Haruhiko Kaiya

dblp:99/386 · DBLP profile ↗
← Back
54ranked-venue papers
25as first author
10since 2021 · last 2025
0000-0001-9816-8001ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 33 · 13 first-author · 2 since 2021Artificial intelligence and machine learning · 16 · 12 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 7Security and privacy · 3Databases, data management, data science and information retrieval · 2 · 1 first-author
YearPublicationVenuePosition
2025 Exhaustive Model Identification on Process Mining
Takeharu Mitsuda, Hiroyuki Nakagawa, Haruhiko Kaiya, Hironori Takeuchi, Sinpei Ogata, Tatsuhiro Tsuchiya
ENASE3
2025 COTTAGE: Supporting Threat Analysis for Security Novices with Auto-Generated Attack Defense Trees
Keita Yamamoto, Masaki Oya, Masaki Hashimoto, Haruhiko Kaiya, Takao Okubo
ICSOFT4
2025 Rating the cost of quality in use for a business system using KAOS model
abstract
Stakeholders want quality in use requirements to be satisfied as much as possible to make their life or business activities better than ever. However, some of them should be abandoned if they are expensive. In this paper, we propose a method for analyzing the cost ratio of quality in use for a life or business system during early requirements analysis. This method enables stakeholders to sort out initially required quality in use requirements. The cost depends on the number and the complexity of operations in a system, their data and users. In this method, KAOS model is thus used because it contains goals, operations, users and data. KAOS model also enables us to represent the roles of both human and artificial systems embedded in a business system. When a part of a system should achieve some functional and quality goal, the goal should be transformed into some operations and their data respectively. The relative cost of some function or quality is thus quantified on the basis of operations, data and associations among them. Through the case study, the results of analysis seemed to meet our intuition. In addition, we found the relative cost of quality in use is not so small. This finding makes stakeholders to abandon some of quality in use in this case if they do not have enough budget and/or time.
Haruhiko Kaiya, Takeru Nakamura, Shinpei Ogata, Hiroyuki Nakagawa, Hironori Takeuchi
KES1
2025 Diffusion Model of Anti-Patterns for Machine Learning Projects
abstract
The development of service systems leveraging Machine Learning (ML) has been actively pursued in recent years. In the development of general service systems, knowledge for effectively managing projects has been systematized. Similarly, in ML service system development projects (ML projects), knowledge such as best practices and patterns is being established. Among these, anti-patterns documenting situations that cause issues in ML projects and their corresponding solutions, are also being organized. However, knowledge like patterns and anti-patterns does not clearly define who should recognize their necessity or apply the solutions. As a result, in ML projects, where collaboration among stakeholders is critical, the utilization of such knowledge often depends on the experience and skills of the individuals involved. In this study, we propose a diffusion model for anti-patterns in ML projects and a method for representing the model. Furthermore, by representing actual anti-patterns as a diffusion model using the proposed method, we verify the effectiveness of the represented model.
Hironori Takeuchi, Haruhiko Kaiya, Hiroyuki Nakagawa, Shinpei Ogata
KES2
2024 A Light-Weight Method of Concept Drift Detection using Heuristic Miner
abstract
Processes of some business or life activities are sometimes changed due to some reasons, such as the emergence of new technologies and the change of the human behavior caused by a seasonal event, e.g. Christmas. Such changes are called concept drift. Detecting concept drift is useful for many reasons. For example, we can update existing out-of-date business rules. Many methods of concept drift detection in processes have been already proposed. However, most of them are a little bit complex because sliding widows should be defined on a log of business process during its analysis. We thus propose a light-weight method for its detection by using heuristic miner, which is a famous algorithm for process discovery. In our method, we simple observe the discovered model to identify the infrequent actions and transitions between actions. Our method helps us to identify several types of concept drift although some types cannot be detected. We discuss how to overcome current limitations of our method.
Haruhiko Kaiya, Yuuki Koga, Soichiro Mori, Shinpei Ogata, Hiroyuki Nakagawa, Hironori Takeuchi
KES1
2023 Finding Contributable Activities Using Non-Verb Attributes In Events
abstract
Many different activities are performed simultaneously in the real world, and one of them contains actions, that can be utilized in another activity. If such actions are actually utilized, the activity utilizing them become more efficiently than ever. We call the activity providing such actions a contributable activity, and the one utilizing the actions a contributed activity. Our research goal is to find such contribution relationships between activities. To achieve the goal, we used a conformance checking technique in the field of process mining research. In the process mining research, logs of actions and control flow models are used, and the logs and the models are usually represented by the verb attribute in an action such as “submit”, “decide” and so on. However, we could not find some contribution relationships by using the logs and models of the verb attribute. We thus examine the usage of non-verb attributes such as a place or a tool in an action for our goal. Through a case study about elderly people care, we find non-verb attributes have some potential to achieve our goal more comprehensively than ever.
Haruhiko Kaiya, Hironori Takeuchi, Hiroyuki Nakagawa, Shinpei Ogata, Shinobu Saito
KES1
2023 Practice-based Collection of Bad Smells in Machine Learning Projects
abstract
In this study, we consider projects for developing service systems using machine learning (ML) techniques. As ML techniques have been introduced in various domains, there is reusable knowledge on ML projects that can be employed for conducting such projects without facing major failures. The usage of such knowledge during a project has not yet been clearly described in the form of reusable knowledge such as best practices or patterns. Thus, in this study, we propose a method for collecting the ominous signs in ML projects as “bad smells” and incorporating them as a part of such reusable knowledge. We confirmed the effectiveness of the proposed method through an evaluation.
