Juergen Rilling

dblp:r/JuergenRilling · DBLP profile ↗
← Back
54ranked-venue papers
4as first author
3since 2021 · last 2022
0000-0002-5441-0385ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 46 · 3 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 1 first-authorDatabases, data management, data science and information retrieval · 7Artificial intelligence and machine learning · 4Computer networks · 1Security and privacy · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2022 A Semantic Web-Enabled Approach for Dependency Management
abstract
The use of external libraries in today’s software projects allows developers to take advantage of features provided by such application programming interfaces (APIs) without having to reinvent the wheel. However, APIs have also introduced new challenges to the software engineering community (e.g. API incompatibilities, software vulnerabilities, and license violations) that extend beyond traditional project boundaries and often involve different software artifacts. One potential solution to these challenges is to provide a technology-independent representation of software dependency semantics and its integration with knowledge from other software artifacts. In our research, we take advantage of the semantic web (SW) and its technology stack to establish a unified knowledge representation of build and dependency repositories. Given this knowledge base, we can now extend and integrate other (heterogeneous) resources to allow for a flexible and comprehensive global impact analysis approach. To illustrate the applicability of our SW-enabled modeling approach, we discuss two different applications. These applications illustrate how our modeling approach can not only integrate and reuse knowledge from dependency management systems and other software artifacts, but also take advantage of inference services provided by the SW to support novel software analytics services across artifact and project boundaries.
Ellis E. Eghan, Juergen Rilling
Int. J. Softw. Eng. Knowl. Eng.2
2022 A user survey on the adoption of crowd-based software engineering instructional screencasts by the new generation of software developers
Parisa Moslehi, Juergen Rilling, Bram Adams
J. Syst. Softw.2
2021 Which Commits Can Be CI Skipped?
abstract
Continuous Integration (CI) frameworks such as Travis CI, automatically build and run tests whenever a new commit is submitted/pushed. Although there are many advantages in using CI, e.g., speeding up the release cycle and automating the test execution process, it has been noted that the CI process can take a very long time to complete. One of the possible reasons for such delays is the fact that some commits (e.g., changes to readme files) unnecessarily kick off the CI process. Therefore, the goal of this paper is to automate the process of determining which commits can be CI skipped. We start by examining the commits of 58 Java projects and identify commits that were explicitly CI skipped by developers. Based on the manual investigation of 1,813 explicitly CI skipped commits, we first devise an initial model of a CI skipped commit and use this model to propose a rule-based technique that automatically identifies commits that should be CI skipped. To evaluate the rule-based technique, we perform a study on unseen datasets extracted from ten projects and show that the devised rule-based technique is able to detect and label CI skip commits, achieving Areas Under the Curve (AUC) values between 0.56 and 0.98 (average of 0.73). Additionally, we show that, on average, our technique can reduce the number of commits that need to trigger the CI process by 18.16 percent. We also qualitatively triangulated our analysis on the importance of skipping the CI process through a survey with 40 developers. The survey results showed that 75 percent of the surveyed developers consider it to be nice, important or very important to have a technique that automatically flags CI skip commits. To operationalize our technique, we develop a publicly available prototype tool, called CI-Skipper, that can be integrated with any git repository and automatically mark commits that can be CI skipped.
