Shanshan Li 0002

dblp:66/5479-2 · DBLP profile ↗
← Back
29ranked-venue papers
3as first author
24since 2021 · last 2026
0000-0001-7028-7981ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 24 · 3 first-author · 19 since 2021Systems, architecture and hardware · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Leveraging Large Language Models for Event Storming in Domain-Driven Design: A Controlled Experiment
Lingli Cao, He Zhang 0001, Shanshan Li 0002, Chenxing Zhong, Uwe Zdun
ICSA3
2026 A digital twin-based approach for dynamic traffic-aware routing and charging of electric vehicles
abstract
• Proposes a Digital Twin framework for EVs routing and charging optimization • Develops a Dual-Population Evolutionary Algorithm regarding to the dynamic environments • Demonstrates robustness under traffic disruptions, road closures, and charging station failures • Enhances adaptability and efficiency of EV operations in urban traffic networks The growing adoption of electric vehicles (EVs) presents new challenges for intelligent transportation systems (ITS), particularly in dynamic traffic environments where routing and charging decisions must adapt to fluctuating conditions. This paper proposes a Digital Twin-based Electric Vehicle Routing and Charging approach (DT-EVRC) that integrates real-time traffic data, predictive analytics, and a Dual-Population Evolutionary Algorithm (DPEA) to optimize EV travel and charging schedules. Unlike traditional static or simplified models, DT-EVRC continuously synchronizes with the physical transportation network, capturing variations in traffic density, charging station availability, and energy constraints. Experimental results on diverse grid-based urban scenarios demonstrate that DT-EVRC achieves robust and adaptive performance under traffic disruptions, road closures, and charging station failures. The proposed approach highlights the potential of digital twin technologies, combined with advanced optimization, to support next-generation ITS by enabling efficient, resilient, and sustainable urban mobility.
Shanshan Li 0002, Linjun Lu, Yuandong Pan, Fumiya Iida
Expert Syst. Appl.2
2026 Quality attributes, challenges, and solutions for designing GenAI-enabled systems
Chenxing Zhong, Jun Lyv, Shanshan Li 0002
Inf. Softw. Technol.4
2025 Detecting Build Dependency Errors by Dynamic Analysis of Build Execution Against Declaration
abstract
Incompletely declared build dependencies in MAKE-based build scripts can result in incorrect or inefficient incremental builds and parallel builds for C/C++ projects. In this sense, developing MAKE-based build scripts (e.g., Makefile) is a nontrivial task, since practitioners need to manually enumerate the dependencies between the parts involved in one build, which may result in serious dependency errors such as missing dependencies or redundant dependencies. To tackle this challenge, the software engineering community has invested considerable effort in dependency error detection. However, due to issues such as incomplete or even missing static dependencies (i.e., dependencies by users declared in Makefile), existing solutions either miss certain critical dependency errors or consume significant time when parsing build dependencies, posing a major challenge to ensure both detection effectiveness and efficiency. We propose a novel approach called BuildChecker to detect the above two critical types of dependency errors in MAKE dependencies that leverages a dynamically generated build execution-declaration model to improve error detection performance and reduce detection time. We evaluate BuildChecker with state-of-the-art tools (Mkcheck, Buildfs, VeriBuild, and VirtualBuild) on 30 projects. The experimental results show that BuildChecker is able to detect a total of 13,579 dependency errors with only 29 false positives, fewer than all the state-of-the-art tools. In terms of detection efficiency, BuildChecker outperforms Buildfs by 1.38 times and Mkcheck by 66.24 times. All dependency errors had been submitted to the practitioners and maintainers of these projects. At the time of writing this article, we received responses from the maintainers of four projects, who confirmed our error reports and fixes. BuildChecker demonstrates a great potential to support practitioners effectively detect build dependency errors.
