EDBT 2026 Demo / reviewers in the wild / expert
Sami Hyrynsalmi
dblp:75/10160
· DBLP profile ↗
32ranked-venue papers
2as first author
13since 2021 · last 2025
0000-0002-5073-3750ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 22 · 2 first-author · 12 since 2021Security and privacy · 5Applied, interdisciplinary, general and emerging computing · 5 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Success Factors in Civic Tech Grassroots Software Ecosystems: Preliminary Findings from an Exploratory Case Study
Antti Knutas, Nicolas Jullien, Wojciech Sanko, Andrey Saltan, Dominik Siemon, Thinh Tran, Sami Hyrynsalmi |
ECSCW | 7 |
| 2025 | Core Theories in Agile Software DevelopmentabstractAbstract The lack of core theories is a challenge for the whole software engineering (SE) discipline, particularly crucial for the agile software development (ASD) field, which is largely practice-driven. Without solid and continuous theoretical development glued by core theories, ASD risks repeating wrong practices and oversimplifying real-world phenomena. To address this issue and foster a strong link between empirical evidence and theoretical development, we conduct this critical review using the Complex Network Analysis (CNA) approach, in response to the editors’ call on the XP2020 conference. Based on 83 selected articles and 88 identified theories, our analysis traced the originating disciplines of these theories and synthesized 3 key theory communities. We position ASD core theories between empirical generalization and middle-range theories in the SE theory spectrum and offer practical guidelines for researchers to use, borrow, and generate ASD theories. It is further recommended that new theory development be aligned with the theory of coordination and control theory while employing Complex Adaptive Systems (CAS) theory as a theoretical lens when borrowing theories to ASD. Xiaofeng Wang 0001, Zheying Zhang, Dominik Siemon, Sami Hyrynsalmi |
XP | 5 |
| 2025 | Management of DevSecOps Process: An Empirical InvestigationabstractABSTRACT Context DevSecOps integrates security into the DevOps project lifecycle, uniting development, operations, and security practices. This integration, while beneficial for developing secure software, introduces complexity from a project management perspective. This study delves into this complexity by examining the 10 knowledge areas of the Project Management Body of Knowledge (PMBOK) within the context of DevSecOps project management. Objective This study aims to explore and understand the application of PMBOK's 10 knowledge areas in managing DevSecOps projects, focusing on the guidelines that are important to consider in integration of security practices throughout the development lifecycle. Method Our research approach involved two phases: Firstly, we developed a theoretical model grounded in DevSecOps guidelines identified from existing literature. Secondly, we conducted a quantitative survey targeting industry practitioners to gather insights into the practical application of the theoretical model. The study involved 138 responses from professionals, which were subsequently analyzed using correlation and Partial Least Squares (PLS) analysis to test the hypotheses posited in the theoretical model. Results The analysis reveals critical insights into the management of DevSecOps projects, highlighting the importance of adhering to specific guidelines to navigate the complexities introduced by the integration of security practices. The empirical data support the theoretical model, underscoring the relevance of PMBOK's knowledge areas in the successful management of DevSecOps projects. Conclusion For organizations committed to the DevSecOps paradigm, it is imperative to consider and implement the identified guidelines. These guidelines not only support the sustainable integration of security practices into DevOps projects but also contribute to the overall success and security of the software developed under this paradigm. Muhammad Azeem Akbar, Arif Ali Khan, Sajjad Mahmood, Sami Hyrynsalmi |
Softw. Pract. Exp. | 4 |
| 2024 | Towards People Maturity for Secure Development and Operations: A visionabstractDevOps (development and operations) is a set of collaborative practices that automate continuous delivery of new software versions with an aim to reduce the development life cycle and produce quality software products. Security is an important attribute of quality software. Software is secure if it does not allow the confidentiality, integrity, and availability of its data, code, or service to be compromised. In order to take full advantage of DevOps, security needs to play an integral part in the development life cycle of a software. The DevSecOps (development, security, and operations) refers to the integrating security practices within the DevOps process. DevSecOps promotes the shifting security to the early stages of a