VLDB 2026 Research / reviewers in the wild / expert
Paolo Giorgini
dblp:g/PaoloGiorgini
· DBLP profile ↗
98ranked-venue papers
10as first author
7since 2021 · last 2026
0000-0003-4152-9683ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 43 · 4 first-author · 3 since 2021Databases, data management, data science and information retrieval · 33 · 4 first-author · 3 since 2021Artificial intelligence and machine learning · 19 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 10Security and privacy · 4Human-computer interaction and ubiquitous computing · 2Theory of computation · 2Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Consent under control with ProPrivacy: Business process compliance verification for GDPR-consent requirementsabstractContext: Since its enforcement in 2018, the General Data Protection Regulation (GDPR) has continued to shape how organizations, in the European Economic Area, design and operate their data-driven services. Consent management, in particular, remains a cornerstone of compliance, but it has also become increasingly complex with the rise of data-intensive business models, digital health platforms, and AI-powered services. Despite the availability of technical and organizational tools, many companies still struggle to adapt legacy and large-scale processes to meet GDPR’s consent requirements. Knowledge about these processes is often fragmented across organizational silos, and documentation is incomplete, making re-engineering activities both tedious and error-prone. Objectives: Companies relies on experts for the re-engineering and validation of their processes, while a comprehensive method is still missing to support them in verifying the compliance of their processes with consent. To address these challenges, this paper proposes a model-based approach that supports business and privacy experts in aligning operational processes with GDPR consent principles. Methods.: Rather than introducing a new language that would require analysts modeling processes from scratch, our framework, ProPrivacy, builds on the widely adopted Business Process Model and Notation 2.0 (BPMN 2.0) modeling language, allowing analysts to enrich existing models with consent requirements. To mitigate verification errors and reduce the effort in analyzing complex models, ProPrivacy then automatically verifies compliance with key GDPR principles related to specific and freely given consent and data minimization. We demonstrate the applicability and scalability of our approach on realistic processes from the healthcare domain, where the management of sensitive data continues to present critical privacy challenges. Conclusions: The results suggest that automated verification of business processes can not only support organizations in achieving compliance with GDPR but also serve as a foundation for certifying accountable and transparent business processes. Marco Robol, Mattia Salnitri, Elda Paja, Paolo Giorgini |
Inf. Softw. Technol. | 4 |
| 2024 | LLM-Driven Knowledge Extraction in Temporal and Description Logics
Damiano Duranti, Paolo Giorgini, Andrea Mazzullo, Marco Robol, Marco Roveri |
EKAW | 2 |
| 2024 | MOOD: Mindfulness fOr sOftware DevelopersabstractPeopleware, which includes anything related to the role of people in Software Development (SD), has been arousing an increasing interest from both the software industry and research community. This interest is due to the current economic system that demands high-quality software products with a short time to market, staying on the budget. This exposes software developers to the risk of experiencing stress, burnout, and reduced motivation, leading, in turn, to reduced job performance, low-quality SD-related artifacts, and increased turnover. Mindfulness represents a promising intervention that might let developers do their best at work, limiting or even preventing the previously mentioned negative outcomes. This paper presents MOOD (Mindfulness fOr sOftware Developers), a research project whose overarching goal is to customize a well-known and validated group-based intervention program, Mindfulness-Based Stress Reduction (MBSR), in the context of SD-related tasks and assess whether it helps developers to improve their well-being and performance, as well as the quality of the SD-related artifacts they produce. Simone Romano 0001, Giuseppe Scanniello, Alessandro Marchetto 0001, Paolo Giorgini, Gloria Guidetti, Daniela Converso, Sara Viotti |
ESEM | 4 |
| 2023 | Consent Verification MonitoringabstractAdvances in personalization of digital services are driven by low-cost data collection and processing, in addition to the wide variety of third-party frameworks for authentication, storage, and marketing. New privacy regulations, such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act, increasingly require organizations to explicitly state their data practices in privacy policies. When data practices change, a new version of the policy is released. This can occur a few times a year, when data collection or processing requirements are rapidly changing. Consent evolution raises specific challenges to ensuring GDPR compliance. We propose a formal consent framework to support organizations, data users, and data subjects in their understanding of policy evolution under a consent regime that supports both the retroactive and non-retroactive granting and withdrawal of consent. The contributions include (i) a formal framework to reason about data collection and access under multiple consent granting and revocation scenarios, (ii) a scripting language that implements the consent framework for encoding and executing different scenarios, (iii) five consent evolution use cases that illustrate how organizations would evolve their policies using this framework, and (iv) a scalability evaluation of the reasoning framework. The framework models are used to verify when user consent prevents or detects unauthorized data collection and access. The framework can be integrated into a runtime architecture to monitor policy violations as data practices evolve in real time. The framework was evaluated using the five use cases and a simulation to measure the framework scalability. The simulation results show that the approach is computationally scalable for use in runtime consent monitoring under a standard model of data collection and access and practice and policy evolution. Marco Robol, Travis D. Breaux, Elda Paja, Paolo Giorgini |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2022 | Real-Time BDI Agents: A Model and Its ImplementationabstractThe BDI model proved to be effective for the developing of applications requiring high-levels of autonomy and to deal with the complexity and unpredictability of real-world scenarios. The model, however, has significant limitations in reacting and handling contingencies within the given real-time constraints. Without an explicit representation of time, existing real-time BDI implementations overlook the temporal implications during the agent’s decision process that may result in delays or unresponsiveness of the system when it gets overloaded. In this paper, we redefine the BDI agent control loop inspired by traditional and well establish algorithms for real-time systems to ensure a proper reaction of agents and their effective application in typical real-time domains. Our model proposes an effective real-time management of goals, plans, and actions with respect to time constraints and resources availability. We propose an implementation of the model for a resource-collection video-game and we validate the approach against a set of significant scenarios. Andrea Traldi, Francesco Bruschetti, Marco Robol, Marco Roveri, Paolo Giorgini |
