VLDB 2026 Research / reviewers in the wild / expert
Heather Lipford
dblp:r/HeatherRichter · also Heather A. Richter, Heather Richter, Heather Richter Lipford
· DBLP profile ↗
64ranked-venue papers
7as first author
15since 2021 · last 2026
0000-0002-5261-0148ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Human-computer interaction and ubiquitous computing · 40 · 4 first-author · 7 since 2021Security and privacy · 16 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 6 · 2 first-authorGraphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 3 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Growing Together for Digital Safety: Examining the Effects of Group Formation and Engagement in Building Privacy and Security Efficacy CSCW018abstractUnderstanding how social interactions affect privacy management is important in today’s digital landscape. We are investigating collective management of privacy and security through a mobile application, CO-oPS, that allows people to view and discuss each other’s app privacy settings within a community of users. Sixteen small, self-organized groups, totaling 81 participants, used the app over a four-week period. Data collection included pre- and post-study surveys measuring privacy perceptions (Community Belonging, Self-Efficacy, Community Collective Efficacy) along with in-app behavioral logs (messaging and viewing activity). In this paper, we present a social network analysis of our field study data, exploring the effects of group formation and engagement on building privacy and security efficacy through CO-oPS interactions. Our analysis reveals that while privacy perceptions were not initially homophilous, they grew more similar over time. Notably, proactively messaging others in the app enhanced personal privacy management confidence. Our results demonstrate the nuanced ways that groups can influence each other in addressing security and privacy needs. Jessica Kropczynski, Mamtaj Akter, Amir Reza Asadi, Hanna AlZughbi, Jinkyung Park, Heather Lipford, Pamela J. Wisniewski |
Proc. ACM Hum. Comput. Interact. | 6 |
| 2025 | Examining Caregiving Roles to Differentiate the Effects of Using a Mobile App for Community Oversight for Privacy and SecurityabstractWe conducted a 4-week field study with 101 smartphone users who self-organized into 22 small groups of family, friends, and neighbors to use "CO-oPS," a mobile app for co-managing mobile privacy and security. We differentiated between those who provided oversight (i.e., caregivers) and those who did not (i.e., caregivees) to examine differential effects on their experiences and behaviors while using CO-oPS. Caregivers reported higher power use, community trust, belonging, collective efficacy, and self-efficacy than caregivees. Both groups' self-efficacy and collective efficacy for mobile privacy and security increased after using CO-oPS. However, this increase was significantly stronger for caregivees. Our research demonstrates how community-based approaches can benefit people who need additional help managing their digital privacy and security. We provide recommendations to support community-based oversight for managing privacy and security within communities of different roles and skills. Mamtaj Akter, Jessica Kropczynski, Heather Lipford, Pamela J. Wisniewski |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | Using AI Assistants in Software Development: A Qualitative Study on Security Practices and ConcernsabstractFollowing the recent release of AI assistants, such as OpenAI's ChatGPT and GitHub Copilot, the software industry quickly utilized these tools for software development tasks, e.g., generating code or consulting AI for advice. While recent research has demonstrated that AI-generated code can contain security issues, how software professionals balance AI assistant usage and security remains unclear. This paper investigates how software professionals use AI assistants in secure software development, what security implications and considerations arise, and what impact they foresee on secure software development. We conducted 27 semi-structured interviews with software professionals, including software engineers, team leads, and security testers. We also reviewed 190 relevant Reddit posts and comments to gain insights into the current discourse surrounding AI assistants for software development. Our analysis of the interviews and Reddit posts finds that despite many security and quality concerns, participants widely use AI assistants for security-critical tasks, e.g., code generation, threat modeling, and vulnerability detection. Their overall mistrust leads to checking AI suggestions in similar ways to human code, although they expect improvements and, therefore, a heavier use for security tasks in the future. We conclude with recommendations for software professionals to critically check AI suggestions, AI creators to improve suggestion security and capabilities for ethical security tasks, and academic researchers to consider general-purpose AI in software development. Jan H. Klemmer, Stefan Horstmann, Nikhil Patnaik, Cordelia Ludden, Cordell Burton Jr., Carson Powers, Fabio Massacci, Akond Ashfaque Ur Rahman, Daniel Votipka, Heather Lipford, Awais Rashid, Alena Naiakshina, Sascha Fahl |
CCS | 10 |
| 2024 | Location Invariant Flood Prediction using Fourier Neural OperatorabstractAs coastal cities are increasingly vulnerable to climate- related flooding, the need for accurate and timely flood predictions is pressing, particularly for emergency response planning. This study presents an approach to predict flood events at high spatial resolution, leveraging inundation maps and 15-minute rainfall data. We employ Fourier Neural Operator (FNO), a method that learns efficient approximations of solutions to parametric partial differential equations. By incorporating multi-modal data types, our FNO model captures the complex dynamics of flood events including water levels in affected areas and long-range spatial and temporal dependencies. This interdisciplinary research contributes to the development of generalizable methods for predicting floods in coastal cities. Chetan Kumar, Diana McSpadden, Steven Goldenberg, Malachi Schram, Heather Lipford, Binata Roy, Jonathan L. Goodall |
ICMLA | 5 |
| 2024 | An Open Data Cube Platform as a Coastal Digital Twin: Prototypes to Inform Flooding and Environmental HealthabstractEarth Science Digital Twins are rapidly evolving to advance earth science understanding and societally relevant decision making. Coastal hazards pose complex and compound threats to dynamic human settlements and land use, inviting their analysis using digital twin technologies. A geospatial approach requires a framework for data assimilation that spans Earth observations, in situ sensor networks, environmental models, and characterization of human population and infrastructure assets. In our study, an Open Data Cube is developed as the core integration platform for a series of prototype case studies: 1) coastal mosquito-borne disease exposure assessment; 2) dasymetric mapping of vulnerable populations; and 3) integrated modeling and observational assessment of a King Tide flood event for Hampton Roads, Virginia (USA.) These prototypes are described with preliminary results. The paper also discusses benefits of the ODC as a Digital Twin as well as impediments and future developments for enhanced capabilities. Thomas R. Allen 0001, Yin-Hsuen Chen, Blake Steiner, George McLeod, Sridhar Katragadda, Brian B. Terry, Joshua R. Baptist, Oguz Yetkin, Navid Tahvildari, Sunghoon Han, Brandon Feldhaus, Heather Lipford |
IGARSS | 12 |
| 2023 | Co-designing Community-based Sharing of Smarthome Devices for the Purpose of Co-monitoring In-home EmergenciesabstractWe conducted 26 co-design interviews with 50 smarthome device owners to understand the perceived benefits, drawbacks, and design considerations for developing a smarthome system that facilitates co-monitoring with emergency contacts who live outside of one’s home. Participants felt that such a system would help ensure their personal safety, safeguard from material loss, and give them peace of mind by ensuring quick response and verifying potential threats. However, they also expressed concerns regarding privacy, overburdening others, and other potential threats, such as unauthorized access and security breaches. To alleviate these concerns, participants designed flexible and granular access control and fail-safe back-up features. Our study reveals why peer-based co-monitoring of smarthomes for emergencies may be beneficial but also difficult to implement. Based on the insights gained from our study, we provide recommendations for designing technologies that facilitate such co-monitoring while mitigating its risks. Leena Alghamdi, Mamtaj Akter, Jessica Kropczynski, Pamela J. Wisniewski, Heather Lipford |
