Bahman Zamani

dblp:82/4850 · DBLP profile ↗
← Back
26ranked-venue papers
3as first author
13since 2021 · last 2026
0000-0001-6424-1442ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 21 · 2 first-author · 10 since 2021Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 HarmonyCAS: A model-driven framework for facilitating interoperability in context-aware systems
Hamed Barangi, Shekoufeh Kolahdouz Rahimi, Bahman Zamani, Hossein Moradi
J. Syst. Softw.3
2026 A Formal Lens on Android Permissions System: Modeling, Verification, and Exploitation Using LLMs and Model Checking
abstract
The Android Permissions System (APS) is a permission-based access control mechanism that controls the applications’ access to protected resources such as user contacts and GPS locations. The evolution of APS—as a critical component of Android—has made the user experience more convenient. However, the vulnerabilities and attacks targeting the APS indicate that its thorough security analysis is essential to ensure system security and to protect user information. Although previous works applied formal methods to verify the security of APS, its new capabilities, such as One-Time Permissions (OTPs), have not yet been studied. In this article, we present a model checking approach for security verification of APS that supports OTPs. We use Large Language Models in a Chain-of-Thought process to assist in extracting the behavior of APS from its documentation and source code to design a formal model and a set of security properties. Then we use the TLC model checker to verify the security properties against the model. We analyze the APS in both Android 6 and Android 11 and we succeed in discovering a previously known vulnerability in Android 6 as well as a new vulnerability in OTPs in Android 11 named Permanent Permission Access (PPA). We also implement an exploit code to show that PPA leads to permanent illegal access to sensitive resources. Our experiments show that the developed exploit app works on the latest versions of Android too (including Android 15). Besides, we propose the required fix to mitigate the vulnerability.
Amirhosein Sayyadabdi, Behrouz Tork Ladani, Bahman Zamani
ACM Trans. Priv. Secur.3
2025 RAIDAD: A model-driven framework for automated and agile development of IoT data analysis software
Mohsen Gholami, Bahman Zamani, Behrouz Shahgholi Ghahfarokhi
Inf. Softw. Technol.2
2025 CoMPers: A configurable conflict management framework for personalized collaborative modeling
Mohammadreza Sharbaf, Bahman Zamani, Gerson Sunyé
J. Syst. Softw.2
2024 A comprehensive framework for inter-app ICC security analysis of Android apps
Atefeh Nirumand, Bahman Zamani, Behrouz Tork Ladani
Autom. Softw. Eng.2
2023 Maaker: A framework for detecting and defeating evasion techniques in Android malware
Hayyan Hasan, Behrouz Tork Ladani, Bahman Zamani
J. Inf. Secur. Appl.3
2023 Conflict management techniques for model merging: a systematic mapping review
Mohammadreza Sharbaf, Bahman Zamani, Gerson Sunyé
Softw. Syst. Model.2
2023 A model-based framework for inter-app Vulnerability analysis of Android applications
abstract
Abstract Android users install various apps, such as banking apps, on their smart devices dealing with user‐sensitive information. The Android framework, via Inter‐Component Communication (ICC) mechanism, ensures that app components (inside the same app or on different apps) can communicate. The literature works have shown that this mechanism can cause security issues, such as app security policy violations, especially in the case of Inter‐App Communication (IAC). Despite the plethora of research on detecting security issues in IAC, detection techniques face fundamental ICC challenges for improving the precision of static analysis. Challenges include providing comprehensive and scalable modeling of app specification, capturing all potential ICC paths, and enabling more effective IAC analysis. To overcome such challenges, in this paper, we propose a framework called VAnDroid2, as an extension of our previous work, to address the security issues in multiple components at both intra‐ and inter‐app analysis levels. VAnDroid2, based on Model‐Driven Reverse Engineering, has extended our previous work as per following: (1) providing a comprehensive Intermediate Representation (IR) of the app which supports extracting all the ICC information from the app, (2) extracting high‐level representations of the apps and their interactions by omitting the details that are not relevant to inter‐app security analysis, and (3) enabling more effective IAC security analysis. This framework is implemented as an Eclipse‐based tool. The results of evaluating VAnDroid2 w.r.t. correctness, scalability, and run‐time performance, and comparing with state‐of‐the‐art analysis tools well indicate that VAnDroid2 is a promising framework in the field of Android inter‐app security analysis.
