EDBT 2026 Demo / reviewers in the wild / expert
Gerardo Canfora
dblp:63/4434
· DBLP profile ↗
170ranked-venue papers
95as first author
18since 2021 · last 2026
0000-0003-0049-1279ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 140 · 72 first-author · 14 since 2021Security and privacy · 18 · 15 first-author · 2 since 2021Artificial intelligence and machine learning · 16 · 13 first-authorDatabases, data management, data science and information retrieval · 6 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 4 first-authorSystems, architecture and hardware · 3 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Datasets, bias, licenses, and terms of use: A large and longitudinal study on the documentation of hugging face machine learning models
Federica Pepe, Vittoria Nardone, Antonio Mastropaolo, Gerardo Canfora, Gabriele Bavota, Massimiliano Di Penta |
Empir. Softw. Eng. | 4 |
| 2025 | The Future of Software Transparency: Bridging Understanding, Measurement, and PracticeabstractAlthough the study of software transparency has deep roots in software engineering, a shared definition and practical application in real-world development contexts remain elusive. Through an in-depth analysis of the academic and industrial landscape, this article provides an overview of the current state of knowledge on software transparency, outlining a path to a deeper understanding of the subject for both developers and researchers. The challenge of software transparency involves not only establishing a formal, widely accepted understanding within the community, but also measuring and quantifying it in production environments. To this end, we survey academics and developers to evaluate an innovative approach to defining transparency and present a vision of a new framework for its quantification. Gregorio Dalia, Annibale Panichella, Andrea Di Sorbo, Gerardo Canfora, Corrado Aaron Visaggio |
ASE | 4 |
| 2025 | Recovering Traceability Links Between Code and Documentation: A RetrospectiveabstractSoftware system documentation is almost always expressed informally in natural language and free text. Examples include requirement specifications, design documents, manual pages, system development journals, error logs, and related maintenance reports. In our 2002 seminal paper we proposed a method based on information retrieval to recover traceability links between source code and free text documents. A premise of our work was that programmers use meaningful names for program items, such as functions, variables, types, classes, and methods. The paper paved the way to the adoption of IR in software engineering opening a new perspective. Reflecting on the past twenty years we briefly overview the many results that have been achieved, however, the emergence of new technologies, such as AI, pose unprecedented challenges. Giuliano Antoniol, Gerardo Canfora, Gerardo Casazza, Andrea De Lucia, Ettore Merlo |
IEEE Trans. Software Eng. | 2 |
| 2024 | SBOM Ouverture: What We Need and What We HaveabstractA Software Bill of Materials (SBOM) is an inventory of the software components used to build a product, which can help customers track security risks throughout the development lifecycle. The popularity of SBOMs grew in May 2021 when the White House issued an executive order to improve the security of the software supply chain and the transparency of the government’s software inventory. Although the growing interest in SBOM, many open challenges need to be addressed to help reduce exposure to cyber risks and enhance the security of software supply chains. To help the industry and research assemble the roadmap to achieve SBOM adoption in practice, in this paper, we analyze the challenges related to enabling technologies and the open issues that research must investigate. Furthermore, we perform a comparative analysis of the existing tools to generate SBOMs, demonstrating that the enabling technologies have not yet reached full automation and maturity. Gregorio Dalia, Corrado Aaron Visaggio, Andrea Di Sorbo, Gerardo Canfora |
ARES | 4 |
| 2024 | Beyond Words: Stylometric Analysis for Detecting AI Manipulation on Social Media
Sonia Laudanna, P. Vinod 0001, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora |
ESORICS (1) | 6 |
| 2024 | How do Hugging Face Models Document Datasets, Bias, and Licenses? An Empirical StudyabstractPre-trained Machine Learning (ML) models help to create ML-intensive systems without having to spend conspicuous resources on training a new model from the ground up. However, the lack of transparency for such models could lead to undesired consequences in terms of bias, fairness, trustworthiness of the underlying data, and, potentially even legal implications. Taking as a case study the transformer models hosted by Hugging Face, a popular hub for pre-trained ML models, this paper empirically investigates the transparency of pre-trained transformer models. We look at the extent to which model descriptions (i) specify the datasets being used for their pre-training, (ii) discuss their possible training bias, (iii) declare their license, and whether projects using such models take these licenses into account. Results indicate that pre-trained models still have a limited exposure of their training datasets, possible biases, and adopted licenses. Also, we found several cases of possible licensing violations by client projects. Our findings motivate further research to improve the transparency of ML models, which may result in the definition, generation, and adoption of Artificial Intelligence Bills of Materials. Federica Pepe, Vittoria Nardone, Antonio Mastropaolo, Gabriele Bavota, Gerardo Canfora, Massimiliano Di Penta |
ICPC | 5 |
| 2023 | A Novel Classification Technique based on Formal MethodsabstractIn last years, we are witnessing a growing interest in the application of supervised machine learning techniques in the most disparate fields. One winning factor of machine learning is represented by its ability to easily create models, as it does not require prior knowledge about the application domain. Complementary to machine learning are formal methods, that intrinsically offer safeness check and mechanism for reasoning on failures. Considering the weaknesses of machine learning, a new challenge could be represented by the use of formal methods. However, formal methods require the expertise of the domain, knowledge about modeling language with its semantic and mathematical rigour to specify properties. In this article, we propose a novel learning technique based on the adoption of formal methods for classification thanks to the automatic generation both of the formula and of the model. In this way the proposed method does not require any human intervention and thus it can be applied also to complex/large datasets. This leads to less effort both in using formal methods and in a better explainability and reasoning about the obtained results. Through a set of case studies from different real-world domains (i.e., driver detection, scada attack identification, arrhythmia characterization, mobile malware detection, and radiomics for lung cancer analysis), we demonstrate the usefulness of the proposed method, by showing that we are able to overcome the performances obtained from widespread classification algorithms. Gerardo Canfora, Francesco Mercaldo, Antonella Santone |
ACM Trans. Knowl. Discov. Data | 1 |
| 2023 | Continuous Integration and Delivery Practices for Cyber-Physical Systems: An Interview-Based StudyabstractContinuous Integration and Delivery (CI/CD) practices have shown several benefits for software development and operations, such as faster release cycles and early discovery of defects. For Cyber-Physical System (CPS) development, CI/CD can help achieving required goals, such as high dependability, yet it may be challenging to apply. This article empirically investigates challenges, barriers, and their mitigation occurring when applying CI/CD practices to develop CPSs in 10 organizations working in eight different domains. The study has been conducted through semi-structured interviews, by applying an open card sorting procedure together with a member-checking survey within the same organizations, and by validating the results through a further survey involving 55 professional developers. The study reveals several peculiarities in the application of CI/CD to CPSs. These include the need for (i) combining continuous and periodic builds while balancing the use of Hardware-in-the-Loop and simulators, (ii) coping with difficulties in software deployment (iii) accounting for simulators and Hardware-in-the-Loop differing in their behavior, and (vi) combining hardware/software expertise in the development team. Our findings open the road toward recommenders aimed at supporting the setting and evolution of CI/CD pipelines, as well as university curricula requiring interdisciplinarity, such as knowledge about hardware, software, and their interplay. Fiorella Zampetti, Damian A. Tamburri, Sebastiano Panichella, Annibale Panichella, Gerardo Canfora, Massimiliano Di Penta |
ACM Trans. Softw. Eng. Methodol. | 5 |
| 2022 | An empirical investigation on the trade-off between smart contract readability and gas consumptionabstractBlockchain technology is becoming increasingly popular, and smart contracts (i.e., programs that run on top of the blockchain) represent a crucial element of this technology. In particular, smart contracts running on Ethereum (i.e., one of the most popular blockchain platforms) are often developed with Solidity, and their deployment and execution consume gas (i.e., a fee compensating the computing resources required). Smart contract development frequently involves code reuse, but poor readable smart contracts could hinder their reuse. However, writing readable smart contracts is challenging, since practices for improving the readability could also be in contrast with optimization strategies for reducing gas consumption. This paper aims at better understanding (i) the readability aspects for which traditional software and smart contracts differ, and (ii) the specific smart contract readability features exhibiting significant relationships with gas consumption. We leverage a set of metrics that previous research has proven correlated with code readability. In particular, we first compare the values of these metrics obtained for both Solidity smart contracts and traditional software systems (written in Java). Then, we investigate the correlations occurring between these metrics and gas consumption and between each pair of metrics. The results of our study highlight that smart contracts usually exhibit lower readability than traditional software for what concerns the number of parentheses, inline comments, and blank lines used. In addition, we found some readability metrics (such as the average length of identifiers and the average number of keywords) that significantly correlate with gas consumption. Anna Vacca, Michele Fredella, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora |
ICPC | 5 |
| 2022 | A systematic literature review of IoT time series anomaly detection solutions
Arnaldo Sgueglia, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora |
Future Gener. Comput. Syst. | 4 |
| 2022 | Patchworking: Exploring the code changes induced by vulnerability fixing activities
Gerardo Canfora, Andrea Di Sorbo, Sara Forootani, Matias Martinez, Corrado Aaron Visaggio |
Inf. Softw. Technol. | 1 |
| 2022 | Profiling gas consumption in solidity smart contracts
Andrea Di Sorbo, Sonia Laudanna, Anna Vacca, Corrado Aaron Visaggio, Gerardo Canfora |
J. Syst. Softw. | 5 |
| 2021 | iSCREAM: a suite for Smart Contract REAdability assessMentabstractBlockchain is increasingly revolutionizing a variety of sectors, from finance to healthcare. Indeed, the availability of public blockchain platforms, such as Ethereum, has stimulated the development of hundreds of decentralized apps (dApps) that combine smart contract(s) and a front-end user interface. Smart contracts are software, as well, and, as traditional software, they require to be developed and maintained or evolved. Among all the quality properties that must be assessed and guaranteed, readability is a key aspect of source code: a highly readable code facilitates its maintainability, portability, and reusability. This is especially true when considering smart contracts, where code reuse is widely adopted. Indeed, smart contract developers often integrate code portions from other smart contracts in their artifacts. To help developers and researchers more easily estimating and monitoring the code readability of smart contracts, in this demo, we present iSCREAM. iSCREAM automatically inspects Solidity smart contracts and computes a set of metrics that previous research demonstrated being related to code readability. We evaluated iSCREAM on 90 real-world smart contract functions, showing that our tool correctly computes all the aforementioned metrics. Demo webpage: https://github.com/mfredella/iSCREAM Gerardo Canfora, Andrea Di Sorbo, Michele Fredella, Anna Vacca, Corrado Aaron Visaggio |
ICSME | 1 |
| 2021 | An NLP-based Tool for Software Artifacts AnalysisabstractSoftware developers rely on various repositories and communication channels to exchange relevant information about their ongoing tasks and the status of overall project progress. In this context, semi-structured and unstructured software artifacts have been leveraged by researchers to build recommender systems aimed at supporting developers in different tasks, such as transforming user feedback in maintenance and evolution tasks, suggesting experts, or generating software documentation. More specifically, Natural Language (NL) parsing techniques have been successfully leveraged to automatically identify (or extract) the relevant information embedded in unstructured software artifacts. However, such techniques require the manual identification of patterns to be used for classification purposes. To reduce such a manual effort, we propose an NL parsing-based tool for software artifacts analysis named NEON that can automate the mining of such rules, minimizing the manual effort of developers and researchers. Through a small study involving human subjects with NL processing and parsing expertise, we assess the performance of NEON in identifying rules useful to classify app reviews for software maintenance purposes. Our results show that more than one-third of the rules inferred by NEON are relevant for the proposed task. Demo webpage: https://github.com/adisorbo/NEON_tool Andrea Di Sorbo, Corrado Aaron Visaggio, Massimiliano Di Penta, Gerardo Canfora, Sebastiano Panichella |
ICSME | 4 |
| 2021 | "Won't We Fix this Issue?" Qualitative characterization and automated identification of wontfix issues on GitHubabstract: Addressing user requests in the form of bug reports and Github issues represents a crucial task of any successful software project. However, user-submitted issue reports tend to widely differ in their quality, and developers spend a considerable amount of time handling them. : By collecting a dataset of around 6,000 issues of 279 GitHub projects, we observe that developers take significant time (i.e., about five months, on average) before labeling an issue as a wontfix. For this reason, in this paper, we empirically investigate the nature of wontfix issues and methods to facilitate issue management process. : We first manually analyze a sample of 667 wontfix issues, extracted from heterogeneous projects, investigating the common reasons behind a “wontfix decision”, the main characteristics of wontfix issues and the potential factors that could be connected with the time to close them. Furthermore, we experiment with approaches enabling the prediction of wontfix issues by analyzing the titles and descriptions of reported issues when submitted. : Our investigation sheds some light on the wontfix issues’ characteristics, as well as the potential factors that may affect the time required to make a “wontfix decision”. Our results also demonstrate that it is possible to perform prediction of wontfix issues with high average values of precision, recall, and F-measure (90%–93%). Sebastiano Panichella, Gerardo Canfora, Andrea Di Sorbo |
Inf. Softw. Technol. | 2 |
| 2021 | A systematic literature review of blockchain and smart contract development: Techniques, tools, and open challenges
Anna Vacca, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora |
