VLDB 2026 Research / reviewers in the wild / expert
Dae-Kyoo Kim
dblp:k/DaeKyooKim
· DBLP profile ↗
53ranked-venue papers
20as first author
14since 2021 · last 2026
0000-0002-7133-9111ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 43 · 18 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 first-authorDatabases, data management, data science and information retrieval · 4 · 1 first-author · 2 since 2021Security and privacy · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Assessing the effectiveness of large language models for Java vulnerability repair: A comparative study
Obieda Ananbeh, Wala Alnozami, Dae-Kyoo Kim |
Autom. Softw. Eng. | 3 |
| 2026 | Artifact validity under varying agent configurations in LLM-assisted software development: A comparative analysis
Dae-Kyoo Kim |
Inf. Softw. Technol. | 1 |
| 2026 | Refactoring techniques for software vulnerabilities
Obieda Ananbeh, Wala Alnozami, Dae-Kyoo Kim, Ming Hua 0003, Weifeng Pan 0001 |
J. Syst. Softw. | 3 |
| 2025 | Assessing output reliability and similarity of large language models in software development: A comparative case study approach
Dae-Kyoo Kim, Ming Hua 0003 |
Inf. Softw. Technol. | 1 |
| 2025 | Comparative analysis of design pattern implementation validity in LLM-based code refactoringabstractDesign patterns are essential in software engineering, providing proven solutions for recurring design challenges, thereby enhancing maintainability, flexibility, and reusability of code. Despite their significance, the ability of Large Language Models (LLMs) to accurately implement these patterns has not been thoroughly explored. This research introduces a novel assessment framework that combines predicate logic specifications with quantitative metrics to evaluate pattern implementation quality. Using two case studies - a Point of Sale System (POSS) and Smart Wallet System (SWS) - we assess the LLMs’ capabilities in implementing design patterns including the Factory Method, Strategy, Composite, Observer, and Singleton patterns. The evaluation framework employs three metrics: Property Satisfaction Rate (PSR), Critical Property Coverage (CPC), and Pattern Implementation Quality Score (PIQS). The results demonstrate varying levels of effectiveness across the LLMs, with Claude achieving the highest average PIQS of 89.51, followed by Meta (88.98), ChatGPT (87.75), Copilot (82.69), and Gemini (71.04). These findings suggest that while LLMs show promise as refactoring tools, they are best utilized as assistive technologies rather than replacements for human developers. Dae-Kyoo Kim |
J. Syst. Softw. | 1 |
| 2025 | A Metamodel-Based Approach for Describing Quantum GatesabstractABSTRACT Quantum computing presents significant challenges for software engineers transitioning from classical to quantum paradigms. Traditional software engineering focuses on Boolean logic and procedural programming, while quantum computing requires understanding complex quantum mechanical principles such as quantum operations, superposition, and entanglement. This paper presents a metamodel‐based approach for formalizing the core principles of quantum gates, providing an accessible abstraction for software engineers. The metamodel captures two fundamental principles in quantum operations: The Euler decomposition principle for single‐qubit gates and the universality principle of multi‐qubit gates. It also represents quantum operation properties such as unitarity, linearity, reversibility, normality, and inner product preservation. The metamodel is validated through its instance models and their implementations in Qiskit, demonstrating both theoretical correctness and practical applicability. The evaluation focuses on the application of quantum gate principles through instance models of the metamodel for critical and complex gates like the Hadamard gate and the Toffoli gate, showing how they can be decomposed based on the Euler decomposition and universality principles while preserving quantum operation properties. This work provides a foundation for systematic quantum software development tools that bridge the gap between classical software engineering practices and quantum computing principles. Dae-Kyoo Kim |
Softw. Pract. Exp. | 1 |
| 2025 | Toward the Fractal Dimension of ClassesabstractThe fractal property has been regarded as a fundamental property of complex networks, characterizing the self-similarity of a network. Such a property is usually numerically characterized by the fractal dimension metric, and it not only helps the understanding of the relationship between the structure and function of complex networks but also finds a wide range of applications in complex systems. The existing literature shows that class-level software networks (i.e., class dependency networks) are complex networks with the fractal property. However, the fractal property at the feature (i.e., methods and fields) level has never been investigated, although it is useful for measuring class complexity and predicting bugs in classes. Furthermore, existing studies on the fractal property of software systems were all performed on un-weighted software networks and have not been used in any practical quality assurance tasks such as bug prediction. Generally, considering the weights on edges can give us more accurate representations of the software structure and thus help us obtain