Rafiq Ahmad Khan

dblp:223/3146 · DBLP profile ↗
← Back
10ranked-venue papers
7as first author
8since 2021 · last 2025
0000-0002-5983-9981ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 9 · 7 first-author · 7 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2025 A SWOT Analysis of Software Development Life Cycle Security Metrics
abstract
ABSTRACT Cyber security is an ongoing and critical concern due to persistent threats posed by threat actors, such as hackers and crackers. With the development of information and communication technologies (ICT), the widespread usage of software systems has transformed modern society in many ways but also created new issues in protecting confidential and sensitive information. The quantification of security measures can provide evidence to support decision‐making in software security, particularly when assessing the security performance of software systems. This entails understanding the key quality criteria of security metrics, which can assist in constructing security models aligned with practical requirements. To delve deeper into this subject, the current study conducted a systematic literature review (SLR) on security metrics and measures within the realm of secure software development (SSD). The study selected 61 research publications for data extraction based on the specific inclusion and exclusion criteria. The study identified 215 software security metrics and classified them into different phases of software development life cycle (SDLC). In order to evaluate the most cited metrics in each phase of SDLC, the strengths, weaknesses, opportunities, and threats (SWOT) analysis was performed. The SWOT analysis offers a structured framework enabling researchers to make more effective, well‐informed decisions and mitigate potential risks, ultimately contributing to more valuable research findings. The study's findings provide researchers guidance for exploring emerging trends and addressing existing gaps in SDLC. This study also provides software professionals with a more comprehensive understanding of security measurements, constraints, and open‐ended specific and general issues.
Ayesha Khalid, Mushtaq Raza, Palwasha Afsar, Rafiq Ahmad Khan, Muhammad Ismail Mohmand, Hanif Ur Rahman
J. Softw. Evol. Process.4
2025 Securing Software Development Through People Maturity: A Fuzzy-AHP Decision-Making Framework
abstract
ABSTRACT The increasing complexity of software development processes has heightened the need for robust security measures. Although technical safeguards are essential, the role of human factors in securing software development remains underexplored. This paper presents a novel approach that integrates people's maturity with a fuzzy analytic hierarchy process (Fuzzy‐AHP) decision‐making framework to enhance the security in software development. The framework provides a systematic method for evaluating and prioritizing human factors that influence an organization's security posture, such as team‐expertized communication and adherence to security protocols. Using the decision‐making model allows the project managers and stakeholders to determine the appropriate areas for improvement and develop the right strategies and actions to nurture a secure and mature development culture. The paper identifies 24 human success factors (HSFs) and human security vulnerabilities (HSVs) and 38 practices for addressing these HSFs and HSVs through systematic literature review (SLR) and empirical survey. Furthermore, we discuss the local and global ranks of each HSF and HSV practice and categorize the identified practices into nine categories to determine the ranks and weight of each category. Based on collected data, Fuzzy‐AHP prioritized these practices; the category “C4: Skill development and stakeholder engagement” is ranked highest at rank‐1 and possesses the most significant weight of 0.12435. Similarly, the highest global weight is 0.051506, and the global ranked (rank‐1) HSF and HSV practice is “P15: Hands‐on practice and stakeholder communication.” The proposed approach complements existing technical methods by addressing the human element of security, making it adaptable to diverse organizational environments. Through this integration of people maturity and Fuzzy‐AHP, the paper contributes a new dimension to securing software development, emphasizing the critical role of human factors in achieving comprehensive security.
Rafiq Ahmad Khan, Hussein Ali Al Hashimi, Hathal Alwageed, Ismail Mohamed Keshta, Alaa Omran Almagrabi, Sarra Ayouni
J. Softw. Evol. Process.1
2025 A Fuzzy-AHP Decision-Making Framework for Optimizing Software Maintenance and Deployment in Information Security Systems
abstract
ABSTRACT Information System Security (ISS) is the primary economic lever for the global economy. It is the cornerstone for value generation, and its absence undeniably affects technology, people, and finances. The emergence of the worldwide information society has introduced fresh economic and legal challenges attributed to the surge in Internet utilization and advancements in the digital economy. Ensuring the security of advancements within information systems has emerged as a primary concern in propelling the evolution of information processes within the software development industry. This study aims to develop and propose a Fuzzy Analytic Hierarchy Process (Fuzzy‐AHP) framework to enhance decision‐making for software maintenance and deployment in ISS. This framework aims to provide a systematic, flexible method for evaluating and prioritizing multiple conflicting criteria under conditions of uncertainty. The study initially adopts an empirical survey to identify software security maintenance and deployment risks and their practices for ISS organizations. Then adopts the Fuzzy‐AHP method to handle the imprecision of expert judgments and organizes decision‐making into a hierarchical structure. The framework is applied to evaluate key criteria related to software maintenance and deployment, including security risks, system performance, operational costs, and compliance requirements. Data from 50 ISS experts were collected and used to validate the framework. The paper identifies 52 security risks in maintenance and deployment (SRMD) processes in ISS and also identified 139 best practices for ensuring security, including regular updates, patch management, and adherence to industry‐standard security protocols. The Fuzzy‐AHP framework effectively structured the decision‐making process by prioritizing criteria and sub‐criteria. The results demonstrated that the framework helps mitigate the subjective biases in expert judgment and provides a more balanced assessment of maintenance and deployment strategies. Prioritizing security risks and compliance emerged as key factors in the decision‐making process. The proposed Fuzzy‐AHP framework provides an innovative and adaptable solution for optimizing ISS organizations' software maintenance and deployment decisions. It addresses the complexity and uncertainty involved in such decisions, offering a transparent and structured approach that improves the accuracy and reliability of outcomes. Future research should focus on empirical validation of the framework in real‐world case studies and expand its application to other industries with similar decision‐making needs.