IJCAI | 5 |
| 2022 | Editorial
Paolo Giorgini, Barbara Weber |
Inf. Syst. | 1 |
| 2021 | COPri v.2 - A core ontology for privacy requirements
Mohamad Gharib, Paolo Giorgini, John Mylopoulos |
Data Knowl. Eng. | 2 |
| 2020 | COPri - A Core Ontology for Privacy Requirements Engineering
Mohamad Gharib, John Mylopoulos, Paolo Giorgini |
RCIS | 3 |
| 2020 | Modelling the interplay of security, privacy and trust in sociotechnical systems: a computer-aided design approach
Mattia Salnitri, Konstantinos Angelopoulos, Michalis Pavlidis, Vasiliki Diamantopoulou, Haralambos Mouratidis, Paolo Giorgini |
Softw. Syst. Model. | 6 |
| 2019 | Design Thinking and Acceptance Requirements for Designing Gamified SoftwareabstractGamification is increasingly applied to engage people in performing tool-supported collaborative tasks. From previous experiences we learned that available gamification guidelines are not sufficient, and more importantly that motivational and acceptance aspects need to be considered when designing gamified software applications. To understand them, stakeholders need to be involved in the design process. This paper aims to (i) identify key requirements for designing gamified solutions, and (ii) understand if existing methods (partially fitting those requirements) can be selected and combined to provide a comprehensive gamification design method. We discuss a set of key requirements for a suitable gamification design method. We illustrate how to select and combine existing methods to define a design approach that fits those requirements usingDesign Thinking and the Agon framework. Furthermore, we present a first empirical evaluation of the integrated design method, with participants including both requirements analysts and end-users of the gamified software. Our evaluation offers initial ideas towards a more general, systematic approach for gamification design. Luca Piras 0003, Daniele Dellagiacoma, Anna Perini, Angelo Susi, Paolo Giorgini, John Mylopoulos |
RCIS | 5 |
| 2019 | Consent Verification Under Evolving Privacy PoliciesabstractPersonal data provides important business value, for example, in the personalization of services. In addition, companies are moving toward new business models, in which products and services are offered without charge to users, but in exchange for targeted advertising revenue. New privacy regulations require organizations to explicitly state their data practices in privacy policies, including which data types will be collected. By consenting to data collections described in a policy, the user acknowledges that he or she is granting the company the authorizations needed to access their data. When data practices change, a new version of the policy is released. This release can occur a few times a year, when requirements are rapidly changing for the collection and processing of personal data. Furthermore, the user may change his or her privacy consent by opting in or out of the policy. We propose a formal framework to support companies and users in their understanding of policies evolution under consent regime that supports both retroactive and non-retroactive consent and consent revocation. Preliminary results include an ontology for policy evolution, expressed in Description Logic, that can be used to formalize consent and data collection logs and then query for which data types can be legally accessed. Marco Robol, Travis D. Breaux, Elda Paja, Paolo Giorgini |
RE | 4 |
| 2019 | Information quality requirements engineering with STS-IQ
Mohamad Gharib, Paolo Giorgini |
Inf. Softw. Technol. | 2 |
| 2019 | Goal-oriented requirements engineering: an extended systematic mapping studyabstractOver the last two decades, much attention has been paid to the area of goal-oriented requirements engineering (GORE), where goals are used as a useful conceptualization to elicit, model, and analyze requirements, capturing alternatives and conflicts. Goal modeling has been adapted and applied to many sub-topics within requirements engineering (RE) and beyond, such as agent orientation, aspect orientation, business intelligence, model-driven development, and security. Despite extensive efforts in this field, the RE community lacks a recent, general systematic literature review of the area. In this work, we present a systematic mapping study, covering the 246 top-cited GORE-related conference and journal papers, according to Scopus. Our literature map addresses several research questions: we classify the types of papers (e.g., proposals, formalizations, meta-studies), look at the presence of evaluation, the topics covered (e.g., security, agents, scenarios), frameworks used, venues, citations, author networks, and overall publication numbers. For most questions, we evaluate trends over time. Our findings show a proliferation of papers with new ideas and few citations, with a small number of authors and papers dominating citations; however, there is a slight rise in papers which build upon past work (implementations, integrations, and extensions). We see a rise in papers concerning adaptation/variability/evolution and a slight rise in case studies. Overall, interest in GORE has increased. We use our analysis results to make recommendations concerning future GORE research and make our data publicly available. Jennifer Horkoff, Fatma Basak Aydemir, Evellin Cardoso, Tong Li 0001, Alejandro Maté, Elda Paja, Mattia Salnitri, Luca Piras 0003, John Mylopoulos, Paolo Giorgini |
Requir. Eng. | 10 |
| 2018 | The Next Release Problem Revisited: A New Avenue for Goal ModelsabstractContext. Goal models have long been critiqued for the time it takes to construct them as well as for their limited cognitive and visual scalability. Is such criticism general or does it depend on the supported task? Objectives. We advocate for the latter and the aim of this paper is to demonstrate that the next release problem is a suitable application domain for goal models. This hypothesis stems from the fact that product release management is a long-term investment, and software products are commonly managed in "themes" which are smaller focus areas of the product. Methods. We employ a version of goal models that is tailored for the next release problem by capturing requirements, synergies among them, constraints, and release objectives. Such goal model allows discovering optimal solutions considering multiple criteria for the next release. Results. A retrospective case study confirms that goal models are easier to read and comprehend when organized in themes, and that the reasoning results help product managers decide for the next release. Our scalability experiments show that, through reasoning based on optimization modulo theories, the discovery of the optimal solution is fast and scales sufficiently well with respect to the model size, connectivity, and number of alternative solutions. Fatma Basak Aydemir, Fabiano Dalpiaz, Sjaak Brinkkemper, Paolo Giorgini, John Mylopoulos |
