Rose F. Gamble

dblp:25/2193 · DBLP profile ↗
← Back
44ranked-venue papers
6as first author
2since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 17 · 1 first-authorHuman-computer interaction and ubiquitous computing · 9 · 3 first-authorArtificial intelligence and machine learning · 6 · 2 first-authorSystems, architecture and hardware · 2 · 1 since 2021Security and privacy · 2Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2Databases, data management, data science and information retrieval · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
7 papers
Services computing and microservices · 79% Requirements engineering and software design · 12% Program verification · 4%
Human-computer interaction and pervasive computing
1 paper
Collaborative and social computing · 100%
Interdisciplinary, comprehensive, and emerging computing
1 paper
Computing education · 100%
Artificial intelligence
2 papers
Knowledge representation and reasoning · 100%

Topics — the 13 heaviest of 18, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Services computing and microservices › service selection
qos-aware service selection
0.212014
Introducing Replaceability into Web Service Composition · IEEE Trans. Serv. Comput. 2014
Services computing and microservices › service composition
web service composition
0.212014
Introducing Replaceability into Web Service Composition · IEEE Trans. Serv. Comput. 2014
Collaborative and social computing
computer-supported cooperative work
0.112011
SEREBRO: facilitating student project team collaboration · ICSE 2011
Computing education
software engineering education
0.012011
SEREBRO: facilitating student project team collaboration · ICSE 2011
Requirements engineering and software design › software architecture
component-based software engineering
0.012001
A notation for problematic architecture interactions · ESEC / SIGSOFT FSE 2001
Requirements engineering and software design
software architecture
0.012001
A notation for problematic architecture interactions · ESEC / SIGSOFT FSE 2001
Knowledge, reasoning and agents › Knowledge representation and reasoning › knowledge-based systems
knowledge-based system design
0.011997
Using meta-knowledge within a multilevel framework for KBS development · Int. J. Hum. Comput. Stud. 1997
Program verification › refinement
specification refinement
0.021993
Seeking Concurrency in Rule-Based Programming · ICSE 1992
Formal Derivation of Rule-Based Programs · IEEE Trans. Software Eng. 1993
Program verification › refinement
program refinement
0.011993
Formal Derivation of Rule-Based Programs · IEEE Trans. Software Eng. 1993
Software maintenance and evolution
software integration
0.012001
A notation for problematic architecture interactions · ESEC / SIGSOFT FSE 2001
Programming languages and type systems › programming paradigms
rule-based programming
0.011992
Seeking Concurrency in Rule-Based Programming · ICSE 1992
Knowledge, reasoning and agents › Knowledge representation and reasoning
expert systems
0.011996
A methodology to incorporateformal methods in hybrid KBS verification · Int. J. Hum. Comput. Stud. 1996
Parallel and multicore computing
concurrent programming
0.011992
Seeking Concurrency in Rule-Based Programming · ICSE 1992

Methods — techniques the papers use, named apart from their topics

demonstration · 0.2qos constraint optimization · 0.2formal methods · 0.0formal refinement · 0.0formal verification · 0.0specification refinement · 0.0program refinement · 0.0
YearPublicationVenuePosition
2025 Securing Microservices: Risk-Adaptive gRPC Access Control Policies
abstract
There is an increased adoption of Google Remote Procedure Call (gRPC) as one of the key communication protocols in microservice architecture (MSA) applications. This adoption leads to extending the need for runtime adaptive access control policies through the service mesh to reduce the risks of compromised microservices reaching other microservices. A service mesh, as a layer within the orchestration solution, provides features, such as secure communication, within a deployed MSA application. However, it lacks the mechanisms for adaptive gRPC access control policies to meet the zero-trust principle of always verifying and never trusting. This paper introduces a novel mechanism that extends our previous work on risk-adaptive access control to the use of gRPC through the service mesh. We demonstrate our approach and show how gRPC adaptive access control policies can be applied dynamically at runtime for deployed microservices. We use Kubernetes as the orchestration solution and Istio as the service mesh platform in a model MSA application called Online Boutique hosted on the CloudLab scientific computing platform.
