Jingyue Li

dblp:47/3099 · DBLP profile ↗
← Back
56ranked-venue papers
14as first author
29since 2021 · last 2026
0000-0002-7958-391XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 46 · 14 first-author · 21 since 2021Security and privacy · 4 · 3 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 Feature-Centric Methodology for Analyzing Cross-Chain NFT Migration Compatibility
Mohd Sameen Chishti, Damilare Peter Oyinloye, Jingyue Li
ICBC3
2026 SoK: cross-chain bridging architectural design flaws and mitigations
abstract
Cross-chain bridges are solutions that enable interoperability between heterogeneous blockchains. In contrast to the underlying blockchains, the bridges often provide inferior security guarantees and have been targets of hacks, causing damage in the range of 1.5 to 2 billion USD in 2022. The current state of bridge architectures is that they are ambiguous, and the relation between overarching architectures, underlying components, and exploits is shallow. We address this gap through a multivocal literature review covering 64 different bridges, including 31 exploits and four known bugs over three years (2021-2023). Our analysis identifies 13 architectural components of blockchain bridges. We link the components to eight types of vulnerabilities, also called design flaws. Furthermore, we identified prevention measures and proposed 11 impact reduction measures based on existing and possible countermeasures to address the imminent exploitation of design flaws. The results present an overview of the state of the art in bridge security, future research directions, and guidelines for designing and implementing secure cross-chain bridge architectures.
Jakob Svennevik Notland, Jingyue Li, Mariusz Nowostawski, Peter Halland Haro
Blockchain Res. Appl.2
2026 Correction to: A comprehensive analysis of challenges and strategies for software release notes on github
Hao He 0012, Kai Gao 0008, Wenxin Xiao, Jingyue Li, Minghui Zhou 0001
Empir. Softw. Eng.5
2025 Chameleon Hash-Based Redactable Blockchains: A Systematic Literature Review
Weilong Lyu, Jingyue Li
ICA3PP (1)4
2025 An empirical study on deployment in cross-chain decentralised autonomous organisations
abstract
Decentralised Autonomous Organisations (DAOs) are self-governing democratic entities that operate and provide services via smart contracts on behalf of their users. Certain DAOs, particularly Decentralised Exchanges (DEXs), have recently expanded their market reach through cross-chain deployment and integration, giving rise to Cross-chain DAOs (XDAOs). These XDAOs face unique governance, deployment, and operations challenges, introducing added complexity and risks compared to traditional single-chain DAOs. While existing research has focused primarily on single-chain DAOs, we observe a shift in practice with DAOs to favour cross-chain deployments. The three largest protocols, Uniswap, Curve, and PancakeSwap, which together represent over half of the total value locked in DEXs, have been deployed across 22, 17, and 9 chains, respectively. This creates a research gap that our study addresses. In this study, we review 48 cross-chain deployments and numerous XDAO interactions, using data primarily from their respective discussion forums. Through thematic and root cause analysis, we identify eight requirements, deviations between DEXs, seven lessons learned for cross-chain deployment, and a framework to generalise the governance and deployment processes in XDAOs. As a result, we provide an improved classification of XDAO governance, highlighting limitations and future directions for cross-chain expansion. • A comprehensive study on cross-chain decentralised protocols and XDAO expansion. • Exploring and identifying diverse requirements of cross-chain deployments. • Exploring and inspecting various patterns of inconsistent enforcement. • Summary of lessons learned from the expansion of leading XDAOs. • Highlighting future research on XDAOs and cross-chain decentralised deployments.
Jakob Svennevik Notland, Jingyue Li, Mariusz Nowostawski
Blockchain Res. Appl.2
2025 Dynamic robustness evaluation for automated model selection in operation
abstract
Context: The increasing use of artificial neural network (ANN) classifiers in systems, especially safety-critical systems (SCSs), requires ensuring their robustness against out-of-distribution (OOD) shifts in operation, which are changes in the underlying data distribution from the data training the classifier. However, measuring the robustness of classifiers in operation with only unlabeled data is challenging. Additionally, machine learning engineers may need to compare different models or versions of the same model and switch to an optimal version based on their robustness. Objective: This paper explores the problem of dynamic robustness evaluation for automated model selection. We aim to find efficient and effective metrics for evaluating and comparing the robustness of multiple ANN classifiers using unlabeled operational data. Methods: To quantitatively measure the differences between the model outputs and assess robustness under OOD shifts using unlabeled data, we choose distance-based metrics. An empirical comparison of five such metrics, suitable for higher-dimensional data like images, is performed. The selected metrics include Wasserstein distance (WD), maximum mean discrepancy (MMD), Hellinger distance (HL), Kolmogorov–Smirnov statistic (KS), and Kullback–Leibler divergence (KL), known for their efficacy in quantifying distribution differences. We evaluate these metrics on 20 state-of-the-art models (ten CIFAR10-based models, five CIFAR100-based models, and five ImageNet-based models) from a widely used robustness benchmark ( RobustBench ) using data perturbed with various types and magnitudes of corruptions to mimic real-world OOD shifts. Results: Our findings reveal that the WD metric outperforms others when ranking multiple ANN models for CIFAR10- and CIFAR100-based models, while the KS metric demonstrates superior performance for ImageNet-based models. MMD can be used as a reliable second option for both datasets. Conclusion: This study highlights the effectiveness of distance-based metrics in ranking models’ robustness for automated model selection. It also emphasizes the significance of advancing research in dynamic robustness evaluation.
Jingyue Li, Zhirong Yang
Inf. Softw. Technol.2
2025 DRacv: Detecting and auto-repairing vulnerabilities in role-based access control in web application
Bing Zhang 0011, Jingyue Li, Haitao He, Rong Ren, Jiadong Ren
J. Netw. Comput. Appl.3
2025 Why Smart Contracts Reported as Vulnerable Were Not Exploited?
abstract
Smart contract security is crucial for blockchain applications. While studies suggest that only a small fraction of reported vulnerabilities are exploited, no follow-up research has investigated the reasons behind this. Our goal is to understand the factors contributing to the low exploitation rate to improve vulnerability detection and defense mechanisms. We collected 136,969 real-world smart contracts and analyzed them using seven vulnerability detectors. We applied Strauss’ grounded theory to gain insights into exploitability and analyzed transaction logs to trace the historic exploitations. Among the 4,364 smart contracts flagged as vulnerable, a significant 75.25% were found to be unexploitable, meaning they were either false positives or posed no security risk. We identified ten reasons for reporting unexploitable vulnerabilities. Furthermore, we found that only 66 out of 1,080 (6%) exploitable contracts had been exploited. We compared the characteristics of exploited versus non-exploited vulnerabilities and identified five factors that may reduce the likelihood of exploitation. Our findings highlight the importance of not treating smart contracts as conventional object-oriented (OO) applications. Researchers must account for the unique features of Solidity, smart contract design principles, and execution environments. Based on these insights, we propose six recommendations to improve smart contract vulnerability detection, prioritization, and mitigation.