Rabe Abdalkareem, Suhaib Mujahid, Emad Shihab, Juergen Rilling
IEEE Trans. Software Eng.4
2020 A feature location approach for mapping application features extracted from crowd-based screencasts to source code
Parisa Moslehi, Bram Adams, Juergen Rilling
Empir. Softw. Eng.3
2020 The missing link - A semantic web based approach for integrating screencasts with security advisories
Ellis E. Eghan, Parisa Moslehi, Juergen Rilling, Bram Adams
Inf. Softw. Technol.3
2019 Semantic Modeling Approach for Software Vulnerabilities Data Sources
abstract
Data sources describing software security vulnerabilities are commonly used by software engineers not only increase the security of software systems but also enhance software productivity and reduce maintenance costs. However, with the constantly growing amount of available security vulnerability information and this information being spread across heterogeneous resources, software developers are struggling in taking full advantage of these resources. The Semantic Web and its supporting technology stack have been widely promoted to support the modeling, reuse and interoperability among heterogeneous data sources. In our research we present a Semantic Web enabled knowledge model which provides a formal and semi-automated approach for unifying vulnerability information resources. As part of this knowledge modeling approach, we also take advantage of Formal Concept Analysis (FCA) to identify vulnerability related knowledge concepts and model them at various abstraction levels. We illustrate the applicability and flexibility of our approach through several usage examples that take advantage of our unified knowledge model and Semantic Web inference services to provide new types of vulnerability analysis.
Sultan S. Alqahtani, Juergen Rilling
PST2
2019 API trustworthiness: an ontological approach for software library adoption
Ellis E. Eghan, Sultan S. Alqahtani, Christopher Forbes, Juergen Rilling
Softw. Qual. J.4
2018 Feature location using crowd-based screencasts
abstract
Crowd-based multi-media documents such as screencasts have emerged as a source for documenting requirements of agile software projects. For example, screencasts can describe buggy scenarios of a software product, or present new features in an upcoming release. Unfortunately, the binary format of videos makes traceability between the video content and other related software artifacts (e.g., source code, bug reports) difficult. In this paper, we propose an LDA-based feature location approach that takes as input a set of screencasts (i.e., the GUI text and/or spoken words) to establish traceability link between the features described in the screencasts and source code fragments implementing them. We report on a case study conducted on 10 WordPress screencasts, to evaluate the applicability of our approach in linking these screencasts to their relevant source code artifacts. We find that the approach is able to successfully pinpoint relevant source code files at the top 10 hits using speech and GUI text. We also found that term frequency rebalancing can reduce noise and yield more precise results.
Parisa Moslehi, Bram Adams, Juergen Rilling
MSR3
2017 An Ontology-Based Approach to Automate Tagging of Software Artifacts
abstract
Context: Software engineering repositories contain a wealth of textual information such as source code comments, developers' discussions, commit messages and bug reports. These free form text descriptions can contain both direct and implicit references to security concerns. Goal: Derive an approach to extract security concerns from textual information that can yield several benefits, such as bug management (e.g., prioritization), bug triage or capturing zero-day attack. Method: Propose a fully automated classification and tagging approach that can extract security tags from these texts without the need for manual training data. Results: We introduce an ontology based Software Security Tagger Framework that can automatically identify and classify cybersecurity-related entities, and concepts in text of software artifacts. Conclusion: Our preliminary results indicate that the framework can successfully extract and classify cybersecurity knowledge captured in unstructured text found in software artifacts.
Sultan S. Alqahtani, Juergen Rilling
ESEM2
2017 Recovering Semantic Traceability Links between APIs and Security Vulnerabilities: An Ontological Modeling Approach
abstract
Over the last decade, a globalization of the software industry took place, which facilitated the sharing and reuse of code across existing project boundaries. At the same time, such global reuse also introduces new challenges to the software engineering community, with not only components but also their problems and vulnerabilities being now shared. For example, vulnerabilities found in APIs no longer affect only individual projects but instead might spread across projects and even global software ecosystem borders. Tracing these vulnerabilities at a global scale becomes an inherently difficult task since many of the existing resources required for such analysis still rely on proprietary knowledge representation. In this research, we introduce an ontology-based knowledge modeling approach that can eliminate such information silos. More specifically, we focus on linking security knowledge with other software knowledge to improve traceability and trust in software products (APIs). Our approach takes advantage of the Semantic Web and its reasoning services, to trace and assess the impact of security vulnerabilities across project boundaries. We present a case study, to illustrate the applicability and flexibility of our ontological modeling approach by tracing vulnerabilities across project and resource boundaries.