J. Syst. Softw. | 4 |
| 2021 | Predicting issue types on GitHub
Rafael Kallis, Andrea Di Sorbo, Gerardo Canfora, Sebastiano Panichella |
Sci. Comput. Program. | 3 |
| 2021 | Exploiting Natural Language Structures in Software Informal DocumentationabstractCommunication means, such as issue trackers, mailing lists, Q&A forums, and app reviews, are premier means of collaboration among developers, and between developers and end-users. Analyzing such sources of information is crucial to build recommenders for developers, for example suggesting experts, re-documenting source code, or transforming user feedback in maintenance and evolution strategies for developers. To ease this analysis, in previous work we proposed Development Emails Content Analyzer (DECA), a tool based on Natural Language Parsing that classifies with high precision development emails' fragments according to their purpose. However, DECA has to be trained through a manual tagging of relevant patterns, which is often effort-intensive, error-prone and requires specific expertise in natural language parsing. In this paper, we first show, with an empirical study, the extent to which producing rules for identifying such patterns requires effort, depending on the nature and complexity of patterns. Then, we propose an approach, named Nlp-based softwarE dOcumentation aNalyzer (NEON), that automatically mines such rules, minimizing the manual effort. We assess the performances of NEON in the analysis and classification of mobile app reviews, developers discussions, and issues. NEON simplifies the patterns identification and rules definition processes, allowing a savings of more than 70 percent of the time otherwise spent on performing such activities manually. Results also show that NEON-generated rules are close to the manually identified ones, achieving comparable recall. Andrea Di Sorbo, Sebastiano Panichella, Corrado Aaron Visaggio, Massimiliano Di Penta, Gerardo Canfora, Harald C. Gall |
IEEE Trans. Software Eng. | 5 |
| 2020 | Detecting Video Game-Specific Bad Smells in Unity ProjectsabstractThe growth of the video game market, the large proportion of games targeting mobile devices or streaming services, and the increasing complexity of video games trigger the availability of video game-specific tools to assess performance and maintainability problems. This paper proposes UnityLinter, a static analysis tool that supports Unity video game developers to detect seven types of bad smells we have identified as relevant in video game development. Such smell types pertain to performance, maintainability and incorrect behavior problems. After having defined the smells by analyzing the existing literature and discussion forums, we have assessed their relevance with a survey involving 68 participants. Then, we have analyzed the occurrence of the studied smells in 100 open-source Unity projects, and also assessed UnityLinter's accuracy. Results of our empirical investigation indicate that developers well-received performance- and behavior-related issues, while some maintainability issues are more controversial. UnityLinter is, in general, accurate enough in detecting smells (86%-100% precision and 50%-100% recall), and our study shows that the studied smell types occur in 39%-97% of the analyzed projects. Antonio Borrelli, Vittoria Nardone, Giuseppe A. Di Lucca, Gerardo Canfora, Massimiliano Di Penta |
MSR | 4 |
| 2020 | About the Robustness and Looseness of Yara Rules
Gerardo Canfora, Mimmo Carapella, Andrea Del Vecchio, Laura Nardi, Antonio Pirozzi, Corrado Aaron Visaggio |
ICTSS | 1 |
| 2020 | Investigating the vulnerability fixing process in OSS projects: Peculiarities and challenges
Gerardo Canfora, Andrea Di Sorbo, Sara Forootani, Antonio Pirozzi, Corrado Aaron Visaggio |
Comput. Secur. | 1 |
| 2020 | An empirical characterization of bad practices in continuous integration
Fiorella Zampetti, Carmine Vassallo, Sebastiano Panichella, Gerardo Canfora, Harald C. Gall, Massimiliano Di Penta |
Empir. Softw. Eng. | 4 |
| 2020 | Demystifying the adoption of behavior-driven development in open source projects
Fiorella Zampetti, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora, Massimiliano Di Penta |
Inf. Softw. Technol. | 4 |
| 2019 | Ticket Tagger: Machine Learning Driven Issue ClassificationabstractSoftware maintenance is crucial for software projects evolution and success: code should be kept up-to-date and error-free, this with little effort and continuous updates for the end-users. In this context, issue trackers are essential tools for creating, managing and addressing the several (often hundreds of) issues that occur in software systems. A critical aspect for handling and prioritizing issues involves the assignment of labels to them (e.g., for projects hosted on GitHub), in order to determine the type (e.g., bug report, feature request and so on) of each specific issue. Although this labeling process has a positive impact on the effectiveness of issue processing, the current labeling mechanism is scarcely used on GitHub. In this demo, we introduce a tool, called Ticket Tagger, which leverages machine learning strategies on issue titles and descriptions for automatically labeling GitHub issues. Ticket Tagger automatically predicts the labels to assign to issues, with the aim of stimulating the use of labeling mechanisms in software projects, this to facilitate the issue management and prioritization processes. Along with the presentation of the tool's architecture and usage, we also evaluate its effectiveness in performing the issue labeling/classification process, which is critical to help maintainers to keep control of their workloads by focusing on the most critical issue tickets. Rafael Kallis, Andrea Di Sorbo, Gerardo Canfora, Sebastiano Panichella |
ICSME | 3 |
| 2019 | A Study on the Interplay between Pull Request Review and Continuous Integration BuildsabstractModern code review (MCR) is nowadays well-adopted in industrial and open source projects. Recent studies have investigated how developers perceive its ability to foster code quality, developers' code ownership, and team building. MCR is often being used with automated quality checks through static analysis tools, testing or, ultimately, through automated builds on a Continuous Integration (CI) infrastructure. With the aim of understanding how developers use the outcome of CI builds during code review and, more specifically, during the discussion of pull requests, this paper empirically investigates the interplay between pull request discussion and the use of CI by means of 64,865 pull request discussions belonging to 69 open source projects. After having analyzed to what extent a build outcome in uences the pull request merger, we qualitatively analyze the content of 857 pull request discussions. Also, we complement such an analysis with a survey involving 13 developers. While pull requests with passed build have a higher chance of being merged than failed ones, and while survey participants confirmed this quantitative finding, other process-related factors play a more important role in the pull request merge decision. Also, the survey participants point out cases where a pull request can be merged in presence of a CI failure, e.g., when a new pull request is opened to cope with the failure, when the failure is due to minor static analysis warnings. The study also indicates that CI introduces extra complexity, as in many pull requests developers have to solve non-trivial CI configuration issues. Fiorella Zampetti, Gabriele Bavota, Gerardo Canfora, Massimiliano Di Penta |
SANER | 3 |
| 2019 | Summarizing vulnerabilities' descriptions to support experts during vulnerability assessment activities
Ernesto Rosario Russo, Andrea Di Sorbo, Corrado Aaron Visaggio, Gerardo Canfora |
J. Syst. Softw. | 4 |
| 2019 | LEILA: Formal Tool for Identifying Mobile Malicious BehaviourabstractWith the increasing diffusion of mobile technologies, nowadays mobile devices represent an irreplaceable tool to perform several operations, from posting a status on a social network to transfer money between bank accounts. As a consequence, mobile devices store a huge amount of private and sensitive information and this is the reason why attackers are developing very sophisticated techniques to extort data and money from our devices. This paper presents the design and the implementation of LEILA (formaL tool for idEntifying mobIle maLicious behAviour), a tool targeted at Android malware families detection. LEILA is based on a novel approach that exploits model checking to analyse and verify the Java Bytecode that is produced when the source code is compiled. After a thorough description of the method used for Android malware families detection, we report the experiments we have conducted using LEILA. The experiments demonstrated that the tool is effective in detecting malicious behaviour and, especially, in localizing the payload within the code: we evaluated real-world malware belonging to several widespread families obtaining an accuracy ranging between 0.97 and 1. Gerardo Canfora, Fabio Martinelli, Francesco Mercaldo, Vittoria Nardone, Antonella Santone, Corrado Aaron Visaggio |
IEEE Trans. Software Eng. | 1 |
| 2018 | A Nlp-based Solution to Prevent from Privacy Leaks in Social Network PostsabstractPrivate and sensitive information is often revealed in posts appearing in Social Networks (SN). This is due to the users' willingness to increase their interactions within specific social groups, but also to a poor knowledge about the risks for privacy. We argue that technologies able to evaluate the sensitiveness of information while it is being published could enhance privacy protection by warning the user about the risks deriving from the disclosure of a certain information. To this aim, we propose a method, and an accompanying tool, to automatically intercept the sensitive information which is delivered in a social network post, through the exploitation of recurrent natural language patterns that are often used by users to disclose private data. A comparison with several machine learning techniques reveals that our method outperforms them, since it is more precise, accurate and not dependent on (i) a specific training set, or (ii) the selection of particular features. Gerardo Canfora, Andrea Di Sorbo, Enrico Emanuele, Sara Forootani, Corrado Aaron Visaggio |
ARES | 1 |
| 2018 | Estimating the number of remaining links in traceability recovery (journal-first abstract)abstractAlthough very important in software engineering, establishing traceability links between software artifacts is extremely tedious, error-prone, and it requires significant effort. Even when approaches for automated traceability recovery exist, these provide the requirements analyst with a, usually very long, ranked list of candidate links that needs to be manually inspected. In this paper we introduce an approach called Estimation of the Number of Remaining Links (ENRL) which aims at estimating, via Machine Learning (ML) classifiers, the number of remaining positive links in a ranked list of candidate traceability links produced by a Natural Language Processing techniques-based recovery approach. We have evaluated the accuracy of the ENRL approach by considering several ML classifiers and NLP techniques on three datasets from industry and academia, and concerning traceability links among different kinds of software artifacts including requirements, use cases, design documents, source code, and test cases. Results from our study indicate that: (i) specific estimation models are able to provide accurate estimates of the number of remaining positive links; (ii) the estimation accuracy depends on the choice of the NLP technique, and (iii) univariate estimation models outperform multivariate ones. Davide Falessi, Massimiliano Di Penta, Gerardo Canfora, Giovanni Cantone |
ASE | 3 |
| 2018 | The relation between developers' communication and fix-Inducing changes: An empirical study
Mario Luca Bernardi, Gerardo Canfora, Giuseppe A. Di Lucca, Massimiliano Di Penta, Damiano Distante |
J. Syst. Softw. | 2 |
| 2017 | How open source projects use static code analysis tools in continuous integration pipelinesabstractStatic analysis tools are often used by software developers to entail early detection of potential faults, vulnerabilities, code smells, or to assess the source code adherence to coding standards and guidelines. Also, their adoption within Continuous Integration (CI) pipelines has been advocated by researchers and practitioners. This paper studies the usage of static analysis tools in 20 Java open source projects hosted on GitHub and using Travis CI as continuous integration infrastructure. Specifically, we investigate (i) which tools are being used and how they are configured for the CI, (ii) what types of issues make the build fail or raise warnings, and (iii) whether, how, and after how long are broken builds and warnings resolved. Results indicate that in the analyzed projects build breakages due to static analysis tools are mainly related to adherence to coding standards, and there is also some attention to missing licenses. Build failures related to tools identifying potential bugs or vulnerabilities occur less frequently, and in some cases such tools are activated in a "softer" mode, without making the build fail. Also, the study reveals that build breakages due to static analysis tools are quickly fixed by actually solving the problem, rather than by disabling the warning, and are often properly documented. Fiorella Zampetti, Simone Scalabrino, Rocco Oliveto, Gerardo Canfora, Massimiliano Di Penta |
MSR | 4 |
| 2017 | Mobile Silent and Continuous Authentication using Apps Sequence
Gerardo Canfora, Giovanni Cappabianca, Pasquale Carangelo, Fabio Martinelli, Francesco Mercaldo, Ernesto Rosario Russo, Corrado Aaron Visaggio |
SECRYPT | 1 |
| 2017 | s2ipt: A Lightweight Network Intrusion Detection/Prevention System based on IPtablesabstractSince each organization has its own security culture and background, there is not an out-of-the-box solution that fits all the possible security requirements.There may be some contexts in which it is necessary to monitor and prevent certain application-level attacks with less impact on pre-existent configuration.For example, there may be some constraints on processing resources of some embedded devices.Starting from this consideration, we developed s2ipt, a python-powered tool which aims to implement a lightweight Netfilter-based network intrusion detection and prevention system (IDS/IPS) by translating Snort community rules into iptables rulesset.s2ipt utilizes the netfilter string matching module to detect application-level attacks.Netfilter reduces the impact on a system, has less memory and CPU footprint, which makes it suitable to run even on low-cost devices than a solution like Snort.s2ipt allows iptables to detect application layer attacks in a transparent way, in fact it only adds new application layer ruleset leaving the existing ones unchanged. Gerardo Canfora, Antonio Pirozzi, Corrado Aaron Visaggio |
SECRYPT | 1 |
| 2017 | Estimating the number of remaining links in traceability recovery
Davide Falessi, Massimiliano Di Penta, Gerardo Canfora, Giovanni Cantone |
Empir. Softw. Eng. | 3 |
| 2017 | Editorial: A five year retrospectiveabstractNon peer reviewed Gerardo Canfora, Darren Dalcher, David Raffo |
J. Softw. Evol. Process. | 1 |
| 2017 | ARENA: An Approach for the Automated Generation of Release NotesabstractRelease notes document corrections, enhancements, and, in general, changes that were implemented in a new release of a software project. They are usually created manually and may include hundreds of different items, such as descriptions of new features, bug fixes, structural changes, new or deprecated APIs, and changes to software licenses. Thus, producing them can be a time-consuming and daunting task. This paper describes ARENA (Automatic RElease Notes generAtor), an approach for the automatic generation of release notes. ARENA extracts changes from the source code, summarizes them, and integrates them with information from versioning systems and issue trackers. ARENA was designed based on the manual analysis of 990 existing release notes. In order to evaluate the quality of the release notes automatically generated by ARENA, we performed four empirical studies involving a total of 56 participants (48 professional developers and eight students). The obtained results indicate that the generated release notes are very good approximations of the ones manually produced by developers and often include important information that is missing in the manually created release notes. Laura Moreno, Gabriele Bavota, Massimiliano Di Penta, Rocco Oliveto, Andrian Marcus, Gerardo Canfora |
