Jun Han 0004

dblp:02/3721-4 · DBLP profile ↗
← Back
94ranked-venue papers
4as first author
7since 2021 · last 2024
0000-0002-0909-1688ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 50 · 4 first-author · 3 since 2021Databases, data management, data science and information retrieval · 20 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 15 · 1 first-authorComputer networks · 5 · 2 since 2021Human-computer interaction and ubiquitous computing · 5Systems, architecture and hardware · 4 · 1 since 2021Artificial intelligence and machine learning · 3Theory of computation · 3Security and privacy · 1
YearPublicationVenuePosition
2024 Detecting Inconsistencies in Microservice-Based Systems: An Annotation-Assisted Scenario-Oriented Approach
abstract
Microservice architecture (MSA) has been widely adopted to develop various large-scale distributed systems. Microservice-based systems (MBSs) comprise a number of independently deployed microservices fulfilling the specific functionalities. Unique characteristics of microservices, such as independent and parallel development, rapid iteration, and distributed deployment, result in low observability and reliability of MBSs. A typical solution is to regulate system behavior in specifications of MBSs, and then develop and test MBSs based on these specifications. However, current microservice specifications focus on describing the APIs of microservices without describing the behavior expectation for an MBS. In this article, we propose an annotation-assisted and scenario-oriented approach, called MSA_Sighter, to detect behavior inconsistencies in MBSs. In MSA_Sighter, the details of an MBS are captured in a description model (MSDM), which can be extracted automatically from the functional services through annotation-assisted runtime component instance analysis and static program analysis. Given a specific business scenario, inconsistency detection is conducted by analyzing the actual behavior's conformance to the expected behavior, where the former is collected through distributed tracing while the latter is derived from the MSDM. We have developed a supporting tool called ConsChecker and evaluated MSA_Sighter's effectiveness on three open-source MBSs in GitHub. The experimental results have shown that MSA_Sighter can effectively detect inconsistencies in MBSs during system development and evolution.
Chang-Ai Sun, Yufei Gong, Meng Li 0042, Jun Han 0004, Yanbo Han
IEEE Trans. Serv. Comput.5
2023 Improving Conformance of Web Services: A Constraint-based Model-driven Approach
abstract
Web services have been widely used to develop complex distributed software systems in the context of Service Oriented Architecture (SOA). As a standard for describing Web services, the Web Service Description Language (WSDL) provides a universal mechanism to describe the service’s functionalities for the service consumers. However, the current WSDL only provides the description of the interfaces to a Web Service without any restrictions or assumptions on how to properly invoke the service, resulting in divergent understanding of the Web service’s behavior between the service developer and service consumer. A particular challenge is how to make explicit the various behavior assumptions and restrictions of a service (for the user), and make sure that the service implementation conforms to them (for the developer). In this article, we propose a constraint-based model-driven approach to improving the behavior conformance of Web services. In our approach, constraints are introduced in an extended WSDL, called CxWSDL, to formally and explicitly express the implicit restrictions and assumptions on the behavior of a Web service, and then the predefined constraints are used to derive test cases in a model-driven manner to test the service implementation’s conformance to its behavior constraints from the user’s perspective. An empirical study involving four real-life Web services was conducted to evaluate the effectiveness of our approach, and four actual inconsistencies were discovered.
Chang-Ai Sun, An Fu, Jingting Jia, Meng Li 0042, Jun Han 0004
ACM Trans. Web5
2022 Inferring data model from service interactions for response generation in service virtualization
Md. Arafat Hossain, Jiaojiao Jiang 0001, Jun Han 0004, Muhammad Ashad Kabir, Jean-Guy Schneider, Chengfei Liu
Inf. Softw. Technol.3
2022 Extracting Formats of Service Messages with Varying Payloads
abstract
Having precise specifications of service APIs is essential for many Software Engineering activities. Unfortunately, available documentation of services is often inadequate and/or imprecise and, hence, cannot be fully relied upon. Generating service documentation manually is a tedious and error-prone task, especially in light of changes to services. Therefore, there is a need for automated support in generating service documentation. In this work, we present a novel approach to infer the API of a service by analyzing recorded messages sent to and received from this service. Our approach includes a novel, two-level clustering technique to cluster messages, a step that many existing approaches to infer message formats fail to perform precisely in the presence of significant variation of payload information of the available messages. We have evaluated our approach on message traces from four different real-world services. The experimental result shows that our approach is more effective than existing techniques in extracting correct message formats from recorded messages.
Md. Arafat Hossain, Jun Han 0004, Jean-Guy Schneider, Jiaojiao Jiang 0001, Muhammad Ashad Kabir, Steve Versteeg
ACM Trans. Internet Techn.2
2021 Mining Cross-Domain Apps for Software Evolution: A Feature-based Approach
abstract
The skyrocketing growth of mobile apps and mobile devices has significantly fueled the competition among app developers. They have leveraged the app store capabilities to analyse app data and identify app improvement opportunities. Existing research has shown that app developers mostly rely on in-domain (i.e., same domain or same app) data to improve their apps. However, relying on in-domain data results in low diversity and lacks novelty in recommended features. In this work, we present an approach that automatically identifies, classifies and ranks relevant popular features from cross-domain apps for recommendation to any given target app. It includes the following three steps: 1) identify cross-domain apps that are relevant to the target app in terms of their features; 2) filter and group semantically the features of the relevant cross-domain apps that are complementary to the target app; 3) rank and prioritize the complementary cross-domain features (in terms of their domain, app, feature and popularity characteristics) for adoption by the target app’s developers. We have run extensive experiments on 100 target apps from 10 categories over 15,200 cross-domain apps from 31 categories. The experimental results have shown that our approach to identifying, grouping and ranking complementary cross-domain features for recommendation has achieved an accuracy level of over 89%. Our semantic feature grouping technique has also significantly outperformed two existing baseline techniques. The empirical evaluation validates the efficacy of our approach in providing personalised feature recommendation and enhancing app’s user serendipity.
Md Kafil Uddin, Qiang He 0001, Jun Han 0004, Caslon Chua
ASE3
2021 SpecMiner: Heuristic-based mining of service behavioral models from interaction traces
Muhammad Ashad Kabir, Jun Han 0004, Md. Arafat Hossain, Steve Versteeg
Future Gener. Comput. Syst.2
2021 R-gram: Inferring message formats of service protocols with relative positional n-grams
Jiaojiao Jiang 0001, Jean-Guy Schneider, Steve Versteeg, Jun Han 0004, Md. Arafat Hossain, Chengfei Liu
J. Netw. Comput. Appl.4
2020 Feature Recommendation by Mining Updates and User Feedback from Competitor Apps
abstract
Competition in mobile applications (i.e., apps) is becoming more and more intense with the increase in popularity of smart phones and mobile devices. Previous research shows that app developers spent considerable amount of time in exploiting user feedback to improve their apps. However, relying on own user feedback is insufficient for app survival in such competitive environment. It is highly important for an app developer to learn from competitors in order to keep the rank higher or become topper in the store (e.g., Google Play1). In this work, we present an approach to automatically classify and rank popular and un-popular features from the competitor apps. We follow 3 steps- (1) extract features from competitor app updates (i.e., whatsNew) and user feedback (i.e, reviews), (2) filter and group the review features that are relevant to whatsNew features, then, classify whatsNew features to binary classes, such as, popular and unpopular, (3) rank and prioritize those popular and unpopular features from competitors in order to recommend developers to adopt or avoid those features. The ranking of whatsNew features are done based on whatsNew-to-review relevance, user sentiments, and popularity of those features. We conduct extensive experiments on 840 updates and 262000 reviews of 84 different competitor apps of 10 categories. We found encouraging results from the experiments and the empirical evaluation validates the efficacy of our approach, hence, potential usefulness to the developers.