more accurate results. The illustration of an approach’s practical use can promote its adoption in practice. In this article, we examine the fractal property of classes by proposing a new metric. Specifically, we build a Feature-Level Software Network (FLSN) for each class to represent the methods/fields and their couplings (including coupling frequencies) within the class and propose a new metric, Fractal Dimension for Classes (FDC) , to numerically describe the fractal property of classes using FLSNs, which captures class complexity. We evaluate FDC theoretically against Weyuker’s nine properties, and the results show that FDC adheres to eight of the nine properties. Empirical experiments performed on a set of 12 large open source Java systems show that (i) for most classes (larger than \(96\%\) ), there exists the fractal property in their FLSNs, (ii) FDC is capable of capturing additional aspects of class complexity that have not been addressed by existing complexity metrics, (iii) FDC significantly correlates with both the existing class-level complexity metrics and the number of bugs in classes, and (iv) FDC , when used together with existing class-level complexity metrics, can significantly improve bug prediction in classes in three scenarios (i.e., bug-count , bug-classification , and effort-aware ) of the cross-project context, but in the within-project context, it cannot. Weifeng Pan 0001, Ming Hua 0003, Dae-Kyoo Kim, Zijiang Yang 0006, Yutao Ma |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2024 | Addressing Class Imbalances in Software Defect DetectionabstractSoftware defect detection (SDD) is concerned with detecting the existence of defects in software modules. There has been a growing interest in applying machine/deep learning to SDD. However, SDD is a binary classification problem, which involves class imbalances causing a bias in learning and there is little work addressing this problem. In this work, we apply four different class balancing techniques—SMOTE, ADASYN, SMOTE-Tomek, and SMOTE-ENN to the SDD problem using both deep learning and machine learning. We use MLP, CNN, and LSTM for deep learning; and decision tree, random forest, logistic regression, and XGB for machine learning. We evaluate the effect of class balancing techniques on those models and conduct a comparative analysis. The study found that class balancing techniques are positive on MLP, but negative on CNN and LSTM, while being positive in all the machine learning techniques. Overall, they are more compatible with machine learning. Dae-Kyoo Kim, Yeasun K. Chung |
J. Comput. Inf. Syst. | 1 |
| 2024 | Deep Learning-Based Code Refactoring: A Review of Current KnowledgeabstractThis paper presents a systematic literature review of deep learning (DL)-based software refactoring, which involves restructuring and simplifying code without altering its external functionality. The study analyzed 17 primary works and found that CNN, RNN, MLP, and GNN are commonly used DL models for code refactoring, with MLP performing the best. However, current research efforts primarily focus on Java code, method-level refactoring, and single language refactoring with varying evaluation methods. The review also highlights the limitations and challenges of DL-based software refactoring and suggests future research directions. Purnima Naik, Salomi Nelaballi, Venkata Sai Pusuluri, Dae-Kyoo Kim |
J. Comput. Inf. Syst. | 4 |
| 2023 | Identifying Key Classes for Initial Software Comprehension: Can We Do It Better?abstractKey classes are excellent starting points for developers, especially newcomers, to comprehend an unknown software system. Though many unsupervised key class identification approaches have been proposed in the literature by representing software as class dependency networks (aka software networks) and using some network metrics (e.g., h-index, a-index, and coreness), they are never aware of the field where the nodes exist and the effect of the field on the importance of the nodes in it. According to the classic field theory in physics, every material particle is in a field through which they exert an impact on other particles in the field via non-contact interactions (e.g., electromagnetic force, gravity, and nuclear force). Similarly, every node in a software network might also exist in a field, which might affect the importance of class nodes in it. In this paper, we propose an approach, iFit, to identify key classes in object-oriented software systems. First, we represent software as a CSNWD(Weighted Directed Class-level Software Network) to capture the topological structure of software, including classes, their couplings, and the direction and strength of couplings. Second, we assume that the nodes in the CSNWDexist in a gravitation-like field and propose a new metric, CG (Cumulative Gravitation-like importance), to measure the importance of classes. CG is inspired by Newton's gravitational formula and uses the PageRank value computed by a biased-PageRank algorithm as the masses of classes. Finally, classes in the system are sorted in descending order according to their CG values, and a cutoff is utilized, that is, the top-ranked classes are recommended as key classes. The experiments were performed on a data set composed of six open-source Java systems from the literature. The results show that iFit is superior to the baseline approaches on 93.75% of the total cases, and is scalable to large-scale software systems. Besides, we find that iFit is neutral to the weighting mechanisms used to assign the weights for different coupling types in the CSNWD, that is, when applying iFit to identify key classes, we can use any one of the weighting mechanisms. Weifeng Pan 0001, Ming Hua 0003, Dae-Kyoo Kim, Zijiang Yang 0006 |
