Tim Storer

dblp:53/1913 · also Timothy Storer · DBLP profile ↗
← Back
24ranked-venue papers
6as first author
6since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 10 · 2 first-author · 4 since 2021Security and privacy · 8 · 4 first-authorHuman-computer interaction and ubiquitous computing · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2025 Assessing Work-Based Learning in the Senior Years of a Software Engineering Graduate Apprenticeship Program
abstract
The software engineering graduate apprenticeship program at the School of Computing, University of Glasgow, has a significant emphasis on work-based learning (WBL), with approximately 80% of the students' time over four years spent in the workplace. This work-based aspect of the program plays a more prominent role in the final two years, by which time apprentices are undertaking increasingly larger roles in the workplace. In this report, we present how we addressed the challenge of structuring and assessing WBL in these senior years such that there is a balance between professional competency attainment and ranked academic achievement, while providing a fair and flexible structure. Based on a model of WBL presented by Raelin in 1997, we outline our rationale for dividing the assessments into workplace projects, workplace journal, and a portfolio of artefacts. The projects are categorised into different types both for flexibility and to encourage academia-industry collaboration, the workplace journal encourages higher forms of reflection, while the portfolio assessment encourages and assesses the attainment of professional competencies. We present our experience of implementing this structure, an analysis of student feedback, and the adjustments made in response. With an increasing focus on work-ready skills and competency-based education in software engineering education, we expect the theory-informed structure we developed, and our experience of running and adapting it, to serve as an exemplar for developing a WBL program at research-led institutions.
Syed Waqar Nabi, Oana Andrei, Matthew Barr, Quintin I. Cutts, Joseph Maguire 0001, Alistair Morrison, Jack Parkinson, Derek Somerville, Tim Storer
CSEE&T9
2025 Out of the Day Job: Perspectives of Industry Practitioners in Co-Design and Delivery of Software Engineering Courses
abstract
Over more than two decades, The University of Glasgow has co-designed and delivered numerous software engineering focused courses with industry partners, covering both technical and discipline specific professional skills. Such collaborations are not unique and many of the benefits are well recognised in the literature. These include enhancing the real-world relevance of curricula, developing student professional networks ahead of graduation and easing recruitment opportunities for employers. However, there is relatively little scholarship on the perspectives of industry practitioners who participate in course design and delivery. This gap is significant, since the effort invested by practitioners is often substantial and may require ongoing support from both the industry partner and academic institution. Understanding the motivations, expectations and experiences of practitioners who engage in course delivery can guide the formation of future partnerships and ensure their long-term sustainability. We begin to address this gap by reporting on the outcomes of a retrospective conducted amongst the practitioner coauthors of this paper, with the academic coauthors acting as facilitators. All coauthors have participated in the recent co-design and delivery of software engineering courses, but we choose to focus explicitly on the perspectives of the practitioners. We report on the themes that emerged from the discussions and our resulting recommendations for future collaborations.
Gillian Daniel, Chris Hall, Per Hammer, Alec-Angus Macdonald, Hollie Marwick-Best, Emma McKenzie, George Popa, Derek Somerville, Tim Storer
ITiCSE (1)9
2023 A Case Study of DevOps Adoption within a Large Financial Organisation
abstract
DevOps is a collection of practices that reduces barriers between development and operations within software organisations, with the aim of increasing product release frequency and reliability. DevOps is increasingly important in the software industry. However, although existing research suggests that organisations face barriers to adoption, there are few case studies of how DevOps is adopted in practice. Therefore many organisations may face challenges in the transition to DevOps and lack guidance from prior experience as to successful strategies for managing the change.This paper presents a case study of DevOps adoption in a software development team within a large financial organisation. The study used a mixed-methods approach of surveys, interviews, and retrospectives to investigate the team’s experience. We collected evidence from 47 team members and document how the team has adopted the different practices. The findings highlight the factors influencing adoption, the benefits realised and the challenges faced. The results provide insights into practitioners’ perspective on DevOps adoption, as well as contributing to the evidence base on this practice in the literature as a basis for future research.
Lixin Su, Tim Storer
ICSME2
2022 Evaluation of Context-Aware Language Models and Experts for Effort Estimation of Software Maintenance Issues
abstract
Reflecting upon recent advances in Natural Language Processing (NLP), this paper evaluates the effectiveness of context-aware NLP models for predicting software task effort estimates. Term Frequency–Inverse Document Frequency (TF-IDF) and Bidirectional Encoder Representations from Transformers (BERT) were used as feature extraction methods; Random forest and BERT feed-forward linear neural networks were used as classifiers. Using three datasets drawn from open-source projects and one from a commercial project, the paper evaluates the models and compares the best performing model with expert estimates from both kinds of datasets. The results suggest that BERT as feature extraction and classifier shows slightly better performance than other combinations, but that there is no significant difference between the presented methods. On the other hand, the results show that expert and Machine Learning (ML) estimate performances are similar, with the experts’ performance being slightly better. Both findings confirmed existing literature, but using substantially different experimental settings.
