Wangyang Yu 0001

dblp:138/5273 · also WangYang Yu 0001 · DBLP profile ↗
← Back
25ranked-venue papers
14as first author
19since 2021 · last 2025
0000-0003-1037-210XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 7 · 3 first-author · 6 since 2021Systems, architecture and hardware · 6 · 6 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 5 · 3 first-author · 2 since 2021Computer networks · 4 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Modeling and Risk Analysis of Cooperative Adaptive Cruise Control Systems Based on Petri Nets and Distributed Edge Intelligence
abstract
Fueled by advancements in intelligent transportation systems, the Internet of Vehicles (IoV) seeks to connect smart vehicles, road infrastructure, and users into a unified network, enhancing traffic efficiency and reducing accident risks. Centralized cloud data collection raises concerns about privacy and communication overhead. To address these, distributed edge intelligence (DEI) reduces transmission costs and improves privacy by implementing machine learning at the network edge. In this context, cooperative adaptive cruise control (CACC) systems, combined with DEI in the IoV framework, enhance transportation system intelligence through real-time data processing and decentralized decision making. This article proposes a modeling and analysis method for CACC systems based on Petri nets. The datasets are automatically generated using tools developed by our team, and machine-learning methods are utilized to perform risk prediction analysis on the CACC model. From the perspective of Petri nets synchronization, we propose risk mitigation strategies from a design standpoint. The research results show that the proposed method significantly reduces signal accumulation and enhances synchronization in CACC systems. This improvement provides new theoretical support and technical guidance for the design and implementation of CACC systems, ultimately enhancing their safety and reliability.
Wangyang Yu 0001, Yumeng Cheng, Xianwen Fang, Xiaojun Zhai, Hongyuan Jing
IEEE Internet Things J.1
2025 Model Checking of $\omega$-Independent Unbounded Petri Nets for an Unbounded System
abstract
This work on model checking of unbounded Petri nets either not really concern the$\omega$-component or only focus on the$\omega$symbols, which may lead to incorrect judgments. This article proposes a model checking approach of$\omega$-independent unbounded Petri nets. First, this approach can ensure the complete state space required for model checking by analyzing the enabled/unenabled marking set of conditionally enabled transition. Second, a comprehensive model checking process of$\omega$-independent unbounded PN is presented, including the generation of extended new modified reachability graph. Third, two theorems are presented to prove that extended new modified reachability graph includes complete reachable markings and sequences of transitions. Finally, the proposed new approach is illustrated through a practical example.
Shuo Wang 0042, Ru Yang 0001, Wangyang Yu 0001, Zhijun Ding, Changjun Jiang 0002
IEEE Trans. Comput. Soc. Syst.3
2025 Formal Modeling of Hybrid System Based on Semi-continuous Colored Petri Net: A Case Study of Adaptive Cruise Control System
abstract
Many Next-Generation consumer electronic devices would be distributed hybrid electronic systems, such as UAVs (Unmanned Aerial Vehicles) and smart electronic cars. The safety and risk control are the key issues for the sustainability of such consumer electronic systems. The modeling of hybrid electronic systems is difficult to be abstracted by traditional Petri Nets. This also makes the reachable marking graph unable to be applied to Petri Nets of the hybrid electronic systems. This paper proposes a novel Petri Net to model and analyze the hybrid electronic systems. We name it a Semi-continuous Colored Petri Net (SCPN) that inherits the excellent modeling capabilities and analysis methods of Petri Nets, and can formally depict hybrid quantities. In addition, we propose the construction algorithm for an SCPN reachable marking graph and prove its finiteness. Finally, we model and analyze an Adaptive Cruise Control (ACC) system of smart electronic cars as an example to prove the validity of SCPN. We use the proposed SCPN to model and analyze the running process of an ACC system under the continuous deceleration scenario of the front vehicle. The application study shows that the ACC system has logic flaws under the constant headway strategy when the front vehicle continues to decelerate. Based on this analysis, improvements to the SCPN of the ACC system are made, effectively enhancing its safety and logical correctness.