CHI | 5 |
| 2023 | A Digital Twin to Link Flood Models, Sensors, and Earth Observations for Coastal Resilience in Hampton Roads, Virginia, U.S.AabstractA Digital Twin (DT) for coastal resilience in a low-lying coastal city necessarily entails characterizing the geophysical terrain, complex hydrologic flows, and infrastructure modifications that affect flooding. Coastal flooding in ports such as Hampton Roads, Virginia, arise from coastal storms, regular tidal estuarine circulation processes, seasonal to interannual external forcing from the ocean via the Gulf Stream and Atlantic Meridional Overturning Circulation (AMOC), and associated local influences on sea-level anomalies. We take a geospatial, hub-based approach to integrate digital linkages and threads among real-time Internet of Things (IoT) water level and flood sensors, an operational hydrodynamic model, localized probabilistic sea-level rise projections, hydro-corrected LiDAR Digital Elevation Models and GIS stormwater infrastructure, and an open data cube that ingests, hosts, and processes Application-Ready Datasets (ARDs.) Our paper describes the structure and cloud integration of a flood sensor network, StormSense, and its augmentation with end-user identified gap sites to improve network coverage and sensitivity to vulnerable communities. The enhancement of the multiple flood sensor networks incorporates multiple APIs and Amazon Web Services to normalize and homogenize data feeds among municipal sensors, private sector sensors, NOAA and USGS gauges, and new sensors sited in partnership with emergency managers, non-profits, and the National Weather Service. We describe the development and improvements of a Delft3D model for hydrodynamic simulation, including characterization and grid improvements of shallow estuarine creeks. The model includes sea-level rise parameters for the Hampton Roads study area. The paper also outlines Earth Observing data in the Virginia Open Data Cube, including products from NASA, NOAA, ESA, and newly incorporated drone data. The data cube hosts multi-purpose data products, such as satellite derived Land Use/Land Cover, MODIS, Landsat, and Sentinel datasets, and large high-resolution, hydro-corrected LiDAR DEMs. We link the data cube to an ArcGIS Hub to provide end-products, disseminate content, and apply GIS analyses for real-time and simulated future scenario dashboard. The hub provides an end-user interface for impact modeling, what-if scenarios and decision support. The paper builds DT infrastructure to support emergency management, public health, and resilience planning. Thomas R. Allen 0001, Sridhar Katragadda, Yin-Hsuen Chen, Brian B. Terry, Joshua R. Baptist, Oguz Yetkin, Navid Tahvildari, Sunghoon Han, Blake Steiner, George McLeod, Soenke Dangendor, Heather Lipford |
IGARSS | 13 |
| 2023 | Evaluating the Impact of Community Oversight for Managing Mobile Privacy and Security
Mamtaj Akter, Madiha Tabassum, Md. Nazmus Sakib Miazi, Leena Alghamdi, Jessica Kropczynski, Pamela J. Wisniewski, Heather Lipford |
SOUPS | 7 |
| 2023 | Exploring privacy implications of awareness and control mechanisms in smart home devicesabstractSmart home users have a variety of controls they can use to configure their devices according to their preferences. However, it is unclear how people utilize these controls, what considerations they make, and the implications of those decisions for users' privacy. To address this gap, we have conducted two complimentary interview studies regarding the controls available for configuring, monitoring, and sharing collected information in two common smart home devices: a smart doorbell and a lock. We interviewed 21 non-owner participants in the lab and 18 owners of these devices over the phone. While both novice users and existing owners were primarily driven by desired functionality while setting up their devices, their configuration decisions impact what data gets collected and how that data and the device are used and shared. Our findings suggest a range of opportunities to improve the privacy-related features and support for smart home devices. Madiha Tabassum, Heather Lipford |
Proc. Priv. Enhancing Technol. | 2 |
| 2022 | Digitally Twinning Coastal Resilience Via Multsensor Imagery, in Situ Sensors, and Geospatial AnalysisabstractIncreasing coastal flooding owing to sea level rise and climate-change drivers of extreme precipitation combine to threaten vulnerable communities, posing imminent as well as evolving dynamic threats given sea-level rise and climate changes. A diversity of social, economic and cultural vulnerabilities, and coping capacities exist across coastal communities, yet decision support systems for response and planning alike are disparate and siloed. Vulnerable urban communities contend with the legacy of racial segregation and discrimination, with manifest disparities leading to unmet health related social needs (HRSNs) such as access to basic resources and health care to treat higher hazard exposures. Coastal cities such as Norfolk, Virginia, USA, exhibit increased tidal, rainfall, and storm surge flooding owing to sea level and climate changes exacerbated by subsidence. Cities lack high-resolution compound flood forecasting and have disparity in exposure and inequitable outcomes, and timely response and future planning to mitigate or adapt to hazards require new techniques and data integration. This project developed the needs, framework and prototype digital architecture and foundations for a digital twin to enable analysis and predictive modeling of coastal flooding. Results outline the impediments and opportunities for open data and scientific analysis of interoperable in situ sensors (coastal flooding), Earth observation imagery, hydrodynamic models, and geospatial data and predictive impact models. Thomas R. Allen 0001, George McLeod, Heather Lipford, Alex Nielsen |
IGARSS | 3 |
| 2022 | Evaluating Students' Perceptions of Online Learning with 2-D Virtual SpacesabstractThe COVID-19 pandemic led the majority of educational institutions to rapidly shift to primarily conducting courses through online, remote delivery. Across different institutions, the tools used for synchronous online course delivery varied. They included traditional video conferencing tools like Zoom, Google Meet, and WebEx as well as non-traditional tools like Gather.Town, Gatherly, and YoTribe. The main distinguishing characteristic of these nontraditional tools is their utilization of 2-D maps to create virtual meeting spaces that mimic real-world spaces. Nadia Najjar, Anna Stubler, Harini Ramaprasad, Heather Lipford, David C. Wilson |
SIGCSE (1) | 4 |
| 2022 | From Parental Control to Joint Family Oversight: Can Parents and Teens Manage Mobile Online Safety and Privacy as Equals?abstractOur research aims to highlight and alleviate the complex tensions around online safety, privacy, and smartphone usage in families so that parents and teens can work together to better manage mobile privacy and security-related risks. We developed a mobile application ("app") for Community Oversight of Privacy and Security ("CO-oPS") and had parents and teens assess whether it would be applicable for use with their families. CO-oPS is an Android app that allows a group of users to co-monitor the apps installed on one another's devices and the privacy permissions granted to those apps. We conducted a study with 19 parent-teen (ages 13-17) pairs to understand how they currently managed mobile safety and app privacy within their family and then had them install, use, and evaluate the CO-oPS app. We found that both parents and teens gave little consideration to online safety and privacy before installing new apps or granting privacy permissions. When using CO-oPS, participants liked how the app increased transparency into one another's devices in a way that facilitated communication, but were less inclined to use features for in-app messaging or to hide apps from one another. Key themes related to power imbalances between parents and teens surfaced that made co-management challenging. Parents were more open to collaborative oversight than teens, who felt that it was not their place to monitor their parents, even though both often believed parents lacked the technological expertise to monitor themselves. Our study sheds light on why collaborative practices for managing online safety and privacy within families may be beneficial but also quite difficult to implement in practice. We provide recommendations for overcoming these challenges based on the insights gained from our study. Mamtaj Akter, Amy J. Godfrey, Jessica Kropczynski, Heather Lipford, Pamela J. Wisniewski |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2021 | Exploring Perceptions of a Localized Content-Sharing System Using Users-as-Beacons
