Francesca Lonetti

dblp:06/4305 · DBLP profile ↗
← Back
35ranked-venue papers
6as first author
10since 2021 · last 2026
0000-0002-4864-2219ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 27 · 5 first-author · 10 since 2021Computer networks · 3Security and privacy · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 A Framework for Similarity-based and Resource-aware Orchestration of End-to-End Test Cases
Cristian Augusto, Antonia Bertolino, Guglielmo De Angelis, Claudio de la Riva, Francesca Lonetti, Jesús Morán
AST5
2026 Recent developments in software engineering for systems-of-systems and software ecosystems
abstract
The increasing scale, distribution, and interconnection of software-intensive systems continue to change the landscape of software engineering research and practice, bringing the diffusion of two similar paradigms: Systems-of-Systems (SoS) and Software Ecosystems (SECO). SoS are characterized by the integration of operationally and managerially independent systems that join together to accomplish a common mission. SoS are central to domains such as transportation, healthcare, defense, smart cities, and industrial automation where heterogeneous systems must cooperate, exchange information, and adapt to evolving missions. On the other hand, SECO describe environments in which a platform and its surrounding network of developers, partners, and organizations co-create software offerings. In SECO, technical artifacts interact with economic and social processes. Modern digital platforms, mobile operating systems, cloud services, and enterprise platforms leverage the capabilities of their ecosystems. This editorial brings together perspectives that explore the shared challenges and complementary insights of SoS and SECO research, aiming to foster a richer understanding of complex software-intensive systems and highlight new opportunities for collaboration across communities. From the long-running, successful series of the International Workshop on Software Engineering for Systems-of-Systems and Software Ecosystems (SESoS), co-located with the IEEE/ACM International Conference on Software Engineering (ICSE), we present this special issue of the Journal of Systems and Software on the topics of SESoS 2024 in Lisbon, Portugal. From a total of 18 submissions, 7 articles were accepted in this special issue. The articles in this collection address fundamental questions of SoS and SECO, including the evolution of functional relations and experimentation practices, the key factors affecting developer experience, also related to women’s inclusion, as well as the adoption of GenAI-driven approaches for vulnerability fixing. These articles offer updates on current advances of SoS and SECO engineering to researchers and practitioners, highlighting opportunities for future research.
Francesca Lonetti, Antonia Bertolino, Pablo Oliveira Antonino, Doo-Hwan Bae
J. Syst. Softw.1
2026 Recent developments in software engineering for systems-of-systems and software ecosystems
Francesca Lonetti, Antonia Bertolino, Pablo Oliveira Antonino, Doo-Hwan Bae
J. Syst. Softw.1
2026 Using Metamorphic Relations in Redundancy-based Fault/Intrusion Tolerance
abstract
Redundancy is widely used as a method for fault and intrusion tolerance. However, if the redundant components lack sufficient diversity, potentially dangerous common mode failures may go undetected. To address this issue, the design diversity approach has been proposed in the literature for decades. In this article, we take an innovative approach to this problem by introducing a broader notion of diversity, which leverages Metamorphic Relations (MRs), i.e., necessary properties that must hold among diverse inputs and diverse outputs. We define two generic categories of MRs that establish data diversity and functional diversity. Furthermore, we elaborate on two corresponding logical architectures, paying particular attention to the necessary conditions for the adjudicator component. Finally, we present an initial evaluation of the proposed architectures, which points out the advantages with respect to their counterparts based on the traditional design diversity method, and discuss future research directions for this novel conceptual approach to redundancy-based fault/intrusion tolerance.
Felicita Di Giandomenico, Giulio Masetti, Francesca Lonetti, Antonia Bertolino
ACM Trans. Softw. Eng. Methodol.3
2024 A framework for the design of fault-tolerant systems-of-systems
Francisco Henrique Ferreira, Elisa Yumi Nakagawa, Antonia Bertolino, Francesca Lonetti, Vânia de Oliveira Neves, Rodrigo Pereira dos Santos
J. Syst. Softw.4
2023 Cross-coverage testing of functionally equivalent programs
abstract
Cross-coverage of a program P refers to the test coverage measured over a different program Q that is functionally equivalent to P. The novel concept of cross-coverage can find useful applications in the test of redundant software. We apply here cross-coverage for test suite augmentation and show that additional test cases generated from the coverage of an equivalent program, referred to as cross tests, can increase the coverage of a program in more effective way than a random baseline. We also observe that -contrary to traditional coverage testing-cross coverage could help finding (artificially created) missing functionality faults.