Mohammed Alhamed, Tim Storer
ICSME2
2021 Playing Planning Poker in Crowds: Human Computation of Software Effort Estimates
abstract
Reliable cost effective effort estimation remains a considerable challenge for software projects. Recent work has demonstrated that the popular Planning Poker practice can produce reliable estimates when undertaken within a software team of knowledgeable domain experts. However, the process depends on the availability of experts and can be time-consuming to perform, making it impractical for large scale or open source projects that may curate many thousands of outstanding tasks. This paper reports on a full study to investigate the feasibility of using crowd workers supplied with limited information about a task to provide comparably accurate estimates using Planning Poker. We describe the design of a Crowd Planning Poker (CPP) process implemented on Amazon Mechanical Turk and the results of a substantial set of trials, involving more than 5000 crowd workers and 39 diverse software tasks. Our results show that a carefully organised and selected crowd of workers can produce effort estimates that are of similar accuracy to those of a single expert.
Mohammed Alhamed, Tim Storer
ICSE2
2021 Sciit: Embedding issue tracking in source control management
Nystrom Edwards, Dhitiwat Jongsuebchoke, Tim Storer
Sci. Comput. Program.3
2019 "I do it because they do it": Social-Neutralisation in Information Security Practices of Saudi Medical Interns
Saad Altamimi, Karen Renaud, Tim Storer
CRiSIS3
2019 Estimating Software Task Effort in Crowds
abstract
A key task during software maintenance is the refinement and elaboration of emerging software issues, such as feature implementations and bug resolution. It includes the annotation of software tasks with additional information, such as criticality, assignee and estimated cost of resolution. This paper reports on a first study to investigate the feasibility of using crowd workers supplied with limited information about an issue and project to provide comparably accurate estimates using planning poker. The paper describes our adaptation of planning poker to crowdsourcing and our initial trials. The results demonstrate the feasibility and potential efficiency of using crowds to deliver estimates. We also review the additional benefit that asking crowds for an estimate brings, in terms of further elaboration of the details of an issue. Finally, we outline our plans for a more extensive evaluation of planning poker in crowds.
Mohammed Alhamed, Tim Storer
ICSME2
2019 Sciit: Aligning Source Control Management and Issue Tracking Architectures
abstract
This paper presents sciit, a distributed issue tracker. Distributed issue tracking eliminates much of the friction that is otherwise necessitated by separately maintaining source code in a distributed source control management system (SCM) and task information in a centralised issue tracker. Sciit goes beyond the state of the art in distributed issue tracking by treating issues as first class change control items, represented as fragments of text anywhere within the SCM. This approach treats issues as representations of work in progress alongside other project artefacts. This alignment allows much of the meta-data about an issue, such as status, affected components and participants to be inferred directly from the state of the SCM, rather than requiring maintenance of this information by a developer. The paper presents a scenario to illustrate the benefits of sciit and an outline of the tool's architecture.
Nystrom Edwards, Dhitiwat Jongsuebchoke, Tim Storer
ICSME3
2019 Behave Nicely! Automatic Generation of Code for Behaviour Driven Development Test Suites
abstract
Behaviour driven development (BDD) has gained widespread use in the software industry. System specifications can be expressed as test scenarios, describing the circumstances, actions and expected outcomes. These scenarios are written in a structured natural language (Gherkin), with each step in the scenario associated with a corresponding step implementation function in the underlying programming language. A challenge recognised by industry is ensuring that the natural language scenarios, step implementation functions and underlying system implementation remain consistent with one another, requiring on-going maintenance effort as changes are made to a system. To address this, we have developed behave_nicely, a tool, for automatically generating step implementation functions from structured natural language steps, with the intention of eliminating the need for maintaining step implementation functions. We evaluated our approach on a sample of 20 white box and 50 black box projects using behaviour driven development, drawn from GitHub. Our results show that behave_nicely can generate step implementation functions for 80% of the white box and 17% of black box projects. We conclude that (a) there is significant potential for automating the process of code generation for BDD tests and (b) that the development of guidelines for writing tests in Gherkin would significantly improve the results.
Tim Storer, Ruxandra Bob
SCAM1
2018 Analyzing Privacy Policies of Zero Knowledge Cloud Storage Applications on Mobile Devices
abstract
With the rapid growth of mobile applications and the increase number of mobile users, many cloud storage services started to design stand-alone mobile applications that can be used to access files remotely from mobile and share them. In this paper, an in-depth analysis has been performed on the privacy policies of zero knowledge cloud storage applications on mobile. The analysis includes the type of information collected, collection mechanisms, purpose for collection, sharing of information, user controls and information retention period. The results showed that most privacy policies addressed important areas of information collection, purposes of collection, information sharing and users' controls. On the other hand, many policies lacked detailed information of the data retention period.