Shanshan Li 0002, Bohan Liu 0003, He Zhang 0001, Guoping Rong, Chenxing Zhong
IEEE Trans. Software Eng.2
2025 Decision Support for Selecting Blockchain-Based Application Design Patterns With Layered Taxonomy and Quality Attributes
abstract
Background:Along with the rapid development and widespread adoption of blockchain technology, many common practices have been summarized into blockchain-based design patterns for application development. However, the numerous and scattered patterns may cause confusion among practitioners. Therefore, adopting appropriate patterns to meet various requirements has become a major challenge, as it requires deep development experience and blockchain technology knowledge.Objective:To address this problem, this paper proposes a decision-support solution to assist with the selection of design patterns during the blockchain-based application development, including a layered taxonomy of design patterns, mappings of quality attributes with the patterns, and a decision model incorporating the taxonomy and mappings.Method:We collected 72 distinct and state-of-the-art design patterns via a Systematic Literature Review (SLR) to establish a layered taxonomy, and 18 unified quality attribute metrics were proposed for blockchain-based pattern assessment and mapping establishment. Based on the pattern taxonomy and quality attribute mappings, we developed a decision model that can provide intuitive guidance for pattern selection.Results:The proposed solution was evaluated through a case study in a seafood supply chain, in which we examined how well the decision model could help identify design flaws and provide reasonable solutions. Additionally, interviews and a questionnaire-based survey were conducted to measure the completeness, correctness, and usefulness of the proposed decision model. The evaluation results indicate that the proposed decision-support solution provides developers with comprehensive guidance, facilitates targeted decision making, and supports intuitive understanding.Conclusions:Our decision-support solution can improve the development efficiency of blockchain-based applications, especially in addressing potential design flaws, achieving targeted quality attributes, and reducing development costs.
Jingyue Li, Shanshan Li 0002, He Zhang 0001, Chenxing Zhong, Bohan Liu 0003, Yue Liu 0010, Qinghua Lu 0001, Xin Zhou 0016
IEEE Trans. Software Eng.4
2025 Refactoring Microservices to Microservices in Support of Evolutionary Design
abstract
Evolutionary designis a widely accepted practice for defining microservice boundaries. It is performed through a sequence of incremental refactoring tasks (we call it“microservice refactoring”), each restructuring only part of a microservice system (a.k.a., refactoring part) into well-defined services for improving the architecture in a controlled manner. Despite its popularity in practice, microservice refactoring suffers from insufficient methodological support. While there are numerous studies addressing similar software design tasks,i.e., software remodularization and microservitization, their approaches prove inadequate when applied to microservice refactoring. Our analysis reveals that their approaches may even degrade the entire architecture in microservice refactoring, as they only optimize the refactoring part in such applications, but neglect the relationships between the refactoring part and the remaining system. As the first response to the need,Micro2Microis proposed to re-partition the refactoring part while optimizing three quality objectives including the interdependence between the refactoring and non-refactoring parts. In addition, it allows architects to intervene in the decision-making process by interactively incorporating their knowledge into the iterative search for optimal refactoring solutions. An empirical study on 13 open-source projects of different sizes shows that the solutions fromMicro2Microperform well and exhibit quality improvement with an average up to 45% to the original architecture. Users ofMicro2Microfound the suggested solutions highly satisfactory. They acknowledge the advantages in terms of infusing human intelligence into decisions, providing immediate quality feedback, and quick exploration capability.
Chenxing Zhong, Shanshan Li 0002, He Zhang 0001, Lanxin Yang, Yuanfang Cai
IEEE Trans. Software Eng.2
2024 A Scheduling Algorithm for Hyperledger Fabric Based on Transaction Batch Processing
abstract
Hyperledger Fabric (Fabric for short), is a consortium blockchain platform that adopts the smart contract paradigm and provides complete operational functions. Although it has become the system with the highest throughput among open source blockchain systems, its performance cannot meet the needs of industrial-grade application scenarios. To further expand the application scenarios of blockchain, this paper proposes a Transaction Batch Processing Scheduling (TBPS) algorithm for multi-channel Fabric networks based on Lyapunov optimization theory. The algorithm maximizes the consensus efficiency of the system while ensuring the minimum transaction accumulation, and provides stability conditions and optimal performance for the system under transaction batch processing. Finally, we built a blockchain network of Fabric’s latest stable version v 2.0 via the cloud platform, providing an order of magnitude of algorithmic parameters by testing transaction processing rates. To simulate the distribution of performance indicators such as transaction delay, system transaction accumulation and average transaction processing rate under different impact factors, and verify the effectiveness of the proposed TBPS algorithm.
