Alessandra Maciel Paz Milani

dblp:278/2011 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2025
0000-0001-8900-4179ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Fuzzy to clear: Elucidating the threat hunter cognitive process and cognitive support needs
abstract
With security threats increasing in frequency and severity, it is critical that we consider the important role of threat hunters. These highly-trained security professionals learn to see, identify, and intercept security threats. Many recent works and existing tools in cybersecurity are focused on automating the threat hunting process, often overlooking the critical human element. Our study shifts this paradigm by emphasizing a human-centered approach to understanding the lived experiences of threat hunters. By observing threat hunters during hunting sessions and analyzing the rich insights they provide, we seek to advance the understanding of their cognitive processes and the tool support they need. Through an in-depth observational study of threat hunters, we introduce a model of how they build and refine their mental models during threat hunting sessions. We also present 23 themes that provide a foundation to better understand threat hunter needs and suggest five actionable design propositions to enhance the tools that support them. Through these contributions, our work enriches the theoretical understanding of threat hunting and provides practical insights for designing more effective, human-centered cybersecurity tools.
Alessandra Maciel Paz Milani, Arty Starr, Samantha Hill, Callum Curtis, Norman Anderson, David Moreno-Lumbreras, Margaret-Anne D. Storey
Comput. Secur.1
2025 Guiding principles for mixed methods research in software engineering
abstract
Abstract Mixed methods research is often used in software engineering, but researchers outside of the social or human sciences often lack experience when using these designs. This paper provides guiding principles and advice on how to design mixed method research, and to encourage the intentional, rigorous, and innovative application of mixed methods in software engineering. It also presents key properties of core mixed method research designs. Through a number of fictitious but recognizable software engineering research scenarios, we showcase how to choose suitable mixed method designs and consider the inevitable trade-offs any design choice leads to. We describe several antipatterns that illustrate what to avoid in mixed method research, and when mixed method research should be considered over other approaches.
Margaret-Anne D. Storey, Rashina Hoda, Alessandra Maciel Paz Milani, Maria Teresa Baldassarre
Empir. Softw. Eng.3
2024 P-Inti: Interactive Visual Representation of Programming Concepts for Learning and Instruction
abstract
Learning to program poses significant challenges, not only to learners but also teaching challenges to instructors. Several previous approaches to facilitate learning to program or analyze algorithms have employed visuals and visualizations, but they are limited in interactivity and in the ability of instructors and learners to customize the visuals to their learning goals. In this work, we present the design and implementation of P-Inti, an interactive constructive learning aid designed to allow learners to use a visual canvas to explore aspects of the state, control flow and execution of a program or algorithm. Instructors can also use the tool to generate interactive visual explanations for code and support quick switching between different algorithms.
Shishir Halaharvi, Gonzalo Méndez 0002, Hamid Mansoor, Quinton Yong, Alessandra Maciel Paz Milani, Margaret-Anne D. Storey, Miguel A. Nacenta
VL/HCC5
2023 A Framework for Automating the Measurement of DevOps Research and Assessment (DORA) Metrics
abstract
The DevOps Research and Assessment (DORA) metrics have been widely accepted by the software industry as a powerful method to quantify DevOps performance, leading to significant interest in their measurement. Existing proprietary solutions are highly customised, and require specific types of cloud infrastructure, limiting their suitability for projects such as libraries, frameworks, and open source projects. To address this gap, we present a framework which operationalizes the DORA metrics independently of a project’s software development life-cycle or type of deployment. We demonstrate the general applicability of this framework by using it to calculate the throughput and stability of 304 popular open source repositories. We find that the time-series data it produces provides meaningful insights into the trending direction of a project’s recent and retrospective throughput and stability performance, especially when significant changes in metrics are correlated with major events in the project’s history. We conclude with recommendations for augmenting our approach with additional information such as bug criticality when such information is available.
Brennan Wilkes, Alessandra Maciel Paz Milani, Margaret-Anne D. Storey
ICSME2