Sultan S. Alqahtani, Ellis E. Eghan, Juergen Rilling
ICST3
2017 On code reuse from StackOverflow: An exploratory study on Android apps
abstract
Context: Source code reuse has been widely accepted as a fundamental activity in software development. Recent studies showed that StackOverflow has emerged as one of the most popular resources for code reuse. Therefore, a plethora of work proposed ways to optimally ask questions, search for answers and find relevant code on StackOverflow. However, little work studies the impact of code reuse from StackOverflow. Objective: To better understand the impact of code reuse from StackOverflow, we perform an exploratory study focusing on code reuse from StackOverflow in the context of mobile apps. Specifically, we investigate how much, why, when, and who reuses code. Moreover, to understand the potential implications of code reuse, we examine the percentage of bugs in files that reuse StackOverflow code. Method: We perform our study on 22 open source Android apps. For each project, we mine their source code and use clone detection techniques to identify code that is reused from StackOverflow. We then apply different quantitative and qualitative methods to answer our research questions. Results: Our findings indicate that 1) the amount of reused StackOverflow code varies for different mobile apps, 2) feature additions and enhancements in apps are the main reasons for code reuse from StackOverflow, 3) mid-age and older apps reuse StackOverflow code mostly later on in their project lifetime and 4) that in smaller teams/apps, more experienced developers reuse code, whereas in larger teams/apps, the less experienced developers reuse code the most. Additionally, we found that the percentage of bugs is higher in files after reusing code from StackOverflow. Conclusion: Our results provide insights on the potential impact of code reuse from StackOverflow on mobile apps. Furthermore, these results can benefit the research community in developing new techniques and tools to facilitate and improve code reuse from StackOverflow.
Rabe Abdalkareem, Emad Shihab, Juergen Rilling
Inf. Softw. Technol.3
2016 SV-AF - A Security Vulnerability Analysis Framework
abstract
The globalization of the software industry has introduced a widespread use of system components across traditional system boundaries. Due to this global reuse, also vulnerabilities and security concerns are no longer limited in their scope to individual systems but instead can now affect global software ecosystems. While known vulnerabilities and security concerns are reported in specialized vulnerability databases, these repositories often remain information silos. In this research, we introduce a modeling approach, which eliminates these silos by linking security knowledge with other software artifacts to improve traceability and trust in software products. In our approach, we introduce a Security Vulnerabilities Analysis Framework (SV-AF) to support evidence based vulnerability detection. Two case studies are presented to illustrate the applicability of our presented approach. In these case studies, we link the NVD vulnerability databases and the Maven build repository to trace vulnerabilities across repository and project boundaries. In our analysis, we identify that 750 Maven project releases are directly affected by known security vulnerabilities and by considering transitive dependencies, an additional 415604 Maven projects can be identified as potentially affected by these vulnerabilities.
Sultan S. Alqahtani, Ellis E. Eghan, Juergen Rilling
ISSRE3
2016 On mining crowd-based speech documentation
abstract
Despite the globalization of software development, relevant documentation of a project, such as requirements and design documents, often still is missing, incomplete or outdated. However, parts of that documentation can be found outside the project, where it is fragmented across hundreds of textual web documents like blog posts, email messages and forum posts, as well as multimedia documents such as screencasts and podcasts. Since dissecting and filtering multimedia information based on its relevancy to a given project is an inherently difficult task, it is necessary to provide an automated approach for mining this crowd-based documentation. In this paper, we are interested in mining the speech part of YouTube screencasts, since this part typically contains the rationale and insights of a screencast. We introduce a methodology that transcribes and analyzes the transcribed text using various Information Extraction (IE) techniques, and present a case study to illustrate the applicability of our mining methodology. In this case study, we extract use case scenarios from WordPress tutorial videos and show how their content can supplement existing documentation. We then evaluate how well existing rankings of video content are able to pinpoint the most relevant videos for a given scenario.
