VLDB 2026 Research / reviewers in the wild / expert
Awais Rashid
dblp:26/3330
· DBLP profile ↗
110ranked-venue papers
19as first author
30since 2021 · last 2025
0000-0002-0109-1341ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 65 · 10 first-author · 9 since 2021Security and privacy · 28 · 4 first-author · 16 since 2021Artificial intelligence and machine learning · 12 · 3 first-author · 2 since 2021Databases, data management, data science and information retrieval · 12 · 4 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 8 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 first-author · 1 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Securing Ultra-Large Scale Infrastructures: Challenges and Opportunities
Awais Rashid |
ICISSP | 1 |
| 2025 | Ownership and Gatekeeping vs. Safeguarding and Consent: How Migrant Parents Navigate Child Data Management ComplexitiesabstractParents pursuing opportunities abroad increasingly find themselves raising children in new cultural and legal environments. This responsibility extends to complying with unfamiliar regulations and safeguarding their children's data which is often complex and a challenging task. In this study, we examine how migrant parents perceive, manage, and safeguard data related to their children. Through interviews with 17 migrant parents and guardians in the UK, we uncover nuanced and evolving perspectives on data ownership and management. Migrant parents express significant concerns about losing control over data shared locally and with extended families abroad, with fears of misuse that could harm their children or jeopardize their immigration status. We discuss their data management strategies and approaches to navigating changing concepts of data ownership and consent. Our findings underscore the need for culturally sensitive support to help migrant families safeguard their children's data and highlight directions for future research into the complexities of cross-border data sharing and its implications. Rui Huan, Kopo M. Ramokapane, Awais Rashid |
SP | 3 |
| 2025 | Security Implications of the Morello Platform: An Empirical Threat Model-Based AnalysisabstractThis article explores the software security potential of ARM’s Morello experimental hardware platform, an embodiment of the Capability Hardware Enhanced RISC Instructions (CHERI) model. We navigate the intricacies of Morello adoption, uncovering both the promise and the challenges it presents for bolstering software security assurance. Employing the Juliet Test Suite, we conduct a rigorous security assessment of Morello’s operational modes—Purecap and Hybrid—shedding light on the ramifications for the software development lifecycle and assurance processes. Our findings affirm the robust spatial safety Morello confers, especially in its Purecap mode, while also underscoring the persisting temporal vulnerabilities in the CheriBSD version used in our experiments. We discuss the novel challenges associated with Morello adoption, including the management of CHERI violation exceptions, the imperative of software-hardware co-validation, and the specialized training requisites for development and assurance teams. We draw attention to potential risks, like crashes from CHERI violations potentially metamorphosing into Denial of Service (DoS) attacks. Transitioning to the Morello model could necessitate substantial alterations in software design principles, development methodologies, and security assurance protocols. Awais Rashid |
ACM Trans. Priv. Secur. | 2 |
| 2024 | Using AI Assistants in Software Development: A Qualitative Study on Security Practices and ConcernsabstractFollowing the recent release of AI assistants, such as OpenAI's ChatGPT and GitHub Copilot, the software industry quickly utilized these tools for software development tasks, e.g., generating code or consulting AI for advice. While recent research has demonstrated that AI-generated code can contain security issues, how software professionals balance AI assistant usage and security remains unclear. This paper investigates how software professionals use AI assistants in secure software development, what security implications and considerations arise, and what impact they foresee on secure software development. We conducted 27 semi-structured interviews with software professionals, including software engineers, team leads, and security testers. We also reviewed 190 relevant Reddit posts and comments to gain insights into the current discourse surrounding AI assistants for software development. Our analysis of the interviews and Reddit posts finds that despite many security and quality concerns, participants widely use AI assistants for security-critical tasks, e.g., code generation, threat modeling, and vulnerability detection. Their overall mistrust leads to checking AI suggestions in similar ways to human code, although they expect improvements and, therefore, a heavier use for security tasks in the future. We conclude with recommendations for software professionals to critically check AI suggestions, AI creators to improve suggestion security and capabilities for ethical security tasks, and academic researchers to consider general-purpose AI in software development. Jan H. Klemmer, Stefan Horstmann, Nikhil Patnaik, Cordelia Ludden, Cordell Burton Jr., Carson Powers, Fabio Massacci, Akond Ashfaque Ur Rahman, Daniel Votipka, Heather Lipford, Awais Rashid, Alena Naiakshina, Sascha Fahl |
CCS | 11 |
| 2024 | Porting to Morello: An In-depth Study on Compiler Behaviors, CERT Guideline Violations, and Security ImplicationsabstractAs the need for secure systems grows, the exploration of secure hardware like Morello, based on the Capability Hardware Enhanced RISC Instructions (CHERI) architecture, becomes crucial. As Morello navigates towards market induction, establishing systematic approaches for transitioning software to its pure capability mode emerges as a crucial research endeavor. This paper investigates two main areas: a comparison with CERT guidelines and an exploitation analysis on the Morello platform. The comparison aims to identify potential developer-induced vulnerabilities and compiler limitations, elucidating how the Morellollvm compiler behaves when there are CERT rule violations. Our exploitation analysis explores the limitations of the Morello-llvm compiler toolchain and the developer errors that could bypass Morello's advanced security features. The findings highlight that despite advancements in toolchains, developer-induced vulnerabilities remain a significant issue, emphasizing the importance of adhering to established programming standards like CERT guidelines. Awais Rashid |
EuroS&P | 2 |
| 2024 | "When Data Breaches Happen, Where Does the Buck Stop?... and where should it stop?"abstractA digital-first society requires its citizens to carry out essential activities online e.g., applying for a passport, managing pension funds or scheduling medical appointments. Sensitive and personal information is requested and provided in the hope that the confidentiality, integrity and availability thereof will be preserved. In reality, data breaches occur with distressing regularity. When this occurs, ‘second’ victims are created: the customers whose data has been leaked. In many cases, service providers demonstrate very little care or concern for these victims, responsibilizing instead of supporting them. We surveyed 175 respondents, including second victims, non-victims and managers. It becomes clear that a ‘feudal security’ paradigm informs organisations’ responses to data breaches. Indeed, the buck seems to stop with second victims, instead of with the breached service provider. We propose an ‘Ethical Responsibilization’ paradigm which would see second victims treated more equitably and fairly. Partha Das Chowdhury, Karen Renaud, Awais Rashid |
NSPW | 3 |
| 2024 | Unveiling the Hunter-Gatherers: Exploring Threat Hunting Practices and Challenges in Cyber Defense
Priyanka Badva, Kopo M. Ramokapane, Eleonora Pantano, Awais Rashid |
USENIX Security Symposium | 4 |
| 2024 | A framework for mapping organisational workforce knowledge profile in cyber securityabstractA cyber security organisation needs to ensure that its workforce possesses the necessary knowledge to fulfil its cyber security business functions. Similarly, where an organisation chooses to delegate their cyber security tasks to a third-party provider, they must ensure that the chosen entity possesses robust knowledge capabilities to effectively carry out the assigned tasks. Building a comprehensive cyber security knowledge profile is a distinct challenge; the field is ever evolving with a range of professional certifications, academic qualifications and on-the-job training. So far, there has been a lack of a well-defined methodology for systematically evaluating an organisation’s cyber security knowledge, specifically derived from its workforce, against a standardised reference point. Prior research on knowledge profiling across various disciplines has predominantly utilised established frameworks such as SWEBOK. However, within the domain of cyber security, the absence of a standardised reference point is notable. In this paper, we advance a framework leveraging Cyber Security Body of Knowledge (CyBOK), to construct an organisation’s knowledge profile. The framework enables a user to identify areas of coverage and where gaps may lie, so that an organisation can consider targeted recruitment or training or, where such expertise may be outsourced, drawing in knowledge capability from third parties. In the latter case, the framework can also be used as a basis for assessing the knowledge capability of such a third party. We present the knowledge profiling framework, discussing three case studies in organisational teams underpinning its initial development, followed by its refinement through workshops with cyber security practitioners. Lata Nautiyal, Awais Rashid |
Comput. Secur. | 2 |
| 2024 | Threat models over space and time: A case study of end-to-end-encrypted messaging applicationsabstractAbstract Threat modeling is one of the foundations of secure systems engineering and must take heed of the context within which systems operate. In this work, we explore the extent to which real‐world systems engineering reflects a changing threat context. We examine the desktop clients of six widely used end‐to‐end‐encrypted mobile messaging applications to understand the extent to which they adjusted their threat model over space (when enabling clients on new platforms, such as desktop clients) and time (as new threats emerged). We experimented with short‐lived adversarial access against these desktop clients and analyzed the results using two popular threat elicitation frameworks, STRIDE and LINDDUN. The results demonstrate that system designers need to track threats in the evolving context within which systems operate and, more importantly, mitigate them by rescoping trust boundaries so that they remain consistent with administrative boundaries. A nuanced understanding of the relationship between trust and administration is vital for robust security, including the provision of safe defaults. Partha Das Chowdhury, Maria Sameen, Jenny Blessing, Nicholas Boucher, Joseph Gardiner, Tom Burrows, Ross J. Anderson, Awais Rashid |
Softw. Pract. Exp. | 8 |
| 2023 | Analysing The Activities Of Far-Right Extremists On The Parler Social NetworkabstractA significant gap remains in our understanding of the types of users who utilise online extremist platforms, as well as how their activity on these platforms influences the radicalisation of others and the dissemination of extremist content online. Our research addresses this gap by focusing on the Parler social network, one of the largest social media platforms used by the extreme far-right, boasting a reported 15 million total users as of January 2022. We present an exploration of the Parler social network, specifically reviewing the roles of users in the network and the types of activity and content shared on the platform. Our methodology provides a novel examination of Parler using tools that have previously been tested to understand other extremist groups. James Stevenson, Matthew Edwards 0001, Awais Rashid |
ASONAM | 3 |
| 2023 | Stuck in the Permissions With You: Developer & End-User Perspectives on App Permissions & Their Privacy RamificationsabstractWhile the literature on permissions from the end-user perspective is rich, there is a lack of empirical research on why developers request permissions, their conceptualization of permissions, and how their perspectives compare with end-users’ perspectives. Our study aims to address these gaps using a mixed-methods approach. Mohammad Tahaei, Ruba Abu-Salma, Awais Rashid |
CHI | 3 |