Tianyuan Hu, Jingyue Li, Bixin Li, André Storhaug
IEEE Trans. Dependable Secur. Comput.2
2025 An Empirical Study on Governance in Bitcoin's Consensus Evolution
abstract
Consensus rule changes in public permissionless blockchains are challenging. Changes can be contentious, and getting all participants to agree could be tedious. Notably, Bitcoin has seen centralisation tendencies in mining and development. However, how these tendencies influence governance processes of consensus evolution has received minimal attention. We explore how the evolution of blockchain systems and the governance of consensus intertwine from socio-technical aspects. Our study analyses the governmental structures in blockchain by looking into Bitcoin. We investigate consensus change processes through grounded theory, comprising quantitative and qualitative data from 34 consensus forks in two different blockchains, Bitcoin Core and Bitcoin Cash. We explore how decentralisation and governance unfold in practice. In contrast to existing studies, we revealed that centralisation tendencies among miners and developers have no direct control over consensus rules in a blockchain. Furthermore, centralisation tendencies do not affect decision-making for consensus evolution governance in the same way as they facilitate consensus attacks, such as 51% attacks. We also discovered that consensus governance is constrained by the technicalities of change and deployment techniques. Consequently, even though miners have the authority to make consensus changes and propose new blocks, they are restricted by deployment techniques and dependence on user adoption.
Jakob Svennevik Notland, Mariusz Nowostawski, Jingyue Li
ACM Trans. Softw. Eng. Methodol.3
2025 Decision Support for Selecting Blockchain-Based Application Design Patterns With Layered Taxonomy and Quality Attributes
abstract
Background:Along with the rapid development and widespread adoption of blockchain technology, many common practices have been summarized into blockchain-based design patterns for application development. However, the numerous and scattered patterns may cause confusion among practitioners. Therefore, adopting appropriate patterns to meet various requirements has become a major challenge, as it requires deep development experience and blockchain technology knowledge.Objective:To address this problem, this paper proposes a decision-support solution to assist with the selection of design patterns during the blockchain-based application development, including a layered taxonomy of design patterns, mappings of quality attributes with the patterns, and a decision model incorporating the taxonomy and mappings.Method:We collected 72 distinct and state-of-the-art design patterns via a Systematic Literature Review (SLR) to establish a layered taxonomy, and 18 unified quality attribute metrics were proposed for blockchain-based pattern assessment and mapping establishment. Based on the pattern taxonomy and quality attribute mappings, we developed a decision model that can provide intuitive guidance for pattern selection.Results:The proposed solution was evaluated through a case study in a seafood supply chain, in which we examined how well the decision model could help identify design flaws and provide reasonable solutions. Additionally, interviews and a questionnaire-based survey were conducted to measure the completeness, correctness, and usefulness of the proposed decision model. The evaluation results indicate that the proposed decision-support solution provides developers with comprehensive guidance, facilitates targeted decision making, and supports intuitive understanding.Conclusions:Our decision-support solution can improve the development efficiency of blockchain-based applications, especially in addressing potential design flaws, achieving targeted quality attributes, and reducing development costs.
Jingyue Li, Shanshan Li 0002, He Zhang 0001, Chenxing Zhong, Bohan Liu 0003, Yue Liu 0010, Qinghua Lu 0001, Xin Zhou 0016
IEEE Trans. Software Eng.3
2024 A survey of deep learning-driven architecture for predictive maintenance
abstract
Over the past decades, deep learning techniques have attracted increased attention from various research and industrial domains aligned with the development of Industry Internet-of-Things(IIoT). Specifically, with the advantage of data-driven methods, industrial organizations are seeking novel proactive strategies supported by analytic models to guarantee the quality of their production by observing degradation or predicting failure ahead of the occurrence of the component or asset. Predictive strategies are expected to promise the influence of unnecessary maintenance interruptions and mitigate the consequence of that, hence, extending the remaining useful life of products. This paper conducts a survey of the utilization of deep learning technologies on engineering applications where they provide satisfactory solutions with respect to specific data types or input signals. 106 primary papers are reviewed on deep learning–driven approaches which mainly explore five of the most popular architectures in the application of predictive maintenance. The main content of this paper summarizes the common advantages of each architecture and, accordingly, points out their limitations, as well as describes the application scopes of fully connected deep neural networks, convolutional neural networks, stacked autoencoders, deep belief networks, and deep recurrent neural networks. Based on the technique discussion for each of them, we intend to provide a comprehensive understanding and guidance of the appropriate usage of deep learning architectures to devise an effective predictive maintenance strategy for the scientific and industrial developers whose expertise lies in the prior domain knowledge of multi-source isomerization data. Moreover, the main content demonstrated the summarization of the decisive factor by which the incremental stages of the approaches were determined, fundamentally including the dataset specification, feature extraction, and the integration of deep learning approaches.
Jingyue Li
Eng. Appl. Artif. Intell.3
2024 A comprehensive analysis of challenges and strategies for software release notes on GitHub
Hao He 0012, Kai Gao 0008, Wenxin Xiao, Jingyue Li, Minghui Zhou 0001
Empir. Softw. Eng.5
2024 SoliTester: Detecting exploitable external-risky vulnerability in smart contracts using contract account triggering method
abstract
Abstract The vulnerability in smart contracts (SCs) on the blockchain system may lead to severe security compromises. The SC can be invoked from an externally owned account (EOA) or a contract account (CA). The account a user creates to receive or send ether is an EOA. A CA contains codes that can interact with SCs. In Solidity SC, some vulnerabilities can only be exploited by the interactions between CAs and vulnerable SCs, which can be named external‐risky vulnerabilities. Most state‐of‐the‐art (SOTA) detectors detect external‐risky vulnerabilities by executing contract codes as an EOA user, thus reporting many unexploitable vulnerabilities. Therefore, we propose a CA‐triggering method to identify exploitable external‐risky vulnerabilities in Solidity SCs. We first designed agent contracts to simulate CAs' interactions with the target SCs in the real blockchain environment. We then detect vulnerability exploitation by analyzing transaction logs between agent contracts and target SCs and identifying successful exploits. We implemented the CA‐triggering method in a tool named SoliTester and evaluated it using three benchmark datasets, which contain three types of external‐risky vulnerabilities, namely, Reentancy (RE), Unchecked Call (UcC), and TxOrigin (TO). The results show that SoliTester can efficiently detect exploitable external‐risky vulnerabilities with significantly better precisions and recalls than SOTA detectors.