Junyu Jia, Shanshan Li 0002, Rufei Ma, He Zhang 0001
ISPDC3
2024 Detecting Build Dependency Errors in Incremental Builds
abstract
Incremental and parallel builds performed by build tools such as Make are the heart of modern C/C++ software projects. Their correct and efficient execution depends on build scripts. However, build scripts are prone to errors. The most prevalent errors are missing dependencies (MDs) and redundant dependencies (RDs). The state-of-the-art methods for detecting these errors rely on clean builds (i.e., full builds of a subset of software configurations in a clean environment), which is costly and takes up to a few hours for large-scale projects. To address these challenges, we propose a novel approach called EChecker to detect build dependency errors in the context of incremental builds. The core idea of EChecker is to automatically update actual build dependencies by inferring them from C/C++ pre-processor directives and Makefile changes from new commits, which avoids clean builds when possible. EChecker achieves higher efficiency than the methods that rely on clean builds while maintaining effectiveness. We selected 12 representative projects, with their sizes ranging from small to large, with 240 commits (20 commits for each project), based on which we evaluated the effectiveness and efficiency of EChecker. We compared the evaluation results with a state-of-the-art build dependency error detection tool. The evaluation shows that the F-1 score of EChecker improved by 0.18 over the state-of-the-art method. EChecker increases the build dependency error detection efficiency by an average of 85.14 times (with a median of 16.30 times). The results demonstrate that EChecker can support practitioners in detecting build dependency errors efficiently.
Shanshan Li 0002, He Zhang 0001, Yang Zhang 0157, Guoping Rong, Manuel Rigger
ISSTA2
2024 Towards a security-optimized approach for the microservice-oriented decomposition
abstract
Abstract Microservice architecture (MSA) is a mainstream architectural style due to its high maintainability and scalability. In practice, an appropriate microservice‐oriented decomposition is the foundation to make a system enjoy the benefits of MSA. In terms of decomposing monolithic systems into microservices, researchers have been exploring many optimization objectives, of which modularity is a predominantly focused quality attribute. Security is also a critical quality attribute, that measures the extent to which a system protects data from malicious access or use by attackers. Considering security in microservices‐oriented decomposition can help avoid the risk of leaking critical data and other unexpected software security issues. However, few researchers consider the security objective during microservice‐oriented decomposition, because the measurement of security and the trade‐off with other objectives are challenging in reality. To bridge this research gap, we propose a security‐optimized approach for microservice‐oriented decomposition (So4MoD). In this approach, we adapt five metrics from previous studies for the measurement of the data security of candidate microservices. A multi‐objective optimization algorithm based on NSGA‐II is designed to search for microservices with optimized security and modularity. To validate the effectiveness of the proposed So4MoD, we perform several experiments on eight open‐source projects and compare the decomposition results to other three state‐of‐the‐art approaches, that is, FoSCI, CO‐GCN, and MSExtractor. The experiment results show that our approach can achieve at least an 11.5% improvement in terms of security metrics. Moreover, the decomposition results of So4MoD outperform other approaches in four modularity metrics, demonstrating that So4MoD can optimize data security while pursuing a well‐modularized MSA.