Md. Nazmus Sakib Miazi, Heather Lipford, Mohamed Shehab |
INTERACT (2) | 2 |
| 2021 | Effects of Privacy Notification Style and Frequency on Phone UsageabstractMany proposed mechanisms for helping people understand the security or privacy of their information involve notifying users at various times regarding how that information is used or shared. However, there is a limit as to how many notifications users could attend to, and increasing the frequency and intrusiveness of the notifications will at some point reduce their effectiveness. We do not yet have good guidelines regarding such tradeoffs for different styles of notifications. In this article, we compare users’ reactions and perceived usefulness of notifications of information access on a smart phone, testing the boundaries of acceptability for four different modes of notifications. Our results indicate that the notifications did increase participants’ awareness of information access, but that even for relatively passive notifications, people became annoyed at fairly low frequencies, and phone use was reduced as frequencies increased. Andrew Besmer, Tyler Thomas, Heather Lipford |
J. Comput. Inf. Syst. | 3 |
| 2021 | Examining Collaborative Support for Privacy and Security in the Broader Context of Tech CaregivingabstractManaging digital privacy and security is often a collaborative process, where groups of individuals work together to share information and give one another advice. Yet, this collaborative process is not always reciprocal or equally shared. In many cases, individuals with more expertise help others without receiving help in return. Therefore, we studied the phenomenon of "Tech Caregiving" by surveying 20 groups (112 individuals) comprised of friends, family members, and/or co-workers who identified at least one member of their group as a someone who provides informal technical support to the people they know. We found that tech caregivers reported significantly higher levels of power use and self-efficacy for digital privacy and security, compared to tech caregivees. However, caregivers and caregivees did not differ based on their self-reportedcommunity collective-efficacy for collaboratively managing privacy and security together as a group. This finding demonstrates the importance of tech caregiving and community belonging in building community collective efficacy for digital privacy and security. We also found that caregivers and caregivees most often communicated via text message or phone when coordinating support, which was most frequently needed when troubleshooting or setting up new devices. Meanwhile, discussions specific to privacy and security represented only a small fraction of the issues for which participants gave or received tech care. Thus, we conclude that educating tech caregivers on how to provide privacy and security-focused support, as well as designing technologies that facilitate such support, has the potential to create positive networks effects towards the collective management of digital privacy and security. Jessica Kropczynski, Reza Ghaiumy Anaraky, Mamtaj Akter, Amy J. Godfrey, Heather Lipford, Pamela J. Wisniewski |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2020 | Smart Home Beyond the Home: A Case for Community-Based Access ControlabstractAs smart devices are becoming commonplace in homes, we need to explore the needs of not just the residents of the home, but also of secondary stakeholders who may be granted access to these devices from outside of the home. We conducted a mixed methods study, which included a survey of 163 smart home device owners and a follow-up interview with 13 individuals who currently share their smart home devices with others outside of their home. Nearly half (47.8%) of our survey participants shared at least one smart home device with someone that did not live with them. Individuals sought greater safety and security by providing remote access to trusted family members or friends. By understanding users' perspectives about privacy and trust in relation to sharing smart home devices beyond the home, we build a case for community-based access control of smart home devices in the Internet of Things. Madiha Tabassum, Jessica Kropczynski, Pamela J. Wisniewski, Heather Lipford |
CHI | 4 |
| 2020 | Towards Building Community Collective Efficacy for Managing Digital Privacy and Security within Older Adult CommunitiesabstractOlder adults are increasingly becoming adopters of digital technologies, such as smartphones; however, this population remains particularly vulnerable to digital privacy and security threats. To date, most research on technology used among older adults focuses on helping individuals overcome their discomfort or lack of expertise with technology to protect them from such threats. Instead, we are interested in how communities of older adults work together to collectively manage their digital privacy and security. To do this, we surveyed 67 individuals across two older adult communities (59 older adults and eight employees or volunteers) and found that the community's collective efficacy for privacy and security was significantly correlated with the individuals' self-efficacy, power usage of technology, and their sense of community belonging. Community collective efficacy is a group's mutual belief in its ability to achieve a shared goal. Using social network analysis, we further unpacked these relationships to show that many older adults interact with others who have similar technological expertise, and closer-knit older adult communities that have low technology expertise (i.e., low power usage and self-efficacy) may increase their community collective efficacy for privacy and security by embedding facilitators (e.g., employees or volunteers) who have more technical expertise within their communities. Our work demonstrates how both peer influence and outside expertise can be leveraged to support older adults in managing their digital privacy and security. Jessica Kropczynski, Zaina Aljallad, Nathan Jeffrey Elrod, Heather Lipford, Pamela J. Wisniewski |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2019 | Motivating Students Beyond Course Requirements with a Serious GameabstractEducators are challenged to provide computer science students enough skills-based practice within the confines of a course. Yet it is also difficult to motivate students to spend additional time for further practice outside of course requirements. We are investigating games and gamification as methods for motivating students to engage in additional practice. In this paper, we report on the study of a fantasy-themed serious game to teach Ruby programming skills. We examine how well it motivated students to complete additional levels of the game than was assigned for course credit in an undergraduate Software Engineering course. Of the 185 student participants, 42.78% completed one or more optional game levels. These students spent more than twice as much time playing than their counterparts who only completed the mandatory game levels. Stacey Watson, Heather Lipford |
SIGCSE | 2 |