Rami Alboqmi, Rose F. Gamble
WINCOM2
2021 Evaluating verification awareness as a method for assessing adaptation risk
abstract
Self-integration requires a system to be self-aware and self-protecting of its functionality and communication processes to mitigate interference in accomplishing its goals. Incorporating self-protection into a framework for reasoning about compliance with critical requirements is a major challenge when the system’s operational environment may have uncertainties resulting in runtime changes. The reasoning should be over a range of impacts and tradeoffs in order for the system to immediately address an issue, even if only partially or imperfectly. Assuming that critical requirements can be formally specified and embedded as part of system self-awareness, runtime verification often involves extensive on-board resources and state explosion, with minimal explanation of results. Model-checking partially mitigates runtime verification issues by abstracting the system operations and architecture. However, validating the consistency of a model given a runtime change is generally performed external to the system and translated back to the operational environment, which can be inefficient. This paper focuses on codifying and embedding verification awareness into a system. Verification awareness is a type of self-awareness related to reasoning about compliance with critical properties at runtime when a system adaptation is needed. The premise is that an adaptation that interferes with a design-time proof process for requirement compliance increases the risk that the original proof process cannot be reused. The greater the risk to limiting proof process reuse, the higher the probability that the requirement would be violated by the adaptation. The application of Rice’s 1953 theorem to this domain indicates that determining whether a given adaptation inherently inhibits proof reuse is undecidable, suggesting the heuristic, comparative approach based on proof metadata that is part of our approach. To demonstrate our deployment of verification awareness, we predefine four adaptations that are all available to three distinct wearable simulations (hearables, stress, and insulin delivery). We capture metadata from applying automated theorem proving to wearable requirements and assess the risk among the four adaptations for limiting the proof process reuse for each of their requirements. The results show that the adaptations affect proof process reuse differently on each wearable. We evaluate our reasoning framework by embedding checkpoints for requirement compliance within the wearable code and log the execution trace of each adaptation. The logs confirm that the adaptation selected by each wearable with the lowest risk of inhibiting proof process reuse for its requirements also causes the least number of requirement failures in execution.
Ian Riley, Sharmin Jahan, Allen Marshall, Charles Walter, Rose F. Gamble
Future Gener. Comput. Syst.5
2020 MAPE-K/MAPE-SAC: An interaction framework for adaptive systems with security assurance cases
abstract
Security certification establishes that a given system satisfies properties and constraints as specified in the system security profile. Mechanisms and techniques have been developed to assess if and how well the system complies with the properties, thereby providing a degree of confidence in the security certification. Generally, certification of security controls defined by NIST SP800-53 is performed at design time to provide confidence in a system’s trustworthiness to achieve the organization’s mission and business requirements. Assuring confidence in a self-adaptive system’s security profile is challenging when both functional and security conditions may change at run time. Static security solutions are insufficient, given that dynamic application of defense mechanisms often needs to dynamically adapt security functionality at run time as part of self-protection. This security adaptation may hinder maintaining functional constraints or vice versa. In addition, adaptation capabilities may give rise to the need for dynamic certification, which can be a difficult procedure given the complexity of the security dependencies. Confidence in an information system’s compliance with security constraints can be expressed using security assurance cases (SACs). NIST security controls are defined with a hierarchical structure that makes them amenable to being specified in terms of SACs. A collection of SACs for related security controls form a network that can be used to measure the confidence of security compliance through certification-based evidence. Once the system is deployed, environmental and functional uncertainties may require the coordination of functional and security adaptations. This paper introduces the MAPE-SAC, a security-focused feedback control loop, and its interaction with a MAPE-K, function and performance-focused control loop, to dynamically manage run-time adaptations in response to changes in functional and security conditions. We illustrate the use of both control loops and their interaction with an example of two independent systems that need to cooperate to facilitate autonomous search and rescue in the aftermath of a natural disaster.
Sharmin Jahan, Ian Riley, Charles Walter, Rose F. Gamble, Matthew Pasco, Philip K. McKinley, Betty H. C. Cheng
Future Gener. Comput. Syst.4
2019 Semantic hierarchies for extracting, modeling, and connecting compliance requirements in information security control standards
abstract
Companies and government organizations are increasingly compelled, if not required by law, to ensure that their information systems will comply with various federal and industry regulatory standards, such as the NIST Special Publication on Security Controls for Federal Information Systems (NIST SP-800-53), or the Common Criteria (ISO 15408-2). Such organizations operate business or mission critical systems where a lack of or lapse in security protections translates to serious confidentiality, integrity, and availability risks that, if exploited, could result in information disclosure, loss of money, or, at worst, loss of life. To mitigate these risks and ensure that their information systems meet regulatory standards, organizations must be able to (a) contextualize regulatory documents in a way that extracts the relevant technical implications for their systems, (b) formally represent their systems and demonstrate that they meet the extracted requirements following an accreditation process, and (c) ensure that all third-party systems, which may exist outside of the information system enclave as web or cloud services also implement appropriate security measures consistent with organizational expectations. This paper introduces a step-wise process, based on semantic hierarchies , that systematically extracts relevant security requirements from control standards to build a certification baseline for organizations to use in conjunction with formal methods and service agreements for accreditation. The approach is demonstrated following a case study of all audit-related controls in the SP-800-53, ISO 15408-2, and related documents. Accuracy, applicability, consistency, and efficacy of the approach were evaluated using controlled qualitative and quantitative methods in two separate studies.
