Xabier Larrucea

dblp:46/395 · DBLP profile ↗
← Back
28ranked-venue papers
20as first author
6since 2021 · last 2025
0000-0002-6402-922XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 26 · 19 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Towards the Analysis of Software Supply Chain and EU Regulations
Xabier Larrucea, Izaskun Santamaría
EuroSPI (2)1
2024 Trustworthy and collaborative traceability management: Experts' feedback on a blockchain-enabled framework
abstract
Abstract Blockchain technology has attracted significant attention in both academia and industry. Recently, the application of blockchain has been advocated in software engineering. The global software engineering paradigm exacerbates trust issues, as distributed and cross‐organizational teams need to share software artifacts. In such a context, there is a need for a decentralized yet reliable traceability knowledge base to keep track of what/how/when/by whom software artifacts were created or changed. This study presents a blockchain‐enabled framework for trustworthy and collaborative traceability management and identifies benefits, challenges, and potential improvements based on the feedback of software engineering experts. A qualitative approach was followed in this study through semistructured interviews with software engineering (SE) experts. Transcripts were analyzed by applying the content analysis technique. The results indicated the emergence of five categories, further grouped into three main categories: experts' perceptions, blockchain‐based software process improvement, and experts' recommendations. In addition, the findings suggested four archetypes of organizations that may be interested in blockchain technology: distributed organizations, organizations with contract‐based projects, organizations in regulated domains, and regulators who may push the use of this technology. Further efforts should be devoted to the integration of the proposal with tools used throughout the software development lifecycle and leveraging the potential of smart contracts in validating the implementation of requirements automatically.
Selina Demi, Mary-Luz Sánchez-Gordón, Monica Kristiansen, Xabier Larrucea
J. Softw. Evol. Process.4
2023 Integrating privacy debt and VSE's software developments
abstract
Abstract With the advent of regulations protecting users such as the General Data Protection Regulation, security and privacy concerns are playing a new role in small settings such as in very small entities. Their relevance is increasing, and privacy is being considered a Troy horse in software developments. In fact, privacy is a part of software architectural decisions, and they must be considered as a technical debt. The contributions of this paper are the following: a privacy debt definition with a principal and an interest, privacy‐related activities to be considered within the ISO/IEC 29110 basic profile, and the use of the net present value within this context. All these contributions help us to integrate privacy debt and VSE's software developments.
Izaskun Santamaría, Xabier Larrucea, Borja Fernández-Gauna
J. Softw. Evol. Process.2
2022 Actor-critic continuous state reinforcement learning for wind-turbine control robust optimization
abstract
The control of Variable-Speed Wind-Turbines (VSWT) extracting electrical power from the wind kinetic energy are composed of subsystems that need to be controlled jointly, namely the blade pitch and the generator torque controllers. Previous state of the art approaches decompose the joint control problem into independent control subproblems, each with its own control subgoal, carrying out separately the design and tuning of a parameterized controller for each subproblem. Such approaches neglect interactions among subsystems which can introduce significant effects. This paper applies Actor-Critic Reinforcement Learning (ACRL) for the joint control problem as a whole, carrying out the simultaneous control parameter optimization of both subsystems without neglecting their interactions, aiming for a globally optimal control of the whole system. The innovative control architecture uses an augmented input space so that the parameters can be fine-tuned for each working condition. Validation results conducted on simulation experiments using the state-of-the-art OpenFAST simulator show a significant efficiency improvement relative to the best state of the art controllers used as benchmarks, up to a 22% improvement in the average power error performance after ACRL training.
Borja Fernández-Gauna, Manuel Graña, Juan-Luis Osa-Amilibia, Xabier Larrucea
Inf. Sci.4
2021 Dealing with Privacy for Protecting Information
Xabier Larrucea, Izaskun Santamaría
EuroSPI1
2021 Towards a privacy debt
abstract
Abstract This study argues the difference between security and privacy and outlines the concept of Privacy Debt as a new Technical Debt. Privacy is gaining momentum in any software system due to mandatory compliance with respect to laws and regulations. There are several types of technical debts within the umbrella of software engineering, and most of them arise during different phases of software development. Several research studies have been focussed on highlighting different types of technical debts. However, authors introduce Privacy Debt as a particular technical debt focussed on privacy management and linked to a perturbative method. Privacy must be considered not only as technical debt requirements but also at design and deployment phases, among others. In addition, this method is illustrated with a use case.