project. Traditionally, security testing is done towards the end of the software lifecycle. However, fixing issues later in the process is more costly than making sure defects do not happen in the beginning. DevSecOps goes beyond automation, continuous integration, testing and delivery processes, since it also encompasses people. In fact, DevSecOps promotes the collaboration between the development, operations, and security teams. When security comes into DevOps routines, people play an even more relevant role involving the collaboration between those teams and security team. In any organization policies, standards, procedures and code of conducts are designed for people to follow. People are executers of policies. The human factor is one of the major forces behind effectiveness, or failure of a security system. Traditionally, the organizations focus on protecting their infrastructure, from security threats and they ignore human behavior that may result in malicious activities during software development process. Human aspect is considered as one of the major reasons of security vulnerability is due to malicious human behavior, who are involved in DevSecOps process; human may make mistakes due to lack of security perceptions, skills, and knowledge. Muhammad Azeem Akbar, Saima Rafi, Sami Hyrynsalmi, Arif Ali Khan |
EASE | 3 |
| 2024 | Multivocal Literature Review on DevOps Critical Success FactorsabstractDevOps is a methodology that seeks to unify development and operations teams in organizations, aiming to facilitate faster software delivery and promote collaboration to build a positive company culture. Our research aims to investigate the current state-of-the-art of DevOps, align academic research with industry practices, and identify critical success factors. We conducted a comprehensive literature review using a variety of databases and search engines, which revealed that several factors are essential to the success of DevOps, including DevOps culture, automation processes, continuous integration, and deployment, monitoring, and feedback, standardization with tools, team leadership, and DecSecOps for security issues. While DevOps has gained significant attention, it remains essential to understand practitioners’ perspectives. Our research has the potential to strengthen the concepts and ideas of critical success factors, broaden DevOps practices and perspectives for professionals, and enhance academic knowledge in this area. Nasreen Azad, Sami Hyrynsalmi |
EASE | 2 |
| 2024 | 6GSoft: Software for Edge-to-Cloud ContinuumabstractIn the era of 6G, developing and managing software requires cutting-edge software engineering (SE) theories and practices tailored for such complexity across a vast number of connected edge devices. Our project aims to lead the development of sustainable methods and energy-efficient orchestration models specifically for edge environments, enhancing architectural support driven by AI for contemporary edge-to-cloud continuum computing. This initiative seeks to position Finland at the forefront of the 6G landscape, focusing on sophisticated edge orchestration and robust software architectures to optimize the performance and scalability of edge networks. Collaborating with leading Finnish universities and companies, the project emphasizes deep industry-academia collaboration and international expertise to address critical challenges in edge orchestration and software architecture, aiming to drive significant advancements in software productivity and market impact. Muhammad Azeem Akbar, Matteo Esposito 0001, Sami Hyrynsalmi, Karthikeyan Dinesh Kumar, Valentina Lenarduzzi, Xiaozhou Li 0002, Ali Mehraj, Tommi Mikkonen, Sergio Moreschini, Niko Mäkitalo, Markku Oivo, Anna-Sofia Paavonen, Risha Parveen, Kari Smolander, Ruoyu Su, Kari Systä, Davide Taibi 0001, Zheying Zhang, Muhammad Zohaib |
SEAA | 3 |
| 2024 | 6G secure quantum communication: a success probability prediction modelabstractAbstract The emergence of 6G networks initiates significant transformations in the communication technology landscape. Yet, the melding of quantum computing (QC) with 6G networks although promising an array of benefits, particularly in secure communication. Adapting QC into 6G requires a rigorous focus on numerous critical variables. This study aims to identify key variables in secure quantum communication (SQC) in 6G and develop a model for predicting the success probability of 6G-SQC projects. We identified key 6G-SQC variables from existing literature to achieve these objectives and collected training data by conducting a questionnaire survey. We then analyzed these variables using an optimization model, i.e., Genetic Algorithm (GA), with two different prediction methods the Naïve Bayes Classifier (NBC) and Logistic Regression (LR). The results of success probability prediction models indicate that as the 6G-SQC matures, project success probability significantly increases, and costs are notably reduced. Furthermore, the best fitness rankings for each 6G-SQC project variable determined using NBC and LR indicated a strong positive correlation (rs = 0.895). The t-test results (t = 0.752, p = 0.502 > 0.05) show no significant differences between the rankings calculated using both prediction models (NBC and LR). The results reveal that the developed success probability prediction model, based on 15 identified 6G-SQC project variables, highlights the areas where practitioners need to focus more to facilitate the cost-effective and successful implementation of 6G-SQC projects. Muhammad Azeem Akbar, Arif Ali Khan, Sami Hyrynsalmi, Javed Ali Khan |