Md Kafil Uddin, Qiang He 0001, Jun Han 0004, Caslon Chua
MobiQuitous3
2020 Comparison of Text-Based and Feature-Based Semantic Similarity Between Android Apps
Md Kafil Uddin, Qiang He 0001, Jun Han 0004, Caslon Chua
WISE (1)3
2020 CalBehav: A Machine Learning-Based Personalized Calendar Behavioral Model Using Time-Series Smartphone Data
abstract
Abstract The electronic calendar is a valuable resource nowadays for managing our daily life appointments or schedules, also known as events, ranging from professional to highly personal. Researchers have studied various types of calendar events to predict smartphone user behavior for incoming mobile communications. However, these studies typically do not take into account behavioral variations between individuals. In the real world, smartphone users can differ widely from each other in how they respond to incoming communications during their scheduled events. Moreover, an individual user may respond the incoming communications differently in different contexts subject to what type of event is scheduled in her personal calendar. Thus, a static calendar-based behavioral model for individual smartphone users does not necessarily reflect their behavior to the incoming communications. In this paper, we present a machine learning based context-aware model that is personalized and dynamically identifies individual’s dominant behavior for their scheduled events using logged time-series smartphone data, and shortly name as ‘CalBehav’. The experimental results based on real datasets from calendar and phone logs, show that this data-driven personalized model is more effective for intelligently managing the incoming mobile communications compared to existing calendar-based approaches.
Iqbal H. Sarker, Alan W. Colman, Jun Han 0004, A. S. M. Kayes, Paul A. Watters
Comput. J.3
2020 Quantifying the adaptability of workflow-based service compositions
Khavee Agustus Botangen, Jian Yu 0002, Yanbo Han, Quan Z. Sheng, Jun Han 0004
Future Gener. Comput. Syst.5
2020 A positional keyword-based approach to inferring fine-grained message formats
Jiaojiao Jiang 0001, Steve Versteeg, Jun Han 0004, Md. Arafat Hossain, Jean-Guy Schneider
Future Gener. Comput. Syst.3
2020 BehavDT: A Behavioral Decision Tree Learning to Build User-Centric Context-Aware Predictive Model
Iqbal H. Sarker, Alan W. Colman, Jun Han 0004, Asif Irshad Khan, Yoosef B. Abushark, Khaled Salah 0001
Mob. Networks Appl.3
2019 A Policy Model and Framework for Context-Aware Access Control to Information Resources†
abstract
In today’s dynamic ICT environments, the ability to control users’ access to information resources and services has become ever important. On the one hand, it should provide flexibility to adapt to the users’ changing needs, while on the other hand, it should not be compromised. The user is often faced with different contexts and environments that may change the user’s information needs. To allow for this, it is essential to incorporate the dynamically changing context information into the access control policies to reflect different contexts and environments through the use of a new context-aware access control (CAAC) approach with both dynamic associations of user-role and role-permission capabilities. Our proposed CAAC framework differs from the existing access control frameworks in that it supports context-sensitive access control to information resources and dynamically re-evaluates the access control decisions when there are dynamic changes to the context. It uses the dynamic context information to specify the user-role and role-permission assignment policies. We first present a formal policy model for our framework, specifying CAAC policies. Using this model, we then introduce a policy ontology for modeling CAAC policies and a policy enforcement architecture which supports access to resources according to the dynamically changing context information. In addition, we demonstrate the feasibility of our framework by considering (i) the completeness, correctness and consistency of the ontology concepts through application to healthcare scenarios and (ii) the performance and usability testing of the framework when using desktop and mobile-based prototypes.
A. S. M. Kayes, Jun Han 0004, Wenny Rahayu, Tharam S. Dillon, Md. Saiful Islam 0003, Alan W. Colman
Comput. J.2
2019 Context-aware access control with imprecise context characterization for cloud-based data resources
A. S. M. Kayes, Wenny Rahayu, Tharam S. Dillon, Elizabeth Chang 0001, Jun Han 0004
Future Gener. Comput. Syst.5
2019 SDSN@RT: A middleware environment for single-instance multitenant cloud applications
abstract
Summary With the single‐instance multitenancy (SIMT) model for composite Software‐as‐a‐Service (SaaS) applications, a single composite application instance can host multiple tenants, yielding the benefits of better service and resource utilization and reduced operational cost for the SaaS provider. An SIMT application needs to share services and their aggregation (the application) among its tenants while supporting variations in the functional and performance requirements of the tenants. The SaaS provider requires a middleware environment that can deploy, enact, and manage a designed SIMT application, to achieve the varied requirements of the different tenants in a controlled manner. This paper presents the SDSN@RT (software‐defined service networks at runtime) middleware environment that can meet the aforementioned requirements. SDSN@RT represents an SIMT composite cloud application as a multitenant service network, where the same service network simultaneously hosts a set of virtual service networks, one for each tenant. A service network connects a set of services and coordinates the interactions between them. A virtual service network realizes the requirements for a specific tenant and can be deployed, configured, and logically isolated in the service network at runtime. SDSN@RT also supports the monitoring and runtime changes of the deployed multitenant service networks. We show the feasibility of SDSN@RT with a prototype implementation and demonstrate its capabilities to host SIMT applications and support their changes with a case study. The performance study of the prototype implementation shows that the runtime capabilities of our middleware incur little overhead.
Indika Kumara, Jun Han 0004, Alan W. Colman, Willem-Jan van den Heuvel, Damian A. Tamburri, Malinda Kapuruge
Softw. Pract. Exp.2
2018 Constraint-Based Model-Driven Testing of Web Services for Behavior Conformance
Chang-Ai Sun, Meng Li 0042, Jingting Jia, Jun Han 0004
ICSOC4
2018 Mining accurate message formats for service APIs
abstract
APIs play a significant role in the sharing, utilization and integration of information and service assets for enterprises, delivering significant business value. However, the documentation of service APIs can often be incomplete, ambiguous, or even non-existent, hindering API-based application development efforts. In this paper, we introduce an approach to automatically mine the fine-grained message formats required in defining the APIs of services and applications from their interaction traces, without assuming any prior knowledge. Our approach includes three major steps with corresponding techniques: (1) classifying the interaction messages of a service into clusters corresponding to message types, (2) identifying the keywords of messages in each cluster, and (3) extracting the format of each message type. We have applied our approach to network traces collected from four real services which used the following application protocols: REST, SOAP, LDAP and SIP. The results show that our approach achieves much greater accuracy in extracting message formats for service APIs than current state-of-art approaches.