ICSE | 4 |
| 2023 | Pride: Prioritizing Documentation Effort Based on a PageRank-Like Algorithm and Simple Filtering RulesabstractCode documentation can be helpful in many software quality assurance tasks. However, due to resource constraints (e.g., time, human resources, and budget), programmers often cannot document their work completely and timely. In the literature, two approaches (one is supervised and the other is unsupervised) have been proposed to prioritize documentation effort to ensure the most important classes to be documented first. However, both of them contain several limitations. The supervised approach overly relies on a difficult-to-obtain labeled data set and has high computation cost. The unsupervised one depends on a graph representation of the software structure, which is inaccurate since it neglects many important couplings between classes. In this paper, we propose an improved approach, named Pride, to prioritize documentation effort. First, Pride uses a weighted directed class coupling network to precisely describe classes and their couplings. Second, we propose a PageRank-like algorithm to quantify the importance of classes in the whole class coupling network. Third, we use a set of software metrics to quantify source code complexity and further propose a simple but easy-to-operate filtering rule. Fourth, we sort all the classes according to their importance in descending order and use the filtering rule to filter out unimportant classes. Finally, a threshold$k$is utilized, and the top-$k$% ranked classes are the identified important classes to be documented first. Empirical results on a set of nine software systems show that, according to the average ranking of the Friedman test, Pride is superior to the existing approaches in the whole data set. Weifeng Pan 0001, Ming Hua 0003, Dae-Kyoo Kim, Zijiang Yang 0006 |
IEEE Trans. Software Eng. | 3 |
| 2022 | Deep learning application on code clone detection: A review of current knowledge
Maggie Lei, Namrata Aundhkar, Dae-Kyoo Kim |
J. Syst. Softw. | 5 |
| 2022 | ABAC-Based Security Model for DDSabstractSecurity is increasingly critical in data communication of distributed environments. DDS is a middleware standard for data-centric publish/subscribe communication in a large scale real-time environment. DDS provides a security model for secure data communication. A major service of the security model is authorization. The authorization is based on the contents of messages rather than the information about the participant which should be the subject for access control. In this article, we present a novel approach for improved authorization of the DDS security model using ABAC. We first analyze the DDS security model and identify integration points for ABAC. Based on the analysis, we incorporate ABAC entities into the security model with ABAC behaviors defined across RTPS and DCPS. We implemented the model in XACML and evaluated by applying it to a patient monitoring system in the healthcare domain for its effectiveness, scalability, and efficiency in a controlled environment. The evaluation on effectiveness demonstrates that the model successfully enforces access control during the discovery process in a dynamic changing setting. The evaluation on scalability and efficiency demonstrates that the model is capable of handling 1,050 access requests simultaneously under the average of 40.60 milliseconds which satisfies the TT3 requirements in IEC 61850-5 with the average ABAC overheads of 10.62 milliseconds accounting for 26.67 percent of the communication time. Hwimin Kim, Dae-Kyoo Kim, Alaa S. Alaerjan |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | ElementRank: Ranking Java Software Classes and Packages using a Multilayer Complex Network-Based ApproachabstractSoftware comprehension is an important part of software maintenance. To understand a piece of large and complex software, the first problem to be solved is where to start the understanding process. Choosing to start the comprehension process from the important software elements has proven to be a practical way. Research on complex networks opens new opportunities for identifying important elements, and many approaches have been proposed. However, the software networks that existing approaches use neglect the multilayer nature of software systems. That is, nodes in the network can have different types of relationships at the same time, and each type of relationship forms a specific layer. Worse still, they mainly focus on identifying important classes, and little work has been done on quantifying package importance. In this paper, we propose an ElementRank approach to provide a ranked list of classes (or packages) for maintainers to start the comprehension process. The top-ranked classes (or packages) can be seen as the starting points for the software comprehension process at the class (or package) level. First, we introduce two kinds of multilayer software networks to