Matthew L. Hale, Rose F. Gamble
Requir. Eng.2
2018 Toward Increasing Collaboration Awareness in Software Engineering Teams
abstract
This Research Full Paper investigates collaborative personality traits in undergraduate software engineering teams. Online tools, such as Slack.com, provide team engagement and project management. While metrics can be defined for team and individual performance, it is difficult to measure collaboration and its impacts. Specifically, the forms of collaboration that lead to a successful software product should have associated metrics that correlate with individual performance, peer assessments, and project outcomes. Given the difficulty of assembling teams that best exemplify collaborative personality traits, it may be more beneficial for team members to recognize these traits so that their positive aspects can be exploited toward a successful product outcome. We employ IBM WatsonTMPersonality Insights service to analyze team Slack.com posts collected from forty students across ten teams and two semesters of the capstone class. We correlate thirteen traits recognized for influencing collaboration with team grades, Sprint meeting check-in quality, and peer evaluations. The correlations show that each trait is related to at least one performance metric during at least one of the Sprints. We discuss the potential meaning of different traits emerging at different times during the semester and how that can inform strategies for software developer collaboration awareness and reward.
Shuddha Chowdhury, Charles Walter, Rose F. Gamble
FIE3
2016 Configuring an appropriate team environment to satisfy relevant criteria
abstract
Accredited computer science programs have a capstone course requiring a significant programming project. Generally, these projects are part of a software engineering class and require a team effort. To facilitate team interaction, instructor monitoring, and objective performance assessment, an appropriate team environment, or set of components and services that can be combined to form an environment, must be chosen, configured, and managed. Since many of the popular team environments have subscription or per-seat licensing, educational institutions could pay significant costs to keep pace with industry. However, instructors should be able to provide a work environment with modern tools to facilitate team interaction and foster productivity while at the same time minimizing cost and reducing their configuration and management effort. In this paper, we survey a wide range of team environments and individual services for team interaction. We compare and contrast them against a set of general, user, and instructor criteria, highlighting features that are relevant to a software engineering team in an educational setting. In addition to the survey, we discuss an open source, experimental platform we are developing to allow instructors to incorporate free services and create a collaborative team environment based on the criteria they want to target.
Charles Walter, Ian Riley, Rose F. Gamble
FIE3
2016 Dynamic Change Arcs to Explore Model Forecasts
abstract
Abstract In many planning applications, a computational model is used to make predictions about the effects of management or engineering decisions. To understand the implications of alternative scenarios, a user typically adjusts one or more of the input parameters, runs the model, and examines the outcomes using simple charts. For example, a time series showing changes in productivity or revenue might be generated. While this approach can be effective in showing the projected effects of changes to the model's input parameters, it fails to show the mechanisms that cause those changes. In order to promote understanding of model mechanics using a simple graphical device, we propose dynamic change arcs. Dynamic change arcs graphically reveal the internal model structure as cause and effect linkages. They are signed to show both positive and negative effects. We implemented this concept using a species interaction model developed for fisheries management based on a system of Lotka‐Volterra equations. The model has 10 economically important fish species and incorporates both predation and competition between species. The model predicts that changing the catch of one species can sometimes result in changes in biomass of another species through multi‐step causal chains. The dynamic change arcs make it possible to interpret the resulting complex causal chains and interaction effects. We carried out an experiment to evaluate three alternative forms of arcs for portraying causal connections in the model. The results show that all linkage representations enabled participants to reason better about complex chains of causality than not showing linkages. However, none of them were significantly better than the others.