RE | 4 |
| 2018 | Analysis of information quality requirements in business processes, revisited
Mohamad Gharib, Paolo Giorgini, John Mylopoulos |
Requir. Eng. | 2 |
| 2018 | Multi-objective reasoning with constrained goal models
Chi Mai Nguyen, Roberto Sebastiani, Paolo Giorgini, John Mylopoulos |
Requir. Eng. | 3 |
| 2017 | A Holistic Approach for Privacy Protection in E-GovernmentabstractImproving e-government services by using data more effectively is a major focus globally. It requires Public Administrations to be transparent, accountable and provide trustworthy services that improve citizen confidence. However, despite all the technological advantages on developing such services and analysing security and privacy concerns, the literature does not provide evidence of frameworks and platforms that enable privacy analysis, from multiple perspectives, and take into account citizens' needs with regards to transparency and usage of citizens information. This paper presents the VisiOn (Visual Privacy Management in User Centric Open Requirements) platform, an outcome of a H2020 European Project. Our objective is to enable Public Administrations to analyse privacy and security from different perspectives, including requirements, threats, trust and law compliance. Finally, our platform-supported approach introduces the concept of Privacy Level Agreement (PLA) which allows Public Administrations to customise their privacy policies based on the privacy preferences of each citizen. Konstantinos Angelopoulos, Vasiliki Diamantopoulou, Haralambos Mouratidis, Michalis Pavlidis, Mattia Salnitri, Paolo Giorgini, José Fran. Ruiz |
ARES | 6 |
| 2017 | Towards an Ontology for Privacy Requirements via a Systematic Literature Review
Mohamad Gharib, Paolo Giorgini, John Mylopoulos |
ER | 2 |
| 2017 | Goal Models for Acceptance Requirements Analysis and Gamification Design
Luca Piras 0003, Elda Paja, Paolo Giorgini, John Mylopoulos |
ER | 3 |
| 2017 | From Secure Business Process Modeling to Design-Level Security VerificationabstractTracing and integrating security requirements throughout the development process is a key challenge in security engineering. In socio-technical systems, security requirements for the organizational and technical aspects of a system are currently dealt with separately, giving rise to substantial misconceptions and errors. In this paper, we present a model-based security engineering framework for supporting the system design on the organizational and technical level. The key idea is to allow the involved experts to specify security requirements in the languages they are familiar with: business analysts use BPMN for procedural system descriptions; system developers use UML to design and implement the system architecture. Security requirements are captured via the language extensions SecBPMN2 and UMLsec. We provide a model transformation to bridge the conceptual gap between SecBPMN2 and UMLsec. Using UMLsec policies, various security properties of the resulting architecture can be verified. In a case study featuring an air traffic management system, we show how our framework can be practically applied. Qusai Ramadan, Mattia Salnitri, Daniel Strüber 0001, Jan Jürjens, Paolo Giorgini |
MoDELS | 5 |
| 2017 | Gamification solutions for software acceptance: A comparative study of Requirements Engineering and Organizational Behavior techniquesabstractGamification is a powerful paradigm and a set of best practices used to motivate people carrying out a variety of ICT-mediated tasks. Designing gamification solutions and applying them to a given ICT system is a complex and expensive process (in time, competences and money) as software engineers have to cope with heterogeneous stakeholder requirements on one hand, and Acceptance Requirements on the other, that together ensure effective user participation and a high level of system utilization. As such, gamification solutions require significant analysis and design as well as suitable supporting tools and techniques. In this work, we compare concepts, tools and techniques for gamification design drawn from Software Engineering and Human and Organizational Behaviors. We conduct a comparison by applying both techniques to the specific Meeting Scheduling exemplar used extensively in the Requirements Engineering literature. Luca Piras 0003, Elda Paja, Paolo Giorgini, John Mylopoulos, Roberta Cuel, Diego Ponte |
RCIS | 3 |
| 2017 | Modeling and Reasoning on Requirements Evolution with Constrained Goal Models
Chi Mai Nguyen, Roberto Sebastiani, Paolo Giorgini, John Mylopoulos |
SEFM | 3 |
| 2017 | Designing secure business processes with SecBPMN
Mattia Salnitri, Fabiano Dalpiaz, Paolo Giorgini |
Softw. Syst. Model. | 3 |
| 2016 | Modeling Structured and Unstructured Processes: An Empirical Evaluation
Evellin Cardoso, Katsiaryna Labunets, Fabiano Dalpiaz, John Mylopoulos, Paolo Giorgini |
ER | 5 |
| 2016 | Requirements Evolution and Evolution Requirements with Constrained Goal Models
Chi Mai Nguyen, Roberto Sebastiani, Paolo Giorgini, John Mylopoulos |
ER | 3 |
| 2016 | Solving the next adaptation problem with prometheusabstractDealing with multiple requirement failures is an essential capability for self-adaptive software systems. This capability becomes more challenging in the presence of conflicting goals. This paper is concerned with the next adaptation problem: the problem of finding the best next adaptation in the presence of multiple failures. ‘Best’ here means that the adaptation chosen optimizes a given set of objective functions, such as the cost of adaptation or the degree of failure for system requirements. The paper proposes a formal framework for defining the next adaptation problem, assuming that we can specify quantitatively the constraints that hold between indicators that measure the degree of failure of each requirement and control parameters. These constraints, along with one or several objective functions, are translated into a constrained multi-objective optimization problem that can be solved by using an OMT/SMT (Optimization Modulo Theories/Satisfiability Modulo Theories) solver, such as OptiMathSAT. The proposed framework is illustrated with the Meeting Scheduler exemplar and a second, e-shop case study. Konstantinos Angelopoulos, Fatma Basak Aydemir, Paolo Giorgini, John Mylopoulos |
RCIS | 3 |