Rafiq Ahmad Khan, Ismail Mohamed Keshta, Hussein Ali Al Hashimi, Alaa Omran Almagrabi, Hathal Alwageed, Musaad Alzahrani
J. Softw. Evol. Process.1
2024 Evaluation of requirement engineering best practices for secure software development in GSD: An ISM analysis
abstract
Abstract Technological advancement makes the world a global village. Security is an evergreen and everlasting area, because of the continuous threat from Hackers and Crackers. The immense use of software systems has modernized human society in every aspect. Thus, it is crucial to devise new processes, techniques, and tools to support teams in the development of secure code from the early stages of the software development process, while potentially reducing the costs and shortening the time to market. Considering the significance of software security, it is important to consider the security practices from the early phase of the software development life cycle (SDLC), that is, requirements engineering (RE). Hence, this study aims to identify and categorize RE practices important to apply for secure software development (SSD) in a geographically distributed development environment. To study the RE practices concerning SSD, we conducted a questionnaire survey with industrial experts in the global software development (GSD) context. Furthermore, the interpretive structure modeling (ISM) approach was applied to evaluate the relationship between the RE security practice core categories. This paper identifies 70 practices and classifies them into 11 fundamental dimensions (categories) to assist GSD organizations in specifying the requirements for SSD. The ISM results show that the “Awareness of Secure Requirement Engineering (SRE)” category has the most decisive influence on the other 10 core categories of the identified RE security practices. With the help of empirical evidence and the ISM approach, this work attempts to identify potential security practices and to give a set of secure RE practices that can be used to improve the security of the software development process.
Rafiq Ahmad Khan, Muhammad Azeem Akbar, Saima Rafi, Alaa Omran Almagrabi, Musaad Alzahrani
J. Softw. Evol. Process.1
2024 Security risks of global software development life cycle: Industry practitioner's perspective
abstract
Abstract Software security has become increasingly important because the malicious attack and other hacker risks of a computer system have grown popularity in the last few years. As a result, several researchers have examined security solutions as early as the requirement engineering phase. With the growth of the software business and the internet, there is a need to understand the security risks against each phase of the software development life cycle (SDLC). This study aims to empirically investigate and prioritize the risks that could negatively impact the software security aspects of SDLC in the context of global software development (GSD). To achieve the study objectives, we conducted an industrial empirical study to determine the impact of software security threats against each phase of SDLC. Furthermore, the fuzzy analytical hierarchy process (FAHP) was used to prioritize the list of software security risks against the SDLC. The results and analysis of this study provide a ranked‐based decision‐making framework, which assists the practitioners in considering the most critical security risks on priority. The results show “improper plan for secure requirement identification, inception, authentication, authorization, and privacy,” “lack of threat models updating,” “lack of output validation,” “lack of certification in the final release and archive,” and “spoofing” as the top‐ranked security risks of SDLC in GSD. In addition, the application of FAHP is novel in this domain as it is helpful to address multicriteria decision‐making problems.
Rafiq Ahmad Khan, Siffat Ullah Khan, Muhammad Azeem Akbar, Musaad Alzahrani
J. Softw. Evol. Process.1
2022 Exploring Security Procedures in Secure Software Engineering: A Systematic Mapping Study
abstract
Various new technologies have developed as software security solutions have become more critical. One of the essential parts of software quality is the product's security. Though providing examples covering all phases of secure software development is necessary, very few of these situations have been documented. More than a few approaches have been proposed and implemented to handle software security, but only a few of them provide valid evidence for developing secure software applications. This paper presents the results of a Systematic Mapping Study (SMS), which was carried out to determine the existence of software security metrics, tools, standards, and security-related research topics mainly discussed and addressed. A total of 116 studies were chosen for inclusion in this review. Selected studies led us to discover 55 Secure Software Engineering (SSE) metrics, 68 SSE tools, 33 SSE standards, and 12 SSE research topics that have been discussed and addressed. This effort will aid software development firms in better understanding existing security measures employed in creating secure software. It can also serve as a foundation for researchers to build and create new software security solutions and identify new research directions.