Autom. Softw. Eng. | 3 |
| 2024 | Role of quantum computing in shaping the future of 6 G technologyabstractThe emergence of 6 G technology heralds a groundbreaking era in digital connectivity, envisaging universal and seamless links. To address the intricate computational and security requirements of this revolution, the integration of quantum computing (QC) into these networks is perceived as a promising solution. The objective this study presents a comprehensive investigation into the potential roles and implications of QC within the context of 6 G technology. To address the objectives of this study, firstly, we have conducted literature survey to identify the key applications of using QC in 6 G technology. Secondly, we performed interview study with industry experts to identify the best practices related to the key application of QC in 6 G technology. Our study unfolds in two distinct stages: firstly, we identify 15 key applications of QC in 6 G technology and segmented into 4 core areas. Secondly, the literature findings were empirically validated by conducting interview study and identified 49 best practices related to one of the identified key applications of QC in 6 G technology. The outcomes of this research lay a solid foundation for understanding both the pivotal applications of QC in 6 G technology and the effective practices for its implementation, thus providing valuable insights to both academics and industry practitioners. Muhammad Azeem Akbar, Arif Ali Khan, Sami Hyrynsalmi |
Inf. Softw. Technol. | 3 |
| 2024 | Work-from-home impacts on software project: A global study on software development practices and stakeholder perceptionsabstractContext The COVID‐19 pandemic has had a disruptive impact on how people work and collaborate across all global economic sectors, including software business. While remote working is not new for software engineers, forced WFH situations come with both limitations and opportunities. As the ‘new normal’ for working might be based on the current state of Work‐from‐home (WFH), it is useful to understand what has happened and learn from that. Objective This study aims to gain insights into how their WFH arrangement impacts project management and software engineering. We are also interested in exploring these impacts in different contexts, such as startups and established companies. Method We conducted a global‐scale, cross‐sectional survey during the spring and summer 2021. Our results are based on quantitative and qualitative analysis of 297 valid responses. Results We characterize the profile of WFH in both spatial and temporal aspects, together with a set of common collaborative tools and coordination and control mechanisms. We revealed some areas of project management that are relatively more challenging during WFH situations, such as coordination, communication and project planning. We also revealed a mixed picture of the perceived impact of WFH on different software engineering activities. Conclusion WFH is a situational phenomenon which can have both negative and positive impact on software teams. For practitioners, we suggest a unified approach to consider the context of WFH, collaborative tools, associated coordination and control approaches and a process that resolve those aspects that are sensitive to physical interaction. Anh Nguyen-Duc 0001, Dron Khanna, Giang Huong Le, Des Greer, Xiaofeng Wang 0001, Luciana A. M. Zaina, Gerardo Matturro, Jorge Melegati, Eduardo Guerra 0001, Petri Kettunen, Sami Hyrynsalmi, Henry Edison, Afonso Sales, Rafael Chanin, Didzis Rutitis, Kai-Kristian Kemell, Abdullah Aldaeej, Tommi Mikkonen, Juan Garbajosa, Pekka Abrahamsson |
Softw. Pract. Exp. | 11 |