C. St. Jean, Colin Ware, Rose F. Gamble
Comput. Graph. Forum3
2015 Stream Processing with Secure Information Flow Constraints
Indrakshi Ray, Raman Adaikkalavan, Xing Xie 0002, Rose F. Gamble
DBSec4
2015 Gauging influence in software development teams
abstract
Agile software development teams are generally small, focused groups that require highly motivated members operating in a high-trust environment. Through interactive communication and collaborative work, team members can influence project outcomes both directly and indirectly. One method to examine influence is in terms of communication and control flow among team members when sharing a communication medium and artifact development tools. There currently exist several approaches for characterizing team communication using social network analysis. However, these approaches require modification to be applicable for measuring control flow influence in small teams. In this paper, we discuss the methodology and results of an influence study in which we analyze data generated by student teams in a capstone Software Engineering course. We develop three metrics to measure direct and indirect influence among team members, taking into account the temporal order of interactions and the small size of the teams studied. We correlate the influence metrics with grades, existing participation metrics, and team evaluation scores. The results suggest that our influence metrics correlate to a team member's perceived role on the team, measures of team communication and levels of task performance. This suggests that instructors can recognize the levels of influence exerted by team members by examining team communication and control flow, allowing for mediation prior to product development milestones.
Allen Marshall, Rose F. Gamble
FIE2
2015 Measuring the Potential for Victimization in Malicious Content
abstract
Sending malicious content to users for obtaining personnel, financial, or intellectual property has become a multi-billion dollar criminal enterprise. This content is primarily presented in the form of emails, social media posts, and phishing websites. User training initiatives seek to minimize the impact of malicious content through improved vigilance. Training works best when tailored to specific user deficiencies. However, tailoring training requires understanding how malicious content victimizes users. In this paper, we link a set of malicious content design factors, in the form of degradations and sophistications, to their potential to form a victimization prediction metric. The design factors examined are developed from an analysis of over 100 pieces of content from email, social media and websites. We conducted an experiment using a sample of the content and a game-based simulation platform to evaluate the efficacy of our victimization prediction metric. The experimental results and their analysis are presented as part of the evaluation.
Matthew L. Hale, Rose F. Gamble, John Hale, Charles Haney, Charles Walter
ICWS2
2014 Embedding a Distributed Auditing Mechanism in the Service Cloud
abstract
The Cloud Security Alliance identified the "notorious nine" threats for cloud computing. The range of these threats across the cloud indicates that centralized prevention and detection would be highly inefficient, potentially reporting incidents to tenants well after they occur and are difficult to mitigate. This paper presents an auditing framework for the service cloud that distributes logging, monitoring, and reporting at the local service level, at the application or session level that can involve multiple tenant services, and at the cloud level where corroboration and verification of threats takes place. To verify the forensic coverage of the framework, a set of CAPEC attack patterns are investigated to match attack evidence gathering and mitigation techniques with the proposed distributed detection and mitigation levels of the framework.
Sarra Alqahtani, Rose F. Gamble
SERVICES2
2014 Toward Increasing Awareness of Suspicious Content through Game Play
abstract
Phishing, elicitation, and impersonation techniques are performed using multiple forms, targeting content specific to the delivery modality, such as email, social media, and general browser communications. Education to increase awareness is one mechanism to combat phishing. Average email and internet users are less attentive to media warnings and training materials provided by employers than they are in interactive environments. In this paper, we overview a game concept that immerses users in a role play challenge where they must send email, use social media, and browse the web and determine whether content received within these modalities is trustworthy or not. The game, built as a Javascript framework, simulates phishing scams, measures trust and suspicion levels, and individualizes training for users. The game architecture employs components that facilitate dynamic content generation in each of the modalities, customize experiment design for specific assessment and training, and perform sophisticated tracking for automated analysis of user trust content assessments. We discuss the game content, the specific requirements the game must comply with, and the experiments to be conducted using the game.
Matthew L. Hale, Rose F. Gamble
SERVICES2
2014 Introducing Replaceability into Web Service Composition
abstract
By discovering and reusing relevant web services, an organization can select and compose those services that most closely meet its business and Quality of Service (QoS) needs. As the number of available web services increases, selecting the best fit services for a given task becomes more challenging. QoS attributes play a significant role in the selection process by directing service composition constraints to a workflow plan that has the best QoS values. Two major problems arise at runtime when undesirable events necessitate the need to reselect services and replan the service bindings. First, if the reselection process consumes additional time, it can impact a temporal QoS constraint. Second, the newly generated composition might not comply with other QoS constraints imposed on the plan. This paper proposes an approach to composing web services that both performs reselection and avoids the violation of QoS constraints after replanning by defining and evaluating a replaceability property. Replaceability factors directly into the algorithm's original service selection process considering all QoS constraints.