Xabier Larrucea, Izaskun Santamaría, Manuel Graña
IET Softw.1
2020 An ICS Based Scenario Generator for Cyber Ranges
Xabier Larrucea, Alberto Molinuevo Martín
EuroSPI1
2020 Designing a Cyber Range Exercise for Educational Purposes
Xabier Larrucea, Izaskun Santamaría
EuroSPI1
2020 Analysing encryption mechanisms and functional safety in a ROS-based architecture
abstract
Abstract Robot Operating System (ROS) is a middleware for connecting different components of robots. However, its use is becoming more popular in other domains such as in the automotive sector where initial prototypes have been customized and deployed in cars for demonstrating different functional purposes. Nevertheless, ROS has not been yet tested enough to be used in secure and safety environments. For example, in order to strengthen our ROS architecture, we have encrypted the messages within it. Therefore, this paper analyses the impact of Advanced Encryption Standard (AES) encryption mechanism and the functional safety of our prototype. In this sense, we are considering encrypting messages and we assess the timing constraints, as suggested by the ISO 26262, required for assuring a secure communication between components.
Xabier Larrucea, Pablo González-Nalda, Ismael Etxeberria, Mari Carmen Otero
J. Softw. Evol. Process.1
2020 Managing security debt across PLC phases in a VSE context
abstract
Abstract Nowadays, security and safety aspects are two of the major concerns for any software system development, especially while developing safety critical systems. This is especially relevant for very small entities because they have a limited amount of resources for dealing with all these aspects at the same time. In addition, these systems are highly regulated domains, and they involve a huge set of standards focused on safety and security‐related issues. Therefore, these small entities are not only facing hurdles related to technical aspects but also from the so‐called technical debt when overarching a critical development. This paper extends the assurance cases approach by integrating security aspects within the life cycle, and it proposes a framework for managing the associated security technical debt for very small entities. A tool chain is outlined, and the approach is illustrated with an industrial use case.
Xabier Larrucea, Izaskun Santamaría, Borja Fernández-Gauna
J. Softw. Evol. Process.1
2019 Dealing with Security in a Real DevOps Environment
Xabier Larrucea, Alberto Berreteaga, Izaskun Santamaría
EuroSPI1
2019 Gamification for software process improvement: a practical approach
abstract
Gamification is a research field that is intended to increase motivation, so it is especially indicated in human capital intensive environments such as the software industry. Within Software Engineering, one of the main issues regarding software process improvement (SPI) is personnel motivation in specific SPI initiatives. These issues are stronger in small and medium software development companies where employees have to deal with the pressure of deadlines and occasional work overload. To address the adoption of SPI initiatives, the researchers implemented a defined gamification framework for deployment in SPI efforts in order to increase motivation among software workers and to enhance SPI results. The framework was rolled out in a small Spanish software development organisation, which is conducting internal SPI initiatives. To validate the effectiveness of the implemented framework, a controlled experiment was carried out in which an experimental group adopted SPI improvements using a gamification approach. The implementation results show that the application of the framework does not increase personnel motivation in SPI tasks although it contributes to enhancing the SPI tasks performance. This study discusses the limitations and recommendations to implement appropriately the SPI‐gamification framework in the scope of small and medium software development companies.
Eduardo Herranz, Javier García Guzmán, Antonio de Amescua Seco, Xabier Larrucea
IET Softw.4
2019 Assessing source code vulnerabilities in a cloud-based system for health systems: OpenNCP
abstract
Healthcare systems have been improved in order to provide support to cross‐border situations where one citizen from one country travels to another country and requires the use of their health records. Several initiatives have been carried out to tackle this problem. This is the case for the OpenNCP which is supported by the European Commission by providing a common network and an infrastructure to connect different national healthcare systems which most of the times are cloud‐based systems. The OpenNCP plays a key role in communicating health records among European Union's member states, and therefore it manages sensitive information. Therefore, this study provides a security analysis of this platform and a prototype is developed for identifying secure patterns in source code.
Xabier Larrucea, Izaskun Santamaría, Ricardo Colomo-Palacios
IET Softw.1
2019 Service level agreement-based GDPR compliance and security assurance in (multi)Cloud-based systems
abstract
Compliance with the new European General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and security assurance are currently two major challenges of Cloud‐based systems. GDPR compliance implies both privacy and security mechanisms definition, enforcement and control, including evidence collection. This study presents a novel DevOps framework aimed at supporting Cloud consumers in designing, deploying and operating (multi)Cloud systems that include the necessary privacy and security controls for ensuring transparency to end‐users, third parties in service provision (if any) and law enforcement authorities. The framework relies on the risk‐driven specification at design time of privacy and security level objectives in the system service level agreement and in their continuous monitoring and enforcement at runtime.
