Maha Sroor

dblp:333/3008 · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0001-6998-7358ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 4 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Managing security issues in software containers: From practitioners' perspective
abstract
Software development industries are increasingly adopting containers to enhance the scalability and flexibility of applications. Security in containerized projects is a critical challenge that can lead to data breaches and performance degradation, thereby directly affecting the reliability and operations of the container services. Despite the ongoing effort to manage the security issues in containerized projects in SE research, more investigations are needed to explore the human perspective of security management in containerized projects. This research aims to explore security management in containerized projects by exploring how SE practitioners manage the security issues in containerized projects. A clear understanding of security management in containerized projects will enable industries to develop robust security strategies that enhance software reliability and trust. To achieve this, we conducted two semi-structured interview studies to examine how practitioners approach security management. The first study focused on practitioners’ perceptions of security challenges in containerized environments, where we interviewed 15 participants between December 2022 and October 2023. The second study explored how to address security issues, with 20 participants interviewed between October 2024 and December 2024. Data analysis reveals how SE practitioners address the various security challenges in containerized projects. Our analysis also identified the technical and non-technical enablers that can be utilized to enhance security in containerized projects. Overall, we propose a conceptual model that visualizes how practitioners manage security issues in containerized projects. We argue that our proposed model will guide practitioners in making informed decisions to plan, develop, and deploy secure container systems.
Maha Sroor, Rahul Mohanani, Ricardo Colomo-Palacios, Sandun Dasanayake, Tommi Mikkonen
J. Syst. Softw.1
2025 A Systematic Mapping Study on Risks and Vulnerabilities in Software Containers
abstract
Software containers are widely adopted for developing and deploying software applications. Despite their popularity, major security concerns arise during container development and deployment. Software engineering (SE) research literature reveals a lack of reviewed, aggregated and organized knowledge of risks and vulnerabilities, security practices, and tools in container-based systems development and deployment. Therefore, we conducted a Systematic Mapping Study (SMS) based on 129 selected primary studies to explore and organize existing knowledge on security issues in software container systems. Data from the primary studies enabled us to identify critical risks and vulnerabilities across the container life-cycle and categorize them using a novel taxonomy. Additionally, the findings highlight the causes and implications and provide a list of mitigation techniques to overcome these risks and vulnerabilities. Furthermore, we provide an aggregation of security practices and tools that can help support and improve the overall security of container systems. This study offers critical insights into the current landscape of security issues within software container systems. Our analysis highlights the need for future SE research to focus on security enhancement practices that strengthen container systems and develop effective mitigation strategies to comprehensively address existing risks and vulnerabilities.
Maha Sroor, Teerath Das, Rahul Mohanani, Tommi Mikkonen
APSEC1
2024 Practitioners' Perceptions of Security Issues in Software Containers: A Qualitative Study
abstract
Software containers have emerged as solutions for developing and deploying software applications. Despite the popularity and portability of containers, there is significant concern about container security, which hinders their adoption. Recent research has made efforts to investigate container security theoretically and experimentally. Meanwhile, software practitioners have also developed practices to improve and maintain container security based on their work experience. However, a notable gap exists in expressing practitioners' viewpoints on container security. Consequently, this study aims to understand practitioners' perceptions of container security and their man-agement strategies in real-world projects. We conducted semi-structured interviews with practitioners across various domains to explore their opinions on container security issues, causes, implications, tools, and practices. Our data analysis reveals emergent patterns in handling container security in real projects. These patterns are presented as a model that highlights the relationships between the major themes and how they affect each other. Our findings reveal that containers offer many advantages to software systems but face challenges in maintaining security. Finally, this research attempts to bridge the knowledge gap between academia and industry by providing a comprehensive understanding of container security issues as perceived by the practitioners and their interrelationships.
Maha Sroor, Rahul Mohanani, Teerath Das, Tommi Mikkonen, Sandun Dasanayake
SEAA1
2023 Anomaly Detection Through Container Testing: A Survey of Company Practices
Salla Timonen, Maha Sroor, Rahul Mohanani, Tommi Mikkonen
PROFES (1)2
2022 Leverage Software Containers Adoption by Decreasing Cyber Risks and Systemizing Refactoring of Monolithic Applications
Maha Sroor
PROFES1