Tianyuan Hu, Jingyue Li, Xiangfei Xu, Bixin Li
J. Softw. Evol. Process.2
2024 SQLPsdem: A Proxy-Based Mechanism Towards Detecting, Locating and Preventing Second-Order SQL Injections
abstract
Due to well-hidden and stage-triggered properties of second-order SQL injections in web applications, current approaches are ineffective in addressing them and still report high false negatives and false positives. To reduce false results, we propose a Proxy-based static analysis and dynamic execution mechanism towards detecting, locating and preventing second-order SQL injections (SQLPsdem). The static analysis first locates SQL statements in web applications and identifies all data sources and injection points (e.g., Post, Sessions, Database, File names) that injection attacks can exploit. After that, we reconstruct the SQL statements and use attack engines to jointly generate attacks to cover all the state-of-the-art attack patterns so as to exploit these applications. We then use proxy-based dynamic execution to capture the data transmitted between web applications and their databases. The data are the reconstructed SQL statements with variable values from the attack payloads. If a web application is vulnerable, the data will contain malicious attacks on the database. We match the data with rules formulated by attack patterns to detect first and second-order SQL injection vulnerabilities in web applications, particularly the second-order ones. We use a representative and complete coverage of attack patterns and precise matching rules to reduce false results. By escaping and truncating malicious payloads in the data transmitted from the web application to the database, we can eliminate the possible negative impact of the data on the database. In the evaluation, by generating 52,771 SQL injection attacks using four attack generators, SQLPsdem successfully detects 26 second-order (including 13 newly discovered ones) and 375 first-order SQL injection vulnerabilities in 12 open-source web applications. SQLPsdem can also 100% eliminate the malicious impact of the data with negligible overhead.
Bing Zhang 0011, Rong Ren, Mingcai Jiang, Jiadong Ren, Jingyue Li
IEEE Trans. Software Eng.6
2023 Perceived Trust in Blockchain Systems: An Interview-based Survey
abstract
Blockchain systems have received increased interest over the past few years, and several new fields of use, such as supply chain systems, are being investigated. Since blockchain is still a new technology, various papers have explored how to apply it to support use cases outside the limited scope of digital currencies. Systems require solid technological implementation and perceived trust among users to ensure their interests and successful usage in practice. This study aimed to understand what graphic user interface (GUI) elements of a blockchain-based system make users trust that their best interests, such as security and privacy, are maintained in the systems. As a case study, we developed a few blockchain-based supply chain GUI mockups with different elements that reflect the security and privacy features of the system. We then conducted 30 interviews in Norway and China to collect the users’ opinions on whether the information presented in the GUIs helps them trust the system. The results show that users want access to as much information and data as the system can provide. The users’ trust in the system increases if the GUI features give users the impression that the inner workings of the blockchain-based system are transparent. However, users prefer the information presented as more conceptual than technical in the first place. However, users appreciate the possibility of clicking on the conceptual explanation and getting more in-depth blockchain-related technical information if needed.
Huikun Liu, Zhaowei Jiang, He Zhang 0001, Jingyue Li, Sigurd Eileras, Haakon Pelsholen Busterud
EASE5
2023 A Systematic Literature Review on Client Selection in Federated Learning
abstract
With the arising concerns of privacy within machine learning, federated learning (FL) was invented in 2017, in which the clients, such as mobile devices, train a model and send the update to the centralized server. Choosing clients randomly for FL can harm learning performance due to different reasons. Many studies have proposed approaches to address the challenges of client selection of FL. However, no systematic literature review (SLR) on this topic existed. This SLR investigates the state of the art of client selection in FL and answers the challenges, solutions, and metrics to evaluate the solutions. We systematically reviewed 47 primary studies. The main challenges found in client selection are heterogeneity, resource allocation, communication costs, and fairness. The client selection schemes aim to improve the original random selection algorithm by focusing on one or several of the aforementioned challenges. The most common metric used is testing accuracy versus communication rounds, as testing accuracy measures the successfulness of the learning and preferably in as few communication rounds as possible, as they are very expensive. Although several possible improvements can be made with the current state of client selection, the most beneficial ones are evaluating the impact of unsuccessful clients and gaining a more theoretical understanding of the impact of fairness in FL.
Carl Smestad, Jingyue Li
EASE2
2023 Evaluating the Impact of ChatGPT on Exercises of a Software Security Course
abstract
Along with the development of large language models (LLMs), e.g., ChatGPT, many existing approaches and tools for software security are changing. It is, therefore, essential to understand how security-aware these models are and how these models impact software security practices and education. In exercises of a software security course at our university, we ask students to identify and fix vulnerabilities we insert in a web application using state-of-the-art tools. After ChatGPT, especially the GPT-4 version of the model, we want to know how the students can possibly use ChatGPT to complete the exercise tasks. We input the vulnerable code to ChatGPT and measure its accuracy in vulnerability identification and fixing. In addition, we investigated whether ChatGPT can provide a proper source of information to support its outputs. Results show that ChatGPT can identify 20 of the 28 vulnerabilities we inserted in the web application in a white-box setting, reported three false positives, and found four extra vulnerabilities beyond the ones we inserted. ChatGPT makes nine satisfactory penetration testing and fixing recommendations for the ten vulnerabilities we want students to fix and can often point to related sources of information.
Jingyue Li, Per Håkon Meland, Jakob Svennevik Notland, André Storhaug, Jostein Hjortland Tysse
ESEM1
2023 Efficient Avoidance of Vulnerabilities in Auto-completed Smart Contract Code Using Vulnerability-constrained Decoding
abstract
Auto-completing code enables developers to speed up coding significantly. Recent advances in transformer-based large language model (LLM) technologies have been applied to code synthesis. However, studies show that many of such synthesized codes contain vulnerabilities. We propose a novel vulnerability-constrained decoding approach to reduce the amount of vulnerable code generated by such models. Using a small dataset of labeled vulnerable lines of code, we fine-tune an LLM to include vulnerability labels when generating code, acting as an embedded classifier. Then, during decoding, we deny the model to generate these labels to avoid generating vulnerable code. To evaluate the method, we chose to automatically complete Ethereum Blockchain smart contracts (SCs) as the case study due to the strict requirements of SC security. We first fine-tuned the 6-billion-parameter GPT-J model using 186,397 Ethereum SCs after removing the duplication from 2,217,692 SCs. The fine-tuning took more than one week using ten GPUs. The results showed that our fine-tuned model could synthesize SCs with an average BLEU (BiLingual Evaluation Understudy) score of 0.557. However, many codes in the auto-completed SCs were vulnerable. Using the code before the vulnerable line of 176 SCs containing different types of vulnerabilities to auto-complete the code, we found that more than 70% of the auto-completed codes were insecure. Thus, we further fine-tuned the model on other 941 vulnerable SCs containing the same types of vulnerabilities and applied vulnerability-constrained decoding. The fine-tuning took only one hour with four GPUs. We then auto-completed the 176 SCs again and found that our approach could identify 62% of the code to be generated as vulnerable and avoid generating 67% of them, indicating the approach could efficiently and effectively avoid vulnerabilities in the auto-completed code.
