Bashar Nuseibeh

dblp:26/1319 · also Bashar Ahmad Nuseibeh · DBLP profile ↗
← Back
150ranked-venue papers
34as first author
23since 2021 · last 2026
0000-0002-3476-053XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 112 · 32 first-author · 12 since 2021Human-computer interaction and ubiquitous computing · 14 · 5 since 2021Security and privacy · 11 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 1 since 2021Computer networks · 3 · 1 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1Theory of computation · 1
YearPublicationVenuePosition
2026 Human-centric security for smart homes: A scoping review
abstract
Smart home technologies, like cameras, door locks, and speakers, are increasingly used in our everyday lives. However, their continuous data collection and internet connectivity pose various security risks. While research on smart home security has mainly focused on technological aspects, human experience and societal factors also play a crucial role. Various human and social factors, such as user experience with smart home devices, security design processes, and government regulations, are intertwined and influence each other, affecting smart home security. It is therefore important to understand and consider these interconnected factors in technology design to secure homes that contain increasingly connected devices. This scoping review provides an overview of current human-centered studies (N=102) on smart home security, which aims to help researchers and practitioners better navigate this field. We present a conceptual framework that outlines key challenges in ensuring smart home security with a synthesis of insights on contributing human factors. We then summarize general security design principles and map existing user-centred security approaches in smart homes, and highlight research directions for future investigation. Beyond mapping existing studies, the review reveals a growing emphasis on engaging multiple stakeholders, especially smart home users, in shaping human-centered security.
Wanling Cai, Liliana Pasquale, Kushal Ramkumar, John C. McCarthy 0002, Bashar Nuseibeh, Gavin Doherty
Comput. Secur.5
2025 Predicting Loneliness Using Machine Learning and Self-Logged Behavioural Data
abstract
Loneliness is a growing public health concern, particularly among older adults, and has been linked to adverse physical and mental health outcomes. This study presents a machine learning approach to predict levels of loneliness using behavioural and emotional data collected from 124 participants through a mobile phone application over a 71-day period. The dataset includes 27 features derived from self-logged information such as wellbeing scores, mood fluctuations, and time spent in various home locations. Feature selection was applied to identify the most discriminative indicators, with classification and regression models evaluated using both Support Vector Machine (SVM), and Random Forest (RF). We applied feature selection to identify the most discriminative indicators and evaluated both Support Vector Machine (SVM) and Random Forest (RF) models for classification and regression. The highest classification accuracy—69.19% on a 7-point loneliness scale—was achieved using a five-fold SVM with the top 13 features. In the regression task, the best performance was observed using 26 features, resulting in a minimum Mean Squared Error (MSE) of 0.6752. These findings indicate that a selected subset of behavioural and emotional features can offer a meaningful estimation of loneliness levels. This has potential to inform the design of real-time, personalised digital tools aimed at identifying and supporting individuals at risk of loneliness.
Mohamed Bennasar, Dmitri S. Katz, Avelie Stuart, Amel Bennaceur, Daniel Gooch, Arosha K. Bandara, Blaine A. Price, Bashar Nuseibeh
KES8
2025 Intelligent Agents for Requirements Engineering: Use, Feasibility and Evaluation
abstract
Large language models (LLMs) have enabled new tools in requirements engineering (RE), often in the form of intelligent agents or virtual assistants. These tools can transform how software engineers perform RE tasks and interact with stakeholders. However, existing research primarily focuses on showcasing the capabilities of these tools rather than their design and evaluation in RE-specific contexts. This limits our understanding of their practical value and hinders broader adoption. To address this gap, we propose a reference model to guide the design, use, and evaluation of intelligent RE agents. Our work introduces new RE use cases, along with evaluation metrics for intelligent RE agents. We present a study design to support systematic development and share early findings demonstrating the feasibility of our approach. The use cases show how agents can add value for RE practitioners, while our synthesized catalogue supports tool evaluation. Finally, our analysis of commercial agents reveals that these tools already support certain aspects of the envisioned RE use cases.
Jacek Dabrowski 0001, Wanling Cai, Amel Bennaceur, Bashar Nuseibeh, Faeq Alrimawi
RE4
2025 Prompt Me: Intelligent Software Agent for Requirements Engineering - A Vision Paper
Jacek Dabrowski 0001, Amel Bennaceur, Gopi Krishnan Rajbahadur, Bashar Nuseibeh, Faeq Alrimawi
REFSQ4
2025 Engineering Within Boundaries When Software Has None
abstract
I served as Editor-in-Chief of IEEETransactions on Software Engineeringfor four years between 2010 and 2013. Then and now I advocated for a broadening of software engineering to incorporate a range of multi-disciplinary inputs and to address human and social concerns. In this retrospective editorial, I reflect on the considerable progress that has been made in the intervening years and make the case for an even more radical reframing of the software engineering discipline. Such a reframing will require new trans-disciplinary methodologies for research and practice, and new representations of the lived experiences and values of software users. I suggest two conceptual shorthands for what I advocate: Living Labs 2.0 and Context 2.0. Dear reader, please forgive my indulgence.
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2025 Diagnosing Unknown Attacks in Smart Homes Using Abductive Reasoning
abstract
Security attacks are rising, as evidenced by the number of reported vulnerabilities. Among them, unknown attacks, including new variants of existing attacks, technical blind spots or previously undiscovered attacks, challenge enduring security. This is due to the limited number of techniques that diagnose these attacks and enable the selection of adequate security controls. In this paper, we propose an automated technique that detects and diagnoses unknown attacks by identifying the class of attack and the violated security requirements, enabling the selection of adequate security controls. Our technique combines anomaly detection to detect unknown attacks with abductive reasoning to diagnose them. We first model the behaviour of the smart home and its requirements as a logic program in Answer Set Programming (ASP). We then apply Z-Score thresholding to the anomaly scores of an Isolation Forest trained using unlabeled data to simulate unknown attack scenarios. Finally, we encode the network anomaly in the logic program and perform abduction by refutation to identify the class of attack and the security requirements that this anomaly may violate. We demonstrate our technique using a smart home scenario, where we detect and diagnose anomalies in network traffic.We evaluate the precision, recall and F1-score of the anomaly detector and the diagnosis technique against 18 attacks from the ground truth labels provided by two datasets, CICIoT2023 and IoT-23. Our experiments show that the anomaly detector effectively identifies anomalies when the network traces are strong indicators of an attack. When provided with sufficient contextual data, the diagnosis logic effectively identifies true anomalies, and reduces the number of false positives reported by anomaly detectors. Finally, we discuss how our technique can support the selection of adequate security controls.
Kushal Ramkumar, Wanling Cai, John C. McCarthy 0002, Gavin Doherty, Bashar Nuseibeh, Liliana Pasquale
IEEE Trans. Software Eng.5
2024 Meta-Modelling Kindness
abstract
Kindness is a psycho-social phenomenon that is also recognized as an important pro-social behaviour. The use of digital technology provides opportunities to promote kindness in various ways, such as in social media campaigns and online communities. In principle, software engineers are well positioned to develop automated systems that can facilitate software-mediated kindness. However, in practice, incorporating kindness concerns explicitly in the development and use of software systems is challenging: kindness is highly context dependent, affected by a range of factors such as intentions and opportunity.
Faeq Alrimawi, Bashar Nuseibeh
MODELS2
2024 Reflections on using the story completion method in designing tangible user interfaces
abstract
There are many design techniques to support the co-design of tangible technologies. However, few of these design methods allow the involvement of users at scale and across diverse geographic locations. While popular in psychology, the story completion method (SCM) has only recently started to be adopted within the HCI community. We explore whether SCM can generate meaningful design insights from large, diverse study populations for the design of Tangible User Interfaces (TUIs). Based on the results of two questionnaire studies using SCM, we conclude that the method can be used to generate meaningful design insights. Drawing on a systematic review of 870 TUI papers, we then contextualise the strengths and weaknesses of SCM against commonly used design methods, before reflecting on our experience of using the method across two distinct domains. We discuss the advantages of the method (particularly in terms of the scale and diversity of participation) and the challenges (particularly around constructing meaningful story stems, and developing the correct level of scaffolding to support creativity). We conclude that SCM is particularly suitable to be used in the early stages of the design process to understand the socio-cultural context of deployment.
Daniel Gooch, Arosha K. Bandara, Amel Bennaceur, Emilie Giles, Lydia Harkin, Dmitri S. Katz, Mark Levine, Vikram Mehta, Bashar Nuseibeh, Clifford Stevenson, Avelie Stuart, Catherine V. Talbot, Blaine A. Price
Int. J. Hum. Comput. Stud.9
2024 The IDEA of Us: An Identity-Aware Architecture for Autonomous Systems
abstract
Autonomous systems, such as drones and rescue robots, are increasingly used during emergencies. They deliver services and provide situational awareness that facilitate emergency management and response. To do so, they need to interact and cooperate with humans in their environment. Human behaviour is uncertain and complex, so it can be difficult to reason about it formally. In this article, we propose IDEA: an adaptive software architecture that enables cooperation between humans and autonomous systems, by leveraging the social identity approach. This approach establishes that group membership drives human behaviour. Identity and group membership are crucial during emergencies, as they influence cooperation among survivors. IDEA systems infer the social identity of surrounding humans, thereby establishing their group membership. By reasoning about groups, we limit the number of cooperation strategies the system needs to explore. IDEA systems select a strategy from the equilibrium analysis of game-theoretic models that represent interactions between group members and the IDEA system. We demonstrate our approach using a search-and-rescue scenario, in which an IDEA rescue robot optimises evacuation by collaborating with survivors. Using an empirically validated agent-based model, we show that the deployment of the IDEA system can reduce median evacuation time by 13.6%.
Carlos Gavidia-Calderon, Anastasia Kordoni, Amel Bennaceur, Mark Levine, Bashar Nuseibeh
ACM Trans. Softw. Eng. Methodol.5
2023 Accounting for socio-technical resilience in software engineering
abstract
Resilience engineering (RE) is most commonly applied at the organisational level, and has historically been associated with safety-critical industries such as nuclear, medical or aviation. This paper explores the application of RE frameworks within software engineering, and investigates resilient performance of the socio-technical system that supports the creation of software. We present a preliminary study based on a secondary analysis of data from previous ethnographic studies of commercial software practice. This analysis uses an RE framework devised for small team practice in safety critical settings. We present and discuss three salient episodes of software practice that illustrate the application of RE principles to software engineering, and suggest how this kind of analysis may benefit software engineering. We present challenges and opportunities based on our experience and propose future research directions.
Tamara Lopez, Helen Sharp, Michel Wermelinger, Melanie Langer, Mark Levine, Caroline Jay, Yijun Yu 0001, Bashar Nuseibeh
CHASE8
2023 Towards a Socio-Technical Understanding of Police-Citizen Interactions
Min Zhang 0027, Arosha K. Bandara, Richard Philpot, Avelie Stuart, Zoe Walkington, Camilla Elphick, Lara Frumkin, Graham Pike, Blaine A. Price, Mark Levine, Bashar Nuseibeh
INTERACT (3)11
2023 Feel It, Code It: Emotional Goal Modelling for Gender-Inclusive Design
Diane Hassett, Amel Bennaceur, Bashar Nuseibeh
REFSQ3
2023 A Card-based Ideation Toolkit to Generate Designs for Tangible Privacy Management Tools
abstract
Effective privacy protection in dynamic UbiComp environments requires users to be able to manage their privacy seamlessly across diverse contexts. To support this, designers need to go beyond GUI-based interactions and utilise tangible and embodied interactions. To help designers in such endeavours, we present the TTP toolkit: a card-based ideation kit to generate designs for tangible privacy management tools. The toolkit translates the Privacy Care framework for tangible-supported privacy management into a game intended to support designers in developing TUI privacy management tools. We demonstrate use of our toolkit through 10 online participatory workshops with 22 interaction designers. Our results demonstrate that the toolkit was effective in supporting the participants to creatively and collaboratively generate meaningful conceptual designs of tangible tools for privacy management.
Vikram Mehta, Daniel Gooch, Arosha K. Bandara, Blaine A. Price, Bashar Nuseibeh
TEI5
2023 Forensic readiness of industrial control systems under stealthy attacks
abstract
Cyberattacks against Industrial Control Systems (ICS) can have harmful physical impacts. Investigating such attacks can be difficult, as evidence could be lost to physical damage. This is especially true with stealthy attacks ; i.e., attacks that can evade detection. In this paper, we aim to engineer Forensic Readiness (FR) in safety-critical, geographically distributed ICS, by proactively collecting potential evidence of stealthy attacks. The collection of all data generated by an ICS at all times is infeasible due to the large volume of such data. Hence, our approach only triggers data collection when there is the possibility for a potential stealthy attack to cause damage. We determine the conditions for such an event by performing predictive, model-based, safety checks. Furthermore, we use the geographical layout of the ICS and the safety predictions to identify data that is at risk of being lost due to damage, i.e., relevant data. Finally, to reduce the control performance overhead resulting from real-time data collection, we select a subset of relevant data to collect by performing a trade-off between expected impact of the attack and the estimated cost of collection. We demonstrate these ideas using simulations of the widely-used Tennessee–Eastman Process (TEP) benchmark. We show that the proposed approach does not miss relevant data and results in a reduced control performance overhead compared to the case when all data generated by the ICS is collected. We also showcase the applicability of our approach in improving the efficiency of existing ICS forensic log analysis tools.
Mazen Azzam, Liliana Pasquale, Gregory M. Provan, Bashar Nuseibeh
Comput. Secur.4
2023 Topology-Aware Adaptive Inspection for Fraud in I4.0 Supply Chains
abstract
Supply chain fraud involving counterfeit or adulterated products presents threats to human health and safety. Quality inspection is a key fraud mitigation tool where inspection planning involves allocating inspection resources across geographically dispersed assets considering both the cost and value of the inspection. I4.0 environments pose further challenges as their heterogeneous and dynamic cyber-physical environment creates a large inspection resource allocation solution space, causing the corresponding analysis to be computationally complex. In this article, we contribute to supporting optimal inspection decisions of dynamic cyber-physical supply chains through the use of structural representations—topologiesof the supply chain, physical premises, and their production context. We present an approach for topology modeling of supply chains and illustrate its use within an adaptive inspection approach, showing that structural information can reduce malicious process discovery times by up to 90%.
Thomas Welsh, Faeq Alrimawi, Ali Farahani, Diane Hassett, Andrea Zisman, Bashar Nuseibeh
IEEE Trans. Ind. Informatics6
2023 Security Responses in Software Development
abstract
The pressure on software developers to produce secure software has never been greater. But what does security look like in environments that do not produce security-critical software? In answer to this question, this multi-sited ethnographic study characterizes security episodes and identifies five typical behaviors in software development. Using theory drawn from information security and motivation research in software engineering, this article characterizes key ways in which individual developers form security responses to meet the demands of particular circumstances, providing a framework managers and teams can use to recognize, understand, and alter security activity in their environments.
Tamara Lopez, Helen Sharp, Arosha K. Bandara, Thein Tun, Mark Levine, Bashar Nuseibeh
ACM Trans. Softw. Eng. Methodol.6
2023 Adaptive Observability for Forensic-Ready Microservice Systems
abstract
Microservice-based applications may include multiple instances of microservices running on containerised infrastructures. These infrastructures pose challenges to digital investigations of security incidents because digital evidence can be destroyed when containers are terminated. Observability techniques are used to facilitate the investigation of incidents in microservice systems. However, existing observability approaches do not address security incidents when there is a need to perform digital forensic investigations. Furthermore, approaches to proactively support digital forensic investigations are limited to security incidents that are known a priori. In this paper, we propose an adaptive observability approach based on game theory. The approach addresses the challenge of implementing forensic-ready microservice systems while considering uncertainties in security incidents. Our approach provides evidence collection capabilities for microservice systems and continually adapts to improve the forensic readiness of microservices. Specifically, the approach uses game theory to model and reason about the interactions between users and microservices, determining the optimal time and manner for observing microservices before the occurrence of security incidents. The performance of the approach has been assessed and compared with other observability approaches. Results of the evaluation indicate that adaptive observability outperforms other observability approaches, with improvements ranging from 3.1% up to 42.50%.