Hussein Al-Helal, Rose F. Gamble
IEEE Trans. Serv. Comput.2
2013 Assessing individual performance in Agile undergraduate software engineering teams
abstract
The Agile Software Development (ASD) process is at the forefront of rapid product development driven by changing customer requirements and a trusted, self-organizing development team. Scrum has become a viable model of ASD focusing on determining immediate deliverables and structuring short timelines, called Sprints, for designing, implementing, and providing them for testing by the customer. While these practices are being adopted by organizations, there is significant difficulty in scaling them to the classroom. Once in place, it is a complex task to evaluate individual student performance based solely on the product outcome and Sprint grade. Thus, there is limited opportunity to catch performance problems that may lead to missing deliverable deadlines or decreasing team trust. In this paper, we impose ASD using Scrum on a senior software projects course in Computer Science. Using a collaborative environment that embeds a social network, project management modules, and event capture system, we perform broad data and event capture and analysis to investigate metrics that are relevant to assessing individual performance aspects related to functioning on an Agile team for software development. Our results suggest that predictive data is available after each Sprint to ascertain individual performance attributes and their relationship to product outcomes.
Rose F. Gamble, Matthew L. Hale
FIE1
2013 Analysis of End-to-End SOA Security Protocols with Mobile Devices
abstract
Service Oriented Architecture (SOA) is an architectural style that provides agility to align technical solutions to a modular business Web Services (WS) that are well decoupled from their consumers. This agility is extended to the Cloud model. To achieve a high level of security and a degree of decoupling, SOA encourages the use of standardized transport schemes such as SOAP/HTTP(s) with WS family of standards specifications (commonly referred to as WS-* (WS-star)) to ease the interoperability complexity and security concerns in enterprise networks, which have medium/high bandwidth and reliable/wired networks. However, these protocol standards are ill suited for mobile devices due to their limited computational capabilities, low bandwidth, and intermittent connectivity. In this paper, we present an analysis of WS-* standards, classifying and discussing their inter-dependencies to provide a basis for determining the limitation of mobile device use in SOA and for establishing an architectural consideration baseline for selecting appropriate security mechanisms.
Norman Ahmed, Mark Linderman, Rose F. Gamble, Bharat K. Bhargava
MDM (2)3
2013 Information flow control for stream processing in clouds
abstract
In the near future, clouds will provide situational monitoring services using streaming data. Examples of such services include health monitoring, stock market monitoring, shopping cart monitoring, and emergency control and threat management. Offering such services require securely processing data streams generated by multiple, possibly competing and/or complementing, organizations. Processing of data streams also should not cause any overt or covert leakage of information across organizations. We propose an information flow control model adapted from the Chinese Wall policy that can be used to protect against sensitive data disclosure. We propose architectures that are suitable for securely and efficiently processing streaming information belonging to different organizations. We discuss how performance can be further improved by sharing the processing of multiple queries. We demonstrate the feasibility of our approach by implementing a prototype of our system and show the overhead incurred due to the information flow constraints.
Xing Xie 0002, Indrakshi Ray, Raman Adaikkalavan, Rose F. Gamble
SACMAT4
2013 Auditing Requirements for Implementing the Chinese Wall Model in the Service Cloud
abstract
The service cloud model allows for the composition of services into an application that can respond to tenant requests. The composition of services, which may originate with different vendors, results in a service chain that supports end-to-end round trip messaging. Thus, the service cloud model must support provisioning services for the request without incurring a conflict of interest (COI) in their message exchange among vendors. Service vendors must disclose their COI classes for storage and analysis by the cloud because as services are provisioned to an application, additional conflict classes may be added, preventing the service from future compositions to avoid COI. In this paper, we present a strategy to centrally store and monitor COI classes for services in a service chain using principles of the Chinese Wall Model. We introduce a Security Monitoring Database (SMDB) that audits and monitors the COI classes as they exist or are assigned to hosted services, including the tenant services making requests. We describe an algorithm to prevent COI before provisioning services and dynamically detect it during run time due to concurrent service invocations using the SMDB information.