Hironori Takeuchi, Haruhiko Kaiya, Hiroyuki Nakagawa, Shinpei Ogata
KES2
2022 A Proposal to Find Mutually Contributable Business or Life Activities Using Conformance Checking
abstract
We propose a method to comprehensively find a pair of business or life activities, which can mutually contribute to each other. We assume that the activities with synchronized processes can mutually contribute to each other. A process model of an activity is thus compared to a log of another activity for measuring whether the activities can synchronize their processes to a certain extent using a conformance checking technique. The threshold of the extent is defined on the basis of a randomly generated log containing the same events as those in the compared log. We tentatively evaluated the method through a case study, and confirmed that the method seemed to be valid.
Haruhiko Kaiya, Tomoya Misawa, Shinpei Ogata, Shinobu Saito, Hiroyuki Nakagawa, Hironori Takeuchi
KES1
2022 Efficient secure DevOps using process mining and Attack Defense Trees
abstract
In this paper, we propose a method to efficiently ensure security in the DevOps lifecycle through operations and development. To ensure sufficient security in DevOps, it is essential to perform sufficient threat analysis during development. However, threat analysis is generally a heavy task and difficult to apply to agile processes. In addition, existing technologies are not sufficient for security feedback from Dev to Ops and Ops to Dev, which are important elements of DevOps. In this paper, we propose a method for detecting attacks using anomaly detection from operation logs, and extracting vulnerabilities and candidate countermeasures using information such as CAPEC and CWE. Furthermore, we propose a method to determine the excess or deficiency of the countermeasure by comparing it with the Attack-Defense Trees created in the previous development. By applying our proposal to an actual development case, we confirm that the proposed method works effectively.
Takao Okubo, Haruhiko Kaiya
KES2
2021 Tools for logging and analyzing goal dependency modeling
abstract
Modeling goal dependencies among people and systems contributes to exploring the systems valuable to the people. Therefore, guiding such modeling processes is useful for the system development. Because there is no predefined process model of good goal dependency modeling, we have to clarify the characteristics of actual modeling processes for a start. In this paper, we introduce the tools for logging and analyzing goal dependency modeling. We also report a case study to use the tools so as to find common characteristics of the modeling processes. We expect such tools help us to find how to guide a modeling process. The logging tool is developed by expanding an existing modeling tool called astah. Each developer can thus easily record the logs with his/her familiar modeling tool. The analyzing tools finally visualize each modeling process in several ways by using Graphvis. We can observe the development process, and analyze the common characteristics with the help of these tools. Although we cannot find the unknown and unique characteristics, we can confirm some reasonable characteristics. For example, the ratio of transitions between goals and other elements is larger than the other ratio.
Haruhiko Kaiya, Kouta Hayashi, Yu Sato
KES1
2020 Evaluating Mutual Requirements Evolution of Several Information Systems
abstract
We have proposed a method of eliciting requirements for several different systems together. We expect the method brings the following advantages. First, it improves the efficiency of human, time and space resources as well as system the development effort. Second, it helps a requirements analyst to be aware of unknown requirements of the users so that each system brings new values. Third, the method encourage mutual contribution among systems. In this paper, we extend the method so as to confirm whether the expectations above are satisfied, and examine it. To confirm it, metrics are defined on the basis of several types of traceability links and stereo types.
Haruhiko Kaiya
KES1
2020 A Tool to Manage Traceability on Several Models and Its Use Case
abstract
To examine requirements and design of a system, using graphical models such as UML is one of the effective ways because it helps developers to understand the system and activities using the system. Usually, more than two types of notations are used to represent a system. At the age of digital transformation, relationships among several different systems should be also discussed and they are of course represented in several different notations. To improve the development and the analysis of several systems using such several notations, traceability among elements in the different notations should be managed, but most techniques focus on the traceability among a single project. In this paper, we present a tool to manage traceability on several different models. The tool is developed as a plugin of an existing graphical modeling tool called Astah. Astah enables us to describe UML models as well as mind maps, data flow diagrams, flow charts and so on. To evaluate our tool, we performed a method to elicit requirements of several different systems together by using the tool. We confirmed our tool was helpful to perform the method, but some additional functions would improve the performance more than now. The additional functions are as follows: tracing links transitively, annotating each link to clarify its type and recording an end of a link while the end is removed from a model.