Md. Arafat Hossain, Steve Versteeg, Jun Han 0004, Muhammad Ashad Kabir, Jiaojiao Jiang 0001, Jean-Guy Schneider
SANER3
2018 Individualized Time-Series Segmentation for Mining Mobile Phone User Behavior
abstract
Mobile phones can record individual’s daily behavioral data as a time-series. In this paper, we present an effective time-series segmentation technique that extracts optimal time segments of individual’s similar behavioral characteristics utilizing their mobile phone data. One of the determinants of an individual’s behavior is the various activities undertaken at various times-of-the-day and days-of-the-week. In many cases, such behavior will follow temporal patterns. Currently, researchers use either equal or unequal interval-based segmentation of time for mining mobile phone users’ behavior. Most of them take into account static temporal coverage of 24-h-a-day and few of them take into account the number of incidences in time-series data. However, such segmentations do not necessarily map to the patterns of individual user activity and subsequent behavior because of not taking into account the diverse behaviors of individuals over time-of-the-week. Therefore, we propose a behavior-oriented time segmentation (BOTS) technique that takes into account not only the temporal coverage of the week but also the number of incidences of diverse behaviors dynamically for producing similar behavioral time segments over the week utilizing time-series data. Experiments on the real mobile phone datasets show that our proposed segmentation technique better captures the user’s dominant behavior at various times-of-the-day and days-of-the-week enabling the generation of high confidence temporal rules in order to mine individual mobile phone users’ behavior.
Iqbal H. Sarker, Alan W. Colman, Muhammad Ashad Kabir, Jun Han 0004
Comput. J.4
2017 Identifying Recent Behavioral Data Length in Mobile Phone Log
abstract
Mobile phone log data (e.g., phone call log) is not static as it is progressively added to day-by-day according to individual's diverse behaviors with mobile phones. Since human behavior changes over time, the most recent pattern is more interesting and significant than older ones for predicting individual's behavior. The goal of this poster paper is to identify the recent behavioral data length dynamically from the entire phone log for recency-based behavior modeling. To the best of our knowledge, this is the first dynamic recent log-based study that takes into account individual's recent behavioral patterns for modeling their phone call behaviors.
Iqbal H. Sarker, Muhammad Ashad Kabir, Alan W. Colman, Jun Han 0004
MobiQuitous4
2017 A Petri-Net-Based Virtual Deployment Testing Environment for Enterprise Software Systems
abstract
The landscape of modern enterprise IT environments is that a large number of distributed software systems interact and cooperate with each other to support daily business operations. With the prevalence of cloud computing, the level of system connectivity increases further. The large scale of such an environment makes it difficult to test a system's quality attributes such as performance and scalability before it is actually deployed in the production environment. Under the currently dominant iterative and incremental software development paradigm, this difficulty is even more pronounced when the quality attributes of an enterprise system need to be examined and evaluated at early stages but a large part of its operating environment is not available or accessible. In this paper, we present a Coloured Petri nets (CPN) based system behaviour emulation approach and a lightweight emulated testing framework for provisioning a virtual deployment testing environment for an enterprise software system, so that its quality attributes, especially scalability, can be evaluated without physically connecting to the real production environment. It is worth noting that the focus of this work is on the testing environment which enables virtual system deployment and testing, instead of being on the research topic of deployment test. CPN and its associated design and simulation tools have been used and integrated to model and execute the behaviour of those cooperating endpoint systems that an enterprise software system interacts with. We have successfully implemented an industry standard protocol Lightweight Directory Access Protocol in our approach and applied it in testing the scalability of a real-world enterprise application, CA Technologies’ IdentityManager. A thorough in-lab performance study has also been conducted to examine the capacity and scalability of this approach.
Jian Yu 0002, Jun Han 0004, Jean-Guy Schneider, Cameron M. Hine, Steve Versteeg
Comput. J.2
2017 Software-Defined Service Networking: Performance Differentiation in Shared Multi-Tenant Cloud Applications
abstract
A composite cloud application can achieve economies of scale by sharing partner services between tenants at runtime, following the Single-Instance Multi-Tenancy (SIMT) model. However, supporting runtime sharing with tenant-specific functional and performance variations in an SIMT application is challenging. We address this challenge by proposing the Software-Defined Service Networking (SDSN) approach. SDSN realizes an SIMT composite cloud application with a managed service network and a set of managed virtual service networks (VSNs) that share the service network. The service network is formed by connecting a set of partner services according to their capabilities and interoperability. To achieve the functional and performance requirements of a particular tenant, a VSN composes a subset of the services under a specific configuration design over the service network, and regulates the interactions between the services concerned according to a specific regulation design. We describe how a service network and its VSNs are designed and enacted to achieve the SIMT objectives. We show the feasibility of SDSN, demonstrate the utilization benefits it achieves, and quantify the runtime overhead it incurs.
Indika Kumara, Jun Han 0004, Alan W. Colman, Malinda Kapuruge
IEEE Trans. Serv. Comput.2
2016 Behavior-Oriented Time Segmentation for Mining Individualized Rules of Mobile Phone Users
abstract
Mobile or cellular phones can record various types of context data related to a user's phone call activities. In this paper, we present an approach to discovering individualized behavior rules for mobile users from their phone call records, based on the temporal context in which a user accepts, rejects or misses a call. One of the determinants of an individual's phone behavior is the various activities undertaken at various times of a day and days of the week. In many cases, such behavior will follow temporal patterns. Currently, researchers modeling user behavior using temporal context statically segment time into arbitrary categories (e.g., morning, evening) or periods (e.g., 1 hour). However, such time categorization does not necessarily map to the patterns of individual user activity and subsequent behavior. Therefore, we propose a behavior-oriented time segmentation (BOTS) technique that dynamically identifies diverse time segments for an individual user's behaviors based on the phone call records. Experiments on real datasets show that our proposed technique better captures the user's dominant call response behavior at various times of the day and week, thereby enabling more appropriate rules to be created for the purpose of automated handling of incoming calls, in an intelligent call interruption management system.
Iqbal H. Sarker, Alan W. Colman, Muhammad Ashad Kabir, Jun Han 0004
DSAA4
2016 Evidence-Based Behavioral Model for Calendar Schedules of Individual Mobile Phone Users
abstract
The electronic calendar usually serves as a personal organizer and is a valuable resource for managing daily activities or schedules of the users. Naturally, a calendar provides various contextual information about individual's scheduled events/appointments, e.g., meeting. A number of researchers have utilized such information to predict human behavior for mobile communication, by assuming a predefined event-behavior mapping which is static and non-personalized. However, in the real world, people differ from each other in how they respond to incoming calls during their scheduled events, even a particular individual may respond differently subject to what type of event is scheduled in the calendar. Thus a static behavioral model does not necessarily map to calendar schedules and corresponding phone call response behavior of individuals. Therefore, we propose an evidencebased behavioral model (EBM) that dynamically identifies the actual call response behavior of individuals for various calendar events based on their mobile phone log that records the data related to a user's phone call activities. Experiments on real datasets show that our proposed technique better captures the user's call response behavior for various calendar events, thereby enabling more appropriate rules to be created for the purpose of automated handling of incoming calls in an intelligent call interruption management system.
Iqbal H. Sarker, Muhammad Ashad Kabir, Alan W. Colman, Jun Han 0004
DSAA4
2016 Engineering Socially-Aware Systems and Applications
abstract
With the convergence of pervasive mobile computing and social networking, interest has grown significantly in software systems and applications that are aware of users' social context to make pervasive applications more intelligent and accessible. Thus, socially-aware systems have further advanced context-aware systems taking account of human social context such as social relationships to enable the attainment of users' tasks in different domains. However, social context-awareness introduces a variety of software engineering challenges. In this paper, we address these challenges by proposing a software engineering process that provides a methodological framework for developing various types of socially-aware applications from requirements elicitation through to concrete implementation. We provide context models and software infrastructure to assist developers in rapid prototyping. We also present two case studies to demonstrate the feasibility and applicability of our software engineering process by presenting how this process can be used to develop two different types of socially-aware applications utilizing our model and infrastructure. Finally, we evaluate our software engineering approach with respect to a set of software quality metrics.