André Storhaug, Jingyue Li, Tianyuan Hu
ISSRE2
2023 Personalized First Issue Recommender for Newcomers in Open Source Projects
abstract
Many open source projects provide good first issues (GFIs) to attract and retain newcomers. Although several automated GFI recommenders have been proposed, existing recommenders are limited to recommending generic GFIs without considering differences between individual newcomers. However, we observe mismatches between generic GFIs and the diverse background of newcomers, resulting in failed attempts, discouraged onboarding, and delayed issue resolution. To address this problem, we assume that personalized first issues (PFIs) for newcomers could help reduce the mismatches. To justify the assumption, we empirically analyze 37 newcomers and their first issues resolved across multiple projects. We find that the first issues resolved by the same newcomer share similarities in task type, programming language, and project domain. These findings underscore the need for a PFI recommender to improve over state-of-the-art approaches. For that purpose, we identify features that influence newcomers' personalized selection of first issues by analyzing the relationship between possible features of the newcomers and the characteristics of the newcomers' chosen first issues. We find that the expertise preference, OSS experience, activeness, and sentiment of newcomers drive their personalized choice of the first issues. Based on these findings, we propose a Personalized First Issue Recommender (PFIRec), which employs LamdaMART to rank candidate issues for a given newcomer by leveraging the identified influential features. We evaluate PFIRec using a dataset of 68,858 issues from 100 GitHub projects. The evaluation results show that PFIRec outperforms existing first issue recommenders, potentially doubling the probability that the top recommended issue is suitable for a specific newcomer and reducing one-third of a newcomer's unsuccessful attempts to identify suitable first issues, in the median. We provide a replication package at https://zenodo.org/record/7915841.
Wenxin Xiao, Jingyue Li, Hao He 0012, Ruiqiao Qiu, Minghui Zhou 0001
ASE2
2023 Characterize Software Release Notes of GitHub Projects: Structure, Writing Style, and Content
abstract
Release notes (RNs) summarize important changes between two successive software releases to facilitate software upgrades and serve as means of communication between software and its users. However, existing research has shown that many users cannot extract the information they want from RNs effectively and efficiently due to poor structure and insufficient content. Many efforts have been devoted to categorizing documented information in RNs, however, how exactly RNs are organized, in what way RNs are written, and what is written in RNs with respect to project domains and release types remain under investigation. To bridge this knowledge gap, we manually analyzed 612 RNs from 233 top popular GitHub projects to characterize their Structure, Writing Style, and Content. We find 64.54% of RNs organize changes into hierarchical structures following three strategies, i.e., by Change Type, Affected Module, or Change Priority. And 11.60% of RNs adopt multiple strategies to present the changes. Among the three strategies to organize changes, by Change Type is mostly adopted. RNs of major releases and System Software are more likely to organize changes by Affected Module. We also find three types of Writing Styles: Expository, Descriptive, and Persuasive with increasing explanation information and manual effort, taking 30.07%, 34.80%, and 35.13% of RNs, respectively. 83.10% of RNs in System Software projects adopt the Descriptive and Persuasive writing style. For Content, we find System Software and Libraries & Frameworks projects are more likely to record Breaking Changes, while Software Tools projects emphasize Enhancements. Besides, Fixed Bugs and Security Changes are less common in RNs of major releases. Our findings not only serve practitioners with a roadmap for customizing high-quality RNs but also shed light on future research on automating RN.
Weiwei Xu 0001, Kai Gao 0008, Jingyue Li, Minghui Zhou 0001
SANER4
2023 Revisit security in the era of DevOps: An evidence-based inquiry into DevSecOps industry
abstract
Abstract By adopting agile and lean practices, DevOps aims to achieve rapid value delivery by speeding up development and deployment cycles, which however lead to more security concerns that cannot be fully addressed by an isolated security role only in the final stage of development. DevSecOps promotes security as a shared responsibility integrated into the DevOps process that seamlessly intertwines development, operations, and security from the start throughout to the end of cycles. While some companies have already begun to embrace this new strategy, both industry and academia are still seeking a common understanding of the DevSecOps movement. The goal of this study is to report the state‐of‐the‐practice of DevSecOps, including the impact of DevOps on security, practitioners' understanding of DevSecOps, and the practices associated with DevSecOps as well as the challenges of implementing DevSecOps. The authors used a mixed‐methods approach for this research. The authors carried out a grey literature review on DevSecOps, and surveyed the practitioners of DevSecOps in industry of China. The status quo of DevSecOps in industry is summarized. Three major software security risks are identified with DevOps, where the establishment of DevOps pipeline provides opportunities for security‐related activities. The authors classify the interpretations of DevSecOps into three core aspects of DevSecOps capabilities, cultural enablers, and technological enablers. To materialise the interpretations into daily software production activities, the recommended DevSecOps practices from three perspectives—people, process, and technology. Although a preliminary consensus is that DevSecOps is regarded as an extension of DevOps, there is a debate on whether DevSecOps is a superfluous term. While DevSecOps is attracting an increasing attention by industry, it is still in its infancy and more effort needs to be invested to promote it in both research and industry communities.
Xin Zhou 0016, Runfeng Mao, He Zhang 0001, Qiming Dai, Haifeng Shen, Jingyue Li, Guoping Rong
IET Softw.7
2023 AST-SafeSec: Adaptive Stress Testing for Safety and Security Co-Analysis of Cyber-Physical Systems
abstract
Cyber-physical systems are becoming more intelligent with the adoption of heterogeneous sensor networks and machine learning capabilities that deal with an increasing amount of input data. While this complexity aims to solve problems in various domains, it adds new challenges for the system assurance. One issue is the rise in the number of abnormal behaviors that affect system performance due to possible sensor faults and attacks. The combination of safety risks, which are usually caused by random sensor faults and security risks that can happen during any random system state, makes the full coverage testing of the cyber-physical system challenging. Existing techniques are inadequate to deal with complex safety and security co-risks against cyber-physical systems. In this paper, we propose AST-SafeSec, an analysis methodology for both safety and security aspects that utilizes reinforcement learning to identify the most likely adversarial paths at various normal or failure states of a cyber-physical system that can influence system behavior through its sensor data. The methodology is evaluated using an autonomous vehicle scenario by incorporating a security attack into the stochastic sensor elements of a vehicle. Evaluation results show that the methodology analyzes the interaction of malicious attacks with random faults and identifies the incident caused by the interactions and the most likely path that leads to the incident.