Haruhiko Kaiya, Shogo Tatsui, Atsuo Hazeyama, Shinpei Ogata, Takao Okubo, Nobukazu Yoshioka, Hironori Washizaki
KES1
2019 Towards A Knowledge Base for Software Developers to Choose Suitable Traceability Techniques
abstract
Huge amount of techniques for creating, maintaining and/or recovering traceability among software development artifacts have been proposed. It is thus not easy for a potential user of such techniques to choose a technique suitable for his/her project because too many techniques exist and projects are different from each other. In this paper, we proposed a model for characterizing a traceability technique with respect to its users. The model can become a meta-model of the knowledge base for such users. The model is designed on the basis of the contents of existing technical papers so that we can easily describe model instances on the basis of technical papers. The model is represented in a feature model, and it has four mandatory features: source, destination, consequence and process. The user can at least understand a technique is unsuitable for him/her by referring such features. If a technique estimates the traceability relationships, the instance of its feature model may contain the quality metrics of its estimation such as precision and recall. It has also several optional features: assumptions, preprocess and tool. Although we sometimes cannot obtain such optional features from technical papers, they are so helpful for a user to decide a technique suitable for him/her. On the basis of the feature model, we described model instances of several techniques in technical papers. We also examined and discussed who the suitable user for each technique is.
Haruhiko Kaiya, Atsuo Hazeyama, Shinpei Ogata, Takao Okubo, Nobukazu Yoshioka, Hironori Washizaki
KES1
2018 Security Requirement Modeling Support System Using Software Security Knowledge Base
abstract
With the growing number of services on the Internet, the need for secure software development has increased. It is required for secure software development to consider security in the whole development life cycle. It is indispensable for secure software development to use various types of security knowledge. This study deals with security requirement analysis. Existing security requirements modeling systems do not provide a function to create an artifact while referring to security knowledge in an integrated manner. In this paper, the authors develop a modeling support system for a misuse case diagram that enables the association of knowledge with elements that constitute the diagram. The results of an experiment using the system show the system's usefulness in both the integration of the knowledge base with the artifact creation environment and the association of the knowledge with the elements of the diagram.
Atsuo Hazeyama, Shun'ichi Tanaka, Takafumi Tanaka, Hiroaki Hashiura, Seiji Munetoh, Takao Okubo, Haruhiko Kaiya, Hironori Washizaki, Nobukazu Yoshioka
COMPSAC (2)7
2018 Meta-Requirements for Information System Requirements: Lesson Learned from Software Ecosystem Researches
abstract
An information system should be specified so that the world containing the system meets the needs of people, who is interested in the world. Such needs are called requirements in problem frames. Concrete requirements have great diversity because each people focuses on different activities in the different worlds. However, we believe all requirements follow some laws when the requirements are proper. We call such laws as meta-requirements. We discuss and enumerate such meta-requirements in this paper so that we can judge some requirements are proper or not. Currently, we have four meta-requirements. First meta-requirement is the decrease of human effort. This is the most traditional and fundamental requirement when an artificial elements such as information systems are embedded in a world. Second one is the increase of human gain, which is dual of the first one. The rest meta-requirements come from researches of software ecosystem. Third meta-requirement is sustainability of the world. Fourth one is the increase of human participation in the world. We have already has our own requirements modeling notation called GDMA. However, we cannot examine requirements written in GDMA against all four meta-requirements. We thus extend our GDMA so that we can examine them against all the meta-requirements. We then exemplify some concrete requirements meet our four meta-requirements.
Haruhiko Kaiya
KES1
2018 Cloud Security and Privacy Metamodel - Metamodel for Security and Privacy Knowledge in Cloud Services
Hironori Washizaki, Takehisa Kato, Haruhiko Kaiya, Shinpei Ogata, Eduardo B. Fernández, Hideyuki Kanuka, Masayuki Yoshino, Dan Yamamoto, Takao Okubo, Nobukazu Yoshioka, Atsuo Hazeyama
MODELSWARD4
2017 Identifying Fundamental Goals from Objects in a Scenario to Facilitate System Introduction
abstract
To introduce suitable and innovative information systems into our daily activity, we have to know actual goals of its stakeholders. However, requirements analysts cannot directly know such goals, and stakeholders usually cannot state them explicitly even with the help of why questions. Analysts can directly observe or know the way of tasks in the activity, i.e. scenario. In this paper, we propose an early requirements analysis method using a scenario and goals in a bottom up way. In the method, the analysts first identify superficial objects and their attributes from the scenario, and construct a superficial goal model. The analysts then identify conceptual objects which do not appear in the scenario by combining and generalizing the superficial objects and goals. On the basis of the objects and superficial goals, the analysts identify the fundamental goals of the stakeholders. We are applying the method to examples to confirm how it works.
Yoshihide Chubachi, Haruhiko Kaiya
COMPSAC (2)2
2017 Traceability Link Mining - Focusing on Usability
abstract
The recovery of traceability links to requirements from a functional model created through analysis/design is crucial to understand existing systems for reuse, improvement or maintenance. Functional and non-functional requirements generally are implicitly interpreted and non-systematically woven into a functional model by analysts/designers. Traditional traceability link recovery methods focusing on terminology or syntactic structure, however, have a recovery limit because such interpretation and weave are not paid enough attention. This paper presents a novel idea to decompose such a functional model into model components in order to accurately trace a components to requirements especially non-functional requirements. We call such the decomposition traceability link mining. A screen transition model is adopted as the functional model because of the focus on usability.
