VLDB 2026 Research / reviewers in the wild / expert
Musaad Alzahrani
dblp:151/4192
· DBLP profile ↗
7ranked-venue papers
3as first author
4since 2021 · last 2026
0000-0002-6585-4483ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 7 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Robust and efficient log anomaly detection: A hybrid ID-semantic approach for evolving systems
Musaad Alzahrani |
Inf. Softw. Technol. | 1 |
| 2025 | A Fuzzy-AHP Decision-Making Framework for Optimizing Software Maintenance and Deployment in Information Security SystemsabstractABSTRACT Information System Security (ISS) is the primary economic lever for the global economy. It is the cornerstone for value generation, and its absence undeniably affects technology, people, and finances. The emergence of the worldwide information society has introduced fresh economic and legal challenges attributed to the surge in Internet utilization and advancements in the digital economy. Ensuring the security of advancements within information systems has emerged as a primary concern in propelling the evolution of information processes within the software development industry. This study aims to develop and propose a Fuzzy Analytic Hierarchy Process (Fuzzy‐AHP) framework to enhance decision‐making for software maintenance and deployment in ISS. This framework aims to provide a systematic, flexible method for evaluating and prioritizing multiple conflicting criteria under conditions of uncertainty. The study initially adopts an empirical survey to identify software security maintenance and deployment risks and their practices for ISS organizations. Then adopts the Fuzzy‐AHP method to handle the imprecision of expert judgments and organizes decision‐making into a hierarchical structure. The framework is applied to evaluate key criteria related to software maintenance and deployment, including security risks, system performance, operational costs, and compliance requirements. Data from 50 ISS experts were collected and used to validate the framework. The paper identifies 52 security risks in maintenance and deployment (SRMD) processes in ISS and also identified 139 best practices for ensuring security, including regular updates, patch management, and adherence to industry‐standard security protocols. The Fuzzy‐AHP framework effectively structured the decision‐making process by prioritizing criteria and sub‐criteria. The results demonstrated that the framework helps mitigate the subjective biases in expert judgment and provides a more balanced assessment of maintenance and deployment strategies. Prioritizing security risks and compliance emerged as key factors in the decision‐making process. The proposed Fuzzy‐AHP framework provides an innovative and adaptable solution for optimizing ISS organizations' software maintenance and deployment decisions. It addresses the complexity and uncertainty involved in such decisions, offering a transparent and structured approach that improves the accuracy and reliability of outcomes. Future research should focus on empirical validation of the framework in real‐world case studies and expand its application to other industries with similar decision‐making needs. Rafiq Ahmad Khan, Ismail Mohamed Keshta, Hussein Ali Al Hashimi, Alaa Omran Almagrabi, Hathal Alwageed, Musaad Alzahrani |
J. Softw. Evol. Process. | 6 |
| 2024 | Evaluation of requirement engineering best practices for secure software development in GSD: An ISM analysisabstractAbstract Technological advancement makes the world a global village. Security is an evergreen and everlasting area, because of the continuous threat from Hackers and Crackers. The immense use of software systems has modernized human society in every aspect. Thus, it is crucial to devise new processes, techniques, and tools to support teams in the development of secure code from the early stages of the software development process, while potentially reducing the costs and shortening the time to market. Considering the significance of software security, it is important to consider the security practices from the early phase of the software development life cycle (SDLC), that is, requirements engineering (RE). Hence, this study aims to identify and categorize RE practices important to apply for secure software development (SSD) in a geographically distributed development environment. To study the RE practices concerning SSD, we conducted a questionnaire survey with industrial experts in the global software development (GSD) context. Furthermore, the interpretive structure modeling (ISM) approach was applied to evaluate the relationship between the RE security practice core categories. This paper identifies 70 practices and classifies them into 11 fundamental dimensions (categories) to assist GSD organizations in specifying the requirements for SSD. The ISM results show that the “Awareness of Secure Requirement Engineering (SRE)” category has the most decisive influence on the other 10 core categories of the identified RE security practices. With the help of empirical evidence and the ISM approach, this work attempts to identify potential security practices and to give a set of secure RE practices that can be used to improve the security of the software development process. Rafiq Ahmad Khan, Muhammad Azeem Akbar, Saima Rafi, Alaa Omran Almagrabi, Musaad Alzahrani |
J. Softw. Evol. Process. | 5 |