Nektaria Kaloudi, Jingyue Li
IEEE Trans. Inf. Forensics Secur.2
2023 Runtime Evolution of Bitcoin's Consensus Rules
abstract
The runtime evolution of a system concerns the ability to make changes during runtime without disrupting the service. Blockchain systems need to provide continuous service and integrity. Similar challenges have been observed in centrally controlled distributed systems or mobile applications that handle runtime evolution, mainly by supporting compatible changes or running different versions concurrently. However, these solutions are not applicable in the case of blockchains, and thus, new solutions are required. This study investigates Bitcoin consensus evolution by analysing over a decade of data from Bitcoin's development channels using Strauss’ grounded theory approach and root cause analysis. The results show nine deployment features which form nine deployment techniques and ten lessons learned. Our results illustrate how different deployment techniques fit different contexts and pose different levels of consensus failure risks. Furthermore, we provide guidelines for risk minimisation during consensus rule deployment for blockchain in general and Bitcoin in particular.
Jakob Svennevik Notland, Mariusz Nowostawski, Jingyue Li
IEEE Trans. Software Eng.3
2022 Security and Privacy Challenges in Blockchain Interoperability - A Multivocal Literature Review
abstract
Transferring data and value across different blockchains is one of the biggest obstacles to further expansion. Blockchain interoperability allows different networks to communicate and transfer data between them and are increasingly crucial for blockchain applications. However, the concern about security and privacy in blockchain interoperability arises naturally. This work aims to provide the state-of-the-art related to security and privacy challenges in blockchain interoperability. We conducted a multivocal literature review (MLR) and analyzed 16 scientific and 30 grey literature, respectively. We examined different security and privacy challenges related to both blockchain in general and blockchain interoperability approaches such as Notary Schemes, Sidechains and Hashed Time-Lock Contracts. Possible mitigations are analysed, and open challenges that arose from the mitigations are highlighted.
Terje Haugum, Bjørnar Hoff, Jingyue Li
EASE4
2022 A Vulnerability Detection Framework for Hyperledger Fabric Smart Contracts Based on Dynamic and Static Analysis
abstract
Hyperledger Fabric is another development of blockchain technology after Ethereum, which is more suitable as an operating platform for smart contracts. However, the testing technology of Hyperledger Fabric smart contracts (also known as chaincode) is not yet mature currently. Based on this, this paper studies the vulnerability detection of Golang chaincodes. Firstly, we summarize 17 kinds of Golang chaincode vulnerabilities by investigating existing research. Secondly, taking the high accuracy of dynamic detection and the high efficiency of static detection into consideration, we propose a chaincode vulnerability detection framework that combines the dynamic symbolic execution and the static abstract syntax tree analysis technology. We also implement a supporting-tool that can detect the above 15 types of vulnerabilities. Finally, we test the tool by 15 chaincodes collected from GitHub and unknown vulnerabilities were detected in 13 projects. The precision turned out to be 91% after manual inspection. In order to verify the recall rate, we manually inject 30 vulnerabilities into the collected chaincodes and all of them are detected. The evaluation results show the accuracy of the proposed vulnerability detection method for Hyperledger Fabric smart contracts.
Peiru Li, Shanshan Li 0002, Mengjie Ding, Jiapeng Yu, He Zhang 0001, Xin Zhou 0016, Jingyue Li
EASE7
2022 Geolocation estimation of target vehicles using image processing and geometric computation
abstract
Estimating vehicles’ locations is one of the key components in intelligent traffic management systems (ITMSs) for increasing traffic scene awareness. Traditionally, stationary sensors have been employed in this regard. The development of advanced sensing and communication technologies on modern vehicles (MVs) makes it feasible to use such vehicles as mobile sensors to estimate the traffic data of observed vehicles. This study aims to explore the capabilities of a monocular camera mounted on an MV in order to estimate the geolocation of the observed vehicle in a global positioning system (GPS) coordinate system. We proposed a new methodology by integrating deep learning, image processing, and geometric computation to address the observed-vehicle localization problem. To evaluate our proposed methodology, we developed new algorithms and tested them using real-world traffic data. The results indicated that our proposed methodology and algorithms could effectively estimate the observed vehicle’s latitude and longitude dynamically.
Elnaz Namazi, Rudolf Mester, Chaoru Lu, Jingyue Li
Neurocomputing4
2022 Special section on IST for EASE2021
Anh Nguyen-Duc 0001, Barbara Weber, Jingyue Li
Inf. Softw. Technol.4
2021 Critical Understanding of Security Vulnerability Detection Plugin Evaluation Reports
abstract
Integrated development environment (IDE) plugins aimed at detecting web application security vulnerabilities can help developers create secure applications in the first place. Most of such IDE plugins use static source code analysis approaches. Although several empirical studies evaluated the plugins and compared their precision and recall of detecting web application security, few follow-up studies tried to understand the evaluation results. We analyzed more than 20,000 vulnerability reports based on 7,215 distinct test cases spanning 11 categories of web application vulnerabilities to understand the evaluation results of three open-source IDE plugins, namely, SpotBugs, FindSecBugs, and Early Security Vulnerability Detector (ESVD), which aimed at detecting security vulnerabilities of Java-based web applications. Our results identify many factors besides the source code analysis approach that can dramatically bias the detection performance. Based on our insights, we improved the studied plugins. In addition, our study raises the alarm that, without solid root cause analyses, the evaluation and comparisons of security vulnerability detection approaches and tools could be misleading. Thus, we proposed a guideline on reporting the evaluation results of the security vulnerability detection approaches.