Yukiya Yazawa, Shinpei Ogata, Kozo Okano, Haruhiko Kaiya, Hironori Washizaki
COMPSAC (2)4
2017 A CASE tool for Goal Dependency Model with Attributes based on An Existing UML Editor
abstract
To facilitate the suitable introduction of innovative information technologies into a social activity such as healthcare and entertainment, such an activity should be modeled and analyzed. We have already proposed a modeling language called Goal Dependency Model with Attributes (GDMA) for such purposes. To encourage many requirements analysts to use GDMA, the operational and learning effort shall be minimized as much as possible. In addition, described models shall be analyzed as efficiently as possible. To satisfy these two requirements, we proposed a UML-based notation for GDMA. We also developed a CASE tool based on an existing UML editor. We evaluated our notation and the tool through an experiment. Although subjects in the experiment were bachelor students, the subjects gave positive feedbacks to the tool.
Haruhiko Kaiya, Kazuto Haga
KES1
2017 Preliminary Systematic Literature Review of Software and Systems Traceability
abstract
Traceability is important knowledge for improving the artifacts of software and systems and processes related to them. Even in a single system, various kinds of artifacts exist. Various kinds of processes also exist, and each of them relates to different kinds of artifacts. Traceability over them has thus large diversity. In addition, developers in each process have different types of purposes to improve their artifacts and process. Research results in traceability have to be categorized and analyzed so that such a developer can choose one of them to achieve his/her purposes. In this paper, we report on the results of Systematic Literature Review (SLR) related to software and systems traceability. Our SLR is preliminary one because we only analyzed articles in ACM digital library and IEEE computer society digital library. We found several interesting trends in traceability research. For example, researches related to creating or maintaining traceability are larger than those related to using it or thinking its strategy. Various kinds of traceability purposes are addressed or assumed in many researches, but some researches do not specify purposes. Purposes related to changes and updates are dominant.
Haruhiko Kaiya, Ryohei Sato, Atsuo Hazeyama, Shinpei Ogata, Takao Okubo, Takafumi Tanaka, Nobukazu Yoshioka, Hironori Washizaki
KES1
2016 Modelling Goal Dependencies and Domain Model Together
abstract
Several actors such as human, organization, software applications and hardware units perform our daily activities such as medical care, entertainment and so on. We call each daily activity a socio-technical system (STS), and we also call actors except human and organizations Machines. Human and organizations in an STS become better than ever when new Machines are introduced into the STS and they are beneficial to human and organizations. Although modelling goal dependencies in such a STS contributes to identifying beneficial Machines because such a dependency can represent an actor asks some Machine to achieve his own goal. It is however not easy for modelers to describe a correct dependency. We thus proposed and exemplified an extended modelling notation called Goal Dependency Model with Objects (GDMO) based on strategic dependency (SD) in i*. In GDMO, objects related to a goal in an SD are explicitly specified. Modelers can determine an actor has the right to want the goal to be achieved because relationships between the actor and the objects such as ownership clarify the right. They can also determine another actor has the ability to achieve the goal. In addition, relationships among objects, i.e. a domain model, can suggest missing SDs, and the boundary of an STS can be determined without omission.
Haruhiko Kaiya
KES1
2016 A Metamodel for Security and Privacy Knowledge in Cloud Services
abstract
We propose a metamodel for handling security and privacy in cloud service development and operation. The metamodel is expected to be utilized for building a knowledge base to accumulate, classify and reuse existing cloud security and privacy patterns and practices in a consistent and uniform way. Moreover the metamodel and knowledge base are expected to be utilized for designing and maintaining architectures for cloud service systems incorporating security and privacy.
Hironori Washizaki, Sota Fukumoto, Misato Yamamoto, Masatoshi Yoshizawa, Yoshiaki Fukazawa, Takehisa Kato, Shinpei Ogata, Haruhiko Kaiya, Eduardo B. Fernández, Hideyuki Kanuka, Yuki Kondo, Nobukazu Yoshioka, Takao Okubo, Atsuo Hazeyama
SERVICES8
2016 Early Requirements Analysis for a Socio-Technical System Based on Goal Dependencies
abstract
A socio-technical system (STS) consists of many different actors such as people, organizations, software applications and infrastructures. We call actors except both people and organizations machines. Machines should be carefully introduced into the STS because the machines are beneficial to some people or organization but harmful to others. We thus propose a goal-oriented requirements modelling language called GDMA based on i* so that machines with the following characteristics can be systematically specified. First, machines make the goals of each people be achieved more and better than ever. Second, machines make people achieve goals fewer and easier than ever. We also propose analysis techniques of GDMA to judge whether or not the introduction of machines are appropriate or not. Several machines are introduced into an as-is model of GDMA locally with the help of model transformation techniques. Then, such an introduction is evaluated globally on the basis of metrics derived from the model structure. We confirmed that GDMA could evaluate the successful and failure of existing projects.
Haruhiko Kaiya, Shinpei Ogata, Shinpei Hayashi, Motoshi Saeki
SoMeT1
2016 Requirements Analysis for Privacy Protection and Third Party Awareness Using Logging Models
abstract
An information system can store personal information of its primary users such as shopping histories, and some third party wants or happens to know such information. Because the system usually provides its privacy policy and its users have to give their consent to it, they sometimes have to partially give up the protection of their privacy. On the other hand, a chance of a third party to know such information is too limited if the policy is too defensive. We proposed a method to explore trade-offs between protection of such information and access permissions for a third party, and exemplified it. In this method, operation logs of a system are focused. The structure of each log is then modelled for analysing what kinds of information can be accessed by a third party. Access limitations of each third party are explored so as to balance the protection of privacy information against access right of third parties.