IEEE Trans. Software Eng. | 6 |
| 2016 | Exploring Mobile User Experience Through Code Quality Metrics
Gerardo Canfora, Andrea Di Sorbo, Francesco Mercaldo, Corrado Aaron Visaggio |
PROFES | 1 |
| 2016 | How I Met Your Mother? - An Empirical Study about Android Malware PhylogenesisabstractAndroid malware is becoming more and more aggressive, in terms of impact on the victim’s device and in terms of capability of evading detection. Not only smartphones with their sensitive information are targeted by attackers, but also devices such as watches, glasses and everything that can be connected to the Internet of Things. Current signature based antimalware or anomaly based detection are not able to detect zero-day attacks: even trivial code transformation can overcome detection. New malware is often not really new: malware writers are used to add functionality to existing malware, or merge different pieces of existing malware code: this determines the families of Android malware i.e. malware programs that have in common some essential features or behaviors and modify some other parts. To be able to recognize the malware familiy a malware belongs to is useful for malware analysis, fast infection response, and quick incident resolution. In this paper we introduce DescentDroid, a tool that traces back the malware descendant family. We experiment our technique with an extended dataset comprising malware and trusted applications, obtaining high precision in recognizing the malware family membership. Gerardo Canfora, Francesco Mercaldo, Antonio Pirozzi, Corrado Aaron Visaggio |
SECRYPT | 1 |
| 2016 | Silent and Continuous Authentication in Mobile EnvironmentabstractDue to the increasing pervasiveness of mobile technologies, sensitive user information is often stored on
mobile devices. Nowadays, mobile devices do not continuously verify the identity of the user while sensitive
activities are performed. This enables attackers full access to sensitive data and applications on the device, if
they obtain the password or grab the device after login. In order to mitigate this risk, we propose a continuous
and silent monitoring process based on a set of features: orientation, touch and cell tower. The underlying
assumption is that the features are representative of smartphone owner behaviour and this is the reason why
the features can be useful to discriminate the owner by an impostor. Results show that our system, modeling
the user behavior of 21 volunteer participants, obtains encouraging results, since we measured a precision in
distinguishing an impostor from the owner between 99% and 100%. Gerardo Canfora, Paolo Di Notte, Francesco Mercaldo, Corrado Aaron Visaggio |
SECRYPT | 1 |
| 2016 | ARdoc: app reviews development oriented classifierabstractGoogle Play, Apple App Store and Windows Phone Store are well known distribution platforms where users can download mobile apps, rate them and write review comments about the apps they are using. Previous research studies demonstrated that these reviews contain important information to help developers improve their apps. However, analyzing reviews is challenging due to the large amount of reviews posted every day, the unstructured nature of reviews and its varying quality. Sebastiano Panichella, Andrea Di Sorbo, Emitza Guzman, Corrado Aaron Visaggio, Gerardo Canfora, Harald C. Gall |
SIGSOFT FSE | 5 |
| 2016 | What would users change in my app? summarizing app reviews for recommending software changesabstractMobile app developers constantly monitor feedback in user reviews with the goal of improving their mobile apps and better meeting user expectations. Thus, automated approaches have been proposed in literature with the aim of reducing the effort required for analyzing feedback contained in user reviews via automatic classification/prioritization according to specific topics. In this paper, we introduce SURF (Summarizer of User Reviews Feedback), a novel approach to condense the enormous amount of information that developers of popular apps have to manage due to user feedback received on a daily basis. SURF relies on a conceptual model for capturing user needs useful for developers performing maintenance and evolution tasks. Then it uses sophisticated summarisation techniques for summarizing thousands of reviews and generating an interactive, structured and condensed agenda of recommended software changes. We performed an end-to-end evaluation of SURF on user reviews of 17 mobile apps (5 of them developed by Sony Mobile), involving 23 developers and researchers in total. Results demonstrate high accuracy of SURF in summarizing reviews and the usefulness of the recommended changes. In evaluating our approach we found that SURF helps developers in better understanding user needs, substantially reducing the time required by developers compared to manually analyzing user (change) requests and planning future software changes. Andrea Di Sorbo, Sebastiano Panichella, Carol V. Alexandru, Junji Shimagaki, Corrado Aaron Visaggio, Gerardo Canfora, Harald C. Gall |
SIGSOFT FSE | 6 |
| 2016 | An HMM and structural entropy based detector for Android malware: An empirical study
Gerardo Canfora, Francesco Mercaldo, Corrado Aaron Visaggio |
Comput. Secur. | 1 |
| 2015 | Effectiveness of Opcode ngrams for Detection of Multi Family Android MalwareabstractWith the wide diffusion of smartphones and their usage in a plethora of processes and activities, these devices have been handling an increasing variety of sensitive resources. Attackers are hence producing a large number of malware applications for Android (the most spread mobile platform), often by slightly modifying existing applications, which results in malware being organized in families. Some works in the literature showed that opcodes are informative for detecting malware, not only in the Android platform. In this paper, we investigate if frequencies of ngrams of opcodes are effective in detecting Android malware and if there is some significant malware family for which they are more or less effective. To this end, we designed a method based on state-of-the-art classifiers applied to frequencies of opcodes ngrams. Then, we experimentally evaluated it on a recent dataset composed of 11120 applications, 5560 of which are malware belonging to several different families. Results show that an accuracy of 97% can be obtained on the average, whereas perfect detection rate is achieved for more than one malware family. Gerardo Canfora, Andrea De Lorenzo, Eric Medvet, Francesco Mercaldo, Corrado Aaron Visaggio |
ARES | 1 |
| 2015 | Composition-Malware: Building Android Malware at Run TimeabstractWe present a novel model of malware for Android, named composition-malware, which consists of composing fragments of code hosted on different and scattered locations at run time. An key feature of the model is that the malicious behavior could dynamically change and the payload could be activated under logic or temporal conditions. These characteristics allow a malware written according to this model to evade current malware detection technologies for Android platform, as the evaluation has demonstrated. The aim of the paper is to propose new approaches to malware detection that should be adopted in anti-malware tools for blocking a composition-malware. Gerardo Canfora, Francesco Mercaldo, Giovanni Moriano, Corrado Aaron Visaggio |
ARES | 1 |
| 2015 | How can i improve my app? Classifying user reviews for software maintenance and evolutionabstractApp Stores, such as Google Play or the Apple Store, allow users to provide feedback on apps by posting review comments and giving star ratings. These platforms constitute a useful electronic mean in which application developers and users can productively exchange information about apps. Previous research showed that users feedback contains usage scenarios, bug reports and feature requests, that can help app developers to accomplish software maintenance and evolution tasks. However, in the case of the most popular apps, the large amount of received feedback, its unstructured nature and varying quality can make the identification of useful user feedback a very challenging task. In this paper we present a taxonomy to classify app reviews into categories relevant to software maintenance and evolution, as well as an approach that merges three techniques: (1) Natural Language Processing, (2) Text Analysis and (3) Sentiment Analysis to automatically classify app reviews into the proposed categories. We show that the combined use of these techniques allows to achieve better results (a precision of 75% and a recall of 74%) than results obtained using each technique individually (precision of 70% and a recall of 67%). Sebastiano Panichella, Andrea Di Sorbo, Emitza Guzman, Corrado Aaron Visaggio, Gerardo Canfora, Harald C. Gall |
ICSME | 5 |
| 2015 | Development Emails Content Analyzer: Intention Mining in Developer Discussions (T)abstractWritten development communication (e.g. mailing lists, issue trackers) constitutes a precious source of information to build recommenders for software engineers, for example aimed at suggesting experts, or at redocumenting existing source code. In this paper we propose a novel, semi-supervised approach named DECA (Development Emails Content Analyzer) that uses Natural Language Parsing to classify the content of development emails according to their purpose (e.g. feature request, opinion asking, problem discovery, solution proposal, information giving etc), identifying email elements that can be used for specific tasks. A study based on data from Qt and Ubuntu, highlights a high precision (90%) and recall (70%) of DECA in classifying email content, outperforming traditional machine learning strategies. Moreover, we successfully used DECA for re-documenting source code of Eclipse and Lucene, improving the recall, while keeping high precision, of a previous approach based on ad-hoc heuristics. Andrea Di Sorbo, Sebastiano Panichella, Corrado Aaron Visaggio, Massimiliano Di Penta, Gerardo Canfora, Harald C. Gall |
ASE | 5 |
| 2015 | Mobile Malware Detection using Op-code Frequency HistogramsabstractMobile malware has grown in scale and complexity, as a consequence of the unabated uptake of smartphones worldwide. Malware writers have been developing detection evasion techniques which are rapidly making anti-malware technologies uneffective. In particular, zero-days malware is able to easily pass signature based detection, while dynamic analysis based techniques, which could be more accurate and robust, are too costly or inappropriate to real contexts, especially for reasons related to usability. This paper discusses a technique for discriminating Android malware from trusted applications that does not rely on signature, but on identifying a vector of features obtained from the static analysis of the Android's Dalvik code. Experimentation accomplished on a sample of 11,200 applications revealed that the proposed technique produces high precision (over 93%) in mobile malware detection, with an accuracy of 95%. Gerardo Canfora, Francesco Mercaldo, Corrado Aaron Visaggio |
SECRYPT | 1 |
| 2015 | How the Apache community upgrades dependencies: an evolutionary study
Gabriele Bavota, Gerardo Canfora, Massimiliano Di Penta, Rocco Oliveto, Sebastiano Panichella |
Empir. Softw. Eng. | 2 |
| 2015 | Irish: A Hidden Markov Model to detect coded information islands in free text
Luigi Cerulo, Massimiliano Di Penta, Alberto Bacchelli, Michele Ceccarelli, Gerardo Canfora |
Sci. Comput. Program. | 5 |
| 2015 | Improving data-intensive EDA performance with annotation-driven laziness
Quirino Zagarese, Gerardo Canfora, Eugenio Zimeo, Iyad Alshabani, Laurent Pellegrino, Amjad Alshabani, Françoise Baude |
Sci. Comput. Program. | 2 |
| 2015 | Defect prediction as a multiobjective optimization problemabstractSummary In this paper, we formalize the defect‐prediction problem as a multiobjective optimization problem. Specifically, we propose an approach, coined as multiobjective defect predictor (MODEP), based on multiobjective forms of machine learning techniques—logistic regression and decision trees specifically—trained using a genetic algorithm. The multiobjective approach allows software engineers to choose predictors achieving a specific compromise between the number of likely defect‐prone classes or the number of defects that the analysis would likely discover (effectiveness), and lines of code to be analysed/tested (which can be considered as a proxy of the cost of code inspection). Results of an empirical evaluation on 10 datasets from the PROMISE repository indicate the quantitative superiority of MODEP with respect to single‐objective predictors, and with respect to trivial baseline ranking classes by size in ascending or descending order. Also, MODEP outperforms an alternative approach for cross‐project prediction, based on local prediction upon clusters of similar classes. Copyright © 2015 John Wiley & Sons, Ltd. Gerardo Canfora, Andrea De Lucia, Massimiliano Di Penta, Rocco Oliveto, Annibale Panichella, Sebastiano Panichella |
Softw. Test. Verification Reliab. | 1 |
| 2014 | How Developers' Collaborations Identified from Different Sources Tell Us about Code ChangesabstractWritten communications recorded through channels such as mailing lists or issue trackers, but also code co-changes, have been used to identify emerging collaborations in software projects. Also, such data has been used to identify the relation between developers' roles in communication networks and source code changes, or to identify mentors aiding newcomers to evolve the software project. However, results of such analyses may be different depending on the communication channel being mined. This paper investigates how collaboration links vary and complement each other when they are identified through data from three different kinds of communication channels, i.e., mailing lists, issue trackers, and IRC chat logs. Also, the study investigates how such links overlap with links mined from code changes, and how the use of different sources would influence (i) the identification of project mentors, and (ii) the presence of a correlation between the social role of a developer and her changes. Results of a study conducted on seven open source projects indicate that the overlap of communication links between the various sources is relatively low, and that the application of networks obtained from different sources may lead to different results. Sebastiano Panichella, Gabriele Bavota, Massimiliano Di Penta, Gerardo Canfora, Giuliano Antoniol |
ICSME | 4 |
| 2014 | How the evolution of emerging collaborations relates to code changes: an empirical studyabstractDevelopers contributing to open source projects spontaneously group into "emerging'' teams, reflected by messages exchanged over mailing lists, issue trackers and other communication means. Previous studies suggested that such teams somewhat mirror the software modularity. This paper empirically investigates how, when a project evolves, emerging teams re-organize themselves-e.g., by splitting or merging. We relate the evolution of teams to the files they change, to investigate whether teams split to work on cohesive groups of files. Results of this study-conducted on the evolution history of four open source projects, namely Apache httpd, Eclipse JDT, Netbeans, and Samba-provide indications of what happens in the project when teams reorganize. Specifically, we found that emerging team splits imply working on more cohesive groups of files and emerging team merges imply working on groups of files that are cohesive from structural perspective. Such indications serve to better understand the evolution of software projects. More important, the observation of how emerging teams change can serve to suggest software remodularization actions. Sebastiano Panichella, Gerardo Canfora, Massimiliano Di Penta, Rocco Oliveto |
ICPC | 2 |