Erkuden Rios, Eider Iturbe, Xabier Larrucea, Massimiliano Rak, Wissam Mallouli, Jacek Dominiak, Victor Muntés-Mulero, Peter Matthews, Luis Gonzalez
IET Softw.3
2019 Correlations study and clustering from SPI experiences in small settings
abstract
Abstract Software Process Improvement (SPI) initiatives have been applied in a wide set of organisations including very small entities (VSE). In fact, this kind of organisations is facing several hurdles when overarching a SPI initiative. In this context, the ISO/IEC 29110 has been used as a lightweight reference model for steering VSEs in their SPI initiatives. The inherent uncertainty behind the SPI curtains blocks the organisations in their investments. Due to these reasons, we need to identify relationships and similarities in order to predict whether a SPI will succeed or not. We propose the use of Self‐Organising Maps for identifying patterns from these SPI studies. The aim of this paper is to identify correlations among SPI studies and to discover patterns from them.
Xabier Larrucea, Izaskun Santamaría
J. Softw. Evol. Process.1
2018 Approach for Enabling Security Across PLC Phases: An Industrial Use Case
Xabier Larrucea, Félix Nanclares, Izaskun Santamaría, Ricardo Ruiz Nolasco
EuroSPI1
2017 Towards a Survival Analysis of Very Small Organisations
Xabier Larrucea, Izaskun Santamaría
EuroSPI1
2017 Towards the Integration of Security Practices in the Software Implementation Process of ISO/IEC 29110: A Mapping
Mary-Luz Sánchez-Gordón, Ricardo Colomo-Palacios, Alex Sánchez Gordon, Antonio de Amescua Seco, Xabier Larrucea
EuroSPI5
2017 Comparing SPI Survival Studies in Small Settings
Xabier Larrucea, Izaskun Santamaría
SPICE1
2016 Modelling and Certifying Safety for Cyber-Physical Systems: An Educational Experiment
abstract
Modelling and certifying safety systems are not straightforward activities, and they usually require a specific training and experience. The emergence of ISO26262 as a standard for the automotive sector is foreseen as a basic knowledge in the automotive sector. A special attention is required to these safety critical systems and to its related standards. This paper provides a controlled experiment carried out in classroom for teaching and learning safety principles by using Opencert tool.
Xabier Larrucea
SEAA1
2016 A GSN Approach to SEooC for an Automotive Hall Sensor
Xabier Larrucea, Silvana Mergen, Alastair Walker
EuroSPI1
2016 Assessing ISO/IEC29110 by means of ITMark: results from an experience factory
abstract
Abstract ISO/IEC 29110 is intended to help very small entities in improving their software processes. However, this standard is not the only initiative devoted to help organizations in these matters. For instance, ITMark is an established method with an important background in terms of number and diversity of assessments. The aim of this paper is to present a method to assess ISO/IEC 29110 by means of the evaluation performed under the ITMark certification schema built upon an experience factory. To do so, in this paper, authors present, firstly, a mapping for ITMark to ISO/IEC 29110 and, secondly, a study to test the applicability of the assessments made by ITMark in the ISO/IEC 29110 environment taking into account the previous mapping. The main conclusion from this industrial experience is that ITMark can be used as a method for assessing very small entities. Copyright © 2016 John Wiley & Sons, Ltd.
Xabier Larrucea, Izaskun Santamaría, Ricardo Colomo-Palacios
J. Softw. Evol. Process.1
2015 A Tool Suite for Assurance Cases and Evidences: Avionics Experiences
Alejandra Ruiz López, Xabier Larrucea, Huáscar Espinoza
EuroSPI2
2015 An Industrial Experience in Cross Domain Assurance Projects
Alejandra Ruiz López, Xabier Larrucea, Huáscar Espinoza, Franck Aime, Cyril Marchand
EuroSPI2
2014 An industrial assessment for a multimodel framework
abstract
ABSTRACT Software process improvement (SPI) initiatives are facing complex environments where stakeholders need to integrate different reference models in their organizations. There are several approaches to multimodel environments defining some steps or activities that should be carried out for implementing it efficiently inside organizations. This paper presents a report on the use of a multimodel framework integrating three quality reference models in 47 SPI initiatives. Basically, this report is based on statistical data extracted from industrial assessments. Copyright © 2014 John Wiley & Sons, Ltd.
Xabier Larrucea, Izaskun Santamaría
J. Softw. Evol. Process.1
2012 A Harmonized Multimodel Framework for Safety Environments
Xabier Larrucea, Izaskun Santamaría, Paolo Panaroni
EuroSPI1
2010 A Metamodel Integration for Metrics and Processes Correlation
Xabier Larrucea, Eider Iturbe
ICSOFT (1)1
2009 Modelling and Deploying Security Policies
Xabier Larrucea, Rubén Alonso
WEBIST1