Sarra Alqahtani, Rose F. Gamble, Indrakshi Ray
SERVICES2
2013 Building a Compliance Vocabulary to Embed Security Controls in Cloud SLAs
abstract
Mission critical information systems must be certified against a set of security controls to mitigate potential security incidents. Cloud service providers must in turn employ adequate security measures that conform to security controls expected by the organizational information systems they host. Since service implementation details are abstracted away by the cloud, organizations can only rely on service level agreements (SLAs) to assess the compliance of cloud security properties and processes. Various representation schema allow SLAs to embed service security terms, but are disconnected from documents regulating security controls. This paper demonstrates an extensible solution for building a compliance vocabulary that associates SLA terms with security controls. The terms allow services to express which security controls they comply with and enable at-a-glance comparison of security service offerings so organizations can distinguish among cloud service providers that best comply with security expectations. To exemplify the approach, we build a sample vocabulary of terms based on audit security controls from a standard set of governing documents and apply them to an SLA for an example cloud storage service. We assess the compatibility with existing SLAs and calculate the computational overhead associated with the use of our approach in service matchmaking.
Matthew L. Hale, Rose F. Gamble
SERVICES2
2013 A Design and Verification Framework for Service Composition in the Cloud
abstract
The service cloud model allows hosted services to be dynamically provisioned and composed as part of larger, more complex cloud applications. Compatibility of interaction and quality of service are important to provisioning similar services available in the cloud to a client request. Auditing individual services, the composition and its outcome, and the overall cloud resources, used for monetary assessment or to ensure critical operations, also provide properties for reasoning over service and composition capabilities. Security policies and potential violations pose a threat to the composition since sensitive data may be leaked if information flow control guarantees cannot be proven. Service engineering lacks design principles and an expression infrastructure for formal representation and reasoning within a service cloud model. Reasoning over service compositions requires a formal language that can express multiple service and cloud properties. In this paper, we use coordination language techniques to express services, their interaction capabilities and information sharing constraints, and the infrastructure of a service cloud model in which services can be accurately provisioned, composed and reasoned over to provide necessary guarantees. We discuss lessons learned from the process of formulating the service representation and cloud model infrastructure.
Matthew L. Hale, Michael Todd Gamble, Rose F. Gamble
SERVICES3
2012 A Tiered Strategy for Auditing in the Cloud
abstract
In this paper, we outline a tiered approach to auditing information in the cloud. The approach provides perspectives on auditable events that may include compositions of independently formed audit trails. Filtering and reasoning over the audit trails can manifest potential security vulnerabilities and performance attributes as desired by stakeholders.
Rose F. Gamble
IEEE CLOUD2
2012 Architecting Web Service Attack Detection Handlers
abstract
There is a wealth of research on web service attack types and different techniques to mitigate them. However, there is little discussion on reusable methods for implementing these known techniques. In this paper, we introduce two handler architectures that can be reused to implement a broad set of known attack countermeasures. While structurally similar, the architectures differ in the information they require for attack detection, in the needed changes to or restructuring of the message and its content, and in their invocation order among other handlers deployed on the application server and used by the web service. We present the handler architecture designs and how they address the specific web service attack types. We discuss the benefits of their attachment to the Web service. Also, we cover their implementation and deployment details on a JBoss application server and provide a case study to document the results of test runs.
Alex Andrekanic, Rose F. Gamble
ICWS2
2012 SecAgreement: Advancing Security Risk Calculations in Cloud Services
abstract
By choosing to use cloud services, organizations seek to reduce costs and maximize efficiency. For mission critical systems that must satisfy security constraints, this push to the cloud introduces risks associated with cloud service providers not implementing organizationally selected security controls or policies. As internal system details are abstracted away as part of the cloud architecture, the organization must rely on contractual obligations embedded in service level agreements (SLAs) to assess service offerings. Current SLAs focus on quality of service metrics and lack the semantics needed to express security constraints that could be used to measure risk. We create a framework, called SecAgreement (SecAg), that extends the current SLA negotiation standard, WS-Agreement, to allow security metrics to be expressed on service description terms and service level objectives. The framework enables cloud service providers to include security in their SLA offerings, increasing the likelihood that their services will be used. We define and exemplify a cloud service matchmaking algorithm to assess and rank SecAg enhanced WS-Agreements by their risk, allowing organizations to quantify risk, identify any policy compliance gaps that might exist, and as a result select the cloud services that best meet their security needs.