| 2023 | ExD: Explainable DeletionabstractThis paper focuses on a critical yet often overlooked aspect of data in digital systems and services—deletion. Through a review of existing literature we highlight the challenges that user face when attempting to delete data from systems and services, the lack of transparency in how such requests are handled or processed and the lack of clear assurance that the data has been deleted. We highlight that this not only impacts users’ agency over their data but also poses issues with regards to compliance with fundamental legal rights such as the right to be forgotten. We propose a new paradigm – explainable deletion – to improve users’ agency and control over their data and enable systems to deliver effective assurance, transparency and compliance. We discuss the properties required of such explanations and their relevance and benefit for various individuals and groups involved or having an interest in data deletion processes and implications. We discuss various design implications pertaining to explainable deletion and present a research agenda for the community. Kopo M. Ramokapane, Awais Rashid |
NSPW | 2 |
| 2023 | On the privacy of mental health appsabstractAbstract An increasing number of mental health services are now offered through mobile health (mHealth) systems, such as in mobile applications (apps). Although there is an unprecedented growth in the adoption of mental health services, partly due to the COVID-19 pandemic, concerns about data privacy risks due to security breaches are also increasing. Whilst some studies have analyzed mHealth apps from different angles, including security, there is relatively little evidence for data privacy issues that may exist in mHealth apps used for mental health services, whose recipients can be particularly vulnerable. This paper reports an empirical study aimed at systematically identifying and understanding data privacy incorporated in mental health apps. We analyzed 27 top-ranked mental health apps from Google Play Store. Our methodology enabled us to perform an in-depth privacy analysis of the apps, covering static and dynamic analysis, data sharing behaviour, server-side tests, privacy impact assessment requests, and privacy policy evaluation. Furthermore, we mapped the findings to the LINDDUN threat taxonomy, describing how threats manifest on the studied apps. The findings reveal important data privacy issues such as unnecessary permissions, insecure cryptography implementations, and leaks of personal data and credentials in logs and web requests. There is also a high risk of user profiling as the apps’ development do not provide foolproof mechanisms against linkability, detectability and identifiability. Data sharing among 3rd-parties and advertisers in the current apps’ ecosystem aggravates this situation. Based on the empirical findings of this study, we provide recommendations to be considered by different stakeholders of mHealth apps in general and apps developers in particular. We conclude that while developers ought to be more knowledgeable in considering and addressing privacy issues, users and health professionals can also play a role by demanding privacy-friendly apps. Leonardo H. Iwaya, Muhammad Ali Babar 0001, Awais Rashid, Chamila Wijayarathna |
Empir. Softw. Eng. | 3 |
| 2023 | Co-creating a Transdisciplinary Map of Technology-mediated Harms, Risks and Vulnerabilities: Challenges, Ambivalences and OpportunitiesabstractThe phrase "online harms'' has emerged in recent years out of a growing political willingness to address the ethical and social issues associated with the use of the Internet and digital technology at large. The broad landscape that surrounds online harms gathers a multitude of disciplinary, sectoral and organizational efforts while raising myriad challenges and opportunities for the crossing entrenched boundaries. In this paper we draw lessons from a journey of co-creating a transdisciplinary knowledge infrastructure within a large research initiative animated by the online harms agenda. We begin with a reflection of the implications of mapping, taxonomizing and constructing knowledge infrastructures and a brief review of how online harm and adjacent themes have been theorized and classified in the literature to date. Grounded on our own experience of co-creating a map of online harms, we then argue that the map---and the process of mapping---perform three mutually constitutive functions, acting simultaneously as method, medium and provocation. We draw lessons from how an open-ended approach to mapping, despite not guaranteeing consensus, can foster productive debate and collaboration in ethically and politically fraught areas of research. We end with a call for CSCW research to surface and engage with the multiple temporalities, social lives and political sensibilities of knowledge infrastructures. Andrés Domínguez Hernández, Kopo M. Ramokapane, Partha Das Chowdhury, Ola Aleksandra Michalec, Emily Johnstone, Emily Godwin, Alicia G. Cork, Awais Rashid |
Proc. ACM Hum. Comput. Interact. | 8 |
| 2023 | What Users Want From Cloud Deletion and the Information They Need: A Participatory Action StudyabstractCurrent cloud deletion mechanisms fall short in meeting users’ various deletion needs. They assume all data is deleted the same way—data is temporally removed (or hidden) from users’ cloud accounts before being completely deleted. This assumption neglects users’ desire to have data completely deleted instantly or their preference to have it recoverable for a more extended period. To date, these preferences have not been explored. To address this gap, we conducted a participatory study with four groups of active cloud users (five subjects per group). We examined their deletion preferences and the information they require to aid deletion. In particular, we explored how users want to delete cloud data and identify what information about cloud deletion they consider essential, the time it should be made available to them, and the communication channel that should be used. We show that cloud deletion preferences are complex and multi-dimensional, varying between subjects and groups. Information about deletion should be within reach when needed, for instance, be part of deletion controls. Based on these findings, we discuss the implications of our study in improving the current deletion mechanism to accommodate these preferences. Kopo M. Ramokapane, Jose M. Such, Awais Rashid |
ACM Trans. Priv. Secur. | 3 |
| 2023 | SLR: From Saltzer and Schroeder to 2021...47 Years of Research on the Development and Validation of Security API RecommendationsabstractProducing secure software is challenging. The poor usability of security Application Programming Interfaces (APIs) makes this even harder. Many recommendations have been proposed to support developers by improving the usability of cryptography libraries—rooted in wider best practice guidance in software engineering and API design. In this SLR, we systematize knowledge regarding these recommendations. We identify and analyze 65 papers, offering 883 recommendations. Through thematic analysis, we identify seven core ways to improve usability of APIs. Most of the recommendations focus on helping API developers to construct and structure their code and make it more usable and easier for programmers to understand . There is less focus, however, on documentation , writing requirements , code quality assessment , and the impact of organizational software development practices . By tracing and analyzing paper ancestry, we map how this knowledge becomes validated and translated over time. We find that very few API usability recommendations are empirically validated, and that recommendations specific to usable security APIs lag even further behind. Nikhil Patnaik, Andrew C. Dwyer, Joseph Hallett, Awais Rashid |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2023 | Making Sense of the Unknown: How Managers Make Cyber Security DecisionsabstractManagers rarely have deep knowledge of cyber security and yet are expected to make decisions with cyber security implications for software-based systems. We investigate the decision-making conversations of seven teams of senior managers from the same organisation as they complete the Decisions & Disruptions cyber security exercise. We use grounded theory to situate our analysis of their decision-making and help us explore how these complex socio-cognitive interactions occur. We have developed a goal-model (using iStar 2.0) of the teams’ dialogue that illustrates what cyber security goals teams identify and how they operationalise their decisions to reach these goals. We complement this with our model of cyber security reasoning that describes how these teams make their decisions, showing how each team members’ experience, intuition, and understanding affects the team’s overall shared reasoning and decision-making. Our findings show how managers with little cyber security expertise are able to use logic and traditional risk management thinking to make cyber security decisions. Despite their lack of cyber security–specific training, they demonstrate reasoning that closely resembles the decision-making approaches espoused in cyber security–specific standards (e.g., NIST/ISO). Our work demonstrates how organisations and practitioners can enrich goal modelling to capture not only what security goals an organisation has (and how they can operationalise them) but also how and why these goals have been identified. Ultimately, non–cyber security experts can develop their cyber security model based on their current context (and update it when new requirements appear or new incidents happen), whilst capturing their reasoning at every stage. Ben Shreeve, Catarina Gralha, Awais Rashid, João Araújo 0001, Miguel Goulão |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2023 | Privacy Engineering in the Wild: Understanding the Practitioners' Mindset, Organizational Aspects, and Current PracticesabstractPrivacy engineering, as an emerging field of research and practice, comprises the technical capabilities and management processes needed to implement, deploy, and operate privacy features and controls in working systems. For that, software practitioners and other stakeholders in software companies need to work cooperatively toward building privacy-preserving businesses and engineering solutions. Significant research has been done to understand the software practitioners' perceptions of information privacy, but more emphasis should be given to the uptake of concrete privacy engineering components. This research delves into the software practitioners' perspectives and mindset, organisational aspects, and current practices on privacy and its engineering processes. A total of 30 practitioners from nine countries and backgrounds were interviewed, sharing their experiences and voicing their opinions on a broad range of privacy topics. The thematic analysis methodology was adopted to code the interview data qualitatively and construct a rich and nuanced thematic framework. As a result, we identified three critical interconnected themes that compose our thematic framework for privacy engineering “in the wild”: (1) personal privacy mindset and stance, categorised into practitioners' privacy knowledge, attitudes and behaviours; (2) organisational privacy aspects, such as decision-power and positive and negative examples of privacy climate; and, (3) privacy engineering practices, such as procedures and controls concretely used in the industry. Among the main findings, this study provides many insights about the state-of-the-practice of privacy engineering, pointing to a positive influence of privacy laws (e.g., EU General Data Protection Regulation) on practitioners' behaviours and organisations' cultures. Aspects such as organisational privacy culture and climate were also confirmed to have a powerful influence on the practitioners' privacy behaviours. A conducive environment for privacy engineering needs to be created, aligning the privacy values of practitioners and their organisations, with particular attention to the leaders and top management's commitment to privacy. Organisations can also facilitate education and awareness training for software practitioners on existing privacy engineering theories, methods and tools that have already been proven effective. Leonardo H. Iwaya, Muhammad Ali Babar 0001, Awais Rashid |
IEEE Trans. Software Eng. | 3 |
| 2022 | SoK: A Taxonomy for Contrasting Industrial Control Systems Asset Discovery ToolsabstractAsset scanning and discovery is the first and foremost step for organizations to understand what assets they have and what to protect. There is currently a plethora of free and commercial asset scanning tools specializing in identifying assets in industrial control systems (ICS). However, there is little information available on their comparative capabilities and how their respective features contrast. Nor is it clear to what depth of scanning these tools can reach and whether they are fit-for-purpose in a scaled industrial network architecture. We provide the first systematic feature comparison of free-to-use asset scanning tools on the basis of an ICS scanning taxonomy that we propose. Based on the taxonomy, we investigate scanning depths reached by the tools’ features and validate our investigation through experimentation on Siemens, Schneider Electric, and Allen Bradley devices in a testbed environment. Emmanouil Samanis, Joseph Gardiner, Awais Rashid |
ARES | 3 |