| 2014 | CODES: mining source code descriptions from developers discussionsabstractProgram comprehension is a crucial activity, preliminary to any software maintenance task. Such an activity can be difficult when the source code is not adequately documented, or the documentation is outdated. Differently from the many existing software re-documentation approaches, based on different kinds of code analysis, this paper describes CODES (mining sourCe cOde Descriptions from developErs diScussions), a tool which applies a "social'' approach to software re-documentation. Specifically, CODES extracts candidate method documentation from StackOverflow discussions, and creates Javadoc descriptions from it. We evaluated CODES to mine Lucene and Hibernate method descriptions. The results indicate that CODES is able to extract descriptions for 20% and 28% of the Lucene and Hibernate methods with a precision of 84% and 91% respectively. Carmine Vassallo, Sebastiano Panichella, Massimiliano Di Penta, Gerardo Canfora |
ICPC | 4 |
| 2014 | Recommending refactorings based on team co-maintenance patternsabstractRefactoring aims at restructuring existing source code when undisciplined development activities have deteriorated its comprehensibility and maintainability. There exist various approaches for suggesting refactoring opportunities, based on different sources of information, e.g., structural, semantic, and historical. In this paper we claim that an additional source of information for identifying refactoring opportunities, sometimes orthogonal to the ones mentioned above, is team development activity. When the activity of a team working on common modules is not aligned with the current design structure of a system, it would be possible to recommend appropriate refactoring operations---e.g., extract class/method/package---to adjust the design according to the teams' activity patterns. Results of a preliminary study---conducted in the context of extract class refactoring---show the feasibility of the approach, and also suggest that this new refactoring dimension can be complemented with others to build better refactoring recommendation tools. Gabriele Bavota, Sebastiano Panichella, Nikolaos Tsantalis, Massimiliano Di Penta, Rocco Oliveto, Gerardo Canfora |
ASE | 6 |
| 2014 | Automatic generation of release notesabstractThis paper introduces ARENA (Automatic RElease Notes generAtor), an approach for the automatic generation of release notes. ARENA extracts changes from the source code, summarizes them, and integrates them with information from versioning systems and issue trackers. It was designed based on the manual analysis of 1,000 existing release notes. To evaluate the quality of the ARENA release notes, we performed three empirical studies involving a total of 53 participants (45 professional developers and 8 students). The results indicate that the ARENA release notes are very good approximations of those produced by developers and often include important information that is missing in the manually produced release notes. Laura Moreno, Gabriele Bavota, Massimiliano Di Penta, Rocco Oliveto, Andrian Marcus, Gerardo Canfora |
SIGSOFT FSE | 6 |
| 2014 | How changes affect software entropy: an empirical study
Gerardo Canfora, Luigi Cerulo, Marta Cimitile, Massimiliano Di Penta |
Empir. Softw. Eng. | 1 |
| 2013 | A Classifier of Malicious Android ApplicationsabstractMalware for smart phones is rapidly spreading out. This paper proposes a method for detecting malware based on three metrics, which evaluate: the occurrences of a specific subset of system calls, a weighted sum of a subset of permissions that the application required, and a set of combinations of permissions. The experimentation carried out suggests that these metrics are promising in detecting malware, but further improvements are needed to increase the quality of detection. Gerardo Canfora, Francesco Mercaldo, Corrado Aaron Visaggio |
ARES | 1 |
| 2013 | An approach for restructuring text contentabstractSoftware engineers have successfully used Natural Language Processing for refactoring source code. Conversely, in this paper we investigate the possibility to apply software refactoring techniques to textual content. As a procedural program is composed of functions calling each other, a document can be modeled as content fragments connected each other through links. Inspired by software engineering refactoring strategies, we propose an approach for refactoring wiki content. The approach has been applied to the EMF category of Eclipsepedia with encouraging results. Lerina Aversano, Gerardo Canfora, Giuseppe De Ruvo, Maria Tortorella |
ICSE | 2 |
| 2013 | YODA: young and newcomer developer assistantabstractMentoring project newcomers is a crucial activity in software projects, and requires to identify people having good communication and teaching skills, other than high expertise on specific technical topics. In this demo we present Yoda (Young and newcOmer Developer Assistant), an Eclipse plugin that identifies and recommends mentors for newcomers joining a software project. Yoda mines developers' communication (e.g., mailing lists) and project versioning systems to identify mentors using an approach inspired to what ArnetMiner does when mining advisor/student relations. Then, it recommends appropriate mentors based on the specific expertise required by the newcomer. The demo shows Yoda in action, illustrating how the tool is able to identify and visualize mentoring relations in a project, and suggest appropriate mentors for a developer who is going to work on certain source code files, or on a given topic. Demo URL: http://youtu.be/4yrbYT-LAXA. Gerardo Canfora, Massimiliano Di Penta, Stefano Giannantonio, Rocco Oliveto, Sebastiano Panichella |
ICSE | 1 |
| 2013 | An Empirical Investigation on Documentation Usage Patterns in Maintenance TasksabstractWhen developers perform a software maintenance task, they need to identify artifacts-e.g., classes or more specifically methods-that need to be modified. To this aim, they can browse various kind of artifacts, for example use case descriptions, UML diagrams, or source code. This paper reports the results of a study-conducted with 33 participants- aimed at investigating (i) to what extent developers use different kinds of documentation when identifying artifacts to be changed, and (ii) whether they follow specific navigation patterns among different kinds of artifacts. Results indicate that, although participants spent a conspicuous proportion of the available time by focusing on source code, they browse back and forth between source code and either static (class) or dynamic (sequence) diagrams. Less frequently, participants-especially more experienced ones-follow an "integrated" approach by using different kinds of artifacts. Gabriele Bavota, Gerardo Canfora, Massimiliano Di Penta, Rocco Oliveto, Sebastiano Panichella |
ICSM | 2 |
| 2013 | The Evolution of Project Inter-dependencies in a Software Ecosystem: The Case of ApacheabstractSoftware ecosystems consist of multiple software projects, often interrelated each other by means of dependency relations. When one project undergoes changes, other projects may decide to upgrade the dependency. For example, a project could use a new version of another project because the latter has been enhanced or subject to some bug-fixing activities. This paper reports an exploratory study aimed at observing the evolution of the Java subset of the Apache ecosystem, consisting of 147 projects, for a period of 14 years, and resulting in 1,964 releases. Specifically, we analyze (i) how dependencies change over time, (ii) whether a dependency upgrade is due to different kinds of factors, such as different kinds of API changes or licensing issues, and (iii) how an upgrade impacts on a related project. Results of this study help to comprehend the phenomenon of library/component upgrade, and provides the basis for a new family of recommenders aimed at supporting developers in the complex (and risky) activity of managing library/component upgrade within their software projects. Gabriele Bavota, Gerardo Canfora, Massimiliano Di Penta, Rocco Oliveto, Sebastiano Panichella |
ICSM | 2 |
| 2013 | Multi-objective Cross-Project Defect PredictionabstractCross-project defect prediction is very appealing because (i) it allows predicting defects in projects for which the availability of data is limited, and (ii) it allows producing generalizable prediction models. However, existing research suggests that cross-project prediction is particularly challenging and, due to heterogeneity of projects, prediction accuracy is not always very good. This paper proposes a novel, multi-objective approach for cross-project defect prediction, based on a multi-objective logistic regression model built using a genetic algorithm. Instead of providing the software engineer with a single predictive model, the multi-objective approach allows software engineers to choose predictors achieving a compromise between number of likely defect-prone artifacts (effectiveness) and LOC to be analyzed/tested (which can be considered as a proxy of the cost of code inspection). Results of an empirical evaluation on 10 datasets from the Promise repository indicate the superiority and the usefulness of the multi-objective approach with respect to single-objective predictors. Also, the proposed approach outperforms an alternative approach for cross-project prediction, based on local prediction upon clusters of similar classes. Gerardo Canfora, Andrea De Lucia, Massimiliano Di Penta, Rocco Oliveto, Annibale Panichella, Sebastiano Panichella |
ICST | 1 |
| 2013 | A Case Study of Automating User Experience-Oriented Performance Testing on SmartphonesabstractWe have developed a platform named Advanced Test Environment (ATE) for supporting the design and the automatic execution of UX tests for applications running on Android smartphones. The platform collects objective metrics used to estimate the UX. In this paper, we investigate the extent that the metrics captured by ATE are able to approximate the results that are obtained from UX testing with real human users. Our findings suggest that ATE produces UX estimations that are comparable to those reported by human users. We have also compared ATE with three widespread benchmark tools that are commonly used in the industry, and the results show that ATE outperforms these tools. Gerardo Canfora, Francesco Mercaldo, Corrado Aaron Visaggio, Mauro D'Angelo, Antonio Furno, Carminantonio Manganelli |
ICST | 1 |
| 2013 | A Hidden Markov Model to detect coded information islands in free textabstractEmails and issue reports capture useful knowledge about development practices, bug fixing, and change activities. Extracting such a content is challenging, due to the mix-up of source code and natural language, unstructured text. Luigi Cerulo, Michele Ceccarelli, Massimiliano Di Penta, Gerardo Canfora |
SCAM | 4 |
| 2013 | Towards Effective Event-Driven SOA in Enterprise SystemsabstractEvent-driven programming is progressively replacing the call-stack model to improve flexibility, efficiency and scalability in SOA. Enterprise applications often deal with large messages attached to asynchronous events. This could reduce the benefits provided by event-driven programming since the need for having every information propagated as event is counterbalanced by wasting resources when large messages are entirely propagated to destinations that do not use all of them. In this paper, we propose the adoption of the D-WSLink framework for improving data transfers by using a composite and extensible declarative mechanism to inject the desired message transfer strategies into the underlying middleware. At the current stage, we focus mainly on (conditional) lazy transfer mechanisms even though the framework is able to support also smarter strategies. In particular, we compare, through an experimental analysis, our system with Apache Camel in delivering events with large attachments. The results show that the proposed approach is effective not only for programming but also at performance level. Quirino Zagarese, Angelo Furno, Gerardo Canfora, Eugenio Zimeo |
SMC | 3 |
| 2013 | Empirical Principles and an Industrial Case Study in Retrieving Equivalent Requirements via Natural Language Processing TechniquesabstractThough very important in software engineering, linking artifacts of the same type (clone detection) or different types (traceability recovery) is extremely tedious, error-prone, and effort-intensive. Past research focused on supporting analysts with techniques based on Natural Language Processing (NLP) to identify candidate links. Because many NLP techniques exist and their performance varies according to context, it is crucial to define and use reliable evaluation procedures. The aim of this paper is to propose a set of seven principles for evaluating the performance of NLP techniques in identifying equivalent requirements. In this paper, we conjecture, and verify, that NLP techniques perform on a given dataset according to both ability and the odds of identifying equivalent requirements correctly. For instance, when the odds of identifying equivalent requirements are very high, then it is reasonable to expect that NLP techniques will result in good performance. Our key idea is to measure this random factor of the specific dataset(s) in use and then adjust the observed performance accordingly. To support the application of the principles we report their practical application to a case study that evaluates the performance of a large number of NLP techniques for identifying equivalent requirements in the context of an Italian company in the defense and aerospace domain. The current application context is the evaluation of NLP techniques to identify equivalent requirements. However, most of the proposed principles seem applicable to evaluating any estimation technique aimed at supporting a binary decision (e.g., equivalent/nonequivalent), with the estimate in the range [0,1] (e.g., the similarity provided by the NLP), when the dataset(s) is used as a benchmark (i.e., testbed), independently of the type of estimator (i.e., requirements text) and of the estimation method (e.g., NLP). Davide Falessi, Giovanni Cantone, Gerardo Canfora |
IEEE Trans. Software Eng. | 3 |
| 2012 | Sip2Share - A Middleware for Mobile Peer-to-Peer Computing
Gerardo Canfora, Fabio Melillo |
ICSOFT | 1 |
| 2012 | Enabling Advanced Loading Strategies for Data Intensive Web ServicesabstractImproving performance of Web services interactions is an important factor to burst the adoption of SOAin mission-critical applications, especially when they deal with large business objects whose transfer time is not negligible. Designing messages dynamic granularity (offloading) is a key challenge for achieving good performances. This requires the server being able to predict the pieces of data actually used by clients in order to send only such data. However, exact prediction is not easy, and consequently lazy interactions are needed to transfer additional data whenever the prediction fails. To preserve semantics, lazy accesses to the results of a Web service interaction need to work on a dedicated copy of the business object stored as application state. Thus, dynamic offloading can experience an overhead due to a prediction failure, which is the sum of round-trip and storage access delays, which could compromise the benefits of the technique. This paper improves our previous work enabling dynamic offloading for both IN and OUT parameters, and analyses how attributes copies impact on the technique, by comparing the overheads introduced by different storage technologies in a real implementation of a Web services framework that extends CXF. More specifically, we quantitatively characterize the execution contexts that make dynamic offloading effective, and the expected accuracy of the predictive strategy to have a gain in term of response time compared to plain services invocations. Finally, the paper introduces the Attribute Loading Delegation technique that enables optimized data-transfers for those applications where data-intensive multiple-interactions take place. Quirino Zagarese, Gerardo Canfora, Eugenio Zimeo, Françoise Baude |
ICWS | 2 |