| 2019 | Co-designing for Community Oversight: Helping People Make Privacy and Security Decisions TogetherabstractCollective feedback can support an individual's decision-making process. For instance, individuals often seek the advice of friends, family, and co-workers to help them make privacy decisions. However, current technologies often do not provide mechanisms for this type of collaborative interaction. To address this gap, we propose a novel model of Community Oversight for Privacy and Security ("CO-oPS"), which identifies mechanisms for users to interact with people they trust to help one another make digital privacy and security decisions. We apply our CO-oPS model in the context of mobile applications ("apps"). To interrogate and refine this model, we conducted participatory design sessions with 32 participants in small groups of 2-4 people who know one another, with the goal of designing a mobile app that facilitates collaborative privacy and security decision-making. We describe and reflect on the opportunities and challenges that arise from the unequal motivation and trust in seeking support and giving support within and beyond a community. Through this research, we contribute a novel framework for collaborative digital privacy and security decision-making and provide empirical evidence towards how researchers and designers might translate this framework into design-based features. Chhaya Chouhan, Christy M. LaPerriere, Zaina Aljallad, Jessica Kropczynski, Heather Lipford, Pamela J. Wisniewski |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2019 | How Developers Diagnose Potential Security Vulnerabilities with a Static Analysis ToolabstractWhile using security tools to resolve security defects, software developers must apply considerable effort. Success depends on a developer's ability to interact with tools, ask the right questions, and make strategic decisions. To build better security tools and subsequently help developers resolve defects more accurately and efficiently, we studied the defect resolution process-from the questions developers ask to their strategies for answering them. In this paper, we report on an exploratory study with novice and experienced software developers. We equipped them with Find Security Bugs, a security-oriented static analysis tool, and observed their interactions with security vulnerabilities in an open-source system that they had previously contributed to. We found that they asked questions not only about security vulnerabilities, associated attacks, and fixes, but also questions about the software itself, the social ecosystem that built the software, and related resources and tools. We describe the strategic successes and failures we observed and how future tools can leverage our findings to encourage better strategies. Justin Smith 0001, Brittany Johnson, Emerson R. Murphy-Hill, Bill Chu, Heather Lipford |
IEEE Trans. Software Eng. | 5 |
| 2018 | Increasing User Attention with a Comic-based PolicyabstractEnd user license agreements, terms of service agreements and privacy policies all suffer from many of the same problems: people rarely read them and yet still agree to whatever is contained within them. There are many usability challenges with these policies: they are often lengthy, with jargon filled language that is difficult to quickly comprehend. However, these notices are the primary tool for users to understand the privacy implications of their digital activities and make informed decisions on which websites and software they use. Prior research has explored alternative designs for such notices, using more visual and structured interfaces for conveying information. We expand upon these results by exploring a comic-based interface, examining whether it can engage users to pay more attention to a terms of service agreement. Our results indicate that the comic version did hold user attention for longer than text-based alternatives, encouraging deeper investigation into comic-based interfaces. Madiha Tabassum, Abdulmajeed Alqhatani, Marran Aldossari, Heather Lipford |
CHI | 4 |
| 2018 | Security During Application Development: an Application Security Expert PerspectiveabstractMany of the security problems that people face today, such as security breaches and data theft, are caused by security vulnerabilities in application source code. Thus, there is a need to understand and improve the experiences of those who can prevent such vulnerabilities in the first place - software developers as well as application security experts. Several studies have examined developers' perceptions and behaviors regarding security vulnerabilities, demonstrating the challenges they face in performing secure programming and utilizing tools for vulnerability detection. We expand upon this work by focusing on those primarily responsible for application security - security auditors. In an interview study of 32 application security experts, we examine their views on application security processes, their workflows, and their interactions with developers in order to further inform the design of tools and processes to improve application security. Tyler Thomas, Madiha Tabassum, Bill Chu, Heather Lipford |
CHI | 4 |
| 2018 | Evaluating Two Methods for Integrating Secure Programming EducationabstractSecurity vulnerabilities are still prevalent in today's software, yet many can be prevented with standard secure programming techniques. Thus, educators of future developers need to teach students not just how to program, but how to program securely. Many researchers advocate integrating secure programming knowledge and skills across the computer science curriculum. In this paper, we report the results of a study comparing two such methods: our own tool ESIDE, which provides students with security warnings on assignment code, and a security-clinic approach, a one-on-one session with a teaching assistant. Both methods suffered from challenges in incentivizing students to incorporate secure programming techniques into their code. We discuss the relative strengths and weaknesses of these methods, and the challenges of timing and motivation of secure programming education. Madiha Tabassum, Stacey Watson, Bill Chu, Heather Lipford |
SIGCSE | 4 |
| 2018 | Developing Soft Skills with a Classroom Behavior Management Game: (Abstract Only)abstractSoft skills such as collaboration, communication and time management are essential to the success of computer science students both in school and after they enter the IT profession. While employers value these skills highly, there are so many technical skills to cover in computer science programs that these soft skills are not typically primary learning objectives for CS classes. As such, it is difficult to find time and space to address them directly. In this study, we investigate whether Classcraft, a game-based classroom behavior management platform designed for K-12 students, can motivate undergraduate students to develop their soft skills in large computing classes. To this end, we utilized Classcraft with 234 students across two face-to-face sections and one online section of an undergraduate "Introduction to Operating Systems and Networking" course to determine whether gamifying the engagement component of the course would motivate students to participate in co-curricular activities, enhance student collaboration and improve communication and time management. There were no in-game activities - the students in each section of the class earned experience points in Classcraft as a reward for completing class activities ahead of time, collaborative learning and teamwork, and asking or answering questions in class or via discussion forums in our learning management system. In this poster, we report our preliminary results of the impact of such a platform on student engagement in soft skills. Stacey Watson, Julio César Bahamón, Harini Ramaprasad, Heather Lipford |
SIGCSE | 4 |
| 2017 | Detecting Cross-Site Scripting Vulnerabilities through Automated Unit TestingabstractThe best practice to prevent Cross Site Scripting (XSS) attacks is to apply encoders to sanitize untrusted data. To balance security and functionality, encoders should be applied to match the web page context, such as HTML body, JavaScript, and style sheets. A common programming error is the use of a wrong encoder to sanitize untrusted data, leaving the application vulnerable. We present a security unit testing approach to detect XSS vulnerabilities caused by improper encoding of untrusted data. Unit tests for the XSS vulnerability are automatically constructed out of each web page and then evaluated by a unit test execution framework. A grammar-based attack generator is used to automatically generate test inputs. We evaluate our approach on a large open source medical records application, demonstrating that we can detect many 0-day XSS vulnerabilities with very low false positives, and that the grammar-based attack generator has better test coverage than industry best practices. Mahmoud Mohammadi, Bill Chu, Heather Lipford |