Haruhiko Kaiya, Nobukazu Yoshioka, Takao Okubo, Hironori Washizaki, Atsuo Hazeyama
SoMeT1
2015 TESEM: A Tool for Verifying Security Design Pattern Applications by Model Testing
abstract
Because software developers are not necessarily security experts, identifying potential threats and vulnerabilities in the early stage of the development process (e.g., the requirement- or design-phase) is insufficient. Even if these issues are addressed at an early stage, it does not guarantee that the final software product actually satisfies security requirements. To realize secure designs, we propose extended security patterns, which include requirement-and design-level patterns as well as a new model testing process. Our approach is implemented in a tool called TESEM (Test Driven Secure Modeling Tool), which supports pattern applications by creating a script to execute model testing automatically. During an early development stage, the developer specifies threats and vulnerabilities in the target system, and then TESEM verifies whether the security patterns are properly applied and assesses whether these vulnerabilities are resolved.
Takanori Kobashi, Masatoshi Yoshizawa, Hironori Washizaki, Yoshiaki Fukazawa, Nobukazu Yoshioka, Takao Okubo, Haruhiko Kaiya
ICST7
2015 A Case-based Management System for Secure Software Development Using Software Security Knowledge
abstract
In recent years, importance on software security technologies has been recognized and various types of technologies have been developed. On the other hand, in spite of recognition of necessity of providing cases that deal with full life cycle for secure software development, only few are reported. This paper describes a case-based management system (CBMS) that consists of an artifact management system and a knowledge-based management system (KBMS) to manage cases for secure software development. The former manages the artifacts created in secure software life cycle. The latter manages software security knowledge. The case-based management system also manages association between artifacts and software security knowledge and supports both visualization among software security knowledge and between artifacts and software security knowledge. We conducted an experiment to evaluate the system. We describe the effectiveness and future work of the system.
Masahito Saito, Atsuo Hazeyama, Nobukazu Yoshioka, Takanori Kobashi, Hironori Washizaki, Haruhiko Kaiya, Takao Okubo
KES6
2014 Verifying Implementation of Security Design Patterns Using a Test Template
abstract
Although security patterns contain security expert knowledge to support software developers, these patterns may be inappropriately applied because most developers are not security specialists, leading to threats and vulnerabilities. Here we propose a validation method for security design patterns in the implementation phase of software development. Our method creates a test template from a security design pattern, which consists of the "aspect test template" to observe the internal processing and the "test case template". Providing design information creates a test from the test template. Because a test template is recyclable, it can create easily a test, which can validate the security design patterns. As a case study, we applied our method to a web system. The result shows that our method can test repetition in the early stage of implementation, verify pattern applications, and assess whether vulnerabilities are resolved.
Masatoshi Yoshizawa, Takanori Kobashi, Hironori Washizaki, Yoshiaki Fukazawa, Takao Okubo, Haruhiko Kaiya, Nobukazu Yoshioka
ARES6
2014 Security and Privacy Behavior Definition for Behavior Driven Development
Takao Okubo, Yoshio Kakizaki, Takanori Kobashi, Hironori Washizaki, Shinpei Ogata, Haruhiko Kaiya, Nobukazu Yoshioka
PROFES6
2013 Validating Security Design Patterns Application Using Model Testing
abstract
Software developers are not necessarily security specialists, security patterns provide developers with the knowledge of security specialists. Although security patterns are reusable and include security knowledge, it is possible to inappropriately apply a security pattern or that a properly applied pattern does not mitigate threats and vulnerabilities. Herein we propose a method to validate security pattern applications. Our method provides extended security patterns, which include requirement- and design-level patterns as well as a new model testing process using these patterns. Developers specify the threats and vulnerabilities in the target system during an early stage of development, and then our method validates whether the security patterns are properly applied and assesses whether these vulnerabilities are resolved.
Takanori Kobashi, Nobukazu Yoshioka, Takao Okubo, Haruhiko Kaiya, Hironori Washizaki, Yoshiaki Fukazawa
ARES4
2013 Enhancing Goal-Oriented Security Requirements Analysis using Common Criteria-Based Knowledge
abstract
Goal-oriented requirements analysis (GORA) is one of the promising techniques to elicit software requirements, and it is natural to consider its application to security requirements analysis. In this paper, we proposed a method for goal-oriented security requirements analysis using security knowledge which is derived from several security targets (STs) compliant to Common Criteria (CC, ISO/IEC 15408). We call such knowledge security ontology for an application domain (SOAD). Three aspects of security such as confidentiality, integrity and availability are included in the scope of our method because the CC addresses these three aspects. We extract security-related concepts such as assets, threats, countermeasures and their relationships from STs, and utilize these concepts and relationships for security goal elicitation and refinement in GORA. The usage of certificated STs as knowledge source allows us to reuse efficiently security-related concepts of higher quality. To realize our proposed method as a supporting tool, we use an existing method GOORE (goal-oriented and ontology-driven requirements elicitation method) combining with SOAD. In GOORE, terms and their relationships in a domain ontology play an important role of semantic processing such as goal refinement and conflict identification. SOAD is defined based on concepts in STs. In contrast with other goal-oriented security requirements methods, the knowledge derived from actual STs contributes to eliciting security requirements in our method. In addition, the relationships among the assets, threats, objectives and security functional requirements can be directly reused for the refinement of security goals. We show an illustrative example to show the usefulness of our method and evaluate the method in comparison with other goal-oriented security requirements analysis methods.
