and contribute in bug fixing. Developer interactions through commenting on bug reports generate a developer social network that can be used to improve software development and maintenance activities. In large scale complex software projects, software maintenance requires larger groups to participate in its activities. Most previous bug assignments approaches assign only one developer to new bugs. However, bug fixing is a collaborative effort between several developers (i.e., many developers contribute their experience in fixing a bug report). In this work, we build developers social networks based on developers comments on bug reports and detect developers communities. We also assign a relevant community to each newly committed bug report. Moreover, we rank developers in each community based on their experience. An experimental evaluation is conducted on three open source projects namely Net Beans, Free desktop, and Mandriva. The results show that the detected communities are significantly connected with high density. They also show that the proposed approach achieves feasible accuracy of bug assignment. Shadi Banitaan, Mamdouh Alenezi |
ICMLA (2) | 2 |