Jeffy Jahfar Poozhithara

dblp:271/0707 · DBLP profile ↗
← Back
3ranked-venue papers
3as first author
3since 2021 · last 2023
0000-0002-4692-3586ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2023 Keyword Extraction From Specification Documents for Planning Security Mechanisms
abstract
Software development companies heavily invest both time and money to provide post-production support to fix security vulnerabilities in their products. Current techniques identify vulnerabilities from source code using static and dynamic analyses. However, this does not help integrate security mechanisms early in the architectural design phase. We develop VDocScan, a technique for predicting vulnerabilities based on specification documents, even before the development stage. We evaluate VDocScan using an extensive dataset of CVE vulnerability reports mapped to over 3600 product documentations. An evaluation of 8 CWE vulnerability pillars shows that even interpretable whitebox classifiers predict vulnerabilities with up to 61.1% precision and 78% recall. Further, using strategies to improve the relevance of extracted keywords, addressing class imbalance, segregating products into categories such as Operating Systems, Web applications, and Hardware, and using blackbox ensemble models such as the random forest classifier improves the performance to 96% precision and 91.1% recall. The high precision and recall shows that VDocScan can anticipate vulnerabilities detected in a product's lifetime ahead of time during the Design phase to incorporate necessary security mechanisms. The performance is consistently high for vulnerabilities with the mode of introduction: architecture and design.
Jeffy Jahfar Poozhithara, Hazeline U. Asuncion, Brent Lagesse
ICSE1
2023 Predictive Algorithm for Team Mental Model Convergence
abstract
Is everyone on your team on the same page about the task? This is a question team leaders want to know. Herein, we take an approach that can help managers move the team in the right direction of team mental models (TMMs), individually held cognitive representations of task components that when similar and/or accurate can promote task success. We begin by defining the new concept of mental model shifts (MMSs) as the directional shift in each team member’s mental model, leading to an increase or decrease in convergence toward a shared or quality referent mental model. Next, we propose an algorithm that applies the concepts of Markov chains and vector geometry on communication patterns to predict future patterns and TMM convergence (i.e., sharedness and quality) levels. We base the model on a dataset of teams conducting the National Aeronautics and Space Administration (NASA) human exploration research analog (HERA) missions from which we draw communication attributes of MMS, process topic, and message purpose. We show that tasks can be modeled as vectors using the frequency of attribute patterns. Our initial experiments show that an accuracy of up to 86.21% can be achieved in predicting future communication patterns with data from real-world tasks. Furthermore, we validate the estimation of TMM sharedness, showing that the model results are comparable to sharedness ratings provided by subject matter experts with an average accuracy of 71.29%. Research and practical implications are discussed.
Jeffy Jahfar Poozhithara, Deanna M. Kennedy, Spencer Onstot, Agne Januskeviciute, Marjanthi Cekrezi
IEEE Trans. Comput. Soc. Syst.1
2022 Towards Lightweight Detection of Design Patterns in Source Code
abstract
Identifying which design patterns exist in source code helps maintenance engineers better understand source code and determine if new requirements can be satisfied.Automated techniques for finding design patterns generally require much time to label training datasets or to specify rules/queries for each pattern, and is difficult to extend support to secure design patterns (SDPs) and combination patterns.To address these challenges, we introduce PatternScout, a technique for automatic generation of SPARQL queries from UML Class diagrams and Sequence diagrams.These queries are used to detect patterns in the source code.Our results indicate that PatternScout can detect object-oriented design patterns (OODP) with accuracy that is comparable or better than existing techniques.It can also generate queries for SDPs that can be represented as UML Class diagrams.
Jeffy Jahfar Poozhithara, Hazeline U. Asuncion, Brent Lagesse
SEKE1