| 2022 | Privacy Design Strategies for Home Energy Management Systems (HEMS)abstractHome energy management systems (HEMS) offer control and the ability to manage energy, generating and collecting energy consumption data at the most detailed level. However, data at this level poses various privacy concerns, including, for instance, profiling consumer behaviors and large-scale surveillance. The question of how utility providers can get value from such data without infringing consumers’ privacy has remained under-investigated. We address this gap by exploring the pro-sharing attitudes and privacy perceptions of 30 HEMS users and non-users through an interview study. While participants are concerned about data misuse and stigmatization, our analysis also reveals that incentives, altruism, trust, security and privacy, transparency and accountability encourage data sharing. From this analysis, we derive privacy design strategies for HEMS that can both improve privacy and engender adoption. Kopo M. Ramokapane, Caroline Bird, Awais Rashid, Ruzanna Chitchyan |
CHI | 3 |
| 2022 | Threat-Driven Dynamic Security Policies for Cyber-Physical Infrastructures
Joseph Hallett, Simon N. Foley, David Manda, Joseph Gardiner, Dimitri Jonckers, Wouter Joosen, Awais Rashid |
CRITIS | 7 |
| 2022 | Why Rigorous Underpinnings for Cyber Security Education and Training Matter? Experiences from CyBOK: The Cyber Security Body of Knowledge
Awais Rashid |
ICISSP | 1 |
| 2022 | From Utility to Capability: A New Paradigm to Conceptualize and Develop Inclusive PETsabstractThe wider adoption of Privacy Enhancing Technologies (PETs) has relied on usability studies – which focus mainly on an assessment of how a specified group of users interface, in particular contexts, with the technical properties of a system. While human-centred efforts in usability aim to achieve important technical improvements and drive technology adoption, a focus on the usability of PETs alone is not enough. PETs development and adoption requires a broadening of focus to adequately capture the specific needs of individuals, particularly of vulnerable individuals and/or individuals in marginalized populations. We argue for a departure, from the utilitarian evaluation of surface features aimed at maximizing adoption, towards a bottom-up evaluation of what real opportunities humans have to use a particular system. We delineate a new paradigm for the way PETs are conceived and developed. To that end, we propose that Amartya Sen’s capability approach offers a foundation for the comprehensive evaluation of the opportunities individuals have based on their personal and environmental circumstances which can, in turn, inform the evolution of PETs. This includes considerations of vulnerability, age, education, physical and mental ability, language barriers, gender, access to technology, freedom from oppression among many important contextual factors. Partha Das Chowdhury, Andrés Domínguez Hernández, Kopo M. Ramokapane, Awais Rashid |
NSPW | 4 |
| 2022 | Charting App Developers' Journey Through Privacy Regulation Features in Ad NetworksabstractMobile apps enable ad networks to collect and track users. App developers are given “configurations” on these platforms to limit data collection and adhere to privacy regulations; however, the prevalence of apps that violate privacy regulations because of third parties, including ad networks, begs the question of how developers work through these configurations and how easy they are to utilize. We study privacy regulations-related interfaces on three widely used ad networks using two empirical studies, a systematic review and think-aloud sessions with eleven developers, to shed light on how ad networks present privacy regulations and how usable the provided configurations are for developers. We find that information about privacy regulations is scattered in several pages, buried under multiple layers, and uses terms and language developers do not understand. While ad networks put the burden of complying with the regulations on developers, our participants, on the other hand, see ad networks responsible for ensuring compliance with regulations. To assist developers in building privacy regulations-compliant apps, we suggest dedicating a section to privacy, offering easily accessible configurations (both in graphical and code level), building testing systems for privacy regulations, and creating multimedia materials such as videos to promote privacy values in the ad networks’ documentation. Mohammad Tahaei, Kopo M. Ramokapane, Tianshi Li 0001, Jason I. Hong, Awais Rashid |
Proc. Priv. Enhancing Technol. | 5 |
| 2022 | The Case for Adaptive Security InterventionsabstractDespite the availability of various methods and tools to facilitate secure coding, developers continue to write code that contains common vulnerabilities. It is important to understand why technological advances do not sufficiently facilitate developers in writing secure code. To widen our understanding of developers' behaviour, we considered the complexity of the security decision space of developers using theory from cognitive and social psychology. Our interdisciplinary study reported in this article (1) draws on the psychology literature to provide conceptual underpinnings for three categories of impediments to achieving security goals, (2) reports on an in-depth meta-analysis of existing software security literature that identified a catalogue of factors that influence developers' security decisions, and (3) characterises the landscape of existing security interventions that are available to the developer during coding and identifies gaps. Collectively, these show that different forms of impediments to achieving security goals arise from different contributing factors. Interventions will be more effective where they reflect psychological factors more sensitively and marry technical sophistication, psychological frameworks, and usability. Our analysis suggests “adaptive security interventions” as a solution that responds to the changing security needs of individual developers and a present a proof-of-concept tool to substantiate our suggestion. Irum Rauf, Marian Petre, Thein Tun, Tamara Lopez, Paul Lunn, Dirk van der Linden, John N. Towse, Helen Sharp, Mark Levine, Awais Rashid, Bashar Nuseibeh |
ACM Trans. Softw. Eng. Methodol. | 10 |
| 2022 | The Impact of Surface Features on Choice of (in)Secure Answers by Stackoverflow ReadersabstractExisting research has shown that developers will use StackOverflow to answer programming questions: but what draws them to one particular answer over any other? The choice of answer they select can mean the difference between a secure application and insecure one, as the quality of supposedly secure answers can vary. Prior work has studied people posting on Stack Overflow—a two-way communication between the original poster and the Stack Overflow community. Instead, we study the situation of one-way communication, where people only read a Stack Overflow thread without being actively involved in it, sometimes long after a thread has closed. We report on a mixed-method study including a controlled between-groups experiment and qualitative analysis of participants’ rationale (N=1188), investigating whether explanation detail, answer scoring, accepted answer marks, as well as the security of the code snippet itself affect the answers participants accept. Our findings indicate that explanation detail affects what answers participants reading a thread select (p0.05)—theinverseof what research has shown for those asking and answering questions. The qualitative analysis of participants’ rationale further explains how several cognitive biases underpin these findings. Correspondence bias, in particular, plays an important role in instilling readers with a false sense of confidence in an answer through theway it looks, regardless of whether it works, is secure, or if the community agrees with it. As a result, we argue that StackOverflow's use as a knowledge base by people not actively involved in threads—when there is only one-way-communication—may inadvertently contribute to the spread of insecure code, as the community's voting mechanisms hold little power to deter them from answers. Dirk van der Linden, Emma J. Williams, Joseph Hallett, Awais Rashid |
IEEE Trans. Software Eng. | 4 |
| 2022 | The Best Laid Plans or Lack Thereof: Security Decision-Making of Different Stakeholder GroupsabstractCyber security requirements are influenced by the priorities and decisions of a range of stakeholders. Board members and Chief Information Security Officers (CISOs) determine strategic priorities. Managers have responsibility for resource allocation and project management. Legal professionals concern themselves with regulatory compliance. Little is understood about how the security decision-making approaches of these different stakeholders contrast, and if particular groups of stakeholders have a better appreciation of security requirements during decision-making. Are risk analysts better decision makers than CISOs? Do security experts exhibit more effective strategies than board members? This paper explores the effect that different experience and diversity of expertise has on the quality of a team's cyber security decision-making and whether teams with members from more varied backgrounds perform better than those with more focused, homogeneous skill sets. Using data from 208 sessions and 948 players of a tabletop game runin the wildby a major national organization over 16 months, we explore how choices are affected by player background (e.g., cyber security experts versus risk analysts, board-level decision makers versus technical experts) and different team make-ups (homogeneous teams of security experts versus various mixes). We find that no group of experts makes significantly better game decisions than anyone else, and that their biases lead them to not fully comprehend what they are defending or how the defenses work. Ben Shreeve, Joseph Hallett, Matthew Edwards 0001, Kopo M. Ramokapane, Richard Atkins, Awais Rashid |
IEEE Trans. Software Eng. | 6 |
| 2021 | AMoC: A Multifaceted Machine Learning-based Toolkit for Analysing Cybercriminal Communities on the DarknetabstractThere is an increasing demand for expert analysis of cybercriminal communities. Cybercrime is continually becoming more complex due to the rapid development of digital technologies, on the one hand, in new types of criminal activity, such as hacking, distributing malware and DDoS attacks, and on the other hand, in digitised forms of more traditional crimes, such as email scams, phishing, identity theft, and cryptographically secured black markets. Tackling this broad array of behaviour requires tool support for multi-disciplinary investigations, and a connecting framework that can adjust flexibly to changes in the populations being studied. In this work, we present AMoC, a multi-faceted machine learning toolkit that combines structured queries, anomaly detection, social network analysis, topic modelling and accounts recognition to enable comprehensive analysis of cybercriminal communities and users. The toolkit enables the extraction of findings regarding the motivations, behaviour and characteristics of offenders, and how cybercriminal communities react to interventions such as arrests and take-downs. In our demonstration, the toolkit is deployed to analyse over 150,000 accounts from 35 underground marketplaces. Claudia Peersman, Matthew Edwards 0001, Ziauddin Ursani, Awais Rashid |
IEEE BigData | 5 |
| 2021 | "Do this! Do that!, And nothing will happen" Do specifications lead to securely stored passwords?abstractDoes the act of writing a specification (how the code should behave) for a piece of security sensitive code lead to developers producing more secure code? We asked 138 developers to write a snippet of code to store a password: Half of them were asked to write down a specification of how the code should behave before writing the program, the other half were asked to write the code but without being prompted to write a specification first. We find that explicitly prompting developers to write a specification has a small positive effect on the security of password storage approaches implemented. However, developers often fail to store passwords securely, despite claiming to be confident and knowledgeable in their approaches, and despite considering an appropriate range of threats. We find a need for developer-centered usable mechanisms for telling developers how to store passwords: lists of what they must do are not working. Joseph Hallett, Nikhil Patnaik, Ben Shreeve, Awais Rashid |
ICSE | 4 |
| 2021 | Beware suppliers bearing gifts!: Analysing coverage of supply chain cyber security in critical national infrastructure sectorial and cross-sectorial frameworks
Colin Topping, Andrew C. Dwyer, Ola Aleksandra Michalec, Barnaby Craggs, Awais Rashid |
Comput. Secur. | 5 |
