VLDB 2026 Research / reviewers in the wild / expert
Alireza Shameli-Sendi
dblp:23/8338 · also Alireza Shameli Shameli-Sendi
· DBLP profile ↗
23ranked-venue papers
11as first author
7since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 4 first-author · 1 since 2021Software engineering, systems software and programming languages · 6 · 1 first-author · 3 since 2021Security and privacy · 5 · 4 first-authorSystems, architecture and hardware · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | An Intelligent VM Placement Method for Minimizing Energy Cost and Carbon Emission in Distributed Cloud Data Centers
Ehsan Rasoulpour Shabestari, Alireza Shameli-Sendi |
J. Grid Comput. | 2 |
| 2024 | Reducing cold start delay in serverless computing using lightweight virtual machines
Amirmohammad Karamzadeh, Alireza Shameli-Sendi |
J. Netw. Comput. Appl. | 2 |
| 2023 | A multi-objective cloud energy optimizer algorithm for federated environments
Ehsan Khodayarseresht, Alireza Shameli-Sendi |
J. Parallel Distributed Comput. | 2 |
| 2023 | Anomaly detection on OpenStack logs based on an improved robust principal component analysis model and its projection onto column spaceabstractAbstract With the advent of technology and the development of more complex software systems, the size of logs generated by these systems has increasingly risen so that the anomaly detection for remediating common errors has been more difficult than ever. The cloud emergence in the information technology (IT) industry has led to the immigration of enterprises toward it, which has extended the application of cloud management stacks such as OpenStack. By using the OpenStack platform, users can access resource infrastructure and manage virtual machines (VMs). The anomaly detection in OpenStack logs is not realized conveniently due to the substantial size of logs, and it is required to automate this process. Since there is no appropriate open‐source dataset for OpenStack logs, we have generated 25,000 logs by injecting three types of anomalies to propose a more efficient technique in terms of performance and time in detecting anomalies in OpenStack logs relative to recent studies by proper OpenStack log parsing and analyzing these logs by data mining algorithms. To this end, compared to the previous research study, we could improve the anomaly detection performance in terms of F1 score, recall, and precision by 9%, 4%, and 14%, respectively, and decrease the running time relative to the log size by at least 30 s. Parisa Sadat Kalaki, Alireza Shameli-Sendi, Behzad Khalaji Emamzadeh Abbasi |
Softw. Pract. Exp. | 2 |
| 2023 | Detection of microservice-based software anomalies based on OpenTracing in cloudabstractSummary Today, the noticeable tendency of the software industry to break large software projects into loosely coupled modules through a microservice‐based architecture is more than ever. This is because of advantages such as scalability, independence, smaller and faster deployments, improved fault isolation, and flexibility. On the other hand, it should be noted that with the growth of microservice architecture, new complexities have emerged. We need to have a mature DevOps team to handle the complexity involved in maintaining and supporting systems, namely functional and non‐functional monitoring (anomaly monitoring and detection). This challenge can lead to a lot of software development time being spent monitoring and identifying anomalies. Existing approaches are not accurate enough to identify anomalies, and if they are able to identify them, they are unable to identify the category of the anomaly. Our approach in this research is to use distributed tracing with the help of machine learning algorithms to identify performance anomalies, the exact location of each anomaly, and predict its category. In this research, we implemented a software based on microservice architecture and then created a variety of anomalies over time (e.g., physical resources, virtual resources, database, application) to be able to evaluate the proposed model. The resulting dataset is publicly available. Our simulation results show that the proposed model is able to accurately identify the anomalies with 98% accuracy and their category with 99% accuracy. Mohammad Khanahmadi, Alireza Shameli-Sendi, Masoume Jabbarifar, Quentin Fournier, Michel R. Dagenais |
Softw. Pract. Exp. | 2 |
| 2023 | Automating the Translation of Cloud Users' High-Level Security Needs to an Optimal Placement Model in the Cloud InfrastructureabstractDeploying network security functions in the cloud to protect the application, dynamically and with different goals, has been one of the most important topics. An example of these functions can be firewall, DPI, or IDS, which can be placed between different layers of applications as needed. So far, many works have been done regarding the placement of network security functions in the cloud, considering various goals, such as minimizing the consumption of resources, energy consumption, and the cost of users or the service provider. One of the required tasks in this field is to automate the translation of users’ security needs into a placement model to be executed by a solver. In all works, this translation is not considered due to the lack of a model or pattern, and it is assumed that the user has a specific requirement, and as a result, more focus is placed on optimizing the placement or placing the functions in the right place. In order to execute the optimal placement algorithms, we need appropriate goals and related constraints. In this paper, for the first time, a model is proposed to translate high-level user needs to the goals and constraints of the optimal placement algorithm. To ensure the accuracy of the generated placement models, three different scenarios have been considered from the cloud user’s point of view, and the generated placement model has been implemented in the popular Fat-tree topology with the number of nodes from 36 to 540,800. The real scenarios presented in the paper and the accuracy of the output produced by automation model can be welcomed by cloud service providers. Amin Bagheri, Alireza Shameli-Sendi |