Atefeh Nirumand, Bahman Zamani, Behrouz Tork Ladani, Jacques Klein, Tegawendé F. Bissyandé
Softw. Pract. Exp.2
2022 HealMA: a model-driven framework for automatic generation of IoT-based Android health monitoring applications
Maryam Mehrabi, Bahman Zamani, Abdelwahab Hamou-Lhadj
Autom. Softw. Eng.2
2021 ALBA: a model-driven framework for the automatic generation of android location-based apps
Mohammadali Gharaat, Mohammadreza Sharbaf, Bahman Zamani, Abdelwahab Hamou-Lhadj
Autom. Softw. Eng.3
2021 CGenProg: Adaptation of cartesian genetic programming with migration and opposite guesses for automatic repair of software regression faults
Alireza Khalilian 0001, Ahmad Baraani-Dastjerdi, Bahman Zamani
Expert Syst. Appl.3
2021 MEGDroid: A model-driven event generation framework for dynamic android malware analysis
Hayyan Hasan, Behrouz Tork Ladani, Bahman Zamani
Inf. Softw. Technol.3
2021 MUPPIT: a method for using proper patterns in model transformations
Mahsa Panahandeh, Mohammad Hamdaqa, Bahman Zamani, Abdelwahab Hamou-Lhadj
Softw. Syst. Model.3
2020 CaaSSET: A Framework for Model-Driven Development of Context as a Service
Hossein Moradi, Bahman Zamani, Kamran Zamanifar
Future Gener. Comput. Syst.2
2020 SEET: Symbolic Execution of ETL Transformations
Banafsheh Azizi, Bahman Zamani, Shekoufeh Kolahdouz Rahimi
J. Syst. Softw.2
2020 Lossless compaction of model execution traces
Fazilat Hojaji, Bahman Zamani, Abdelwahab Hamou-Lhadj, Tanja Mayerhofer, Erwan Bousse
Softw. Syst. Model.2
2020 Configurable three-way model merging
abstract
Summary Software development is a collaborative activity that requires teams of software engineers to cooperate and work in parallel on versions of models. However, model management techniques such as model differencing, merging, and versioning have turned out to be difficult challenges, due to the complexity of operations and graph‐like nature of models. Therefore, a well‐developed support for model merging process, as well as conflict management, is highly desired. This paper presents a novel process for model merging, called the Epsilon‐based Three‐way Merging Process (E3MP) process. Model merging is a significant problem where there are different versions of a system model amongst modeler teams. E3MP includes three components implemented into the Epsilon framework. First, modelers can define domain‐specific rules that customize the merging process. Second, E3MP enables an automated method for syntactic and semantic conflict detection amongst different versions of the system model. Third, E3MP puts forward a pattern‐based approach for conflict resolution. We applied two generic benchmarks to assess conflict detection and resolution capabilities of our approach and carried out an initial scalability evaluation for the model merge with large models and large change sets. The results of our experiments revealed that the proposed process allows generating consistent and semantically correct merged models.