| 2020 | Schrödinger's security: opening the box on app developers' security rationaleabstractResearch has established the wide variety of security failures in mobile apps, their consequences, and how app developers introduce or exacerbate them. What is not well known is why developers do so---what is the rationale underpinning the decisions they make which eventually strengthen or weaken app security? This is all the more complicated in modern app development's increasingly diverse demographic: growing numbers of independent, solo, or small team developers who do not have the organizational structures and support that larger software development houses enjoy. Dirk van der Linden, Pauline Anthonysamy, Bashar Nuseibeh, Thein Than Tun, Marian Petre, Mark Levine, John N. Towse, Awais Rashid |
ICSE | 8 |
| 2020 | Contextualising and aligning security metrics and business objectives: A GQM-based methodology
Eleni Philippou, Sylvain Frey, Awais Rashid |
Comput. Secur. | 3 |
| 2020 | Interventions for long-term software security: Creating a lightweight program of assurance techniques for developersabstractSummary Though some software development teams are highly effective at delivering security, others either do not care or do not have access to security experts to teach them how. Unfortunately, these latter teams are still responsible for the security of the systems they build: systems that are ever more important to ever more people. We propose that a series of lightweight interventions, six hours of facilitated workshops delivered over three months, can improve a team's motivation to consider security and awareness of assurance techniques, changing its security culture even when no security experts are involved. The interventions were developed after an Appreciative Inquiry and Grounded Theory survey of security professionals to find out what approaches work best. We tested the interventions in a participatory action research field study where we delivered the workshops to three software development organizations and evaluated their effectiveness through interviews beforehand, immediately afterwards, and after twelve months. We found that the interventions can be effective with teams with limited or no security experience and that improvement is long‐lasting. This approach and the learning points arising from the work here have the potential to be applied in many development teams, improving the security of software worldwide. Charles Weir, Ingolf Becker, James Noble 0001, Lynne Blair, M. Angela Sasse, Awais Rashid |
Softw. Pract. Exp. | 6 |
| 2020 | Automatically Dismantling Online Dating FraudabstractOnline romance scams are a prevalent form of mass-marketing fraud in the West, and yet few studies have presented data-driven responses to this problem. In this type of scam, fraudsters craft fake profiles and manually interact with their victims. Because of the characteristics of this type of fraud and how dating sites operate, traditional detection methods (e.g., those used in spam filtering) are ineffective. In this paper, we investigate the archetype of online dating profiles used in this form of fraud, including their use of demographics, profile descriptions, and images, shedding light on both the strategies deployed by scammers to appeal to victims and the traits of victims themselves. Furthermore, in response to the severe financial and psychological harm caused by dating fraud, we develop a system to detect romance scammers on online dating platforms. This paper presents the first fully described system for automatically detecting this fraud. Our aim is to provide an early detection system to stop romance scammers as they create fraudulent profiles or before they engage with potential victims. Previous research has indicated that the victims of romance scams score highly on scales for idealized romantic beliefs. We combine a range of structured, unstructured, and deep-learned features that capture these beliefs in order to build a detection system. Our ensemble machine-learning approach is robust to the omission of profile details and performs at high accuracy (97%) in a hold-out validation set. The system enables development of automated tools for dating site providers and individual users. Guillermo Suarez-Tangil, Matthew Edwards 0001, Claudia Peersman, Gianluca Stringhini, Awais Rashid, Monica T. Whitty |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2020 | "So if Mr Blue Head here clicks the link..." Risk Thinking in Cyber Security Decision MakingabstractCyber security decision making is inherently complicated, with nearly every decision having knock-on consequences for an organisation’s vulnerability and exposure. This is further compounded by the fact that decision-making actors are rarely security experts and may have an incomplete understanding of the security that the organisation currently has in place. They must contend with a multitude of possible security options that they may only partially understand. This challenge is met by decision makers’ risk thinking —their strategies for identifying risks, assessing their severity, and prioritising responses. We study the risk thinking strategies employed by teams of participants in an existing dataset derived from a tabletop cyber-physical systems security game. Our analysis identifies four structural patterns of risk thinking and two reasoning strategies: risk-first and opportunity-first . Our work highlights that risk-first approaches (as prescribed by the likes of NIST-800-53 and ISO 27001) are followed neither substantially nor exclusively when it comes to decision making. Instead, our analysis finds that decision making is affected by the plasticity of teams—that is, the ability to readily switch between ideas and practising both risk-first and opportunity-first reasoning. Ben Shreeve, Joseph Hallett, Matthew Edwards 0001, Pauline Anthonysamy, Sylvain Frey, Awais Rashid |
ACM Trans. Priv. Secur. | 6 |
| 2019 | Everything Is Awesome! or Is It? Cyber Security Risks in Critical Infrastructure
Awais Rashid, Joseph Gardiner, Benjamin Green 0001, Barnaby Craggs |
CRITIS | 1 |
| 2019 | Skip, Skip, Skip, Accept!!!: A Study on the Usability of Smartphone Manufacturer Provided Default Features and User PrivacyabstractAbstract Smartphone manufacturer provided default features (e.g., default location services, iCloud, Google Assistant, ad tracking) enhance the usability and extend the functionality of these devices. Prior studies have highlighted smartphone vulnerabilities and how users’ data can be harvested without their knowledge. However, little is known about manufacturer provided default features in this regard—their usability concerning configuring them during usage, and how users perceive them with regards to privacy. To bridge this gap, we conducted a task-based study with 27 Android and iOS smart-phone users in order to learn about their perceptions, concerns and practices, and to understand the usability of these features with regards to privacy. We explored the following: users’ awareness of these features, why and when do they change the settings of these features, the challenges they face while configuring these features, and finally the mitigation strategies they adopt. Our findings reveal that users of both platforms have limited awareness of these features and their privacy implications. Awareness of these features does not imply that a user can easily locate and adjust them when needed. Furthermore, users attribute their failure to configure default features to hidden controls and insufficient knowledge on how to configure them. To cope with difficulties of finding controls, users employ various coping strategies, some of which are platform specific but most often applicable to both platforms. However, some of these coping strategies leave users vulnerable. Kopo M. Ramokapane, Anthony C. Mazeli, Awais Rashid |
Proc. Priv. Enhancing Technol. | 3 |
| 2019 | The Good, the Bad and the Ugly: A Study of Security Decisions in a Cyber-Physical Systems GameabstractStakeholders' security decisions play a fundamental role in determining security requirements, yet, little is currently understood about how different stakeholder groups within an organisation approach security and the drivers and tacit biases underpinning their decisions. We studied and contrasted the security decisions of three demographics-security experts, computer scientists and managers-when playing a tabletop game that we designed and developed. The game tasks players with managing the security of a cyber-physical environment while facing various threats. Analysis of 12 groups of players (4 groups in each of our demographics) reveals strategies that repeat in particular demographics, e.g., managers and security experts generally favoring technological solutions over personnel training, which computer scientists preferred. Surprisingly, security experts were not ipso facto better players-in some cases, they made very questionable decisions-yet they showed a higher level of confidence in themselves. We classified players' decision-making processes, i.e., procedure-, experience-, scenario- or intuition-driven. We identified decision patterns, both good practices and typical errors and pitfalls. Our game provides a requirements sandbox in which players can experiment with security risks, learn about decision-making and its consequences, and reflect on their own perception of security. Sylvain Frey, Awais Rashid, Pauline Anthonysamy, Maria Pinto-Albuquerque, Syed Asad Naqvi |
IEEE Trans. Software Eng. | 2 |
| 2018 | A Cross-Virtual Machine Network Channel Attack via Mirroring and TAP ImpersonationabstractData privacy and security is a leading concern for providers and customers of cloud computing, where Virtual Machines (VMs) can co-reside within the same underlying physical machine. Side channel attacks within multi-tenant virtualized cloud environments are an established problem, where attackers are able to monitor and exfiltrate data from co-resident VMs. Virtualization services have attempted to mitigate such attacks by preventing VM-to-VM interference on shared hardware by providing logical resource isolation between co-located VMs via an internal virtual network. However, such approaches are also insecure, with attackers capable of performing network channel attacks which bypass mitigation strategies using vectors such as ARP Spoofing, TCP/IP steganography, and DNS poisoning. In this paper we identify a new vulnerability within the internal cloud virtual network, showing that through a combination of TAP impersonation and mirroring, a malicious VM can successfully redirect and monitor network traffic of VMs co-located within the same physical machine. We demonstrate the feasibility of this attack in a prominent cloud platform - OpenStack - under various security requirements and system conditions, and propose countermeasures for mitigation. Atif Saeed, Peter Garraghan, Barnaby Craggs, Dirk van der Linden, Awais Rashid, Syed Asad Hussain |
IEEE CLOUD | 5 |
| 2018 | CPS-SPC 2018: Fourth Workshop on Cyber-Physical Systems Security and PrivaCyabstractCyber-Physical Systems (CPS) are becoming increasingly critical for the well-being of society (e.g., electricity generation and distribution, water treatment, implantable medical devices etc.). While the convergence of computing, communications and physical control in such systems provides benefits in terms of efficiency and convenience, the attack surface resulting from this convergence poses unique security and privacy challenges. These systems represent the new frontier for cyber risk. CPS-SPC is an annual forum in its 4th edition this year, that aims to provide a focal point for the research community to begin addressing the security and privacy challenges of CPS in a comprehensive and multidisciplinary manner and, in tandem with other efforts, build a comprehensive research road map. Awais Rashid, Nils Ole Tippenhauer |
CCS | 1 |
| 2018 | The good, the bad and the ugly: a study of security decisions in a cyber-physical systems gameabstractMotivation: The security of any system is a direct consequence of stakeholders' decisions regarding security requirements. Such decisions are taken with varying degrees of expertise, and little is currently understood about how various demographics - security experts, general computer scientists, managers - approach security decisions and the strategies that underpin those decisions. What are the typical decision patterns, the consequences of such patterns and their impact on the security of the system in question? Nor is there any substantial understanding of how the strategies and decision patterns of these different groups contrast. Is security expertise necessarily an advantage when making security decisions in a given context? Answers to these questions are key to understanding the "how" and "why" behind security decision processes. Sylvain Frey, Awais Rashid, Pauline Anthonysamy, Maria Pinto-Albuquerque, Syed Asad Naqvi |
ICSE | 2 |
| 2018 | μ-DSU: A Micro-Language Based Approach to Dynamic Software Updating
Walter Cazzola, Ruzanna Chitchyan, Awais Rashid, Albert Shaqiri |
Comput. Lang. Syst. Struct. | 3 |
| 2018 | Data exfiltration: A review of external attack vectors and countermeasures
Faheem Ullah, Matthew Edwards 0001, Rajiv Ramdhany, Ruzanna Chitchyan, Muhammad Ali Babar 0001, Awais Rashid |