describe the topological structure of software at the class level and package level, respectively. Second, we propose a weighted PageRank algorithm to calculate the weighted PageRank value of classes (or packages) in each layer of the corresponding multilayer software network. Then, we use AHP (Analytic Hierarchy Process) to weigh each layer in the corresponding multilayer software network, and further aggregate the weighted PageRank value to obtain the global weighted PageRank value for each class (or package). Finally, all the classes (or packages) are ranked according to their global weighted PageRank values in a descending order, and the top-ranked classes (or packages) can serve as the starting points for the software comprehension process at the class (or package) level. ElementRank is validated theoretically using the widely accepted Weyuker’s criteria. Theoretical results show that the global weighted PageRank value for classes (or packages) satisfies most of Weyuker’s properties. Furthermore, ElementRank is evaluated empirically using a set of twelve open source software systems. Through a set of experiments, we show the rank correlation between the results of ElementRank and that of the approaches in the related work, and the benefits of ElementRank are also illustrated in comparison with other approaches in the related work. Empirical results also show that ElementRank can be applied to large software systems. Weifeng Pan 0001, Ming Hua 0003, Carl K. Chang, Zijiang Yang 0006, Dae-Kyoo Kim |
IEEE Trans. Software Eng. | 5 |
| 2020 | Reflection on Building Hybrid Access Control by Configuring RBAC and MAC FeaturesabstractThis paper reflects on the paper titled Building Hybrid Access Control by Configuring RBAC and MAC Features which was published in Information and System Technology, 2014. The publication presents an approach for building a hybrid access control model of Role-Based Access Control and Mandatory Access Control by defining and configuring them in terms of features. The publication has been cited three times, which shows limited impact. We review the citing papers as to how the publication is cited and discuss possible reasons for the limited impact. We also discuss its position in the current state of the arts since the publication. Then, we describe an ongoing effort for a new approach to address the weaknesses of the publication with expected impact. Dae-Kyoo Kim, Ming Hua 0003, Lunjin Lu |
SANER | 1 |
| 2019 | Threshold-Driven Class DecompositionabstractSoftware evolves with modifications which lead to a deviation from the single responsibility principle. Continuous changes deteriorate the quality of software, thereby decreasing cohesion and increasing coupling. There has been much work on improving class cohesion by decomposing a large class of multiple responsibilities into smaller classes with a single responsibility. The decomposition process is iterative until it reaches to the point where classes have a single-responsibility. However, it is hard to determine when to terminate the process. Early termination results in premature decomposition, while late termination leads to over decomposition. In this work, we present a threshold-driven approach to determine a termination point in the decomposition process developed in our previous work. We demonstrate the approach using a case example. Mohammed Hamdi, Rashmi Pethe, Annapoorani Sevugan Chetty, Dae-Kyoo Kim |
COMPSAC (1) | 4 |
| 2019 | Detecting No-Sleep Bugs Using Sequential Reference CountsabstractPower management is critical for mobile devices as energy demands have been constantly growing, while the longevity of battery power remains limited. This paper presents an extension of our previous work on detecting no-sleep energy bugs using sequential reference counts. We use a refined banking application and its implementation in Android Studio to demonstrate the extension. Priyanka Bharat Sakhare, Dae-Kyoo Kim, Mohammed Hamdi |
COMPSAC (1) | 2 |
| 2019 | Measuring Class Cohesion Using Internal and External Class RelationshipsabstractClass cohesion is a design quality that has a great impact on posterior development and maintenance of object-oriented systems. There have been much works on measuring class cohesion based on internal class relationships such as method-attribute referencing and internal method invocations. However, object-oriented systems involve many external class relationships carrying a functional context which should be also taken into account in measuring class cohesion. However, the existing works using internal relationships cannot measure cohesion of classes involving many external relationships. In this paper, we present a novel metric for measuring class cohesion based on both internal and external class relationships through an iterative process. We evaluate the metric by applying it to five applications — ArgoUML, jEdit, JHotDraw, JMeter, and Refactor, and validate the metric theoretically and statistically. The theoretical validation shows that the metric exhibits the required properties for cohesion metrics and the statistical validation shows that the metric captures a new aspect of class cohesion that has not been addressed by the existing works. Junha Lee, Dae-Kyoo Kim, Sooyong Park, Hwimin Kim |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2017 | B-kNN to Improve the Efficiency of kNN