Chenxing Zhong, Shanshan Li 0002, Dong Shao
J. Softw. Evol. Process.6
2024 Metrics for software process simulation modeling
abstract
Abstract Software process simulation (SPS) has become an effective tool for software process management and improvement. However, its adoption in industry is less than what the research community expected due to the burden of measurement cost and the high demand for domain knowledge. The difficulty of extracting appropriate metrics with real data from process enactment is one of the great challenges. We aim to provide evidence‐based support of the process metrics for software process (simulation) modeling. A systematic literature review was performed by extending our previous review series to draw a comprehensive understanding of the metrics for process modeling following our proposed ontology of metrics in SPS. We identify 131 process modeling studies that collectively involve 1975 raw metrics and classified them into 21 categories using the coding technique. We found product and process external metrics are not used frequently in SPS modeling while resource external metrics are widely used. We analyze the causal relationships between metrics. We find that the models exhibit significant diversity, as no pairwise relationship between metrics accounts for more than 10% SPS models. We identify 17 data issues may encounter in measurement and 10 coping strategies. The results of this study provide process modelers with an evidence‐based reference of the identification and the use of metrics in SPS modeling and further contribute to the development of the body of knowledge on software metrics in the context of process modeling. Furthermore, this study is not limited to process simulation but can be extended to software process modeling, in general. Taking simulation metrics as standards and references can further motivate and guide software developers to improve the collection, governance, and application of process data in practice.
Bohan Liu 0003, He Zhang 0001, Liming Dong 0001, Shanshan Li 0002
J. Softw. Evol. Process.5
2024 A blockchain-based and microservices-architected software composition analysis system
abstract
Abstract “Shift To Left” is the cornerstone of the successful implementation of DevSecOps. By testing projects for vulnerabilities in the early stages of development, teams can save overall costs before security issues reach the build phase. As one of the popular practices in “Shift To Left,” the Software Composition Analysis (SCA) system aims to leverage the Software Bill of Materials (SBOM) to enhance software supply chain security. However, the SBOM lacks mature generation and distribution mechanisms, requiring incentive measures to drive industry consensus. Additionally, the data and tools associated with the SBOM lack effective record‐keeping and monitoring, making it challenging to ensure data integrity and tool security. Traditional SCA systems treat SBOM as a regular data format for external service provision, yet fail to solve problems such as lack of shared platforms, inability to guarantee data integrity and tool security, as well as issues with poor interoperation compatibility. This paper introduces blockchain technology into the SCA system, utilizing smart contracts to provide core SBOM tool services and microservices to improve the operational efficiency of smart contract deployment and maintenance. The proposed SCA system effectively provides a shared platform for SBOM with reliable data integrity, guaranteed tool security, and good interoperability.
Xin Zhou 0016, Jinwei Xu, Lingli Cao, Shanshan Li 0002
J. Softw. Evol. Process.7
2024 DOMICO: Checking conformance between domain models and implementations
abstract
Abstract As a predominant design method for microsservices architecture (MSA), domain‐driven design (DDD) utilizes a series of standard patterns in both models and implementations to effectively support the design of architectural elements. However, an implementation may deviate from its original domain model that uses certain patterns. The deviation between a domain model and its implementation is a type of architectural drift, which needs to be detected promptly. This paper proposes an approach, namely DOMICO, to check the conformance between the domain model and its implementation, by which the conformance is formalized by defining eight common structural patterns of domain modeling and their representations in both models and the corresponding source code. Based on the formalization, our approach can not only identify the discrepancies (e.g., divergence, absence, and modification) with respect to pattern elements, but also detect possible violations of 24 compliance rules imposed by the patterns. To validate DOMICO, we performed a case study to investigate its use in a supply chain project and its performance. The results show that DOMICO can accurately identify 100% inconsistency issues in the cases examined. As the first conformance checking approach for DDD, DOMICO can be integrated into the regular domain modeling process and help ensure the conformity of microservice implementations to models.