Parisa Moslehi, Bram Adams, Juergen Rilling
MSR3
2016 Context-awareness in the software domain - A semantic web enabled modeling approach
Mostafa Erfani, Mohammadnaser Zandi, Juergen Rilling, Iman Keivanloo
J. Syst. Softw.3
2016 Tracing known security vulnerabilities in software repositories - A Semantic Web enabled modeling approach
Sultan S. Alqahtani, Ellis E. Eghan, Juergen Rilling
Sci. Comput. Program.3
2015 Message from WEDA Organizing Committee
abstract
Presents the opening message from Workshop organizers.
Guohui Xiao 0001, Juergen Rilling
COMPSAC2
2015 Special Section on Source Code Analysis and Manipulation (SCAM 2013)
Bram Adams, Juergen Rilling
Sci. Comput. Program.2
2015 Preface special section on software clones (IWSC'13)
Rainer Koschke, Juergen Rilling
J. Softw. Evol. Process.2
2014 Spotting working code examples
abstract
Working code examples are useful resources for pragmatic reuse in software development. A working code example provides a solution to a specific programming problem. Earlier studies have shown that existing code search engines are not successful in finding working code examples. They fail in ranking high quality code examples at the top of the result set. To address this shortcoming, a variety of pattern-based solutions are proposed in the literature. However, these solutions cannot be integrated seamlessly in Internet-scale source code engines due to their high time complexity or query language restrictions. In this paper, we propose an approach for spotting working code examples which can be adopted by Internet-scale source code search engines. The time complexity of our approach is as low as the complexity of existing code search engines on the Internet and considerably lower than the pattern-based approaches supporting free-form queries. We study the performance of our approach using a representative corpus of 25,000 open source Java projects. Our findings support the feasibility of our approach for Internet-scale code search. We also found that our approach outperforms Ohloh Code search engine, previously known as Koders, in spotting working code examples.
Iman Keivanloo, Juergen Rilling, Ying Zou 0001
ICSE2
2014 Software trustworthiness 2.0 - A semantic web enabled global source code analysis approach
Iman Keivanloo, Juergen Rilling
J. Syst. Softw.2
2014 SeByte: Scalable clone and similarity search for bytecode
Iman Keivanloo, Chanchal Kumar Roy, Juergen Rilling
Sci. Comput. Program.3
2013 Semantic-Enabled Clone Detection
abstract
We introduce semantic-enabled clone detection, as an approach that emphasizes on importance of the token semantics during the pattern matching for clone detection. This approach can be realized using Semantic Web and its support for knowledge modeling. While the Semantic Web has found wide acceptance in various application and research domains, it still lacks the same acceptance in the source code analysis domain. In this paper we focus on how the Semantic Web and its support for semantic modeling and knowledge retrieval can be applied towards source code clone detection and search. We discuss both, open challenges in the source code clone detection domain, as well as both theoretical and practical aspects on how the Semantic Web can address some of these challenges.
Iman Keivanloo, Juergen Rilling
COMPSAC2
2013 7th international workshop on software clones (IWSC 2013)
abstract
Software Clones are identical or similar pieces of code, models or designs. In this, the 7th International Workshop on Software Clones (IWSC), we will discuss issues in software clone detection, analysis and management, as well as applications to software engineering contexts that can benefit from knowledge of clones. These are important emerging topics in software engineering research and practice. Special emphasis will be given this time to clone management in practice, emphasizing use cases and experiences. We will also discuss broader topics on software clones, such as clone detection methods, clone classification, management, and evolution, the role of clones in software system architecture, quality and evolution, clones in plagiarism, licensing, and copyright, and other topics related to similarity in software systems. The format of this workshop will give enough time for intense discussions.