J. Netw. Comput. Appl. | 6 |
| 2017 | CPS-SPC 2017: Third Workshop on Cyber-Physical Systems Security and PrivaCyabstractCyber-Physical Systems (CPS) are becoming increasingly critical for the well-being of society (e.g., electricity generation and distribution, water treatment, implantable medical devices etc.). While the convergence of computing, communications and physical control in such systems provides benefits in terms of efficiency and convenience, the attack surface resulting from this convergence poses unique security and privacy challenges. These systems represent the new frontier for cyber risk. CPS-SPC is an annual forum, in its 3rd edition this year, that aims to provide a focal point for the research community to begin addressing the security and privacy challenges of CPS in a comprehensive and multidisciplinary manner and, in tandem with other efforts, build a comprehensive research road map. Rakesh Bobba, Awais Rashid |
CCS | 2 |
| 2017 | "I feel stupid I can't delete...": A Study of Users' Cloud Deletion Practices and Coping Strategies
Kopo M. Ramokapane, Awais Rashid, Jose M. Such |
SOUPS | 2 |
| 2017 | The Shadow Warriors: In the no man's land between industrial control systems and enterprise IT systems
Alberto Zanutto, Ben Shreeve, Karolina Follis, Jeremy Busby, Awais Rashid |
SOUPS | 5 |
| 2017 | Panning for gold: Automatically analysing online social engineering attack surfacesabstractThe process of social engineering targets people rather than IT infrastructure. Attackers use deceptive ploys to create compelling behavioural and cosmetic hooks, which in turn lead a target to disclose sensitive information or to interact with a malicious payload. The creation of such hooks requires background information on targets. Individuals are increasingly releasing information about themselves online, particularly on social networks. Though existing research has demonstrated the social engineering risks posed by such open source intelligence, this has been accomplished either through resource-intensive manual analysis or via interactive information harvesting techniques. As manual analysis of large-scale online information is impractical, and interactive methods risk alerting the target, alternatives are desirable. In this paper, we demonstrate that key information pertinent to social engineering attacks on organisations can be passively harvested on a large-scale in an automated fashion. We address two key problems. We demonstrate that it is possible to automatically identify employees of an organisation using only information which is visible to a remote attacker as a member of the public. Secondly, we show that, once identified, employee profiles can be linked across multiple online social networks to harvest additional information pertinent to successful social engineering attacks. We further demonstrate our approach through analysis of the social engineering attack surface of real critical infrastructure organisations. Based on our analysis we propose a set of countermeasures including an automated social engineering vulnerability scanner that organisations can use to analyse their exposure to potential social engineering attacks arising from open source intelligence. Matthew Edwards 0001, Robert Larson, Benjamin Green 0001, Awais Rashid, Alistair Baron |
Comput. Secur. | 4 |
| 2017 | Detecting broken pointcuts using structural commonality and degree of interest
Raffi Khatchadourian, Awais Rashid, Hidehiko Masuhara, Takuya Watanabe 0002 |
Sci. Comput. Program. | 2 |
| 2016 | Mimicry in online conversations: An exploratory study of linguistic analysis techniquesabstractA number of computational techniques have been proposed that aim to detect mimicry in online conversations. In this paper, we investigate how well these reflect the prevailing cognitive science model, i.e. the Interactive Alignment Model. We evaluate Local Linguistic Alignment, word vectors, and Language Style Matching and show that these measures tend to show the features we expect to see in the IAM, but significantly fall short of the work of human classifiers on the same data set. This reflects the need for substantial additional research on computational techniques to detect mimicry in online conversations. We suggest further work needed to measure these techniques and others more accurately. Tom Carrick, Awais Rashid, Paul J. Taylor |
ASONAM | 2 |
| 2016 | Sampling labelled profile data for identity resolutionabstractIdentity resolution capability for social networking profiles is important for a range of purposes, from open-source intelligence applications to forming semantic web connections. Yet replication of research in this area is hampered by the lack of access to ground-truth data linking the identities of profiles from different networks. Almost all data sources previously used by researchers are no longer available, and historic datasets are both of decreasing relevance to the modern social networking landscape and ethically troublesome regarding the preservation and publication of personal data. We present and evaluate a method which provides researchers in identity resolution with easy access to a realistically-challenging labelled dataset of online profiles, drawing on four of the currently largest and most influential online social networks. We validate the comparability of samples drawn through this method and discuss the implications of this mechanism for researchers as well as potential alternatives and extensions. Matthew Edwards 0001, Stephen Wattam, Paul Rayson, Awais Rashid |
IEEE BigData | 4 |
| 2016 | It Bends But Would It Break? Topological Analysis of BGP Infrastructures in EuropeabstractThe Internet is often thought to be a model of resilience, due to a decentralised, organically-grown architecture. This paper puts this perception into perspective through the results of a security analysis of the Border Gateway Protocol (BGP) routing infrastructure. BGP is a fundamental Internet protocol and its intrinsic fragilities have been highlighted extensively in the literature. A seldom studied aspect is how robust the BGP infrastructure actually is as a result of nearly three decades of perpetual growth. Although global black-outs seem unlikely, local security events raise growing concerns on the robustness of the backbone. In order to better protect this critical infrastructure, it is crucial to understand its topology in the context of the weaknesses of BGP and to identify possible security scenarios. Firstly, we establish a comprehensive threat model that classifies main attack vectors, including but non limited to BGP vulnerabilities. We then construct maps of the European BGP backbone based on publicly available routing data. We analyse the topology of the backbone and establish several disruption scenarios that highlight the possible consequences of different types of attacks, for different attack capabilities. We also discuss existing mitigation and recovery strategies, and we propose improvements to enhance the robustness and resilience of the backbone. To our knowledge, this study is the first to combine a comprehensive threat analysis of BGP infrastructures withadvanced network topology considerations. We find that the BGP infrastructure is at higher risk than already understood, due to topologies that remain vulnerable to certain targeted attacks as a result of organic deployment over the years. Significant parts of the system are still uncharted territory, which warrants further investigation in this direction. Sylvain Frey, Yehia El-khatib, Awais Rashid, Karolina Follis, John Edward Vidler, Nicholas J. P. Race, Christopher Edwards |
EuroS&P | 3 |
| 2016 | Discovering "unknown known" security requirementsabstractSecurity is one of the biggest challenges facing organisations in the modern hyper-connected world. A number of theoretical security models are available that provide best practice security guidelines and are widely utilised as a basis to identify and operationalise security requirements. Such models often capture high-level security concepts (e.g., whitelisting, secure configurations, wireless access control, data recovery, etc.), strategies for operationalising such concepts through specific security controls, and relationships between the various concepts and controls. The threat landscape, however, evolves leading to new tacit knowledge that is embedded in or across a variety of security incidents. These unknown knowns alter, or at least demand reconsideration of the theoretical security models underpinning security requirements. In this paper, we present an approach to discover such unknown knowns through multi-incident analysis. The approach is based on a novel combination of grounded theory and incident fault trees. We demonstrate the effectiveness of the approach through its application to identify revisions to a theoretical security model widely used in industry. Awais Rashid, Syed Asad Naqvi, Rajiv Ramdhany, Matthew Edwards 0001, Ruzanna Chitchyan, Muhammad Ali Babar 0001 |
ICSE | 1 |
| 2016 | Reaching the masses: a new subdiscipline of app programmer educationabstractProgrammers’ lack of knowledge and interest in secure development threatens everyone who uses mobile apps. The rise of apps has engaged millions of independent app developers, who rarely encounter any but low level security techniques. But what if software security were presented as a game, or a story, or a discussion? What if learning app security techniques could be fun as well as empowering? Only by introducing the powerful motivating techniques developed for other disciplines can we hope to upskill independent app developers, and achieve the security that we’ll need in 2025 to safeguard our identities and our data. Charles Weir, Awais Rashid, James Noble 0001 |
SIGSOFT FSE | 2 |
| 2016 | Information assurance techniques: Perceived cost effectiveness
Jose M. Such, Antonios Gouglidis, William Knowles, Gaurav Misra, Awais Rashid |
Comput. Secur. | 5 |
| 2016 | Flash mobs, Arab Spring and protest movements: Can we analyse group identities in online conversations?abstractThe Internet has provided people with new ways of expressing not only their individuality but also their collectivity i.e., their group affiliations. These group identities are the shared sense of belonging to a group. Online contact with others who share the same group identity can lead to cooperation and, even, coordination of social action initiatives both online and offline. Such social actions may be for the purposes of positive change, e.g., the Arab Spring in 2010, or disruptive, e.g., the England Riots in 2011. Stylometry and authorship attribution research has shown that it is possible to distinguish individuals based on their online language. In contrast, this work proposes and evaluates a model to analyse group identities online based on textual conversations amongst groups. We argue that textual features make it possible to automatically distinguish between different group identities and detect whether group identities are salient (i.e., most prominent) in the context of a particular conversation. We show that the salience of group identities can be detected with 95% accuracy and group identities can be distinguished from others with 84% accuracy. We also identify the most relevant features that may enable mal-actors to manipulate the actions of online groups. This has major implications for tools and techniques to drive positive social actions online or safeguard society from disruptive initiatives. At the same time, it poses privacy challenges given the potential ability to persuade or dissuade large groups online to move from rhetoric to action. Natalia Criado, Awais Rashid, Larissa Leite |
Expert Syst. Appl. | 2 |
| 2016 | AspectJ code analysis and verification with GASR
Johan Fabry, Coen De Roover, Carlos Noguera, Steffen Zschaler, Awais Rashid, Viviane Jonckers |
J. Syst. Softw. | 5 |
| 2015 | Weak Signals as Predictors of Real-World Phenomena in Social MediaabstractGlobal and national events in recent years have shown that online social media can be a force for good (e.g., Arab Spring) and harm (e.g., the London riots). In both of these examples, social media played a key role in group formation and organization, and in the coordination of the group's subsequent collective actions (i.e., the move from rhetoric to action). Surprisingly, despite its clear importance, little is understood about the factors that lead to this kind of group development and the transition to collective action. This paper focuses on an approach to the analysis of data from social media to detect weak signals, i.e., indicators that initially appear at the fringes, but are, in fact, early indicators of such large-scale real-world phenomena. Our approach is in contrast to existing research which focuses on analysing major themes, i.e., the strong signals, prevalent in a social network at a particular point in time. Analysis of weak signals can provide interesting possibilities for forecasting, with online user-generated content being used to identify and anticipate possible offline future events. We demonstrate our approach through analysis of tweets collected during the London riots in 2011 and use of our weak signals to predict tipping points in that context. Christos Charitonidis, Awais Rashid, Paul J. Taylor |