| 2012 | Mining source code descriptions from developer communicationsabstractVery often, source code lacks comments that adequately describe its behavior. In such situations developers need to infer knowledge from the source code itself or to search for source code descriptions in external artifacts. We argue that messages exchanged among contributors/developers, in the form of bug reports and emails, are a useful source of information to help understanding source code. However, such communications are unstructured and usually not explicitly meant to describe specific parts of the source code. Developers searching for code descriptions within communications face the challenge of filtering large amount of data to extract what pieces of information are important to them. We propose an approach to automatically extract method descriptions from communications in bug tracking systems and mailing lists. We have evaluated the approach on bug reports and mailing lists from two open source systems (Lucene and Eclipse). The results indicate that mailing lists and bug reports contain relevant descriptions of about 36% of the methods from Lucene and 7% from Eclipse, and that the proposed approach is able to extract such descriptions with a precision of up to 79% for Eclipse and 87% for Lucene. The extracted method descriptions can help developers in understanding the code and could also be used as a starting point for source code re-documentation. Sebastiano Panichella, Jairo Aponte, Massimiliano Di Penta, Andrian Marcus, Gerardo Canfora |
ICPC | 5 |
| 2012 | A Bayesian Approach for On-Line Sum/Count/Max/Min Auditing on Boolean Data
Bice Cavallo, Gerardo Canfora |
Privacy in Statistical Databases | 2 |
| 2012 | Who is going to mentor newcomers in open source projects?abstractWhen newcomers join a software project, they need to be properly trained to understand the technical and organizational aspects of the project. Inadequate training could likely lead to project delay or failure. Gerardo Canfora, Massimiliano Di Penta, Rocco Oliveto, Sebastiano Panichella |
SIGSOFT FSE | 1 |
| 2012 | Software: evolution and process A new journal is bornabstractAfter more than 2 years of transitioning, our new periodical, the “Journal of Software: Evolution and Process” is born. The journal continues and enriches the tradition of the “Journal of Software Maintenance and Evolution: Research and Practice” and “Software Process: Improvement and Practice” that have successfully served their respective communities for many years. We will work to ensure that all the positive aspects of the parent journals remain in place, and to make changes that we believe will help the new journal to gain and sustain a leadership position. Nowadays, the way in which software systems are conceived, built, and managed is changing profoundly; open-source and commercial-off-the-shelf products, service-oriented architectures and cloud computing, mobile and pervasive applications, agile methods and lean organizations, DevOps, outsourcing and global development, software as service, value-based software engineering, benefit-driven development and usability engineering, and user enhanceable systems are a few examples of areas that have had an impact on software development, management, and evolution methods and processes. In this rapidly evolving scenario, we have the ambition to offer a new peer-reviewed archival journal that addresses the issues of software conception, development, management, evolution and improvement with a multidisciplinary view that encompasses technologies, processes, services, people, and organizations. The success of this enterprise depends primarily on the quality of papers we will attract: we welcome high-quality papers reporting theoretical findings, empirical investigations, practice reports and state-of-the-art reviews on all aspects of planning, designing, building and evolving large, complex software systems and improving the processes, capabilities and practices required to develop, manage and govern such systems. We also continue to welcome papers from SMEs about the implications of operating and competing in modern contexts and environments and about the adaptations that need to be made to standards and approach to continue to deliver value and improve performance in increasingly demanding environments. We are indebted to members of the outstanding international Advisory Editorial Board for their support and commitment. With this issue, it is our great pleasure to introduce two new members of the Board: Elisabetta Di Nitto, from the Politecnico di Milano, Italy, and Patricia Lago, of VU University, Amsterdam. The new appointments mean that our Board now consists of 54 international scholars from 16 countries. We would also like to take this opportunity to thank all the anonymous external reviewers who, together with the members of the Advisory Editorial Board, have reviewed the 129 manuscripts the journal received in 2011: the reputation of a journal greatly depends on the quality and rigor of its reviewing process, and we are grateful to our reviewers for continuing to provide high quality, constructive, and developmental review reports. We are confident that the “Journal of Software: Evolution and Process” will be able to continue the parent journals' long tradition of publishing high-quality and influential papers on theory and practice of continuous product, process, and service conception, development, management, evolution and improvement, while opening the door to new perspectives and insights. Gerardo Canfora, Darren Dalcher, David Raffo |
J. Softw. Maintenance Res. Pract. | 1 |
| 2011 | Employing Dynamic Object Offloading as a Design Breakthrough for SOA Adoption
Quirino Zagarese, Gerardo Canfora, Eugenio Zimeo |
ICSOC | 2 |
| 2011 | Social interactions around cross-system bug fixings: the case of FreeBSD and OpenBSDabstractCross-system bug fixing propagation is frequent among systems having similar characteristics, using a common framework, or, in general, systems with cloned source code fragments. While previous studies showed that clones tend to be properly maintained within a single system, very little is known about cross-system bug management. Gerardo Canfora, Luigi Cerulo, Marta Cimitile, Massimiliano Di Penta |
MSR | 1 |
| 2011 | Preparing for a new eraabstractEditorial Gerardo Canfora, Darren Dalcher, David Raffo |
J. Softw. Maintenance Res. Pract. | 1 |
| 2011 | In memory of Manny Lehman, 'Father of Software Evolution'abstractThe definitive version can be found at : http://onlinelibrary.wiley.com/ Copyright Wiley [Full text of this article is not available in the UHRA] Gerardo Canfora, Darren Dalcher, David Raffo, Victor R. Basili, Juan Fernández-Ramil, Václav Rajlich, Keith H. Bennett, Elizabeth Burd, Malcolm Munro, Sophia Drossopoulou, Barry W. Boehm, Susan Eisenbach, Greg J. Michaelson, Peter Ross, Paul Wernick, Dewayne E. Perry |
J. Softw. Maintenance Res. Pract. | 1 |
| 2010 | A Probabilistic Approach for On-Line Sum-AuditingabstractIn this paper we consider the problem of auditing databases which support statistical sum-queries to protect the security of sensitive information. We study the special case in which the domain of the sensitive information is a discrete set; in particular, we focus on a boolean domain. Principles and techniques developed for the security of statistical databases in the case of continuous attributes do not apply here. We provide a probabilistic framework for the on-line sum-auditing and we show that sum-queries can be audited by means of a Bayesian network. Finally, we provide a preliminary analysis of the usefulness of the probabilistic approach. Gerardo Canfora, Bice Cavallo |
ARES | 1 |
| 2010 | A comprehensive characterization of NLP techniques for identifying equivalent requirementsabstractThough very important in software engineering, linking artifacts of the same type (clone detection) or of different types (traceability recovery) is extremely tedious, error-prone and requires significant effort. Past research focused on supporting analysts with mechanisms based on Natural Language Processing (NLP) to identify candidate links. Because a plethora of NLP techniques exists, and their performances vary among contexts, it is important to characterize them according to the provided level of support. The aim of this paper is to characterize a comprehensive set of NLP techniques according to the provided level of support to human analysts in detecting equivalent requirements. The characterization consists on a case study, featuring real requirements, in the context of an Italian company in the defense and aerospace domain. The major result from the case study is that simple NLP are more precise than complex ones. Davide Falessi, Giovanni Cantone, Gerardo Canfora |
ESEM | 3 |
| 2010 | Workshop on Emerging Trends in Software Metrics (WETSoM 2010)abstractThe Workshop on Emerging Trends in Software Metrics aims at bringing together researchers and practitioners to discuss the progress of software metrics. The motivation for this workshop is the low impact that software metrics has on current software development. The goals of this workshop are to critically examine the evidence for the effectiveness of existing metrics and to identify new directions for development of software metrics. Gerardo Canfora, Giulio Concas, Michele Marchesi, Ewan D. Tempero, Hongyu Zhang 0002 |
ICSE (2) | 1 |
| 2010 | An eclectic approach for change impact analysisabstractChange impact analysis aims at identifying software artifacts being affected by a change. In the past, this problem has been addressed by approaches relying on static, dynamic, and textual analysis. Recently, techniques based on historical analysis and association rules have been explored. This paper proposes a novel change impact analysis method based on the idea that the mutual relationships between software objects can be inferred with a statistical learning approach. We use the bivariate Granger causality test, a multivariate time series forecasting approach used to verify whether past values of a time series are useful for predicting future values of another time series. Results of a preliminary study performed on the Samba daemon show that change impact relationships inferred with the Granger causality test are complementary to those inferred with association rules. This opens the road towards the development of an eclectic impact analysis approach conceived by combining different techniques. Michele Ceccarelli, Luigi Cerulo, Gerardo Canfora, Massimiliano Di Penta |
ICSE (2) | 3 |
| 2010 | Using multivariate time series and association rules to detect logical change coupling: An empirical studyabstractIn recent years, techniques based on association rules discovery have been extensively used to determine change-coupling relations between artifacts that often changed together. Although association rules worked well in many cases, they fail to capture logical coupling relations between artifacts modified in subsequent change sets. To overcome such a limitation, we propose the use of multivariate time series analysis and forecasting, and in particular the use of Granger causality test, to determine whether a change occurred on a software artifact was consequentially related to changes occurred on some other artifacts. Results of an empirical study performed on four Java and C open source systems show that Granger causality test is able to provide a set of change couplings complementary to association rules, and a hybrid recommender built combining recommendations from association rules and Granger causality is able to achieve a higher recall than the two single techniques. Gerardo Canfora, Michele Ceccarelli, Luigi Cerulo, Massimiliano Di Penta |
ICSM | 1 |
| 2010 | An Exploratory Study of Factors Influencing Change EntropyabstractSoftware systems continuously change for various reasons, such as adding new features, performing bug fixing, or doing some refactoring activities. Such changes may either increase the source code complexity and disorganization, or help to reduce it. Developers apply adequate design principles and assets, including design patterns, to make software resilient to changes and control complexity. This paper empirically investigates the relationship of source code complexity and disorganization-measured using source code entropy-with three factors: different kinds of changes occurring to software systems, the presence of design patterns in the source code, and the number of contributors that modified the source code file. Results of an exploratory study carried out on an interval of the life-time span of two open source systems, ArgoUML and Eclipse-JDT, suggest that (i) different kinds of changes-namely refactorings and other kinds of changes-may contribute either negatively or positively to the entropy, (ii) the use of design patterns does not necessarily help to mitigate code degradation-thus confirming previous findings on the role played by design patterns-and (iii) entropy tends to increase with the number of file committers. Gerardo Canfora, Luigi Cerulo, Massimiliano Di Penta, Francesco Pacilio |
ICPC | 1 |
| 2009 | A Test Framework for Assessing Effectiveness of the Data Privacy Policy's Implementation into Relational DatabasesabstractThe growing migration of business transactions toward the web made data privacy a critical issue to cope with. Many technologies have been proposed in order to preserve sensitive data from illegal disclosure, also known as privacy enhancing technology (PET). Unfortunately, under certain conditions, sensitive data could be obtained by leveraging different malicious mechanisms which exploit actions permitted to the user. Thus, it is needed to face the problem also at the system design level, and not only by integrating a specific PET into the final system. We propose a framework for testing the software systempsilas capability of respecting established data privacy policy. Our test framework aims at detecting the sequence of legal actions which could allow a user to breach the mechanisms for preserving data privacy. The test output helps designers to properly modify those usage scenarios which could compromise data privacy. Experimentation has been carried out in order to make a preliminary assessment of the method. Gerardo Canfora, Corrado Aaron Visaggio, Vito Paradiso |
ARES | 1 |
| 2009 | Ldiff: An enhanced line differencing toolabstractDifferencing tools are highly relevant for a series of software engineering tasks, including analyzing developers' activities, assessing the changeability of software artifacts, and monitoring the maintenance of critical assets such as source clones and vulnerable instructions. This tool demonstration shows the features of ldiff, an enhanced, language-independent line differencing tool. L-diff builds upon the Unix diff and overcomes its limitations in determining whether an artifact line has been changed or is the result of additions and removals, and in tracking artifact fragments that have been moved upward or downward within the file. The paper describes the tool and shows its capability of analyzing changes on different kinds of software artifacts, including use cases, code developed with different programming languages, and test cases. Gerardo Canfora, Luigi Cerulo, Massimiliano Di Penta |
ICSE | 1 |
| 2009 | A Bayesian model for disclosure control in statistical databases
Gerardo Canfora, Bice Cavallo |
Data Knowl. Eng. | 1 |
| 2009 | Guest Editors' Introduction to the Special Section from the International Conference on Software MaintenanceabstractThe two papers in this special section are extended and enhanced versions of ones presented at the International Conference on Software Maintenance (ICSM), held in Paris, France, on 2-5 October 2007. Gerardo Canfora, Ladan Tahvildari, Hausi A. Müller |
IEEE Trans. Software Eng. | 1 |
| 2008 | A Bayesian Approach for on-Line Max AuditingabstractIn this paper we consider the on-line max query auditing problem: given a private association between fields in a data set, a sequence of max queries that have already been posed about the data, their corresponding answers and a new query, deny the answer if a private information is inferred or give the true answer otherwise. We give a probabilistic definition of privacy and demonstrate that max queries can be audited in a simulatable paradigm by means of a Bayesian network. Moreover, we show how our auditing approach is able to manage user prior-knowledge. Gerardo Canfora, Bice Cavallo |
ARES | 1 |