QRS | 3 |
| 2017 | Comparing Educational Approaches to Secure programming: Tool vs. TA
Madiha Tabassum, Stacey Watson, Heather Lipford |
SOUPS | 3 |
| 2017 | A Proposed Visualization for Vulnerability Scan Data
Stacey Watson, Heather Lipford |
SOUPS | 2 |
| 2017 | Making privacy personal: Profiling social network users to inform privacy education and nudging
Pamela J. Wisniewski, Bart P. Knijnenburg, Heather Lipford |
Int. J. Hum. Comput. Stud. | 3 |
| 2016 | Detecting Privilege Escalation Attacks through Instrumenting Web Application Source CodeabstractPrivilege Escalation is a common and serious type of security attack. Although experience shows that many applications are vulnerable to such attacks, attackers rarely succeed upon first trial. Their initial probing attempts often fail before a successful breach of access control is achieved. This paper presents an approach to automatically instrument application source code to report events of failed access attempts that may indicate privilege escalation attacks to a run time application protection mechanism. The focus of this paper is primarily on the problem of instrumenting web application source code to detect access control attack events. We evaluated false positives and negatives of our approach using two open source web applications. Jun Zhu 0002, Bill Chu, Heather Lipford |
SACMAT | 3 |
| 2016 | A Body of Knowledge for Usable Security and Privacy Education (Abstract Only)abstractThe importance of usability in security and privacy technologies is now widely accepted. A vibrant and growing research community in usable security and privacy has contributed a wide range of results in the past 15 years. Despite this, the vast majority of computing students are being exposed to very little of this discipline. In this presentation, we describe our ongoing efforts to enable broader education in this area. We are leading the construction of a body of knowledge for usable security and privacy education, to serve as an organizing framework for the discipline. We are also creating online learning modules for several key topics, as resources for faculty and students. We seek feedback on these resources as well as faculty participants who are interested in utilizing and evaluating the learning modules. Yousra Javed, Heather Lipford |
SIGCSE | 2 |
| 2015 | POSTER: Using Unit Testing to Detect Sanitization FlawsabstractInput sanitization mechanisms are widely used to mitigate vulnerabilities to injection attacks such as cross-site scripting. Static analysis tools and techniques commonly used to ensure that applications utilize sanitization functions. Dynamic analysis must be to evaluate the correctness of sanitization functions. The proposed approach is based on unit testing to bring the advantages of both static and dynamic techniques to the development time. Our approach introduces a technique to automatically extract the sanitization functions and then evaluate their effectiveness against attacks using automatically generated attack vectors. The empirical results show that the proposed technique can detect security flaws cannot find by the static analysis tools. Mahmoud Mohammadi, Bill Chu, Heather Lipford |
CCS | 3 |
| 2015 | Mitigating Access Control Vulnerabilities through Interactive Static AnalysisabstractAccess control vulnerabilities due to programming errors have consistently ranked amongst top software vulnerabilities. Previous research efforts have concentrated on using automatic program analysis techniques to detect access control vulnerabilities in applications. We report a comparative study of six open source PHP applications, and find that implicit assumptions of previous research techniques can significantly limit their effectiveness. We propose a more effective hybrid approach to mitigate access control vulnerabilities. Developers are reminded in-situ of potential access control vulnerabilities, where self-review of code can help them discover mistakes. Additionally, developers are prompted for application-specific access control knowledge, providing samples of code that could be thought of as static analysis by example. These examples are turned into code patterns that can be used in performing static analysis to detect additional access control vulnerabilities and alert the developer to take corrective actions. Our evaluation of six open source applications detected 20 zero-day access control vulnerabilities in addition to finding all access control vulnerabilities detected in previous works. Jun Zhu 0002, Bill Chu, Heather Lipford, Tyler Thomas |
SACMAT | 3 |
| 2015 | Flipped Classroom Strategies for CS EducationabstractThe basic principles of a flipped classroom teaching method are to deliver content outside of the class and to move active learning into the classroom. There are many strategies for delivering the content online, such as having instructors prepare online lectures, wrapping the course around a MOOC, and curating online videos from various sources. There are also many strategies for including active learning in the classroom that go beyond providing programming labs, and can include various forms of peer instruction. In this paper we describe our experiences flipping four different computer science classes across multiple semesters over two years. This breadth of experience with classroom flipping has enabled us to compare strategies and approaches and develop an understanding of which approaches appear to work under which circumstances. We discuss how we structured out-of-class preparatory work, how we created or sourced online videos, how we used active learning activities in-class to scaffold skills development and identify students' misconceptions, and how we structured teams for in class activities. This paper contributes a set of flexible strategies to consider for provision of curricular content out-of-class, structuring students' preparatory work, applying active learning of skills and concepts, and leveraging social interaction and peer instruction for CS education. We present the impact of our approaches based upon leading indicators of course evaluations and student surveys. We discuss lessons learned and students' responses to our strategies. Mary Lou Maher, Celine Latulipe, Heather Lipford, Audrey Rorrer |
SIGCSE | 3 |
| 2015 | Embedding Secure Coding Instruction into the IDE: A Field Study in an Advanced CS CourseabstractMany of the security vulnerabilities common in today's software can be prevented with standard secure coding practices. Computer science students who will become the developers of that software need to learn about those practices so they can prevent such vulnerabilities. Many computing programs are addressing this need through additional lectures, elective courses, or more holistic approaches to integrate security across curriculums. We are exploring a complementary approach, integrating secure coding education into the IDE to provide a learning opportunity in the context of writing code. In this paper, we report on two field studies using an IDE tool in an advanced Web programming course. Our results indicate that the tool can increase students' awareness and knowledge of secure programming, but to be most effective, instructors may need to incentivize its use through in-class methods and careful timing of its introduction. Michael Whitney, Heather Lipford, Bill Chu, Jun Zhu 0002 |
SIGCSE | 2 |