Dhrgam Al Kafaf, Dae-Kyoo Kim, Lunjin Lu |
DATA | 2 |
| 2017 | Class Modularization Using Indirect RelationshipsabstractCohesion significantly impacts on posterior development and maintenance. A well-designed module should be coherent with a single responsibility and less propagative for changes to other modules. In object-oriented development, classes are often modularized based on their relationships to localize change impact. There has been much work on grouping classes using direct class interactions and similarity of lexical information of classes. However, there has been little attention to indirect class relationships which are significant in defining functional semantics in object-oriented systems. In this paper, we present an approach for grouping classes using both direct and indirect class relationships. In the approach, we define a set of metrics for measuring couplings based on indirect class relationships and use them to group classes with the aim of localizing the impact of changes. We evaluate the approach using three applications - JHotDraw, JMeter, and ArgoUML and compare the results with existing work. The evaluation shows that the proposed approach reduces 17.2% and 22.2% of the number of packages that are affected by changes over the existing works. Junha Lee, Dae-Kyoo Kim, Jiwoo Park, Sooyong Park |
ICECCS | 2 |
| 2017 | Design pattern-based model transformation supported by QVT
Dae-Kyoo Kim, Lunjin Lu, Byunghun Lee |
J. Syst. Softw. | 1 |
| 2017 | Special issue on software reuseabstractSpecial issue on software Dae-Kyoo Kim, Eunjee Song, Jungwoo Ryoo, Y. Raghu Reddy |
Softw. Pract. Exp. | 1 |
| 2016 | Decomposing class responsibilities using distance-based method similarity
Junha Lee, Dae-Kyoo Kim, Suntae Kim, Sooyong Park |
Frontiers Comput. Sci. | 2 |
| 2015 | Role-based access control for substation automation systems using XACML
Byunghun Lee, Dae-Kyoo Kim, Hyo-Sik Yang, Hyuksoo Jang |
Inf. Syst. | 2 |
| 2015 | Identifying correlations of findings for building process improvement packages using graph clusteringabstractAbstract Software process improvement (SPI) begins with process assessment based on a process reference model such as CMMI. Process improvement action items in SPI are determined according to the identified strengths and weaknesses of the current practice. Therefore, given that a list of assessment findings has been identified, it is important to analyze correlations of findings and identify relevant findings for building improvement items. However, correlation analysis requires expertise and considerable efforts, which makes it difficult for practitioners to perform it in process improvement projects. In this work, we present a CMMI‐based method for identifying correlations of findings and building improvement packages using graph clustering techniques. We evaluate the method using industrial data. Copyright © 2015 John Wiley & Sons, Ltd. Dae-Kyoo Kim, Sooyong Park |
J. Softw. Evol. Process. | 2 |
| 2015 | Design pattern based model transformation with tool supportabstractSummary A design pattern helps to improve the quality of a software system by providing a proven solution for recurring design problems. However, the abstract and informal nature of prevailing pattern descriptions makes it hard to use design patterns and hinders the development of tool support. In this paper, we present an approach that systematically applies a design pattern to a problem model and transforms it to a solution model with traceability, which helps to understand how a design pattern addresses its intended design problem. In the approach, a design pattern is defined as a pair of solution and problem specifications and a transformation specification. A problem model is checked for pattern applicability, and if applicable, the pattern is applied to the model using the pattern's transformation specification, which results in a solution model conforming to the solution specification of the pattern. This approach establishes an explicit traceability of how pattern properties are incorporated into a model. We demonstrate the approach using the Visitor pattern applied to two case studies. Copyright © 2013 John Wiley & Sons, Ltd. Dae-Kyoo Kim |
Softw. Pract. Exp. | 1 |
| 2014 | Building Sustainable Software by Preemptive Architectural Design Using Tactic-Equipped PatternsabstractSustainability of software architectures has gained increasing attention to cope with factors causing architectural changes such as requirements changes, technological changes, and changes in business strategies and goals. However, there has not been much work on architectural sustainability. In this paper, we present a novel approach for addressing architectural sustainability with respect to non-functional requirements changes through preemptive architectural designs built upon the combined use of architectural patterns and architectural tactics. The approach presented in this paper provides a strategic solution for practitioners to building a quality attribute into a chosen architectural pattern to proactively deal with the requirements changes of quality attribute, which may arise after the construction phase. Dae-Kyoo Kim, Jungwoo Ryoo, Suntae Kim |
ARES | 1 |
| 2014 | Building hybrid access control by configuring RBAC and MAC features
Sangsig Kim, Dae-Kyoo Kim, Lunjin Lu, Eunjee Song |