Wangyang Yu 0001, Yumeng Cheng, Lu Liu 0001, Fei Hao 0001, Xiaojun Zhai, Minsi Chen
ACM Trans. Embed. Comput. Syst.1
2025 Unsupervised Software Defect Prediction Through Multiview Clustering
abstract
The core goal of software defect prediction (SDP) is to identify modules with a high likelihood of defects, thereby enabling prioritization of quality assurance activities with low inspection effort. There are many supervised defect prediction models that are extensively studied. However, these methods require the need for labeling data to get enough training modules, which will cause a lot of waste of human resources. Cross-project defect prediction primarily reuses models trained on other projects with enough historical data. However, this strategy is often hindered by large distribution differences across different projects and privacy concerns of data. Unsupervised learning technique is an alternative solution to the unlabeled data, but it mainly focuses on single-view prediction by concatenating all the software metrics. This ignores the diversity and complementarity of different types of metrics. This study proposes a novel approach, namely, multiview unsupervised software defect prediction (MUSDP). It aims to collaboratively learn the diversity and complementarity of different views to build a robust and reliable defect prediction model. Extensive experiments on$ 28$releases from eight software projects indicate that MUSDP exhibits superior or comparable results regardingG-mean,AUC,$P_{\text{opt}}$, andRecall@20%compared to competing supervised and unsupervised methods. For the interpretation of MUSDP, the number of added and deleted lines significantly influence its predictions.
Zhiqiang Li 0003, Hongyu Zhang 0002, Xiaoyuan Jing, Wangyang Yu 0001, Yueyue Liu 0002
IEEE Trans. Reliab.4
2025 A Distributed Data-Driven and Machine Learning Method for High-Level Causal Analysis in Sustainable IoT Systems
abstract
A causal relationship forms when one event triggers another's change or occurrence. Causality helps to understand connections among events, explain phenomena, and facilitate better decision-making. In IoT systems, massive consumption of energy may lead to specific types of air pollution. There are causal relationships among air pollutants. Analyzing their interactions allows for targeted adjustments in energy use, like shifting to cleaner energy and cutting high-emission sources. This reduces air pollution and boosts energy sustainability, aiding sustainable development. This paper introduces a distributed data-driven machine learning method for high-level causal analysis (DMHC), which extracts general and high-level Complex Event Processing (CEP) rules from unlabeled data. CEP rules can capture the interactions among events and represent the causal relationships among them. DMHC deploys a two-layer LSTM attention mechanism model and decision tree algorithm to filter and label data, extracting general CEP rules. Afterward, it proceeds to generate event logs based on general rules with heuristic mining (HM), extracting high-level CEP rules that pertain to causal relationships. These high-level rules complement the extracted general rules and reflect the causal relationships among the general rules. The proposed high-level methodology is validated using a real air quality dataset.
Wangyang Yu 0001, Jing Zhang 0024, Lu Liu 0001, Xiaojun Zhai, Ruhul Kabir Howlader
IEEE Trans. Sustain. Comput.1
2024 Less: Large-scale Workload Forecasting Model Based on Multiple Sequence Compression
abstract
As application migration to the cloud becomes the mainstream way of application deployment, application runtime management presents a significant need for large-scale workload prediction technology. Existing large-scale workload approaches commonly construct training sets based on all the training samples generated from the original data to generate prediction models. However, due to the similar behavior between different container instances of the microservice application, training and modeling in this way results in a huge number of redundant samples, which produces a significant redundant training overhead. Therefore, this paper proposes Less, a largescale workload forecasting model based on multiple sequence compression. First, based on the grouping results of similar containers, a container workload feature recognition algorithm is proposed to determine the common and individual features of container workloads in each prediction period, so as to guide the compression of workload sequences within each group; second, a fitness function that takes into account the common features, individual features, and the number of sequences are designed, and the optimal compressed sequences are solved by the Whale Optimization Algorithm to efficiently reduce the number of redundant training workload sequences, and then the Bidirectional Gated Recurrent Unit model is built and trained based on the compressed sequences, which effectively reduces the model complexity and overhead while ensuring the accuracy. Finally, we validate the comprehensive advantages of Less in terms of accuracy and overhead based on public datasets and verify the effectiveness of each subpart of our model through ablation experiments.