ASONAM | 2 |
| 2015 | Software Engineering for Privacy in-the-LargeabstractThere will be an estimated 35 zettabytes (35 × 1021) of digital records worldwide by the year 2020. This effectively amounts to privacy management on an ultra-large-scale. In this briefing, we discuss the privacy challenges posed by such an ultra-large-scale ecosystem - we term this “Privacy in the Large”. We will contrast existing approaches to privacy management, reflect on their strengths and limitations in this regard and outline key software engineering research and practice challenges to be addressed in the future. Pauline Anthonysamy, Awais Rashid |
ICSE (2) | 2 |
| 2015 | Engineering Sustainability Through LanguageabstractAs our understanding and care for sustainability concerns increases, so does the demand for incorporating these concerns into software. Yet, existing programming language constructs are not well-aligned with concepts of the sustainability domain. This undermines what we term technical sustainability of the software due to (i) increased complexity in programming of such concerns and (ii) continuous code changes to keep up with changes in (environmental, social, legal and other) sustainability-related requirements. In this paper we present a proof-of-concept approach on how technical sustainability support for new and existing concerns can be provided through flexible language-level programming. We propose to incorporate sustainability-related behaviour into programs through micro-languages enabling such behaviour to be updated and/or redefined as and when required. Ruzanna Chitchyan, Walter Cazzola, Awais Rashid |
ICSE (2) | 3 |
| 2015 | Managing Emergent Ethical Concerns for Software Engineering in SocietyabstractThis paper presents an initial framework for managing emergent ethical concerns during software engineering in society projects. We argue that such emergent considerations can neither be framed as absolute rules about how to act in relation to fixed and measurable conditions. Nor can they be addressed by simply framing them as non-functional requirements to be satisficed. Instead, a continuous process is needed that accepts the 'messiness' of social life and social research, seeks to understand complexity (rather than seek clarity), demands collective (not just individual) responsibility and focuses on dialogue over solutions. The framework has been derived based on retrospective analysis of ethical considerations in four software engineering in society projects in three different domains. Awais Rashid, Karenza Moore, Corinne May-Chahal, Ruzanna Chitchyan |
ICSE (2) | 1 |
| 2015 | Detecting Broken Pointcuts Using Structural Commonality and Degree of Interest (N)abstractPointcut fragility is a well-documented problem in Aspect-Oriented Programming, changes to the base-code can lead to join points incorrectly falling in or out of the scope of pointcuts. Deciding which pointcuts have broken due to base-code changes is a daunting venture, especially in large and complex systems. We present an automated approach that recommends pointcuts that are likely to require modification due to a particular base-code change, as well as ones that do not. Our hypothesis is that join points selected by a pointcut exhibit common structural characteristics. Patterns describing such commonality are used to recommend pointcuts that have potentially broken to the developer. The approach is implemented as an extension to the popular Mylyn Eclipse IDE plug-in, which maintains focused contexts of entities relevant to the task at hand using a Degree of Interest (DOI) model. Raffi Khatchadourian, Awais Rashid, Hidehiko Masuhara, Takuya Watanabe 0002 |
ASE | 2 |
| 2014 | Constructs Competition Miner: Process Control-Flow Discovery of BP-Domain Constructs
David Redlich, Thomas Molka, Wasif Gilani, Gordon S. Blair, Awais Rashid |
BPM | 5 |
| 2014 | Tackling the requirements jigsaw puzzleabstractA key challenge during stakeholder meetings is that of presenting the requirements and conflicts to stakeholders in a way that fosters co-responsibility and co-ownership regarding the conflicts and their resolution. In this paper, we propose a jigsaw puzzle metaphor to make identified conflicts explicit as well as an associated method to utilise this metaphor during stakeholder meetings. The metaphor provides an easy to understand language for stakeholders from otherwise diverse backgrounds. It enables stakeholders to work with a well-understood concept - that of building a system from misshapen pieces. These characteristics foster communication and team work, which improve commitment of stakeholders in co-authoring of requirements and co-responsibility in conflict handling. The gamification of conflict resolution also promotes a relaxed environment, which in turn improves team cooperation and creativity. Our experience in three user studies demonstrates that the jigsaw puzzle indeed improves such co-responsibility and co-ownership when compared with typical text-based representations of requirements. Maria Pinto-Albuquerque, Awais Rashid |
RE | 2 |
| 2013 | EA-Analyzer: automating conflict detection in a large set of textual aspect-oriented requirements
Alberto Sardinha, Ruzanna Chitchyan, Nathan Weston, Phil Greenwood, Awais Rashid |
Autom. Softw. Eng. | 5 |
| 2013 | Towards the practical mutation testing of AspectJ programs
Fabiano Cutigi Ferrari, Awais Rashid, José Carlos Maldonado |
Sci. Comput. Program. | 2 |
| 2013 | Mastering crosscutting architectural decisions with aspectsabstractSUMMARY When reflecting upon driving system requirements such as security and availability, software architects often face decisions that have a broadly scoped impact on the software architecture. These decisions are the core of the architecting process because they typically have implications intertwined in a multitude of architectural elements and across multiple views. Without a modular representation and management of those crucial choices, architects cannot properly communicate, assess and reason about their crosscutting effects. The result is a number of architectural breakdowns, such as misinformed architectural evaluation, time‐consuming trade‐off analysis and unmanageable traceability. This paper presents an architectural documentation approach in which aspects are exploited as a natural way to capture widely‐scoped design decisions in a modular fashion. The approach consists of a simple high‐level notation to describe crosscutting decisions, and a supplementary language that allows architects to formally define how such architectural decisions affect the final architectural decomposition according to different views. On the basis of two case studies, we have systematically assessed to what extent our approach: (i) supports the description of heterogeneous forms of crosscutting architecture decisions, (ii) improves the support for architecture modularity analysis, and (iii) enhances upstream and downstream traceability of crosscutting architectural decisions. Copyright © 2012 John Wiley & Sons, Ltd. Cláudio Sant'Anna, Alessandro F. Garcia 0001, Thaís Vasconcelos Batista, Awais Rashid |
Softw. Pract. Exp. | 4 |
| 2012 | UDesignIt: Towards social media for community-driven designabstractOnline social networks are now common place in day-to-day lives. They are also increasingly used to drive social action initiatives, either led by government or communities themselves (e.g., SeeClickFix, LoveLewisham.org, mumsnet). However, such initiatives are mainly used for crowd sourcing community views or coordinating activities. With the changing global economic and political landscape, there is an ever pressing need to engage citizens on a large-scale, not only in consultations about systems that affect them, but also involve them directly in the design of these very systems. In this paper we present the UDesignIt platform that combines social media technologies with software engineering concepts to empower communities to discuss and extract high-level design features. It combines natural language processing, feature modelling and visual overlays in the form of “image clouds” to enable communities and software engineers alike to unlock the knowledge contained in the unstructured and unfiltered content of social media where people discuss social problems and their solutions. By automatically extracting key themes and presenting them in a structured and organised manner in near real-time, the approach drives a shift towards large-scale engagement of community stakeholders for system design. Phil Greenwood, Awais Rashid, James Walkerdine |
ICSE | 2 |
| 2012 | Pointcut Rejuvenation: Recovering Pointcut Expressions in Evolving Aspect-Oriented SoftwareabstractPointcut fragility is a well-documented problem in Aspect-Oriented Programming; changes to the base code can lead to join points incorrectly falling in or out of the scope of pointcuts. In this paper, we present an automated approach that limits fragility problems by providing mechanical assistance in pointcut maintenance. The approach is based on harnessing arbitrarily deep structural commonalities between program elements corresponding to join points selected by a pointcut. The extracted patterns are then applied to later versions to offer suggestions of new join points that may require inclusion. To illustrate that the motivation behind our proposal is well founded, we first empirically establish that join points captured by a single pointcut typically portray a significant amount of unique structural commonality by analyzing patterns extracted from 23 AspectJ programs. Then, we demonstrate the usefulness of our technique by rejuvenating pointcuts in multiple versions of three of these programs. The results show that our parameterized heuristic algorithm was able to accurately and automatically infer the majority of new join points in subsequent software versions that were not captured by the original pointcuts. Raffi Khatchadourian, Phil Greenwood, Awais Rashid, Guoqing Harry Xu |
IEEE Trans. Software Eng. | 3 |
| 2011 | Modelling adaptability and variability in requirementsabstractThe requirements and design level identification and representation of dynamic variability for adaptive systems is a challenging task. This requires time and effort to identify and model the relevant elements as well as the need to consider the large number of potentially possible system configurations. Typically, each individual variability dimension needs to identified and modelled by enumerating each possible alternative. The full set of requirements needs to be reviewed to extract all potential variability dimensions. Moreover, each possible configuration of an adaptive system needs to be validated before use. In this demonstration, we present a tool suite that is able to manage dynamic variability in adaptive systems and tame such system complexity. This tool suite is able to automatically identify dynamic variability attributes such as variability dimensions, context, adaptation rules, and soft/hard goals from requirements documents. It also supports modelling of these artefacts as well as their run-time verification and validation. Phil Greenwood, Ruzanna Chitchyan, Awais Rashid, Joost Noppen, Franck Fleurey, Arnor Solberg |
RE | 3 |
| 2011 | Inferring test results for dynamic software product linesabstractDue to the very large number of configurations that can typically be derived from a Dynamic Software Product Line (DSPL), efficient and effective testing of such systems have become a major challenge for software developers. In particular, when a configuration needs to be deployed quickly due to rapid contextual changes (e.g., in an unfolding crisis), time constraints hinder the proper testing of such a configuration. In this paper, we propose to reduce the testing required of such DSPLs to a relevant subset of configurations. Whenever a need to adapt to an untested configuration is encountered, our approach determines the most similar tested configuration and reuses its test results to either obtain a coverage measure or infer a confidence degree for the new, untested configuration. We focus on providing these techniques for inference of structural testing results for DSPLs, which is supported by an early prototype implementation. Bruno B. P. Cafeo, Joost Noppen, Fabiano Cutigi Ferrari, Ruzanna Chitchyan, Awais Rashid |
SIGSOFT FSE | 5 |
| 2011 | Unveiling and taming liabilities of aspects in the presence of exceptions: A static analysis based approach
Roberta Coelho, Arndt von Staa, Uirá Kulesza, Awais Rashid, Carlos José Pereira de Lucena |
Inf. Sci. | 4 |