Sindre Beba, Magnus Melseth Karlsen, Jingyue Li, Bing Zhang 0011
APSEC3
2021 Agile Enterprise Architecture by Leveraging Use Cases
abstract
Despite benefits Enterprise Architecture (EA) has brought, EA has also been challenged due to its complexity, heavy workload demands, and poor user acceptance. Researchers and practitioners proposed to use EA in an agile and "business outcome-driven" way. This means that EA should not primarily be developed and used according to a pre-defined framework. Instead, EA should be developed and used for specific business purposes and by means of concrete deliverables. By doing so, a more effective and efficient way of EA application could be enabled. However, there is no common agreement on what types of business goals can be expected to be achieved by using EA (The What) and how to achieve these goals through EA solutions (The How). To address these issues, we analysed the information provided by leading EA tool vendors available on their websites to get inspiration. The results showed that Use Cases (UCs) are used generally to motivate potential EA users by focusing on specific business issues. Then, EA solutions to address such business requirements or challenges are scoped and derived accordingly. We expect relevant findings could bring inspiration to agile EA engineering, change the EA “heavy-weight” reputation, and improve the application of EA even among its sceptics.
Hong Guo 0004, Jingyue Li, Shang Gao 0002, Darja Smite
ENASE2
2020 What Norwegian Developers Want and Need From Security-Directed Program Analysis Tools: A Survey
abstract
Code enforcing access control policies often has high inherent complexity, making it challenging to test using only classical review and testing techniques. To more thoroughly test such code, it is strategic to also use program analysis tools, which often can find subtle, critical bugs going unnoticed to humans. These powerful tools are however rarely used in software consultancy practice, due to factors such as bad usability or unsatisfactory non-functional characteristics. To encourage wider adoption of such tools, more must be learned about how to design them to the preferences of software consultants. Towards this goal, we conducted a survey of Norwegian software consultants. Among our findings is a positive relation between preference for soundness over completeness in tools and preference for annotation-based over automated tools. 51% of the developers surveyed prefer soundness over completeness when detecting access control vulnerabilities, while only 37.5% view completeness as the more important characteristic. Qualitative responses illuminate concerns regarding usability, soundness, completeness, and performance.
Elias Brattli Sørensen, Edvard Kristoffer Karlsen, Jingyue Li
EASE3
2020 Testing and verification of neural-network-based safety-critical control software: A systematic literature review
abstract
Context: Neural Network (NN) algorithms have been successfully adopted in a number of Safety-Critical Cyber-Physical Systems (SCCPSs). Testing and Verification (T&V) of NN-based control software in safety-critical domains are gaining interest and attention from both software engineering and safety engineering researchers and practitioners. Objective: With the increase in studies on the T&V of NN-based control software in safety-critical domains, it is important to systematically review the state-of-the-art T&V methodologies, to classify approaches and tools that are invented, and to identify challenges and gaps for future studies. Method: By searching the six most relevant digital libraries, we retrieved 950 papers on the T&V of NN-based Safety-Critical Control Software (SCCS). Then we filtered the papers based on the predefined inclusion and exclusion criteria and applied snowballing to identify new relevant papers. Results: To reach our result, we selected 83 primary papers published between 2011 and 2018, applied the thematic analysis approach for analyzing the data extracted from the selected papers, presented the classification of approaches, and identified challenges. Conclusion: The approaches were categorized into five high-order themes, namely, assuring robustness of NNs, improving the failure resilience of NNs, measuring and ensuring test completeness, assuring safety properties of NN-based control software, and improving the interpretability of NNs. From the industry perspective, improving the interpretability of NNs is a crucial need in safety-critical applications. We also investigated nine safety integrity properties within four major safety lifecycle phases to investigate the achievement level of T&V goals in IEC 61508-3. Results show that correctness, completeness, freedom from intrinsic faults, and fault tolerance have drawn most attention from the research community. However, little effort has been invested in achieving repeatability, and no reviewed study focused on precisely defined testing configuration or defense against common cause failure.
Jingyue Li
Inf. Softw. Technol.2
2019 Evaluation of Open-Source IDE Plugins for Detecting Security Vulnerabilities
abstract
Securing information systems has become a high priority as our reliance on them increases. Global multi-billion dollar companies have their critical information regularly exposed, costing them money and impairing their users' privacy. To defend against security breaches, IDE-integrated plugins to detect and remove security vulnerabilities in the first place are being used more frequently. More information about these plugins is needed in order to improve the state of the art within the field. Five open-source IDE plugins which can identify and report vulnerabilities are evaluated. We evaluate and compare how many categories of vulnerabilities the plugins can detect, how well the plugins detect the vulnerabilities, and how user-friendly the output of the plugin is to the developers. Our results show that certain vulnerabilities such as injection and broken access control are vastly covered by most plugins, while others have been completely ignored. A discrepancy between the claimed and actually confirmed coverage of the plugins is discovered, underlining the importance of this research. High false positive rate and obvious limitations in usability show that more work is needed before these plugins can be widely used and relied upon in a corporate setting.
Jingyue Li, Sindre Beba, Magnus Melseth Karlsen
EASE1
2019 An experimental evaluation of bow-tie analysis for security
abstract
Purpose Within critical-infrastructure industries, bow-tie analysis is an established way of eliciting requirements for safety and reliability concerns. Because of the ever-increasing digitalisation and coupling between the cyber and physical world, security has become an additional concern in these industries. The purpose of this paper is to evaluate how well bow-tie analysis performs in the context of security, and the study’s hypothesis is that the bow-tie notation has a suitable expressiveness for security and safety. Design/methodology/approach This study uses a formal, controlled quasi-experiment on two sample populations – security experts and security graduate students – working on the same case. As a basis for comparison, the authors used a similar experiment with misuse case analysis, a well-known technique for graphical security modelling. Findings The results show that the collective group of graduate students, inexperienced in security modelling, perform similarly as security experts in a well-defined scope and familiar target system/situation. The students showed great creativity, covering most of the same threats and consequences as the experts identified and discovering additional ones. One notable difference was that these naïve professionals tend to focus on preventive barriers, leading to requirements for risk mitigation or avoidance, while experienced professionals seem to balance this more with reactive barriers and requirements for incident management. Originality/value Our results are useful in areas where we need to evaluate safety and security concerns together, especially for domains that have experience in health, safety and environmental hazards, but now need to expand this with cybersecurity as well.
Per Håkon Meland, Karin Bernsmed, Christian Frøystad, Jingyue Li, Guttorm Sindre
Inf. Comput. Secur.4
2019 Tracking runtime concurrent dependences in java threads using thread control profiling
Lulu Wang 0001, Jingyue Li, Bixin Li
J. Syst. Softw.2
2019 Erratum to "Tracking runtime concurrent dependences in java threads using thread control profiling" [The Journal of Systems and Software 148 (2019) 116-131]
Lulu Wang 0001, Jingyue Li, Bixin Li
J. Syst. Softw.2
2017 A Novel Tool for Automatic GUI Layout Testing
abstract
As mobile apps are expected to run in many different screen sizes, the need to validate the correct positioning and rendering of graphical user interface (GUI) elements in such screens is increasing. In this paper, we first focus on identifying typical layout errors in modern GUIs and categorising them. Then, we implement a tool called Layout Bug Hunter (LBH) to automatically identify if a GUI layout is rendered correctly in different screen sizes. The tool is evaluated on mobile apps and is compared to state-of-the-art layout-testing tools. Results show that LBH can identify all the typical layout errors we categorise, and LBH is more accurate than a layout-testing tool based on image diffing algorithms. In addition, LBH does not require writing layout test scripts manually. LBH is currently implemented on only one mobile app development platform, but it is designed to be portable and extensible. With only limited effort, LBH can be extended to other mobile and web development platforms for layout testing.