Davi Monteiro Barbosa, Yijun Yu 0001, Andrea Zisman, Bashar Nuseibeh
IEEE Trans. Serv. Comput.4
2022 Grounds for Suspicion: Physics-Based Early Warnings for Stealthy Attacks on Industrial Control Systems
abstract
Stealthy attackson Industrial Control Systems can cause significant damage while evading detection. In this article, instead of focusing on the detection of stealthy attacks, we aim to provide early warnings to operators, in order to avoid physical damage and preserve in advance data that may serve as an evidence during an investigation. We propose a framework to providegrounds for suspicion, i.e., preliminary indicators reflecting the likelihood of success of a stealthy attack. We propose two grounds for suspicion based on the behaviour of the physical process: (i)feasibilityof a stealthy attack, and (ii)proximityto unsafe operating regions. We propose a metric to measure grounds for suspicion in real-time and provide soundness principles to ensure that such a metric is consistent with the grounds for suspicion. We apply our framework to Linear Time-Invariant (LTI) systems and formulate the suspicion metric computation as a real-time reachability problem. We validate our framework on a case study involving the benchmark Tennessee-Eastman process. We show through numerical simulation that we can provide early warnings well before a potential stealthy attack can cause damage, while incurring minimal load on the network. Finally, we apply our framework on a use case to illustrate its usefulness in supporting early evidence collection.
Mazen Azzam, Liliana Pasquale, Gregory M. Provan, Bashar Nuseibeh
IEEE Trans. Dependable Secur. Comput.4
2022 The Case for Adaptive Security Interventions
abstract
Despite the availability of various methods and tools to facilitate secure coding, developers continue to write code that contains common vulnerabilities. It is important to understand why technological advances do not sufficiently facilitate developers in writing secure code. To widen our understanding of developers' behaviour, we considered the complexity of the security decision space of developers using theory from cognitive and social psychology. Our interdisciplinary study reported in this article (1) draws on the psychology literature to provide conceptual underpinnings for three categories of impediments to achieving security goals, (2) reports on an in-depth meta-analysis of existing software security literature that identified a catalogue of factors that influence developers' security decisions, and (3) characterises the landscape of existing security interventions that are available to the developer during coding and identifies gaps. Collectively, these show that different forms of impediments to achieving security goals arise from different contributing factors. Interventions will be more effective where they reflect psychological factors more sensitively and marry technical sophistication, psychological frameworks, and usability. Our analysis suggests “adaptive security interventions” as a solution that responds to the changing security needs of individual developers and a present a proof-of-concept tool to substantiate our suggestion.
Irum Rauf, Marian Petre, Thein Tun, Tamara Lopez, Paul Lunn, Dirk van der Linden, John N. Towse, Helen Sharp, Mark Levine, Awais Rashid, Bashar Nuseibeh
ACM Trans. Softw. Eng. Methodol.11
2022 Incidents are Meant for Learning, Not Repeating: Sharing Knowledge About Security Incidents in Cyber-Physical Systems
abstract
Cyber-physical systems (CPSs) are part of many critical infrastructures such as industrial automation and transportation systems. Thus, security incidents targeting CPSs can have disruptive consequences to assets and people. As incidents tend to re-occur, sharing knowledge about these incidents can help organizations be more prepared to prevent, mitigate or investigate future incidents. This paper proposes a novel approach to enable representation and sharing of knowledge about CPS incidents across different organizations. To support sharing, we represent incident knowledge (incident patterns) capturing incident characteristics that can manifest again, such as incident activities or vulnerabilities exploited by offenders. Incident patterns are a more abstract representation of specific incident instances and, thus, are general enough to be applicable to various systems - different from the one in which the incident originally occurred. They can also avoid disclosing potentially sensitive information about an organization's assets and resources. We provide an automated technique toextractan incident pattern from a specific incident instance. To understand how an incident pattern can manifest again in other cyber-physical systems, we also provide an automated technique toinstantiateincident patterns to specific systems. We demonstrate the feasibility of our approach in the application domain of smart buildings. We evaluate correctness, scalability, and performance using two substantive scenarios inspired by real-world systems and incidents.
Faeq Alrimawi, Liliana Pasquale, Deepak Mehta 0001, Nobukazu Yoshioka, Bashar Nuseibeh
IEEE Trans. Software Eng.5
2021 Towards Adaptive Inspection for Fraud in I4.0 Supply Chains
abstract
The effective functioning of society is increasingly reliant on supply chains which are susceptible to fraud, such as the distribution of adulterated products. Inspection is a key tool for mitigating fraud, however it has traditionally been constrained by physical characteristics of supply chains such as their size and geographical distribution. The increasingly cyber-physical nature of supply chains, their autonomy, and their data richness, extends their attack surfaces and thus increases opportunities for fraud. However, it also presents new opportunities for increased and dynamic inspection, which in turn requires more targeted and flexible inspection regimes. In this paper we explore opportunities to engineer adaptive inspection of cyber-physical supply chains to support efforts to reduce fraud. Through using structural representations of supply chains (topological models) we propose defining optimal inspection zones. Such zones circumscribe assets of interest to optimise observation while reducing the intrusiveness of inspection. Using a motivating example of adulterated pharmaceuticals and a proof-of-concept tool we illustrate adaptive inspection, and surface challenges to its realisation, such as value metrics, forensic readiness integration and managing contrasting local and global perspectives.
Thomas Welsh, Faeq Alrimawi, Ali Farahani, Diane Hassett, Andrea Zisman, Bashar Nuseibeh
ETFA6
2021 Up Close & Personal: Exploring User-preferred Image Schemas for Intuitive Privacy Awareness and Control
abstract
Effective end-user privacy management in everyday ubiquitous computing environments requires giving users complex, contextual information about potential privacy breaches and enabling management of these breaches in a timely, engaging and intuitive manner. In this paper, we propose using empirically grounded image schema-based metaphors to help design these interactions. Results from our exploratory user study (N=22) demonstrate end users’ preferences for changes in physical attributes and spatial properties of objects for privacy awareness. For privacy control, end users prefer to exert force and create spatial movement. The study also explores user preferences for wearable vs. ambient form-factors for managing privacy and concludes that a hybrid solution would work for more users across more contexts. We thus provide a combination of form factor preferences, and a focused set of image schemas for designers to use when designing metaphor-based tangible privacy management tools.
Vikram Mehta, Arosha K. Bandara, Blaine A. Price, Bashar Nuseibeh, Daniel Gooch
TEI4
2021 Privacy Care: A Tangible Interaction Framework for Privacy Management
abstract
The emergence of ubiquitous computing (UbiComp) environments has increased the risk of undesired access to individuals’ physical space or their information, anytime and anywhere, raising potentially serious privacy concerns. Individuals lack awareness and control of the vulnerabilities in everyday contexts and need support and care in regulating disclosures to their physical and digital selves. Existing GUI-based solutions, however, often feel physically interruptive, socially disruptive, time-consuming and cumbersome. To address such challenges, we investigate the user interaction experience and discuss the need for more tangible and embodied interactions for effective and seamless natural privacy management in everyday UbiComp settings. We propose the Privacy Care interaction framework, which is rooted in the literature of privacy management and tangible computing. Keeping users at the center,AwarenessandControlare established as the core parts of our framework. This is supported with three interrelated interaction tenets:Direct, Ready-to-Hand,andContextual. Direct refers to intuitiveness through metaphor usage. Ready-to-Hand supports granularity, non-intrusiveness, and ad hoc management, through periphery-to-center style attention transitions. Contextual supports customization through modularity and configurability. Together, they aim to provide experience of an embodied privacy care with varied interactions that are calming and yet actively empowering. The framework provides designers of such care with a basis to refer to, to generate effective tangible tools for privacy management in everyday settings. Through five semi-structured focus groups, we explore the privacy challenges faced by a sample set of 15 older adults (aged 60+) across their cyber-physical-social spaces. The results show conformity to our framework, demonstrating the relevance of the facets of the framework to the design of privacy management tools in everyday UbiComp contexts.
Vikram Mehta, Daniel Gooch, Arosha K. Bandara, Blaine A. Price, Bashar Nuseibeh
ACM Trans. Internet Techn.5
2020 Schrödinger's security: opening the box on app developers' security rationale
abstract
Research has established the wide variety of security failures in mobile apps, their consequences, and how app developers introduce or exacerbate them. What is not well known is why developers do so---what is the rationale underpinning the decisions they make which eventually strengthen or weaken app security? This is all the more complicated in modern app development's increasingly diverse demographic: growing numbers of independent, solo, or small team developers who do not have the organizational structures and support that larger software development houses enjoy.
Dirk van der Linden, Pauline Anthonysamy, Bashar Nuseibeh, Thein Than Tun, Marian Petre, Mark Levine, John N. Towse, Awais Rashid
ICSE3
2020 OASIS: Weakening User Obligations for Security-critical Systems
abstract
Security-critical systems typically place some requirements on the behaviour of their users, obliging them to follow certain instructions when using those systems. Security vulnerabilities can arise when users do not fully satisfy their obligations. In this paper, we propose an approach that improves system security by ensuring that attack scenarios are mitigated even when the users deviate from their expected behaviour. The approach uses structured transition systems to present and reason about user obligations. The aim is to identify potential vulnerabilities by weakening the assumptions on how the user will behave. We present an algorithm that combines iterative abstraction and controller synthesis to produce a new software specification that maintains the satisfaction of security requirements while weakening user obligations. We demonstrate the feasibility of our approach through two examples from the e-voting and e-commerce domains.
Thein Than Tun, Amel Bennaceur, Bashar Nuseibeh
RE3
2020 How are you feeling?: Using Tangibles to Log the Emotions of Older Adults
abstract
The global population is ageing, leading to shifts in healthcare needs. Home healthcare monitoring systems currently focus on physical health, but there is an increasing recognition that psychological wellbeing also needs support. This raises the question of how to design devices that older adults can interact with to log their feelings. We designed three tangible prototypes, based on existing paper-based scales of affect. We report findings from a lab study in which participants used the prototypes to log the emotion from standardised emotional vignettes. We found that the prototypes allowed participants to accurately record identified emotions in a reasonable time. Our participants expressed a perceived need to record emotions, either to share with family/carers or for self-reflection. We conclude that our work demonstrates the potential for in-home tangible devices for recording the emotions of older adults to support wellbeing.
Daniel Gooch, Vikram Mehta, Blaine A. Price, Ciaran McCormick, Arosha K. Bandara, Amel Bennaceur, Mohamed Bennasar, Avelie Stuart, Linda Clare, Mark Levine, Jessica Cohen, Bashar Nuseibeh
TEI12
2020 Designing privacy-aware internet of things applications
Charith Perera, Mahmoud Barhamgi, Arosha K. Bandara, Muhammad Ajmal Azad, Blaine A. Price, Bashar Nuseibeh
Inf. Sci.6
2019 Cautious Adaptation of Defiant Components
abstract
Systems-of-systems are formed by the composition of independently created software components. These components are designed to satisfy their individual requirements, rather than the global requirements of the systems-of-systems. We refer to components that cannot be adapted to meet both individual and global requirements as "defiant" components. In this paper, we propose a "cautious" adaptation approach which supports changing the behaviour of such defiant components under exceptional conditions to satisfy global requirements, while continuing to guarantee the satisfaction of the components' individual requirements. The approach represents both normal and exceptional conditions as scenarios; models the behaviour of exceptional conditions as wrappers implemented using an aspect-oriented technique; and deals with both single and multiple instances of defiant components with different precedence order at runtime. We evaluated an implementation of the approach using drones and boats for an organ delivery application conceived by our industrial partners, in which we assess how the proposed approach help achieve the system-of-systems' global requirements while accommodating increased complexity of hybrid aspects such as multiplicity, precedence ordering, openness and heterogeneity.
Paulo Henrique M. Maia, Matheus Lima Chagas, Yijun Yu 0001, Andrea Zisman, Bashar Nuseibeh
ASE6
2019 Knowledge-Based Architecture for Recognising Activities of Older People
abstract
The world is facing an ageing population phenomenon, coupled with health and social problems, which affect older people’s ability to live independently. This situation challenges the viability of health and social services. Smart home technology can play a significant role in easing the pressure on caregivers, as well as reduce the financial costs of health and social services. Activity of Daily Living (ADL) recognition is an essential step to translate sensor data into activities at high semantic levels. Supervised Machine Learning (ML) algorithms are the most commonly used techniques for this application. However, a common problem is a lack of availability of enough annotated data to train these algorithms. Collecting annotated data is expensive, time consuming, and may violate people’s privacy. Intra- and inter-personal variation in performing complex activities is another challenge for an ML-based activity recognition approach. In this paper, a multi-layered knowledge-based architecture for recognising ADL in real-time is proposed. At the first stage, sensor data is pre-processed; events that describe changes in the environment are detected at the second stage, in which the sequence of events is used to recognise more semantically complex activities at the third stage. A new ADL ontology is proposed to model the knowledge related to the sensor platform and the targeted activities as the previously proposed ontologies were either designed to deal with specific sensor data, or they ignored the context environment information which is important in recognising complex activities.
Mohamed Bennasar, Blaine A. Price, Avelie Stuart, Daniel Gooch, Ciaran McCormick, Vikram Mehta, Linda Clare, Amel Bennaceur, Jessica Cohen, Arosha K. Bandara, Mark Levine, Bashar Nuseibeh
KES12
2019 Requirements We Live By
abstract
Enlightened requirements engineering (RE) researchers and practitioners generally accept that RE is as much about understanding the world as it is about understanding the software and systems that will be built to inhabit that world. As a result, the RE field has fostered a multi-disciplinary following of researchers and practitioners who are prepared to engage deeply in application domains, to apply a range of technical and socio-technical skills to understand those domains, and to accept that the outcome of an effective RE process may not deliver a software system at all. The RE community has also developed, deployed, and evaluated a wide range of contributions that reflect such enlightenment: conceptual models that reflect the relationships between the world and the machine, domain models and scenarios that reflect understandings of problem domains, and enterprise models that reflect the organisations and processes that build and deploy systems. All these in addition to the models that capture the all-important behaviour of systems and software. It seems to me however that the RE discipline is at a crossroads. The mechanics of the discipline appear to be established - much of the published research is now empirical - or technical, but only in so far as it responds to technological advances elsewhere, such as mobile and ubiquitous technologies represented by the Internet of Things, richer application domains such as Industrie 4.0 and Smart Cities, or more advanced computational techniques that are maturing, such AI, machine learning, and blockchains. As a community, we reassure ourselves that our discipline is safe and thriving, after all RE is a “forever problem”: all systems we wish to build will have requirements, now and forever. But this is to be complacent. RE has no protected status to study and deploy requirements. The formal models we elicit, design, and build are increasingly deployable by other disciplines, as are the values that we seek our modern, AI-driven systems to embody. A new and potentially radical re-framing of our discipline may be needed, and I will speculate what this may look like. It may require letting go of what we have considered to be the boundaries of our discipline, while embracing new but fluid boundaries. I have advocated and explored “software without boundaries” as one such framing that challenges the separation of `world and the machine', not because I don't accept the separation of the `what' and the `how', the `indicative' and the `optative', or the `problem' and the `solution', but because the world we live in no longer accepts these separations. Society, more often than not, does not think of systems, of technology, or indeed of software; it thinks of ways of working, ways of interacting, ways of living. Requirements, such as they are, are `requirements we live by' not requirements of systems in the world. At an extreme, if one believes the AI hype, `the world and the machine' will increasingly be replaced by the `world in the machine'. Where does the RE community stand on this, and what can this community do to contribute to the framing and solving of this new reality? My own work in recent years has evolved to reflect the above. I still revisit, with some pride, the `RE Roadmap' that Steve Easterbrook and I published in 2000 - many of the fundamental RE principles we presented still hold today. But I cringe at how we missed the changing nature of the world in which we operate: a world populated by autonomous and adaptive systems, populated by big data and associated analytics, and populated by stakeholders whose multiple perspectives reflect a multitude of ethical and social values, not all of which are wholesome, and many of which are actively subversive or malicious. My own research on security and privacy requirements only scratches the surface of this evolving reality. I invite the RE community to reflect on how it frames its own research in this context.