Chenxing Zhong, He Zhang 0001, Shanshan Li 0002
Softw. Pract. Exp.7
2024 Domain-Driven Design for Microservices: An Evidence-Based Investigation
abstract
MicroService Architecture (MSA), a predominant architectural style in recent years, still faces the arduous task of identifying the boundaries of microservices. Domain-Driven Design (DDD) is regarded as one of the major design methods for addressing this task in practice, which aims to iteratively build domain models using a series of patterns, principles, and practices. The adoption of DDD for MSA (DDD4Min short) can, however, present considerable challenges in terms of a sufficient understanding of the methodological requirements and the application domains. It is imperative to establish a systematic understanding about the various aspects of employing DDD4M and provide effective guidance. This study reports an empirical inquiry that integrates a systematic literature review and a confirmatory survey. By reviewing 34 scientific studies and consulting 63 practitioners, this study reveals several distinctive findings with regard to the state and challenges of as well as the possible solutions for DDD4M applications, from the5W1Hperspectives:When,Where,Why,Who,What, andHow. The analysis and synthesis of evidence show a wide variation in understanding of domain modeling artifacts. The status quo indicates the need for further methodological support in terms of application process, domain model design and implementation, and domain knowledge acquisition and management. To advance the state-of-the-practice, our findings were organized into a preliminary checklist that intends to assist practitioners by illuminating a DDD4M application process and the specific key considerations along the way.
Chenxing Zhong, Shanshan Li 0002, He Zhang 0001
IEEE Trans. Software Eng.2
2023 A performance evaluation method of queuing theory based on Cosmos cross-chain platform
Shanshan Li 0002, Haoming Li 0015
CCF Trans. High Perform. Comput.3
2023 Revisiting the practices and pains of microservice architecture in reality: An industrial inquiry
Xin Zhou 0016, Shanshan Li 0002, Lingli Cao, He Zhang 0001, Zijia Jia, Chenxing Zhong, Zhihao Shan, Muhammad Ali Babar 0001
J. Syst. Softw.2
2023 An optimal scheduling algorithm considering the transactions worst-case delay for multi-channel hyperledger fabric network
Shanshan Li 0002, He Zhang 0001, Liwen Liu, Haoming Li 0015
Parallel Comput.2
2023 The Why, When, What, and How About Predictive Continuous Integration: A Simulation-Based Investigation
abstract
Continuous Integration (CI) enables developers to detect defects early and thus reduce lead time. However, the high frequency and long duration of executing CI have a detrimental effect on this practice. Existing studies have focused on using CI outcome predictors to reduce frequency. Since there is no reported project using predictive CI, it is difficult to evaluate its economic impact. This research aims to investigate predictive CI from a process perspective, including why and when to adopt predictors, what predictors to be used, and how to practice predictive CI in real projects. We innovatively employ Software Process Simulation to simulate a predictive CI process with a Discrete-Event Simulation (DES) model and conduct simulation-based experiments. We develop the Rollback-based Identification of Defective Commits (RIDEC) method to account for the negative effects of false predictions in simulations. Experimental results show that: 1) using predictive CI generally improves the effectiveness of CI, reducing time costs by up to 36.8% and the average waiting time before executing CI by 90.5%; 2) the time-saving varies across projects, with higher commit frequency projects benefiting more; and 3) predictor performance does not strongly correlate with time savings, but the precision of both failed and passed predictions should be paid more attention. Simulation-based evaluation helps identify overlooked aspects in existing research. Predictive CI saves time and resources, but improved prediction performance has limited cost-saving benefits. The primary value of predictive CI lies in providing accurate and quick feedback to developers, aligning with the goal of CI.
Bohan Liu 0003, He Zhang 0001, Weigang Ma, Gongyuan Li, Shanshan Li 0002, Haifeng Shen
IEEE Trans. Software Eng.5
2022 A Reference Architecture for Blockchain-based Traceability Systems Using Domain-Driven Design and Microservices
abstract
Traceability systems are important for solving problems due to the increasing scale of the global supply chain, such as food safety crises and market disorder. Blockchain, as an immutable and decentralized ledger, is able to optimize the traditional traceability system by ensuring the transparency and reliability of the system data. However, the use of blockchain technology may lead to a rapid increase in the complexity of system design and development. It is challenging to address widespread and complicated business, changeable processes, and massive data in practice, which are the main factors restricting the wide application of a blockchain-based traceability system (BTS). Therefore, in this paper, we reviewed relevant studies and proposed a reference architecture for BTSs. The proposed reference architecture can improve the cohesiveness, maintainability, and extensibility of BTSs through domain-driven design (DDD) and microservices. Considering the efficiency reduction caused by massive data and complicated data structure, we further changed the traditional single blockchain framework into multiple subchain networks, which could improve development efficiency and system performance. With the guidance of the architecture trade-off analysis method (ATAM), we evaluated our reference architecture and implemented a prototype in the salmon supply chain scenario. The results show that our solution is effective and adaptable to meet the requirements of BTSs.