| 2023 | Striving for Freedom in a Large-Scale Agile Environment with an Entrepreneurial Mindset of a Product OwnerabstractAbstract In a large-scale agile environment, a Product Owner receives requests from many different directions. Freedom to influence the direction of the product and push ideas forward sometimes requires saying “no”. This is a case study that has been made by interviewing several Product Owners or people working in a Product Owner type of role. The case company, which is a large financial organization, encourages Product Owners to take responsibility by valuing an entrepreneurial mindset. This research examines whether it is possible to exercise entrepreneurial freedom in the Product Owner’s work, and how much freedom the Product Owner has in the direction of the product, i.e. whether they have the freedom to say “no”. A total of 18 Product Owners, and those in similar roles, as well as managers from the case company, were interviewed. The findings show that the role of the Product Owner needs to be clarified in order to have more freedom to act. Prioritizing is difficult and saying “no” is more difficult than desired. Product Owners find the urge for an entrepreneurial attitude understandable, however, it does not seem to fit perfectly into the everyday work life of a Product Owner in a large-scale set-up. When the understanding of the role deepens, Product Owners could have greater freedom to make their products successful. Piret Niva, Maria Paasivaara, Sami Hyrynsalmi |
XP | 3 |
| 2023 | DevOps critical success factors - A systematic literature reviewabstractDevOps is a set of software development and operation practices and a recent addition to a large family of different kinds of software process models. The model emerged out of the observation that information systems operations and developments should be closely integrated activities to ensure the success of any organization. Thus, DevOps methods are an additive tool for companies to improve overall performance in their software development processes and operations. This paper aims to identify the various critical success factors (CSFs) of DevOps projects that have been discussed in prior research. In addition, this study proposes a comprehensive framework for depicting how these CSFs impact or drive DevOps success. This study consists of a systematic literature review to collect the primary articles for the analysis. After searches in four major publication databases and snowballing, we selected 38 primary studies for the analysis. Nearly 100 different CSFs were identified, which were then categorized into Technical, Organizational, and Social & Cultural dimensions. Based on the results of the literature analysis, a comprehensive framework is proposed that depicts how the CSFs impact or drive DevOps success. This paper presents a DevOps framework with various CSFs based on prior literature. The proposed framework will provide collective knowledge of DevOps success factors, which will allow researchers and practitioners to enhance their understanding of CSFs and learn how to handle DevOps issues in organizations. In particular, the paper highlights a number of future research directions related to CSFs. Nasreen Azad, Sami Hyrynsalmi |
Inf. Softw. Technol. | 2 |
| 2022 | A Process Model of Product Strategy Development: A Case of a B2B SaaS Product
Bogdan Moroz, Andrey Saltan, Sami Hyrynsalmi |
PROFES | 3 |
| 2021 | Security in agile software development: A practitioner surveyabstractContext: Software security engineering provides the means to define, implement and verify security in software products. Software security engineering is performed by following a software security development life cycle model or a security capability maturity model . However, agile software development methods and processes, dominant in the software industry, are viewed to be in conflict with these security practices and the security requirements. Objective: Empirically verify the use and impact of software security engineering activities in the context of agile software development , as practiced by software developer professionals. Method: A survey ( N = 61 ) was performed among software practitioners in Finland regarding their use of 40 common security engineering practices and their perceived security impact, in conjunction with the use of 16 agile software development items and activities. Results: The use of agile items and activities had a measurable effect on the selection of security engineering practices. Perceived impact of the security practices was lower than the rate of use would imply: This was taken to indicate a selection bias, caused by e.g. developers’ awareness of only certain security engineering practices, or by difficulties in applying the security engineering practices into an iterative software development workflow. Security practices deemed to have most impact were proactive and took place in the early phases of software development. Conclusion: Systematic use of agile practices conformed, and was observed to take place in conjunction with the use of security practices. Security activities were most common in the requirement and implementation phases. In general, the activities taking place early in the life cycle were also considered most impactful. A discrepancy between the level of use and the perceived security impact of many security activities was observed. This prompts research and methodological development for better integration of security engineering activities into software development processes, methods, and tools. Kalle Rindell, Jukka Ruohonen, Johannes Holvitie, Sami Hyrynsalmi, Ville Leppänen |