Inf. Softw. Technol. | 2 |
| 2014 | Required behavior of sequence diagrams: Semantics and conformanceabstractMany reusable software artifacts such as design patterns and design aspects make use of UML sequence diagrams to describe interaction behaviors. When a pattern or an aspect is reused in an application, it is important to ensure that the sequence diagrams for the application conform to the corresponding sequence diagrams for the pattern or aspect. Reasoning about conformance relationship between sequence diagrams has not been addressed adequately in literature. In this article, we focus on required behaviors specified by a UML sequence diagram and provide a semantic-based formalization of conformance relationships between sequence diagrams. A novel trace semantics is first given that captures precisely required behaviors. A refinement relation between sequence diagrams is then defined based on the semantics. The refinement relation allows a sequence diagram to be refined by changing its structure so long as its required behaviors are preserved. A conformance relation between sequence diagrams is finally given that includes the refinement relation as a special case. It allows one to introduce and rename lifelines, messages, and system variables when reusing sequence diagrams. Properties of the semantics, refinement, and conformance relations are studied. Two case studies are provided to illustrate the efficacy of semantic-based conformance reasoning. Lunjin Lu, Dae-Kyoo Kim |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2013 | Refinement Inference for Sequence Diagrams
Lunjin Lu, Dae-Kyoo Kim |
SOFSEM | 2 |
| 2012 | Pattern-Based Model Transformation Using QVTabstractA design pattern addresses a recurring design problem by providing a proven solution for reuse in software development. However, due to the informal nature of prevailing pattern descriptions, it is difficult to reuse design patterns in practice. There has been much work on tool support for pattern reuse. However, the existing work focuses on only the solution domain of a pattern, leaving largely the problem domain unaddressed which is an important aspect in determining pattern applicability. Also, the existing work uses non-standardized techniques, which makes it difficult to adopt. In this work, we present a novel approach for applying design patterns using Query/View/Transformation (QVT), a de-facto standard for model transformation. In the approach, we make use of both the problem domain and solution domain of a design pattern for checking pattern applicability and verifying pattern conformance. The domains are defined at the metamodel level and mapped each other for a base to define QVT transformation. We demonstrate the approach using the Visitor design pattern applied to an open source drawing tool. Sunuk Park, Dae-Kyoo Kim, Sooyong Park |
APSEC | 2 |
| 2012 | An Interaction-Driven Approach to Identifying Functional Behaviors of Service Robot Systems
Youngdo Cho, Hwangwook Kim, Dae-Kyoo Kim, Sooyong Park |
ICECCS | 3 |
| 2012 | ReMo: A recommendation model for software process improvementabstractSoftware process assessment methods such as SCAMPI and ISO 15504-2 provide an assessment framework for evaluating the current practice of software development organizations. Strengths, weaknesses, and recommendations are core results of process assessment to be used as a basis for process improvement. While the existing models provide concrete methods for identifying strengths and weaknesses of process, they lack detailed approaches to building recommendations, which are crucial in developing strategic improvement plans. This makes it difficult for the assessment team to develop constructive recommendations, which has consequently negative impact on the quality of process improvement. To address this, we present a systematic method for developing recommendations based on a capability-based reference model (e.g., CMMI, SPICE). The presented method is evaluated using real assessment data from industry and the results show the potential of the method. Dae-Kyoo Kim, Sooyong Park |
ICSSP | 2 |
| 2011 | Required Behavior of Sequence Diagrams: Semantics and RefinementabstractSequence diagrams are a widely used design notation for describing software behavior. Many reusable software artifacts such as design patterns and design aspects make use of sequence diagrams to describe interaction behavior. When a pattern or an aspect is reused in an application, it is important to ensure that the sequence diagrams for the application correctly refines the corresponding sequence diagrams for the pattern or aspect. However, reasoning about refinement of sequence diagrams has not been addressed adequately. In this paper, we focus on refinement of required behavior specified by a UML sequence diagram. A novel trace semantics is given that captures precisely required behavior specified by a sequence diagram and a refinement relation between sequence diagrams is formalized based on the semantics. Properties of the trace semantics and the refinement relation are studied. Lunjin Lu, Dae-Kyoo Kim |
ICECCS | 2 |
| 2011 | A Feature-Based Modeling Approach to Configuring Privacy and Temporality in RBAC
Sangsig Kim, Yen-Ting Lee, Yuanlin Zhu, Dae-Kyoo Kim, Lunjin Lu, Vijayan Sugumaran |
SEKE | 4 |
| 2011 | A feature-based approach for modeling role-based access control systems