Muhammad Ashad Kabir, Jun Han 0004, Alan W. Colman, Naif R. Aljohani, Mohammed Basheri, Zhenchang Xing, Shangwei Lin 0001
ICECCS2
2016 A Feature-Based Framework for Developing and Provisioning Customizable Web Services
abstract
A customizable web service is a service that enables service consumers to dynamically determine variants of the service they receive. Provisioning customizable services helps to efficiently address functional variability in customer requirements. However, this is challenging due to: i) the complexity in deriving the right subset of service capabilities for a service variant and ii) the existence of a large number of variants and their dependencies. We propose a feature-based framework to tackle this challenge. In our framework, a feature model is used to capture functional variability in customer requirements at a high-level of abstraction and to provide customers with a much simpler way to customize an atomic service. A service engineering process is designed to facilitate the systematic identification and implementation of variability during service development, and to maintain the mapping between variabilities at the feature modeling level and the service implementation level. We define a generative middleware that supports service deployment and exploits the mapping to enable runtime service customization. A large scale case study based on the Amazon web services is used for evaluation. In addition to addressing the challenge in provisioning customizable services, our experiments show that the generative middleware helps to reduce runtime resource consumption.
Alan W. Colman, Jun Han 0004
IEEE Trans. Serv. Comput.3
2015 QoS-Aware Service Selection for Customisable Multi-tenant Service-Based Systems: Maturity and Approaches
abstract
Multi-tenant service-based systems (SBSs) have become a major paradigm in software engineering in the cloud environment. Instead of serving a single end-user, a multitenant SBS provides multiple tenants with similar and yet customised functionalities with potentially different quality-of service (QoS) values. Thus, existing approaches to service selection for single-tenant SBSs are no longer suitable. Furthermore, the target multi-tenancy maturity level also needs to be considered in the service selection approach for an SBS. In this paper, we propose three novel QoS-aware service selection approaches for composing multi-tenant SBSs that achieve three different multi-tenancy maturity levels. Extensive and comprehensive experiments are conducted and the experimental results show that our approaches outperform the existing approach in both effectiveness and efficiency.
Qiang He 0001, Jun Han 0004, Feifei Chen 0001, Rajesh Vasa, Yun Yang 0001, Hai Jin 0001
CLOUD2
2015 Inferring User Situations from Interaction Events in Social Media
abstract
With the advances of Internet technologies and an explosive growth in the popularity of social media, an increasingly large part of human life is getting digitized and becoming available on the web. This phenomenon brings opportunities and motivates us to infer users’ situations by exploiting their interaction events in various social media such as online social networks, blogs and email. One of the key requirements of inferring situations from interaction events is to consider both the semantic and temporal aspects of events in the situation inference process. In this paper, we address this issue and propose a novel approach to exploiting users’ interaction events in social media to infer their situations. We present an ontology-based interaction event model that captures the properties of users’ interaction activities in social media. We further provide a rule-based situation specification technique that integrates the interaction event ontology (for semantically matching interaction events) with temporal event relationships (for correlating historical interaction events). We also provide a platform to realize the situation reasoning/inference process, which combines semantic matching and complex event processing. We conduct a performance evaluation of the platform to quantify its efficacy. The feasibility and applicability of our approach is demonstrated by developing a socially aware phone call application as a case study.
Muhammad Ashad Kabir, Jun Han 0004, Jian Yu 0002, Alan W. Colman
Comput. J.2
2015 OntCAAC: An Ontology-Based Approach to Context-Aware Access Control for Software Services
abstract
In modern communication environments, the ability to provide access control to information resources and software services in a context-aware manner is crucial. By leveraging the dynamically changing context information, we can achieve context-specific control over access to such resources and services, better satisfying the security and privacy requirements of the stakeholders. Existing access control approaches are highly domain-specific and they control access to services depending on the specific types of context information (e.g. location and time). One of the key limitations of the existing approaches is the lack of systematic capture and use of context information in making context-aware access control decisions. Therefore, new access control approaches are required for such dynamic and context-aware environments. Existing approaches define context as the state/situation of the entities. To achieve context-aware access control, in this paper we not only consider the states of the entities but also consider the states of the relationships between entities. We introduce a generic framework, OntCAAC (Ontology-based Context-Aware Access Control), that adopts semantic technologies in modelling dynamic contexts and corresponding access control policies. It includes a context model specific to access control, capturing the relevant context information. The context model also incorporates the ability to infer high-level implicit context information according to operator-defined rules. Using the context model, the policy model of the OntCAAC framework provides support for specifying and enforcing context-aware access control policies. We have developed a prototype implementation of the framework and have demonstrated its use in making context-aware access control decisions through two case studies from different domains. Experimental results show the feasibility of our approach and quantify the performance overhead of providing context-aware access control for software services.
A. S. M. Kayes, Jun Han 0004, Alan W. Colman
Comput. J.2
2015 Social Context as a Service: Managing Adaptation in Collaborative Pervasive Applications
abstract
We present a social context as a service (SCaaS) platform for managing adaptations in collaborative pervasive applications that support interactions among a dynamic group of actors such as users, stakeholders, infrastructure services, businesses and so on. Such interactions are based on predefined agreements and constraints that characterize the relationships between the actors and are modeled with the notion of social context. In complex and changing environments, such interaction relationships, and thus social contexts, are also subject to change. In existing approaches, the relationships among actors are not modeled explicitly, and instead are often hard-coded into the application. Furthermore, these approaches do not provide adequate adaptation support for such relationships as the changes occur in user requirements and environments. In our approach, inter-actor relationships in an application are modeled explicitly using social contexts, and their execution environment is generated and adaptations are managed by the SCaaS platform. The key features of our approach include externalization of the interaction relationships from the applications, representation and modeling of such relationships from the domain and actor perspectives, their implementation using a service oriented paradigm, and support for their runtime adaptation. We quantify the platform's adaptation overhead and demonstrate its feasibility and applicability by developing a telematics application that supports cooperative convoy.
Muhammad Ashad Kabir, Jun Han 0004, Alan W. Colman, Jian Yu 0002
Int. J. Cooperative Inf. Syst.2
2015 An ontological framework for situation-aware access control of software services
A. S. M. Kayes, Jun Han 0004, Alan W. Colman
Inf. Syst.2
2015 Model-driven development of adaptive web service processes with aspects and rules
Jian Yu 0002, Quan Z. Sheng, Joshua K. Y. Swee, Jun Han 0004, Chengfei Liu, Talal H. Noor
J. Comput. Syst. Sci.4
2015 Reader level filtering for efficient query processing in RFID middleware
Muhammad Ashad Kabir, Jun Han 0004, Bonghee Hong
J. Netw. Comput. Appl.2
2015 Differentiated Performance Management in Virtualized Environments Using Nonlinear Control
abstract
The efficient management of shared resources in virtualized environments has become an important issue with the advent of cloud computing. This is a challenging management task because the resources of a single physical server may have to be shared between multiple virtual machines (VMs) running applications with different performance objectives, under unpredictable and erratic workloads. A number of existing works have developed performance differentiation and resource management techniques for shared resource environments by using linear feedback control approaches. However, the dominant nonlinearities of performance differentiation schemes and virtualized environments mean that linear control techniques do not provide effective control under a wide range of operating conditions. Instead of using linear control techniques, this paper presents a new nonlinear control approach that enables achieving differentiated performance requirements effectively in virtualized environments through the automated provisioning of resources. By using a nonlinear block control structure called the Hammerstein and Wiener model, a nonlinear feedback control system is integrated to the physical server (hypervisor) to efficiently achieve the performance differentiation objectives. The novelty of this approach is the inclusion of a compensation framework, which reduces the impact of nonlinearities on the management system. The experiments conducted in a virtual machine environment have shown significant improvements in performance differentiation and system stability of the proposed nonlinear control approach compared to a linear control system. In addition, the simulation results demonstrate the scalability of this nonlinear approach, providing stable performance differentiation between 10 applications/VMs.