Bashar Nuseibeh
RE1
2019 Text Filtering and Ranking for Security Bug Report Prediction
abstract
Security bug reports can describe security critical vulnerabilities in software products. Bug tracking systems may contain thousands of bug reports, where relatively few of them are security related. Therefore finding unlabelled security bugs among them can be challenging. To help security engineers identify these reports quickly and accurately, text-based prediction models have been proposed. These can often mislabel security bug reports due to a number of reasons such as class imbalance, where the ratio of non-security to security bug reports is very high. More critically, we have observed that the presence of security related keywords in both security and non-security bug reports can lead to the mislabelling of security bug reports. This paper proposes FARSEC, a framework for filtering and ranking bug reports for reducing the presence of security related keywords. Before building prediction models, our framework identifies and removes non-security bug reports with security related keywords. We demonstrate that FARSEC improves the performance of text-based prediction models for security bug reports in 90 percent of cases. Specifically, we evaluate it with 45,940 bug reports from Chromium and four Apache projects. With our framework, we mitigate the class imbalance issue and reduce the number of mislabelled security bug reports by 38 percent.
Fayola Peters, Thein Than Tun, Yijun Yu 0001, Bashar Nuseibeh
IEEE Trans. Software Eng.4
2018 Engineering Software for Life in Cyber-Physical-Social Spaces
Bashar Nuseibeh
ENASE1
2018 Editorial: The First
abstract
No abstract available.
Bashar Nuseibeh
ACM Trans. Auton. Adapt. Syst.1
2018 Feature-Driven Mediator Synthesis: Supporting Collaborative Security in the Internet of Things
abstract
As the number, complexity, and heterogeneity of connected devices in the Internet of Things (IoT) increase, so does our need to secure these devices, the environment in which they operate, and the assets they manage or control. Collaborative security exploits the capabilities of these connected devices and opportunistically composes them to protect assets from potential harm. By dynamically composing these capabilities, collaborative security implements the security controls that satisfy both security and non-security requirements. However, this dynamic composition is often hampered by the heterogeneity of the devices available in the environment and the diversity of their behaviours. In this article, we present a systematic, tool-supported approach for collaborative security where the analysis of requirements drives the opportunistic composition of capabilities to realise the appropriate security control in the operating environment. This opportunistic composition is supported through a combination of feature modelling and mediator synthesis. We use features and transition systems to represent and reason about capabilities and requirements. We formulate the selection of the optimal set of features to implement adequate security control as a multi-objective constrained optimisation problem and use constraint programming to solve it efficiently. The selected features are then used to scope the behaviours of the capabilities and thereby restrict the state space for synthesising the appropriate mediator. The synthesised mediator coordinates the behaviours of the capabilities to satisfy the behaviour specified by the security control. Our approach ensures that the implemented security controls are the optimal ones, given the capabilities available in the operating environment. We demonstrate the validity of our approach by implementing a feature-driven mediation for collaborative security tool and applying it to a collaborative robots case study.
Amel Bennaceur, Thein Than Tun, Arosha K. Bandara, Yijun Yu 0001, Bashar Nuseibeh
ACM Trans. Cyber Phys. Syst.5
2018 On the Interplay Between Cyber and Physical Spaces for Adaptive Security
abstract
Ubiquitous computing is resulting in a proliferation of cyber-physical systems that host or manage valuable physical and digital assets. These assets can be harmed by malicious agents through both cyber-enabled or physically-enabled attacks, particularly ones that exploit the often ignored interplay between the cyber and physical world. The explicit representation of spatial topology is key to supporting adaptive security policies. In this paper we explore the use of Bigraphical Reactive Systems to model the topology of cyber and physical spaces and their dynamics. We utilise such models to perform speculative threat analysis through model checking to reason about the consequences of the evolution of topological configurations on the satisfaction of security requirements. We further propose an automatic planning technique to identify an adaptation strategy enacting security policies at runtime to prevent, circumvent, or mitigate possible security requirements violations. We evaluate our approach using a case study concerned with countering insider threats in a building automation system.
Christos Tsigkanos, Liliana Pasquale, Carlo Ghezzi, Bashar Nuseibeh
IEEE Trans. Dependable Secur. Comput.4
2018 CrowdService: Optimizing Mobile Crowdsourcing and Service Composition
abstract
Some user needs can only be met by leveraging the capabilities of others to undertake particular tasks that require intelligence and labor. Crowdsourcing such capabilities is one way to achieve this. But providing a service that leverages crowd intelligence and labor is a challenge, since various factors need to be considered to enable reliable service provisioning. For example, the selection of an optimal set of workers from those who bid to perform a task needs to be made based on their reliability, expected reward, and distance to the target locations. Moreover, for an application involving multiple services, the overall cost and time constraints must be optimally allocated to each involved service. In this article, we develop a framework, named C rowd S ervice , that supplies crowd intelligence and labor as publicly accessible crowd services via mobile crowdsourcing. The article extends our earlier work by providing an approach for constraints synthesis and worker selection. It employs a genetic algorithm to dynamically synthesize and update near-optimal cost and time constraints for each crowd service involved in a composite service and selects a near-optimal set of workers for each crowd service to be executed. We implement the proposed framework on Android platforms and evaluate its effectiveness, scalability, and usability in both experimental and user studies.
Xin Peng 0001, Jingxiao Gu, Tian Huat Tan, Jun Sun 0001, Yijun Yu 0001, Bashar Nuseibeh, Wenyun Zhao
ACM Trans. Internet Techn.6
2017 Enabling End-Users to Protect their Privacy
abstract
In this paper we present our ongoing work to build an approach to empower users of IoT-based cyber physical systems to protect their privacy by themselves. Our approach allows users to identify the privacy risks involved in sharing private data with a data consumer, assess the value of their private data based on identified risks and take a pragmatic data sharing decision balancing the risks with the benefits generated by the sharing. Our approach features a knowledgebase, called the Privacy Oracle, that exploits the power of the Semantic Web to determine how raw metadata can be combined by data consumers to infer privacy-sensitive information as well as the privacy risks associated with the disclosure of inferred information.
Mahmoud Barhamgi, Mu Yang, Chia-Mu Yu, Yijun Yu 0001, Arosha K. Bandara, Djamal Benslimane, Bashar Nuseibeh
AsiaCCS7
2017 O2O service composition with social collaboration
abstract
In Online-to-Offline (O2O) commerce, customer services may need to be composed from online and offline services. Such composition is challenging, as it requires effective selection of appropriate services that, in turn, support optimal combination of both online and offline services. In this paper, we address this challenge by proposing an approach to O2O service composition which combines offline route planning and social collaboration to optimize service selection. We frame general O2O service composition problems using timed automata and propose an optimization procedure that incorporates: (1) a Markov Chain Monte Carlo (MCMC) algorithm to stochastically select a concrete composite service, and (2) a model checking approach to searching for an optimal collaboration plan with the lowest cost given certain time constraint. Our procedure has been evaluated using the simulation of a rich scenario on effectiveness and scalability.
Wenyi Qian, Xin Peng 0001, Jun Sun 0001, Yijun Yu 0001, Bashar Nuseibeh, Wenyun Zhao
ASE5
2017 Learning to share: engineering adaptive decision-support for online social networks
abstract
Some online social networks (OSNs) allow users to define friendship-groups as reusable shortcuts for sharing information with multiple contacts. Posting exclusively to a friendship-group gives some privacy control, while supporting communication with (and within) this group. However, recipients of such posts may want to reuse content for their own social advantage, and can bypass existing controls by copy-pasting into a new post; this cross-posting poses privacy risks. This paper presents a learning to share approach that enables the incorporation of more nuanced privacy controls into OSNs. Specifically, we propose a reusable, adaptive software architecture that uses rigorous runtime analysis to help OSN users to make informed decisions about suitable audiences for their posts. This is achieved by supporting dynamic formation of recipient-groups that benefit social interactions while reducing privacy risks. We exemplify the use of our approach in the context of Facebook.
Yasmin Rafiq, Luke Dickens, Alessandra Russo, Arosha K. Bandara, Mu Yang, Avelie Stuart, Mark Levine, Gül Çalikli, Blaine A. Price, Bashar Nuseibeh
ASE10
2017 Are you ready? Towards the engineering of forensic-ready systems
abstract
As security incidents continue to impact organisations, there is a growing demand for systems to be `forensic-ready' - to maximise the potential use of evidence whilst minimising the costs of an investigation. Researchers have supported organisational forensic readiness efforts by proposing the use of policies and processes, aligning systems with forensics objectives and training employees. However, recent work has also proposed an alternative strategy for implementing forensic readiness called forensic-by-design. This is an approach that involves integrating requirements for forensics into relevant phases of the systems development lifecycle with the aim of engineering forensic-ready systems. While this alternative forensic readiness strategy has been discussed in the literature, no previous research has examined the extent to which organisations actually use this approach for implementing forensic readiness. Hence, we investigate the extent to which organisations consider requirements for forensics during systems development. We first assessed existing research to identify the various perspectives of implementing forensic readiness, and then undertook an online survey to investigate the consideration of requirements for forensics during systems development lifecycles. Our findings provide an initial assessment of the extent to which requirements for forensics are considered within organisations. We then use our findings, coupled with the literature, to identify a number of research challenges regarding the engineering of forensic-ready systems.
George Grispos, Jesús García-Galán, Liliana Pasquale, Bashar Nuseibeh
RCIS4
2017 Adaptive information security and privacy
abstract
Although security and privacy by design underpin effective engineering of software intensive systems, the dynamic reality of modern information systems means that such systems are the subject of changes of many different forms that can affect their operational environment, their behaviour, and the behaviour of their users, both legitimate and malicious. Systems must therefore be adaptive by design, in order to adapt effectively at runtime. In particular, these systems must be able to adapt their security and privacy controls, both proactively or in response to a variety of changes in their environment, in the threats they face, and in the assets they are required to protect. This talks presents both empirical and engineering challenges to achieving adaptive security and privacy in information systems. Acknowledging that information systems are increasingly both socio-technical and cyber-physical, the talk explores the impact of cyber-physical-social boundaries and their effective management when engineering secure, privacy-aware, and forensics-ready systems.
Bashar Nuseibeh
RCIS1
2017 Using Argumentation to Explain Ambiguity in Requirements Elicitation Interviews
abstract
The requirements elicitation process often starts with an interview between a customer and a requirements analyst. During these interviews, ambiguities in the dialogic discourse may reveal the presence of tacit knowledge that needs to be made explicit. It is therefore important to understand the nature of ambiguities in interviews and to provide analysts with cognitive tools to identify and alleviate ambiguities. Ambiguities perceived by analysts are sometimes triggered by specific categories of terms used by the customer such as pronouns, quantifiers, and vague or under-specified terms. However, many of the ambiguities that arise in practice cannot be rooted in single terms. Rather, entire fragments of speech and their relation to the mental state of the analyst need to be considered.In this paper, we show that particular types of ambiguities can be characterised by means of argumentation theory. Argumentation is the study of how conclusions can be reached through logical reasoning. In an argumentation theory, statements are represented as arguments, and conflict relations among statements are represented as attacks. Based on a set of ambiguous fragments extracted from interviews, we define a model of the mental state of the analyst during an interview and translate it into an argumentation theory. Then, we show that many of the ambiguities can be characterized in terms of 'attacks' on arguments. The main novelty of this work is in addressing the problem of explaining fragment-level ambiguities in requirements elicitation interviews through the formal modeling of the analyst's mental model using argumentation theory. Our contribution provides a data-grounded, theoretical basis to have a more complete understanding of the ambiguity phenomenon, and lays the foundations to design intelligent computer-based agents that are able to automatically identify ambiguities.
Yehia Elrakaiby, Alessio Ferrari 0001, Paola Spoletini, Stefania Gnesi, Bashar Nuseibeh
RE5
2017 On evidence preservation requirements for forensic-ready systems
abstract
Forensic readiness denotes the capability of a system to support digital forensic investigations of potential, known incidents by preserving in advance data that could serve as evidence explaining how an incident occurred. Given the increasing rate at which (potentially criminal) incidents occur, designing so‰ware systems that are forensic-ready can facilitate and reduce the costs of digital forensic investigations. However, to date, little or no attention has been given to how forensic-ready so‰ftware systems can be designed systematically. In this paper we propose to explicitly represent evidence preservation requirements prescribing preservation of the minimal amount of data that would be relevant to a future digital investigation. We formalise evidence preservation requirements and propose an approach for synthesising specifications for systems to meet these requirements. We present our prototype implementation—based on a satisfiability solver and a logic-based learner—which we use to evaluate our approach, applying it to two digital forensic corpora. Our evaluation suggests that our approach preserves relevant data that could support hypotheses of potential incidents. Moreover, it enables significant reduction in the volume of data that would need to be examined during an investigation.
Dalal Alrajeh, Liliana Pasquale, Bashar Nuseibeh
ESEC/SIGSOFT FSE3
2016 CrowdService: serving the individuals through mobile crowdsourcing and service composition
abstract
Some user needs in real life can only be accomplished by leveraging the intelligence and labor of other people via crowdsourcing tasks. For example, one may want to confirm the validity of the description of a secondhand laptop by asking someone else to inspect the laptop on site. To integrate these crowdsourcing tasks into user applications, it is required that crowd intelligence and labor be provided as easily accessible services (e.g., Web services), which can be called crowd services. In this paper, we develop a framework named CROWDSERVICE which supplies crowd intelligence and labor as publicly accessible crowd services via mobile crowdsourcing. We implement the proposed framework on the Android platform and evaluate the usability of the framework with a user study.
Xin Peng 0001, Jingxiao Gu, Tian Huat Tan, Jun Sun 0001, Yijun Yu 0001, Bashar Nuseibeh, Wenyun Zhao
ASE6
2016 Examining active error in software development
abstract
Software rarely works as intended while it is being written. Things go wrong in the midst of everyday practice, and developers are commonly understood to form theories and strategies for dealing with them. Errors in this sense are not bugs left behind in software, they are actively encountered and experienced. This paper reports findings of an ethnographically-informed study undertaken to examine error encountered at the desk. Films depicting paired open-source development practice over the course of a month were analyzed to identify and delineate instances of active error. Instances were interpreted within a framework of error handling drawn from psychology research. Analyses of representative instances are given and discussed in relation to software engineering research that examines practice at the desk. Findings demonstrate that the significance of active error in software development is personal, shaped by passing time, the emergence of preferred practices and environmental changes.