Zeyuan Ding, Binbin Feng, Wangyang Yu 0001, Bolan Zhang
ICWS3
2024 Enhancing security in e-business processes: Utilizing dynamic slicing of Colored Petri Nets for logical vulnerability detection
Wangyang Yu 0001, Lu Liu 0001, Xiaojun Zhai, Yumeng Cheng
Future Gener. Comput. Syst.1
2024 Formal Modeling and Analysis of User Activity Sequence in Online Social Networks: A Stochastic Petri Net-Based Approach
abstract
The continuous interaction of users and information aggregation has become a social phenomena over massive social media platforms. However, the uncertainty of users’ behavior is leading great challenges to social networks analysis in terms of system structure, evolution characteristics, dynamic behavior, and so forth. Thus, this article proposes a formal user behavior modeling and analysis approach. First, aiming at identifying the behavior patterns of user activity sequence, we present a user activity transition system model based on stochastic Petri net (SPN), which can formally depict the process and structures of social users click activities. Then, the average number of tokens in each place, the probability density function of the tokens, the token flow rate of transitions, and the time spent in each state are analyzed by isomorphic it into a Markov chain (MC), respectively. These four indicators are used to evaluate the performance of the proposed system model. The experimental results demonstrate that the proposed approach can help us to understand the rules of users’ first activity and activity preferences, so as to provide practical suggestions for the development of social networking platforms and content recommendation.
Wangyang Yu 0001, Jinming Kong, Fei Hao 0001, Jian Li 0032
IEEE Trans. Comput. Soc. Syst.1
2024 A Multiperspective Fraud Detection Method for Multiparticipant E-Commerce Transactions
abstract
Detection and prevention of fraudulent transactions in e-commerce platforms have always been the focus of transaction security systems. However, due to the concealment of e-commerce, it is not easy to capture attackers solely based on the historic order information. Many works try to develop technologies to prevent frauds, which have not considered the dynamic behaviors of users from multiple perspectives. This leads to an inefficient detection of fraudulent behaviors. To this end, this article proposes a novel fraud detection method that integrates machine learning and process mining models to monitor real-time user behaviors. First, we establish a process model concerning the business-to-customer (B2C) e-commerce platform, by incorporating the detection of user behaviors. Second, a method for analyzing abnormalities that can extract important features from event logs is presented. Then, we feed the extracted features to a support vector machine (SVM)-based classification model that can detect fraud behaviors. We demonstrate the effectiveness of our method in capturing dynamic fraudulent behaviors in e-commerce systems through the experiments.
Wangyang Yu 0001, Lu Liu 0001, Yisheng An, Bo Yuan 0004, John Panneerselvam
IEEE Trans. Comput. Soc. Syst.1
2024 Modeling and Analysis of ETC Control System with Colored Petri Net and Dynamic Slicing
abstract
Nowadays, Electronic Toll Collection (ETC) control systems have been widely adopted to smoothen traffic flow on highways. However, as it is a complex business interaction system, there are inevitably flaws in its control logic process, such as the problem of vehicle fee evasion. We find that there is more than one way for vehicles to evade fees. This shows that it is difficult to ensure the completeness of its design. Therefore, it is necessary to adopt a novel formal method to model and analyze its design, detect flaws, and modify it. In this article, a Colored Petri net (CPN) is introduced to establish its model. To analyze and modify the system model more efficiently, a dynamic slicing method of CPN is proposed. First, a static slice is obtained from the static slicing criterion by backtracking. Second, considering all binding elements that can be enabled under the initial marking, a forward slice is obtained from the dynamic slicing criterion by traversing. Third, the dynamic slicing of CPN is obtained by taking the intersection of both slices. The proposed dynamic slicing method of CPN can be used to formalize and verify the behavior properties of an ETC control system, and the flaws can be detected effectively. As a case study, the flaw about a vehicle that has not completed the payment following the previous vehicle to pass the railing is detected by the proposed method.
Wangyang Yu 0001, Jinming Kong, Zhijun Ding, Xiaojun Zhai, Zhiqiang Li 0003
ACM Trans. Embed. Comput. Syst.1
2023 Work-in-Progress-A Large-Scale Workload Forecasting Model for Containers
abstract
As application migration to the cloud becomes the mainstream way of application deployment, application runtime management presents a significant need for large-scale workload prediction technology. However, existing large-scale workload forecasting models focus more on improving model accuracy and ignore the models’ storage, training time, and testing time, which leads to colossal overhead. Therefore, this paper proposes a large-scale workload forecasting model for containers. First, based on the workload value features and waveform features, a feature-enhanced workload similarity calculation algorithm is proposed to determine the grouping of containers with similar workload patterns in real time by analyzing the historical similarity and recent similarity of workloads among different containers; second, we employ Transformer as the base model to design position encoding and attention mask based on the real-time workload similarity relationship and achieve forecasting model parallelized training based on the multi-head self-attention mechanism, which balances the workload prediction accuracy and model overhead. Finally, we will validate the comprehensive advantages of our model in terms of accuracy and overhead based on public datasets and verify the effectiveness of each subpart of our model through ablation experiments.