| 2010 | An exploratory study of fault-proneness in evolving aspect-oriented programsabstractThis paper presents the results of an exploratory study on the fault-proneness of aspect-oriented programs. We analysed the faults collected from three evolving aspect-oriented systems, all from different application domains. The analysis develops from two different angles. Firstly, we measured the impact of the obliviousness property on the fault-proneness of the evaluated systems. The results show that 40% of reported faults were due to the lack of awareness among base code and aspects. The second analysis regarded the fault-proneness of the main aspect-oriented programming (AOP) mechanisms, namely pointcuts, advices and intertype declarations. The results indicate that these mechanisms present similar fault-proneness when we consider both the overall system and concern-specific implementations. Our findings are reinforced by means of statistical tests. In general, this result contradicts the common intuition stating that the use of pointcut languages is the main source of faults in AOP. Fabiano Cutigi Ferrari, Rachel Burrows, Otávio Augusto Lazzarini Lemos, Alessandro F. Garcia 0001, Eduardo Figueiredo 0001, Nélio Cacho, Frederico Lopes, Nathalia Temudo, Liana Silva, Sérgio Soares, Awais Rashid, Paulo César Masiero, Thaís Vasconcelos Batista, José Carlos Maldonado |
ICSE (1) | 11 |
| 2009 | Pointcut Rejuvenation: Recovering Pointcut Expressions in Evolving Aspect-Oriented SoftwareabstractPointcut fragility is a well-documented problem in Aspect-Oriented Programming; changes to the base-code can lead to join points incorrectly falling in or out of the scope of pointcuts. We present an automated approach that limits fragility problems by providing mechanical assistance in pointcut maintenance. The approach is based on harnessing arbitrarily deep structural commonalities between program elements corresponding to join points selected by a pointcut. The extracted patterns are then applied to later versions to offer suggestions of new join points that may require inclusion. We demonstrate the usefulness of our technique by rejuvenating pointcuts in multiple versions of several open-source AspectJ programs. The results show that our parameterized heuristic algorithm was able to automatically infer new join points in subsequent versions with an average recall of 0.93. Moreover, these join points appeared, on average, in the top 4thpercentile of the suggestions, indicating that the results were precise. Raffi Khatchadourian, Phil Greenwood, Awais Rashid, Guoqing Harry Xu |
ASE | 3 |
| 2009 | EA-Analyzer: Automating Conflict Detection in Aspect-Oriented RequirementsabstractOne of the aims of aspect-oriented requirements engineering is to address the composability and subsequent analysis of crosscutting and non-crosscutting concerns during requirements engineering. Composing concerns may help to reveal conflicting dependencies that need to be identified and resolved. However, detecting conflicts in a large set of textual aspect-oriented requirements is an error-prone and time-consuming task. This paper presents EA-analyzer, the first automated tool for identifying conflicts in aspect-oriented requirements specified in natural-language text. The tool is based on a novel application of a Bayesian learning method that has been effective at classifying text. We present an empirical evaluation of the tool with three industrial-strength requirements documents from different real-life domains. We show that the tool achieves up to 92.97% accuracy when one of the case study documents is used as a training set and the other two as a validation set. Alberto Sardinha, Ruzanna Chitchyan, Nathan Weston, Phil Greenwood, Awais Rashid |
ASE | 5 |
| 2009 | Domain-Specific Metamodelling Languages for Software Language Engineering
Steffen Zschaler, Dimitrios S. Kolovos, Nicholas Drivalos Matragkas, Richard F. Paige, Awais Rashid |
SLE | 5 |
| 2009 | VML* - A Family of Languages for Variability Management in Software Product Lines
Steffen Zschaler, Pablo Sánchez 0002, João Pedro Santos, Mauricio Alférez, Awais Rashid, Lidia Fuentes, Ana Moreira 0001, João Araújo 0001, Uirá Kulesza |
SLE | 5 |
| 2009 | A framework for constructing semantically composable feature models from natural language requirements
Nathan Weston, Ruzanna Chitchyan, Awais Rashid |
SPLC | 3 |
| 2009 | Formal semantic conflict detection in aspect-oriented requirements
Nathan Weston, Ruzanna Chitchyan, Awais Rashid |
Requir. Eng. | 3 |
| 2008 | On the Impact of Evolving Requirements-Architecture Dependencies: An Exploratory Study
Safoora Shakil Khan, Phil Greenwood, Alessandro F. Garcia 0001, Awais Rashid |
CAiSE | 4 |
| 2008 | Assessing the Impact of Aspects on Exception Flows: An Exploratory Study
Roberta Coelho, Awais Rashid, Alessandro F. Garcia 0001, Fabiano Cutigi Ferrari, Nélio Cacho, Uirá Kulesza, Arndt von Staa, Carlos José Pereira de Lucena |
ECOOP | 2 |
| 2008 | Mutation Testing for Aspect-Oriented ProgramsabstractMutation testing has been shown to be one of the strongest testing criteria for the evaluation of both programs and test suites. Comprehensive sets of mutants require strong test sets to achieve acceptable testing coverage. Moreover, mutation operators are valuable for the evaluation of other testing approaches. Although its importance has been highlighted for aspect-oriented (AO) programs, there is still a need for a suitable set of mutation operators for AO languages. The quality of the mutation testing itself relies on the quality of such operators. This paper presents the design of a set of mutation operators for AspectJ-based programs. These operators model instances of fault types identified in an extensive survey. The fault types and respective operators are grouped according to the related language features. We also discuss the generalisation of the fault types to AO approaches other than AspectJ and the coverage that may be achieved with the application of the proposed operators. In addition, a cost analysis based on two case studies involving real-world applications has provided us feedback on the most expensive operators, which will support the definition of further testing strategies. Fabiano Cutigi Ferrari, José Carlos Maldonado, Awais Rashid |
ICST | 3 |
| 2008 | Aspect Mining in Procedural Object Oriented CodeabstractAlthough object-oriented programming promotes reusable and well factored entity decomposition, industrial software often shows traces of lack of object-oriented design and procedural thinking. This results in domain entity scattered and tangled code. This is often true in data intensive applications. Aspect mining techniques search for various patterns of scattered and tangled code pertaining to crosscutting concerns. However, in the presence of non-abstracted domain logic, the crosscutting concerns identified are inaccurately related to aspects since lack of 00 abstraction introduces false positives. This paper identifies the difficulty of identifying crosscutting concerns in systems lacking elementary object-oriented structure. It presents an approach classifying various crosscutting concerns. We report our experience on an industrial software system. Muhammad Usman Bhatti, Stéphane Ducasse, Awais Rashid |
ICPC | 3 |
| 2008 | Aspect-Oriented Requirements Engineering: An IntroductionabstractAspect-oriented requirements engineering (AORE) techniques provide new composition mechanisms to specify and reason about dependencies that crosscut elements of a requirements specification. This paper introduces the basic concepts of aspect-oriented requirements engineering and its support for compositional reasoning--reasoning about dependencies and interactions--over a requirements specification. Typical applications of aspect-oriented requirements engineering techniques are also highlighted. The paper concludes with an annotated bibliography of key tools, techniques and application studies. Awais Rashid |
RE | 1 |
| 2008 | A Formal Approach to Semantic Composition of Aspect-Oriented RequirementsabstractThe goal of aspect-oriented requirements engineering (AORE) is to identify possible crosscutting concerns, and to develop composition specifications around those concerns. These compositions can be used to reason about potential conflicts in the requirements and to relate requirements to architecture in semantically meaningful ways. Recent work in AORE has moved from a syntactic approach to composition, which leads to fragile compositions and increased coupling between aspect and base concerns, to a semantic composition approach, based on semantics of the natural language itself. However, such compositions are at present only informally specified, and as such formal reasoning about the requirements and the subsequent derivations are difficult. We present a formal approach to these semantic-based compositions which facilitates this reasoning. We show that the approach especially lends itself to identifying conflicts between requirements and mapping compositions to a derived architecture. Nathan Weston, Ruzanna Chitchyan, Awais Rashid |
RE | 3 |
| 2008 | Rejuvenate Pointcut: A Tool for Pointcut Expression Recovery in Evolving Aspect-Oriented SoftwareabstractAspect-oriented programming (AOP) strives to localize the scattered and tangled implementations of crosscutting concerns (CCCs) by allowing developers to declare that certain actions (advice) should be taken at specific points (join points) during the execution of software where a CCC (an aspect) is applicable. However, it is non-trivial to construct optimal pointcut expressions (a collection of join points) that capture the true intentions of the programmer and, upon evolution, maintain these intentions. We demonstrate an AspectJ source-level inferencing tool called rejuvenate pointcut which helps developers maintain pointcut expressions over the lifetime of a software product. A key insight into the tool's construction is that the problem of maintaining pointcut expressions bears strong similarity to the requirements traceability problem in software engineering; hence, the underlying algorithm was devised by adapting existing approaches for requirements traceability to pointcut maintenance. The Eclipse IDE-based tool identifies intention graph patterns pertaining to a pointcut and, based on these patterns, uncovers other potential join points that may fall within the scope of the pointcut with a given confidence. This work represents a significant step towards providing tool-supported maintainability for evolving aspect-oriented software. Raffi Khatchadourian, Awais Rashid |
SCAM | 2 |
| 2008 | An Exploratory Study of Information Retrieval Techniques in Domain AnalysisabstractDomain analysis involves not only looking at standard requirements documents (e.g., use case specifications) but also at customer information packs, market analyses, etc. Looking across all these documents and deriving, in a practical and scalable way, a feature model that is comprised of coherent abstractions is a fundamental and non-trivial challenge. We conduct an exploratory study to investigate the suitability of Information Retrieval (IR) techniques for scalable identification of commonalities and variabilities in requirement specifications for software product lines. Accordingly, based on observations derived from industrial experience and on state-of-the-art research and practice, we also propose an initial framework, leveraging IR to systematically abstract requirements from existing specifications of a given domain into a feature model. We evaluate this framework, present a roadmap for its further extension, and formulate hypotheses to guide future work in exploring IR techniques for domain analysis. Vander Alves, Christa Schwanninger, Luciano Barbosa, Awais Rashid, Peter Sawyer, Paul Rayson, Christoph Pohl, Andreas Rummler |
SPLC | 4 |
| 2008 | Early Aspects: Aspect-Oriented Requirements and Architecture for Product Lines ([email protected])abstractEarly aspects deal with crosscutting concerns in requirements analysis, domain analysis and architecture design [1]. Work on early aspects focuses on systematically identifying, modularizing, and analyzing such crosscutting concerns and their impact at the early phases of the software development life cycle. Vander Alves, Christa Schwanninger, Paul C. Clements, Awais Rashid, Ana Moreira 0001, João Araújo 0001, Elisa L. A. Baniassad, Bedir Tekinerdogan |
SPLC | 4 |
| 2007 | On the Impact of Aspectual Decompositions on Design Stability: An Empirical Study
Phil Greenwood, Thiago T. Bartolomei, Eduardo Figueiredo 0001, Marcos Dósea, Alessandro F. Garcia 0001, Nélio Cacho, Cláudio Sant'Anna, Sérgio Soares, Paulo Borba, Uirá Kulesza, Awais Rashid |
ECOOP | 11 |
| 2007 | A Comparative Study of Aspect-Oriented Requirements Engineering ApproachesabstractAspect-Oriented Requirements Engineering (AORE) aims at improving separation of concerns in the problem space by offering new ways of modularising requirements. Over recent years several AORE approaches have emerged by evolving contemporary requirements approaches such as viewpoints-, scenarios- and goal-based models. Due to the novelty of these techniques, there is a lack of systematic comparative studies analyzing the benefits and drawbacks they can offer to the requirements engineering practice. This paper presents a case study contrasting four eminent AORE approaches in terms of time effectiveness and accuracy of their produced outcome. We address challenges related to the heterogeneous definitions for AORE model concepts as well as the fact that they perform similar general requirements process activities in different ways. In order to address these challenges, we provide a mapping of the AORE approaches onto general RE activities and provide a common naming scheme. The case study results show that specification of aspect compositions in AORE presents an effort bottleneck that has to be carefully weighed against the added benefits of modularity and analysis of systemic properties offered by AORE. Consequently, our study provides an initial yet significant stepping stone towards improving the evaluation of AORE approaches and understanding their contribution to requirements engineering. Américo Sampaio, Phil Greenwood, Alessandro F. Garcia 0001, Awais Rashid |