Tamara Lopez, Marian Petre, Bashar Nuseibeh
VL/HCC3
2016 Adaptive evidence collection in the cloud using attack scenarios
Liliana Pasquale, Sorren Hanvey, Mark Mcgloin, Bashar Nuseibeh
Comput. Secur.4
2016 Automating trade-off analysis of security requirements
Liliana Pasquale, Paola Spoletini, Mazeiar Salehie, Luca Cavallaro, Bashar Nuseibeh
Requir. Eng.5
2015 Ariadne: Topology Aware Adaptive Security for Cyber-Physical Systems
abstract
This paper presents Ariadne, a tool for engineering topology aware adaptive security for cyber-physical systems. It allows security software engineers to model security requirements together with the topology of the operational environment. This model is then used at runtime to perform speculative threat analysis to reason about the consequences that topological changes arising from the movement of agents and assets can have on the satisfaction of security requirements. Our tool also identifies an adaptation strategy that applies security controls when necessary to prevent potential security requirements violations.
Christos Tsigkanos, Liliana Pasquale, Carlo Ghezzi, Bashar Nuseibeh
ICSE (2)4
2015 Automated analysis of security requirements through risk-based argumentation
Yijun Yu 0001, Virginia N. L. Franqueira, Thein Than Tun, Roel J. Wieringa, Bashar Nuseibeh
J. Syst. Softw.5
2014 Traceability for Adaptive Information Security in the Cloud
abstract
One of the key challenges in cloud computing is the security of the consumer data stored and processed by cloud machines. When the usage context of a cloud application changes, or when the context is unknown, there is a risk that security policies are violated. To minimize this risk, cloud applications need to be engineered to adapt their security policies to maintain satisfaction of security requirements despite changes in their usage context. We call such adaptation capability Adaptive Information Security. The paper argues that one of the prerequisites to adaptive information security is the use of traceability as a means to understanding the relationship between security requirements and security policies. Using an example, we motivate the need for improving traceability in the development of cloud applications.
Armstrong Nhlabatsi, Thein Than Tun, Niamul Khan, Yijun Yu 0001, Arosha K. Bandara, Khaled M. Khan, Bashar Nuseibeh
IEEE CLOUD7
2014 Self-adaptation through incremental generative model transformations at runtime
abstract
A self-adaptive system uses runtime models to adapt its architecture to the changing requirements and contexts. However, there is no one-to-one mapping between the requirements in the problem space and the architectural elements in the solution space. Instead, one refined requirement may crosscut multiple architectural elements, and its realization involves complex behavioral or structural interactions manifested as architectural design decisions. In this paper we propose to combine two kinds of self-adaptations: requirements-driven self-adaptation, which captures requirements as goal models to reason about the best plan within the problem space, and architecture-based self-adaptation, which captures architectural design decisions as decision trees to search for the best design for the desired requirements within the contextualized solution space. Following these adaptations, component-based architecture models are reconfigured using incremental and generative model transformations. Compared with requirements-driven or architecture-based approaches, the case study using an online shopping benchmark shows promise that our approach can further improve the effectiveness of adaptation (e.g. system throughput in this case study) and offer more adaptation flexibility.
Bihuan Chen 0001, Xin Peng 0001, Yijun Yu 0001, Bashar Nuseibeh, Wenyun Zhao
ICSE4
2014 Distilling privacy requirements for mobile applications
abstract
As mobile computing applications have become commonplace, it is increasingly important for them to address end-users’ privacy requirements. Privacy requirements depend on a number of contextual socio-cultural factors to which mobility adds another level of contextual variation. However, traditional requirements elicitation methods do not sufficiently account for contextual factors and therefore cannot be used effectively to represent and analyse the privacy requirements of mobile end users. On the other hand, methods that do investigate contextual factors tend to produce data that does not lend itself to the process of requirements extraction. To address this problem we have developed a Privacy Requirements Distillation approach that employs a problem analysis framework to extract and refine privacy requirements for mobile applications from raw data gathered through empirical studies involving end users. Our approach introduces privacy facets that capture patterns of privacy concerns which are matched against the raw data. We demonstrate and evaluate our approach using qualitative data from an empirical study of a mobile social networking application.
Keerthi Thomas, Arosha K. Bandara, Blaine A. Price, Bashar Nuseibeh
ICSE4
2014 Engineering topology aware adaptive security: Preventing requirements violations at runtime
abstract
Adaptive security systems aim to protect critical assets in the face of changes in their operational environment. We have argued that incorporating an explicit representation of the environment's topology enables reasoning on the location of assets being protected and the proximity of potentially harmful agents. This paper proposes to engineer topology aware adaptive security systems by identifying violations of security requirements that may be caused by topological changes, and selecting a set of security controls that prevent such violations. Our approach focuses on physical topologies; it maintains at runtime a live representation of the topology which is updated when assets or agents move, or when the structure of the physical space is altered. When the topology changes, we look ahead at a subset of the future system states. These states are reachable when the agents move within the physical space. If security requirements can be violated in future system states, a configuration of security controls is proactively applied to prevent the system from reaching those states. Thus, the system continuously adapts to topological stimuli, while maintaining requirements satisfaction. Security requirements are formally expressed using a propositional temporal logic, encoding spatial properties in Computation Tree Logic (CTL). The Ambient Calculus is used to represent the topology of the operational environment - including location of assets and agents - as well as to identify future system states that are reachable from the current one. The approach is demonstrated and evaluated using a substantive example concerned with physical access control.
Christos Tsigkanos, Liliana Pasquale, Claudio Menghi, Carlo Ghezzi, Bashar Nuseibeh
RE5
2014 Adaptive Sharing for Online Social Networks: A Trade-off Between Privacy Risk and Social Benefit
abstract
Online social networks such as Facebook allow users to control which friend sees what information, but it can be a laborious process for users to specify every receiver for each piece of information they share. Therefore, users usually group their friends into social circles, and select the most appropriate social circle to share particular information with. However, social circles are not formed for setting privacy policies, and even the most appropriate social circle still cannot adapt to the changes of users' privacy requirements influenced by the changes in context. This problem drives the need for better privacy control which can adaptively filter the members in a selected social circle to satisfy users' requirements while maintaining users' social needs. To enable such adaptive sharing, this paper proposes a utility-based trade-off framework that models users' concerns (i.e. Potential privacy risks) and incentives of sharing (i.e. Potential social benefits), and quantifies users' requirements as a trade-off between these two types of utilities. By balancing these two metrics, our framework suggests a subset of a selected circle that aims to maximise users' overall utility of sharing. Numerical simulation results compare the outcome of three sharing strategies in randomly changing contexts.
Mu Yang, Yijun Yu 0001, Arosha K. Bandara, Bashar Nuseibeh
TrustCom4
2014 Signing Off: The State of the Journal
abstract
I T has been a pleasure and a
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2013 Engineering adaptive privacy: on the role of privacy awareness requirements
abstract
Applications that continuously gather and disclose personal information about users are increasingly common. While disclosing this information may be essential for these applications to function, it may also raise privacy concerns. Partly, this is due to frequently changing context that introduces new privacy threats, and makes it difficult to continuously satisfy privacy requirements. To address this problem, applications may need to adapt in order to manage changing privacy concerns. Thus, we propose a framework that exploits the notion of privacy awareness requirements to identify runtime privacy properties to satisfy. These properties are used to support disclosure decision making by applications. Our evaluations suggest that applications that fail to satisfy privacy awareness requirements cannot regulate users' information disclosure. We also observe that the satisfaction of privacy awareness requirements is useful to users aiming to minimise exposure to privacy threats, and to users aiming to maximise functional benefits amidst increasing threat severity.
Inah Omoronyia, Luca Cavallaro, Mazeiar Salehie, Liliana Pasquale, Bashar Nuseibeh
ICSE5
2013 Requirements-driven adaptive digital forensics
abstract
We propose the use of forensic requirements to drive the automation of a digital forensics process. We augment traditional reactive digital forensics processes with proactive evidence collection and analysis activities, and provide immediate investigative suggestions before an investigation starts. These activities adapt depending on suspicious events, which in turn might require the collection and analysis of additional evidence. The reactive activities of a traditional digital forensics process are also adapted depending on the investigation findings.
Liliana Pasquale, Yijun Yu 0001, Mazeiar Salehie, Luca Cavallaro, Thein Than Tun, Bashar Nuseibeh
RE6
2013 Specifying software features for composition: A tool-supported approach
Thein Than Tun, Robin C. Laney, Yijun Yu 0001, Bashar Nuseibeh
Comput. Networks4
2013 Resolving vulnerability identification errors using security requirements on business process models
abstract
Purpose In any information security risk assessment, vulnerabilities are usually identified by information‐gathering techniques. However, vulnerability identification errors – wrongly identified or unidentified vulnerabilities – can occur as uncertain data are used. Furthermore, businesses' security needs are not considered sufficiently. Hence, security functions may not protect business assets sufficiently and cost‐effectively. This paper aims to resolve vulnerability errors by analysing the security requirements of information assets in business process models. Design/methodology/approach Business process models have been selected for use, because there is a close relationship between business process objectives and risks. Security functions are evaluated in terms of the information flow of business processes regarding their security requirements. The claim that vulnerability errors can be resolved was validated by comparing the results of a current risk assessment approach with the proposed approach. The comparison is conducted both at three entities of an insurance company, as well as through a controlled experiment within a survey among security professionals. Findings Vulnerability identification errors can be resolved by explicitly evaluating security requirements in the course of business; this is not considered in current assessment methods. Originality/value It is shown that vulnerability identification errors occur in practice. With the explicit evaluation of security requirements, identification errors can be resolved. Risk assessment methods should consider the explicit evaluation of security requirements.
Stefan Taubenberger, Jan Jürjens, Yijun Yu 0001, Bashar Nuseibeh
Inf. Manag. Comput. Secur.4
2013 Editorial: State of the Journal
abstract
Happy New Year. I say this not only to wish you all a happy new year, but as a statement expressing my relief and optimistic outlook. Relief that the first fully online issue of the IEEE Transactions on Software Engineering (TSE) has been published, and optimism that it heralds a positive evolution of archival journal publication. I must confess that I was a somewhat nervous convert to online publication of TSE. Not because I don’t accept the obvious benefits of electronic online publication, but because I still get a lot of pleasure from flipping through hardcopies of journals, and I was aware that many colleagues shared the same sentiment. I also felt a sense of responsibility for TSE—a flagship software engineering journal—and opted for a conservative evolution to its online presence, rather than being a first adopter when I started as Editor-in-Chief three years ago. The reality, however, is that the majority of TSE readers already access papers electronically and the appearance of preprints of TSE papers in the CS Digital Library immediately on their acceptance has meant that TSE online publication has been with us for sometime already anyway. For those with a desire for a physical manifestation of the journal, a quarterly digest and CD-ROM containing the published papers will still be sent to individual subscribers as part of the format of OnlinePlus. Another reason for optimism is TSE’s return to monthly rather than bimonthly publication. For some time, the backlog of accepted TSE papers has been growing, and authors have had to wait for over a year to see their papers published in hardcopy. Although preprints of accepted papers are available online immediately upon acceptance, full citation information, including volume, issue, and page numbers, was not available until papers appeared in print. This may have had a negative effect on the citation of papers and perhaps discouraged prospective new authors from submitting their work. Combined with a substantial increase in annual page budget of TSE, I hope that timely publication of full and final version of accepted papers will improve the accessibility of published material. It is customary for there to be a first editorial of the year to give readers some publication statistics. TSE continues to be the software engineering journal with the highest impact factor, but last year saw a drop in impact factor from 2.22 in 2010 to 1.98 in 2011. Recall that the impact factor measures the number of times, on average, a paper published in a journal is cited during a 2-year period, and is also a function of the number of papers published in the journal as a whole. So why has there been another drop in the impact factor of again TSE this year? It is not entirely clear—although it appears to be a pattern for most of the other IEEE Computer Society’s periodicals. One explanation that I alluded to above is the large backlog of unpublished but accepted papers that, despite being available online, do not have citation information till much later, leading other authors to cite earlier accounts of the research such as conference papers or even technical reports. In terms of submissions, TSE received 381 papers in 2012, up from 359 in 2011. Because of the increase in pages budgeted per volume, and despite TSE publishing increasingly longer papers, 82 papers were published in 2012, up from 48 in 2011. Of course, the papers published in TSE in any one year are not necessarily drawn from the same pool of submitted papers, as many papers will have been submitted in an earlier year, so the numbers should not be used to calculate so-called acceptance rates. Nonetheless, it is interesting to observe that 297 papers were also rejected in 2012, compared to 219 in 2011. So last year I was able to say that, on average, one paper was submitted to TSE per day, and one was accepted per week. This year both figures have gone up slightly. Looking ahead, it will be interesting to see what OnlinePlus publication does to some of these statistics. From an editorial perspective, little has changed. Submitted papers still undergo the same peer review and editorial process that they have in the past. Increased page budgets, faster publication, and somewhat more flexible pagination alleviate some of the operational constraints on editors, to the benefit of readers and writers. Looking even further ahead, we may well observe that the traditional volume/issue structure of a journal may need to be revisited, as papers are accepted and published continuously. I believe there is still value in the publishing machinery associated with the production of the journal—for example the fine copy editing and production work by Kathy Santa Maria and her colleagues. Online publication and increased page budgets may well allow for more and longer papers, but there is still an associated cost of (and benefit from) the editing that takes place. I take this opportunity therefore to remind potential authors that TSE also welcomes short paper submissions, which can often be reviewed faster than is possible with many conferences, with the added benefit of revision cycles to improve the work. The novelty, rigor, significance, and evaluation of the work published, however, still has to be determined by the review process.
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2013 Editorial [new associate editors]
abstract
It is the Editor-in-Chief's (EiC's) pleasure to welcome a number of new associate editors to the editorial board of the IEEE Transactions on Software Engineering. They are: Luciano Baresi, Daniela Damian, Robert DeLine, Audris Mockus, Gail Murphy, Mauro Pezze, Gian Pietro Pico, Helen Sharp, and Paolo Tonella. They bring a wealth of expertise in a broad range of research areas within software engineering, consolidating traditional strengths in areas such as software testing, and strengthening areas such as empirical studies of software development, mobile computing, and adaptive systems. Short professional biographies are included. At the same time, the EiC would like to bid farewell to those associate editors whose terms of service have ended: Martin Robillard, Peggy Storey, and Tetsuo Tamai. He thanks them for their distinguished contributions over a number of years, and for continuing to handle submitted manuscripts already on their editorial stack.
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2013 In Memoriam - David Notkin (1953-2013)
abstract
David Samuel Notkin, whose technical, educational, and social contributions to computer science and software engineering research made him a major figure in the field, died on 22 April 2013, at his home in Seattle, Washington. He was 58 years old. The cause of his death was cancer. David is best known for his research, with his many graduate students, on software evolution. He asked why software is often so hard and expensive to change, and he worked to reduce the difficulty of software evolution to an essential minimum. This focus came from his belief that the ability to change software - its softness - is where its true but under-realized potential resides. He asked questions such as whether we can identify and close the gap between Brooks' notions of accidental and essential software complexity? How much should rather than does it cost to develop, test, and evolve software? Can we make the cost of change proportionate rather than disproportionate to the apparent complexity of changes to be made? Can we design software analysis methods that realize the best properties of both static and dynamic analysis techniques? Beyond technical contributions, David is widely recognized and admired for his exceptional skill as a research mentor for graduate students and as a powerful and unwavering advocate for improving gender diversity in computer science. A brief biography is given highlighting Notkin's professional achievements.
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2013 Editorial
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2013 In Memoriam: Mary Jean Harrold (1947-2013)
abstract
Recounts the career and contributions of Mary Jean Harrold.