Inf. Softw. Technol. | 4 |
| 2020 | Business Model Canvas Should Pay More Attention to the Software Startup TeamabstractBusiness Model Canvas (BMC) is a tool widely used to describe startup business models. Despite the various business aspects described, BMC pays a little emphasis on team- related factors. The importance of team-related factors in software development has been acknowledged widely in literature. While not as extensively studied, the importance of teams in software startups is also known in both literature and among practitioners. In this paper, we propose potential changes to BMC to have the tool better reflect the importance of the team, especially in a software startup environment. Based on a literature review, we identify various components related to the team, which we then further support with empirical data. We do so by means of a qualitative case study of five startups. Kai-Kristian Kemell, Atte Elonen, Mari Suoranta, Anh Nguyen-Duc 0001, Juan Garbajosa, Rafael Chanin, Jorge Melegati, Usman Rafiq, Abdullah Aldaeej, Nana Assyne, Afonso Sales, Sami Hyrynsalmi, Juhani Risku, Henry Edison, Pekka Abrahamsson |
SEAA | 12 |
| 2018 | Surveying Secure Software Development Practices in FinlandabstractCombining security engineering and software engineering is shaping the software development processes and shifting the emphasis of information security from the operation environment into the main information asset: the software itself. To protect software and data assets, software development is subjected to an increasing amount of external regulation and organizational security requirements. To fulfill these requirements, the practitioners producing secure software have plenty of models, guidelines, standards and security instructions to follow, but very little scientific knowledge about effectiveness of the security they take. Kalle Rindell, Jukka Ruohonen, Sami Hyrynsalmi |
ARES | 3 |
| 2018 | Technical debt and agile software development practices and processes: An industry practitioner surveyabstractContext: Contemporary software development is typically conducted in dynamic, resource-scarce environments that are prone to the accumulation of technical debt. While this general phenomenon is acknowledged, what remains unknown is how technical debt specifically manifests in and affects software processes, and how the software development techniques employed accommodate or mitigate the presence of this debt. Objectives: We sought to draw on practitioner insights and experiences in order to classify the effects of agile method use on technical debt management, given the popularity and perceived success of agile methods. We explore the breadth of practitioners’ knowledge about technical debt; how technical debt is manifested across the software process; and the perceived effects of common agile software development practices and processes on technical debt. In doing so, we address a research gap in technical debt knowledge and provide novel and actionable managerial recommendations. Method: We designed, tested and executed a multi-national survey questionnaire to address our objectives, receiving 184 responses from practitioners in Brazil, Finland, and New Zealand. Results: Our findings indicate that: 1) Practitioners are aware of technical debt, although, there was under utilization of the concept, 2) Technical debt commonly resides in legacy systems, however, concrete instances of technical debt are hard to conceptualize which makes it problematic to manage, 3) Queried agile practices and processes help to reduce technical debt; in particular, techniques that verify and maintain the structure and clarity of implemented artifacts (e.g., Coding standards and Refactoring) positively affect technical debt management. Conclusions: The fact that technical debt instances tend to have characteristics in common means that a systematic approach to its management is feasible. However, notwithstanding the positive effects of some agile practices on technical debt management, competing stakeholders’ interests remain a concern. Johannes Holvitie, Sherlock A. Licorish, Rodrigo O. Spínola, Sami Hyrynsalmi, Stephen G. MacDonell, Thiago Souto Mendes, Jim Buchan, Ville Leppänen |
Inf. Softw. Technol. | 4 |
