Elaine Venson

dblp:177/4516 · DBLP profile ↗
← Back
10ranked-venue papers
5as first author
4since 2021 · last 2025
0000-0002-7607-5936ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 7 · 3 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-authorSecurity and privacy · 1 · 1 first-author
YearPublicationVenuePosition
2025 Exploring the Role of Service Design in Software Development: A Systematic Mapping
Henrique Pucci Pinto, Júlia de Souza, Elaine Venson, Rejane Maria da Costa Figueiredo
ENASE3
2024 The effects of required security on software development effort
Elaine Venson, Bradford K. Clark, Barry W. Boehm
J. Syst. Softw.1
2023 How SonarQube-identified technical debt is prioritized: An exploratory case study
Reem Alfayez, Robert Winn, Wesam Alwehaibi, Elaine Venson, Barry W. Boehm
Inf. Softw. Technol.4
2021 Analyzing Software Security-related Size and its Relationship with Vulnerabilities in OSS
abstract
This paper presents a preliminary and exploratory study of the relationship of software security-related size, in lines of code, and the software security level, expressed as the vulnerability density. We developed a classifier and employed source code analyzers to determine the proportion of security-related code and the security level of a sample of 162 open source software (OSS) projects, developed in five different programming languages. Based on the information collected, we analyzed the proportion of security-related code and investigated its correlation with the static analysis vulnerability density of the selected projects. We found that the proportion of security size in OSS can vary depending on its type. Enterprise OSS present a median of 22 % of its code related to security, whereas volunteer-based OSS have a 9% median. We did not find a correlation between security-related size and vulnerability density. However, by filtering only volunteer-based OSS projects in the sample, we found a moderate positive correlation between vulnerability density and the proportion of security-related size. Our study results do not support the idea that a larger proportion of security-related code is associated with more security in terms of a lower vulnerability density. Nonetheless, the type of OSS, namely volunteer-based or enterprise, seems to have a significant impact on software security. Volunteer-based OSS presented a smaller proportion of security-related code, but as this proportion increases, so does the vulnerabilities, indicating a worsening on the security level. The phenomenon was not identified in enterprise OSS.
Elaine Venson, Ting Fung Lam, Bradford K. Clark, Barry W. Boehm
QRS1
2020 A systematic literature review of technical debt prioritization
abstract
Repaying all technical debt (TD) present in a system may be unfeasible, as there is typically a shortage in the resources allocated for TD repayment. Therefore, TD prioritization is essential to best allocate such resources to determine which TD items are to be repaid first and which items are to be delayed until later releases. This study conducts a systematic literature review (SLR) to identify and analyze the currently researched TD prioritization approaches. The employed search strategy strove to achieve high completeness through the identification of a quasi-gold standard set, which was used to establish a search string to automatically retrieve papers from select research databases. The application of selection criteria, along with forward and backward snowballing, identified 24 TD prioritization approaches. The analysis of the identified approaches revealed a scarcity of approaches that account for cost, value, and resources constraint and a lack of industry evaluation. Furthermore, this SLR unveils potential gaps in the current TD prioritization research, which future research may explore.
Reem Alfayez, Wesam Alwehaibi, Robert Winn, Elaine Venson, Barry W. Boehm
TechDebt@ICSE4
2019 Costing Secure Software Development: A Systematic Mapping Study
abstract
Building more secure software is a recent concern for software engineers due to increasing incidences of data breaches and other types of cyber attacks. However, software security, through the introduction of specialized practices in the software development life cycle, leads to an increase in the development cost. Although there are many studies on software cost models, few address the additional costs required to build secure software. We conducted a systematic review in the form of a mapping study to classify and analyze the literature related to the impact of security in software development costs. Our search strategy strove to achieve high completeness by the identification of a quasi-gold-standard set of papers, which we then used to establish a search string and retrieve papers from research databases automatically. The application of inclusion/exclusion criteria resulted in a final set of 54 papers, which were categorized according to the approach to software security cost analysis. Perform Security Review, Apply Threat Modeling, and Perform Security Testing were the three most frequent activities related to cost, and Common Criteria was the most applied standard. We also identified ten approaches to estimating software security costs for development projects; however, their validation remains a challenge, which could be addressed in future studies.