Motoshi Saeki, Shinpei Hayashi, Haruhiko Kaiya
Int. J. Softw. Eng. Knowl. Eng.3
2012 Model Transformation Patterns for Introducing Suitable Information Systems
abstract
When information systems are introduced in a social setting such as a business, the systems will give bad and good impacts on stakeholders in the setting. Requirements analysts have to predict such impacts in advance because stakeholders cannot decide whether the systems are really suitable for them without such prediction. In this paper, we propose a method based on model transformation patterns for introducing suitable information systems. We use metrics of a model to predict whether a system introduction is suitable for a social setting. Through a case study, we show our method can avoid an introduction of a system, which was actually bad for some stakeholders. In the case study, we use a strategic dependency model in i* to specify the model of systems and stakeholders, and attributed graph grammar for model transformation. We focus on the responsibility and the satisfaction of stakeholders as the criteria for suitability about systems introduction in this case study.
Haruhiko Kaiya, Shunsuke Morita, Shinpei Ogata, Kenji Kaijiri, Shinpei Hayashi, Motoshi Saeki
APSEC1
2011 Effective Security Impact Analysis with Patterns for Software Enhancement
abstract
Unlike functional implementations, it is difficult to analyze the impact software enhancements on security. One of the difficulties is identifying the range of effects by new security threats, and the other is developing proper countermeasures. This paper proposes an analysis process that uses two kinds of security pattern: security requirements patterns (SRP) for identifying threats and security design patterns (SDP) for identifying countermeasures at an action class level. With these two patterns and the conventional traceability methodology, developers can estimate and compare the amounts of modifications needed by multiple security countermeasures.
Takao Okubo, Haruhiko Kaiya, Nobukazu Yoshioka
ARES2
2010 Enhancing Domain Knowledge for Requirements Elicitation with Web Mining
abstract
To elicit software requirements, we have to have knowledge about a problem domain, e.g., healthcare, shopping or banking where the software is applied. A description of domain knowledge such as a domain ontology helps requirements analysts to elicit requirements completely and correctly to some extent even if they do not have such knowledge sufficiently. Several requirements elicitation methods and tools using domain knowledge description have been thus proposed, but how to develop and to enhance such description is rarely discussed. Summarizing existing documents related to the domain is one of the typical ways to develop such description, and an interview to domain experts is another typical way. However, requirements cannot be elicited completely only with such domain-specific knowledge because a user of such knowledge, i.e., a requirements analyst is not a domain expert in general. Requirements could be also elicited more correctly with both specific and general knowledge because general knowledge sometimes improves understandings of analysts about domain-specific knowledge. In this paper, we propose a method and a tool to enhance an ontology of domain knowledge for requirements elicitation by using Web mining. In our method and our tool, a domain ontology consists of concepts and their relationships. Our method and tool helps an analyst with a domain ontology to mine general concepts necessary for his requirements elicitation from documents on Web and to add such concepts to the ontology. We confirmed enhanced ontologies contribute to improving the completeness and correctness of elicited requirements through a comparative experiment.
Haruhiko Kaiya, Yuutarou Shimizu, Hirotaka Yasui, Kenji Kaijiri, Motoshi Saeki
APSEC1
2010 Towards an Integrated Support for Traceability of Quality Requirements using Software Spectrum Analysis
Haruhiko Kaiya, Kasuhisa Amemiya, Yuutarou Shimizu, Kenji Kaijiri
ICSOFT (2)1
2009 Spectrum Analysis for Quality Requirements by Using a Term-Characteristics Map
Haruhiko Kaiya, Masaaki Tanigawa, Shunichi Suzuki, Tomonori Sato, Kenji Kaijiri
CAiSE1
2009 Detecting Regulatory Vulnerability in Functional Requirements Specifications
Motoshi Saeki, Haruhiko Kaiya, Satoshi Hattori
ICSOFT (1)2
2009 A Tool for Attributed Goal-Oriented Requirements Analysis
abstract
This paper presents an integrated supporting tool for Attributed Goal-Oriented Requirements Analysis (AGORA), which is an extended version of goal-oriented analysis. Our tool assists seamlessly requirements analysts and stakeholders in their activities throughout AGORA steps including constructing goal graphs with group work, prioritizing goals, and version control of goal graphs.
Motoshi Saeki, Shinpei Hayashi, Haruhiko Kaiya
ASE3
2008 Supporting the Elicitation of Requirements Compliant with Regulations
Motoshi Saeki, Haruhiko Kaiya
CAiSE2
2008 So/M: A Requirements Definition Tool Using Characteristics of Existing Similar Systems
abstract
During a software system development, existing similar systems are useful because such systems and their documents help developers to understand and reuse problems and solutions of the new system. Especially, such helps are effective if developers are not familiar with the new system. In this paper, we present a supporting tool called "So/M" for an analyst to define software requirements. By using So/M, the analyst can easily refer functions of existing similar systems, their commonality and the relationships among them. So/M also enables the analyst to choose the candidate of requirements, and to generate the skeleton of requirements. During a comparative experiment, we have confirmed that So/M significantly helped analysts unfamiliar with a system to be developed.