| 2015 | Questions developers ask while diagnosing potential security vulnerabilities with static analysisabstractSecurity tools can help developers answer questions about potential vulnerabilities in their code. A better understanding of the types of questions asked by developers may help toolsmiths design more effective tools. In this paper, we describe how we collected and categorized these questions by conducting an exploratory study with novice and experienced software developers. We equipped them with Find Security Bugs, a security-oriented static analysis tool, and observed their interactions with security vulnerabilities in an open-source system that they had previously contributed to. We found that they asked questions not only about security vulnerabilities, associated attacks, and fixes, but also questions about the software itself, the social ecosystem that built the software, and related resources and tools. For example, when participants asked questions about the source of tainted data, their tools forced them to make imperfect tradeoffs between systematic and ad hoc program navigation strategies. Justin Smith 0001, Brittany Johnson, Emerson R. Murphy-Hill, Bill Chu, Heather Lipford |
ESEC/SIGSOFT FSE | 5 |
| 2015 | A study of interactive code annotation for access control vulnerabilitiesabstractWhile there are a variety of existing tools to help detect security vulnerabilities in code, they are seldom used by developers due to the time or security expertise required. We are investigating techniques integrated within the IDE to help developers detect and mitigate security vulnerabilities. In this paper, we examine using interactive annotation for access control vulnerabilities. We evaluated whether developers could indicate access control logic using interactive annotation and understand the vulnerabilities reported as a result. Our study indicates that developers can easily find and annotate access control logic but can struggle to use our tool to trace the cause of the vulnerability. Our results provide design guidance for improving the interaction and communication of such security tools with developers. Tyler Thomas, Bill Chu, Heather Lipford, Justin Smith 0001, Emerson R. Murphy-Hill |
VL/HCC | 3 |
| 2015 | Facebook apps and tagging: The trade-off between personal privacy and engaging with friendsabstractThe use of social network sites offers many potential social benefits, but also raises privacy concerns and challenges for users. The trade‐off users have to make between using sites such as Facebook to connect with their friends versus protecting their personal privacy is not well understood. Furthermore, very little behavioral research has focused on how personal privacy concerns are related to information disclosures made by one's friends. Our survey study of 116 Facebook users shows that engaging with friends through tagging activity and third‐party application use is associated with higher levels of personal Facebook usage and a stronger emotional attachment to Facebook. However, users who have high levels of personal privacy concern and perceive a lack of effectiveness in Facebook's privacy policies tend to engage less frequently in tagging and app activities with friends, respectively. Our model and results explore illustrate the complexity of the trade‐off between privacy concerns, engaging with friends through tagging and apps, and Facebook usage. Pamela J. Wisniewski, Heather Lipford, Emmanuel Bello-Ogunu |
J. Assoc. Inf. Sci. Technol. | 3 |
| 2015 | Mapping User Preference to Privacy Default SettingsabstractManaging the privacy of online information can be a complex task often involving the configuration of a variety of settings. For example, Facebook users determine which audiences have access to their profile information and posts, how friends can interact with them through tagging, and how others can search for them—and many more privacy tasks. In most cases, the default privacy settings are permissive and appear to be designed to promote information sharing rather than privacy. Managing privacy online can be complex and often users do not change defaults or use granular privacy settings. In this article, we investigate whether default privacy settings on social network sites could be more customized to the preferences of users. We survey users' privacy attitudes and sharing preferences for common SNS profile items. From these data, we explore using audience characterizations of profile items to quantify fit scores that indicate how well default privacy settings represent user privacy preferences. We then explore the fit of various schemes, including examining whether privacy attitude segmentation can be used to improve default settings. Our results suggest that using audience characterizations from community data to create default privacy settings can better match users' desired privacy settings. Jason Watson, Heather Lipford, Andrew Besmer |
ACM Trans. Comput. Hum. Interact. | 2 |
| 2014 | SIW 2014: First Workshop on Security Information WorkersabstractThe human element is often considered the weakest element in security. Although many kinds of humans interact with systems that are designed to be secure, one particular type of human is especially important, the security information worker. Security information workers include software developers, system administrators, and intelligence analysts. This workshop aims to develop and stimulate discussion about security information workers. Emerson R. Murphy-Hill, Heather Lipford, Bill Chu, Robert Biddle |
CCS | 2 |
| 2013 | Interactive support for secure programming educationabstractSoftware flaws are a root cause of many of today's information security vulnerabilities. Current curricula emphasis on traditional information security issues does not address this root cause. We propose educating students on secure programming techniques through interactive tool support in the Integrated Development Environment (IDE). We believe this approach can complement other curricula efforts by teaching and providing continuous reinforcement of practices throughout programming tasks. In this paper, we evaluate our prototype tool, ASIDE, which provides instant security warnings, detailed explanations of vulnerabilities, and code generation. We report the results of an observational study on 20 students from an advanced Web programming course. The results provide early evidence that our tool could potentially help students learn about and practice secure programming in the context of their programming assignments. Jun Zhu 0002, Heather Lipford, Bill Chu |
SIGCSE | 2 |
| 2012 | Fighting for my space: coping mechanisms for sns boundary regulationabstractSharing information online via social network sites (SNSs) is at an all-time high, yet research shows that users often exhibit a marked dissatisfaction in using such sites. A compelling explanation for this dichotomy is that users are struggling against their SNS environment in an effort to achieve their preferred levels of privacy for regulating social interactions. Our research investigates users' SNS boundary regulation behavior. This paper presents results from a qualitative interview-based study to identify "coping mechanisms" that users devise outside explicit boundary-regulation interface features in order to manage interpersonal boundaries. Our categorization of such mechanisms provides insight into interaction design issues and opportunities for new SNS features. Pamela J. Wisniewski, Heather Lipford, David C. Wilson |
CHI | 2 |
| 2012 | Evaluating interactive support for secure programmingabstractImplementing secure code is an important and oft-overlooked non-functional requirement. Secure programming errors are a subset of program errors that result in many common privacy and security breaches in commercial software. We are seeking to provide interactive support for secure programming in the development environment. In this paper, we have evaluated our prototype tool, ASIDE, which provides real-time warnings and code generation to reduce secure programming errors introduced by programmers. We evaluate the potential use and effectiveness of ASIDE on both novice and professional developers in two comparison user studies. Our results demonstrate that the interactive support can help address this important non-functional requirement, and suggest guidelines for such tools to support programmers. Jing Xie 0011, Heather Lipford, Bei-tseng Chu |
CHI | 2 |
| 2012 | Someone to watch over meabstractTraditional security mechanisms are part of a larger socio-technical system involving the people and organizations that use them. Yet, those security mechanisms rarely take this social context and social processes into account. In this paper we propose to make security more social, by integrating community oversight into security mechanisms. Like a neighborhood watch, community oversight can provide additional information as more people are able to detect anomalies and problems, as well as foster greater awareness and social norms of security-related behaviors. We describe this new paradigm, several scenarios of use, and the sets of issues involved in implementing this approach. Heather Lipford, Mary Ellen Zurko |