Antonia Bertolino, Guglielmo De Angelis, Felicita Di Giandomenico, Francesca Lonetti
AST4
2023 Model-based security testing in IoT systems: A Rapid Review
abstract
Security testing is a challenging and effort-demanding task in IoT scenarios. The heterogeneous devices expose different vulnerabilities that can influence the methods and cost of security testing. Model-based security testing techniques support the systematic generation of test cases for the assessment of security requirements by leveraging the specifications of the IoT system model and of the attack templates. This paper aims to review the adoption of model-based security testing in the context of IoT, and then provides the first systematic and up-to-date comprehensive classification and analysis of research studies in this topic. We conducted a systematic literature review analysing 803 publications and finally selecting 17 primary studies, which satisfied our inclusion criteria and were classified according to a set of relevant analysis dimensions. We report the state-of-the-art about the used formalisms, the test techniques, the objectives, the target applications and domains; we also identify the targeted security attacks, and discuss the challenges, gaps and future research directions. Our review represents the first attempt to systematically analyze and classify existing studies on model-based security testing for IoT. According to the results, model-based security testing has been applied in core IoT domains. Models complexity and the need of modeling evolving scenarios that include heterogeneous open software and hardware components remain the most important shortcomings. Our study shows that model-based security testing of IoT applications is a promising research direction. The principal future research directions deal with: extending the existing modeling formalisms in order to capture all peculiarities and constraints of complex and large scale IoT networks; the definition of context-aware and dynamic evolution modelling approaches of IoT entities; and the combination of model-based testing techniques with other security test strategies such as penetration testing or learning techniques for model inference.
Francesca Lonetti, Antonia Bertolino, Felicita Di Giandomenico
Inf. Softw. Technol.1
2023 An automated framework for continuous development and testing of access control systems
abstract
Abstract Automated testing in DevOps represents a key factor for providing fast release of new software features assuring quality delivery. In this paper, we introduce DOXAT, an automated framework for continuous development and testing of access control mechanisms based on the XACML standard. It leverages mutation analysis for the selection and assessment of the test strategies and provides automated facilities for test oracle definition, test execution, and results analysis, in order to speedup and automate the Plan, Code, Build, and Test phases of DevOps process. We show the usage of the framework during the planning and testing phases of the software development cycle of a PDP example.
Said Daoudagh, Francesca Lonetti, Eda Marchetti
J. Softw. Evol. Process.2
2022 Designing and testing systems of systems: From variability models to test cases passing through desirability assessment
abstract
Abstract In the early stages of a system of systems (SoS) conception, several constituent systems could be available that provide similar functionalities. An SoS design methodology should provide adequate means to model variability in order to support the opportunistic selection of the most desirable SoS configuration. We propose the VANTESS approach that (i) supports SoS modeling taking into account the variation points implied by the considered constituent systems; (ii) includes a heuristics to weight benefits and costs of potential architectural choices (called as SoS variants) for the selection of the constituent systems; and finally (iii) also helps test planning for the selected SoS variant by deriving a simulation model on which test objectives and scenarios can be devised. We illustrate an application example of VANTESS to the “educational” SoS and discuss its pros and cons within a focus group.
Francesca Lonetti, Vânia de Oliveira Neves, Antonia Bertolino
J. Softw. Evol. Process.1
2021 About the Assessment of Grey Literature in Software Engineering
abstract
There is an ongoing interest in the Software Engineering field for multivocal literature reviews including grey literature. However, at the same time, the role of the grey literature is still controversial, and the benefits of its inclusion in systematic reviews are object of discussion. Some of these arguments concern the quality assessment methods for grey literature entries, which is often considered a challenging and critical task. On the one hand, apart from a few proposals, there is a lack of an acknowledged methodological support for the inclusion of Software Engineering grey literature in systematic surveys. On the other hand, the unstructured shape of the grey literature contents could lead to bias in the evaluation process impacting on the quality of the surveys. This work leverages an approach on fuzzy Likert scales, and it proposes a methodology for managing the explicit uncertainties emerging during the assessment of entries from the grey literature. The methodology also strengthens the adoption of consensus policies that take into account the individual confidence level expressed for each of the collected scores.
Guglielmo De Angelis, Francesca Lonetti
EASE2
2020 Assessing Testing Strategies for Access Control Systems: A Controlled Experiment
abstract
This paper presents a Controlled Experiment (CE) for assessing testing strategies in the context of Access Control (AC); more precisely, the CE is performed by considering the AC Systems (ACSs) based on the XACML Standard. We formalized the goal of the CE, and we assessed two available test cases generation strategies in terms of three metrics: Effectiveness, Size and Average Percentage Faults Detected (APFD). The experiment operation is described and the main results are analyzed.