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2012 Social Adaptation - When Software Gives Users a Voice
Raian Ali, Inah Omoronyia, Mazeiar Salehie, Bashar Nuseibeh
ENASE5
2012 Caprice: a tool for engineering adaptive privacy
abstract
In a dynamic environment where context changes frequently, users’ privacy requirements can also change. To satisfy such changing requirements, there is a need for continuous analysis to discover new threats and possible mitigation actions. A frequently changing context can also blur the boundary between public and personal space, making it difficult for users to discover and mitigate emerging privacy threats. This challenge necessitates some degree of self-adaptive privacy management in software applications.
Inah Omoronyia, Liliana Pasquale, Mazeiar Salehie, Luca Cavallaro, Gavin Doherty, Bashar Nuseibeh
ASE6
2012 Requirements-driven adaptive security: Protecting variable assets at runtime
abstract
Security is primarily concerned with protecting assets from harm. Identifying and evaluating assets are therefore key activities in any security engineering process - from modeling threats and attacks, discovering existing vulnerabilities, to selecting appropriate countermeasures. However, despite their crucial role, assets are often neglected during the development of secure software systems. Indeed, many systems are designed with fixed security boundaries and assumptions, without the possibility to adapt when assets change unexpectedly, new threats arise, or undiscovered vulnerabilities are revealed. To handle such changes, systems must be capable of dynamically enabling different security countermeasures. This paper promotes assets as first-class entities in engineering secure software systems. An asset model is related to requirements, expressed through a goal model, and the objectives of an attacker, expressed through a threat model. These models are then used as input to build a causal network to analyze system security in different situations, and to enable, when necessary, a set of countermeasures to mitigate security threats. The causal network is conceived as a runtime entity that tracks relevant changes that may arise at runtime, and enables a new set of countermeasures. We illustrate and evaluate our proposed approach by applying it to a substantive example concerned with security of mobile phones.
Mazeiar Salehie, Liliana Pasquale, Inah Omoronyia, Raian Ali, Bashar Nuseibeh
RE5
2012 Privacy arguments: Analysing selective disclosure requirements for mobile applications
abstract
Privacy requirements for mobile applications offer a distinct set of challenges for requirements engineering. First, they are highly dynamic, changing over time and locations, and across the different roles of agents involved and the kinds of information that may be disclosed. Second, although some general privacy requirements can be elicited a priori, users often refine them at runtime as they interact with the system and its environment. Selectively disclosing information to appropriate agents is therefore a key privacy management challenge, requiring carefully formulated privacy requirements amenable to systematic reasoning. In this paper, we introduce privacy arguments as a means of analysing privacy requirements in general and selective disclosure requirements (that are both content- and context-sensitive) in particular. Privacy arguments allow individual users to express personal preferences, which are then used to reason about privacy for each user under different contexts. At runtime, these arguments provide a way to reason about requirements satisfaction and diagnosis. Our proposed approach is demonstrated and evaluated using the privacy requirements of BuddyTracker, a mobile application we developed as part of our overall research programme.
Thein Than Tun, Arosha K. Bandara, Blaine A. Price, Yijun Yu 0001, Charles B. Haley, Inah Omoronyia, Bashar Nuseibeh
RE7
2012 Speculative requirements: Automatic detection of uncertainty in natural language requirements
abstract
Stakeholders frequently use speculative language when they need to convey their requirements with some degree of uncertainty. Due to the intrinsic vagueness of speculative language, speculative requirements risk being misunderstood, and related uncertainty overlooked, and may benefit from careful treatment in the requirements engineering process. In this paper, we present a linguistically-oriented approach to automatic detection of uncertainty in natural language (NL) requirements. Our approach comprises two stages. First we identify speculative sentences by applying a machine learning algorithm called Conditional Random Fields (CRFs) to identify uncertainty cues. The algorithm exploits a rich set of lexical and syntactic features extracted from requirements sentences. Second, we try to determine the scope of uncertainty. We use a rule-based approach that draws on a set of hand-crafted linguistic heuristics to determine the uncertainty scope with the help of dependency structures present in the sentence parse tree. We report on a series of experiments we conducted to evaluate the performance and usefulness of our system.
Hui Yang 0004, Anne N. De Roeck, Vincenzo Gervasi, Alistair Willis, Bashar Nuseibeh
RE5
2012 SecuriTAS: a tool for engineering adaptive security
abstract
This paper presents SecuriTAS, a tool to engineer adaptive security. It allows software designers to model security concerns together with the requirements of a system. This model is then used at runtime to analyze changes in security concerns and select the best set of security controls necessary to protect the system.
Liliana Pasquale, Claudio Menghi, Mazeiar Salehie, Luca Cavallaro, Inah Omoronyia, Bashar Nuseibeh
SIGSOFT FSE6
2012 The thin line between products
abstract
This talk will discuss some of the research challenges arising from the increased customization and personalization capabilities of many software products, and the subsequent difficulties in engineering distinct and viable product lines. The talk will explore the opportunities that the engineering of adaptive systems have to offer to address these challenges, and some ways in which software product line engineering can help structure and manage the engineering of adaptive systems. The talk will draw on examples from security and privacy - quality requirements that often cut across product boundaries, and that are heavily dependent on the variable contexts in which these products may operate.
Bashar Nuseibeh
SPLC (1)1
2012 Analysing monitoring and switching problems for adaptive systems
Mohammed Salifu, Yijun Yu 0001, Arosha K. Bandara, Bashar Nuseibeh
J. Syst. Softw.4
2012 State of the Journal
abstract
MY two-year term as Editor-in-Chief of the IEEE Transactions on Software Engineering (TSE) has flown by, and I am fortunate to have been given the opportunity to continue for a further two years. I think these are challenging times for scholarly journals, whose content needs to undergo rigorous and lengthy review, often repeatedly, until a group of expert peers, an associate editor, and an editor-in-chief all deem the content suitable for publication. It can be tempting for authors to publish incremental results, lightly evaluated, in conferences with fixed review deadlines, or in magazines that publish highlights quickly and to audiences who may not wish to invest many hours engaging with the details of the authors’ research. I am not going to use this editorial as a forum for reiterating the arguments for journal publication, except to say that I am a firm believer in the value of scholarly journals as the bedrock of a mature engineering discipline and of a discipline with substantial research problems. I also believe that journals provide both the opportunity and the gatekeeping necessary to present and filter significant research results, the quality of which readers can be confident. That is not to say that there is less value in the late-breaking result, the accessible highlight, or even the timely tweet, but this does not replace the foundational work upon which our discipline is built, and which still invariably gets meticulously documented in leading journals such as TSE. Nonetheless, recognizing the need for timeliness of publication and the environmentally friendly opportunities provided by online publication, TSE will be moving to a “mostly online” mode of delivery in 2013. Through IEEE Computer Society’s OnlinePlusTM (http://www.computer.org/portal/web/publications/onlineplus), TSE papers will not only be available online as soon as they are accepted for publication (which has been the case for some time through online Preprints and RapidPosts), they will also be packaged as an electronic offering as the default form of subscription. This will be accompanied by a quarterly 6 inch by 9 inch digest in hardcopy, containing paper details— including titles, authors, abstracts, and citation information—and a disk containing the PDF version of the papers and supplemental material. Readers wishing to continue to receive hardcopies of the full journal can do so for an additional subscription fee, using a print-on-demand service. This will, of course, generate financial savings to publishers, some of which I am happy to say will be passed on to authors and readers in the form of an increased page budget, which will rise from 904 in 2011 to 1,512 pages in 2012, and in cost savings to subscribers starting in 2013 when OnlinePlusTM goes into effect for TSE. This should help reduce the year-long backlog of papers accepted for publication but still waiting to appear “in print.” Of course, the costs of publication are not solely in printing and shipping. TSE papers are lightly edited and formatted, and the additional page budget does come with some additional costs that will be absorbed by the savings achieved from going online. This is the time of the year when I give you some quantitative indicators of the state of the journal over the past 12 months. TSE received 360 new submissions and published 48 papers. Sixty-six papers were accepted in 2011, while 300 were rejected (of these, some 149 papers were rejected administratively without undergoing review for a variety reasons, such as being out of scope, being badly presented to such an extent as to prevent review, or missing some fundamental components of scholarly research such as the articulation of a research problem or the evaluation of the proposed solution). As Editor-in-Chief, and guided by the Editorial Board of Associate Editors, I have tried to ensure that each paper submitted—even those rejected without review—receives some form for qualitative feedback to help authors develop their work further. I sometimes also offer substantial feedback to authors of papers before submission to help keep down the potential time wasted in nonproductive reviews post submission. For the first time in five years, the Thompson/ISI Impact Factor of TSE dropped—to 2.216 in 2010 from 3.75 in 2009. This is somewhat disappointing, although it should be viewed in the context of other scholarly journals in the area, all of whom also saw a drop in their impact factor. Indeed, TSE remains the software engineering title with the highest impact factor. Recall that impact factor measures the number of times, on average, a paper published in a journal is cited during a 2-year period, and is also a function of the number of papers published in the journal as a whole. It is only one measure of “influence” and there has been a flurry of indices (and tools that count them) that have become popular in recent years. Of course, journals that publish popular surveys or literature reviews often get rewarded with higher impact factors. However, this is not a goal that I have set for TSE, and I would prefer that the impact of TSE is evaluated through other means, for example through the application or use of TSE research results in practice (which does not normally attract citations). This kind of impact, however, is harder to measure, and I hope that readers will write to me with examples of non-citation-based impact or with explanations for why citations numbers may have dropped in recent years.
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2011 In the best families: tracking and relationships
abstract
A growing body of research has been exploring the use of control mechanisms to address the privacy concerns raised by location-tracking technology. We report on a qualitative study of two family groups who used a custom-built tracking application for an extended period of time. Akin to sociological breaching experiments, the study focuses on the interferences between location tracking and relationship management. We analyze the tensions that can arise between affordances of the technology and uses that the contracts between family members legitimize. We describe how, by fostering misperceptions and 'nudging' behaviors, location-tracking technology can generate anxieties and conflicts even in close relationships. We discuss their vulnerability to the overreaching effects of tracking, against which the use of mechanisms such as location-sharing preferences and feedback may not be socially viable.
Clara Mancini, Yvonne Rogers, Keerthi Thomas, Adam N. Joinson, Blaine A. Price, Arosha K. Bandara, Lukasz Jedrzejczyk, Bashar Nuseibeh
CHI8
2011 Learning to adapt requirements specifications of evolving systems
abstract
We propose a novel framework for adapting and evolving software requirements models. The framework uses model checking and machine learning techniques for verifying properties and evolving model descriptions. The paper offers two novel contributions and a preliminary evaluation and application of the ideas presented. First, the framework is capable of coping with errors in the specification process so that performance degrades gracefully. Second, the framework can also be used to re-engineer a model from examples only, when an initial model is not available. We provide a preliminary evaluation of our framework by applying it to a Pump System case study, and integrate our prototype tool with the NuSMV model checker. We show how the tool integrates verification and evolution of abstract models, and also how it is capable of re-engineering partial models given examples from an existing system.
Rafael V. Borges, Artur S. d'Avila Garcez, Luís C. Lamb, Bashar Nuseibeh
ICSE4
2011 Specifying and detecting meaningful changes in programs
abstract
Software developers are often interested in particular changes in programs that are relevant to their current tasks: not all changes to evolving software are equally important. However, most existing differencing tools, such as diff, notify developers of more changes than they wish to see. In this paper, we propose a technique to specify and automatically detect only those changes in programs deemed meaningful, or relevant, to a particular development task. Using four elementary annotations on the grammar of any programming language, namely Ignore, Order, Prefer and Scope, developers can specify, with limited effort, the type of change they wish to detect. Our algorithms use these annotations to transform the input programs into a normalised form, and to remove clones across different normalised programs in order to detect non-trivial and relevant differences. We evaluate our tool on a benchmark of programs to demonstrate its improved precision compared to other differencing approaches.
Yijun Yu 0001, Thein Than Tun, Bashar Nuseibeh
ASE3
2011 Risk and argument: A risk-based argumentation method for practical security
abstract
When showing that a software system meets certain security requirements, it is often necessary to work with formal and informal descriptions of the system behavior, vulnerabilities, and threats from potential attackers. In earlier work, Haley et al. [1] showed structured argumentation could deal with such mixed descriptions. However, incomplete and uncertain information, and limited resources force practitioners to settle for good-enough security. To deal with these conditions of practice, we extend the method of Haley et al. with risk assessment. The proposed method, RISA (RIsk assessment in Security Argumentation), uses public catalogs of security expertise to support the risk assessment, and to guide the security argumentation in identifying rebuttals and mitigations for security requirements satisfaction. We illustrate RISA with a realistic example of PIN Entry Device.
Virginia N. L. Franqueira, Thein Than Tun, Yijun Yu 0001, Roel J. Wieringa, Bashar Nuseibeh
RE5
2011 Unknown knowns: Tacit knowledge in requirements engineering
abstract
Summary form only given. Due to increasing complexity of software in embedded systems, the software development requires approaches that can manage that complexity in a similar way as this is done in general-purpose software, but at the same time provide support for embedded systems specifics. In this paper we give a short overview of a component-based approach that meets these requirements.
Peter Sawyer, Vincenzo Gervasi, Bashar Nuseibeh
RE3
2011 OpenArgue: Supporting argumentation to evolve secure software systems
abstract
When software systems are verified against security requirements, formal and informal arguments provide a structure for organizing the software artifacts. Our recent work on the evolution of security-critical software systems demonstrates that our argumentation technique is useful in limiting the scope of change and in identifying changes to security properties. In support of this work, we have developed OpenArgue, a tool for syntax checking, visualizing, formalizing, and reasoning about incremental arguments. OpenArgue has been integrated with requirements engineering tools for Problem Frames and i∗, and applied to an Air Traffic Management (ATM) case study.
Yijun Yu 0001, Thein Than Tun, Alessandra Tedeschi, Virginia N. L. Franqueira, Bashar Nuseibeh
RE5
2011 Problem Analysis of Traditional IT-Security Risk Assessment Methods - An Experience Report from the Insurance and Auditing Domain
Stefan Taubenberger, Jan Jürjens, Yijun Yu 0001, Bashar Nuseibeh
SEC4
2011 Social sensing: when users become monitors
abstract
Adaptation requires a system to monitor its operational context to ensure that when changes occur, a suitable adaptation action is planned and taken at runtime. The ultimate goal of adaptation is that users get their dynamic requirements met efficiently and correctly. Context changes and users' judgment of the role of the system in meeting their requirements are drivers for adaptation. In many cases, these drivers are hard to identify by designers at design time and hard to monitor by the use of exclusively technological means by the system at runtime. In this paper, we propose Social Sensing as the activity performed by users who act as monitors and provide information needed for adaptation at runtime. Such information helps the system cope with technology limitations and designers' uncertainty. We discuss the motivation and foundations of Social Sensing and outline a set of research challenges to address in future work.