| 2008 | A System to Prevent Multi-users and Multi-sessions Attack to Breach Privacy Policies in a Trust-End FilterabstractAmong the different technological solutions realized in order to preserve data privacy, the front end trust filter could be effectively applied in environments characterized by high dynamism and untrustworthiness. Unfortunately, a preliminary assessment of this approach suggested a possible weakness: by using different user's profiles the privacy policy can be eluded and sensitive information could be obtained by inference over legal data set. This paper proposes a solution that could be helpful for two purposes: it could be used in the design phase for identifying which use scenarios (i.e., sequences of legal queries) could threaten data privacy; additionally, it could be used for identifying users which could potentially exploit inference for disclosing confidential information. Gerardo Canfora, Corrado Aaron Visaggio |
COMPSAC | 1 |
| 2008 | Evaluation of BPMN Models Quality - A Family of Experiments
Elvira Rolón Aguilar, Félix García 0001, Francisco Ruiz 0001, Mario Piattini, Corrado Aaron Visaggio, Gerardo Canfora |
ENASE | 6 |
| 2008 | Reasoning under Uncertainty in On-Line Auditing
Gerardo Canfora, Bice Cavallo |
Privacy in Statistical Databases | 1 |
| 2008 | A wrapping approach for migrating legacy system interactive functionalities to Service Oriented Architectures
Gerardo Canfora, Anna Rita Fasolino, Gianni Frattolillo, Porfirio Tramontana |
J. Syst. Softw. | 1 |
| 2008 | A framework for QoS-aware binding and re-binding of composite web services
Gerardo Canfora, Massimiliano Di Penta, Raffaele Esposito, Maria Luisa Villani |
J. Syst. Softw. | 1 |
| 2008 | Web Application Evaluation and Refactoring: A Quality-Oriented Improvement Approach
Luis Olsina, Alejandra Garrido 0001, Gustavo Rossi, Damiano Distante, Gerardo Canfora |
J. Web Eng. | 5 |
| 2008 | Special issue on Software Engineering and Soft Computing
Gerardo Canfora, Witold Pedrycz |
Soft Comput. | 1 |
| 2007 | Tuning anonymity level for assuring high data quality: an empirical studyabstractPreserving data privacy is posing new challenges to software engineering researchers. Current technologies can be too cumbersome, pervasive or costly to be successfully applied in dynamic and complex scenarios where data exchange occurs among a large number of applications. Anonymization techniques seem to be a promising candidate, even if preliminary investigations suggest that they could deteriorate the quality of data. An empirical study has been carried out in order to understand the relationship between the anonymization level and the degradation of data quality. Gerardo Canfora, Corrado Aaron Visaggio |
ESEM | 1 |
| 2007 | Search-based testing of service level agreementsabstractThe diffusion of service oriented architectures introduces the need for novel testing approaches. On the one side, testing must be able to identify failures in the functionality provided by service. On the other side, it needs to identify cases in which the Service Level Agreement (SLA) negotiated between the service provider and the service consumer is not met. This would allow the developer to improve service performances, where needed, and the provider to avoid promising Quality of Service (QoS) levels that cannot be guaranteed. This paper proposes the use of Genetic Algorithms to generate inputs and configurations for service-oriented systems that cause SLA violations. The approach has been implemented in a tool and applied to an audio processing workflow and to a service for chart generation. In both cases, the approach was able to produce test data able to violate some QoS constraints. Massimiliano Di Penta, Gerardo Canfora, Gianpiero Esposito, Valentina Mazza, Marcello Bruno |
GECCO | 2 |
| 2007 | Model-Driven Development of Web Applications with UWA, MVC and JavaServer Faces
Damiano Distante, Paola Pedone, Gustavo Rossi, Gerardo Canfora |
ICWE | 4 |
| 2007 | An empirical study on the evolution of design patternsabstractDesign patterns are solutions to recurring design problems, conceived to increase benefits in terms of reuse, code quality and, above all, maintainability and resilence to changes. This paper presents results from an empirical study aimed at understanding the evolution of design patterns in three open source systems, namely JHotDraw, ArgoUML, and Eclipse-JDT. Specifically, the study analyzes how frequently patterns are modified, to what changes they undergo and what classes co-change with the patterns. Results show how patterns more suited to support the application purpose tend to change more frequently, and that different kind of changes have a different impact on co-changed classes and a different capability of making the system resilent to changes. Lerina Aversano, Gerardo Canfora, Luigi Cerulo, Concettina Del Grosso, Massimiliano Di Penta |
ESEC/SIGSOFT FSE | 2 |
| 2007 | Building measure-based prediction models for UML class diagram maintainability
Marcela Genero, M. Esperanza Manso, Corrado Aaron Visaggio, Gerardo Canfora, Mario Piattini |
Empir. Softw. Eng. | 4 |
| 2007 | Evaluating performances of pair designing in industry
Gerardo Canfora, Aniello Cimitile, Félix García 0001, Mario Piattini, Corrado Aaron Visaggio |
J. Syst. Softw. | 1 |
| 2006 | Developing and executing java AWT applications on limited devices with TCPTEabstractThe paper describes TCPTE, a framework that supports the development of thin-client applications for mobile devices. By using this framework, Java AWT applications can be executed on a server and their graphical interfaces can be displayed on a remote client. TCPTE combines in a single framework the advantages of thin-client computing with the richness of client-server graphical interfaces and the simplicity of development that characterizes desktop applications. Gerardo Canfora, Giuseppe Di Santo, Eugenio Zimeo |
ICSE | 1 |
| 2006 | Redesigning legacy applications for the web with UWAT+: a case studyabstractThis paper reports on a case study of redesigning a legacy application for the Web using the Ubiquitous Web Applications Design Framework with an extended version of its Transaction Design Model (UWAT+). Web application design methodologies hold the promise of engineering high-quality and long-lived Web systems and rich Internet applications. However, many such techniques focus solely on green-field development, and do not properly address the situation of leveraging the value locked in legacy systems. The redesign process supported by UWAT+ holistically blends design recovery technologies for capturing the know-how embedded in the legacy application with forward design methods particularly well suited for Web-based systems. The case study highlights some of the benefits of using UWAT+ in this context, as well as identifying possible areas for improvement in the redesign process and opportunities for tool automation to support it. Damiano Distante, Gerardo Canfora, Scott R. Tilley, Shihong Huang |
ICSE | 2 |
| 2006 | On the Use of Line Co-change for Identifying Crosscutting Concern CodeabstractCrosscutting concerns are software system features whose implementation is spread across many modules as tangled and scattered code. Identifying such code helps developers to change the concern and/or re-factor it to an aspect. This paper evaluates the suitability of line co-change as a technique for the identification of crosscutting concerns. A line co-change aim at identifying source code lines that have been changed together in a commit transaction performed using a versioning system such as CVS. Promising results have been obtained by evaluating the approach to identify four crosscutting concerns present in an open-source system, JHotDraw. The paper also shows that line co-change can be effectively complemented with clone detection to improve the performance achieved by the separate approaches Gerardo Canfora, Luigi Cerulo, Massimiliano Di Penta |
ICSM | 1 |
| 2006 | Service Composition (re)Binding Driven by Application-Specific QoS
Gerardo Canfora, Massimiliano Di Penta, Raffaele Esposito, Francesco Perfetto, Maria Luisa Villani |
ICSOC | 1 |
| 2006 | Productivity of Test Driven Development: A Controlled Experiment with Professionals
Gerardo Canfora, Aniello Cimitile, Félix García 0001, Mario Piattini, Corrado Aaron Visaggio |
PROFES | 1 |
| 2006 | WECAP: A Web Environment for Project Planning
Lerina Aversano, Gerardo Canfora, Corrado Aaron Visaggio |
SEKE | 2 |
| 2006 | How Distribution Affects the Success of Pair ProgrammingabstractRecent experiments demonstrated the effectiveness of pair programming in terms of quality and productivity. Growing interest towards global software development is fostering the design of suitable methods and tools for distributing software processes, at any level of detail, from entire subprocesses up to a single activity. Consequently, people placed in different locations could also share programming tasks and related practices, such as pair programming. Unfortunately, distribution might seriously compromise the success of pair programming, due to communication and collaboration issues. We have performed an experiment in order to investigate the impact of distribution on pair programming when performing maintenance tasks. An interesting conjecture stems from the experiment: under certain conditions, distributed pair's components tend to dismiss from each other, stopping the collaborative work. This can be a very expensive risk factor to keep into account when planning tasks of distributed pair programming. Gerardo Canfora, Aniello Cimitile, Giuseppe A. Di Lucca, Corrado Aaron Visaggio |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2006 | FMESP: Framework for the modeling and evaluation of software processes
Félix García 0001, Mario Piattini, Francisco Ruiz 0001, Gerardo Canfora, Corrado Aaron Visaggio |
J. Syst. Archit. | 4 |
| 2006 | Technology-driven business evolution
Lerina Aversano, Thierry Bodhuin, Gerardo Canfora, Maria Tortorella |
J. Syst. Softw. | 3 |
| 2006 | Revisiting the Delta IC approach to component recovery
Rainer Koschke, Gerardo Canfora, Jörg Czeranski |
Sci. Comput. Program. | 2 |
| 2006 | Applying a framework for the improvement of software process maturityabstractAbstract This article presents the results and lessons learned in the application of the Framework for the Modelling and Measurement of Software Processes (FMESP) in a software company dedicated to the development and maintenance of software for information systems. The aim of FMESP is to provide companies with a conceptual and technological framework for the management of their process models and measurement models in an integrated way. Modelling and measurement are two key factors to promote continuous process improvement. As a result, important benefits were obtained. The company improved the maturity of its processes which allowed it to obtain the ISO 9000 certification. From a research point of view, Action‐Research was successfully applied and as a result the framework was improved and important feedback was obtained, bringing to light new important issues which will be tacked in future work. Copyright © 2005 John Wiley & Sons, Ltd. Gerardo Canfora, Félix García 0001, Mario Piattini, Francisco Ruiz 0001, Corrado Aaron Visaggio |
Softw. Pract. Exp. | 1 |
| 2005 | An approach for QoS-aware service composition based on genetic algorithmsabstractWeb services are rapidly changing the landscape of software engineering. One of the most interesting challenges introduced by web services is represented by Quality Of Service (QoS)--aware composition and late--binding. This allows to bind, at run--time, a service--oriented system with a set of services that, among those providing the required features, meet some non--functional constraints, and optimize criteria such as the overall cost or response time. In other words, QoS--aware composition can be modeled as an optimization problem.We propose to adopt Genetic Algorithms to this aim. Genetic Algorithms, while being slower than integer programming, represent a more scalable choice, and are more suitable to handle generic QoS attributes. The paper describes our approach and its applicability, advantages and weaknesses, discussing results of some numerical simulations. Gerardo Canfora, Massimiliano Di Penta, Raffaele Esposito, Maria Luisa Villani |
GECCO | 1 |
| 2005 | Using Test Cases as Contract to Ensure Service Compliance Across Releases
Marcello Bruno, Gerardo Canfora, Massimiliano Di Penta, Gianpiero Esposito, Valentina Mazza |
ICSOC | 2 |
| 2005 | QoS-Aware Replanning of Composite Web ServicesabstractRun-time service discovery and late-binding constitute some of the most challenging issues of service-oriented software engineering. For late-binding to be effective in the case of composite services, a QoS-aware composition mechanism is needed. This means determining the set of services that, once composed, not only will perform the required functionality, but also will best contribute to achieve the level of QoS promised in service level agreements (SLAs). However, QoS-aware composition relies on estimated QoS values and workflow execution paths previously obtained using a monitoring mechanism. At run-time, the actual QoS values may deviate from the estimations, or the execution path may not be the one foreseen. These changes could increase the risk of breaking SLAs and obtaining a poor QoS. Such a risk could be avoided by replanning the service bindings of the workflow slice still to be executed. This paper proposes an approach to trigger and perform composite service replanning during execution. An evaluation has been performed simulating execution and replanning on a set of composite service workflows. Gerardo Canfora, Massimiliano Di Penta, Raffaele Esposito, Maria Luisa Villani |
ICWS | 1 |
| 2005 | Proxy-based Hand-off of Web Sessions for User MobilityabstractThe proliferation of different kinds of mobile devices, ranging from personal wireless devices, such as PDAs and smart phones, to small notebooks, is enabling ubiquitous personal computing. However, even if a personal device is able to access to different kinds of information, often it does not represent the best solution to retrieve a stream of data from the Internet or to visualize it with an acceptable quality. This problem is promoting several research efforts oriented to the definition of techniques and network components able to support the migration of working sessions from a device to a more apt one. Research results related to the mobility of hosts are not sufficient to solve the problem of user mobility. The paper presents a protocol built a top HTTP for enabling session hand-off in Web applications, which, by exploiting a proxy-based architecture, is able to work without interventions on existing applications and Web infrastructure. Gerardo Canfora, Giuseppe Di Santo, Gabriele Venturi, Eugenio Zimeo, Maria Vittoria Zito |
MobiQuitous | 1 |
| 2005 | Empirical Study on the Productivity of the Pair Programming
Gerardo Canfora, Aniello Cimitile, Corrado Aaron Visaggio |
XP | 1 |
| 2005 | A family of experiments to validate metrics for software process models
Gerardo Canfora, Félix García 0001, Mario Piattini, Francisco Ruiz 0001, Corrado Aaron Visaggio |
J. Syst. Softw. | 1 |
| 2005 | Pair designing as practice for enforcing and diffusing design knowledgeabstractEvolving software's design requires that the members of the team acquire a deep and complete knowledge of the domain, the architectural components, and their integration. Such information is scarcely addressed within the design documentation and it is not trivial to derive it. A strategy for enforcing the consciousness of such hidden aspects of software's design is needed. One of the expected benefits of pair programming is fostering (tacit) knowledge building between the components of the pair and fastening its diffusion within the project's team. We have applied the paradigm of pair programming to the design phase and we have named it ‘pair designing’. We have realized an experiment and a replica in order to understand if pair designing can be used as an effective means for diffusing and enforcing the design knowledge while evolving the system's design. The results suggest that pair designing could be a suitable means to disseminate and enforce design knowledge. Copyright © 2005 John Wiley & Sons, Ltd. Emilio Bellini, Gerardo Canfora, Félix García 0001, Mario Piattini, Corrado Aaron Visaggio |
J. Softw. Maintenance Res. Pract. | 2 |