| 2016 | Multi-objective risk analysis with goal modelsabstractRisks of software projects are often ignored and risk analysis is left for later stages of project life-cycle, resulting in serious financial losses. This paper proposes a goal-oriented risk analysis framework that includes inter-dependencies among treatments and risks in terms of likelihood and generate optimal solutions with respect to multiple objectives such as goal rewards, treatment costs, or risk factor. The Loan Origination Process illustrates our approach and a detailed analysis of the visual notation is provided. Fatma Basak Aydemir, Paolo Giorgini, John Mylopoulos |
RCIS | 2 |
| 2016 | Privacy Requirements: Findings and Lessons Learned in Developing a Privacy PlatformabstractInformation practices and systems that make use of personal and health-related information are governed by European laws and regulations to prevent unauthorized use and disclosure. Failure to comply with these laws and regulations results in huge monetary sanctions, which both private companies and public administrations want to avoid. How to comply with these laws, requires understanding the privacy requirements imposed on information systems. A holistic approach to privacy requirements specification calls for understanding not only the requirements derived from law, but also citizens' needs with respect to privacy. In this paper, we report on our experience in conducting privacy requirements engineering as part of a H2020 European Project, namely VisiOn (Visual Privacy Management in User Centric Open Requirements) for the development of a privacy platform to improve the interaction between Public Administrations (PA) and citizens, while guarding the privacy of the latter. Specifically, we present the process for eliciting, classifying, prioritizing, and validating privacy requirements for the two types of users, namely PA and citizen. The process is applied to different cases spanning from healthcare to other e-governmental initiatives, with the active involvement of the corresponding PAs. We report on findings and lessons learned from this experience. Mohamad Gharib, Mattia Salnitri, Elda Paja, Paolo Giorgini, Haralambos Mouratidis, Michalis Pavlidis, José Fran. Ruiz, Sandra Fernandez, Andrea Della Siria |
RE | 4 |
| 2016 | Goal-Oriented Requirements Engineering: A Systematic Literature MapabstractOver the last two decades, much attention has been paid to the area of Goal-Oriented Requirements Engineering(GORE), where goals are used as a useful conceptualization to elicit, model and analyze requirements, capturing alternatives and conflicts. Goal modeling has been adapted and applied to many sub-topics within RE and beyond, such as agent-orientation, aspect-orientation, business intelligence, model-driven development, security, and so on. Despite extensive efforts in this field, the RE community lacks a recent, general systematic literature review of the area. As a first step towards providing a GORE overview, we present a Systematic Literature Map, focusing on GORE-related publications at a high-level, categorizing and analyzing paper information in order to answer several research questions, while omitting a detailed analysis of individual paper quality. Our Literature Map covers the 246 top-cited GORE-related conference and journal papers, according to Scopus, classifying them into a number of descriptive paper types and topics, providing an analysis of the data, which is made publicly available. We use our analysis results to make recommendations concerning future GORE research. Jennifer Horkoff, Fatma Basak Aydemir, Evellin Cardoso, Tong Li 0001, Alejandro Maté, Elda Paja, Mattia Salnitri, John Mylopoulos, Paolo Giorgini |
RE | 9 |
| 2016 | Acceptance Requirements and Their Gamification SolutionsabstractWe live in the days of social software where social interactions, from simple notifications to complex business processes, are supported by software platforms such as Facebook and Twitter. But for any social software to be successful, it must be used by a sizeable portion of its intended user community. Usage requirements are usually referred to as Acceptance Requirements and they have been studied in the literature both for general technology as well as software. Operationalization techniques for such requirements often consist of making a game out of software usage where users are rewarded/penalized depending onthe degree of their participation. The game may be competitive or non-competitive, depending on the anticipated personality traits of intended users. Making a game out of usage is often referred to as Gamification, and gamification has attracted huge attention in the literature for the past few years because it offers a novelapproach to software technology usage. This paper proposes a generic framework for designing gamified solutions for acceptance requirements. The framework consists of a generic acceptance goal model that characterizes the problem space by capturing possible refinements for acceptance requirements, and a generic gamification model that capturespossible gamified operationalizations of acceptance requirements. These models have been extracted from the literature and they are highly dependent on context (cognitive and social) elements of the intended user community. The proposed framework isillustrated with the Meeting Scheduler exemplar. Luca Piras 0003, Paolo Giorgini, John Mylopoulos |
RE | 2 |
| 2016 | Towards an Integrated Platform for Adaptive Socio-technical Systems for Smart SpacesabstractThe widespread availability of mobile devices equipped with sensors on board is strongly pushing towards the development of smart spaces -- offices, streets, hospital, airports, homes and shops equipped with sensing systems to help people find relevant information quickly and use services comfortably, often in a collaborative way. A common aspect in these scenarios is that the technology complexity is amplified by the organisational and procedural complexity of the application domain: this is in fact typical of socio-technical systems -- kinds of systems that inherently need to be conceived, designed and developed taking into account both the technological and the human/organisational aspects from the earliest stages. In this paper, we select and discuss some challenges in the definition and development of adaptive socio-technical systems for smart spaces, the selected challenges aim at focusing in particular on (i) a socio-technical model and process, (ii) a multi-level integration framework, and (iii) methods and system analysis techniques for runtime adaptation. In fact, designing such systems requires the suitable combination of enabling technologies into an operational framework, integrating and coordinating a multiplicity of processes managed by complex organisations, each made up of independent and autonomous units. Giacomo Cabri, Massimo Cossentino, Enrico Denti, Paolo Giorgini, Ambra Molesini, Monica Mordonini, Michele Tomaiuolo, Luca Sabatucci |
WETICE | 4 |