Zeyuan Ding, Binbin Feng, Wangyang Yu 0001
ICWS3
2023 Grading and Calculation of Synchronic Distance in Petri Nets for Trustworthy Modeling and analyzing
abstract
Synchronization plays a crucial role in computer systems, providing support for system security, data consistency, and coordination. It contributes to the establishment and application of trust, security, and dependability in distributed systems and concurrent computing to a significant extent. This article makes innovative contributions in the field of synchronic distance in Petri net. We provide refined definitions for the hierarchical classification of synchronic levels in Petri net, proposing the concepts of absolute synchronization, strong synchronization, and extended synchronization based on different conditions. Furthermore, we propose an innovative method for calculating synchronic distance. This method can automate the calculation of synchronic distance between any two transitions using computer computation, resulting in improved accuracy and reduced errors. This novel approach provides an effective tool for system security and trustworthy modeling, as accurate synchronic distance calculations allow for better evaluation of synchronic distance between different transitions, leading to the identification of potential security vulnerabilities and design flaws, thereby enhancing the credibility of decision-making and promoting the reliability of models and analysis results. To validate the proposed method, we introduce a specific example of a Petri net with concurrency, demonstrate the practicality and effectiveness of the proposed method and algorithm through analysis of this example. Our work extends the research on Petri net synchronic distance, further advancing the understanding and exploration of this field.
Yumeng Cheng, Wangyang Yu 0001, Xiaojun Zhai, Fei Hao 0001
TrustCom2
2023 Dual-LightGCN: Dual light graph convolutional network for discriminative recommendation
Wenqing Huang, Fei Hao 0001, Jiaxing Shang, Wangyang Yu 0001, Shengke Zeng, Carmen Bisogni, Vincenzo Loia
Comput. Commun.4
2023 Modeling and Analyzing Logic Vulnerabilities of E-Commerce Systems at the Design Phase
abstract
E-commerce systems have become tremendously popular and important for modern business processes in the world of the digital economy. E-commerce business processes rely on the distributed and concurrent interaction process among Web applications of participants, such as clients, merchants, third-party payment platforms (TPPs), and bank systems. Such complex business interactions bridge the gap of trustiness among participants and introduce new security challenges in the form of logical vulnerabilities, which are prevalent in the business process at the application level. The most pressing challenge is to guarantee security throughout the checkout process at the conceptual design phase such that the logic errors can be detected before the actual implementation. Maintenance and repair of implemented e-commerce systems can be extremely costly. To this end, this article proposes a novel modeling and analyzing methodology for multiparticipants and multisessions e-commerce interaction processes based on colored Petri nets (CPNs). First, we define a novel model that can efficiently depict the key properties of e-commerce business interaction processes. Second, several modeling principles are formulated based on the design specification of e-commerce systems. Finally, the concept of Transaction-Logical Consistency is defined to analyze and verify the logical vulnerabilities of e-commerce systems. Through a discussed case study, we demonstrate the feasibility and applicability of the proposed methodology and its efficiency in detecting problems those can potentially lead to logical vulnerabilities.
Wangyang Yu 0001, Lu Liu 0001, Xiaoming Wang 0001, Ovidiu Bagdasar, John Panneerselvam
IEEE Trans. Syst. Man Cybern. Syst.1
2022 Multi-factor Balanced Feedback and Reliability Analysis of Adaptive Cruise Control System Based on Petri Nets
abstract
The intelligent transportation system has developed rapidly in recent years, and its reliability and safety have also attracted a lot of attention. The Adaptive Cruise control (ACC) system is a significant achievement of traffic intelligence. The principle of the ACC system is the process of balance feedback between the relative speed and distance of the front and current vehicles. In this paper, the running principle of ACC system is abstracted, and the Balanced Feedback Net (BFN) is proposed to model and analyze it based on Petri nets. The reachable marking graph and the incidence matrix of Petri nets are used to analyze the BFN model. The analysis results show a certain risk of rear-end collision in the balance feedback process of the ACC system. In this regard, we give a relevant risk identification algorithm to reduce the risk of rear-end collision and improve the reliability of the ACC system.