| 2004 | Fuzzy ordering of fuzzy numbersabstractFuzzy numbers cannot be easily ordered as ordinary real numbers. Several proposals have addressed this problem, each with some drawbacks and limitations. This paper renounces to the idea of finding a universal ordering method for fuzzy numbers and suggests to compute the degree by which an arbitrary permutation of fuzzy numbers is ordered. Thus, ordering becomes itself fuzzy. This is useful in the development of decision support systems as a higher degree of accurateness is achieved, with respect to existing methods. However, accuracy is counterbalanced by a higher computation time. The paper address this issue, by proposing an efficient numeric solution. Gerardo Canfora, Luigi Troiano |
FUZZ-IEEE | 1 |
| 2004 | An Algorithm for Web Service Discovery through Their CompositionabstractThe Web services stack of standards is designed to support the reuse and the interoperation of software components on the Web. A critical step in the process of developing applications based on the service oriented architecture is the service discovery. This paper shows how service composition can be used as a technique to support service discovery. The paper discusses the current state of research in this area and introduces a semantic matching algorithm that exploits the possibility to compose multiple services in order to satisfy a service request. Lerina Aversano, Gerardo Canfora, Anna Ciampi |
ICWS | 2 |
| 2004 | Introducing Quality System in Small and Medium Enterprises: An Experience Report
Lerina Aversano, Gerardo Canfora, Giovanni Capasso, Giuseppe A. Di Lucca, Corrado Aaron Visaggio |
PROFES | 2 |
| 2004 | An Experience of Fuzzy Linear Regression applied to Effort Estimation
Gerardo Canfora, Luigi Cerulo, Luigi Troiano |
SEKE | 1 |
| 2004 | Seventh European Conference on Software Maintenance and Reengineering (CSMR 2003)
Mark van den Brand, Gerardo Canfora, Tibor Gyimóthy |
J. Softw. Maintenance Res. Pract. | 2 |
| 2003 | Transforming quantities into qualities in assessment of software systemsabstractThe assessment of software systems often requires to consider together qualitative and quantitative aspects. Because of the different nature, measures belong to different domains. The main problem is to aggregate such information into a derived measure able to provide an overall estimation. This problem has been traditionally solved trough the transformation of qualitative assessments into quantitative measures. Indeed, such a transformation implicitly assumes a conceptual equivalence between the terms quantitative and objective on one side, and qualitative and subjective on the other side. An alternative approach is to consider logical aggregation models, able to infer the overall evaluation based on the assessment of individual attributes. This approach requires an early transformation of quantitative measures in qualitative assessments. Such a transformation is possible trough the use of judgment functions. The aim of this paper is to introduce the judgment functions and to study their properties. Gerardo Canfora, Luigi Cerulo, Luigi Troiano |
COMPSAC | 1 |
| 2003 | A Rule-Based Method to Aggregate Criteria with Different Relevance
Gerardo Canfora, Luigi Troiano |
IFSA | 1 |
| 2003 | A Tool for Decision Support Implementing OFNWA Approach: A Case Study
Gerardo Canfora, Luigi Cerulo, Rosa Preziosi, Luigi Troiano |
SEKE | 1 |
| 2003 | Guest Editors' Introduction: 2001 International Conference on Software Maintenance
Gerardo Canfora, Anneliese Amschler Andrews |
IEEE Trans. Software Eng. | 1 |
| 2002 | Understanding SQL through Iconic InterfacesabstractVisual query languages represent an evolution, in terms of understandability and adaptability, with respect to traditional textual languages. We present an iconic query system that enables the interaction of a novice user with a relational database. Our goal is to help a novice user to learn and comprehend the relational data model and a textual query language such as SQL, through the use of the iconic metaphore. In this sense our approach is different from most of the visual query systems proposed in the literature that present the user with a higher level query language, hiding the underlying data model. We also present results from an experiment conducted with first year students to evaluate the effectiveness of our approach. Lerina Aversano, Gerardo Canfora, Andrea De Lucia, Silvio Stefanucci |
COMPSAC | 2 |
| 2002 | Workshop on Cooperative Supports for Distributed Software Engineering ProcessesabstractGlobally distributed software development challenges traditional techniques of software engineering and new approached to solved communication, collaboration and coordination problems are to be sought. This workshop intends to gather practitioners and researchers from academia, industry, and government, to review the current state of the practice, to report on, and to present issues and solutions in the general area of computer supported cooperative methodologies and technologies applied to software engineering processes. Gerardo Canfora, Andrea De Lucia |
COMPSAC | 1 |
| 2002 | ContentP2P: A Peer-to-Peer Content Management SystemabstractThe paper presents a new application of content management based on a peer-to-peer platform. Several advantages following our choice of the peer-to-peer paradigm within the content management context are discussed, such as the improved scalability and flexibility of the system and the preserved ownership and off-line control of content from content creators. Gerardo Canfora, Sandro Manzo, Vincenzo Fabio Rollo, Maria Luisa Villani |
COMPSAC | 1 |
| 2002 | From Knowledge Management Concepts Toward Software Engineering Practices
Gerardo Canfora, Aniello Cimitile, Corrado Aaron Visaggio |
PROFES | 1 |
| 2002 | Introducing eservices in business process modelsabstractThe need for automatic support of business processes that extend over the boundaries of an enterprise is a recognized need of emerging virtual organizations. To make workflow technologies useful during the enactment of business processes involving many partners that reciprocally provide and consume services, it is important to provide a model, and supporting technologies, to manage the introduction of services in workflow models.This paper introduces a framework for the introduction of eServices in business process models. The framework comprises RDF based languages to model processes, services, and service composition, and supporting technologies to generate executable workflow models, including interfaces to the actual services, from the models. Lerina Aversano, Gerardo Canfora |
SEKE | 2 |
| 2002 | A visual approach to define XML to FO transformationsabstractXML is the most influential standard for data exchange and Web presentation. The power of XML derives from the fact that the aspects of structuring, representing and visualizing a piece of information are handled independently with specific tools.In this article we deal with the information visualization aspect, which in XML is managed through XSLT transformations, and propose a visual approach to define XML to FO transformations. The approach has been implemented in a graphical environment that eases the definition of the format and visualization of XML documents by means of a graphicalcontent/container metaphor. Gerardo Canfora, Luigi Cerulo |
SEKE | 1 |
| 2002 | The importance of dealing with uncertainty in the evaluation of software engineering methods and toolsabstractThe correct choice of software tools and methods is a critical success factor to reach and maintain market leadership. A mature approach to estimate the impact and risk of technology adoption is required. This paper underlines the need for dealing with uncertainty to manage correctly the risk of decision-making and proposes a method for evaluating software engineering methods and tools. The method, named Software Engineering Fuzzy Evaluation Method (SEFEM) is centred on a new class of fuzzy aggregators named Ordered Fuzzy Number Weighted Averaging (OFNWA). Gerardo Canfora, Luigi Troiano |
SEKE | 1 |
| 2002 | Business process reengineering and workflow automation: a technology transfer experience
Lerina Aversano, Gerardo Canfora, Andrea De Lucia, Pierpaolo Gallucci |
J. Syst. Softw. | 2 |
| 2002 | Automating the management of software maintenance workflows in a large software enterprise: a case studyabstractAbstract This case study presents the results from a pilot project aimed at introducing workflow management technologies and a Web‐based software tool in a large software enterprise. In particular, we analyzed and modeled the workflows and documents at the site of the ordinary maintenance process and implemented a prototype for the management of the process using a commercial‐Web‐based workflow management system. This paper reports on the experience gained from a 10‐month project, which included the experimental use at a single site of the workflow prototype for 4 months in an industrial setting involving more than 800 maintenance service requests on a large software system. Copyright © 2002 John Wiley & Sons, Ltd. Lerina Aversano, Gerardo Canfora, Andrea De Lucia, Silvio Stefanucci |
J. Softw. Maintenance Res. Pract. | 2 |
| 2002 | Recovering Traceability Links between Code and DocumentationabstractSoftware system documentation is almost always expressed informally in natural language and free text. Examples include requirement specifications, design documents, manual pages, system development journals, error logs, and related maintenance reports. We propose a method based on information retrieval to recover traceability links between source code and free text documents. A premise of our work is that programmers use meaningful names for program items, such as functions, variables, types, classes, and methods. We believe that the application-domain knowledge that programmers process when writing the code is often captured by the mnemonics for identifiers; therefore, the analysis of these mnemonics can help to associate high-level concepts with program concepts and vice-versa. We apply both a probabilistic and a vector space information retrieval model in two case studies to trace C++ source code onto manual pages and Java code to functional requirements. We compare the results of applying the two models, discuss the benefits and limitations, and describe directions for improvements. Giuliano Antoniol, Gerardo Canfora, Gerardo Casazza, Andrea De Lucia, Ettore Merlo |
IEEE Trans. Software Eng. | 2 |
| 2001 | Decomposing legacy systems into objects: an eclectic approach
Gerardo Canfora, Aniello Cimitile, Andrea De Lucia, Giuseppe A. Di Lucca |
Inf. Softw. Technol. | 1 |
| 2001 | Maintaining traceability links during object-oriented software evolutionabstractAbstract This paper presents a method to build and maintain traceability links and properties of a set of object‐oriented software releases. The method recovers an ‘as is’ design from C++ software releases, compares recovered designs at the class interface level, and helps the user to deal with inconsistencies by pointing out regions of code where differences are concentrated. The comparison step exploits edit distance and a maximum match algorithm. The method has been experimented with on two freely available C++ systems. Results as well as examples of applications to the visualization of the traceability information and to the estimation of the size of changes during maintenance are reported in the paper. Copyright © 2001 John Wiley & Sons, Ltd. Giuliano Antoniol, Gerardo Canfora, Gerardo Casazza, Andrea De Lucia |
Softw. Pract. Exp. | 2 |
| 2000 | Information Retrieval Models for Recovering Traceability Links between Code and DocumentationabstractThe research described in the paper is concerned with the application of information retrieval to software maintenance, and in particular to the problem of recovering traceability links between the source code of a system and its free text documentation. We introduce a method based on the general idea of vector space information retrieval and apply it in two case studies to trace C++ source code onto manual pages and Java code onto functional requirements. The case studies discussed in the paper replicate the studies presented by G. Antoniol et al. (1999; 2000), respectively where a probabilistic information retrieval model was applied. We compare the results of vector space and probabilistic models and formulate hypotheses to explain the differences. Giuliano Antoniol, Gerardo Canfora, Gerardo Casazza, Andrea De Lucia |
ICSM | 2 |
| 2000 | A Design Rationale Based Environment for Cooperative MaintenanceabstractThis paper describes Cooperative Maintenance Conceptual Model ( CM 2 ), a conceptual model aimed at supporting software maintenance in a collaborative fashion. The main goal of CM 2 is to support the software maintenance process through the acquisition, structuring and distribution of the information concerned with the maintenance process itself. Information is structured as a network of linked comments and concerns both the analysis and design activities (Rationale in the Large) and the implementation of a change (Rationale in the Small). We also present COMANCHE (COoperative MAintenance Network Centered Hypertextual Enviroment), an enviroment which reflects the CM 2 ideas and principles. Gerardo Canfora, Gerardo Casazza, Andrea De Lucia |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2000 | Decomposing legacy programs: a first step towards migrating to client-server platforms
Gerardo Canfora, Aniello Cimitile, Andrea De Lucia, Giuseppe A. Di Lucca |
J. Syst. Softw. | 1 |
| 1999 | Maintaining Traceability During Object-Oriented Software Evolution: A Case StudyabstractThis paper presents an approach to build and visualize traceability links and properties of a set of OO software releases. The process recovers an "as is" design from C++ software releases, compares recovered designs at the class interface level, and helps the user to deal with inconsistencies by pointing out regions of code where differences are concentrated. The comparison process exploits edit distance and a maximum match algorithm and has been experimented with 9 releases of a library of foundation classes. Results as well as consideration related to presentation issues are reported in the paper. Giuliano Antoniol, Gerardo Canfora, Andrea De Lucia |
ICSM | 2 |
| 1999 | A System for Generating Reverse Engineering Tools: A Case Study of Software Modularisation
Gerardo Canfora, Andrea De Lucia, Giuseppe A. Di Lucca |
Autom. Softw. Eng. | 1 |
| 1999 | An Incremental Object-Oriented Migration Strategy for RPG Legacy SystemsabstractWe present a strategy for incrementally migrating legacy systems to object-oriented platforms. The migration process consists of six sequential phases and encompasses reverse engineering and reengineering activities. The aim of reverse engineering is to decompose programs into components implementing the user interface and components implementing application domain objects. The identification of objects is centred around persistent data stores and exploits object-oriented design metrics. Wrapping is the core of the reengineering activities. It makes new systems able to exploit existing resources, thus allowing an incremental and selective replacement of the identified objects. The migration strategy has been defined and experimented within the project ERCOLE (Encapsulation, Reengineering and Coexistence of Object with Legacy) on legacy systems developed in RPG for the IBM AS/400 environment. Gerardo Canfora, Andrea De Lucia, Giuseppe A. Di Lucca |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 1998 | Conditioned program slicing
Gerardo Canfora, Aniello Cimitile, Andrea De Lucia |
Inf. Softw. Technol. | 1 |
| 1998 | An integrated environment for reuse reengineering C code
Gerardo Canfora, Andrea De Lucia, Malcolm Munro |
J. Syst. Softw. | 1 |