Tharindu Patikirikorala, Liuping Wang, Alan W. Colman, Jun Han 0004
IEEE Trans. Netw. Serv. Manag.4
2014 PO-SAAC: A Purpose-Oriented Situation-Aware Access Control Framework for Software Services
A. S. M. Kayes, Jun Han 0004, Alan W. Colman
CAiSE2
2014 SocioTelematics: Harnessing social interaction-relationships in developing automotive applications
Muhammad Ashad Kabir, Jun Han 0004, Alan W. Colman
Pervasive Mob. Comput.2
2014 User-centric social context information management: an ontology-based approach and platform
Muhammad Ashad Kabir, Jun Han 0004, Jian Yu 0002, Alan W. Colman
Pers. Ubiquitous Comput.2
2014 Formulating Cost-Effective Monitoring Strategies for Service-Based Systems
abstract
When operating in volatile environments, service-based systems (SBSs) that are dynamically composed from component services must be monitored in order to guarantee timely and successful delivery of outcomes in response to user requests. However, monitoring consumes resources and very often impacts on the quality of the SBSs being monitored. Such resource and system costs need to be considered in formulating monitoring strategies for SBSs. The critical path of a composite SBS, i.e., the execution path in the service composition with the maximum execution time, is of particular importance in cost-effective monitoring as it determines the response time of the entire SBS. In volatile operating environments, the critical path of an SBS is probabilistic, as every execution path can be critical with a certain probability, i.e., its criticality. As such, it is important to estimate the criticalities of different execution paths when deciding which parts of the SBS to monitor. Furthermore, cost-effective monitoring also requires management of the trade-off between the benefit and cost of monitoring. In this paper, we propose CriMon, a novel approach to formulating and evaluating monitoring strategies for SBSs. CriMon first calculates the criticalities of the execution paths and the component services of an SBS and then, based on those criticalities, generates the optimal monitoring strategy considering both the benefit and cost of monitoring. CriMon has two monitoring strategy formulation methods, namely local optimisation and global optimisation. In-lab experimental results demonstrate that the response time of an SBS can be managed cost-effectively through CriMon-based monitoring. The effectiveness and efficiency of the two monitoring strategy formulation methods are also evaluated and compared.
Qiang He 0001, Jun Han 0004, Yun Yang 0001, Hai Jin 0001, Jean-Guy Schneider, Steve Versteeg
IEEE Trans. Software Eng.2
2013 Can Control-Component Libraries Reduce the Costs of Developing Control Engineering-Based Self-Adaptive Systems?
abstract
Many approaches have been proposed to develop self-adaptive software systems based on control engineering methods in recent years. However, these research works only evaluate the self-adaptive capabilities of the proposed control solution, but no evaluation is performed to quantify the costs of implementing such a control solution. This paper provides results of an empirical study, conducted to quantify the implementation, testing and knowledge requirement costs of building a self-adaptive software system using control engineering methods. Our objective is to investigate, whether these costs can be significantly reduced if a library of prepackaged control components is available to software engineers. The findings of the study indicate that the aforementioned costs can be significantly reduced when supporting libraries are available. We also list the lessons learned from this study and recommendations, which may be useful in designing experiments to evaluate engineering costs of self-adaptive methods in the future.
Tharindu Patikirikorala, Alan W. Colman, Jun Han 0004
APSEC (1)3
2013 ROAD4SaaS: Scalable Business Service-Based SaaS Applications
Malinda Kapuruge, Jun Han 0004, Alan W. Colman, Indika Kumara
CAiSE2
2013 Enabling Ad-hoc Business Process Adaptations through Event-Driven Task Decoupling
Malinda Kapuruge, Jun Han 0004, Alan W. Colman, Indika Kumara
CAiSE2
2013 A Business Protocol Unit Testing Framework for Web Service Composition
Jian Yu 0002, Jun Han 0004, Steven O. Gunarso, Steve Versteeg
CAiSE2
2013 Runtime Evolution of Service-Based Multi-tenant SaaS Applications
Indika Kumara, Jun Han 0004, Alan W. Colman, Malinda Kapuruge
ICSOC2
2013 Scenario-Based Validation of Requirements for Context-Aware Adaptive Services
abstract
Context-awareness and adaptability are highly desirable features for services that are operating in dynamic environments. Recently, a number of approaches have been introduced to support the development of such services. But, validating the varying requirements of these services is still a major challenge. In this paper, we introduce a novel scenario-based approach to address this challenge. First, our approach captures a service's requirements as two sets of scenarios: functional and adaptation. The functional scenarios represent the service's core functionality, while the adaptation scenarios capture the service's runtime adaptation in response to context changes. The service properties that need to hold at runtime are also represented graphically in a form similar to the scenarios. Second, a technique is introduced to enumerate and generate the specifications of a service's variants from its scenarios. The generated variants are then validated against the service properties to ensure their validity. This technique also checks the consistency of the service's adaptation requirements (scenarios). Case studies have shown that with our approach, a small number of service scenarios specified by the software engineer is able to cover a large number of service variants, which are generated and validated automatically.
Mahmoud Hussein, Jun Han 0004, Jian Yu 0002, Alan W. Colman
ICWS2
2013 Supporting Adaptation Patterns in the Event-Driven Business Process Modeling Paradigm
Malinda Kapuruge, Jun Han 0004, Alan W. Colman
WISE (2)2
2013 An Ontology-Based Approach to Context-Aware Access Control for Software Services
A. S. M. Kayes, Jun Han 0004, Alan W. Colman
WISE (1)2
2012 QoS-Driven Service Selection for Multi-tenant SaaS
abstract
Cloud-based software applications (Software as a Service - SaaS) for multi-tenant provisioning have become a major development paradigm in Web engineering. Instead of serving a single end-user, a multi-tenant SaaS provides multiple end-users with the same functionality but with potentially different quality-of-service (QoS) values. The service selection for such a SaaS is a complex decision-making process which involves a number of stakeholders with different QoS requirements. SaaS developers need to compose services with different QoS values to meet end-users' different multidimensional QoS constraints for the SaaS. Furthermore, they also need to satisfy SaaS providers' optimisation goals for the SaaS, such as least resource cost and best system performance. Existing QoS-aware service selection approaches are oriented at a single tenant. They do not consider the characteristics of multi-tenant SaaS and hence are ineffective and inefficient when applied to compose multi-tenant SaaS. In this paper, we introduce a novel QoS-driven approach for helping SaaS developers select the services for composing multi-tenant SaaS, which achieves SaaS providers' optimisation goals while fulfilling the end-users' different levels of QoS constraints. The proposed approach is evaluated using an example SaaS synthetically generated based on a dataset of real-world Web services. Experimental results show that our approach significantly outperforms existing approaches in terms of both effectiveness and performance.