Said Daoudagh, Francesca Lonetti, Eda Marchetti
ICISSP2
2020 Quality-of-Experience driven configuration of WebRTC services through automated testing
abstract
Quality of Experience (QoE) refers to the end users level of satisfaction with a real-time service, in particular in relation to its audio and video quality. Advances in WebRTC technology have favored the spread of multimedia services through use of any browser. Provision of adequate QoE in such services is of paramount importance. The assessment of QoE is costly and can be done only late in the service lifecycle. In this work we propose a simple approach for QoE-driven non-functional testing of WebRTC services that relies on the ElasTest open-source platform for end-to-end testing of large complex systems. We describe the ElasTest platform, the proposed approach and an experimental study. In this study, we compared qualitatively and quantitatively the effort required in the ElasTest supported scenario with respect to a "traditional" solution, showing great savings in terms of effort and time.
Antonia Bertolino, Antonello Calabrò, Guglielmo De Angelis, Francisco Gortázar, Francesca Lonetti, Michel Maes-Bermejo, Guiomar Tunon de Hita
QRS5
2020 XACMET: XACML Testing & Modeling
Said Daoudagh, Francesca Lonetti, Eda Marchetti
Softw. Qual. J.2
2019 A Decentralized Solution for Combinatorial Testing of Access Control Engine
abstract
In distributed environments, information security is a key factor and access control is an important means to guarantee confidentiality of sensitive and valuable data. In this paper, we introduce a new decentralized framework for testing of XACML-based access control engines. The proposed framework is composed of different web services and provides the following functionalities: I) generation of test cases based on combinatorial testing strategies; ii) decentralized oracle that associates the expected result to a given test case, i.e. an XACML request; and finally, iii) a GUI for interacting with the framework and providing some analysis about the expected results. A first validation confirms the efficiency of the proposed approach.
Said Daoudagh, Francesca Lonetti, Eda Marchetti
ICISSP2
2018 Issues and Challenges of Access Control in the Cloud
abstract
Cloud computing offers scalable and efficient information sharing and storage resources. However, the risk of security breaches for personal and private data in this computing environment is very high. Access control is among the most adopted means to assure that sensible information or resources are correctly accessed. This paper provides an overview of main access control models in cloud infrastructures discussing most important challenges. In particular, focusing on access control policy specification, analysis, verification and enforcement, we also identify some emerging issues and point out some solutions and future research directions for cloud computing.
Francesca Lonetti, Eda Marchetti
WEBIST1
2018 On-line tracing of XACML-based policy coverage criteria
abstract
Currently, eXtensible Access Control Markup Language (XACML) has becoming the standard for implementing access control policies and consequently more attention is dedicated to testing the correctness of XACML policies. In particular, coverage measures can be adopted for assessing test strategy effectiveness in exercising the policy elements. This study introduces a set of XACML coverage criteria and describes the access control infrastructure, based on a monitor engine, enabling the coverage criterion selection and the on‐line tracing of the testing activity. Examples of infrastructure usage and of assessment of different test strategies are provided.
Francesca Lonetti, Eda Marchetti
IET Softw.1
2018 A categorization scheme for software engineering conference papers and its application
Antonia Bertolino, Antonello Calabrò, Francesca Lonetti, Eda Marchetti, Breno Miranda
J. Syst. Softw.3
2018 A tour of secure software engineering solutions for connected vehicles
Antonia Bertolino, Antonello Calabrò, Felicita Di Giandomenico, Giuseppe Lami, Francesca Lonetti, Eda Marchetti, Fabio Martinelli, Ilaria Matteucci, Paolo Mori
Softw. Qual. J.5
2018 Special issue on automation of software testing: improving practical applicability
Christof J. Budnik, Gordon Fraser 0001, Francesca Lonetti, Hong Zhu 0002
Softw. Qual. J.3
2017 Towards Automated Deployment of Self-adaptive Applications on Hybrid Clouds (Short Paper)
Lom-Messan Hillah, Rodrigo Elia Assad, Antonia Bertolino, Márcio Eduardo Delamaro, Fabio De Rosa, Vinicius Cardoso Garcia, Francesca Lonetti, Ariele-Paolo Maesano, Libero Maesano, Eda Marchetti, Breno Miranda, Auri M. R. Vincenzi, Juliano Iyoda
SEFM7
2016 Model-based Learning Assessment Management
abstract
Model-based simulation and monitoring are becoming part of advanced learning environments. In this paper, we propose a model-based simulation and monitoring framework for management of learning assessment and we describe its architecture and main functionalities. The proposed framework allows user-friendly learning simulation with a strong support for collaboration and social interactions. Moreover, it monitors the learners' behavior during simulation execution and it is able to compute the learning scores useful for the learner knowledge assessment. The preliminary experimental feedback of the evaluation of the simulation and monitoring framework inside a real environment is also reported.