Elaine Venson, Xiaomeng Guo, Zidi Yan, Barry W. Boehm
ARES1
2019 The Impact of Software Security Practices on Development Effort: An Initial Survey
abstract
Background: Software projects are facing the need to adopt security practices during the software development life cycle (SDLC). Nevertheless, the amount of effort to be invested in order to achieve a certain level of software security is not clear yet. Aims: The goal of this study is to get an overview of the application of software security practices in the industry and to identify the impact of the introduction of such activities in software development projects in terms of effort/cost. Method: We conducted a survey on a software security group of a professional social network by applying a random sampling strategy to establish a representative set of participants. Results: The questionnaire was fully answered by 110 participants, from the 808 profiles that were invited from the sampling frame. The results show that security practices have been applied thoroughly in the projects and revealed high variability in secure software development effort across the participants' projects. Further research is needed to understand the different professionals' perspectives regarding security effort in projects. As lessons learned, we found that the professional social network offered a demographically diverse sampling frame, but this comes with hurdles that need to be overcome. Conclusions: The experiences of the participants showed that security is a factor that drives effort in software projects, and security practices need to be taken into account when planning software development initiatives. Our findings about the current state of practices and adoptions can help practitioners and researchers in future endeavors.
Elaine Venson, Reem Alfayez, Marília Miranda Forte Gomes, Rejane Maria da Costa Figueiredo, Barry W. Boehm
ESEM1
2018 Calibrating use case points using bayesian analysis
abstract
Background: Use Case Points (UCPs) have been widely used to estimate software size for object-oriented projects. Yet, many research papers criticize the UCPs methodology for not being verified and validated with data, leading to inaccurate size estimates.
Kan Qi, Anandi Hira, Elaine Venson, Barry W. Boehm
ESEM3
2018 Why there is still few women in Engineering? A perspective from female students and professors in an Engineering campus
abstract
This paper presents the scenario of the Engineering courses of the Faculty UnB Gama (FGA) in relation to the number of male newcomers versus the number of female ones. It is possible to see, through analysis of the data collected, that the number of male students is much higher than that of female ones, from the creation of the campus in the second semester of 2008 until now. This occurs despite FGAs efforts in promoting the Engineering courses on campus using an experimental laboratory, through the Girls in Computing Program, supported by the National Council of Scientific and Technologic Development (CNPq), in partnership with the high schools of the region. Lectures are also conducted, focused on the female public, and looking do debunk the idea that Engineering is a typically male-oriented course, and trying to awaken the vocational interest of women towards Engineering. Through the surveys focused in the low rate of women in engineering courses, some things come up: (1) the lack of stimuli from family and friends when they intend to graduate in this field, and (2), in a way, the stigmatized role of women in Engineering.
Edna Dias Canedo, Giovanni Almeida Santos, Fabiana Freitas Mendes, Elaine Venson, Rejane Maria da Costa Figueiredo
FIE4
2016 Academy-industry collaboration and the effects of the involvement of undergraduate students in real world activities
abstract
As stated by the IEEE Curriculum Guidelines for Undergraduate Degree Programs in Software Engineering, elements outside the classroom such as field trips, visits to industry and technical presentations can affect student's preparation for professional practice. This work describes a framework of academy-industry collaboration where students develop practical and academic activities in a real world scenario. It is a methodological research, in which a case study was conducted with a Government Agency that has a close collaboration with a University. This joint project led to the proposition of new software processes for the organization and produced research and capstone project papers. Results demonstrate that students have acquired experience in solving real world problems in the industry; they received recognition in the academic community through the acceptance of papers in international conferences; and also, the projects executed with the students produced outcomes that brought benefits to the government agency, under study.
Elaine Venson, Rejane Maria da Costa Figueiredo, Wander C. M. Pereira da Silva, Luiz C. M. Ribeiro Jr.
FIE1