Naoyuki Kitazawa, Akira Osada, Kazuyuki Kamijo, Haruhiko Kaiya, Kenji Kaijiri
COMPSAC4
2008 Metrics for a Model Driven Development Context
Motoshi Saeki, Haruhiko Kaiya
ENASE2
2008 Supporting Requirements Change Management in Goal Oriented Analysis
abstract
Requirements changes frequently occur at any time of a software development process and their management is a crucial issue to develop software of high quality. Meanwhile, recently goal-oriented analysis techniques are being put into practice to elicit requirements. In this situation, the change management of goal graphs and its support is necessary. This paper presents two topics related to change management of goal graphs; 1) version control of goal graphs and 2) impact analysis on a goal graph when its modifications occur. In our version control system, we extract the differences between successive versions of a goal graph by means of monitoring modification operations performed through a goal graph editor, and store them in a repository. Our impact analysis detects conflicts that arise when a new goal is added, and investigates the achievability of the other goals when the existing goal is deleted.
Daisuke Tanabe, Kohei Uno, Kinji Akemine, Takashi Yoshikawa, Haruhiko Kaiya, Motoshi Saeki
RE5
2007 Effects of Thesaurus in Requirements Elicitation
Junzo Kato, Motoshi Saeki, Atsushi Ohnishi, Haruhiko Kaiya, Shuichiro Yamamoto
RCIS4
2006 Japanese Workshop on Requirements Engineering Tools (JWRET)
abstract
Requirements Engineering begins to attract attention as a trump letting a project succeed and software improve its reliability. There already exist a lot of research results in requirements engineering area, and they seem to be helpful for practitioners. However, it is not so easy to use such research results because most of them do not provide stable and scalable tool support. One of the reasons is that tasks in requirements engineering highly depend on human decisions and/or insights and it seems to be hard to achieve such tasks systematically and automatically. Of course, we can find several tools to support requirements engineering process. For example, there is a survey of requirements management tools in INCOSE site [1]. Tools for goal oriented requirements analysis can be found in [2] and [3]. One of the common points of such tools is they are really helpful to achieve human-centric tasks in requirements engineering. Therefore, we have to explore what kinds of systematic or automatic support could be provided to improve humancentric tasks in requirements engineering. That is the reason why we plan this workshop. In this workshop, participants will explore tools to support requirements processes: e.g. requirements elicitation, requirement specification, requirements validation, or requirements management.
Takako Nakatani, Haruhiko Kaiya
ASE2
2006 Using Domain Ontology as Domain Knowledge for Requirements Elicitation
abstract
Domain knowledge is one of crucial factors to get a great success in requirements elicitation of high quality, and only domain experts, not requirements analysts, have it. We propose a new requirements elicitation method ORE (ontology based requirements elicitation), where a domain ontology can be used as domain knowledge. In our method, a domain ontology plays a role on semantic domain which gives meanings to requirements statements by using a semantic function. By using inference rules on the ontology and a quality metrics on the semantic function, an analyst can be navigated which requirements should be added for improving completeness of the current version of the requirements and/or which requirements should be deleted from the current version for keeping consistency. We define this process as a method and evaluate it by an experimental case study of software music players
Haruhiko Kaiya, Motoshi Saeki
RE1
2005 Improving the detection of requirements discordances among stakeholders
Haruhiko Kaiya, Daisuke Shinbara, Jinichi Kawano, Motoshi Saeki
Requir. Eng.1
2004 Weaving Multiple Viewpoint Specifications in Goal Oriented Requirements Analysis
abstract
Goal oriented requirements analysis is one of the useful method to bridge the gaps between stakeholders needs and a requirements specification. Goals are structured as a directed graph, and its upper parts show the needs and its lower parts show the requirements. Although goals come from several different viewpoints, such viewpoints are not separated explicitly in such a goal graph. As a result, following kinds of problems can be occurred. First, we cannot easily remove or modify one viewpoint which affects several different goals. Second, it is difficult to analyze several different viewpoints separately and/or incrementally. For example, we cannot analyze a family of products simultaneously. Third, such a graph is not intrinsically scalable. In this paper, we propose a method to weave several goal graphs each of which represents a viewpoint. Several candidates of a weaved graph are systematically generated based on the structural characteristics of graphs for each viewpoint. By using this method, we can overcome the problems above, and we can easily propose alternative requirements specification if a specification is rejected by stakeholders.
Haruhiko Kaiya, Motoshi Saeki
APSEC1
2004 FC Method: A Practical Approach to Improve Quality and Efficiency of Software Processes for Embedded System Revision
abstract
We introduce a design method for revising embedded software system. Engineers can accept requirements changes of hardware components and functions reasonably because design documents are managed in small unit. We can apply this method stepwise because this method can be coped with a development process that heavily depends on the hardware structure. We report an application of this method in our company so as to validate it. From the application, we can confirm that the quality of software was improved about in twice, and that efficiency of development process was also improved over three times.