Shanshan Li 0002, Huikun Liu, He Zhang 0001
APSEC2
2022 A Vulnerability Detection Framework for Hyperledger Fabric Smart Contracts Based on Dynamic and Static Analysis
abstract
Hyperledger Fabric is another development of blockchain technology after Ethereum, which is more suitable as an operating platform for smart contracts. However, the testing technology of Hyperledger Fabric smart contracts (also known as chaincode) is not yet mature currently. Based on this, this paper studies the vulnerability detection of Golang chaincodes. Firstly, we summarize 17 kinds of Golang chaincode vulnerabilities by investigating existing research. Secondly, taking the high accuracy of dynamic detection and the high efficiency of static detection into consideration, we propose a chaincode vulnerability detection framework that combines the dynamic symbolic execution and the static abstract syntax tree analysis technology. We also implement a supporting-tool that can detect the above 15 types of vulnerabilities. Finally, we test the tool by 15 chaincodes collected from GitHub and unknown vulnerabilities were detected in 13 projects. The precision turned out to be 91% after manual inspection. In order to verify the recall rate, we manually inject 30 vulnerabilities into the collected chaincodes and all of them are detected. The evaluation results show the accuracy of the proposed vulnerability detection method for Hyperledger Fabric smart contracts.
Peiru Li, Shanshan Li 0002, Mengjie Ding, Jiapeng Yu, He Zhang 0001, Xin Zhou 0016, Jingyue Li
EASE2
2022 Performance Modeling of Hyperledger Fabric 2.0
abstract
Hyperledger Fabric has become one of the most widely used consortium blockchain frameworks with the ability to execute custom smart contracts. Performance modeling and network evaluation are necessary for performance estimation and optimization of the Fabric blockchain platform. The compatibility and effectiveness of existing performance modeling methods must be improved. For this reason, we proposed a compatible performance modeling method using queuing theory for Fabric considering the limited transaction pool. Taking the 2.0 version of Fabric as a case, we have established the model for the transaction process in the Fabric network. By analyzing the two-dimensional continuous-time Markov process of this model, we solved the system stationary equation and obtained the analytical expressions of performance indicators such as the system throughput, the system steady-state queue length, and the system’s average response time. We collected the required parameter values through the official test suite. An extensive analysis and simulation was performed to verify the accuracy and the effectiveness of the model and formula. We believe that this method can be extended to a wide range of scenarios in other blockchain systems.
Shanshan Li 0002, Liwen Liu, He Zhang 0001, Xin Zhou 0016, Qinghua Lu 0001
EASE2
2022 Modeling Cross-blockchain Process Using Queueing Theory: The Case of Cosmos
abstract
In order to solve the interconnection and intercommunication problem of a large number of co-existing blockchains, such as public chains, private chains, and consortium chains, cross-chain technology has recently become a hot research topic among scholars years. Due to the limited processing speed of cross-chain transactions, too many cross-chain transactions in the short term may cause network congestion and negatively affect cross-chain performance. Therefore, it is necessary to evaluate and optimize the performance of the cross-blockchain transaction process. This paper takes a typical cross-blockchain model Cosmos as an example and proposes a queuing theoretical model based on limited space. The difference equation is established through the three-dimensional continuous-time Markov process, and performance metrics such as average queue length, transaction execution time, and transaction response time are obtained. Finally, we experimentally simulate the analytical solutions of the relevant performance metrics to verify the effectiveness of the proposed model. We believe this analytical approach can be generalized to other cross-blockchain systems.