| 2015 | Social specifications of business processes with AzzurraabstractA business process is first and foremost a social interaction among multiple participants. Business process modeling languages support the description of business processes in operational terms, as collections of interleaved activities conducted by human and software agents. However, such descriptions do not capture adequately the richness of social interaction among participants. To address this deficiency, we propose Azzurra, a specification language for modeling and enacting business processes. Azzurra is founded on social concepts, such as roles, agents and commitments among them, and Azzurra specifications are social models consisting of sets of commitments. As such, Azzurra specifications support flexible executions of business processes, and provide a semantic notion of actor accountability and business process compliance. In this paper, we present syntax and semantics of Azzurra, and we propose algorithms to determine runtime compliance with an Azzurra specification. Fabiano Dalpiaz, Evellin Cardoso, Giulia Canobbio, Paolo Giorgini, John Mylopoulos |
RCIS | 4 |
| 2015 | A goal-based approach for automated specification of Information Quality policiesabstractOrganizational and social aspects are key factors for the analysis of Information Quality (IQ) requirements. This is particularly true in the case of complex socio-technical systems where computerized components coexist with humans and social structures and effective IQ policies can be defined only as a combination of all these factors. Although, several policy-based approaches have been proposed in the literature, none of them offer an adequate conceptual support to combine the technical and organizational perspective in the analysis of IQ requirements. In this paper, we propose a goal-based approach based on an extended version of Secure Tropos to model and analyze IQ requirements from a socio-technical perspective. Our approach provides mechanisms for an automatic derivation of IQ policies, which are specified in terms of permitted, forbidden and obligated activities. Verification of correctness and consistency of the derived policies are supported by automated analysis techniques. We illustrated our approach with an example concerning the stock market system. Mohamad Gharib, Paolo Giorgini |
RCIS | 2 |
| 2015 | Modeling and Reasoning About Information Quality Requirements
Mohamad Gharib, Paolo Giorgini |
REFSQ | 2 |
| 2015 | Modelling and reasoning about security requirements in socio-technical systems
Elda Paja, Fabiano Dalpiaz, Paolo Giorgini |
Data Knowl. Eng. | 3 |
| 2014 | Exploring alternative designs for sociotechnical systemsabstractSociotechnial systems (STSs) consist of a complex interplay of technical components, humans, and organizations. As other types of systems, STSs need to evolve in response to changing requirements and operational environments. Evolving STSs is a complex activity, which requires reconfiguration of technical components as well as rerouting of interactions among human and social actors. Moreover, reconfiguration has to respect participant autonomy, while coping with conflicting goals and noncooperation in identifying a configuration that minimizes changes relative to the current configuration. In this paper, we present a framework that supports design and evolution of STSs. The framework includes (i) the DEST language for modeling STSs as goal-oriented actors that interact via social commitments; (ii) techniques for building a network of interactions that fulfills participant requirements; and (iii) techniques for evolving an existing STS while minimizing change. We encode the design and evolution of STSs as an automated planning problem. Fatma Basak Aydemir, Paolo Giorgini, John Mylopoulos, Fabiano Dalpiaz |
RCIS | 2 |
| 2014 | Taking goal models downstream: A systematic roadmapabstractCreating and reasoning with goal models is useful for capturing, understanding, and communicating about requirements in the early stages of information system (re)development. However, the utility of goal models is greatly enhanced when an awareness of system intentions can feed into other stages in the requirements analysis process (e.g. requirements elaboration, validation, planning), and can be used as part of the entire system life cycle (e.g., architecture, process design, coding, testing, monitoring, adaptation, and evolution). In order to understand the progress that has been made in integrating goal models with downstream system development, we ask: what approaches exist which map/integrate/transform goal-oriented languages to other software artifacts or languages? To answer this question, we conduct a systematic survey, producing a roadmap of work summarizing 174 publications. Results include a categorization of the “why?” and “how?” for each approach. Findings show that there are a wide variety of proposals with many proposed sources and targets, covering multiple paradigms, motivated by a variety of purposes. We conclude that although much work has been done in this area, the work is fragmented and is often still in a proposal stage. Jennifer Horkoff, Tong Li 0001, Feng-Lin Li, Mattia Salnitri, Evellin Cardoso, Paolo Giorgini, John Mylopoulos, João Pimentel 0001 |
RCIS | 6 |
| 2014 | Protos: Foundations for engineering innovative sociotechnical systemsabstractWe address the challenge of requirements engineering for sociotechnical systems, wherein humans and organizations supported by technical artifacts such as software interact with one another. Traditional requirements models emphasize the goals of the stakeholders above their interactions. However, the participants in a sociotechnical system may not adopt the goals of the stakeholders involved in its specification. We motivate, Protos, a requirements engineering approach that gives prominence to the interactions of autonomous parties and specifies a sociotechnical system in terms of its participants' social relationships, specifically, commitments. The participants can adopt any goal they like, a key basis for innovative behavior, as long as they interact according to the commitments. Protos describes an abstract requirements engineering process as a series of refinements that seek to satisfy stakeholder requirements by incrementally expanding a specification set and an assumption set, and reducing requirements until all requirements are accommodated. We demonstrate this process via the London Ambulance System described in the literature. Amit K. Chopra, Fabiano Dalpiaz, Fatma Basak Aydemir, Paolo Giorgini, John Mylopoulos, Munindar P. Singh |
RE | 4 |
| 2014 | Requirements-driven deployment - Customizing the requirements model for the host environment
Raian Ali, Fabiano Dalpiaz, Paolo Giorgini |
Softw. Syst. Model. | 3 |
| 2013 | Managing Security Requirements Conflicts in Socio-Technical Systems
Elda Paja, Fabiano Dalpiaz, Paolo Giorgini |
ER | 3 |
| 2013 | Specifying and Reasoning over Socio-Technical Security Requirements with STS-Tool
Elda Paja, Fabiano Dalpiaz, Mauro Poggianella, Pierluigi Roberti, Paolo Giorgini |
ER | 5 |
| 2013 | Trust-based specification of sociotechnical systems
Elda Paja, Amit K. Chopra, Paolo Giorgini |
Data Knowl. Eng. | 3 |
| 2013 | Reasoning with contextual requirements: Detecting inconsistency and conflicts