Rawan Baalous, Ronald Poet, Tim Storer
IC2E3
2018 Third-party verifiable voting systems: Addressing motivation and incentives in e-voting
Robbie Simpson, Tim Storer
J. Inf. Secur. Appl.2
2017 Does CloudSim Accurately Model Micro Datacenters?
abstract
Novel cloud computing algorithms and techniques are initially evaluated via testbeds, simulators and mathematical models of datacenter infrastructure. However, it can be difficult to perform cross validation of these platforms against realistic scale infrastructures due to the prohibitive costs involved. This paper describes an approach to evaluating a cloud simulator through an empirical study involving a micro datacenter of commodity Raspberry Pi devices. To demonstrate the methodology, we compare performance of real-world workloads on this physical infrastructure against corresponding models of the workloads and infrastructure on the CloudSim simulator. After modelling a Raspberry Pi micro datacenter in CloudSim, we claim that the simulator lacks sufficient accuracy for cloud infrastructure experiments.
Dhahi Alshammari, Jeremy Singer, Tim Storer
CLOUD3
2017 Experimenting with Realism in Software Engineering Team Projects: An Experience Report
abstract
Over Several years, we observed that our students were sceptical of Software Engineering practices, because we did not convey the experience and demands of production quality software development. Assessment focused on features delivered, rather than imposing responsibility for longer term `technical debt'. Academics acting as 'uncertain' customers were rejected as malevolent and implausible. Student teams composed of novices lacked the benefits of leadership provided by more experienced engineers. To address these shortcomings, real customers were introduced, exposing students to real requirements uncertainty. Flipped classroom teaching was adopted, giving teams one day each week to work on their project in a redesigned laboratory. Software process and quality were emphasised in the course assessment, imposing technical debt. Finally, we introduced a leadership course for senior students, who acted as mentors to the project team students. This paper reports on the experience of these changes, from the perspective of different stakeholders.
Robbie Simpson, Tim Storer
CSEE&T2
2015 Formalising Responsibility Modelling for Automatic Analysis
Robbie Simpson, Tim Storer
EOMAS@CAiSE2
2013 Comparison of the Data Recovery Function of Forensic Tools
Joe Buchanan-Wollaston, Tim Storer, William Glisson
IFIP Int. Conf. Digital Forensics2
2013 Encouraging second thoughts: Obstructive user interfaces for raising security awareness
abstract
We propose a suite of user interface widgets to intuitively inform a user of a mobile device's sense of comfort at the user's proposed actions.
Tim Storer, Stephen Marsh 0001, Sylvie Noël, Babak Esfandiari, Khalil El-Khatib, Pamela Briggs, Karen Renaud, Mehmet Vefa Bicakci
PST1
2013 A framework for continuous, transparent mobile device authentication
Heather Crawford, Karen Renaud, Tim Storer
Comput. Secur.3
2009 Accuracy: The Fundamental Requirement for Voting Systems
abstract
There have been several attempts to develop a comprehensive account of the requirements for voting systems, particularly for public elections. Typically, these approaches identify a number of "high level" principals which are then refined either into more detailed statements or more formal constructs. Unfortunately, these approaches do not acknowledge the complexity and diversity of the contexts in which voting takes place. This paper takes a different approach by arguing that the only requirement for a voting system is that it is accurate. More detailed requirements can then be derived from this high level requirement for the particular context in which the system is implemented and deployed. A general, formal high level model for voting systems and their context is proposed. Several related definitions of accuracy for voting systems are then developed, illustrating how the term "accuracy" is in interpreted in different contexts. Finally, a context based requirement for voting system privacy is investigated as an example of deriving a subsidiary requirement from the high level requirement for accuracy.
Tim Storer, Russell Lock
ARES1
2009 Deriving Information Requirements from Responsibility Models
Ian Sommerville, Russell Lock, Tim Storer, John Dobson
CAiSE3
2007 An Evaluation Framework for Grid-based Learning Technologies
abstract
The ELeGI project+aims to define new models of human learning, enabling ubiquitous and collaborative learning, by merging experiential, personalised and contextualised approaches. An advanced service-oriented Grid based software architecture for learning has been defined and implemented by the consortium, using a number of different educational applications. The ELeGI evaluation framework was developed to help manage the overall set of evaluations required for the project, and to distinguish between the evaluation of applications and middleware. It encompasses all aspects of a learning environment, in order to identify "Grid added value " and "Learning added value". In this paper we discuss the concept of "Usability" and QoS for evaluation in ELeGI, with two illustrative examples of evaluation of an educational application integration with Grid services.
Colin Allison, Tim Storer, Stuart D. J. Purdie, Rosa Michaelson
ICALT2
2005 Two Variations to the mCESG Pollsterless E-Voting Scheme
abstract
Over the past several years, the UK government has piloted several new voting technologies during local authority elections. The mCESG pollsterless Remote Electronic Voting (REV) system, which was designed with the UK electoral context in mind, is described in detail by Storer and Duncan (2004). Here, we describe two variations to the mCESG scheme which (a) improve its suitability for the variety of electoral systems in use in the UK and (b) provide a means for resisting coercion attacks to which the original scheme was vulnerable.
Tim Storer, Ishbel Duncan
COMPSAC (1)1
2005 Electronic Voting in the UK: Current Trends in Deployment , Requirements and Technologies
Tim Storer, Ishbel Duncan
PST1
2004 Practical Remote Electronic Elections for the UK
Tim Storer, Ishbel Duncan
PST1