Shanshan Li 0002, Haoming Li 0015, He Zhang 0001
ICPADS2
2022 Impacts, causes, and solutions of architectural smells in microservices: An industrial investigation
abstract
Abstract As a recently predominant architecture style, MicroService Architecture (MSA) is likely to suffer the issues of poor maintainability due to inappropriate microservice boundaries. Architectural Smell (AS), as a metaphor for potential architectural issues that may have negative impacts on software maintenance, can be used to pinpoint refactoring opportunity for evolving microservice boundary. However, existing studies mostly focus on AS detection with little further investigation on the possible impacts, causes, and solutions of AS, which does little help in addressing the bad smells in architecture. Our goal in this study is to bridge this gap by investigating the possible impacts, causes, and solutions of AS in MSA‐based systems. An industrial case study is carried out to collect repository data and practitioners' views on six typical ASes in a real MSA‐based telecommunication system. Statistical Analysis and Coding techniques are used in the analyses of quantitative and qualitative data respectively. The results show that AS influences the modularity, modifiability, analyzability, and testability of the MSA‐based system, which further induce extra cross‐team communication, change‐ and fault‐prone microservices. To explore the causes for AS, a five‐aspect conceptual classification with technology, project, organization, business, and professional is proposed, in which the business and organization aspects take the major roles. Both technical and non‐technical solutions are distilled to deal with ASes despite potential constraints. These results and their comparison to current literature are discussed, which provide practical implications in coping with AS in microservices.
Chenxing Zhong, He Zhang 0001, Shanshan Li 0002
Softw. Pract. Exp.4
2021 HFContractFuzzer: Fuzzing Hyperledger Fabric Smart Contracts for Vulnerability Detection
abstract
With its unique advantages such as decentralization and immutability, blockchain technology has been widely used in various fields in recent years. The smart contract running on the blockchain is also playing an increasingly important role in decentralized application scenarios. Therefore, the automatic detection of security vulnerabilities in smart contracts has become an urgent problem in the application of blockchain technology. Hyperledger Fabric is a smart contract platform based on enterprise-level licensed distributed ledger technology. However, the research on the vulnerability detection technology of Hyperledger Fabric smart contracts is still in its infancy. In this paper, we propose HFContractFuzzer, a method based on Fuzzing technology to detect Hyperledger Fabric smart contracts, which combines a Fuzzing tool for golang named go-fuzz and smart contracts written by golang. We use HFContractFuzzer to detect vulnerabilities in five contracts from typical sources and discover that four of them have security vulnerabilities, proving the effectiveness of the proposed method.
Mengjie Ding, Peiru Li, Shanshan Li 0002, He Zhang 0001
EASE3
2021 Understanding and addressing quality attributes of microservices architecture: A Systematic literature review
Shanshan Li 0002, He Zhang 0001, Zijia Jia, Chenxing Zhong, Cheng Zhang 0010, Zhihao Shan, Jinfeng Shen, Muhammad Ali Babar 0001
Inf. Softw. Technol.1
2020 Exploring the Challenges of Developing and Operating Consortium Blockchains: A Case Study
abstract
Blockchain and smart contracts are being embraced by more and more industrial practitioners in multiple domains including agriculture, manufacturing, and healthcare. As a distributed, immutable, and partly public ledger, the consortium blockchain demonstrates its potential to enable trustworthy interoperability and collaboration between organizations. However, the mismatch between the unruled software engineering practices and the increased interest of the consortium blockchain technology may pose threats to the quality of systems implemented. To mitigate the possible threats, this study takes the angle of software engineering to systematically understand the challenges and possible solutions in terms of developing and operating a consortium blockchain-based system. For this purpose, we conducted a case study on a typical consortium blockchain-based system and exhaustively collected the data by two rounds in-depth interviews on practitioners of different roles in the case project. Based on the data analysis, eight pairs of challenges and potential solutions were identified, which cover the phases of the development and operation of consortium blockchains. Moreover, we also captured two implications after further analysis of the findings, which worth the special attention of researchers in the near future, i.e. DevOps and microservices for blockchain or smart contracts.