Rainer Koschke, Elmar Jürgens, Juergen Rilling
ICSE3
2013 Assessing the quality factors found in in-line documentation written in natural language: The JavadocMiner
Ninus Khamis, Juergen Rilling, René Witte
Data Knowl. Eng.2
2012 Doppel-Code: A Clone Visualization Tool for Prioritizing Global and Local Clone Impacts
abstract
In our research, we have focused on mining software repositories to support software engineering development and code clone search. We developed Doppel-Code, a clone visualization tool to aid searching for code clones across 18 000 open source projects. For clone visualization, we take into account clone impact - both globally and locally - to further aid developers' software maintenance activities.
Christopher Forbes, Iman Keivanloo, Juergen Rilling
COMPSAC3
2012 Semantic Web - The Missing Link in Global Source Code Analysis?
abstract
There has been an ongoing trend towards open and shared source code that is published on the Internet in large software repositories to support collaborative development processes. While traditional source code analysis techniques perform well in single project contexts, new types of global source code analysis techniques are slowly introduced to address the analysis of global distributed and often incomplete source code. In this article, we discuss how the Semantic Web, an enabling technology for these emerging source code analysis domains, can support a standardized, formal, and semantic rich representation to model these corpora. We also illustrate how inference services can be used to provide support for emerging source code analysis approaches on this data, such as search, call graph construction, and clone detection.
Iman Keivanloo, Juergen Rilling, Philippe Charland
COMPSAC2
2012 When open source turns cold on innovation - The challenges of navigating licensing complexities in new research domains
abstract
In this poster, we review the limitations open source licences introduce to the application of Linked Data in Software Engineering. We investigate whether open source licences support special requirements to publish source code as Linked Data on the Internet.
Christopher Forbes, Iman Keivanloo, Juergen Rilling
ICSE3
2012 Applying technical stock market indicators to analyze and predict the evolvability of open source projects
abstract
For decades stock market traders make financially critical buy/sell decisions depending on external and internal factors affecting the price of individual stocks. Moving Averages combined with technical analysis patterns are some of the most basic and widely used indicators to support buy/sell decisions. In this research, we present a novel cross-disciplinary approach that uses these technical stock market indicators for analyzing the community evolvability of open source software systems.
Aseel Hmood, Mostafa Erfani, Iman Keivanloo, Juergen Rilling
ICSM4
2012 SeByte: A semantic clone detection tool for intermediate languages
abstract
SeByte is a semantic clone detection tool which accepts Java bytecode (binary) as input. SeByte provides a complementary approach to traditional pattern-based source code level clone detection. It is capable of detecting clones missed by existing clone detection tools since it exploits both pattern and content similarity at binary level.
Iman Keivanloo, Chanchal Kumar Roy, Juergen Rilling
ICPC3
2012 A Linked Data platform for mining software repositories
abstract
The mining of software repositories involves the extraction of both basic and value-added information from existing software repositories. The repositories will be mined to extract facts by different stakeholders (e.g. researchers, managers) and for various purposes. To avoid unnecessary pre-processing and analysis steps, sharing and integration of both basic and value-added facts are needed. In this research, we introduce SeCold, an open and collaborative platform for sharing software datasets. SeCold provides the first online software ecosystem Linked Data platform that supports data extraction and on-the-fly inter-dataset integration from major version control, issue tracking, and quality evaluation systems. In its first release, the dataset contains about two billion facts, such as source code statements, software licenses, and code clones from 18 000 software projects. In its second release the SeCold project will contain additional facts mined from issue trackers and versioning systems. Our approach is based on the same fundamental principle as Wikipedia: researchers and tool developers share analysis results obtained from their tools by publishing them as part of the SeCold portal and therefore make them an integrated part of the global knowledge domain. The SeCold project is an official member of the Linked Data dataset cloud and is currently the eighth largest online dataset available on the Web.