NSPW | 1 |
| 2012 | +Your circles: sharing behavior on Google+abstractUsers are sharing and consuming enormous amounts of information through online social network interaction every day. Yet, many users struggle to control what they share to their overlapping social spheres. Google+ introduces circles, a mechanism that enables users to group friends and use these groups to control their social network feeds and posts. We present the results of a qualitative interview study on the sharing perceptions and behavior of 27 Google+ users. These results indicate that many users have a clear understanding of circles, using them to target information to those most interested in it. Yet, despite these positive perceptions, there is only moderate use of circles to control information flow. We explore reasons and risks associated with these behaviors and provide insight on the impact and open questions of this privacy mechanism. Jason Watson, Andrew Besmer, Heather Lipford |
SOUPS | 3 |
| 2011 | ASIDE: IDE support for web application securityabstractMany of today's application security vulnerabilities are introduced by software developers writing insecure code. This may be due to either a lack of understanding of secure programming practices, and/or developers' lapses of attention on security. Much work on software security has focused on detecting software vulnerabilities through automated analysis techniques. While they are effective, we believe they are not sufficient. We propose to increase developer awareness and promote practice of secure programming by interactively reminding programmers of secure programming practices inside Integrated Development Environments (IDEs). We have implemented a proof-of-concept plugin for Eclipse and Java. Initial evaluation results show that this approach can detect and address common web application vulnerabilities and can serve as an effective aid for programmers. Our approach can also effectively complement existing software security best practices and significantly increase developer productivity. Jing Xie 0011, Bill Chu, Heather Lipford, John T. Melton |
ACSAC | 3 |
| 2011 | Why do programmers make security errors?abstractA large number of software security vulnerabilities are caused by software errors that are committed by software developers. We believe that interactive tool support will play an important role in aiding software developers to develop more secure software. However, an in-depth understanding of how and why software developers produce security bugs is needed to design such tools. We conducted a semi-structured interview study on 15 professional software developers to understand their perceptions and behaviors related to software security. Our results reveal a disconnect between developers' conceptual understanding of security and their attitudes regarding their personal responsibility and practices for software security. Jing Xie 0011, Heather Lipford, Bill Chu |
VL/HCC | 2 |
| 2010 | Moving beyond untagging: photo privacy in a tagged worldabstractPhoto tagging is a popular feature of many social network sites that allows users to annotate uploaded images with those who are in them, explicitly linking the photo to each person's profile. In this paper, we examine privacy concerns and mechanisms surrounding these tagged images. Using a focus group, we explored the needs and concerns of users, resulting in a set of design considerations for tagged photo privacy. We then designed a privacy enhancing mechanism based on our findings, and validated it using a mixed methods approach. Our results identify the social tensions that tagging generates, and the needs of privacy tools to address the social implications of photo privacy management. Andrew Besmer, Heather Lipford |
CHI | 2 |
| 2010 | Visual vs. compact: a comparison of privacy policy interfacesabstractIn this paper, we compare the impact of two different privacy policy representations -- AudienceView and Expandable Grids -- on users modifying privacy policies for a social network site. Despite the very different interfaces, there were very few differences in user performance. However, users had clear, and different, preferences and acknowledged the tradeoffs between the two representations. Our results imply that while either interface would be a usable option for policy settings, a combination may appeal to a wider audience and offer the best of both worlds. Heather Lipford, Jason Watson, Michael Whitney, Katherine Froiland, Robert W. Reeder |
CHI | 1 |
| 2010 | Users' (mis)conceptions of social applications
Andrew Besmer, Heather Lipford |
Graphics Interface | 2 |
| 2010 | The impact of social navigation on privacy policy configurationabstractSocial navigation is a promising approach to help users make better privacy and security decisions using community knowledge and expertise. Social navigation has recently been applied to several privacy and security systems such as peer-to-peer file sharing, cookie management, and firewalls. However, little empirical evaluation of social navigation cues has been performed in security or privacy systems to understand the real impact such knowledge has on user behavior and the resulting policies. In this paper, we explore the application of social navigation to access control policy configuration using an empirical between subjects study. Our results indicate that community information does impact user behavior, but only when the visual representation of the cue is sufficiently strong. Andrew Besmer, Jason Watson, Heather Lipford |
SOUPS | 3 |
| 2009 | Social applications: exploring a more secure frameworkabstractOnline social network sites, such as MySpace, Facebook and others have grown rapidly, with hundreds of millions of active users. A new feature on many sites is social applications -- applications and services written by third party developers that provide additional functionality linked to a user's profile. However, current application platforms put users at risk by permitting the disclosure of large amounts of personal information to these applications and their developers. This paper formally abstracts and defines the current access control model applied to these applications, and builds on it to create a more secure framework. We do so in the interest of preserving as much of the current architecture as possible, while seeking to provide a practical balance between security and privacy needs of the users, and the needs of the applications to access users' information. We present a user study of our interface design for setting a user-to-application policy. Our results indicate that the model and interface work for users who are more concerned with their privacy, but we still need to explore alternate means of creating policies for those who are less concerned. Andrew Besmer, Heather Lipford, Mohamed Shehab, Gorrell P. Cheek |
SOUPS | 2 |
| 2008 | Charting new ground: modeling user behavior in interactive geovisualizationabstractGeovisualization has traditionally played a critical role in analysis and decision-making, but recent developments have also brought a revolution in widespread online access to geographic data and integration tools, particularly for map-based interfaces. This next generation of geovisualization applications is often characterized by high interactivity and strong end-user participation in both development and use. Building the most effective tools to support user-centered geographic visualization faces a significant challenge, though: very little is known about how people interact with maps. To date, map use research has typically focused on higher order use goals or cognitive interpretations of static map representations. Our research employs Human-Computer Interaction approaches in order to investigate user behaviors that contribute to interactive map use and understanding. This paper describes our approach to studying geovisualization interaction and presents our pilot user studies and initial interaction model. By building a better understanding of how people interact with map interfaces, we will be able to design better user-centered geographic visualizations and learn how to best customize these applications to specific user groups. David C. Wilson, Heather Lipford, Erin A. Carroll, Pamela J. Wisniewski, Nadia Najjar |