Antonello Calabrò, Francesca Lonetti, Eda Marchetti, Sarah Zribi, Tom Jorquera
MODELSWARD2
2016 Design of a Simulation Framework for Model-based Learning
abstract
In model-driven learning, simulation of Business Process is a key step for improving the learners's skills and enhancing teaching performance. In this paper, we provide the architectural design and the main functionalities of a model-based learning simulation framework. The main objectives of the proposed framework are: i) enable user-friendly learning simulation with a strong support for collaboration and social interactions; ii) provide a process-driven learning environment that allows emulation of the learner behavior when no learners are available to be involved on the simulation; iii) include event-based monitoring aiming at providing feedbacks for the learner assessment.
Sarah Zribi, Antonello Calabrò, Francesca Lonetti, Eda Marchetti, Tom Jorquera, Jean-Pierre Lorré
MODELSWARD3
2015 A Toolchain for Model-based Design and Testing of Access Control Systems
abstract
In access control systems, aimed at regulating the accesses to protected data and resources, a critical component is the Policy Decision Point (PDP), which grants or denies the access according to the defined policies. Due to the complexity of the standard languag-e, it is recommended to rely on model-driven approaches which allow to overcome difficulties in the XACML policy definition. We provide in this paper a toolchain that involves a model-driven approach to specify and generate XACML policies and also enables automated testing of the PDP component. We use XACML-based testing strategies for generating appropriate test cases which are able to validate the functional aspects, constraints, permissions and prohibitions of the PDP. An experimental assessment of the toolchain and its use on a realistic case study are also presented.
Said Daoudagh, Donia El Kateb, Francesca Lonetti, Eda Marchetti, Tejeddine Mouelhi
MODELSWARD3
2015 Similarity testing for access control
Antonia Bertolino, Said Daoudagh, Donia El Kateb, Christopher Henard, Yves Le Traon, Francesca Lonetti, Eda Marchetti, Tejeddine Mouelhi, Mike Papadakis
Inf. Softw. Technol.6
2014 Extending UML Testing Profile Towards Non-functional Test Modeling
abstract
The research community has broadly recognized the importance of the validation of non-functional properties including performance and dependability requirements. However, the results of a systematic survey we carried out evidenced the lack of a standard notation for designing non-functional test cases. For some time, the greatest attention of Model-Based Testing (MBT) research has focused on functional aspects. The only exception is represented by the UML Testing Profile (UML-TP) that is a lightweight extension of UML to support the design of testing artifacts, but it only provides limited support for non-functional testing. In this paper we provide a first attempt to extend UML-TP for improving the design of non-functional tests. The proposed extension deals with some important concepts of non-functional testing such as the workload and the global verdicts. As a proof of concept we show how the extended UML-TP can be used for modeling non-functional test cases of an application example.
Federico Toledo Rodríguez, Francesca Lonetti, Antonia Bertolino, Macario Polo, Beatriz Pérez Lamancha
MODELSWARD2
2014 A Requirements-Led Approach for Specifying QoS-Aware Service Choreographies: An Experience Report
Neil A. M. Maiden, James Lockerbie, Konstantinos Zachos, Antonia Bertolino, Guglielmo De Angelis, Francesca Lonetti
REFSQ6
2014 Testing of PolPA-based usage control systems
Antonia Bertolino, Said Daoudagh, Francesca Lonetti, Eda Marchetti, Fabio Martinelli, Paolo Mori
Softw. Qual. J.3
2013 A Toolchain for Designing and Testing XACML Policies
abstract
In modern pervasive application domains, such as Service Oriented Architectures (SOAs) and Peer-to-Peer (P2P) systems, security aspects are critical. Justified confidence in the security mechanisms that are implemented for assuring proper data access is a key point. In the last years XACML has become the de facto standard for specifying policies for access control decisions in many application domains. Briefly, an XACML policy defines the constraints and conditions that a subject needs to comply with for accessing a resource and doing an action in a given environment. Due to the complexity of the language, XACML policy specification is a difficult and error prone process that requires specific knowledge and a high effort to be properly managed.