Mohammadreza Sharbaf, Bahman Zamani
Softw. Pract. Exp.2
2019 Model execution tracing: a systematic mapping study
Fazilat Hojaji, Tanja Mayerhofer, Bahman Zamani, Abdelwahab Hamou-Lhadj, Erwan Bousse
Softw. Syst. Model.3
2019 A model-driven framework for developing multi-agent systems in emergency response environments
Samaneh Hoseindoost, Tahereh Adamzadeh, Bahman Zamani, Afsaneh Fatemi
Softw. Syst. Model.3
2019 VAnDroid: A framework for vulnerability analysis of Android applications using a model-driven reverse engineering technique
abstract
Summary Android is extensively used worldwide by mobile application developers. Android provides applications with a message passing system to communicate within and between them. Due to the risks associated with this system, it is vital to detect its unsafe operations and potential vulnerabilities. To achieve this goal, a new framework, called VAnDroid, based on Model Driven Reverse Engineering (MDRE), is presented that identifies security risks and vulnerabilities related to the Android application communication model. In the proposed framework, some security‐related information included in an Android app is automatically extracted and represented as a domain‐specific model. Then, it is used for analyzing security configurations and identifying vulnerabilities in the corresponding application. The proposed framework is implemented as an Eclipse‐based tool, which automatically identifies the Intent Spoofing and Unauthorized Intent Receipt as two attacks related to the Android application communication model. To evaluate the tool, it has been applied to several real‐world Android applications, including 20 apps from Google Play and 110 apps from the F‐Droid repository. VAnDroid is also compared with several existing analysis tools, and it is shown that it has a number of key advantages over those tools specifically regarding its high correctness, scalability, and usability in discovering vulnerabilities. The results well indicate the effectiveness and capacity of the VAnDroid as a promising approach in the field of Android security.
Atefeh Nirumand, Bahman Zamani, Behrouz Tork Ladani
Softw. Pract. Exp.2
2018 EVL+Strace: a novel bidirectional model transformation approach
Leila Samimi-Dehkordi, Bahman Zamani, Shekoufeh Kolahdouz Rahimi
Inf. Softw. Technol.2
2017 A model-based framework for automatic generation of a pattern language verifier
abstract
Summary Design patterns solve recurring design problems. One of the best practices, to solve a whole problem in a specific context, is to apply patterns in the form of a collection of related patterns, ie, a pattern language (PL). However, with the rapid growth of the number of patterns and their interrelationships in PLs and because manual verification of the applied PLs is a tedious and error‐prone task, when designing in PL‐based fashion, there is a need for tool support to verify the applied PLs. In our previous work, aimed at automating the development process of PL verification tools, a PL formalism was presented. This paper, based on the presented formalism, describes a framework called Pattern Language Verifier Generator (PLVGen) that automatically generates a pattern language verifier (PLV) for any given PL assuming its constituent patterns are represented in the Unified Modeling Language (UML). Using a modelware approach, two metamodels named pattern language specification language (PLSL) and pattern specification language (PSL) are developed to model the given PL and its patterns, respectively. By getting the models of a PL and its patterns, PLVGen automatically generates an epsilon validation language (EVL) module representing the expected PLV. By launching PLV, the applied PL on a UML model will be verified. To evaluate the applicability of PLVGen in practice, we automatically generated three PLVs. The statistics regarding the generated PLVs, as case studies, illustrate the scalability of PLVGen. Compared with similar tools, the generated PLVs are more portable, transparent, and free of ambiguities.
Alireza Rouhi, Bahman Zamani
Softw. Pract. Exp.2
2016 Towards a formal model of patterns and pattern languages
Alireza Rouhi, Bahman Zamani
Inf. Softw. Technol.2
2013 Pattern Language Verification in Model Driven Design
Bahman Zamani, Gregory Butler
Inf. Sci.1
2009 Describing Pattern Languages for Checking Design Models
abstract
Many designers use the patterns of a pattern language in creating the design model. In designing with patterns, there are three aspects of the pattern language that must be taken into consideration: structural, syntactic, and semantic. That means, the patterns must be applied correctly, the relationship between patterns must be correct, and the design model must be semantically correct. The syntactic aspect is important for pattern languages due to the fact that the patterns in a pattern language are interconnected via several relationships. To achieve automatic design model checking, the three aspects of a pattern language must be precisely defined. We propose formalisms for representing the structural, syntactic, and semantic aspects of a pattern language. As our case study, we select a pattern language in the domain of enterprise application architecture, and show how the pattern language is described using the proposed formalism.
Bahman Zamani, Gregory Butler
APSEC1
2008 A Pattern Language Verifier for Web-Based Enterprise Applications
Bahman Zamani, Sahar Kayhani, Gregory Butler
MoDELS1