Kristian Fjeld Hasselknippe, Jingyue Li
APSEC2
2012 CBCD: Cloned buggy code detector
abstract
Developers often copy, or clone, code in order to reuse or modify functionality. When they do so, they also clone any bugs in the original code. Or, different developers may independently make the same mistake. As one example of a bug, multiple products in a product line may use a component in a similar wrong way. This paper makes two contributions. First, it presents an empirical study of cloned buggy code. In a large industrial product line, about 4% of the bugs are duplicated across more than one product or file. In three open source projects (the Linux kernel, the Git version control system, and the PostgreSQL database) we found 282, 33, and 33 duplicated bugs, respectively. Second, this paper presents a tool, CBCD, that searches for code that is semantically identical to given buggy code. CBCD tests graph isomorphism over the Program Dependency Graph (PDG) representation and uses four optimizations. We evaluated CBCD by searching for known clones of buggy code segments in the three projects and compared the results with text-based, token-based, and AST-based code clone detectors, namely Simian, CCFinder, Deckard, and CloneDR. The evaluation shows that CBCD is fast when searching for possible clones of the buggy code in a large system, and it is more precise for this purpose than the other code clone detectors.
Jingyue Li, Michael D. Ernst
ICSE1
2011 Selection of third party software in Off-The-Shelf-based software development - An interview study with industrial practitioners
Claudia P. Ayala, Øyvind Hauge, Reidar Conradi, Xavier Franch, Jingyue Li
J. Syst. Softw.5
2010 Transition from a plan-driven process to Scrum: a longitudinal case study on software quality
abstract
Although Scrum is an important topic in software engineering and information systems, few longitudinal industrial studies have investigated the effects of Scrum on software quality, in terms of defects and defect density, and the quality assurance process. In this paper we report on a longitudinal study in which we have followed a project over a three-year period. We compared software quality assurance processes and software defects of the project between a 17-month phase with a plan-driven process, followed by a 20-month phase with Scrum. The results of the study did not show a significant reduction of defect densities or changes of defect profiles after Scrum was used. However, the iterative nature of Scrum resulted in constant system and acceptance testing and related defect fixing, which made the development process more efficient in terms of fewer surprises and better control of software quality and release date. In addition, software quality and knowledge sharing got more focus when using Scrum. However, Scrum put more stress and time pressure on the developers, and made them reluctant to perform certain tasks for later maintenance, such as refactoring.
Jingyue Li, Nils Brede Moe, Tore Dybå
ESEM1
2010 Cost drivers of software corrective maintenance: An empirical study in two companies
abstract
To estimate the corrective software maintenance effort, we must know the factors that have the strongest influence on corrective maintenance activities. In this study, we have analyzed activities and effort of correcting 810 software defects in one Norwegian software company and 577 software defects in another. We compared the defect profiles according to the defect correction effort. We also analyzed defect descriptions and recorded discussions between developers in the course of correcting defects in order to understand what led to the high cost of correcting some types of defects. The study shows that size and complexity of the software to be maintained, maintainers?' experience, and tool and process support are the most influential cost drivers of corrective maintenance in one company, while domain knowledge is one of the main cost drivers of corrective maintenance in the other company. This illustrates that models for estimating software corrective maintenance effort have to be customized based on the defect profiles and cost drivers of each company and project to be useful.
Jingyue Li, Tor Stålhane, Jan M. W. Kristiansen, Reidar Conradi
ICSM1
2010 Change profiles of a reused class framework vs. two of its applications
Anita Gupta, Jingyue Li, Reidar Conradi, Harald Rønneberg, Einar Landre
Inf. Softw. Technol.2
2009 A case study comparing defect profiles of a reused framework and of applications reusing it
Anita Gupta, Jingyue Li, Reidar Conradi, Harald Rønneberg, Einar Landre
Empir. Softw. Eng.2
2008 Some lessons learned in conducting software engineering surveys in china
abstract
Component-Based Software Engineering (CBSE) with Open Source Software and Commercial-Off-the-Shelf (COTS) components, Open Source Software (OSS) based development, and Software Outsourcing (SO) are becoming increasingly important for the Chinese software industry. It is therefore necessary to establish pragmatic and possibly nation-specific guidelines for Chinese software companies regarding the use of CBSE, OSS, and SO. Such guidelines should be based on insights from actual practice, which are in our case, obtained through surveys. A European state-of-the-practice survey on COTS- and OSS-oriented CBSE was conducted in Germany, Italy, and Norway in 2004-2005. We repeated similar surveys in China, with an extended survey on OSS and SO. We encountered many difficulties in conducting the surveys, but in most cases managed to find working solutions. We report on the lessons learned while conducting these surveys. In particular, we address issues relating to sampling, contacting respondents, data collection, and data validation. The main lessons are: 1) it was necessary to cooperate with a third-party organization with close relations to Chinese software companies; 2) it was necessary to assign researchers to this third-party organization to facilitate data collection and to control the quality of the data collected; and 3) an email survey, after an initial telephone call to establish contact, was the best method for getting questionnaires completed by Chinese respondents.
Junzhong Ji, Jingyue Li, Reidar Conradi, Chunnian Liu, Jianqiang Ma, Weibing Chen
ESEM2
2008 The Impact of Test Driven Development on the Evolution of a Reusable Framework of Components - An Industrial Case Study
abstract
Test driven development (TDD) is a software engineering technique to promote fast feedback, task-oriented development, improved quality assurance and more comprehensible low-level software design. Benefits have been shown for non-reusable software development in terms of improved quality (e.g. lower defect density). We have carried out an empirical study of a framework of reusable components, to see whether these benefits can be shown for reusable components. The framework is used in building new applications and provides services to these applications during runtime. The three first versions of this framework were developed using traditional test-last development, while for the two latest versions TDD was used. Our results show benefits in terms of reduced mean defect density (35.86%), when using TDD, over two releases. Mean change density was 76.19% lower for TDD than for test-last development. Finally, the change distribution for the TDD approach was 33.3% perfective, 5.6% adaptive and 61.1% preventive.