Matthew L. Hale, Rose F. Gamble
SERVICES2
2011 Predicting individual performance in student project teams
abstract
Due to the critical role of communication in project teams, capturing and analyzing developer design notes and conversations for use as performance predictors is becoming increasing important as software development processes become more asynchronous. Current prediction methods require human Subject Matter Experts (SME) to laboriously examine and rank user content along various categories such as participation and the information they express. SEREBRO is an integrated courseware tool that captures social and development artifacts automatically and provides real time rewards, in the form of badges and titles, indicating a user's progress towards predefined goals using a variety of automated assessment measures. The tool allows for instructor visualization, involvement, and feedback in the ongoing projects and provides avenues for the instructor to adapt or adjust project scope or individual role assignments based on past or current individual performance levels. This paper evaluates and compares the use of two automated SEREBRO measures with SME content-based analysis and work product grades as predictors of individual performance. Data is collected from undergraduate software engineering teams using SEREBRO, whose automated measures of content and contribution perform as well as SME ratings and grades to suggest individual performance can be predicted in real-time.
Matthew L. Hale, Noah Jorgenson, Rose F. Gamble
CSEE&T3
2011 SEREBRO: facilitating student project team collaboration
abstract
In this demonstration, we show SEREBRO, a lightweight courseware developed for student team collaboration in a software engineering class. SEREBRO couples an idea forum with software project management tools to maintain cohesive interaction between team discussion and resulting work products, such as tasking, documentation, and version control. SEREBRO has been used consecutively for two years of software engineering classes. Student input and experiments on student use in these classes has directed SERBRO to its current functionality.
Noah Jorgenson, Matthew L. Hale, Rose F. Gamble
ICSE3
2011 Self-adapting workflow reconfiguration
Robert Baird, Noah Jorgenson, Rose F. Gamble
J. Syst. Softw.3
2010 Measuring Creativity in Software Development
Courtney Nelson, Bradley J. Brummel, Frank Grove, Noah Jorgenson, Sandip Sen, Rose F. Gamble
ICCC6
2006 Elevating Interaction Requirements for Web Service Composition
Michelle Hepner, Michael Todd Gamble, Rose F. Gamble
SEKE3
2006 Interaction Partnering Criteria for COTS Components
Manasi Kelkar, Melanie Smith, Rose F. Gamble
SEKE3
2006 Patterns of conflict among software components
Michelle Hepner, Rose F. Gamble, Manasi Kelkar, Leigh A. Davis, Daniel Flagg
J. Syst. Softw.2
2005 Establishing Connectors as Integration Services
abstract
A "pure" service-oriented architecture (SOA) is an architectural style with a loose-coupling of services (components) that interact via message passing (connectors) through the standards based and WSDL defined service interfaces regardless of the interacting components’ heterogeneity.
Michelle Hepner, Rose F. Gamble
WICSA2
2004 A patterned approach for linking knowledge-based systems to external resources
abstract
Knowledge-based systems (KBSs) have been developed and used in industry and government as assistance systems, voting partner systems, and embedded applications. As web-based systems change the face of software implementations, these closed, internal KBSs need to be integrated into multicomponent applications that provide updated and extensible services. Therefore, KBSs must be adapted to an environment in which data and control are exchanged with external processes and resources; complementing other participating systems or using them to refine its own results. This integration can be a daunting task. If improperly done, it can result in an inefficient and unmanageable composite application. One approach to simplifying this task is the use of architectural patterns for integration. These patterns are assembled from functional entities that resolve component interoperability conflicts. In this paper, we describe an architectural pattern called the Knowledge Director pattern, which directs the integration of a closed KBS into a broader application environment.
Leigh A. Davis, Rose F. Gamble, S. Kimsen
IEEE Trans. Syst. Man Cybern. Part B2
2003 Defining Change Management Properties for Component Interoperability Assessment
Michael Todd Gamble, Rose F. Gamble, Leigh A. Davis
SEKE2
2002 The impact of component architectures on interoperability
Leigh A. Davis, Rose F. Gamble, Jamie Payton
J. Syst. Softw.2
2001 A notation for problematic architecture interactions
abstract
The progression of component-based software engineering (CBSE) is essential to the rapid, cost-effective development of complex software systems. Given the choice of well-tested components, CBSE affords reusability and increases reliability. However, applications developed according to this practice can often suffer from difficult maintenance and control, problems that stem from improper or inadequate integrate solutions. Avoiding such unfortunate results requires knowledge of what causes the interoperability problems in the first place. The time for this assessment is during application design. In this paper, we define problematic architecture interactions using a simple notation with extendable properties. Furthermore, we delineate a multi-phase process for pre-integration analysis that relies on this notation. Through this effort, potential problematic architecture interactions can be illuminated and used to form the initial requirements of an integration architecture.