Iman Keivanloo, Christopher Forbes, Aseel Hmood, Mostafa Erfani, Christopher Neal, George Peristerakis, Juergen Rilling
MSR7
2011 Reasoning about Global Clones: Scalable Semantic Clone Detection
abstract
The Semantic Web is slowly transforming the Web as we know it into a machine understandable pool of information that can be consumed and reasoned about by various clients. Source code is no exception to this trend and various communities have proposed standards to share code as linked data. With the availability of large amounts of open source code published in publicly accessible repositories, the introduction of massive horizontal scaling frameworks, and cloud computing infrastructures, a new era of software mining across information silos is reshaping the software engineering landscape. Given these technological advances, analyzing code at a global scale, across systems, projects and organizational boundaries, becomes feasible. In this paper, we introduce a clone detection algorithm and its implementation that can scale to such large global datasets, by modeling clones using description logic and applying a horizontal scaling Semantic Web reasoner. We demonstrate how our simple feature vector that only uses control statements, data types and method calls, can yield results similar to other popular clone detection tools. Our approach does not only allow us to reliably identify clones in a global context. By using a semantic reasoner, it also allows us to expand clone detection to a new class of semantic clones. We have compared our algorithm to some of the leading clone detection tools (DECKARD, CCFinder, JCD, and Simian) in order to validate our approach and show the differences in detected clones and performance.
Philipp Schügerl, Juergen Rilling, Philippe Charland
COMPSAC2
2011 Quality Validation through Pattern Detection - A Semantic Web Perspective
abstract
Given the ongoing trend towards the globalization of software systems, open networks, and distributed platforms, validating non-functional requirements and quality becomes essential. Our research addresses this challenge from two different perspectives: (1) the integration of knowledge and tool resources through Semantic Web technologies as part of our SE-PAD environment, in order to reduce or eliminate existing traditional information and analysis silos. (2) The ability to reason upon linked resources to infer both explicit and implicit patterns to support the validation of quality aspects. We have applied our SE-PAD environment for the detection of security and design patterns, as well as the violations of secure programming guidelines.
David Walsh 0003, Philipp Schügerl, Juergen Rilling, Philippe Charland
COMPSAC3
2011 SeClone - A Hybrid Approach to Internet-Scale Real-Time Code Clone Search
abstract
Real-time code clone search is an emerging family of clone detection research that aims at finding clone pairs matching an input code fragment in fractions of a second. For these techniques to meet actual real world requirements, they have to be scalable and provide a short response time. Our research presents a hybrid clone search approach using source code pattern indexing, information retrieval clustering, and Semantic Web reasoning to respectively achieve short response time, handle false positives, and support automated grouping/querying.
Iman Keivanloo, Juergen Rilling, Philippe Charland
ICPC2
2010 SE-CodeSearch: A scalable Semantic Web-based source code search infrastructure
abstract
Available code search engines provide typically coarse-grained lexical search. To address this limitation we present SE-CodeSearch, a Semantic Web-based approach for Internet-scale source code search. It uses an ontological representation of source code facts and analysis knowledge to complete missing information using inference engine. This approach allows us to reason and search across project boundaries containing often incomplete code fragments extracted in a one-pass and no-order manner. The infrastructure provides a scalable approach to process and query across large code bases mined from software repositories and code fragments found online. We have implemented our SE-CodeSearch as part of SE-Advisor framework to demonstrate the scalability and applicability of our Internet-scale code search in a software maintenance context.
Iman Keivanloo, Laleh Roostapour, Philipp Schügerl, Juergen Rilling
ICSM4
2010 Flexible Ontology Population from Text: The OwlExporter
René Witte, Ninus Khamis, Juergen Rilling
LREC3
2010 Automatic Quality Assessment of Source Code Comments: The JavadocMiner
Ninus Khamis, René Witte, Juergen Rilling
NLDB3
2010 An evaluation of timed scenario notations
Jameleddine Hassine, Juergen Rilling, Rachida Dssouli
J. Syst. Softw.2
2009 A Contextual Guidance Approach to Software Security
abstract
With the ongoing trend towards the globalization of software systems and their development, components in these systems might not only work together, but may end up evolving independently from each other. Modern IDEs have started to incorporate support for these highly distributed environments, by adding new collaborative features. As a result, assessing and controlling system quality (e.g. security concerns) during system evolution in these highly distributed systems become a major challenge. In this research, we introduce a unified ontological representation that integrates best security practices in a context-aware tool implementation. As part of our approach, we integrate information from traditional static source code analysis with semantic rich structural information in a unified ontological representation. We illustrate through several use cases how our approach can support the evolvability of software systems from a security quality perspective.