Odd Petter N. Slyngstad, Jingyue Li, Reidar Conradi, Harald Rønneberg, Einar Landre, Harald Wesenberg
ICSEA2
2008 Identifying and Understanding Architectural Risks in Software Evolution: An Empirical Study
Odd Petter N. Slyngstad, Jingyue Li, Reidar Conradi, Muhammad Ali Babar 0001
PROFES2
2008 A State-of-the-Practice Survey of Risk Management in Development with Off-the-Shelf Software Components
abstract
An international survey on risk management in software development with off-the-shelf (OTS) components is reported upon and discussed. The survey investigated actual risk-management activities and their correlations with the occurrences of typical risks in OTS component-based development. Data from 133 software projects in Norway, Italy, and Germany were collected using a stratified random sample of IT companies. The results show that OTS components normally do not contribute negatively to the quality of the software system as a whole, as is commonly expected. However, issues such as the underestimation of integration effort and inefficient debugging remain problematic and require further investigation. The results also illustrate several promising effective risk-reduction activities, e.g., putting more effort into learning relevant OTS components, integrating unfamiliar components first, thoroughly evaluating the quality of candidate OTS components, and regularly monitoring the support capability of OTS providers. Five hypotheses are proposed regarding these risk-reduction activities. The results also indicate that several other factors, such as project, cultural, and human-social factors, have to be investigated to thoroughly deal with the possible risks of OTS-based projects.
Jingyue Li, Reidar Conradi, Odd Petter N. Slyngstad, Marco Torchiano, Maurizio Morisio, Christian Bunse
IEEE Trans. Software Eng.1
2007 A Survey on the Business Relationship between Chinese Outsourcing Software Suppliers and Their Outsourcers
abstract
The business relationship between a software outsourcer and its suppliers is gradually moving from contract relationship to partnership. The partnership type between the outsourcer and the supplier is considered as a key predictor of outsourcing success. Although several studies have investigated the practices and benefits of building partnership from an outsourcer's perspective, few of them have studied these issues from the supplier's viewpoint, especially in the context of offshore software outsourcing. Since more and more Chinese software companies are getting outsourcing subcontracts from abroad, it is important to investigate the effect of business relationship on their performance, and to identify possible enhancements. Our study has collected data by a questionnaire-based survey from 53 finished projects in 41 Chinese software suppliers. Twenty-six of our investigated suppliers claim to have contract relationship with their outsourcers and the remaining 27 think they have partnership with outsourcers. Results from our study show, however, that 1) processes and methods used by suppliers to solve conflicts with outsourcers do not follow their self-claimed contract relationships or partnership; 2) there is no significant correlations between the type of relationship and the success of outsourced projects; 3) more personnel with proper language and communication skills need to be educated in order to facilitate Chinese companies to build and maintain a proper partnership with their outsourcers.
Jingyue Li, Jianqiang Ma, Reidar Conradi, Weibing Chen, Junzhong Ji, Chunnian Liu
APSEC1
2007 The Empirical Studies on Quality Benefits of Reusing Software Components
abstract
The benefits of reusing software components have been studied for many years. Several previous studies have concluded that reused components have fewer defects in general than non-reusable components. However, few of these studies have gone a further step, i.e., investigating which type of defects has been reduced because of reuse. Thus, it is suspected that making a software component reusable will automatically improve its quality. This paper presents an on-going industrial empirical study on the quality benefits of reuse. We are going to compare the defects types, which are classified by ODC (Orthogonal Defect Classification), of the reusable component vs. the non-reusable components in several large and medium software systems. The intention is to figure out which defects have been reduced because of reuse and the reasons of the reduction.
Jingyue Li, Anita Gupta, Jon Arvid Børretzen, Reidar Conradi
COMPSAC (2)1
2007 Making Cost Effective Security Decision with Real Option Thinking
abstract
One of the major challenges in IT security management is determining how much to spend and where to spend. This requires understanding of the economic issues regarding IT security. Real option analysis presents a viable alternative to traditional economic tools in planning and valuing security investment in uncertain environment. This paper illustrates how decision makers can use real option thinking to articulate and compare different security solutions in terms of their business value in an environment characterized by high levels of uncertainty.
Jingyue Li, Xiaomeng Su
ICSEA1
2007 An Industrial Survey of Software Outsourcing in China
Jianqiang Ma, Jingyue Li, Weibing Chen, Reidar Conradi, Junzhong Ji, Chunnian Liu
PROFES2
2006 An empirical study on decision making in off-the-shelf component-based development
abstract
Component-based software development (CBSD) is becoming more and more important since it promotes reuse to higher levels of abstraction. As a consequence, many components are available being either open-source software (OSS) or commercial-off-the-shelf (COTS). However, it is still unclear how the decision for acquiring OSS or COTS components is made in practice. This paper describes an empirical study on why project decision-makers selected COTS instead of OSS components, or vice versa. The study was performed as an international survey in Norway, Italy and Germany. It focused on decision making on using off-the-shelf (OTS) components. We have gathered answers from 83 projects using only COTS components and 44 projects using only OSS components. Results of this study show significant differences and commonalities of integrating OSS or COTS components. Moreover, the study illustrates several research questions that warrant future research.
Jingyue Li, Reidar Conradi, Odd Petter N. Slyngstad, Christian Bunse, Marco Torchiano, Maurizio Morisio
ICSE1
2006 A State-of-the-Practice Survey of Off-the-Shelf Component-Based Development Processes
Jingyue Li, Marco Torchiano, Reidar Conradi, Odd Petter N. Slyngstad, Christian Bunse
ICSR1
2006 An empirical study of variations in COTS-based software development processes in the Norwegian IT industry
Jingyue Li, Finn Olav Bjørnson, Reidar Conradi, Vigdis By Kampenes
Empir. Softw. Eng.1
2005 An Empirical Study on Off-the-Shelf Component Usage in Industrial Projects
Jingyue Li, Reidar Conradi, Odd Petter N. Slyngstad, Christian Bunse, Muhammad Umair Ahmed Khan, Marco Torchiano, Maurizio Morisio
PROFES1
2004 A Study of Developer Attitude to Component Reuse in Three IT Companies
Jingyue Li, Reidar Conradi, Parastoo Mohagheghi, Odd Are Sæhle, Øivind Wang, Erlend Naalsund, Ole Anders Walseth
PROFES1
2001 Electronic Homework on the WWW
Chunnian Liu, Junzhong Ji, Chengzhong Yang, Jingyue Li
Web Intelligence5