Raian Ali, Fabiano Dalpiaz, Paolo Giorgini |
Inf. Softw. Technol. | 3 |
| 2013 | Adaptive socio-technical systems: a requirements-based approach
Fabiano Dalpiaz, Paolo Giorgini, John Mylopoulos |
Requir. Eng. | 2 |
| 2012 | Aligning Software Configuration with Business and IT Context
Fabiano Dalpiaz, Raian Ali, Paolo Giorgini |
CAiSE | 3 |
| 2012 | A NFR-Based Framework for User-Centered Adaptation
Fabiano Dalpiaz, Estefanía Serral, Pedro Valderas, Paolo Giorgini, Vicente Pelechano |
ER | 4 |
| 2012 | STS-tool: Socio-technical Security Requirements through social commitmentsabstractSecurity Requirements Engineering (SRE) deals with the elicitation and analysis of security needs to specify security requirements for the system-to-be. In previous work, we have presented STS-ml, a security requirements modelling language for Socio-Technical Systems (STSs) that elicits security needs, using a goal-oriented approach, and derives the security requirements specification based on these needs. Particularly, STS-ml relates security to the interaction among actors in the STS. In this paper, we present STS-Tool, the modelling and analysis support tool for STS-ml. STS-Tool allows designers to model a STS at a high-level of abstraction, while expressing security needs over the interactions between the actors in the STS, and derive security requirements in terms of social commitments - promises with contractual validity - once the modelling is done. Elda Paja, Fabiano Dalpiaz, Mauro Poggianella, Pierluigi Roberti, Paolo Giorgini |
RE | 5 |
| 2012 | Implicit: a multi-agent recommendation system for web search
Aliaksandr Birukou, Enrico Blanzieri, Paolo Giorgini |
Auton. Agents Multi Agent Syst. | 3 |
| 2011 | Sociotechnical Trust: An Architectural Approach
Amit K. Chopra, Elda Paja, Paolo Giorgini |
ER | 3 |
| 2011 | Goal-driven risk assessment in requirements engineering
Yudistira Asnar, Paolo Giorgini, John Mylopoulos |
Requir. Eng. | 2 |
| 2010 | Multi-dimensional Uncertainty Analysis in Secure and Dependable DomainabstractMost of the critical aspects for secure and dependable systems, such as safety, integrity, availability, are related to uncertainty. Literature proposes many approaches to deal with uncertainty, mainly in the area of risk management and safety and reliability engineering. However, what is still missing is a clear understanding of the nature of uncertainty that very often has produced mistreatments in the design. In this paper, we propose a conceptual model for uncertainty that can be used to deal with systems' qualities such as security and dependability. Particularly, we will consider the relation between uncertainty risk and how risk affects quality attributes of the system. We use a case study in Air Traffic Management to illustrate our approach. Yudistira Asnar, Paolo Giorgini |
ARES | 2 |
| 2010 | Modeling and Reasoning about Service-Oriented Applications via Goals and Commitments
Amit K. Chopra, Fabiano Dalpiaz, Paolo Giorgini, John Mylopoulos |
CAiSE | 3 |
| 2010 | Adaptation in Open Systems: Giving Interaction Its Rightful Place
Fabiano Dalpiaz, Amit K. Chopra, Paolo Giorgini, John Mylopoulos |
ER | 3 |
| 2010 | Extending Organizational Modeling with Business Services Concepts: An Overview of the Proposed Architecture
Hugo Estrada-Esquivel, Alicia Martínez Rebollar, Oscar Pastor 0001, John Mylopoulos, Paolo Giorgini |
ER | 5 |
| 2010 | Business Processes Contextualisation via Context Analysis
Jose Luis de la Vara, Raian Ali, Fabiano Dalpiaz, Juan Sánchez, Paolo Giorgini |
ER | 5 |
| 2010 | A goal-based framework for contextual requirements modeling and analysis
Raian Ali, Fabiano Dalpiaz, Paolo Giorgini |
Requir. Eng. | 3 |
| 2010 | An architectural description language for secure Multi-Agent SystemsabstractMulti-Agent Systems (MAS) architectures are gaining popularity for building open, distributed, and evolving information systems. Unfortunately, despite considerable work in the fields of software architecture and MAS during the last decade, few resea Haralambos Mouratidis, Manuel Kolp, Paolo Giorgini, Stéphane Faulkner |
Web Intell. Agent Syst. | 3 |
| 2009 | An Architecture for Requirements-Driven Self-reconfiguration
Fabiano Dalpiaz, Paolo Giorgini, John Mylopoulos |
CAiSE | 2 |
| 2009 | Designing socio-technical systems: from stakeholder goals to social networks
Volha Bryl, Paolo Giorgini, John Mylopoulos |
Requir. Eng. | 2 |
| 2008 | Analyzing Business Continuity through a Multi-layers Model
Yudistira Asnar, Paolo Giorgini |
BPM | 2 |
| 2008 | Location-Based Variability for Mobile Information Systems
Raian Ali, Fabiano Dalpiaz, Paolo Giorgini |
CAiSE | 3 |
| 2008 | Balanced Goalcards - Combining Goal Analysis and Balanced Scorecards
Alberto Siena, Alessio Bonetti, Paolo Giorgini |
ENASE | 3 |
| 2008 | Location-Based Software Modeling and Analysis: Tropos-Based Approach
Raian Ali, Fabiano Dalpiaz, Paolo Giorgini |
ER | 3 |
| 2008 | Modeling and Analyzing Variability for Mobile Information Systems
Raian Ali, Fabiano Dalpiaz, Paolo Giorgini |
ICCSA (2) | 3 |
| 2008 | GRAnD: A goal-oriented approach to requirement analysis in data warehouses
Paolo Giorgini, Stefano Rizzi, Maddalena Garzetti |
Decis. Support Syst. | 1 |
| 2007 | From Trust to Dependability through Risk AnalysisabstractThe importance of critical systems has been widely recognized and several efforts are devoted to integrate dependability requirements in their development process. Such efforts result in a number of models, frameworks, and methodologies that have been proposed to model and assess the dependability of critical systems. Among them, risk analysis considers the likelihood and severity of failures for evaluating the risk affecting the system. In our previous work, we introduced the Tropos goal-risk framework, a formal framework for modeling, assessing, and treating risks on the basis of the likelihood and severity of failures. In this paper, we refine this framework introducing the notion of trust for assessing risks on the basis of the organizational setting of the system. The assessment process is also enhanced to analyze risks along trust relations among actors. To make the discussion more concrete, we illustrate the framework with a case study on partial airspace delegation in air traffic management system Yudistira Asnar, Paolo Giorgini, Fabio Massacci, Nicola Zannone |
ARES | 2 |
| 2007 | Supporting Requirements Analysis in Tropos: A Planning-Based Approach
Volha Bryl, Paolo Giorgini, John Mylopoulos |
PRIMA | 2 |
| 2007 | Secure and Dependable Patterns in Organizations: An Empirical ApproachabstractDesigning a secure and dependable system is not just a technical issue, it involves also a deep analysis of the organizational and the social environment in which the system will operate. In this paper, we detail our experience in modeling and analyzing requirements for an industrial case (air traffic management system) using the Secure Tropos framework. Particularly, we focus on modeling and reasoning about trust and risk relations within the organizational structure; we discuss pros and cons of Secure Tropos stemming from our experience and lessons learned which might be general interests for RE methodologies. Yudistira Asnar, Paolo Giorgini, Roberto Bonato, Valentino Meduri, Carlo Riccucci |