GIS | 2 |
| 2008 | Reviewing Meetings in TeamSpaceabstractA number of prototype meeting capture applications have been created in the past decade, yet relatively little research has focused on the review and long-term use of real captured meeting information. To that end, we have implemented a system called TeamSpace for capturing and reviewing general meetings. In this article, we describe the long-term deployment of TeamSpace to a university research group, along with a pseudo-controlled study involving the same group of users and their meetings. We gained a detailed understanding of the behavioral patterns involved in reviewing meeting content and how to improve on the experience. Our evaluations also demonstrate several of the barriers and challenges in realizing the potential benefits of meeting capture. Heather Lipford, Gregory D. Abowd |
Hum. Comput. Interact. | 1 |
| 2007 | Game2Learn: building CS1 learning games for retentionabstractThis paper presents Game2Learn, an innovative project designed to leverage games in retaining students in computer science (CS). In our two-pronged approach, students in integrative final-year capstone courses and summer research experiences develop games to teach computer science, which, in turn, will be used to improve introductory computing courses. Our successful model for summer undergraduate research and capstone projects engages students in solving the computing retention problem, allows them to quickly create games, and instructs students in user- and learner-centered design and research methods. Results show that this method of building games to teach engages students at multiple levels, inspiring newer students that one day their homework may all be games, and encouraging advanced students to continue on into graduate studies in computing. Tiffany Barnes, Heather Lipford, Eve Powell, Amanda Chaffin, Alex Godwin |
ITiCSE | 2 |
| 2007 | Examining privacy and disclosure in a social networking communityabstractThe polularity of social networking websites such as Facebook and the subsequent levels and depth of online disclosures have raised several concerns for user privacy. Previous research into these sites has indicated the importance of disclosures between users as well as an under-utilization of extensive privacy options. This study qualitatively examines college students' disclosure and privacy behaviors and attitudes on Facebook.com. Results support current research into social networking and privacy and provide user-generated explanations for observed disclosure and privacy trends. Implications for future research into privacy software are discussed. Katherine Strater, Heather Lipford |
SOUPS | 2 |
| 2005 | An empirical investigation of capture and access for software requirements activities
Heather Lipford, Christopher A. Miller 0001, Gregory D. Abowd, Idris Hsi |
Graphics Interface | 1 |
| 2005 | Towards a Smarter Meeting Record-Capture and Access of Meetings Revisited
Werner Geyer, Heather Lipford, Gregory D. Abowd |
Multim. Tools Appl. | 2 |
| 2004 | Tagging Knowledge Acquisition Sessions To Facilitate Knowledge TraceabilityabstractKnowledge Acquisition (KA) is important throughout systems development for gathering expert domain knowledge that is incorporated into the requirements and design of a system. There are problems ensuring that accurate and useful knowledge is captured initially, refined as needed, and transferred to later development efforts in a usable format. We present a method, called tagging, for addressing these problems without undue burden on the KA practitioners, along with initial studies to examine the feasibility of real-time tagging and to inform the design of a tool called TAGGER. TAGGER operates by permitting KA discussions to be "tagged" as they happen with concepts and groupings relevant to software development. Heather Lipford, Gregory D. Abowd, Christopher A. Miller 0001, Harry Funk |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2003 | Making multimedia meeting records more meaningfulabstractMeetings contain a large amount of rich project information that is often not documented. Capturing audio and video of a meeting can provide a comprehensive meeting record. However, finding detailed information in that record can be challenging because there is no structural information other than time to help the user navigate. This paper surveys various ways of creating indices into meeting records and introduces the notion of creating indices based upon user interaction with domain-specific artifacts. As an example, we present a prototype system that uses general team artifacts to provide meaningful pointers into the meeting record. Werner Geyer, Heather Lipford, Gregory D. Abowd |
ICME | 2 |
| 2003 | Tagging Knowledge Acquisition Sessions to Facilitate Knowledge Traceability
Heather Lipford, Gregory D. Abowd, Christopher A. Miller 0001, Harry Funk |
SEKE | 1 |
| 2001 | A team collaboration space supporting capture and access of virtual meetingsabstractIn this paper, we address the design issues of a collaborative workspace system, called TeamSpace, that supports geographically distributed teams by managing shared work processes and maintaining shared artifacts in a project. TeamSpace attempts to integrate both synchronous and asynchronous types of team interaction into a task-oriented environment. Since meetings are an integral part of teamwork, our current work focuses on supporting virtual meetings as part of a larger collaborative work process. We present an initial TeamSpace prototype that supports asynchronous meeting management seamlessly integrated with capture and access of synchronous distributed meetings. The captured synchronous data is integrated with other related information in TeamSpace, enabling users to efficiently gain knowledge of both current and past team activities. Werner Geyer, Heather Lipford, Ludwin Fuchs, Tom Frauenhofer, Shahrokh Daijavad, Steven E. Poltrock |
GROUP | 2 |
| 2001 | Integrating Meeting Capture within a Collaborative Team Environment
Heather Lipford, Gregory D. Abowd, Werner Geyer, Ludwin Fuchs, Shahrokh Daijavad, Steven E. Poltrock |
UbiComp | 1 |
| 2000 | A Proposed Curriculum for an Undergraduate Software Engineering DegreeabstractWe have developed a curriculum for a software engineering undergraduate degree. We used the medical school clinical model to guide our design as it successfully combines both knowledge and practice components. Through rotations, our curriculum will provide graduates with both an advanced knowledge of software engineering concepts and practical skills that have been honed in a realistic setting. We present our proposed curriculum and the difficulties we foresee in implementing it. Michael McCracken, Idris Hsi, Heather Lipford, Robert Waters, Laura Burkhart |
CSEE&T | 3 |
| 1997 | Formalizing and Integrating the Dynamic Model within OMTabstractThe Object Modeling Technique (OMT), a commonly used object-oriented development technique, comprises the object, dynamic, and functional models to provide three complementary views that graphically describe different aspects of systems.The lack of a well-defined semantics for the integration of the three models hinders the overall development process, particularly during the design phase.Previously, we formalized the object model in terms of algebraic specifications.However, the algebraic specifications only capture the static, structural aspects of a system.They do not explicitly describe the behavior, which is critical for system development, especially for the design phase.It is necessary to formalize the dynamic model in terms of the structural descriptions in order to specify and verify the system behavior using rigorous techniques.This paper presents a well-defined formal model for both the object and dynamic models and their integration.The formal model is described in terms of a well-known specification language, LOTOS.Formalization of the graphical notation enables numerous automated processing and analysis tasks, such as behavior simulation and consistency checks between levels of specifications. Enoch Y. Wang, Heather Lipford, Betty H. C. Cheng |
ICSE | 2 |