Raian Ali, Mazeiar Salehie, Inah Omoronyia, Bashar Nuseibeh, Walid Maalej
SIGSOFT FSE5
2011 Analysing anaphoric ambiguity in natural language requirements
Hui Yang 0004, Anne N. De Roeck, Vincenzo Gervasi, Alistair Willis, Bashar Nuseibeh
Requir. Eng.5
2011 Editorial: State of the Journal
abstract
HAPPY New Year. It has been exactly one year since I started as Editor-in-Chief of the IEEE Transactions on Software Engineering (TSE), so in this editorial I would like to refl ect on to refl ect on this last year and to share with you some facts and fi gures and my plans for the next year. In my fi rst editorial last January, I suggested three medium term goals for the journals that I reiterate below and which I believe still hold: 1. To reemphasize the broad scope of the journal, encouraging the publication of multidisciplinary research as well as specialization in software engineering. 2. To engage with the software engineering community at large, including other journals, about the software engineering discipline, using not only the journal itself as a forum but through other professional outlets such as conferences and the Web. 3. To support a debate on the nature of scholarly discourse in software engineering, such as the kind and length of papers published in the journal, or the different forms of peer review and discussion around what is published. My fi rst goal above is rather subtle. The scope of the journal is already quite precisely defi ned and has not changed for some time. However, I still believe that as software—and software engineering—continues to permeate society and the development of systems of all kinds, software engineering research also has opportunities to grow. To grow in terms of its interaction with other disciplines outside its traditional boundaries, but also to grow it terms of specialization within, say, problem domain boundaries. To this end, I have encouraged the TSE editorial board to help solicit a broader range of submissions, but also to handle submissions outside TSE’s traditional boundaries with tolerance, even enthusiasm. This sometimes means making an additional effort to guide authors to formulate or reformulate submissions to make the work more accessible to a software engineering audience. The impact of this approach will take some time to have a visible effect, as most of the papers submitted to TSE in 2010 have yet to be published. With respect to my second goal above, community engagement is an ongoing effort. In 2010 I met with the editorsin-chief of many of the software engineering research journals, and we discussed ways in which we can help present research that is novel and exciting, that is rigorous and well-presented, and that is relevant and useful to readers of our publications. I have encouraged, but only been partially successful, in engaging TSE readers to contribute to the debate about the discipline of software engineering. I say “partially successful” because there has been almost no discussion on the TSE electronic forum, but I have received many individual e-mails from readers addressing very specifi c issues, such as those that I raise in my regular editorials. It does seem that an open ended invitation to discuss the discipline is too vague to engage most readers, and so I will continue to discuss specifi c topics in each issue of the journal. The third goal above is one that has been receiving attention from other journal and magazine editors as well. I do sense that the value of journal publications in software engineering is back on the rise, and I feel that my appeal to authors to submit different kinds (and lengths) of manuscripts is being addressed. I have said previously that there is nothing sacred about the kind and length of a software engineering research contribution, and in the last year TSE received more short and a few very long manuscripts. In all cases, I have asked associate editors to consider if content justifi es the length, rather than be distracted by any notion of suggested manuscript length. Papers published in 2011 will be partly the result of such an approach. What else have I learned from year 1? Well, personally, I have been saddened to observe that much of my time is spent handling exceptions of the rather unpleasant variety—plagiarism, duplicate or overlapping submissions, and, in a few cases, appeals. I have absolutely no problem at all with appeals. Authors should feel free to question review decisions on their papers—the review process is not infallible—and queries or complaints help test the robustness of the process and the resultant decisions. Similarly, I encourage readers to write and question or discuss published papers’ content. Some readers have chosen to do this anonymously and that’s fi ne, although I would welcome more open technical commentaries, which TSE has the mechanism to publish in hardcopy or in the digital library. What does bother me are the incidents of what can only be termed unethical behavior—such as plagiarism. The penalties for this are severe, and a “prohibited authors” list is updated and circulated among all IEEE editors each month, with each additional named author fully investigated before being “blacklisted” and barred from future submission to the journal. Incidence of self-plagiarism or duplicate submissions are equally troubling, and a real time drain for editors and reviewers. In a future editorial, I will also discuss the undesirable phenomenon of an LPU—a “least publishable unit”—which unfortunately seems be a way for some authors to increase their publication counts by publishing very small incremental contributions over previously published work. Duplicate or heavily overlapping submissions are often detected, due to the limited and specialized community of reviewers and the open and interactive relationships between journal editors.
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2011 Editorial: What Makes a Publication Archival?
abstract
ARE journals more archival than conference proceedings? I don't think so. Most published conference proceedings live in libraries, digital or otherwise, and in that sense they are as archival as any other library publication. So what is it that distinguishes a conference paper from a journal paper? If it is the additional detail that a longer journal paper allows, then this may explain why many readers tell me that they often fi nd journal papers hard to read. I think it is more than just detail though. Could it be the additional evaluation that journal publication demands? This is certainly a reason that many editors and reviewers give me. However, I have sat on many conference program committees in recent years, and I have observed expectations for high standards of evaluation, especially at the so-called top conferences. So, for such conference papers, is there much to distinguish them from journal papers? I must admit, I often fi nd it hard to make such a distinction myself. The feedback I get from readers suggests that I am not alone. In recent months, I have discussed this issue with two prominent software engineering writers and editors (who, fortunately, are also readers of TSE). One lamented that journal papers “these days” lack the depth of contribution and thoroughness of evaluation that one expects from a mature engineering discipline. The other harked back “to the days when” journals published new and exciting research, some of which has been shown to be highly infl uential without having been evaluated thoroughly at the time of original publication. So what is a journal editor to do? Lower evaluation standards to increase the likelihood of more “exciting” work getting published (and risk that the research may be fl awed or useless, and therefore less “archival”)? Or, only publish research that has depth and substantial evaluation? Or is there a better middle ground? If you are expecting me to answer these questions, then stop reading now. If you have answers to these questions yourself, then please let me know. I would welcome your thoughts. I believe that we need to restore journal publication as the forum for publication of new work (rather than serving simply as a worthy extension of conference publications). I have been trying to facilitate this in TSE, by speeding up the review process, encouraging editors to engage in more discussion with their reviewers to better understand and judge research work, and therefore be better placed to make risky but promising decisions rather than conservative ones only. At the same time, I have emphasized TSE's expectations for high standards of evaluation, but encouraged the authors to engage with TSE editors and reviewers (anonymously) to get the work in to publication shape, iteratively. This allows TSE to serve, in part, the role traditionally reserved for conference publications. I hope those of you who write, review, and edit TSE papers have noticed this, and that readers will notice the results in the coming months. Finally, it is my pleasure to introduce and welcome a new member of the TSE editorial board, Professor Martin Robillard. Martin has managed to publish research that is novel and exciting, yet also establish himself, through his writings, as a researcher who undertakes rigorous evaluation of his work.
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2010 Contravision: exploring users' reactions to futuristic technology
abstract
How can we best explore the range of users' reactions when developing future technologies that may be controversial, such as personal healthcare systems? Our approach -- ContraVision -- uses futuristic videos, or other narrative forms, that convey either negative or positive aspects of the proposed technology for the same scenarios. We conducted a user study to investigate what range of responses the different versions elicited. Our findings show that the use of two systematically comparable representations of the same technology can elicit a wider spectrum of reactions than a single representation can. We discuss why this is so and the value of obtaining breadth in user feedback for potentially controversial technologies.
Clara Mancini, Yvonne Rogers, Arosha K. Bandara, Tony Coe, Lukasz Jedrzejczyk, Adam N. Joinson, Blaine A. Price, Keerthi Thomas, Bashar Nuseibeh
CHI9
2010 A Methodology for Automatic Identification of Nocuous Ambiguity
Hui Yang 0004, Anne N. De Roeck, Alistair Willis, Bashar Nuseibeh
COLING4
2010 Automatic detection of nocuous coordination ambiguities in natural language requirements
abstract
Natural language is prevalent in requirements documents. However, ambiguity is an intrinsic phenomenon of natural language, and is therefore present in all such documents. Ambiguity occurs when a sentence can be interpreted differently by different readers. In this paper, we describe an automated approach for characterizing and detecting so-called nocuous ambiguities, which carry a high risk of misunderstanding among different readers. Given a natural language requirements document, sentences that contain specific types of ambiguity are first extracted automatically from the text. A machine learning algorithm is then used to determine whether an ambiguous sentence is nocuous or innocuous, based on a set of heuristics that draw on human judgments, which we collected as training data. We implemented a prototype tool for Nocuous Ambiguity Identification (NAI), in order to illustrate and evaluate our approach. The tool focuses on coordination ambiguity. We report on the results of a set of experiments to assess the performance and usefulness of the approach.
Hui Yang 0004, Alistair Willis, Anne N. De Roeck, Bashar Nuseibeh
ASE4
2010 "Privacy-shake", : a haptic interface for managing privacy settings in mobile location sharing applications
abstract
We describe the "Privacy-Shake", a novel interface for managing coarse grained privacy settings. We built a prototype that enables users of Buddy Tracker, an example location sharing application, to change their privacy preferences by shaking their phone. Users can enable or disable location sharing and change the level of granularity of disclosed location by shaking and sweeping their phone. In this poster we present and motivate our work on Privacy-Shake and report on a lab-based evaluation of the interface with 16 participants.
Lukasz Jedrzejczyk, Blaine A. Price, Arosha K. Bandara, Bashar Nuseibeh
Mobile HCI4
2010 Mobile Privacy Requirements on Demand
Bashar Nuseibeh
PROFES1
2010 Extending Nocuous Ambiguity Analysis for Anaphora in Natural Language Requirements
abstract
This paper presents an approach to automatically identify potentially nocuous ambiguities, which occur when text is interpreted differently by different readers of requirements written in natural language. We extract a set of anaphora ambiguities from a range of requirements documents, and collect multiple human judgments on their interpretations. The judgment distribution is used to determine if an ambiguity is nocuous or innocuous. We investigate a number of antecedent preference heuristics that we use to explore aspects of anaphora which may lead a reader to favour a particular interpretation. Using machine learning techniques, we build an automated tool to predict the antecedent preference of noun phrase candidates, which in turn is used to identify nocuous ambiguity. We report on a series of experiments that we conducted to evaluate the performance of our automated system. The results show that the system achieves high recall with a consistent improvement on baseline precision subject to some ambiguity tolerance levels, allowing us to explore and highlight realistic and potentially problematic ambiguities in actual requirements documents.
Hui Yang 0004, Anne N. De Roeck, Vincenzo Gervasi, Alistair Willis, Bashar Nuseibeh
RE5
2010 On the impact of real-time feedback on users' behaviour in mobile location-sharing applications
abstract
Effective privacy management requires that mobile systems' users be able to make informed privacy decisions as their experience and knowledge of a system progresses. Prior work has shown that making such privacy decisions is a difficult task for users because systems do not provide support for awareness, visibility and accountability when sharing privacy-sensitive information. This paper reports results of our investigation into the efficacy of real-time feedback as a mechanism for incorporating these features of social translucence in location-sharing applications, in order to help users make better privacy decisions. We explored the role of real-time feedback in the context of Buddy Tracker, a mobile location-sharing application. Our work focuses on ways in which real-time feedback affects people's behaviour in order to identify the main criteria for acceptance of this technology. Based on the data from a three week field trial of Buddy Tracker, a focus group session, and interviews, we found that when using a system that provided real-time feedback, people were more accountable for their actions and reduced the number of unreasonable location requests. We have used the results of our study to propose high-level design criteria for incorporating real-time feedback into information sharing applications in a manner that ensures social acceptance of the technology.
Lukasz Jedrzejczyk, Blaine A. Price, Arosha K. Bandara, Bashar Nuseibeh
SOUPS4
2010 Editorial: A New Decade of TSE
abstract
Introduction and Vision I am honored to be taking over as Editor in Chief of the IEEE Transactions of Software Engineering (TSE). Jeff Kramer will be a hard act to follow, but I am immensely grateful to him for handing over the journal in such a healthy state, and for helping me learn the new job to ensure a smooth transition. It goes without saying that my primary goal as Editor is to maintain the journal’s reputation and standing as the leading forum for publishing the highest quality of research in software engineering. However, these are exciting and changing times in the world of publishing and in the discipline of software engineering, and I believe that TSE must lead the way by finding innovative ways to disseminate software engineering research and by contributing to setting and reflecting the research agenda in the field. To this end I have three medium term goals for my tenure as Editor: 1. To reemphasize the broad scope of the journal, encouraging the publication of multidisciplinary research as well as specialization in software engineering. 2. To engage with the software engineering community at large, including other journals, about the software engineering discipline, using not only the journal itself as a forum but through other professional outlets such as conferences and the web. 3. To support a debate on the nature of scholarly discourse in software engineering, such as the kind and length of papers published in the journal, or the different forms of peer review and discussion around what is published. Tactics The length of papers published in TSE has on occasion been a topic for some discussion. I do not propose to change the policy in this area but to clarify it, as I think it hides a number of issues within it. TSE publishes papers of any length, as long as their length is appropriate for the content presented. The discussion has often centered around what to do if accepted papers are over the IEEE Computer Society’s recommended length of 15 pages. However, there is an equally interesting discussion to be had for short papers. My view is this: There is nothing sacred about the length of a software engineering research contribution. Substantial pieces of work may need lengthy and detailed accounts of techniques, or of empirical studies or other kinds of evidence; but equally valuable results may be published in short papers. Indeed, other disciplines manage to publish seminal results in four pages. I will continue to be guided by my associate editors as to what constitutes an appropriate length for any particular contribution. I believe that we, as a community, have largely won the battle of persuading our deans and managers that publishing in conferences is a respectable form of publication. However, in a world of economic difficulties, carbon footprint consciousness, and fast internet-time publication, there is a strong case to be made that we need to redress the balance and publish more of our research in journals. Indeed, I would go as far as saying that many research students now go through their entire doctoral studies publishing in workshops and conferences only, and think that all research contributions can fit into the 2-column, 10-page format of IEEE conference publications. As a result, other than their PhD dissertations, these students do not get an opportunity to publish their work in an archival journal format. Of course, the frequency of conference reviewing has also had an impact on the nature of reviews that referees are asked to write. With little scope for improving conference papers before publication and heavy referee review loads, reviews tend to be short critiques of papers, rather than substantive engagements with the content that authors are trying to present. I therefore believe that journal reviews and revision allow for better quality work to be produced incrementally and then published. Of course, the journal publication process is not without cost to authors, referees, and editors, and we need to acknowledge this and tackle it head on. I was very taken by the discussion by Crowcroft et al. [1] on the varying incentives of the different stakeholders in the publication process: authors, referees, and editors. For TSE, the kind of behavior I would like to incentivize is for authors to submit innovative, rigorous, and well-presented accounts of their research and not overload the system with half-baked ideas or very small increments on previous work. I would like to incentivize referees to agree to review papers and to produce rigorous, thoughtful reviews. And, I would like to incentivize editors to seek and encourage submission of a wider range of contributions that will serve our research and practitioner community better. I have no magic to generate these incentives. However, in a year’s time TSE will make a number of awards to authors, referees, and (associate) editors to acknowledge the quality of research, feedback, and editing. I welcome feedback from the community on the specification of such awards.
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2010 Editorial: Readers, Writers, Reviewers, and Editors
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2010 In Memoriam: Robin Milner and Amir Pnueli
abstract
Provides the biographies for two members of the computing community, Robin Milner and Amir Pnueli, who recently passed away. Both were Turing Award winners and both contributed in fundamental ways to the foundations of software engineering.