Wangyang Yu 0001, Liang Qi 0001
SMC2
2022 Knowledge points navigation based on three-way concept lattice for autonomous learning
Fei Hao 0001, Yanqi Gong, Wangyang Yu 0001, Vincenzo Loia
Pattern Recognit. Lett.3
2022 A Detection Method for Abnormal Transactions in E-Commerce Based on Extended Data Flow Conformance Checking
abstract
With the development of smart devices and mobile communication technologies, e‐commerce has spread over all aspects of life. Abnormal transaction detection is important in e‐commerce since abnormal transactions can result in large losses. Additionally, integrating data flow and control flow is important in the research of process modeling and data analysis since it plays an important role in the correctness and security of business processes. This paper proposes a novel method of detecting abnormal transactions via an integration model of data and control flows. Our model, called Extended Data Petri net (DPNE), integrates the data interaction and behavior of the whole process from the user logging into the e‐commerce platform to the end of the payment, which also covers the mobile transaction process. We analyse the structure of the model, design the anomaly detection algorithm of relevant data, and illustrate the rationality and effectiveness of the whole system model. Through a case study, it is proved that each part of the system can respond well, and the system can judge each activity of every mobile transaction. Finally, the anomaly detection results are obtained by some comprehensive analysis.
Wangyang Yu 0001, Peng Teng, Guanjun Liu, Dongming Xiang
Wirel. Commun. Mob. Comput.2
2021 Modeling and Analysis of Medical Resource Sharing and Scheduling for Public Health Emergencies based on Petri Nets
abstract
Medical information systems (MIS) play a vital role in managing and scheduling medical resources to underpin healthcare services, which has become more critically important during major public health emergencies. During the Covid-19 pandemic, MIS is facing significant challenges to cope with the surge in demands of medical resources, resulting in more deaths and wider spreading of the disease. Our research examines how to allocate and utilize the medical resources across hospitals in a more accurate, and effective way to mitigate medical resource shortages and sustain the resource provisions. This paper mainly investigated the hospital’s supply-and-demand problems for medical resources under major public health emergencies by analyzing the allocation of medical staff resources. Furthermore, a formal method based on the Colored Petri Nets (CPN) has been proposed to model and characterize the medical business process and resource scheduling tasks. The experiments demonstrate that our approach can correctly and efficiently complete the dynamical scheduling process for surging requests.
Wangyang Yu 0001, Menghan Jia, Bo Yuan 0004
MSN1
2021 Cross-Project Defect Prediction via Landmark Selection-Based Kernelized Discriminant Subspace Alignment
abstract
Cross-project defect prediction (CPDP) refers to identifying defect-prone software modules in one project (target) using historical data collected from other projects (source), which can help developers find bugs and prioritize their testing efforts. Recently, CPDP has attracted great research interest. However, the source and target data usually exist redundancy and nonlinearity characteristics. Besides, most CPDP methods do not exploit source label information to uncover the underlying knowledge for label propagation. These factors usually lead to unsatisfactory CPDP performance. To address the above limitations, we propose a landmark selection-based kernelized discriminant subspace alignment (LSKDSA) approach for CPDP. LSKDSA not only reduces the discrepancy of the data distributions between the source and target projects, but also characterizes the complex data structures and increases the probability of linear separability of the data. Moreover, LSKDSA encodes label information of the source data into domain adaptation learning process and makes itself with good discriminant ability. Extensive experiments on 13 public projects from three benchmark datasets demonstrate that LSKDSA performs better than a range of competing CPDP methods. The improvement is 3.44%-11.23% in g-measure, 5.75%-11.76% in AUC, and 9.34%-33.63% in MCC, respectively.
Zhiqiang Li 0003, Jingwen Niu, Xiaoyuan Jing, Wangyang Yu 0001
IEEE Trans. Reliab.4
2020 Petri net-based methods for analyzing structural security in e-commerce business processes
Wangyang Yu 0001, Zhijun Ding, Lu Liu 0001, Xiaoming Wang 0001, Richard David Crossley
Future Gener. Comput. Syst.1
2020 Modeling and analysis of medical resource allocation based on Timed Colored Petri net
Wangyang Yu 0001, Menghan Jia, Xianwen Fang, Yao Lu 0021, Jianchun Xu
Future Gener. Comput. Syst.1
2020 A Dynamic Data Slice Approach to the Vulnerability Analysis of E-Commerce Systems
abstract
The e-commerce business process net (EBPN) is a novel formal model for describing an e-commerce system and its interactive parts, such as shoppers, merchants, and the third-party payment platforms. Vulnerability analysis has a great impact on the trustworthiness of EBPN, which is an issue stemming from data inconsistency problems. Data inconsistency problems affect the consistency of the EBPN transaction analysis. The underlying causes of inconsistent data are closely related to concurrent operations, such as control flow and data flow. However, most of the existing detection methods have difficulties characterizing the vulnerabilities and interactions of control and data flows. In this paper, we propose a new method based on the dynamic data slice (DDS) that considers both transaction consistency and data state consistency. First, by analyzing control flow characteristics of EBPN, we obtain the dynamic slice. This dynamic slice is based on all paths of the EBPN reachability graph. Second, we perform the data inconsistency analysis by considering both transaction consistency and data-state consistency. Based on these, we construct a DDS to characterize the behavioral logic and the data-dependence information. The DDS acquires the dynamic data firing sequence. Based on that sequence and a given data marking, we can construct the DDSs for several types of EBPNs. Constructing the DDS can be completed in polynomial time. The DDS is designed to characterize the behavioral logic and data-dependence information. Based on these, we design a method to judge the data constraints. This method satisfies the EBPN need for transaction consistency by considering both the control and data states. In addition, according to the data-dependence information, we can lock the vulnerable regions caused by abnormal trading data in the system. Finally, we give a method to compute the vulnerability level.