Shanshan Li 0002, Qianwen Xu 0003, Peiyu Hou, Xiudi Chen, He Zhang 0001, Guoping Rong
EASE1
2019 Microservice Architecture in Reality: An Industrial Inquiry
abstract
Background: Seeking an appropriate architecture for a software design is always a challenge in recent decades. Although microservices as a lightweight architecture style is claimed that can improve the current practices with several characteristics, many practices are based upon the different circumstances and reflect the variant effects. An empirical inquiry brings us a systematic insight into the industrial practices on microservices. Objective: This study is to investigate the gap between the ideal visions and real industrial practices on microservices and what benefits we can gain from the industrial experiences. Method: We carried out a series of industrial interviews with thirteen different types of companies. The collected data were then codified according to the defined qualitative methods. Results: We characterized the gaps between the typical characteristics accepted in the community and the industrial practices of microservices. Furthermore, the compromise between benefits and sufferings of microservices around these nine dimensions were also investigated. Conclusion: We confirmed the benefits of the microservices that can be obtained from practice as well as their possible pains that need to be addressed with extra expense from experiences. Besides, some outlined pains, e.g., organizational transformation, decomposition, distributed monitoring, and bug localization, may inspire researchers to conduct the further research.
He Zhang 0001, Shanshan Li 0002, Zijia Jia, Chenxing Zhong, Cheng Zhang 0010
ICSA2
2019 A dataflow-driven approach to identifying microservices from monolithic applications
Shanshan Li 0002, He Zhang 0001, Zijia Jia, Zheng Li 0001, Cheng Zhang 0010, Qiuya Gao, Jidong Ge, Zhihao Shan
J. Syst. Softw.1
2017 From Monolith to Microservices: A Dataflow-Driven Approach
abstract
Emerging from the agile practitioner communities, the microservice-oriented architecture emphasizes implementing and employing multiple small-scale and independently deployable microservices, rather than encapsulating all function capabilities into one monolithic application. Correspondingly, microservice-oriented decomposition, which has been identified to be an extremely challenging and complex task, plays a crucial and prerequisite role in developing microservice-based software systems. To address this challenge and reduce the complexity, we proposed a top-down analysis approach and developed a dataflow-driven decomposition algorithm. In brief, a three-step process is defined: first, engineers together with users conduct business requirement analysis and construct a purified while detailed dataflow diagram of the business logic; then, our algorithm combines the same operations with the same type of output data into a virtual abstract dataflow; finally, the algorithm extracts individual modules of "operation and its output data" from the virtual abstract dataflow to represent the identified microservice candidates. We have employed two use cases to demonstrate our microservice identification mechanism, as well as making comparisons with an existing microservice identification tool. The comparison and evaluation show that, our dataflow-driven identification mechanism is able to deliver more rational, objective, understandable and consistent microservice candidates, through a more rigorous and practical implementation procedure.
Shanshan Li 0002, Zheng Li 0001
APSEC2
2016 A Map of Threats to Validity of Systematic Literature Reviews in Software Engineering
abstract
Context: The assessment of Threats to Validity (TTVs) is critical to secure the quality of empirical studies in Software Engineering (SE). In the recent decade, Systematic Literature Review (SLR) was becoming an increasingly important empirical research method in SE. One of the mechanisms of insuring the level of scientific value in the findings of an SLR is to rigorously assess its validity. Hence, it is necessary to realize the status quo and issues of TTVs of SLRs in SE. Objective: This study aims to investigate the-state-of-the-practice of TTVs of the SLRs published in SE, and further support SE researchers to improve the assessment and strategies against TTVs in order to increase the quality of SLRs in SE. Method: We conducted a tertiary study by reviewing the SLRs in SE that report the assessment of TTVs. Results: We identified 316 SLRs published from 2004 to the first half of 2015, in which TTVs are discussed. The issues associated to TTVs were also summarized and categorized. Conclusion: The common TTVs related to SLR research, such as internal validity and reliability, were thoroughly discussed in most SLRs. The threats to construct validity and external validity drew less attention. Moreover, there are few strategies and tactics being reported to cope with the various TTVs.
Xin Zhou 0016, Yuqin Jin, He Zhang 0001, Shanshan Li 0002, Xin Huang 0019
APSEC4