Rafiq Ahmad Khan, Siffat Ullah Khan, Muhammad Ilyas 0002
EASE1
2022 Change Management in Cloud-Based Offshore Software Development: A Researchers Perspective
Muhammad Azeem Akbar, Saima Rafi, Rafiq Ahmad Khan, Muhammad Tanveer Riaz
PROFES4
2021 Challenges and Their Practices in Adoption of Hybrid Cloud Computing: An Analytical Hierarchy Approach
abstract
Cloud computing adoption provides various advantages for companies. In particular, hybrid cloud shares the advantages of both the public and private cloud technologies because it combines the private in-house cloud with the public on-demand cloud. In order to obtain benefits from the opportunities provided by the hybrid cloud, organizations want to adopt or develop novel capabilities. Maturity models have proved to be an exceptional and easily available method for evaluating and improving capabilities. However, there is a dire need for a robust framework that helps client organizations in the adoption and assessment of hybrid cloud. Therefore, this research paper aims to present a taxonomy of the challenging factors faced by client organizations in the adoption of hybrid cloud. Typically, such a taxonomy is presented on the basis of obtained results from the empirical analysis with the execution of analytical hierarchy process (AHP) method. From the review of literature and empirical study, in total 13 challenging factors are recognized and plotted into four groups: “Lack of Inclination,” “Lack of Readiness,” “Lack of Adoption,” and “Lack of Satisfaction.” The AHP technique is executed to prioritize the identified factors and their groups. By this way, we found that “Lack of Adoption” and “Lack of Satisfaction” are the most significant groups from the identified challenging factors. Findings from AHP also show that “public cloud security concern” and “achieving QoS” are the upper ranking factors confronted in the adoption of hybrid cloud mechanism by client organizations because their global weight (0.201) is greater than those of all the other reported challenging factors. We also found out 46 practices to address the identified challenges. The taxonomy developed in this study offers a comprehensive structure for dealing with hybrid cloud computing issues, which is essential for the success and advancement of client and vendor organizations in hybrid cloud computing relationships.
Siffat Ullah Khan, Habib Ullah Khan, Rafiq Ahmad Khan
Secur. Commun. Networks4
2020 The State of the Art on Secure Software Engineering: A Systematic Mapping Study
abstract
Secure Software Development (SSD) is becoming a major challenge, due to the increasing complexity, openness and extensibility of Information and Communication Technologies (ICTs). These make the overall security requirements analysis very difficult. Many techniques have been theoretically developed, however, there is a lack of empirical evidence of its application in building secure software system. A Systematic Mapping Study (SMS) has been conducted in this paper to examine the existence of software security frameworks, models and methods. In total, we selected 116 primary studies. After examining the selected studies, we identified 37 Secure Software Engineering (SSE) paradigms/frameworks/models. The results show that the most frequently used SSE frameworks/models are "Microsoft Software Development Life Cycle (MS-SDL)", "Misuse case modeling", "Abuse case modeling", "Knowledge Acquisition for Automated Specification", "System Security Engineering-Capability Maturity Model (SSE-CMM)" and "Secure Tropos Methodology". This work will help organizations in the development of software to better understand existing security initiatives used in the development of secure software. It can also provide researchers with a basis for designing and developing new methods of software security and identifying new axis of research.
Rafiq Ahmad Khan, Siffat Ullah Khan, Muhammad Ilyas 0002, Mohammad Yazid Bin Idris
EASE1
2018 A preliminary structure of software security assurance model
abstract
Software security is an important aspect that needs to be considered during the entire software development life cycle (SDLC). Integrating software security at each phase of SDLC has become an urgent need. To address software security, various approaches, techniques, methods, practices, and models have been proposed and developed. However, recent research shows that many software development methodologies do not explicitly include methods for incorporating software security during the development of software as it evolves from requirements engineering to its final disposal. The primary objective of this research is to study the state-of-the-art of security in the context of SDLC by following systematic mapping study (SMS). In the second phase, we will identify, through systematic literature review (SLR) and empirical study in the industry, the software security contributions, security challenges and their practices for global software development (GSD) vendors. The ultimate aim is to develop a Software Security Assurance Model (SSAM) to assist GSD vendor organisations in measuring their readiness towards the development of secure software.
Rafiq Ahmad Khan, Siffat Ullah Khan
ICGSE1