Mimi Wang, Zhijun Ding, Peihai Zhao, Wangyang Yu 0001, Changjun Jiang 0002
IEEE Trans. Syst. Man Cybern. Syst.4
2018 Analyzing E-Commerce Business Process Nets via Incidence Matrix and Reduction
abstract
E-commerce business process nets (EBPNs) are a novel formal model for describing and validating e-commerce systems including interactive parties such as shopper, merchant, and third-party payment platform. Data errors and nondeterminacy of the data states during the trading process can be depicted with the help of EBPNs. However, the problem about how to analyze EBPNs remains largely open. To analyze their data-liveness, data-boundedness, and reachability, this paper presents two analysis methods. For EBPNs, reachability analysis is proposed based on a 3-D incidence matrix method. Additionally, reduction methods are proposed for a special EBPN. Finally, the validity and reliability of the proposed methods are illustrated via the examples of e-commerce systems.
Wangyang Yu 0001, ChunGang Yan, Zhijun Ding, Changjun Jiang 0002, MengChu Zhou
IEEE Trans. Syst. Man Cybern. Syst.1
2016 Modeling and Verification of Online Shopping Business Processes by Considering Malicious Behavior Patterns
abstract
Recently, online shopping integrating third-party payment platforms (TPPs) introduces new security challenges due to complex interactions between Application Programming Interfaces (APIs) of Merchants and TPPs. Malicious clients may exploit security vulnerabilities by calling APIs in an arbitrary order or playing various roles. To deal with the security issue in the early stages of system development, this paper presents a formal method for modeling and verification of online shopping business processes with malicious behavior patterns considered based on Petri nets. We propose a formal model called E-commerce Business Process Net to model a normal online shopping business process that represent intended functions, and malicious behavior patterns representing a potential attack that violates the security goals at the requirement analysis phase. Then, we synthesize the normal business process and malicious behavior patterns by an incremental modeling method. According to the synthetic model, we analyze whether an online shopping business process is resistant to the known malicious behavior patterns. As a result, our approach can make the software design provably secured from the malicious attacks at process design time and, thus, reduces the difficulty and cost of modification for imperfect systems at the release phase. We demonstrate our approach through a case study.
Wangyang Yu 0001, ChunGang Yan, Zhijun Ding, Changjun Jiang 0002, MengChu Zhou
IEEE Trans Autom. Sci. Eng.1
2014 Modeling and Validating E-Commerce Business Process Based on Petri Nets
abstract
E-commerce and online shopping with a third-party payment platform have rapidly developed recently, and encountered many fault tolerance and security problems concerned by users. The causes of these problems include malicious behavior and imperfect business processes. The latter lead to the emergence of security vulnerabilities and loss of user funds which become more and more serious these years. We focus on the business process of e-commerce, and propose a formal model for constructing an e-commerce business process called an E-commerce Business Process Net. It integrates both data and control flows based on Petri nets. Rationality and transaction consistency are defined and validated to guarantee the transaction properties of an e-commerce business process. This paper offers a complete methodology for modeling and validating an e-commerce system with a third-party payment platform from the view point of a business process. Its use enables a designer to identify errors early in the design process and correct them before the deployment phase. In order to demonstrate the applicability and feasibility of the methodology, we have modeled and validated a real-world e-commerce business process and discovered the problems that cause the violation of transaction properties.
Wangyang Yu 0001, ChunGang Yan, Zhijun Ding, Changjun Jiang 0002, MengChu Zhou
IEEE Trans. Syst. Man Cybern. Syst.1