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2010 Editorial: How Special Should Issues Be?
abstract
SOFTWARE testing and analysis continue to be areas in which IEEE Transaction on Software Engineering (TSE) receives many submissions. In this issue, Barbara Ryder and Andreas Zeller guest edit a special section of selected papers from ISSTA 2008, the original papers having undergone signifi cant revision, extension, and substantive peer review. I would like to thank Barbara and Andreas for all their work in putting this special section together over a long period of time, and to the authors for their contributions and their patience while waiting for their papers to be published. Special issues are a prominent feature of TSE and other journals, and there are a number of forthcoming issues in the TSE publication pipeline. I’d be interested to hear readers’ views about the usefulness of such special issues. I understand that they can provide a useful thematic resource for researchers and practitioners working in particular areas, but the inevitable consequence is that they limit the number of regular papers that can be published in any one issue or volume. This can affect the diversity of topics covered by the journal. Since starting as Editor-in-Chief back in January, I have not approved any new proposals for special issues. This will not be felt by readers till many more months down the line as the current queue of special issue papers gets published. I hope this will eventually allow the many regular papers awaiting publication to appear in print much more quickly. Of course, “in print” is only one way the papers are available. As soon as any paper is accepted for publication in TSE, it is available to subscribers electronically for download. I hope readers are making use of this facility on the TSE website (http://www.computer. org/portal/web/tse/), found under “PrePrints” and “RapidPosts.” Last but not least, I’d like to welcome two new distinguished additions to the TSE Editorial Board: Dr. Jane ClelandHuang and Dr. Dag Sjoberg. I am very grateful to both of them for agreeing to serve as Associate Editors, bringing to TSE their considerable expertise in empirical software engineering and the applications of software engineering research in practice. Both Dag and Jane have immediately found themselves loaded with a number of papers to manage—a consequence of the popularity of the areas in which they work.
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2010 Editorial
Bashar Nuseibeh
IEEE Trans. Software Eng.1
2009 From spaces to places: emerging contexts in mobile privacy
abstract
Mobile privacy concerns are central to Ubicomp and yet remain poorly understood. We advocate a diversified approach, enabling the cross-interpretation of data from complementary methods. However, mobility imposes a number of limitations on the methods that can be effectively employed. We discuss how we addressed this problem in an empirical study of mobile social networking. We report on how, by combining a variation of experience sampling and contextual interviews, we have started focusing on a notion of context in relation to privacy, which is subjectively defined by emerging socio-cultural knowledge, functions, relations and rules. With reference to Gieryn's sociological work, we call this place, as opposed to a notion of context that is objectively defined by physical and factual elements, which we call space. We propose that the former better describes the context for mobile privacy.
Clara Mancini, Keerthi Thomas, Yvonne Rogers, Blaine A. Price, Lukasz Jedrzejczyk, Arosha K. Bandara, Adam N. Joinson, Bashar Nuseibeh
UbiComp8
2009 Are Your Lights Off? Using Problem Frames to Diagnose System Failures
abstract
This paper reports on our experience of investigating the role of software systems in the power blackout that affected parts of the United States and Canada on 14 August 2003. Based on a detailed study of the official report on the blackout, our investigation has aimed to bring out requirements engineering lessons that can inform development practices for dependable software systems. Since the causes of failures are typically rooted in the complex structures of software systems and their world contexts, we have deployed and evaluated a framework that looks beyond the scope of software and into its physical context, directing attention to places in the system structures where failures are likely to occur. We report that (i) Problem Frames were effective in diagnosing the causes of failures and documenting the causes in a schematic and accessible way, and (ii) errors in addressing the concerns of biddable domains, model building problems, and monitoring problems had contributed to the blackout.
Thein Than Tun, Michael Jackson 0001, Robin C. Laney, Bashar Nuseibeh, Yijun Yu 0001
RE4
2009 Early Identification of Problem Interactions: A Tool-Supported Approach
Thein Than Tun, Yijun Yu 0001, Robin C. Laney, Bashar Nuseibeh
REFSQ4
2009 Studying location privacy in mobile applications: 'predator vs. prey' probes
abstract
No abstract available.
Keerthi Thomas, Clara Mancini, Lukasz Jedrzejczyk, Arosha K. Bandara, Adam N. Joinson, Blaine A. Price, Yvonne Rogers, Bashar Nuseibeh
SOUPS8
2009 Specifying features of an evolving software system
abstract
Abstract Software development is increasingly concerned with maintaining and extending existing software systems to meet the evolving user requirements. Many of these systems are feature‐rich and are developed incrementally. As structures of existing software systems—in addition to the user requirements—influence the specifications, specifying these systems poses unique challenges. This paper reports on our experience of applying an engineering approach to specifying an evolving feature‐rich television software system. In this approach, features are specified modularly by first fitting their problems to known problem patterns, and then analyzing typical concerns—meaning the potential causes of errors—associated with those patterns. In cases where the existing design poses difficulties when fitting problems to patterns, we transform its structure using known design mechanisms so that the problems fit the patterns. After deriving specifications of individual features, possible interactions between features are detected, before declaratively specifying resolutions to undesired interactions. As the concerns of features and their composition are addressed separately, the specifications derived are modular, thus, providing rich treaceability to their requirements. As well as discussing how features may be specified using natural language, we also show how their descriptions may be formalized using a form of temporal logic called the Event Calculus, and prove their correctness using an off‐the‐shelf tool. Copyright © 2009 John Wiley & Sons, Ltd.
Thein Than Tun, Tim Trew, Michael Jackson 0001, Robin C. Laney, Bashar Nuseibeh
Softw. Pract. Exp.5
2008 Customizing Choreography: Deriving Conversations from Organizational Dependencies
abstract
Evolving business needs call for customizable choreographed interactions. However, choreography descriptions do not capture the problem-domain knowledge required to perform the customization effectively. Hence, we propose performing the customization to models of organizational requirements motivating the interaction. To facilitate the derivation of the resulting choreography description, we propose an alignment between conversations and organizational dependencies. We employ the domain knowledge and formal semantics of requirements models to find customization alternatives and reason about them. Using the alignment, we derive constraints on conversations systematically from customized requirements models.
Ayman Mahfouz, Leonor Barroca 0001, Robin C. Laney, Bashar Nuseibeh
EDOC4
2008 Building Contingencies into Specifications
abstract
We propose an approach to runtime feature composition and conflict resolution that combines arbitration and contingencies. By arbitration we mean the resolution of conflicts between features using priorities. Contingency means having several specifications per feature, satisfying the same requirement, depending on the current state of the shared resource. Evaluation of our approach shows that combining arbitration and contingencies ensures that in the event of a conflict, requirements of the conflicting features are eventually satisfied.
Armstrong Nhlabatsi, Robin C. Laney, Bashar Nuseibeh
RE3
2008 A final editorial
Bashar Nuseibeh
Autom. Softw. Eng.1
2008 Security Requirements Engineering: A Framework for Representation and Analysis
abstract
This paper presents a framework for security requirements elicitation and analysis. The framework is based on constructing a context for the system, representing security requirements as constraints, and developing satisfaction arguments for the security requirements. The system context is described using a problem-oriented notation, then is validated against the security requirements through construction of a satisfaction argument. The satisfaction argument consists of two parts: a formal argument that the system can meet its security requirements and a structured informal argument supporting the assumptions expressed in the formal argument. The construction of the satisfaction argument may fail, revealing either that the security requirement cannot be satisfied in the context or that the context does not contain sufficient information to develop the argument. In this case, designers and architects are asked to provide additional design information to resolve the problems. We evaluate the framework by applying it to a security requirements analysis within an air traffic control technology evaluation project.
Charles B. Haley, Robin C. Laney, Jonathan D. Moffett, Bashar Nuseibeh
IEEE Trans. Software Eng.4
2008 Guest Editors' Introduction: Special Section on Software Engineering for Secure Systems
abstract
THE proliferation of computers in society has meant that organizational and personal assets are increasingly stored and manipulated by software systems. The scale of misuse of these assets has also increased because of their worldwide accessibility through the Internet and the automation of systems. Security is concerned with the prevention of such misuse. While no system can be made completely secure, understanding the context in which a system will be deployed and used, the risks and threats of its misuse, and the systematic development of its software are increasingly recognized as critical to its success. The cross-fertilization of systems development techniques from software engineering and security engineering offers opportunities to minimize duplication of research efforts in both areas and, more importantly, to bridge gaps in our knowledge of how to develop secure softwareintensive systems. The aim of this special issue is to publish novel research work that draws upon software engineering to develop secure systems more effectively. Its scope covers the processes, techniques, technology, people, and knowledge bases that have, or need, the capability to contribute to producing more secure software-intensive systems. In response to the call for papers for this special section, we received 41 submissions, regarding software engineering issues addressing the requirements, design, coding, testing, and maintenance of secure software systems. Each paper was reviewed by at least three expert referees. After two rounds of reviewing, we selected six papers which focus on requirements and design of secure software. The first two papers address both security and privacy requirements, making use of varying degrees of formalism to represent and analyze those requirements. “Analyzing Regulatory Rules for Privacy and Security Requirements” by Travis Breaux and Annie Anton addresses the often overwhelming complexity of regulatory requirements of financial, healthcare, and other software. The formalism and process presented glean enforceable security policy directly from the regulatory statutes. “Privately Finding Specifications” by Westley Weimer and Nina Mishra deals with one of the daunting realities of data sharing, the fact that it is often an all or nothing proposition. This paper describes an attempt to mitigate oversharing in the discovery of software specifications by perturbing program traces. The careful addition of noise into the traces allows specification discovery while preventing the exposure of other sensitive aspects of the program. The next three papers consider how the design of software systems can be realized through security infrastructure. “Semantics-Based Design for Secure Web Services” by Massimo Bartoletti, Pierpaolo Degano, Gian Luigi Ferrari, and Roberto Zunino considers how to develop secure Web services by formally reasoning about policy compliance over historical behaviors. In essence, Web services “contract” (compose) with those systems that respect policies of interest, thereby ensuring globally secure behavior. “Provable Protection against Web Application Vulnerabilities Related to Session Data Dependencies” by Lieven Desmet, Pierre Verbaeten, Wouter Joosen, and Frank Piessens acknowledge recent advances in secure Web application design and development that have made online systems safer. The techniques detailed in this paper prevent misuse of often loosely coupled session dependencies in and among Web applications. “WASP: Protecting Web Applications Using Positive Tainting and Syntax-Aware Evaluation” by William Halfond, Alessandro Orso, and Panagiotis Manolios presents a novel method for preventing SQL injection attacks—attacks in which the adversary inserts arbitrary database query code into an application by manipulating input strings. The paper uses language techniques to dynamically annotate ”trusted” strings, thereby avoiding any use of potentially unsafe strings. The final paper presents a method of certifying that a software system meets its security requirements. “Applying Formal Methods to a Certifiably Secure Software System” by Connie Heitmeyer, Myla Archer, Elizabeth Leonard, and John McLean adds to recent advances that are beginning to make this costly and complex process of formal verification tractable. This paper presents a novel certification method that uses formalized security models to construct a mechanized proof of security over a real-world target system. The papers in this special section demonstrate the strength of research in the area of engineering secure software. If the range and strength of the submissions to the special section are anything to go by, the area is healthy and vibrant and we fully expect many of the submissions that IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, VOL. 34, NO. 1, JANUARY/FEBRUARY 2008 3
Patrick D. McDaniel, Bashar Nuseibeh
IEEE Trans. Software Eng.2
2007 Model-Based Security Engineering of Distributed Information Systems Using UMLsec
abstract
Given the explosive growth of digitally stored information in modern enterprises, distributed information systems together with search engines are increasingly used in companies. By enabling the user to search all relevant information sources with one single query, however, crucial risks concerning information security arise. In order to make these applications secure, it is not sufficient to penetrate- and-patch past system development, but security analysis has to be an integral part of the system design process for such distributed information systems. This work presents the experiences and results of the security analysis of a search engine in the intranet of a German car manufacturer, by making use of an approach to model-based security engineering that is based on the UML extension UMLsec. The focus lies on the application's single-sign-on-mechanism, which was analyzed using the UMLsec method and tools. Main results of the paper include afield report on the employment of the UMLsec method in an industrial context as well as indications on its benefits and limitations.
Bastian Best, Jan Jürjens, Bashar Nuseibeh
ICSE3
2007 Specifying Monitoring and Switching Problems in Context
abstract
Context-aware applications monitor changes in their operating environment and switch their behaviour to keep satisfying their requirements. Therefore, they must be equipped with the capability to detect variations in their operating context and to switch behaviour in response to such variations. However, specifying monitoring and switching in such applications can be difficult due to their dependence on varying contextual properties which need to be made explicit. In this paper, we present a problem- oriented approach to represent and reason about contextual variability and assess its impact on requirements; to elicit and specif' concerns facing monitors and switchers, such as initialisation and interference; and to specify monitoring and switching behaviours that can detect changes and adapt in response. We illustrate our approach by applying it to a published case study.
Mohammed Salifu, Yijun Yu 0001, Bashar Nuseibeh
RE3
2006 Requirements Engineering Research in Some Future Worlds: An Exercise in Scenario Planning
abstract
We hope this will be a panel discussion with a difference. Each of our panel members has been given a scenario description of the world in 2020, significantly different from our own.
David Bush, Bashar Nuseibeh
RE2
2006 Identifying Nocuous Ambiguities in Natural Language Requirements
abstract
We present a novel technique that automatically alerts authors of requirements to the presence of potentially dangerous ambiguities. We first establish the notion of nocuous ambiguities, which are those that are likely to lead to misunderstandings. We test our approach on coordination ambiguities, which occur when words such as and or are used. Our starting point is a dataset of ambiguous phrases from a requirements corpus and associated human judgements about their interpretation. We then use heuristics, based largely on word distribution information, to automatically replicate these judgements. The heuristics eliminate ambiguities which people interpret easily, leaving the nocuous ones to be analysed and rewritten by hand. We report on a series of experiments that evaluate our heuristics' performance against the human judgements. Many of our heuristics achieve high precision, and recall is greatly increased when they are used in combination
Francis Chantree, Bashar Nuseibeh, Anne N. De Roeck, Alistair Willis
RE2
2006 Using trust assumptions with security requirements
Charles B. Haley, Robin C. Laney, Jonathan D. Moffett, Bashar Nuseibeh
Requir. Eng.4
2006 Guest Editors' Introduction to the Special Section on the International Conference on Software Engineering
abstract
THE 27th International Conference on Software Engineering (ICSE '05) was held in St. Louis, Missouri, 15-21 May 2005. Of the 313 papers submitted to the conference, 44 were published in the conference proceedings, and, of those, four of the best were selected and invited for revision and extension. The papers cover four diverse topics but share rigorous technical presentations of novel work, substantially validated or evaluated. The papers are briefly summarized.
William G. Griswold, Bashar Nuseibeh
IEEE Trans. Software Eng.2
2005 Introduction to Research Papers
abstract
At the heart of the ICSE-2005 program are the 44 research papers selected by the Program Committee (PC) from the 313 submissions to the conference. All submissions were rigorously reviewed by the PC -- each submission received reviews from at least three different PC members. The PC then met on 5-6 November 2004 in Newport Beach, California, USA, to discuss the submissions and make the final selections for the program. Each of the papers selected for publication in the proceedings and presentation at the conference was chosen on its own merits and without comparison to any others.The papers selected cover a wide range of research areas, which are not always amenable to a simple classification. Nevertheless, the papers are clustered into sessions that broadly represent the dominant research themes of the work described.The PC comprised 43 members drawn from a wide cross section of the software engineering community. The PC members worked hard to put the program of research papers together. Each PC member received an average of 22 papers to review prior to the PC meeting, followed by a substantial e-mail conversation and two full days discussing papers at the PC meeting. It was our pleasure and privilege to work with such a professional group of people to produce the quality of the program before you. Our deepest thanks go to the PC.We must also thank the organizers of SIGSOFT FSE 2005, who generously hosted our PC meeting and assisted in numerous local arrangements. In particular, we thank Dick Taylor, Debra Brodbeck, and Susan Knight. Their help in producing a trouble-free, enjoyable PC meeting helped keep the PC's spirits high through two long days.We would be remiss if we did not lavish praise and thanks on Richard van de Stadt and the CyberChair conference management system. CyberChair streamlined many of the PC's activities, and Richard added several new features to CyberChair that saved us days of work in staging the PC meeting.Finally, we thank our General Chair, Catalin Roman, for bringing us together, making us partners in creating ICSE 2005, and giving us the guidance and freedom we needed to create the best possible research program. In doing so, he has given us one of the most rewarding experiences of our professional lives.