IEEE Trans. Serv. Comput. | 2 |
| 2021 | A Scalable Stateful Approach for Virtual Security Functions OrchestrationabstractPrevious works suggested different approaches to implementing service chaining. Their goal is to enhance the performance of the middleboxes and satisfy the expectations of the cloud providers and users. To meet these expectations, the delay factor, i.e., flow through the low-cost paths, as well as the best node processing factor, are considered. Achieving these two goals simultaneously turns the middlebox optimal placement into an NP-hard problem. Therefore, when the problem size is large, it is infeasible to obtain an optimal solution at a reasonable time. One of the important issues which has not been considered in the previous works is stateful optimal placement when receiving a new request. Due to resource constraints as well as financial costs for the customers, it is not possible to create functions for all requests. Therefore, not only it is possible to integrate the same network functions between new flows, but it will also be examined between new on-demand network functions as well as existing ones. Our proposed approach not only reduces the creation of network functions that can be cost-effective for the customer but also because of the migration of previous network functions (integration with on-demand network functions) to optimize new requests, overall, it will optimize the entire network cost over time. We formulated the problem as 0-1 programming problem. The results of this article are based on a fat-tree data center. To show that our stateful solution is scalable in large networks, we use network zoning and topology partitioning heuristics. Our simulations show that we were able to scale our placement model to a network with 54K nodes and 1.5M edges. Niloofar Moradi, Alireza Shameli-Sendi, Alireza Khajouei |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2020 | An efficient security data-driven approach for implementing risk assessment
Alireza Shameli-Sendi |
J. Inf. Secur. Appl. | 1 |
| 2020 | Dynamic Firewall Decomposition and Composition in the CloudabstractFirewalls filter malicious traffic and provide the network with a satisfying level of security. Thus, their performance is critical for the whole network. Rule-based firewalls are the most widely deployed among traditional ones. However, as the size of the rule list of a firewall increases, lookup latency increases significantly. One main solution to enhance the performance of a firewall is to reorder rules based on traffic characteristics to obtain the minimum number of packet matches. The optimal firewall rule ordering problem (ORO) is NP-Complete. Therefore, setting up a centralized firewall for a whole network is infeasible. Our proposed solution dynamically scales in and out firewalls across multiple administrative domains for more efficient rules optimization, filtering, and better attack response. The proposed solution, in this paper, outsources the firewall functions into micro firewalls, which are located in different places and have their configurations. Therefore, traffic is treated locally and in a distributed way. The experimental results show that our proposed solution is scalable regarding the organization's network requirements. Moreover, the central firewall is relaxed executing rules optimization algorithms in consecutive time intervals, inefficiency. Sima Bagheri, Alireza Shameli-Sendi |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | A scalable network-aware framework for cloud monitoring orchestration
Masoume Jabbarifar, Alireza Shameli-Sendi, Bettina Kemme |
J. Netw. Comput. Appl. | 2 |
| 2019 | Efficient Provisioning of Security Service Function Chaining Using Network Security Defense PatternsabstractNetwork functions virtualization intertwined with software-defined networking opens up great opportunities for flexible provisioning and composition of network functions, known as network service chaining. In the cloud, this allows providers to create service chains tuned to each application type while optimizing resources' utilization. This is particularly useful to accommodate different tenants' applications with different security needs. However, considering security provisioning from the single perspective of resources optimization may lead to deployment solutions that do not comply with well-known security-related best practices and recommendations. In this paper, we propose network security defense patterns (NSDP) aimed at leveraging the best practice and know-how from the security experts and at capturing various security constraints to efficiently select compliant security functions' deployment options. The placement problem being a NP-Hard problem to solve, we also propose a scalable networking and computing resources aware optimization framework to efficiently provision different NSDPs. We further show the feasibility of implementing NSDPs in the cloud infrastructure through the integration of our approach into an open source cloud framework, namely OpenStack, in our test laboratory. The simulation results show the effectiveness of our approach in selecting an optimal placement of the security functions for large data centers with hundreds of thousands of computing nodes, while complying with the predefined security constraints and improving the scalability compared to the current placement algorithms. Alireza Shameli-Sendi, Yosr Jarraya, Makan Pourzandi, Mohamed Cheriet |
IEEE Trans. Serv. Comput. | 1 |