Leigh A. Davis, Rose F. Gamble, Jamie Payton, Gerður Jónsdóttir, Dennis J. Underwood
ESEC / SIGSOFT FSE2
1999 Using KBS verification techniques to demonstrate the existence of rule anomalies in ADBs
A. V. Pai, Rose F. Gamble, Robert Plant
Inf. Softw. Technol.2
1999 Rule-based systems formalized within a software architectural style
Rose F. Gamble, Patricia Stiger, Robert Plant
Knowl. Based Syst.1
1997 Classifying and detecting anomalies in hybrid knowledge-based systems
Ranadeep Mukherjee, Rose F. Gamble, Jennifer A. Parkinson
Decis. Support Syst.2
1997 Using meta-knowledge within a multilevel framework for KBS development
abstract
This paper describes a multilevel development life cycle of representation refinement for knowledge-based systems that incorporates meta-knowledge at each level. The methodology uses formal techniques in the specification of the domain knowledge, the cognitive aspects and the representation. The methodology provides the knowledge engineer with a dynamic perspective of the system which can be used in conjunction with the static aspects found in the representation abstractions. To provide perspective, the paper details the refinement of one of the levels called the intermediate level, in which an implementation-independent representation is created by the use of a knowledge filter.
Robert Plant, Rose F. Gamble
Int. J. Hum. Comput. Stud.2
1996 A methodology to incorporateformal methods in hybrid KBS verification
Rose F. Gamble, D. M. Baughman
Int. J. Hum. Comput. Stud.1
1996 Eliminating Redundancy, Conflict, and Incompleteness from Knowledge-Based Systems
abstract
The reliability of knowledge-based systems (KBSs) has been the subject of a great deal of recent research. Much of this research focuses on the verification of KBSs, specifically to eliminate redundant rules, conflicting rules, and to ensure that the KBS is complete. Often, verification is approached by testing the structural properties of the KBS after the rules have been defined. In this paper we take a different approach and show how the process of formal program derivation from software engineering can be applied to KBSs. The use of these techniques eliminates the need for post-development verification because program derivation guarantees that the KBS will not contain redundant rules, conflicting rules, or be incomplete. As such, verification concerns are addressed during development.
Rose F. Gamble, Teresa M. Shaft
Int. J. Softw. Eng. Knowl. Eng.1
1995 Integrating a formal specification course with a software projects course via an editing tool
abstract
This paper reports on a two-course sequence for undergraduate students that provides them with an intensive course in formal specification methods and a traditional software design course. The specification course provides an appreciation for the use of rigorous specification methods within the software lifecycle. The manual nature of developing a formal specification provides the appropriate justification for the projects in the software design course in which the students create useful tools to aid the development of a formal specification. Within the project course, the students developed the first prototype of a graphical editor for building Z specifications. We discuss the building of the editing tool and its integration into the software engineering curriculum.
Rose F. Gamble
SIGCSE1
1993 Formal Derivation of Rule-Based Programs
abstract
It is shown that a combination of specification and program refinement may be applied to deriving efficient concurrent rule-based programs. Specification refinement is used to generate an initial rule-based program that is refined into a program which is highly concurrent and efficient. This program derivation strategy is divided into two major tasks. The first task relies on specification refinement. Techniques similar to those employed in the derivation of UNITY programs are used to produce a correct rule-based program having a static knowledge base. The second task involves program refinement and is specific to the development of concurrent rule-based programs. It relies heavily on the availability of a computational model, such as Swarm, that has the ability to dynamically restructure the knowledge base. The ways in which a Swarm program can be translated to OPS5 specifically, given some restrictions, while maintaining the correctness criteria are discussed.>
Gruia-Catalin Roman, Rose F. Gamble, William E. Ball
IEEE Trans. Software Eng.2
1992 Seeking Concurrency in Rule-Based Programming
abstract
This paper describes a formal approach for developing concurrent rule-based programs. Specification refinement is used to generate an initial version of the program. Program refinement is then applied to produce a highly concurrent and efficient version of the same program. Techniques for deriving concurrent programs through either specification or program refinement have been described in previous literature. The main contribution of this paper consists of extending the applicability of these techniques to a broad class of rule-based programs. To the best of our knowledge, this is the first time formal derivation is employed in the context of rule-based programming.
Gruia-Catalin Roman, Rose F. Gamble, William E. Ball
ICSE2
1991 Formal Verification of Pure Production System Programs
Rose F. Gamble, Gruia-Catalin Roman, William E. Ball
AAAI1