Kazuma Aizawa, Haruhiko Kaiya, Kenji Kaijiri
COMPSAC2
2004 Identifying Stakeholders and Their Preferences about NFR by Comparing Use Case Diagrams of Several Existing Systems
Haruhiko Kaiya, Akira Osada, Kenji Kaijiri
RE1
2003 PAORE: Package Oriented Requirements Elicitation
abstract
We propose a new requirements elicitation method in the domains of ERP, CRM, and SCM by using specifications of several existing package software. We have analyzed the requirements elicitation processes of experienced analysts in a specific domain, and found that they clarify requirements by referring the specifications of existing packages that seem to be satisfied with customer's needs. This process can be formulated into two subprocesses: 1) package selection, where an analyst compares the customer's needs with functions/nonfunctions of packages and selects the suitable candidates of packages; and 2) requirements evolution, where he examines the selected packages with his customer and an approved part of specifications of packages are added into their requirements. The proposed method, called PAORE (package oriented requirements elicitation method) is designed based on the analysis. We applied this method to a simple but realistic example of Web-based sales supporting system and assessed it.
Junzo Kato, Morio Nagata, Shuichiro Yamamoto, Motoshi Saeki, Haruhiko Kaiya, Hisayuki Horai, Atsushi Ohnishi, Seiichi Komiya, Kenji Watahiki
APSEC5
2003 VDM over PSP: A Pilot Course for VDM Beginners to Confirm its Suitability for Their Development
abstract
Although formal methods seem to be useful, there is no clear way for beginners to know whether the methods are suitable for them and for their problem domain, before using the methods in practice. We propose a method to confirm the suitability of a formal method. The method is realized as a pilot course based on the PSP. A course mentioned in this paper is designed for a typical formal method, VDM. Our course also helps beginners of VDM to learn VDM gradually and naturally. During the course, they can confirm its suitability as follows; first, they practice several exercises for software development, while techniques of VDM are introduced gradually. Second, process data and product data of software development are recorded in each exercise. Third, by evaluating these data by several metrics, they can confirm the suitability of VDM for their work.
Hisayuki Suzumori, Haruhiko Kaiya, Kenji Kaijiri
COMPSAC2
2003 Trade-off Analysis between Security Policies for Java Mobile Codes and Requirements for Java Application
abstract
We propose a method for analyzing trade-off between security policies for Java mobile codes and requirements for Java application. We assume that mobile codes are downloaded from different sites, they are used in an application on a site, and their functions are restricted by security policies on the site. We clarify which functions to be performed under the policies on the site using our tool [H. Kaiya et al., (2002)]. We also clarify which functions are needed so as to meet the requirements for the application by goal oriented requirements analysis (GORA). By comparing functions derived from the policies and functions from the requirements, we find conflicts between the policies and the requirements, and also find vagueness of the requirements.
Haruhiko Kaiya, Kouta Sasaki, Yasunori Maebashi, Kenji Kaijiri
RE1
2002 AGORA: Attributed Goal-Oriented Requirements Analysis Method
abstract
This paper presents an extended version of the goal-oriented requirements analysis method called AGORA, where attribute values, e.g. contribution values and preference matrices, are added to goal graphs. An analyst attaches contribution values and preference values to edges and nodes of a goal graph respectively during the process for refining and decomposing the goals. The contribution value of an edge stands for the degree of the contribution of the sub-goal to the achievement of its parent goal, while the preference matrix of a goal represents the preference of the goal for each stakeholder. These values can help an analyst to choose and adopt a goal from the alternatives of the goals, to recognize the conflicts among the goals, and to analyze the impact of requirements changes. Furthermore the values on a goal graph and its structural characteristics allow the analyst to estimate the quality of the resulting requirements specification, such as correctness, unambiguity, completeness etc. The estimated quality values can suggest which goals should be improved and/or refined. In addition, we have applied AGORA to a user account system and assessed it.
Haruhiko Kaiya, Hisayuki Horai, Motoshi Saeki
RE1
1999 Conducting Requirements Evolution by Replacing Components in the Current System
abstract
As new software components become available for an existing system, we can evolve not only the system itself but also its requirements based on the new components. We propose a method to support requirements evolution by replacing a component with another component, and by changing the current requirements so as to adapt to the new component. To explore the possibilities of such a replacement, we use the technique of specification matching. To change the current requirements, we modify the structure by following the concept of Design by Contract.
Haruhiko Kaiya, Kenji Kaijiri
APSEC1
1995 Building the Structure of Specification Documents from Utterances of Requirements Elicitation Meetings
abstract
In the process of requirements elicitation in software development, it is usual for participants with different roles to have a series of meetings and requirements analysts to compose specification documents between the meetings. There have many studies supporting these processes, such as cooperative working models in meetings, tools based on those models, and specification and design methods such as structured analyses and object-oriented analysis. However, there have been no studies describing specification documents based on contents of meetings. Participants communicate verbally with each other, so we consider that an effective method should be based on verbal histories. i.e. utterances appearing in meetings. We propose a method to write specification documents considering that structures of meetings are reflected into structures of specification documents. Briefly, the assumed basis of our method is that analysts put pairs of subsequently discussed topics (we call them "temporally adjacent topics") into close positions in the tree structures of the specification documents. We also assess the feasibility and the effectiveness of the method through several experiments and case studies.
Nobuyuki Miura, Haruhiko Kaiya, Motoshi Saeki
APSEC2