| 2018 | Software Project Estimation Using Improved Use Case PointabstractEstimating metrics, such as effort, schedule and cost, needed for a software to be created and launched into market have significant economical effects. One of the most extensively utilized method for such estimation is a technique called Use Case Points. It is based on the use case modeling which is a popular and widely used technique for capturing and describing the functional requirements of a software system. In this paper multitude number of techniques have been proposed as the basis for improving estimation of the effort, schedule, and costs of software projects. These terms are conceptually similar but utilize different parameter values and metrics. Moreover, different versions of use case points have been proposed. This method suffers some limitations such as less accuracy, failure to consider software risks, failure to consider software quality aspects, failure to consider different levels of software security, and so on. The aim of this paper is to propose a new approach for cost estimation, based on use case points method, by considering all the existing risks related to software projects. The results indicate that the new estimation approach can produce relatively accurate estimates and also declare various aspects of project risks during project estimation. Our results also provide guidance for organizations that want to develop a software project. Sima Bagheri, Alireza Shameli-Sendi |
SERA | 2 |
| 2018 | Realtime intrusion risk assessment model based on attack and service dependency graphs
Alireza Shameli-Sendi, Michel R. Dagenais, Lingyu Wang 0001 |
Comput. Commun. | 1 |
| 2018 | Dynamic Optimal Countermeasure Selection for Intrusion Response SystemabstractDesigning an efficient defense framework is challenging with respect to a network's complexity, widespread sophisticated attacks, attackers' ability, and the diversity of security appliances. The Intrusion Response System (IRS) is intended to respond automatically to incidents by attuning the attack damage and countermeasure costs. The existing approaches inherit some limitations, such as using static countermeasure effectiveness, static countermeasure deployment cost, or neglecting the countermeasures' negative impact on service quality (QoS). These limitations may lead the IRS to select inappropriate countermeasures and deployment locations, which in turn may reduce network performance and disconnect legitimate users. In this paper, we propose a dynamic defense framework that selects an optimal countermeasure against different attack damage costs. To measure the attack damage cost, we propose a novel defense-centric model based on a service dependency graph. To select the optimal countermeasure dynamically, we formulate the problem at hand using a multi-objective optimization concept that maximizes the security benefit, minimizes the negative impact on users and services, and minimizes the security deployment cost with respect to the attack damage cost. Alireza Shameli-Sendi, Habib Louafi, Wenbo He 0003, Mohamed Cheriet |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2017 | Payless Monitoring Service for Tenants in Cloud with Traffic and Energy-Aware Function DeploymentabstractMany applications are distributed in cloud as they consist of different modules and tiers. Cloud tenant must be able to monitor the deployed applications to ensure that it is operating correctly, meeting its SLAs, and fulfilling business requirements. Activating all type of monitoring functions for all tenant's applications at the same time is costly. The more required monitoring functions the more allocated cloud resources. Moreover, it incurs monetary cost for tenants. In this paper, the problem of virtual monitoring function (vMF) placement for service chains is modeled by maximizing both the network and computing resource utilization. Beside that, we propose a set of tenant policies, which are either monetary-driven or performance-driven, translated as constrains in optimal placement algorithm. Simulation results show that the proposed model can reduce the total incurred cost by up to 10% compared to the best non-optimal heuristic. Moreover, the proposed model can decrease the execution time about 84% compared to the basic solution. Alireza Shameli-Sendi, Habib Louafi, Mohamed Cheriet |
CloudCom | 1 |
| 2016 | Taxonomy of information security risk assessment (ISRA)
Alireza Shameli-Sendi, Rouzbeh Aghababaei-Barzegar, Mohamed Cheriet |
Comput. Secur. | 1 |
| 2015 | Multistage OCDO: Scalable Security Provisioning Optimization in SDN-Based CloudabstractCloud computing is increasingly changing the landscape of computing, however, one of the main issues that is refraining potential customers from adopting the cloud is the security. Network functions virtualization together with software-defined networking can be used to efficiently coordinate different network security functionality in the network. To squeeze the best out of network capabilities, there is need for algorithms for optimal placement of the security functionality in the cloud infrastructure. However, due to the large number of flows to be considered and complexity of interactions in these networks, the classical placement algorithms are not scalable. To address this issue, we elaborate an optimization framework, namely OCDO, that provides adequate and scalable network security provisioning and deployment in the cloud. Our approach is based on an innovative multistage approach that combines together decomposition and segmentation techniques to the problem of security functions placement while coping with the complexity and the scalability of such an optimization problem. We present the results of multiple scenarios to assess the efficiency and the adequacy of our framework. We also describe our prototype implementation of the framework integrated into an open source cloud framework, i.e. Open stack. Yosr Jarraya, Alireza Shameli-Sendi, Makan Pourzandi, Mohamed Cheriet |