Antonia Bertolino, Marianne Busch, Said Daoudagh, Nora Koch, Francesca Lonetti, Eda Marchetti
ICST5
2012 Automatic XACML Requests Generation for Policy Testing
abstract
Access control policies are usually specified by the XACML language. However, policy definition could be an error prone process, because of the many constraints and rules that have to be specified. In order to increase the confidence on defined XACML policies, an accurate testing activity could be a valid solution. The typical policy testing is performed by deriving specific test cases, i.e. XACML requests, that are executed by means of a PDP implementation, so to evidence possible security lacks or problems. Thus the fault detection effectiveness of derived test suite is a fundamental property. To evaluate the performance of the applied test strategy and consequently of the test suite, a commonly adopted methodology is using mutation testing. In this paper, we propose two different methodologies for deriving XACML requests, that are defined independently from the policy under test. The proposals exploit the values of the XACML policy for better customizing the generated requests and providing a more effective test suite. The proposed methodologies have been compared in terms of their fault detection effectiveness by the application of mutation testing on a set of real policies.
Antonia Bertolino, Said Daoudagh, Francesca Lonetti, Eda Marchetti
ICST3
2012 Property-Driven Software Engineering Approach
abstract
We present a research roadmap that defines an enhanced model-driven software engineering approach focused on non-functional properties models. Currently, we have implemented two sub-processes of this roadmap: Property Modeling and Monitoring. We provide a property-driven approach to runtime monitoring based on a comprehensive Property Meta- Model (PMM) and on a generic configurable event-based monitoring infrastructure.
Antinisca Di Marco, Francesca Lonetti, Guglielmo De Angelis
ICST2
2012 The X-CREATE Framework - A Comparison of XACML Policy Testing Strategies
Antonia Bertolino, Said Daoudagh, Francesca Lonetti, Eda Marchetti
WEBIST3
2009 Exploiting signal strength detection and collision cancellation for tag identification in RFID systems
abstract
Radio Frequency IDentification (RFID) systems are becoming more and more popular in the field of ubiquitous computing, in particular for objects identification. An RFID system is composed by one or more readers and a number of tags. One of the main issues in an RFID network is the fast and reliable identification of all tags in the reader range. The reader issues some queries, and tags properly answer. Then, the reader must identify the tags from such answers. This is crucial for most applications. Since the transmission medium is shared, the typical problem to be faced is a MAC-like one, i.e. to avoid or limit the number of tags transmission collisions. We propose a protocol which, under some assumptions about transmission techniques, achieves a 60% performance on the average (in terms of transmitted bits). It is based on a proper recursive splitting of the concurrent tags sets and on signal storing and later cancellation, until all tags have been identified.
Maurizio A. Bonuccelli, Francesca Lonetti, Francesca Martelli
ISCC2
2007 Instant collision resolution for tag identification in RFID networks
Maurizio A. Bonuccelli, Francesca Lonetti, Francesca Martelli
Ad Hoc Networks2
2006 Tree Slotted Aloha: a New Protocol for Tag Identification in RFID Networks
abstract
In this paper, we approach the problem of identifying a set of objects in an RFID network. We propose a modified version of slotted aloha protocol to reduce the number of transmission collisions. All tags select a slot to transmit their ID by generating a random number. If there is a collision in a slot, the reader broadcasts the next identification request only to tags which collided in that slot. Simulation results show that our approach performs better than framed slotted aloha and query tree based protocols, in terms of number of slots needed to identify all tags, which is a commonly used metric, strictly related to delay
Maurizio A. Bonuccelli, Francesca Lonetti, Francesca Martelli
WOWMOM2
2005 Temporal Transcoding for Mobile Video Communication
abstract
Third generation mobile communication systems will provide more advanced types of interactive and distribution services, and video is one of the most prominent applications for multimedia communications. Adapting the media content to different networks characteristics (communication links and access terminals), in order to enable video delivery with acceptable service quality, is one of the most important problems in this setting. In this paper, we consider one of the video adaptation methods, namely video transcoding, and we present new buffer-based strategies for temporal video transcoding in a real-time context. Simulation results show that our strategies achieve a good performance in hard transcoding conditions also.
Maurizio A. Bonuccelli, Francesca Lonetti, Francesca Martelli
MobiQuitous2