Philipp Schügerl, David Walsh 0003, Juergen Rilling, Philippe Charland
COMPSAC (2)3
2009 Beyond generated software documentation - A web 2.0 perspective
abstract
Over the last decades, software engineering processes have constantly evolved to reflect cultural, social, technological, and organizational changes, which are often a direct result of the Internet. The introduction of the Web 2.0 resulted in further changes creating an interactive, community driven platform. However, these ongoing changes have yet to be reflected in the way we document software systems. Documentation generators, like Doxygen and its derivatives (Javadoc, Natural Docs, etc.) have become the de-facto industry standards for creating external technical software documentation from source code. However, the inter-woven representation of source code and documentation within a source code editor limits the ability of these approaches to provide rich media, internationalization, and interactive content. In this paper, we combine the functionality of a Web browser with a source code editor to provide source code documentation with rich media content. The paper presents our fully functional implementation of the editor within the Eclipse framework.
Philipp Schügerl, Juergen Rilling, Philippe Charland
ICSM2
2009 Use Case Maps as a property specification language
Jameleddine Hassine, Juergen Rilling, Rachida Dssouli
Softw. Syst. Model.2
2008 Semantic Technologies in System Maintenance (STSM 2008)
abstract
This paper gives a brief overview of the International Workshop on Semantic Technologies in System Maintenance. It describes a number of semantic technologies (e.g., ontologies, text mining, and knowledge integration techniques) and identifies diverse tasks in software maintenance where the use of semantic technologies can be beneficial, such as traceability, system comprehension, software artifact analysis, and information integration.
Juergen Rilling, René Witte, Dragan Gasevic, Jeff Z. Pan
ICPC1
2008 An Approach for Mapping Features to Code Based on Static and Dynamic Analysis
abstract
System evolution depends greatly on the ability of a maintainer to locate source code that is specific to feature implementation. Existing feature location techniques require either exercising several features of the system, or rely heavily on domain experts to guide the feature location process. In this paper, we present a novel approach for feature location that combines static and dynamic analysis techniques. An execution trace is generated by exercising the feature under study (dynamic analysis). A component dependency graph (static analysis) is used to rank the components invoked in the trace according to their relevance to the feature. Our ranking technique is based on the impact of a component modification on the rest of the system. The proposed approach is automatic to a large extent relieving users from any decision that would otherwise require extensive domain knowledge of the system. A case study is presented to support and evaluate the applicability of our approach.
Abhishek Rohatgi, Abdelwahab Hamou-Lhadj, Juergen Rilling
ICPC3
2007 Empowering Software Maintainers with Semantic Web Technologies
René Witte, Juergen Rilling
ESWC3
2007 Feature interaction analysis: a maintenance perspective
abstract
Software systems have become more complex, with myriad features and multiple functionalities. A major challenge in developing and maintaining such complex software is to identify potential conflicts among its features. Feature interaction analysis becomes progressively more difficult as software's feature combinations and available scenarios increase. Software maintainers need to identify and analyze conflicts that can arise from feature modification requests. Our approach combines Use Case Maps with Formal Concept Analysis to assist maintainers in identifying feature modification impacts at the requirements level, without the need to examine the source code. We demonstrate the applicability of this approach using a teleommunication case study
Maryam Shiri, Jameleddine Hassine, Juergen Rilling
ASE3
2007 Ontological Text Mining of Software Documents
René Witte, Qiangqiang Li, Juergen Rilling
NLDB4
2007 Benchmarking usability of early designs using predictive metrics
abstract
This paper introduces a set of novel metrics-based prediction models that allow stakeholders and user interface designers to assess, compare and choose among alternative designs in early development stages. Most of the existing usability evaluation methods require a fully functional prototype. Tests are also mostly conducted after the development and deployment of the software. Tests also require a specific costly lab which may result in significant maintenance costs. The proposed models in this paper reply on the correlations that we discovered between predictive usability metrics and the results of usability tests performed by users. Our empirical investigations show that predictive metrics and user-oriented tests conducted by users provide similar scores regarding the overall usability as well as other parameters such as learnability and efficiency of alternative designs before their development and deployment.