RE | 2 |
| 2007 | Secure Tropos: a Security-Oriented Extension of the Tropos MethodologyabstractAlthough security plays an important role in the development of multiagent systems, a careful analysis of software development processes shows that the definition of security requirements is, usually considered after the design of the system. One of the reasons is the fact that agent oriented software engineering methodologies have not integrated security concerns throughout their developing stages. The integration of security concerns during the whole range of the development stages can help in the development of more secure multiagent systems. In this paper we introduce extensions to the Tropos methodology to enable it to model security concerns throughout the whole development process. A description of the new concepts and modelling activities is given together with a discussion on how these concepts and modelling activities are integrated to the current stages of Tropos. A real life case study from the health and social care sector is used to illustrate the approach. Haralambos Mouratidis, Paolo Giorgini |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2007 | Security Attack Testing (SAT) - testing the security of information systems at design time
Haralambos Mouratidis, Paolo Giorgini |
Inf. Syst. | 2 |
| 2006 | Modelling Risk and Identifying Countermeasure in Organizations
Yudistira Asnar, Paolo Giorgini |
CRITIS | 2 |
| 2006 | Detecting Conflicts of InterestabstractSystem vulnerabilities are often caused by the presence of conflicts within the organization where the system-to-be would eventually operate. In particular, conflicts of interest are very harmful since actors can exploit their positions/roles relative to the system for gaining personal advantage. Capturing and resolving such conflicts is a necessary condition for developing secure information systems. In this paper, we show how conflicts of interest can be formally detected during requirements analysis. This allows system designers to investigate the causes for which conflicts may occur in an organization. Thereby, they can better understand the organizational structure and so provide appropriate countermeasures to resolve or at least mitigate them Paolo Giorgini, Fabio Massacci, John Mylopoulos, Nicola Zannone |
RE | 1 |
| 2006 | Preface
Chiara Ghidini, Paolo Giorgini, Wiebe van der Hoek |
Auton. Agents Multi Agent Syst. | 2 |
| 2006 | Multi-Agent Architectures as Organizational Structures
Manuel Kolp, Paolo Giorgini, John Mylopoulos |
Auton. Agents Multi Agent Syst. | 2 |
| 2006 | Modeling Secure Systems Using an Agent-oriented Approach and Security PatternsabstractIn this paper we describe an approach for modeling security issues in information systems. It is based on an agent-oriented approach, and extends it with the use of security patterns. Agent-oriented software engineering provides advantages when modeling security issues, since agents are often a natural way of conceptualizing an information system, in particular at the requirements stage, when the viewpoints of multiple stakeholders need to be considered. Our approach uses the Tropos methodology for modeling a system as a set of agents and their social dependencies, with specific extensions for representing security constraints. As an extension to the existing methodology we propose the use of security patterns. These patterns capture proven solutions to common security issues, and support the systematic and structured mapping of these constraints to an architectural model of the system, in particular for non-security specialists. Haralambos Mouratidis, Michael Weiss 0001, Paolo Giorgini |
Int. J. Softw. Eng. Knowl. Eng. | 3 |
| 2005 | Goal-oriented requirement analysis for data warehouse designabstractSeveral surveys indicate that a significant percentage of data warehouses fail to meet business objectives or are outright failures. One of the reasons for this is that requirement analysis is typically overlooked in real projects. In this paper we propose a goal-oriented approach to requirement analysis for data warehouses, based on the Tropos methodology. Two different perspectives are integrated for requirement analysis: organizational modeling, centered on stakeholders, and decisional modeling, focused on decision makers. Our approach can be employed within both a demand-driven and a mixed supply/demand-driven design framework: in the second case, while the operational sources are still explored to shape hierarchies, user requirements play a fundamental role in restricting the area of interest for analysis and in choosing facts, dimensions, and measures. The methodology proposed, supported by a prototype, is described with reference to a real case study. Paolo Giorgini, Stefano Rizzi, Maddalena Garzetti |
DOLAP | 1 |
| 2005 | Security Patterns Meet Agent Oriented Software Engineering: A Complementary Solution for Developing Secure Information Systems
Haralambos Mouratidis, Michael Weiss 0001, Paolo Giorgini |
ER | 3 |
| 2005 | Software engineering for large-scale multi-agent systems - SELMAS'05abstractis becoming present in every aspect of our lives, pushing us inevitably towards a world of distributed, context-aware computing systems. SELMAS'05, Software Everywhere - Context-Aware Agents, builds on the success of precedent SELMAS workshops, but with a special emphasis on the impact of the agent technology in the development of large context-aware systems. SELMAS has a track record of bringing together researchers and practitioners with a variety of perspectives in order to engage in lively discussion and debate. Alessandro F. Garcia 0001, Ricardo Choren, Carlos José Pereira de Lucena, Alexander B. Romanovsky, Tom Holvoet, Paolo Giorgini |
ICSE | 6 |
| 2005 | Modeling Security Requirements Through Ownership, Permission and DelegationabstractSecurity requirements engineering is emerging as a branch of software engineering, spurred by the realization that security must be dealt with early on during the requirements phase. Methodologies in this field are challenging, as they must take into account subtle notions such as trust (or lack thereof), delegation, and permission; they must also model entire organizations and not only systems-to-be. In our previous work we introduced Secure Tropos, a formal framework for modeling and analyzing security requirements. Secure Tropos is founded on three main notions: ownership, trust, and delegation. In this paper, we refine Secure Tropos introducing the notions of at-least delegation and trust of execution; also, at-most delegation and trust of permission. We also propose monitoring as a security design pattern intended to overcome the problem of lack of trust between actors. The paper presents a semantic for these notions, and describes an implemented formal reasoning tool based on Datalog. Paolo Giorgini, Fabio Massacci, John Mylopoulos, Nicola Zannone |
