VLDB 2026 Research / reviewers in the wild / expert
Sandun Dasanayake
dblp:148/1286
· DBLP profile ↗
6ranked-venue papers
3as first author
2since 2021 · last 2026
0000-0001-6409-9001ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 6 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Managing security issues in software containers: From practitioners' perspectiveabstractSoftware development industries are increasingly adopting containers to enhance the scalability and flexibility of applications. Security in containerized projects is a critical challenge that can lead to data breaches and performance degradation, thereby directly affecting the reliability and operations of the container services. Despite the ongoing effort to manage the security issues in containerized projects in SE research, more investigations are needed to explore the human perspective of security management in containerized projects. This research aims to explore security management in containerized projects by exploring how SE practitioners manage the security issues in containerized projects. A clear understanding of security management in containerized projects will enable industries to develop robust security strategies that enhance software reliability and trust. To achieve this, we conducted two semi-structured interview studies to examine how practitioners approach security management. The first study focused on practitioners’ perceptions of security challenges in containerized environments, where we interviewed 15 participants between December 2022 and October 2023. The second study explored how to address security issues, with 20 participants interviewed between October 2024 and December 2024. Data analysis reveals how SE practitioners address the various security challenges in containerized projects. Our analysis also identified the technical and non-technical enablers that can be utilized to enhance security in containerized projects. Overall, we propose a conceptual model that visualizes how practitioners manage security issues in containerized projects. We argue that our proposed model will guide practitioners in making informed decisions to plan, develop, and deploy secure container systems. Maha Sroor, Rahul Mohanani, Ricardo Colomo-Palacios, Sandun Dasanayake, Tommi Mikkonen |
J. Syst. Softw. | 4 |
| 2024 | Practitioners' Perceptions of Security Issues in Software Containers: A Qualitative StudyabstractSoftware containers have emerged as solutions for developing and deploying software applications. Despite the popularity and portability of containers, there is significant concern about container security, which hinders their adoption. Recent research has made efforts to investigate container security theoretically and experimentally. Meanwhile, software practitioners have also developed practices to improve and maintain container security based on their work experience. However, a notable gap exists in expressing practitioners' viewpoints on container security. Consequently, this study aims to understand practitioners' perceptions of container security and their man-agement strategies in real-world projects. We conducted semi-structured interviews with practitioners across various domains to explore their opinions on container security issues, causes, implications, tools, and practices. Our data analysis reveals emergent patterns in handling container security in real projects. These patterns are presented as a model that highlights the relationships between the major themes and how they affect each other. Our findings reveal that containers offer many advantages to software systems but face challenges in maintaining security. Finally, this research attempts to bridge the knowledge gap between academia and industry by providing a comprehensive understanding of container security issues as perceived by the practitioners and their interrelationships. Maha Sroor, Rahul Mohanani, Teerath Das, Tommi Mikkonen, Sandun Dasanayake |
SEAA | 5 |
| 2019 | Impact of requirements volatility on software architecture: How do software teams keep up with ever-changing requirements?abstractAbstract Requirements volatility is a major issue in software development, causing problems such as higher defect density, project delays, and cost overruns. Software architecture that guides the overall vision of software product is one of the areas that is greatly affected by requirements volatility. Since critical architecture decisions are made based on the requirements at hand, changes in requirements can result significant changes in architecture. With the wide adoption of agile software development, software architectures are designed to accommodate possible future changes. However, the changes has to be carefully managed as unnecessary and excessive changes can bring negative consequences. An exploratory case study was conducted to study the impact of requirements volatility on software architecture. Fifteen semistructured, thematic interviews were conducted in a European software company. The research revealed poor communication, information distortion, and external dependencies as the main factors that cause requirement volatility and inadequate architecture documentation, inability to trace design rationale, and increased complexity as the main implications of requirements volatility on software architecture. Insights from software teams' awareness of the requirement volatility, factors contribute to it, and possible ways to mitigate its implications will be utilized to improve the management of requirement volatility during software architecting process. Sandun Dasanayake, Sanja Aaramaa, Jouni Markkula, Markku Oivo |
J. Softw. Evol. Process. | 1 |
| 2017 | Requirements volatility in software architecture design: an exploratory case studyabstractRequirements volatility is a major issue in software (SW) development, causing problems such as project delays and cost overruns. Even though there is a considerable amount of research related to requirement volatility, the majority of it is inclined toward project management aspects. The relationship between SW architecture design and requirements volatility has not been researched widely, even though changing requirements may for example lead to higher defect density during testing. An exploratory case study was conducted to study how requirements volatility affects SW architecture design. Fifteen semi-structured, thematic interviews were conducted in the case company, which provides the selection of software products for business customers and consumers. The research revealed the factors, such as requirements uncertainty and dynamic business environment, causing requirements volatility in the case company. The study identified the challenges that requirements volatility posed to SW architecture design, including scheduling and architectural technical debt. In addition, this study discusses means of mitigating the factors that cause requirements volatility and addressing the challenges posed by requirements volatility. SW architects are strongly influenced by requirement volatility. Thus understanding the factors causing requirements volatility as well as means to mitigate the challenges has high industrial relevance. Sanja Aaramaa, Sandun Dasanayake, Markku Oivo, Jouni Markkula, Samuli Saukkonen |
ICSSP | 2 |
| 2016 | An Empirical Study on Collaborative Architecture Decision Making in Software Teams
Sandun Dasanayake, Jouni Markkula, Sanja Aaramaa, Markku Oivo |
ECSA | 1 |
| 2014 | Concerns in software development: a systematic mapping studyabstractContext: Successfully addressing stakeholder concerns that are related to software system development and operation is crucial to achieving development goals. The importance of using a systematic approach to addressing these concerns throughout the software development life cycle is growing as more and more systems are employed to handle critical tasks. Objective: The goal of this study is to provide an overview of addressing concerns across the software development life cycle. Method: A systematic mapping study was conducted using a pre-defined protocol. Four digital databases were searched for research literature and primary studies were selected after a three round selection process conducted by multiple researchers. Results: The extracted data are processed and the results are reported from different viewpoints. The results are also analyzed against our research goals. Conclusion: We show that there is a considerable variation in the use of terminologies and addressing concerns in different phases of the software development life cycle. Sandun Dasanayake, Jouni Markkula, Markku Oivo |
EASE | 1 |