Sangsig Kim, Dae-Kyoo Kim, Lunjin Lu, Suntae Kim, Sooyong Park |
J. Syst. Softw. | 2 |
| 2010 | Supporting Flexible Reification of Design PatternsabstractDesign patterns have been widely accepted as a solution for solving recurring design problems in object-oriented development. Reifications of design patterns can vary from one development environment to another, and use of inappropriate reifications may impose a serious threat to quality of a software system. In this paper, we propose an approach to applying the profile mechanism in reifying a design pattern. Central to this approach are stereotypes that are defined in a profile and used to represent different roles in a design pattern. Developers can apply these stereotypes in their application model when design patterns are used. The advantage of the profile mechanism is that developers can 1) define their own reification of a pattern in a profile based on a specific software system, and 2) find errors in an application model via the conformance checking of the model against the profile. More importantly, we apply our existing tool called ICER, which is based on the profile mechanism, to provide automatic checking for the application of design patterns. To illustrate the advantage of the profile mechanism supported by ICER, we show the different reifications for the Observer pattern. Last, experimental results show that ICER does not suffer from the scalability problem as the size of an application model increases. Wuwei Shen, Dae-Kyoo Kim, Jian Liu 0008 |
APSEC | 2 |
| 2010 | A Verifiable Modeling Approach to Configurable Role-Based Access Control
Dae-Kyoo Kim, Lunjin Lu, Sangsig Kim |
FASE | 1 |
| 2010 | Tool support for quality-driven development of software architecturesabstractIn this paper, we present a prototype tool that supports the systematic development of software architectures driven by quality requirements using architectural tactics. The tool allows one to configure architectural tactics based on quality requirements and compose the configured tactics to produce an initial architecture for the system. We demonstrate the tool for developing an architecture for a resource profiling system in the web environment and validate the results using a set of metrics. Suntae Kim, Dae-Kyoo Kim, Sooyong Park |
ASE | 2 |
| 2009 | Quality-driven architecture development using architectural tactics
Suntae Kim, Dae-Kyoo Kim, Lunjin Lu, Sooyong Park |
J. Syst. Softw. | 2 |
| 2008 | A Tactic-Based Approach to Embodying Non-functional Requirements into Software ArchitecturesabstractThis paper presents an approach for embodying nonfunctional requirements (NFRs) into software architecture using architectural tactics. Architectural tactics are reusable architectural building blocks, providing general architectural solutions for commonly occurring issues related to quality attributes. In this approach, architectural tactics are represented as feature models, and their semantics is defined using the role-based metamodeling language (RBML) which is a UML-based pattern specification notation. Given a set of NFRs, architectural tactics are elected and composed. The composed tactic is then used to instantiate an initial architecture for the application where the NFRs are embodied. A stock trading system is used to demonstrate the approach. Suntae Kim, Dae-Kyoo Kim, Lunjin Lu, Sooyong Park |
EDOC | 2 |
| 2008 | Pattern-Based Transformation Rules for Developing Interaction Models of Access Control Systems
Dae-Kyoo Kim, Lunjin Lu |
ICSR | 1 |
| 2008 | Evaluating pattern conformance of UML models: a divide-and-conquer approach and case studies
Dae-Kyoo Kim, Wuwei Shen |
Softw. Qual. J. | 1 |
| 2006 | A Pattern-Based Technique for Developing UML Models of Access Control SystemsabstractThis paper describes a pattern-based technique for systematic development of UML models of secure systems using access control. Access control is viewed and specified as a design pattern. An access control pattern is applied to a functional UML model of an application to be secured using a composition algorithm. We demonstrate the technique using mandatory access control (MAC) and a model of a simple file system. We also discuss how the composed model can be evaluated for security assurance expected from the applied access control Dae-Kyoo Kim, Priya Gokhale |
COMPSAC (1) | 1 |
| 2006 | Inference of Design Pattern Instances in UML models via Logic Programming
Dae-Kyoo Kim, Lunjin Lu |
ICECCS | 1 |
| 2005 | Evaluating Conformance of UML Models to Design PatternsabstractIn this paper, we describe an approach to checking conformance of UML class diagrams to design patterns. The technique provides a set of checks that evaluate syntactic and semantic pattern conformance. Syntactic pattern conformance is concerned with structural conformance of a class diagram to the structural properties of a pattern. Semantic pattern conformance is concerned with conformance of invariants and pre- and post-conditions in a class diagram to semantic pattern properties. A class diagram is said to conform a pattern when it acquires both syntactic and semantic conformance. Dae-Kyoo Kim |
ICECCS | 1 |