RE | 1 |
| 2005 | ST-Tool: A CASE Tool for Security Requirements EngineeringabstractSecurity requirements engineering is emerging as a branch of software engineering, spurred by the realization that security must be dealt with early on during the requirements phase. We propose ST-tool, a CASE tool developed for modeling and analyzing functional and security requirements. Paolo Giorgini, Fabio Massacci, John Mylopoulos, Nicola Zannone |
RE | 1 |
| 2005 | Goal-oriented requirements analysis and reasoning in the Tropos methodology
Paolo Giorgini, John Mylopoulos, Roberto Sebastiani |
Eng. Appl. Artif. Intell. | 1 |
| 2005 | When security meets software engineering: a case of modelling secure information systems
Haralambos Mouratidis, Paolo Giorgini, Gordon A. Manson |
Inf. Syst. | 2 |
| 2004 | Simple and Minimum-Cost Satisfiability for Goal Models
Roberto Sebastiani, Paolo Giorgini, John Mylopoulos |
CAiSE | 2 |
| 2004 | Tropos: An Agent-Oriented Software Development Methodology
Paolo Bresciani, Anna Perini, Paolo Giorgini, Fausto Giunchiglia, John Mylopoulos |
Auton. Agents Multi Agent Syst. | 3 |
| 2003 | Organizational Patterns for Early Requirements Analysis
Manuel Kolp, Paolo Giorgini, John Mylopoulos |
CAiSE | 2 |
| 2003 | Integrating Security and Systems Engineering: Towards the Modelling of Secure Information Systems
Haralambos Mouratidis, Paolo Giorgini, Gordon A. Manson |
CAiSE | 2 |
| 2003 | Requirement Engineering Meets Security: A Case Study on Modelling Secure Electronic Transactions by VISA and Mastercard
Paolo Giorgini, Fabio Massacci, John Mylopoulos |
ER | 1 |
| 2003 | An Ontology for Modelling Security: The Tropos Approach
Haralambos Mouratidis, Paolo Giorgini, Gordon A. Manson |
KES | 2 |
| 2003 | Distributed Belief Revision
Aldo Franco Dragoni, Paolo Giorgini |
Auton. Agents Multi Agent Syst. | 2 |
| 2002 | Reasoning with Goal Models
Paolo Giorgini, John Mylopoulos, Eleonora Nicchiarelli, Roberto Sebastiani |
ER | 1 |
| 2002 | Information systems development through social structuresabstractInformation systems for organizations such as e-business and knowledge management systems must continually evolve to adapt to their operational environment. Unfortunately, current development methodologies do not support system evolution well, making software an obstacle to organizational changes. The paper describes a framework that develops and evolves seamlessly a system-to-be within its organizational environment. We adopt a set of social structures --- organizational styles and social patterns --- based on concepts of organization theory and agent approaches, as a foundation to model early and late requirements as well as architectural and detailed design. We illustrate the use of the social structures through a case study, and we specify one of the styles in Formal Tropos language. This research has been conducted within the context of the Tropos project. Manuel Kolp, Paolo Giorgini, John Mylopoulos |
SEKE | 2 |
| 2002 | Mental States Recognition from CommunicationabstractIn order to perform effective communication, agents must be able to foresee the effects of their utterances on the addressee's mental state. In this paper we study the consequences of an utterance on the mental state of a hearer. Given an agent communication language with a STRIPS‐like semantics, we propose a set of criteria that allow the binding of the speaker's mental state to its uttering of a certain sentence. On the basis of these criteria, we give an abductive procedure that the hearer can adopt to partially recognize the speaker's mental state that led to a specific utterance. Aldo Franco Dragoni, Paolo Giorgini, Luciano Serafini |
J. Log. Comput. | 2 |
| 2001 | Information Access in Implicit Culture FrameworkabstractThe goal of a System for Implicit Culture Support (SICS) is to establish an implicit culture phenomenon, namely when the elements of a set behave according to the culture of a generally different group of agents. Earlier work claimed that Implicit Culture support can be seen as a generalization of Collaborative Filtering. In this paper, we recall the concept of Implicit Culture, show how it is useful for automatically exploit tacit knowledge and we present an implementation of a System for Implicit Culture Support. Enrico Blanzieri, Paolo Giorgini, Paolo Massa, Sabrina Recla |
CIKM | 2 |
| 2001 | Implicit Culture for Multi-agent Interaction Support
Enrico Blanzieri, Paolo Giorgini, Paolo Massa, Sabrina Recla |
CoopIS | 2 |
| 2001 | Information systems as social structuresabstractOrganizations are changing at an ever-faster pace, as they try to keep up with globalization and the information revolution. Unfortunately, information systems technologies do not support system evolution well, making information systems a roadblock to organizational change. We propose to view information systems as social structures and define methodologies which develop and evolve seamlessly an information system within its operational environment. To this end, this paper proposes an ontology for information systems that is inspired by social and organizational structures. The ontology adopts components of the i* organizational modeling framework, which is founded on the notions of actor, goal and social dependency. Social patterns, drawn from research on cooperative and distributed architectures, offer a more macroscopic level of social structure description. Finally, the proposed ontology includes organizational styles inspired from organization theory. These are used not only to model the overall organizational context of an information system, but also its architecture. Social patterns and organizational styles are defined in terms of configurations of i* concepts. The research has been conducted in the context of the Tropos project. Ariel Fuxman, Paolo Giorgini, Manuel Kolp, John Mylopoulos |
FOIS | 2 |
| 2001 | Agent- Oriented Software Development: A Case Study
Paolo Giorgini, Anna Perini, John Mylopoulos, Fausto Giunchiglia, Paolo Bresciani |
SEKE | 1 |
| 2000 | From Entities and Relationships to Social Actors and Dependencies
John Mylopoulos, Ariel Fuxman, Paolo Giorgini |
ER | 3 |
| 1997 | Distributed Knowledge Revision/IntegrationabstractWe propose a distributed architecture for knowledge revisionintegration, where each element is conceived as a knowledgebased system able to exchange information with the others.since nodes can be affected by some degree of incompetence, part of the information running through the network may be incorrect and might cause contradictions in the knowledge base of some nodes.To manage these contradictions, each node is equipped with a belief revision module which makes it able to discriminate among more or less credible information and more or less reliable information sources.Our aim is that of comparing on a simulation basis the performances and the characteristics of this distributed system vs. those of a centralised architecture.We report here the fmt results of our experiments. .' % , . Aldo Franco Dragoni, Paolo Giorgini, Paolo Puliti |
CIKM | 2 |