William G. Griswold, Bashar Nuseibeh
ICSE2
2005 On Modelling Access Policies: Relating Roles to their Organisational Context
abstract
The restriction of access is a mechanism by which organisations protect their information assets. Requirements models use actor definitions to describe users and to specify their access policies. Actors normally represent roles that users adopt, while roles can represent different things, such as a position in an organisation or the assignment of a task. Current requirements modelling approaches do not provide a systematic way of defining roles for incorporation into access policies. We address this issue by proposing a framework that facilitates the derivation of role definitions from their wider organisational context. We illustrate how our framework can be used to extend a formal version of i* - to define and verify access policies definitions -and demonstrate its applicability via a case study.
Robert Crook, Darrel C. Ince, Bashar Nuseibeh
RE3
2005 Keeping ubiquitous computing to yourself: A practical model for user control of privacy
Blaine A. Price, Karim Adam, Bashar Nuseibeh
Int. J. Hum. Comput. Stud.3
2004 Problem Frames: A Case for Coordination
Leonor Barroca 0001, José Luiz Fiadeiro, Michael Jackson 0001, Robin C. Laney, Bashar Nuseibeh
COORDINATION5
2004 The Effect of Trust Assumptions on the Elaboration of Security Requirements
Charles B. Haley, Robin C. Laney, Jonathan D. Moffett, Bashar Nuseibeh
RE4
2004 The Conundrum of Categorising Requirements: Managing Requirements for Learning on the Move
Debra Trusso Haley, Bashar Nuseibeh, Helen Sharp, Josie Taylor
RE2
2004 Composing Requirements Using Problem Frames
Robin C. Laney, Leonor Barroca 0001, Michael Jackson 0001, Bashar Nuseibeh
RE4
2004 Using Abuse Frames to Bound the Scope of Security Problems
Luncheng Lin, Bashar Nuseibeh, Darrel C. Ince, Michael Jackson 0001
RE2
2004 Architecture-driven Problem Decomposition
Lucia Rapanotti, Jon G. Hall, Michael Jackson 0001, Bashar Nuseibeh
RE4
2003 ViewPoints: meaningful relationships are difficult!
abstract
The development of complex systems invariably involves many stakeholders who have different perspectives on the problem they are addressing, the system being developed, and the process by which it is being developed. The ViewPoints framework was devised to provide an organisational framework in which these different. perspectives, and their relationships, could be explicitly represented and analysed The framework acknowledges the inevitability of multiple inconsistent views, promotes separation of concerns, and encourages decentralised specification while providing support for integration through relationships and composition. In this paper, we reflect on the ViewPoints framework, current work and future research directions.
Bashar Nuseibeh, Jeff Kramer, Anthony Finkelstein
ICSE1
2003 Introducing Abuse Frames for Analysing Security Requirements
abstract
We are developing an approach using Jackson's Problem Frames to analyse security problems in order to determine security vulnerabilities. We introduce the notion of an anti-requirement as the requirement of a malicious user that can subvert an existing requirement. We incorporate anti-requirements into so-called abuse frames to represent the notion of a security threat imposed by malicious users in a particular problem context. We suggest how abuse frames can provide a means for bounding the scope of security problems in order to analyse security threats and derive security requirements.
Luncheng Lin, Bashar Nuseibeh, Darrel C. Ince, Michael Jackson 0001, Jonathan D. Moffett
RE2
2003 Modelling access policies using roles in requirements engineering
Robert Crook, Darrel C. Ince, Bashar Nuseibeh
Inf. Softw. Technol.3
2003 Guest editorial
Bashar Nuseibeh
Requir. Eng.1
2002 An Abductive Approach for Analysing Event-Based Requirements Specifications
Alessandra Russo, Rob Miller 0002, Bashar Nuseibeh, Jeff Kramer
ICLP3
2002 Security Requirements Engineering: When Anti-Requirements Hit the Fan
abstract
Everyone agrees that security is a problem, ranging from Microsoft to the banks that have been recent victims of rogue traders. What is paradoxical is that there does not seem to be a wholehearted commitment by both academics and industry to treat this topic systematically at the top level of requirements engineering. Our vision is of a future in which we inform the security requirements engineering process by organisational theory. This would act as the bridge between the well-ordered world of the software project informed by conventional requirements and the unexpected world of anti-requirements associated with the malicious user. We frame a vision for the requirements engineering community that would involve the community solving six difficult problems.
Robert Crook, Darrel C. Ince, Luncheng Lin, Bashar Nuseibeh
RE4
2002 Relating Software Requirements and Architectures Using Problem Frames
abstract
Problem frames provide a means of analyzing and decomposing problems. They emphasise the world outside of the computer, helping the developer to focus on the problem domain, instead of drifting into inventing solutions. However, even modestly complex problems can force us into detailed consideration of the architecture of the solution. This is counter to the intention of the problem frames approach, which is to delay consideration of the solution space until a good understanding of the problem is gained. We therefore extend problem frames, allowing architectural structures, services and artifacts to be considered as part of the problem domain. Through a case study, we show how this extension enhances the applicability of problem frames in permitting an architecture-based approach to software development. We conclude that, through our extension, the applicability of problem frames is extended to include domains with existing architectural support.
Jon G. Hall, Michael Jackson 0001, Robin C. Laney, Bashar Nuseibeh, Lucia Rapanotti
RE4
2002 Lightweight validation of natural language requirements
abstract
Abstract In this paper, we report on our experiences of using lightweight formal methods for the partial validation of natural language requirements documents. We describe our approach to checking properties of models obtained by shallow parsing of natural language requirements, and apply it to a case study based on part of a NASA specification of the Node Control Software on the International Space Station. The experience reported supports our position that it is feasible and useful to perform automated analysis of requirements expressed in natural language. Indeed, we identified a number of errors in our case study that were also independently discovered and corrected by NASA's Independent Validation and Verification Facility in a subsequent version of the same document, and others that were not discovered. The paper describes the techniques we used, the errors we found and reflects on the lessons learned. Copyright © 2001 John Wiley & Sons, Ltd.
Vincenzo Gervasi, Bashar Nuseibeh
Softw. Pract. Exp.2
2001 An Analysis-Revision Cycle to Evolve Requirements Specifications
abstract
We argue that the evolution of requirements specifications can be supported by a cycle composed of two phases: analysis and revision. We investigate an instance of such a cycle, which combines two techniques of logical abduction and inductive learning to analyze and revise specifications respectively.
Artur S. d'Avila Garcez, Alessandra Russo, Bashar Nuseibeh, Jeff Kramer
ASE3
2001 Making inconsistency respectable in software development
Bashar Nuseibeh, Steve M. Easterbrook, Alessandra Russo
J. Syst. Softw.1
2000 Workshop on multi-dimensional separation of concerns in software engineering
abstract
Separation of concerns has been central to software engineering for decades, yet its many advantages are still not fully realized. A key reason is that traditional modularization mechanisms do not allow simultaneous decomposition according to multiple kinds of (overlapping and interacting) concerns. This workshop was intended to bring together researchers working on more advanced modularization mechanisms, and practitioners who have experienced the need for them, as a step towards a common understanding of the issues, problems and research challenges.
Peri L. Tarr, William H. Harrison, Harold Ossher, Anthony Finkelstein, Bashar Nuseibeh, Dewayne E. Perry
ICSE5
2000 Editorial
Bashar Nuseibeh
Autom. Softw. Eng.1
2000 Introduction to Special Issue
Bashar Nuseibeh, David F. Redmiles
Autom. Softw. Eng.1
1999 How Multi-Disciplinary Is RE (really)?
Steve M. Easterbrook, Bashar Nuseibeh
RE2
1999 An Empirical Investigation of Multiple Viewpoint Reasoning in Requirements Engineering
abstract
Multiple viewpoints are often used in Requirements Engineering to facilitate traceability to stakeholders, to structure the requirements process, and to provide richer modelling by incorporating multiple conflicting descriptions. In the latter case, the need to reason with inconsistent models introduces considerable extra complexity. This paper describes an empirical study of the utility of multiple world reasoning (using abduction) for domain modelling. In the study we used a range of different models (ranging from correct to very incorrect), different fanouts, different amounts of data available from the domain, and different modelling primitives for representing time. In the experiments there was no significant change in the expressive power of models that incorporate multiple conflicting viewpoints. Whilst this does not negate the advantages of viewpoints during requirements elicitation, it does suggest some limits to the utility of viewpoints during requirements modelling. 1. Int...
Tim Menzies, Steve M. Easterbrook, Bashar Nuseibeh, Sam Waugh
RE3
1999 Guest Editorial: Introduction to the Special Section - Managing Inconsistency in Software Development
Carlo Ghezzi, Bashar Nuseibeh
IEEE Trans. Software Eng.2
1998 Managing Inconsistent Specifications: Reasoning, Analysis, and Action
abstract
In previous work, we advocated continued development of specifications in the presence of inconsistency. To support this, we used classical logic to represent partial specifications and to identify inconsistencies between them. We now present an adaptation of classical logic, which we term quasi-classical (QC) logic, that allows continued reasoning in the presence of inconsistency. The adaptation is a weakening of classical logic that prohibits all trivial derivations, but still allows all resolvants of the assumptions to be derived. Furthermore, the connectives behave in a classical manner. We then present a development called labeled QC logic that records and tracks assumptions used in reasoning. This facilitates a logical analysis of inconsistent information. We discuss that application of labeled QC logic in the analysis of multiperspective specifications. Such specifications are developed by multiple particpants who hold overlapping, often inconsistent, views of the systems they are developing.
Anthony Hunter, Bashar Nuseibeh
ACM Trans. Softw. Eng. Methodol.2
1997 Making Requirements Measurable (Tutorial)
abstract
No abstract available.
Bashar Nuseibeh, Suzanne Robertson
ICSE1
1997 Analyzing Inconsistent Specifications
abstract
In previous work we advocated continued development of specifications in the presence of inconsistency. To support this we presented quasi-classical (QC) logic for reasoning with inconsistent specifications. The logic allows the derivation of non-trivial classical inferences from inconsistent information. In this paper we present a development called labelled QC logic, and some associated analysis tools, that allows the tracking and diagnosis of inconsistent information. The results of analysis are then used to guide further development in the presence of inconsistency. We illustrate the logic and our tools by specifying and analysing parts of the London Ambulance Service. We argue that the scalability of our approach is made possible by deploying the ViewPoints framework for multi-perspective development, such that our analysis tools are only used on partial specifications of a manageable size.
Anthony Hunter, Bashar Nuseibeh
RE2
1997 Making Requirements Measurable
Bashar Nuseibeh, Suzanne Robertson
RE1
1996 Method engineering for multi-perspective software development
Bashar Nuseibeh, Anthony Finkelstein, Jeff Kramer
Inf. Softw. Technol.1
1996 Conflicting Requirements: When the Customer is Not Always Right
Bashar Nuseibeh
Requir. Eng.1
1995 Decentralised Process Enactment in a Multi-Perspective Development Environment
abstract
The ViewPoints framework for distributed and concurrent software engineering provides an alternative approach to traditional centralised software development environments.WJe investigate the use of decentralised process models to drive consistency checking and conflict resolution in this framework.Our process models use pattern matching on local development histories to determine the particular situation (state) of the development process, and employ rules to trigger situationdependent assistance to the user.We describe how communication between such process models facilitates the decentralised management of explicitly defined consistency constraints in the ViewPoints framework.
Ulf Leonhardt, Jeff Kramer, Bashar Nuseibeh
ICSE3
1995 Managing inconsistencies in an evolving specification
abstract
In an evolving specification, considerable effort is spent handling recurrent inconsistencies. Detecting and resolving inconsistencies is only part of the problem: a resolved inconsistency might not stay resolved. Frameworks in which inconsistency is tolerated help by allowing resolution to be delayed. However, evolution of a specification may affect both resolved and unresolved inconsistencies. We address these problems by explicitly recording relationships between partial specifications (ViewPoints), representing both resolved and unresolved inconsistencies. We assume that ViewPoints will often be inconsistent with one another, and we ensure that a complete work record is kept, detailing any inconsistencies that have been detected, and what actions, if any, have been taken to resolve them. The work record is then used to reason about the effects of subsequent changes to ViewPoints, without constraining the development process.
Steve M. Easterbrook, Bashar Nuseibeh
RE2
1995 Report on the Second IEEE International Symposium on Requirements Engineering (RE '95), York, UK, 27-29 March 1995
Bashar Nuseibeh
Autom. Softw. Eng.1
1994 Inconsistency Handling in Multperspective Specifications
abstract
The development of most large and complex systems necessarily involves many people-each with their own perspectives on the system defined by their knowledge, responsibilities, and commitments. To address this we have advocated distributed development of specifications from multiple perspectives. However, this leads to problems of identifying and handling inconsistencies between such perspectives. Maintaining absolute consistency is not always possible. Often this is not even desirable since this can unnecessarily constrain the development process, and can lead to the loss of important information. Indeed since the real-world forces us to work with inconsistencies, we should formalize some of the usually informal or extra-logical ways of responding to them. This is not necessarily done by eradicating inconsistencies but rather by supplying logical rules specifying how we should act on them. To achieve this, we combine two lines of existing research: the ViewPoints framework for perspective development, interaction and organization, and a logic-based approach to inconsistency handling. This paper presents our technique for inconsistency handling in the ViewPoints framework by using simple examples.>
Anthony Finkelstein, Dov M. Gabbay, Anthony Hunter, Jeff Kramer, Bashar Nuseibeh
IEEE Trans. Software Eng.5
1994 A Framework for Expressing the Relationships Between Multiple Views in Requirements Specification
abstract
Composite systems are generally comprised of heterogeneous components whose specifications are developed by many development participants. The requirements of such systems are invariably elicited from multiple perspectives that overlap, complement, and contradict each other. Furthermore, these requirements are generally developed and specified using multiple methods and notations, respectively. It is therefore necessary to express and check the relationships between the resultant specification fragments. We deploy multiple ViewPoints that hold partial requirements specifications, described and developed using different representation schemes and development strategies. We discuss the notion of inter-ViewPoint communication in the context of this ViewPoints framework, and propose a general model for ViewPoint interaction and integration. We elaborate on some of the requirements for expressing and enacting inter-ViewPoint relationships-the vehicles for consistency checking and inconsistency management. Finally, though we use simple fragments of the requirements specification method CORE to illustrate various components of our work, we also outline a number of larger case studies that we have used to validate our framework. Our computer-based ViewPoints support environment, The Viewer, is also briefly described.>
Bashar Nuseibeh, Jeff Kramer, Anthony Finkelstein
IEEE Trans. Software Eng.1
1993 Expressing the Relationships Between Multiple Views in Requirements Specification
Bashar Nuseibeh, Jeff Kramer, Anthony Finkelstein
ICSE1
1992 Viewpoints: A Framework for Integrating Multiple Perspectives in System Development
abstract
This paper outlines a framework which supports the use of multiple perspectives in system development, and provides a means for developing and applying systems design methods. The framework uses "viewpoints" to partition the system specification, the development method and the formal representations used to express the system specifications. This VOSE (viewpoint-oriented systems engineering) framework can be used to support the design of heterogeneous and composite systems. We illustrate the use of the framework with a small example drawn from composite system development and give an account of prototype automated tools based on the framework.
Anthony Finkelstein, Jeff Kramer, Bashar Nuseibeh, L. Finkelstein, Michael Goedicke
Int. J. Softw. Eng. Knowl. Eng.3