| 2005 | Generating UML Models from Domain PatternsabstractThe development of a family of applications in a domain can be greatly eased if patterns in the domain are systematically reused. Systematic use of such patterns can be achieved by tools that support the specification of patterns and their instantiation in a specific application context. In this paper, we present a prototype tool called RBML-Pattern Instantiator (RBML-PI) that generates application-specific UML class diagrams and sequence diagrams from a pattern specification described in the Role-Based Metamodeling Language (RBML), a pattern specification language defining a domain-specific sub-language of the UML. We give an overview of the RBML using the Visitor design pattern, and demonstrate the tool using an RBML specification for the CheckIn-CheckOut (CICO) domain pattern that specifies services to check in and check out items. We use the CICO pattern specification to generate an application-specific UML model of a library system using RBML-PI. Dae-Kyoo Kim, Jon Whittle 0001 |
SERA | 1 |
| 2004 | Modeling Role-Based Access Control Using Parameterized UML Models
Dae-Kyoo Kim, Indrakshi Ray, Robert B. France |
FASE | 1 |
| 2004 | Modeling and Composing Scenario-Based Requirements with Aspects
João Araújo 0001, Jon Whittle 0001, Dae-Kyoo Kim |
RE | 3 |
| 2004 | Using uml to visualize role-based access control constraintsabstractOrganizations use Role-Based Access Control (RBAC) to protect information resources from unauthorized access. We propose an approach, based on the Unified Modeling Language (UML), that shows how RBAC policies can be systematically incorporated into an application design. We consider an RBAC model to be a pattern which we express using UML diagram templates; RBAC policies for an application conforming to this model can be generated by instantiating these templates with values obtained from the application. The constraints of the RBAC model are expressed using the Object Constraint Language (OCL). OCL constraints, based on first-order logic, are difficult to understand. To alleviate this problem, we show how violation of such constraints can be visually represented using object diagram templates. With adequate tool support, developers can use these to demonstrate constraint violations in their applications. Our approach is illustrated using a small banking application. Indrakshi Ray, Robert B. France, Dae-Kyoo Kim |
SACMAT | 4 |
| 2004 | A UML-Based Pattern Specification TechniqueabstractInformally described design patterns are useful for communicating proven solutions for recurring design problems to developers, but they cannot be used as compliance points against which solutions that claim to conform to the patterns are checked. Pattern specification languages that utilize mathematical notation provide the needed formality, but often at the expense of usability. We present a rigorous and practical technique for specifying pattern solutions expressed in the unified modeling language (UML). The specification technique paves the way for the development of tools that support rigorous application of design patterns to UML design models. The technique has been used to create specifications of solutions for several popular design patterns. We illustrate the use of the technique by specifying observer and visitor pattern solutions. Robert B. France, Dae-Kyoo Kim, Sudipto Ghosh 0001, Eunjee Song |
IEEE Trans. Software Eng. | 2 |
| 2003 | A Role-Based Metamodeling Approach to Specifying Design PatternsabstractDesign patterns describe solutions to recurring design problems in the development of software designs. To encourage the use of design patterns, we are investigating tool support for incorporating patterns into UML models. The development of such tools requires patterns to be specified at the metamodel level. Patterns may be specified using roles, where a role is played by model elements. However, the notion of role in the object-oriented community is strictly based on objects, and does not allow the use of the word "role" in any other place where the context is not object-based. In this paper, we propose a notion of role that can be used to specify design patterns at the metamodel level. We survey the characteristics of object-based roles and generalize them. Based on the generalized notion of a role define a new notion of a model role which is played by a model element. We illustrate the use of model roles with a specification of a variant of the Observer design pattern. Dae-Kyoo Kim, Robert B. France, Sudipto Ghosh 0001, Eunjee Song |
COMPSAC | 1 |
| 2002 | Using Role-Based Modeling Language (RBML) to Characterize Model FamiliesabstractCost-effective development of large, integrated computer-based systems can be realized through systematic reuse of development experiences throughout the development process. We describe a technique for representing reusable modeling experiences. The technique allows developers to express domain-specific design patterns as a sub-language of the modeling language, the UML. Use of the sub-language to build application-specific UML models results in the reuse of the embedded design experiences. We use a notation called the (meta)Role-Based Modeling Language (RBML) to define UML sub-languages. A (meta-)Role Model is a specialization of the UML (Unified Modeling Language) meta-model, that is, it determines a sub-language of the UML. We show how RBML can be used to define domain-specific design patterns. Dae-Kyoo Kim, Robert B. France, Sudipto Ghosh 0001, Eunjee Song |
ICECCS | 1 |