| 2024 | Security risks of global software development life cycle: Industry practitioner's perspectiveabstractAbstract Software security has become increasingly important because the malicious attack and other hacker risks of a computer system have grown popularity in the last few years. As a result, several researchers have examined security solutions as early as the requirement engineering phase. With the growth of the software business and the internet, there is a need to understand the security risks against each phase of the software development life cycle (SDLC). This study aims to empirically investigate and prioritize the risks that could negatively impact the software security aspects of SDLC in the context of global software development (GSD). To achieve the study objectives, we conducted an industrial empirical study to determine the impact of software security threats against each phase of SDLC. Furthermore, the fuzzy analytical hierarchy process (FAHP) was used to prioritize the list of software security risks against the SDLC. The results and analysis of this study provide a ranked‐based decision‐making framework, which assists the practitioners in considering the most critical security risks on priority. The results show “improper plan for secure requirement identification, inception, authentication, authorization, and privacy,” “lack of threat models updating,” “lack of output validation,” “lack of certification in the final release and archive,” and “spoofing” as the top‐ranked security risks of SDLC in GSD. In addition, the application of FAHP is novel in this domain as it is helpful to address multicriteria decision‐making problems. Rafiq Ahmad Khan, Siffat Ullah Khan, Muhammad Azeem Akbar, Musaad Alzahrani |
J. Softw. Evol. Process. | 4 |
| 2019 | Using Client-Based Class Cohesion Metrics to Predict Class MaintainabilityabstractIt has been established that there is a strong positive correlation between class cohesion (what we call internal connection-based class cohesion) and class maintainability. Unfortunately, the potential for using internal connection-based class cohesion to predict class maintainability is limited because we cannot measure this class cohesion until the class has been designed and coded. In this paper, we define client-based class cohesion which can be measured in the design phase. Thus, we are able in the design phase to use class cohesion to predict class maintainability. Further, the potential exists that measurements of this client-based class cohesion may in some ways be more useful than measurements of internal connection-based cohesion. This may be true because in addition to involving factors internal to the class in question, external factors, i.e., client classes, are also involved. We conduct an empirical study to investigate the extent to which a client-based class cohesion metric can be used individually and in combination with other internal connection-based class cohesion metrics to predict class maintainability. The results of the study indicate that the client-based class cohesion metric is very promising and may lead to improved results. Musaad Alzahrani, Saad Alqithami, Austin Melton |
COMPSAC (1) | 1 |
| 2017 | Defining and Validating a Client-Based Cohesion Metric for Object-Oriented ClassesabstractCohesion of a software module broadly refers to the relatedness of the elements of the module. A highly cohesive module has elements that all contribute to a single common purpose. Such modules are believed to be more understandable and maintainable. Most existing object-oriented class cohesion metrics measure the cohesion of a class based on internal connections between the methods of the class where two methods are internally connected if they both reference common attributes in the class. In this paper, we propose a client-based class cohesion metric which we name CCC and which measures the cohesion of a class based on how its public methods are used by its clients. The required information for CCC to calculate the cohesion of a class can be extracted during the high-level design phase from class and communication diagrams defined by the Unified Modeling Language (UML). We validate the proposed metric theoretically, and we empirically demonstrate its usefulness. Theoretically, we analyze the compliance of CCC with the cohesion metric properties. Empirically, we investigate the relations between fourteen class cohesion metrics, including CCC, to determine if CCC captures an aspect of cohesion that is not addressed by the other class cohesion metrics. Moreover, we analyze the extent to which the fourteen class cohesion metrics, including CCC, can individually and in combination predict class testability in terms of testing effort. Our results show that CCC captures an aspect of class cohesion that has not been addressed by the other metrics and that CCC is a predictor for class testability in terms of testing effort. Musaad Alzahrani, Austin Melton |
COMPSAC (1) | 1 |
| 2014 | Instability and Abstractness Metrics Based on ResponsibilityabstractOver the last few decades, a lot of research has been done to measure software quality including using high-level design metrics to measure the quality of the design. R. C. Martin's metrics are some of the best-known software package metrics. Martin began with a set of object oriented design principles and designed his metrics based on these principles. In this paper we begin with Martin's principles and use them to modify his instability and abstractness metrics which were defined to identify poorly designed packages which are hard to maintain and reuse. We modify Martin's metrics based on the concept of responsibility, our motivation is that packages with different levels of responsibility should have different weights with respect to the instability and abstraction metrics. We present a case study to validate the modified metrics, the comparative study shows the differences between the proposed metrics and Martin's metrics. We found that the proposed instability and abstractness metrics are very promising and lead to improved results. Saleh Almugrin, Waleed Albattah, Omar Alaql, Musaad Alzahrani, Austin Melton |
COMPSAC | 4 |