Qiang He 0001, Jun Han 0004, Yun Yang 0001, John C. Grundy, Hai Jin 0001
IEEE CLOUD2
2012 ICAF: A Context-Aware Framework for Access Control
A. S. M. Kayes, Jun Han 0004, Alan W. Colman
ACISP2
2012 Modeling and Verification of Context-Aware Systems
abstract
Verifying adaptive behavior is a critical challenge in the development of context-aware systems due to their complexity and uncertainty. This paper presents our novel model-based approach that provides a modeling framework to (1) specify the structural and behavioral aspects of a context-aware system, (2) define invariants of the system that need to be satisfied regardless of the adaptations, and (3) support formal verification of the system model against the invariants. Underlying this framework is our ROAD4Context model that supports the separation of adaptation concerns in context-aware systems. We show how the behavioral model of ROAD4Context can be translated into Petri nets, and how it can be verified against the system invariants. We demonstrate our approach through the modeling and verification of an adaptive cruise control system.
Minh H. Tran, Alan W. Colman, Jun Han 0004, Hongyu Zhang 0002
APSEC3
2012 SCIMS: A Social Context Information Management System for Socially-Aware Applications
Muhammad Ashad Kabir, Jun Han 0004, Jian Yu 0002, Alan W. Colman
CAiSE2
2012 Dynamic Performance Management in Multi-tenanted Business Process Servers Using Nonlinear Control
Tharindu Patikirikorala, Indika Kumara, Alan W. Colman, Jun Han 0004, Liuping Wang, Denis Weerasiri, Waruna Ranasinghe
ICSOC4
2012 PerCAS: An Approach to Enabling Dynamic and Personalized Adaptation for Context-Aware Services
Jian Yu 0002, Jun Han 0004, Quan Z. Sheng, Steven O. Gunarso
ICSOC2
2012 Enabling the Delivery of Customizable Web Services
abstract
Due to differences in consumer requirements, a Web service usually has multiple service variants for use in different business contexts. In such situations, delivering customizable services helps increase efficiency not only in service description and publication but also in service consumption. However, existing approaches for providing customizable services enforce the tight coupling between providers and consumers. Nor do they take into account recursive nature of service customization. Consequently, the approaches hamper the widespread use of customizable services in SOA. In this paper, we propose a language, namely Web Service Variability Description Language (WSVL), which formalizes the customization interface between providers and consumers using the XML technology to address these problems. We also describe a reference architecture for service deployment and a service engineering technique which together support the provisioning of WSVL-based customizable services. A proof-of-concept prototype system is introduced to demonstrate the feasibility of our approach.
Alan W. Colman, Jun Han 0004
ICWS3
2012 Quokka: visualising interactions of enterprise software environment emulators
abstract
Enterprise software systems operate in large-scale, heterogeneous, distributed environments which makes assessment of non-functional properties, such as scalability and robustness, of those systems particularly challenging. Enterprise environment emulators can provide test-beds representative of real environments using only a few physical hosts thereby allowing assessment of the non-functional properties of enterprise software systems. To date, analysing outcomes of these tests has been an ad hoc and somewhat tedious affair; largely based on manual and/or script-assisted inspection of interaction logs. Quokka visualises emulations significantly aiding analysis and comprehension. Emulated interactions can be viewed live (in real-time) as well as be replayed at a later stage, furthermore, basic charts are used to aggregate and summarise emulations, helping to identify performance and scalability issues.
Cameron M. Hine, Jean-Guy Schneider, Jun Han 0004, Steve Versteeg
ASE3
2012 Scenario-Driven Development of Context-Aware Adaptive Web Services
Mahmoud Hussein, Jian Yu 0002, Jun Han 0004, Alan W. Colman
WISE3
2012 Representing Service-Relationships as First Class Entities in Service Orchestrations
Malinda Kapuruge, Jun Han 0004, Alan W. Colman
WISE2
2012 A semantically enhanced service repository for user-centric service discovery and management
Jian Yu 0002, Quan Z. Sheng, Jun Han 0004, Yanbo Wu, Chengfei Liu
Data Knowl. Eng.3
2012 An evaluation of multi-model self-managing control schemes for adaptive performance management of software systems
Tharindu Patikirikorala, Alan W. Colman, Jun Han 0004, Liuping Wang
J. Syst. Softw.3
2011 Defining Customizable Business Processes without Compromising the Maintainability in Multi-tenant SaaS Applications
abstract
In Software-as-a-Service (SaaS) delivery model a vendor maintains a single application instance, which is used by multiple tenants. However, due to changing business requirements tenants expect customizations. Providing such customizations is trivial to retain tenants but a challenge to the vendor due to multi-tenancy. In this paper we present an approach to define such customizable business processes in multi-tenant SaaS applications without unnecessary and hard to maintain duplication of process definitions and deployments.
Malinda Kapuruge, Alan W. Colman, Jun Han 0004
IEEE CLOUD3
2011 Tackling the Loss of Control: Standards-Based Conjoint Management of Security Requirements for Cloud Services
abstract
The loss of control over information assets is a major security and privacy concern in the Cloud. Service consumers typically have no insights which controls protect their information assets and how effectively. To tackle this challenge, we propose an approach where service providers and consumers conjointly manage security requirements for a Cloud service following the ISO 27001 standard for information security management. We have developed a security management platform that provides tool support for service providers and consumers (i) to specify and consolidate security requirements and (ii) to collect, measure, analyse and report information about the effectiveness of implemented controls. By involving service consumers in management activities following an international standard, our approach helps service providers to increase transparency and traceability of their security measures whereas service consumers gain much-needed insights in the protection of their information assets. The applicability of our approach is demonstrated with an example scenario.
Ingo Mueller 0001, Jun Han 0004, Jean-Guy Schneider, Steve Versteeg
IEEE CLOUD2
2011 An Approach to Model-Based Development of Context-Aware Adaptive Systems
abstract
Many software systems need to be developed with adaptation in mind, where at runtime they need to detect changes in their operating environments and adapt themselves to cope with these changes while achieving or preserving the overall system goals. In recent years, there has been much research in the communities of context-aware systems and self-adaptive systems with their own foci. However, addressing context awareness and self-adaptation in a consistent and integrated manner remains a major challenge. In this paper, we introduce a novel approach to modeling and realizing such context-aware adaptive software systems. Our approach explicitly separates but relates the context model and the system model, so that their relationships, changes, and change impacts across the system and its contexts can be clearly captured and managed. In particular, we differentiate management context from operational context as to whether or not context changes cause system adaptation. To enable runtime changes to the system, its contexts, and their relationships, they all have their runtime representation, so that they can be manipulated and managed at runtime. Our component model for realizing the approach directly supports component interface definitions for context and management as well as functionality. Furthermore, we have developed a tool to generate the system implementations from their models and to validate and verify their context-aware adaptive behavior. We demonstrate our approach through the modeling and realization of a context-aware vehicle route planning system.
Mahmoud Hussein, Jun Han 0004, Alan W. Colman
COMPSAC2
2011 Modeling and Coordinating Social Interactions in Pervasive Environments
abstract
The convergence of Internet and mobile devices has radically changed the way people communicate and interact with each other, and demand for applications that are "social" enough to assist their daily interactions. To support such device mediated interactions, the social relationships between actors need to be systematically modeled and represented. In addition, an application facilitating such interactions should be able to deal with the task conflicts that occur when an actor is involved in multiple interactions simultaneously. To address these issues, in this paper we present an approach to modeling and coordinating social interactions with the notion of social context. It supports social interaction modeling from both the domain- and player-centric perspectives. In particular, the player-centric model provides the basis to coordinate multiple interactions in which an actor is involved. We further introduce a fuzzy logic based reasoning technique to infer the overall importance of each interaction, assisting the actor to resolve conflicts and make decisions. Finally, we validate our approach through a prototype implementation and test cases analysis.