ESEM | 4 |
| 2007 | JAT: A Test Automation Framework for Multi-Agent SystemsabstractAutomated tests have been widely used as a supporting mechanism during software development and maintenance activities. It improves the confidence on software releases as it seeks to uncover regression bugs, and serves as a live documentation which is very useful when evolving systems. Concerning multi agent systems (MASs), some characteristics such as agent autonomy and asynchronous message-based interaction bring a degree of non-determinism which presents new testing challenges. This paper proposes JAT, a framework for building and running MASs test scenarios, which relies on the use of aspect-oriented techniques to monitor the autonomous agents during tests and control the test input of asynchronous test cases. The tool has been developed on top of JADE, a widely used agent platform implemented in Java. We have used JAT on testing 3 different MASs. Our experience shows that JAT can be used to build test scenarios which can achieve high fault-detection effectiveness. Roberta Coelho, Elder Cirilo, Uirá Kulesza, Arndt von Staa, Awais Rashid, Carlos José Pereira de Lucena |
ICSM | 5 |
| 2006 | Aspect-oriented software development beyond programmingabstractThis tutorial focuses on applying aspect-oriented software development (AOSD) concepts beyond the programming stage of the software development life cycle. Using concrete methods, tools, techniques and notations we discuss how to use AOSD techniques to systematically treat crosscutting concerns during requirements engineering (RE), architecture design and detailed design as well as the mapping between aspects at these stages. With a clear focus on composition, modelling, trade-off analysis and assessment methods, the tutorial imparts an engineering ethos for translation into day-to-day processes and practices. Awais Rashid, Alessandro F. Garcia 0001, Ana Moreira 0001 |
ICSE | 1 |
| 2006 | Aspect-Oriented Software Development Beyond Programming
Awais Rashid, Alessandro F. Garcia 0001, Ana Moreira 0001 |
ICSR | 1 |
| 2006 | Domain Models Are NOT Aspect Free
Awais Rashid, Ana Moreira 0001 |
MoDELS | 1 |
| 2006 | An architectural pattern for designing component-based application frameworksabstractAbstract A widely used architecture for the development of software systems is the component‐based application framework. Such frameworks offer two mechanisms. First, they provide component integration and interoperability services which make it possible to extend the framework with various third‐party components. Second, they provide mechanisms to customize the integrated components to the specific needs of applications to be built using the framework. This paper describes an architectural pattern for designing such frameworks so that the appropriate mix of fixed and flexible elements can be integrated into architectures that maximize scalability and extensibility. The pattern is illustrated by frameworks developed for three different application domains: electronic design automation, scientific visualization and numerical simulation, and industrial control systems. Copyright © 2005 John Wiley & Sons, Ltd. David Parsons 0001, Awais Rashid, Alexandru C. Telea, Andreas Speck |
Softw. Pract. Exp. | 2 |
| 2005 | A Concern-Oriented Requirements Engineering Model
Ana Moreira 0001, João Araújo 0001, Awais Rashid |
CAiSE | 3 |
| 2005 | CoCA: A Composition-Centric Approach to Requirements EngineeringabstractIn this paper, we discuss how mutual influences (e.g. conflicts) of different stakeholder concerns can be detected and reasoned about through composition and stepwise refinement. Some concepts from the aspect-oriented software development paradigm are used to support the composition-centric approach. Ruzanna Chitchyan, Ian Sommerville, Awais Rashid |
RE | 3 |
| 2005 | Multi-Dimensional Separation of Concerns in Requirements EngineeringabstractExisting requirements engineering approaches manage broadly scoped requirements and constraints in a fashion that is largely two-dimensional, where functional requirements serve as the base decomposition with non-functional requirements cutting across them. Therefore, crosscutting functional requirements are not effectively handled. This in turn leads to architecture trade-offs being mainly guided by the non-functional requirements, so that the system quality attributes can be satisfied. In this paper, we propose a uniform treatment of concerns at the requirements engineering level, regardless of their functional, non-functional or crosscutting nature. Our approach is based on the observation that concerns in a system are, in fact, a subset, and concrete realisations, of abstract concerns in a meta concern space. One can delineate requirements according to these abstract concerns to derive more system-specific, concrete concerns. We introduce the notion of a compositional intersection, which allows us to choose appropriate sets of concerns in our multi-dimensional separation as a basis to observe trade-offs among other concerns. This provides a rigorous analysis of requirements-level trade-offs as well as important insights into various architectural choices available to satisfy a particular functional or non-functional concern. Ana Moreira 0001, Awais Rashid, João Araújo 0001 |
RE | 2 |
| 2005 | Early-AIM: An Approach for Identifying Aspects in RequirementsabstractIdentifying aspects at an early stage helps to achieve separation of crosscutting concerns in the initial system analysis, instead of deferring such decisions to later stages of design and code, and thus, having to perform costly refactorings. This paper describes the early-AIM (early aspects identification method) approach that utilises corpus-based natural language processing (NLP) techniques to effectively enable the identification and modelling of early aspects in a semi-automated way. Américo Sampaio, Awais Rashid, Paul Rayson |
RE | 2 |
| 2005 | Towards a taxonomy of software changeabstractAbstract Previous taxonomies of software change have focused on the purpose of the change (i.e., the why) rather than the underlying mechanisms. This paper proposes a taxonomy of software change based on characterizing the mechanisms of change and the factors that influence these mechanisms. The ultimate goal of this taxonomy is to provide a framework that positions concrete tools, formalisms and methods within the domain of software evolution. Such a framework would considerably ease comparison between the various mechanisms of change. It would also allow practitioners to identify and evaluate the relevant tools, methods and formalisms for a particular change scenario. As an initial step towards this taxonomy, the paper presents a framework that can be used to characterize software change support tools and to identify the factors that impact on the use of these tools. The framework is evaluated by applying it to three different change support tools and by comparing these tools based on this analysis. Copyright © 2005 John Wiley & Sons, Ltd. Jim Buckley, Tom Mens, Matthias Zenger, Awais Rashid, Günter Kniesel-Wünsche |
J. Softw. Maintenance Res. Pract. | 4 |
| 2005 | A database evolution taxonomy for object-oriented databasesabstractLike any other database application, object database applications are subject to evolution. Evolution, however, is a critical requirement in object-oriented databases as it is a fundamental characteristic of complex applications such as computer-aided design and manufacturing (CAD/CAM) and office information systems. Object-oriented databases are inherently suited to supporting such applications. In this paper we present a database evolution taxonomy for object-oriented databases. We describe a conceptual database model and use it to define the taxonomy. We also present the various invariants and rules governing the various evolution operations. The execution sequence of rules is described. An implementation of the database model and the evolution taxonomy in the Semi-Autonomous Database Evolution System (SADES), is discussed. The implementation employs aspect-oriented programming techniques to provide a flexible means of transforming objects upon evolution, and implementing some application-specific evolution primitives. A case study compares the evolution taxonomy with existing evolution approaches. The comparison demonstrates that the taxonomy and its corresponding implementation in SADES provide improved coverage of the fundamental evolution operations to which an object database might be subjected. At the same time, erosion of the database structure is avoided by maintaining a coherent and comprehensible view of historical changes. Copyright © 2005 John Wiley & Sons, Ltd. Awais Rashid, Peter Sawyer |
J. Softw. Maintenance Res. Pract. | 1 |
| 2004 | Supporting Flexible Object Database Evolution with Aspects
Awais Rashid, Nicholas A. Leidenfrost |
GPCE | 1 |
| 2004 | Framed Aspects: Supporting Variability and Configurability for AOP
Neil Loughran, Awais Rashid |
ICSR | 2 |
| 2004 | From Aspectual Requirements to Proof Obligations for Aspect-Oriented Systems
Shmuel Katz, Awais Rashid |
RE | 2 |
| 2003 | A Framework for Customisable Schema Evolution in Object-Oriented DatabasesabstractThis paper describes an evolution framework supporting customization of the schema evolution and instance adaptation approaches in an object database management system. The framework is implemented as an integral part of an interpreter for a language with a versioned type system and employs concepts from object-oriented frameworks and aspect-oriented programming to support flexible changes. Some example customizations currently implemented with the framework are also described. Awais Rashid |
IDEAS | 1 |
| 2003 | Editorial: Aspect-oriented Programming and Separation of Crosscutting Concernsabstract1 Computing Department, Lancaster University, UK Awais Rashid, Lynne Blair |
Comput. J. | 1 |
| 2002 | Early Aspects: A Model for Aspect-Oriented Requirements EngineerinabstractEffective RE must reconcile the need to achieve separation of concerns with the need to satisfy broadly scoped requirements and constraints. Techniques such as use cases and viewpoints help achieve separation of stakeholders' concerns but ensuring their consistency with global requirements and constraints is largely unsupported. We build on recent work that has emerged from the aspect-oriented programming (AOP) community to propose a general model for aspect oriented requirements engineering (AORE). The model supports separation of crosscutting functional and non-functional properties at the requirements level. We argue that early separation of such crosscutting properties supports effective determination of their mapping and influence on artefacts at later development stages. A realisation of the model based on a case study of a toll collection system is presented. Awais Rashid, Peter Sawyer, Ana Moreira 0001, João Araújo 0001 |
RE | 1 |
| 2001 | A Database Evolution Approach for Object-Oriented DatabasesabstractThe paper describes a composite evolution approach which integrates the evolution of the various types of entities in an object-oriented database into one model. The approach provides maintainers with a coherent and comprehensible view of the system and at the same time maintains change histories at a fine granularity. Links among meta-objects are implemented using dynamic relationships which are semantic constructs and first-class objects. Referential integrity is maintained by the relationships architecture reducing the evolution complexity at the meta-object level. A customisable and exchangeable instance adaptation approach is proposed. The approach is based on separating the instance adaptation code from class versions using aspects, abstractions used in Aspect-Oriented Programming to localise crosscutting concerns. A high level object-oriented model offering transparent access to the proposed evolution functionality is provided. Awais Rashid |
ICSM | 1 |
| 2000 | From Object-Oriented to Aspect-Oriented Databases
Awais Rashid, Elke Pulvermüller |
DEXA | 1 |
| 1999 | Dynamic Relationships in Object Oriented Databases: A Uniform Approach
Awais Rashid, Peter Sawyer |
DEXA | 1 |
| 1998 | Facilitating Virtual Representation of CAD Data Through A Learning Based Approach to Conceptual Database Evolution Employing Direct Instance Sharing
Awais Rashid, Peter Sawyer |
DEXA | 1 |