| 1998 | An Extensible System for Source Code AnalysisabstractConstructing code analyzers may be costly and error prone if inadequate technologies and tools are used. If they are written in a conventional programming language, for instance, several thousand lines of code may be required even for relatively simple analyses. One way of facilitating the development of code analyzers is to define a very high-level domain-oriented language and implement an application generator that creates the analyzers from the specification of the analyses they are intended to perform. This paper presents a system for developing code analyzers that uses a database to store both a no-loss fine-grained intermediate representation and the results of the analyses. The system uses an algebraic representation, called F(p), as the user-visible intermediate representation. Analyzers are specified in a declarative language, called F(p)-l, which enables an analysis to be specified in the form of a traversal of an algebraic expression, with access to, and storage of, the database information the algebraic expression indices. A foreign language interface allows the analyzers to be embedded in C programs. This is useful for implementing the user interface of an analyzer, for example, or to facilitate interoperation of the generated analyzers with pre-existing tools. The paper evaluates the strengths and limitations of the proposed system, and compares it to other related approaches. Gerardo Canfora, Aniello Cimitile, Ugo de Carlini, Andrea De Lucia |
IEEE Trans. Software Eng. | 1 |
| 1996 | Specifying code analysis toolsabstractCustomised code analysis tools for the maintenance and evolution of existing software systems can be created by storing program information in a database, and using an application generator to translate the high-level specifications of the analyses the tools are intended to perform. We present a high-level domain-specific language for the specification of program analysis tools that exploit an algebraic program representation called F(p). The algebraic representation is a compact program view which describes the static composition of the control structures and the set of the resulting potential executions. Operands of the algebraic expression (that represent the program's constructs) are used as indexes to access information stored in the database. The specification language provides facilities for the traversal of the program representation and access to the associated information in the database. The program model and the analysis results are integrated into a unique conceptual model, thus simplifying the reuse of the results of an analysis and the integration of the tools. Gerardo Canfora, Aniello Cimitile, Andrea De Lucia |
ICSM | 1 |
| 1996 | Recovering a Conceptual Data Model from COBOL Code
Gerardo Canfora, Aniello Cimitile, Giuseppe A. Di Lucca |
SEKE | 1 |
| 1996 | An Integrated Environment for Reuse Reengineering C Code
Gerardo Canfora, Andrea De Lucia, Malcolm Munro |
SEKE | 1 |
| 1995 | Algorithms for program dependence graph productionabstractOne of the greatest difficulties of setting up a software maintenance workbench is the definition of an internal representation of programs from which different external representations can be automatically constructed. This is because many techniques and tools exist that support and automate individual maintenance activities, and each of these techniques and tools operates on its own specific representation of the program. This paper presents our program representation, called F(p), and shows how it can be used as an index to access program information. This allows many existing representations to be derived from F(p). The paper presents two novel algorithms to derive two existing program representations, namely the control dependence graph and the sets of uses that can be reached from each variable definition (which provide the additional information needed to draw the program dependence graph). Gerardo Canfora, Aniello Cimitile |
ICSM | 1 |
| 1995 | Towards reengineering in reuse reengineering processesabstractReuse of existing software has been regarded in recent years as a feasible solution to software quality and productivity improvement problems. Various reference paradigms for setting up a reuse reengineering process have been proposed. With reference to the RE/sup 2/ (Reverse Engineering and Reuse Reengineering) paradigm, this paper addresses the problems of the election phase. In particular, by describing an approach to the reuse reengineering of COBOL programs, it tackles the transformation of a set of candidate components into a set of actually reusable modules. This involves the identification of a module template that allows the COBOL code components to be easily reused, and the definition of reverse engineering and reengineering techniques to package the components into the template. Gerardo Canfora, Anna Rita Fasolino, Maria Tortorella |
ICSM | 1 |
| 1995 | Prolog for Software Maintenance
Gerardo Canfora, Aniello Cimitile, Maria Tortorella |
SEKE | 1 |
| 1995 | Iesem: Integrated Environment for Software Evolution ManagementabstractSoftware evolution has no common paradigm which practitioners can adhere to. On the contrary, there is a wide range of models, methods, techniques, and tools which are selected according to the specific task, the application domain, the professional experience, and the organizational culture. We argue that different approaches and technologies may be combined into a unique platform to satisfy the needs of software systems which evolve over long periods of time. This paper presents the Integrated Environment for Software Evolution Management (IESEM) which includes software repositories, reverse engineering tools, rationale capture tools, software measurement tools, and a user-friendly interface. It can manage heterogeneous systems characterized by various design methods and programming languages. IESEM is based on a central repository which stores software engineering artifacts, program code, design, and implementation decisions in the form of a traceability graph. The repository stores also software measures computed both from programs and external CASE repositories. Measures are used to control software degradation during its evolution and to support decisions based on quality factors. The key concepts of IESEM, its design, and implementation are presented. The use of IESEM during development and maintenance is discussed. A case study shows IESEM's effectiveness in performing maintenance tasks. Gerardo Canfora, Filippo Lanubile, Giuseppe Visaggio |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 1995 | Assessing modularization and code scavenging techniquesabstractAbstract The destiny of legacy software is a relevant economic problem. Many companies are experiencing the friction that legacy systems oppose to the change and growth of their business. Nevertheless, these systems cannot be simply discarded and replaced with new ones developed according to the new organization requirements. Existing systems record a great deal of knowledge and expertise used to set up solutions to real problems in different application domains and it is imperative that this knowledge must not be lost, partly because it may not be recorded anywhere else than in the code. This paper discusses the problems related to the modularization of legacy systems, with the emphasis being placed on the automation of code scavenging. It is argued that a balance must be struck between the modularization of legacy code, and the production of reusable, easy‐to‐evolve modules. The paper provides a framework for examining system modularization methods and identifies a set of attributes that define their quality. An overview of modularization techniques is presented, and an evaluation is made to assess their strength and identify and understand their major limitations. Finally, an attempt is made to identify techniques and tools that are nature enough to be transferred from research laboratories to industry. Gerardo Canfora, Aniello Cimitile, Giuseppe Visaggio |
J. Softw. Maintenance Res. Pract. | 1 |
| 1994 | Reengineering Legacy Systems to Meet Quality Requirements: An Experience ReportabstractThe paper is a summary of a third party re-engineering project aiming to adjust a legacy system to the new quality standard established by the customer. The quality standard is defined in the form of a set of metrics each associated with a range of acceptable values. A set of 100 programs has been restructured and modularised to meet the quality requirements. When possible, automated tools have been used in order to reduce the costs, standardise the results, and ease the transfer of techniques and methodologies to the customer. The re-engineered programs have replaced the original versions in the customer production environment. Their quality, and in particular their understandability and maintainability, is considerably increased as confirmed by the customer's technical personnel. The work described is a preliminary step towards the definition of a larger re-engineering project to bring the customer's software portfolio into line with the new quality standard.> P. Antonini, Gerardo Canfora, Aniello Cimitile |
ICSM | 2 |
| 1994 | Software Salvaging Based on ConditionsabstractThis paper presents algorithms for isolating reusable functions in large monolithic programs. The functions to be isolated are specified in terms of either pre-conditions or binding conditions, and these are mapped onto predicates on program's variables. Code components whose execution is triggered and/or bound by these predicates are then isolated. Each component is a candidate to implement a reusable function. The algorithms exploit a representation of the subject program in the form of a program dependence graph. This work forms part of RE/sup 2/, a research project that addresses the wider issue of software reuse. RE/sup 2/ project aims to promote the reuse of software through the exploration of reverse engineering and re-engineering techniques to identify and extract reusable software components from existing systems.> Gerardo Canfora, Aniello Cimitile, Andrea De Lucia, Giuseppe A. Di Lucca |
ICSM | 1 |
| 1994 | A Precise Method for Identifying Reusable Abstract Data Types in CodeabstractThis paper presents the results of research within the RE/sup 2/ project of a refinement of two existing methods for identifying reusable abstract data types. These methods are based on the relationships existing between the user defined types and procedure-like components that use them in their headings and on direct dominance trees and strong direct dominance trees that are refinements of the call directed graph of a program. It shows how these methods can be used to give a more precise set of reusable abstract data types. The method is then applied to a program and the results are compared with the existing method.> Gerardo Canfora, Aniello Cimitile, Maria Tortorella, Malcolm Munro |
ICSM | 1 |
| 1994 | Recovering object classes and inheritance relationships from existing code
Gerardo Canfora, Giuseppe A. Di Lucca, Maria Tortorella |
SEKE | 1 |
| 1994 | RE2: Reverse-engineering and reuse re-engineeringabstractAbstract Initial research in reuse was in the designing and implementation of reusable software. This research, although fruitful, did not address the area of extracting reusable components from existing software. In this paper the term reuse is used to mean the ‘reuse of existing source code’. A process called ‘reuse re‐engineering’ is defined and this, together with techniques from reverse‐engineering, form a new method for achieving reuse. A reference paradigm is established to implement the reuse re‐engineering process. This process is divided into five sequential phases, each characterized by the objects it produces. These phases are: candidature, election, qualification, classification and storage, and search and display. This paper concentrates on the first three phases because they produce reusable modules from existing systems. In selecting candidates for reuse, different abstractions have to be applied, namely functional abstraction (algorithms) and data abstractions (data structures and data types). This paper presents a formalized approach to each of these abstractions. The approach proposed in this paper aims to promote reuse in industrial software production environments. Gerardo Canfora, Aniello Cimitile, Malcolm Munro |
J. Softw. Maintenance Res. Pract. | 1 |
| 1993 | Extracting Abstract Data Types from C Programs: A Case StudyabstractThe results of a case study in identifying and extracting reusable abstract data types from C programs are presented. Reuse re-engineering processes already established in the RE/sup 2/ project are applied. The method for identifying abstract data types uses an interconnection graph called a variable-reference graph, and coincidental and spurious connections within the graph are resolved using a statistical technique. A prototype tool is described which demonstrates the feasibility of the method. The tool is used to analyze a C program, and a number of abstract data types are identified and used in the maintenance of the original program. The validity of the method is assessed by a simple manual analysis of the source code. The resulting reusable components are then specified using the formal notation Z.> Gerardo Canfora, Aniello Cimitile, Malcolm Munro, C. J. Taylor |
ICSM | 1 |
| 1993 | A reverse engineering process for design level document production from ADA code
Gerardo Canfora, Aniello Cimitile, Ugo de Carlini |
Inf. Softw. Technol. | 1 |
| 1993 | Correction to "A Logic-Based Approach to Reverse Engineering Tools Production"abstractA typographic error in rule 10 in the above-titled paper (see ibid., vol.18, no.12, p.1053-64, Dec. 1992), is corrected.> Gerardo Canfora, Aniello Cimitile, Ugo de Carlini |
IEEE Trans. Software Eng. | 1 |
| 1992 | Data flow diagrams: reverse engineering production and animationabstractThe authors propose the use of interactive animation techniques as a support to reverse engineering processes oriented to the synthesis of semantic abstractions. Starting from data flow diagrams, a formal model, called dynamic data flow diagrams (DDFDs), has been defined, which can be used for the production of executable models of a software system. A strategy for the DDFD interactive animation is also put forward. Finally, the authors describe a prototype tool for (i) the production of the DDFD which models an ADA system starting from the analysis of the code and (ii) the interactive animation of such a model according to the proposed strategy.> Gerardo Canfora, Lucio Sansone, Giuseppe Visaggio |
ICSM | 1 |
| 1992 | Reverse-engineering and intermodular data flow: A theoretical approachabstractAbstract Starting from the need for formalization and models to represent and repeat reverse‐engineering activities, this paper presents a proposal in the field of data flow analysis. In particular, the authors propose a formal model for a practical approach to the reconstruction of intermodular data flow associated with the structure charts of a Pascal software system. Specific matrices extracted straight from code are presented and matrix calculation is then exploited to obtain a final matrix containing all the information needed for the reconstruction of the data flow. Finally, this flow is reconstructed by means of transformations on the elements in this matrix. Gerardo Canfora, Aniello Cimitile |
J. Softw. Maintenance Res. Pract. | 1 |
| 1992 | A Logic-Based Approach to Reverse Engineering Tools ProductionabstractDifficulties arising in the use of documents produced by reverse engineering tools are analyzed. With reference to intermodular data flow analysis for Pascal software systems, an interactive and evolutionary tool is proposed. The tool is based on the production of intermodular data flow information by static analysis of code, its representation in a Prolog program dictionary, and a Prolog abstractor that allows the specific queries to be answered.> Gerardo Canfora, Aniello Cimitile, Ugo de Carlini |
IEEE Trans. Software Eng. | 1 |
| 1991 | A logic based approach to reverse engineering tools productionabstractSome of the reasons for difficulties arising in the use of design documents produced by reverse engineering tools are analyzed. With reference to intermodular dataflow analysis for Pascal software systems, an interactive tool is proposed to more effectively help the maintainer. The tool is based on: the production of intermodular dataflow information by static analysis of the code; their representation in a Prolog program dictionary; and a Prolog abstractor that allows specific queries of maintainers to be answered. A logic-based approach to the design and implementation of an interactive tool which analyzes the intermodularal data flow of a program is discussed.> Gerardo Canfora, Aniello Cimitile, Ugo de Carlini |
ICSM | 1 |
| 1990 | Reverse engineering and data flow diagrams in ADA environment
Gerardo Canfora, Aniello Cimitile, Ugo de Carlini |
Microprocessing and Microprogramming | 1 |