Muhammad Ashad Kabir, Jun Han 0004, Alan W. Colman
ICECCS2
2011 Modeling and Managing Variability in Process-Based Service Compositions
Alan W. Colman, Jun Han 0004
ICSOC3
2011 Achieving Multi-tenanted Business Processes in SaaS Applications
Malinda Kapuruge, Alan W. Colman, Jun Han 0004
WISE3
2010 Service-Based Development of Context-Aware Automotive Telematics Systems
abstract
Automotive software has increasingly become context-aware and adaptive to deal with dynamically changing environments. This paper presents our novel service-based approach to support the structural and behavioral adaptation of automotive telematics. We adopt services to (1) provide physical context facts and (2) facilitate context-aware interactions between entities of automotive telematics systems. In this paper, we introduce a layered architecture of our approach and demonstrate how the approach is applied to develop context-aware automotive telematics systems that support V2X interactions. The empirical evaluations show that our service-based approach is scalable to supporting run-time adaptation of automotive telematics.
Minh H. Tran, Alan W. Colman, Jun Han 0004
ICECCS3
2010 Optimizing the Configuration of Web Service Monitors
Garth Heward, Jun Han 0004, Ingo Mueller 0001, Jean-Guy Schneider, Steve Versteeg
ICSOC2
2010 An Approach to Query Decomposition for Reader Level Filtering in RFID Middleware
abstract
In RFID systems, middleware is used to filter enormous streaming data gathered continuously from readers to process application requests. The high volume of data makes middleware often in a highly overloaded situation. Nowadays, readers are becoming smart and provide filtering functionality. The reader filtering capability can be used to reduce data volume as well as middleware work-load. However, if middleware dispatches query conditions to reader without any adjustment, it may generate huge amount of duplicate data which imposes considerable load on the middleware. So, the appropriate schema of data volume reduction is required. In this paper, we propose a query decomposition technique to divide queries into sub-queries for middleware and reader level execution. This new approach of query execution resolves the problem of duplicate data generation. Our experiments show that the proposed approach considerably improves the performance of middleware by reducing the query processing time and the network traffic between reader and middleware.
Muhammad Ashad Kabir, Jun Han 0004, Wooseok Ryu, Bonghee Hong
RTCSA2
2010 Propagation of Data Protection Requirements in Multi-stakeholder Web Services Systems
Tan Phan, Jun Han 0004, Garth Heward, Steve Versteeg
WISE2
2010 Protecting data in multi-stakeholder web service system
abstract
Current Web Service security standards have inadequate support for end-to-end protection of data when some receivers of the data are unknown to the sender. This paper presents an approach to aid collaborative partner services in properly protecting each other's data. Our approach allows each partner to derive an adequate protection mechanism with minimum performance overhead for each message it sends based on those of the corresponding messages it receives. We modify the message handling mechanisms of Web Service engines to dynamically gather protection requirements for a given outgoing message by aggregating requirements from original owners of message data.
Tan Phan, Jun Han 0004, Garth Heward, Steve Versteeg
WWW2
2009 Social context: Supporting interaction awareness in ubiquitous environments
abstract
In ubiquitous computing environments, certain entities (or actors) often need to interact with each other in achieving a joint goal in a dynamically changing context. To perform such interactions in a seamless manner, the actors need to be aware of not only their physical context (e.g. location) but
Minh H. Tran, Jun Han 0004, Alan W. Colman
MobiQuitous2
2008 Quality-Driven Business Policy Specification and Refinement for Service-Oriented Systems
Tan Phan, Jun Han 0004, Jean-Guy Schneider, Kirk Wilson
ICSOC2
2008 Synthesizing Service Composition Models on the Basis of Temporal Business Rules
Jian Yu 0002, Yanbo Han, Jun Han 0004, Paolo Falcarin, Maurizio Morisio
J. Comput. Sci. Technol.3
2008 Introduction to the Special Issue
John C. Grundy, Jun Han 0004
J. Syst. Softw.2
2007 The Four Major Challenges of Engineering Adaptive Software Architectures
abstract
Building an adaptive software system that can cope with changing requirements and changing environments presents four major challenges. These are (1) to receive, represent and reason about changing requirements and goals; (2) to cope with volatility of the computational context in which it executes; (3) to work with other systems that are heterogeneous and distributed; and (4) to do all of the above without becoming too complex to develop and maintain. These challenges can be addressed by architectures that focus on the adaptivity of relationships rather than entities. Role-Oriented Adaptive Design (ROAD) is presented as such an architecture that addresses the challenges.
Jun Han 0004, Alan W. Colman
COMPSAC (2)1
2007 Performance Evaluation and Prediction for Legacy Information Systems
abstract
Database-centric information systems are critical to the operations of large organisations. In particular, they often process a large amount of data with stringent performance requirements. Currently, however, there is a lack of systematic approaches to evaluating and predicting their performance when they are subject to an exorbitant growth of workload. In this paper, we introduce such a systematic approach that combines benchmarking, production system monitoring, and performance modelling (BMM) to address this issue. The approach helps the performance analyst to understand the system's operating environment and quantify its performance characteristics under varying load conditions via monitoring and benchmarking. Based on such realistic measurements, modelling techniques are used to predict the system performance. Our experience of applying BMM to a real-world system demonstrates the capability of BMM in predicting the performance of existing and enhanced software architectures in planning for its capacity growth.
Antony Tang, Jun Han 0004
ICSE3
2007 Guiding the Service Composition Process with Temporal Business Rules
abstract
Service composition has become an important paradigm for building distributed applications and e-business processes. While effort has been reported to verify a posteriori whether a given composition such as a BPEL schema satisfies the predefined behavioural properties, little effort has been made to utilise the properties to assist the designer in developing a correct service composition in the first place. This paper reports our first attempt towards this goal by presenting a framework and associated techniques to provide automated guidance to the designer during the composition design process. The guidance can be suggestions on the next valid steps in the business process, identifications of missing/misplaced steps, and/or propositions for inserting, deleting or reordering activities. The guidance is provided based on the temporal business rules which state the temporal/sequential relationships between business activities.
Jun Han 0004, Tan Phan, Jian Yu 0002
ICWS1
2007 A rationale-based architecture model for design traceability and reasoning
Antony Tang, Jun Han 0004
J. Syst. Softw.3
2007 Using Bayesian belief networks for change impact analysis in architecture design
Antony Tang, Ann E. Nicholson, Jun Han 0004
J. Syst. Softw.4
2007 Using role-based coordination to achieve software adaptability
Alan W. Colman, Jun Han 0004
Sci. Comput. Program.2
2006 Security-Oriented Service Composition and Evolution
abstract
This paper introduces a framework for security-oriented software service composition and evolution. Key building blocks of the framework are a semantic model for specifying the security objectives and properties at the service and system levels, the negotiation and re-negotiation techniques for service composition and evolution, and the analysis techniques for checking the security compatibility between services and the satisfaction of system-level security goals. It focuses on developing techniques that allow system developers to design required security into service compositions with predictability and to maintain or adapt service compositions in changed security contexts.