Mohammad Donyaee, Ahmed Seffah, Juergen Rilling
SMC3
2006 An Ontology-Based Approach to Software Comprehension - Reasoning about Security Concerns
abstract
There exists a large variety of techniques to detect and correct software security vulnerabilities at the source code level, including human code reviews, testing, and static analysis. In this article, we present a static analysis approach that supports both the identification of security flaws and the reasoning about security concerns. We introduce an ontology-based program representation that lets security experts and programmers specify their security concerns as part of the ontology. Within our tool implementation, we support complex queries on the underlying program model using either predefined or user-defined concepts and relations. Queries regarding security concerns, such as exception handling, object accessibility etc. are demonstrated in order to show the applicability and flexibility of our approach
Juergen Rilling, Volker Haarslev
COMPSAC (1)2
2005 Abstract Operational Semantics for Use Case Maps
Jameleddine Hassine, Juergen Rilling, Rachida Dssouli
FORTE2
2005 An ASM Operational Semantics for Use Case Maps
abstract
Scenario-driven requirement specifications are widely used to capture and represent functional requirements. Use case maps (UCM) is being standardized as part of the user requirements notation (URN), an addition to ITU-T's family of languages. UCM models allow the description of functional requirements and high-level designs at early stages of the development process. Recognizing the importance of having a well defined semantic, we propose, in this paper, a concise and rigorous formal semantics for use case maps, defined in terms of multi-agent abstract state machines. The proposed formal semantics addresses UCM's operational semantics and provides a sound basis for executing UCM specifications using simulation tools and supporting formal verification.
Jameleddine Hassine, Juergen Rilling, Rachida Dssouli
RE2
2005 3D visualization techniques to support slicing-based program comprehension
Juergen Rilling, Sudhir P. Mudur
Comput. Graph.1
2004 Context Driven Slicing Based Coupling Measure
abstract
We present a framework of program slicing based coupling measurements to evaluate software quality. The proposed framework combines the well-known coupling measurement, CBO (coupling between object classes), RFC (response from classes), and MPC (message passing coupling), with slicing based source code analysis. The proposed measures are implemented in our CONCEPT tool, and an initial experimental analysis has been performed to illustrate the applicability of our measurements.
Juergen Rilling, Wen Jun Meng, Olga Ormandjieva
ICSM1
2004 Granularity-Driven Dynamic Predicate Slicing Algorithms for Message Passing Systems
Hon Fung Li, Juergen Rilling, Dhrubajyoti Goswami
Autom. Softw. Eng.2
2001 MOOSE - A Task-Driven Program Comprehension Environment
abstract
Many tools have been developed to derive abstract representations from existing source code. Yet, most of these tools provide only little help in providing an encompassing picture of the system under examination. Graphical visualization techniques derived from reverse engineered source code have long been recognized for their impact on improving the comprehensibility of software systems and their source code. In this paper, we present a task-oriented approach to software comprehension by introducing our MOOSE (Montreal Object-Oriented Slicing Environment) environment that provides a task-driven wizard approach that supports a cognitive comprehension model combined with reverse engineering techniques, algorithmic and visualization support. We close our discussion with a brief overview of typical software comprehension tasks and how the MOOSE environment will benefit users during these comprehension tasks.
Juergen Rilling, Ahmed Seffah
COMPSAC1
1998 Dynamic program slicing methods
Bogdan Korel, Juergen Rilling
Inf. Softw. Technol.2