<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//TaxonX//DTD Taxonomic Treatment Publishing DTD v0 20100105//EN" "../../nlm/tax-treatment-NS0.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:tp="http://www.plazi.org/taxpub" article-type="research-article" dtd-version="3.0" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">109</journal-id>
      <journal-id journal-id-type="index">urn:lsid:arphahub.com:pub:3dc5f44e-8666-58db-bc76-a455210e8891</journal-id>
      <journal-title-group>
        <journal-title xml:lang="en">JUCS - Journal of Universal Computer Science</journal-title>
        <abbrev-journal-title xml:lang="en">jucs</abbrev-journal-title>
      </journal-title-group>
      <issn pub-type="ppub">0948-695X</issn>
      <issn pub-type="epub">0948-6968</issn>
      <publisher>
        <publisher-name>Journal of Universal Computer Science</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.3217/jucs-022-04-0494</article-id>
      <article-id pub-id-type="publisher-id">23121</article-id>
      <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Research Article</subject>
        </subj-group>
        <subj-group subj-group-type="scientific_subject">
          <subject>D.2.11 - Software Architectures</subject>
          <subject>D.4.6 - Security and Protection</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Web Data Amalgamation for Security Engineering: Digital Forensic Investigation of Open Source Cloud</article-title>
      </title-group>
      <contrib-group content-type="authors">
        <contrib contrib-type="author" corresp="yes">
          <name name-style="western">
            <surname>Imran</surname>
            <given-names>Asif</given-names>
          </name>
          <email xlink:type="simple">asifimran@du.ac.bd</email>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
        <contrib contrib-type="author" corresp="no">
          <name name-style="western">
            <surname>Aljawarneh</surname>
            <given-names>Shadi A.</given-names>
          </name>
          <xref ref-type="aff" rid="A2">2</xref>
        </contrib>
        <contrib contrib-type="author" corresp="no">
          <name name-style="western">
            <surname>Sakib</surname>
            <given-names>Kazi</given-names>
          </name>
          <xref ref-type="aff" rid="A1">1</xref>
        </contrib>
      </contrib-group>
      <aff id="A1">
        <label>1</label>
        <addr-line content-type="verbatim">University of Dhaka, Dhaka, Bangladesh</addr-line>
        <institution>University of Dhaka</institution>
        <addr-line content-type="city">Dhaka</addr-line>
        <country>Bangladesh</country>
      </aff>
      <aff id="A2">
        <label>2</label>
        <addr-line content-type="verbatim">Jordan University of Science and Technology, Irbid, Jordan</addr-line>
        <institution>Jordan University of Science and Technology</institution>
        <addr-line content-type="city">Irbid</addr-line>
        <country>Jordan</country>
      </aff>
      <author-notes>
        <fn fn-type="corresp">
          <p>Corresponding author: Asif Imran (<email xlink:type="simple">asifimran@du.ac.bd</email>).</p>
        </fn>
        <fn fn-type="edited-by">
          <p>Academic editor: </p>
        </fn>
      </author-notes>
      <pub-date pub-type="collection">
        <year>2016</year>
      </pub-date>
      <pub-date pub-type="epub">
        <day>01</day>
        <month>04</month>
        <year>2016</year>
      </pub-date>
      <volume>22</volume>
      <issue>4</issue>
      <fpage>494</fpage>
      <lpage>520</lpage>
      <uri content-type="arpha" xlink:href="http://openbiodiv.net/62E7BD49-D045-5B04-B2D7-16E626D007E0">62E7BD49-D045-5B04-B2D7-16E626D007E0</uri>
      <uri content-type="zenodo_dep_id" xlink:href="https://zenodo.org/record/5505033">5505033</uri>
      <history>
        <date date-type="received">
          <day>30</day>
          <month>10</month>
          <year>2015</year>
        </date>
        <date date-type="accepted">
          <day>30</day>
          <month>03</month>
          <year>2016</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>Asif Imran, Shadi A. Aljawarneh, Kazi Sakib</copyright-statement>
        <license license-type="creative-commons-attribution" xlink:href="" xlink:type="simple">
          <license-p>This article is freely available under the J.UCS Open Content License.</license-p>
        </license>
      </permissions>
      <abstract>
        <label>Abstract</label>
        <p>The largely distributed nature and growing demand for open source Cloud makes the infrastructure an ideal target for malicious attacks that grants unauthorized access to its data storage and posses a serious threat to Cloud software security. In case of any nefarious activity, the Cloud provenance information used by Digital Forensic experts to identify the issue is itself prone to tampering by the malicious entities and results in insecure software running in Cloud. This paper proposes a scheme that ensures Software Security and Security of Cloud provenance in a series of steps, the first of which involves binding the provenance journals with user-data from which those were derived. Next, mechanisms for merging provenance with unstructured web data for improved Security Intelligence (SI) is identified. Detection of attack models for nefarious malware activities in six Software as a Service (SaaS) applications running in real-life Cloud is taken as the research case and the performance of the proposed algorithms for those are analyzed. The Success Rates (SR) for melding the web data to secure provenance for the six specific SaaS applications are found to be 85.0554%, 96.7032%, 98.3871%, 93.9732%, 80.5000% and 84.9257% respectively. Hence, this paper proposes a framework for effectively ameliorating the current scheme of Cloud based Software Security, thereby achieving wider acceptance of open source Cloud.</p>
      </abstract>
    </article-meta>
  </front>
</article>