Jun Han 0004, Khaled M. Khan
APSEC1
2006 Secrobat: Secure and Robust Component-based Architectures
abstract
Software systems, component-based systems (CBS) in particular, have a lot of vulnerabilities that may be exploited by intruders. Companies spend much time and money to "patch " them up. It is partly due to the fact that a system's security features are often added to the system after its functional requirements have been addressed. As such, system security features are not systematically designed into the system, and consequently the system has inherent security "holes". Therefore, there is a strong need for a systematic engineering approach to developing secure and robust systems, especially distributed systems, by considering functional and security requirements at the same time. In particular, these systems should be highly adaptive and reconfigurable in order to resist different types of attacks and failures. This paper introduces a reference architecture, called Secrobat, for creating secure and robust CBS. It has several key features including defensive components and the adaptive and reconfigurable architecture with the hybrid peer/super-peer structure. The reference architecture is illustrated with an example gaming system.
Artem Vorobiev, Jun Han 0004
APSEC2
2006 International workshop on service oriented software engineering (IW-SOSE'06)
abstract
No abstract available.
Elisabetta Di Nitto, Robert J. Hall 0001, Jun Han 0004, Yanbo Han, Andrea Polini, Kurt Sandkuhl, Andrea Zisman
ICSE3
2006 Using Dynamic Asynchronous Aggregate Search for Quality Guarantees of Multiple Web Services Compositions
Xuan Thang Nguyen, Ryszard Kowalczyk, Jun Han 0004
ICSOC3
2006 Adaptive Service Agreement and Process Management
abstract
The ASAPM project aims at developing new techniques, mechanisms and software solutions for enablement of flexible, dynamic and robust management of serviceoriented application provision processes to ensure collective functionality, end-to-end QoS and stateful coordination of complex services.
Boris Wu, Jian Ying Zhang, Mohan Baruwal Chhetri, SukKeong Goh, Xuan Thang Nguyen, Ingo Mueller 0001, E. Gomes, Jun Han 0004, Ryszard Kowalczyk
ICWS10
2006 Pattern Based Property Specification and Verification for Service Composition
Jian Yu 0002, Tan Phan Manh, Jun Han 0004, Yanbo Han, Jianwu Wang 0001
WISE3
2006 A survey of architecture design rationale
Antony Tang, Muhammad Ali Babar 0001, Ian Gorton, Jun Han 0004
J. Syst. Softw.4
2005 Consistency and Interoperability Checking for Component Interaction Rules
abstract
In component-based software development, it is important to ensure interoperability between components based on their unambiguous semantic descriptions, in order to obtain a viable system. A body of recent work has explored the use of formal languages in specifying component interaction protocols for interoperability checking, but lacks the practicality required by software practitioners for daily use. Faced with this, we have developed a lightweight specification approach to component interaction rules, which has the necessary expressiveness and employs event patterns in rule specification for easy adoption by practitioners. In this paper, we present a FSA-based semantic model for such rules and novel studies of rule consistency and system-wide protocol interoperability for components annotated with interaction rules. We also develop incremental approaches and tools to check these properties, which provide an effective means to discover errors in the design of component interaction rules and component-based system architectures.
Jun Han 0004
APSEC2
2005 Coordination Systems in Role-Based Adaptive Software
Alan W. Colman, Jun Han 0004
COORDINATION2
2005 Pattern-Based Specification and Validation of Web Services Interaction Properties
Jun Han 0004
ICSOC2
2005 A Survey of the Use and Documentation of Architecture Design Rationale
abstract
Many claims have been made about the problems caused by not documenting design rationale. The general perception is that designers and architects usually do not fully understand the critical role of systematic use and capture of design rationale. However, there is to date little empirical evidence available on what design rationale mean to practitioners, how valuable they consider them, and how they use and document design rationale during the design process. This paper reports an empirical study that surveyed practitioners to probe their perception of the value of design rationale and how they use and document background knowledge related to their design decisions. Based on eighty-one valid responses, this study has discovered that practitioners recognize the importance of documenting design rationale and frequently use them to reason about their design choices. However, they have indicated barriers to the use and documentation of design rationale. Based on the findings, we conclude that much research is needed to develop methodology and tool support for design rationale capture and usage. Furthermore, we put forward some research questions that would benefit from further investigation into design rationale in order to support practice in industry.
Antony Tang, Muhammad Ali Babar 0001, Ian Gorton, Jun Han 0004
WICSA4
2005 Predicting Change Impact in Architecture Design with Bayesian Belief Networks
abstract
Research into design rationale in the past has focused on the representation of reasons and has omitted the connections between design rationales and design artefacts. Without such connections, designers and architects cannot easily assess how changing requirements or designs may affect the system. In this paper, we introduce a model called Architecture Rationale and Element Linkage (AREL) to represent the causal relationship between architecture elements and decisions. We further model AREL as a Bayesian Belief Network (BBN) to capture the probabilistic relationships between architecture elements and decisions in an architecture design model. Such probabilistic modelling enables architects to quantitatively predict and diagnose impact of change when part of the requirements or designs are changing. Using a partial design of a cheque image processing system, we illustrate how AREL is used to represent the decision model and how BBN is used to predict and diagnose change in the architecture design. We use a UML tool to capture the AREL model and a BBN tool to compute the probabilities of change impact.
Antony Tang, Jun Han 0004, Ann E. Nicholson
WICSA3
2004 A Comparative Analysis of Architecture Frameworks
abstract
Architecture frameworks are methods used in architecture modeling. They provide a structured and systematic approach to designing systems. To date there has been little analysis on their roles in system and software engineering and if they are satisfactory. This study provides a model of understanding through analyzing the goals, inputs and outcomes of six architecture frameworks. It characterizes two classes of architecture frameworks and identifies some of their deficiencies. To overcome these deficiencies, we propose to use costs, benefits and risks for architecture analysis. We also propose a method to delineate architecture activities from detailed design activities.
Antony Tang, Jun Han 0004, Pin Chen
APSEC2
2003 Ensuring Compatible Interactions within Component-based Software Systems
abstract
The interface definition of a component in a distributed system forms the contract between the component itself and its neighbouring components regarding the use of its services. In general, such a contract should cover the issues of service functionality, usage and quality. The interface definition languages (IDLs) used by commercial middleware standards such as CORBA primarily address the signature issues of such a contract, i.e., the forms and types of component or object services. Nothing is said about other aspects of the contract, including the way in which the component services are to be used. We introduce a framework and associated techniques that augment commercial IDLs with interaction protocol specifications and validate component interactions against such protocol specifications at run-time. In effect, the validation becomes a useful tool for testing whether or not the object services are used properly in a distributed system. Our approach has been implemented in the CORBA context, but can be readily applied to other IDL-based object/component systems.
Jun Han 0004, Ksze Kae Ker
APSEC1
2003 A Security Characterisation Framework for Trustworthy Component Based Software Systems
abstract
This paper explores how to characterize security properties of software components, and how to reason about their suitability for a trustworthy compositional contract. Our framework provides an explicit opportunity for software composers as well as software components to test a priori security properties of software components in a system composition. The proposed framework uses logic programming as a tool to represent security properties of atomic components and reason about their compositional matching with other components. This enables software components as well as composers to "test" possible matches and mismatches between the security properties of the candidate components and the security requirements of the enclosing applications systems.
Khaled M. Khan, Jun Han 0004
COMPSAC2