CLOUD | 2 |
| 2015 | Optimal placement of sequentially ordered virtual security appliances in the cloudabstractTraditional enterprise network security is based on the deployment of security appliances placed on some specific locations filtering, monitoring the traffic going through them. In this perspective, security appliances are chained in specific order to perform different security functions on the traffic. In the cloud, the same approach is often adopted using virtual security appliances to protect traffic for different virtual applications with the challenge of dealing with the flexible and elastic nature of the cloud. In this paper, we investigate the problem of placing virtual security appliances within the data center in order to minimize network latency and computing costs for security functions while maintaining the required sequential order of traversing virtual security appliances. We propose a new algorithm computing the best place to deploy these virtual security appliances in the data center. We further integrated our placement algorithm in an open source cloud framework, i.e. Openstack, in our test laboratory. The preliminary results show that we are placing the virtual security appliances in the required sequential order while improving the efficiency compared to the current default placement algorithm in Openstack. Alireza Shameli-Sendi, Yosr Jarraya, Mohamed Fekih Ahmed, Makan Pourzandi, Chamseddine Talhi, Mohamed Cheriet |
IM | 1 |
| 2015 | ORCEF: Online response cost evaluation framework for intrusion response system
Alireza Shameli-Sendi, Michel R. Dagenais |
J. Netw. Comput. Appl. | 1 |
| 2015 | Taxonomy of Distributed Denial of Service mitigation approaches for cloud computingabstractCloud computing has a central role to play in meeting today׳s business requirements. However, Distributed Denial-of-Service (DDoS) attacks can threaten the availability of cloud functionalities. In recent years, many effort has been expended to detect the various DDoS attack types. In this survey paper, our concentration is on how to mitigate these attacks. We believe that cloud computing technology can substantially change the way we respond to a DDoS attack, based on a number of new characteristics, which were introduced with the advent of this technology. We first present a new taxonomy of DDoS mitigation strategies to organize the work. Then, we go on to discuss the main features of existing DDoS mitigation strategies and explain their functionalities in the cloud environment. Afterwards, we show how the existing DDoS mechanisms fit into the network topology of the cloud. Finally, we discuss some of these DDoS mechanisms in detail, and compare their behavior in the cloud. Our objective is to show how these characteristics bring a novel perspective to existing DDoS mechanisms, and so give researchers new insights into how to mitigate DDoS attacks in the cloud computing. Alireza Shameli-Sendi, Makan Pourzandi, Mohamed Fekih Ahmed, Mohamed Cheriet |
J. Netw. Comput. Appl. | 1 |
| 2014 | Cloud Computing: A Risk Assessment ModelabstractCloud computing has recently emerged compelling paradigm by introducing several characteristics such as on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. Despite the fact that cloud computing offers huge cost benefits for companies, the unique security challenges have been introduced in a cloud environment that make risk assessment challenging. Cloud consumers need a protection to their cloud applications against cyber attacks. Although some security controls and policies are devised for each element of cloud computing, we need a framework with overall quantitative risk assessment model. The aim of this paper is to propose a framework for assessing the security risks associated with cloud computing platforms. The fully quantitative, iterative, and incremental approach enables cloud customer/provider to assess and manage cloud security risks. A proper result of risk assessment leads to have appropriate risk management mechanism for mitigating risks and reach to an acceptance security level. Alireza Shameli-Sendi, Mohamed Cheriet |
IC2E | 1 |
| 2014 | Taxonomy of intrusion risk assessment and response system
Alireza Shameli-Sendi, Mohamed Cheriet, Abdelwahab Hamou-Lhadj |
Comput. Secur. | 1 |
| 2010 | L-SYNC: Larger Degree Clustering Based Time-Synchronisation for Wireless Sensor NetworkabstractIn many existing synchronization protocols within wireless sensor networks, the effect of routing algorithm in synchronization precision of two remote nodes is not being considered. In several protocols such as SLTP, this issue is considered for local time estimation of a remote node. Cluster creation is according to ID technique. This technique incurs an increase in cluster overlapping and eventually the routing algorithm will be affected and requires more hops to move from one cluster to another remote cluster. In this article, we present L-SYNC method, which creates large degree clusters for wireless sensor networks synchronization. Using large degree clustering, L-SYNC can reduce path hops. Also, LSYNC uses linear regression method to calculate clock offset and skew in each cluster. Therefore, it is capable to compute skew and offset intervals between each node and its head cluster and, in other words, it can estimate the local time of remote nodes in future and past. To estimate the local time for remote nodes, routing algorithm is used and conversion technique is performed in each time changing hop. The fewer L-SYNC hops could increase the precision. Simulation results illustrate that monotonous clustering formation can increase the precision in synchronization. However, more overhead and time period are needed for clustering formation. Masoume Jabbarifar, Alireza Shameli-Sendi, Hossein Pedram, Mehdi Dehghan 0001, Michel R. Dagenais |
SERA | 2 |