| 2018 | Diversification and obfuscation techniques for software security: A systematic literature reviewabstractContext: Diversification and obfuscation are promising techniques for securing software and protecting computers from harmful malware. The goal of these techniques is not removing the security holes, but making it difficult for the attacker to exploit security vulnerabilities and perform successful attacks. Objective: There is an increasing body of research on the use of diversification and obfuscation techniques for improving software security; however, the overall view is scattered and the terminology is unstructured. Therefore, a coherent review gives a clear statement of state-of-the-art, normalizes the ongoing discussion and provides baselines for future research. Method: In this paper, systematic literature review is used as the method of the study to select the studies that discuss diversification/obfuscation techniques for improving software security. We present the process of data collection, analysis of data, and report the results. Results: As the result of the systematic search, we collected 357 articles relevant to the topic of our interest, published between the years 1993 and 2017. We studied the collected articles, analyzed the extracted data from them, presented classification of the data, and enlightened the research gaps. Conclusion: The two techniques have been extensively used for various security purposes and impeding various types of security attacks. There exist many different techniques to obfuscate/diversify programs, each of which targets different parts of the programs and is applied at different phases of software development life-cycle. Moreover, we pinpoint the research gaps in this field, for instance that there are still various execution environments that could benefit from these two techniques, including cloud computing, Internet of Things (IoT), and trusted computing. We also present some potential ideas on applying the techniques on the discussed environments. Shohreh Hosseinzadeh, Sampsa Rauti, Samuel Laurén, Jari-Matti Mäkelä, Johannes Holvitie, Sami Hyrynsalmi, Ville Leppänen |
Inf. Softw. Technol. | 6 |
| 2018 | A case study on software vulnerability coordination
Jukka Ruohonen, Sampsa Rauti, Sami Hyrynsalmi, Ville Leppänen |
Inf. Softw. Technol. | 3 |
| 2017 | Busting a Myth: Review of Agile Security Engineering MethodsabstractEngineering methods are essential in software development, and form a crucial element in the design and implementation of software security. Security engineering processes and activities have a long and well-standardized history of integration with software development methods. The inception of iterative and incremental software development methods raised suspicions of an inherent incompatibility between the traditional non-agile security processes and the new agile methods. This suspicion still affects the attitude towards agile security. To examine and explore this myth, this study presents a literature review of a selected set of agile secure software development methods. A systematic literature method was used to find the definitive set of secure agile software development methods, of which a core set of 11 papers was selected for analysis, and the security activities documented in the methods were extracted. The results show a wide and well-documented adaptation of security activities in agile software development, with the observed activities covering the whole security development life cycle. Based on the analysis, the inherent insecurity of the agile software development methods can be declared to be a mere myth. Kalle Rindell, Sami Hyrynsalmi, Ville Leppänen |
ARES | 2 |
| 2017 | Mining social networks of open source CVE coordinationabstractCoordination is one central tenet of software engineering practices and processes. In terms of software vulnerabilities, coordination is particularly evident in the processes used for obtaining Common Vulnerabilities and Exposures (CVEs) identifiers for discovered and disclosed vulnerabilities. As the central CVE tracking infrastructure maintained by the non-profit MITRE Corporation has recently been criticized for time delays in CVE assignment, almost an ideal case is available for studying software and security engineering coordination practices with practical relevance. Given this pragmatic motivation, this paper examines open source CVE coordination that occurs on the public oss-security mailing list. By combining social network analysis with a data-driven, exploratory research approach, the paper asks six data mining questions with practical relevance. By contemplating about answers to the questions asked by means of descriptive statistics, the paper consequently contributes not only to the contemporary industry debates, but also to the tradition of empirical vulnerability research. The perspective and the case are both novel in this tradition, thus opening new avenues for further empirical inquiries and practical improvements for the contemporary CVE coordination. Jukka Ruohonen, Sami Hyrynsalmi, Sampsa Rauti, Ville Leppänen |
IWSM-Mensura | 2 |
| 2017 | Top Management Support for Software Cost Estimation - A Case Study of the Current Practice and Impacts
Jurka Rahikkala, Sami Hyrynsalmi, Ville Leppänen, Tommi Mikkonen, Johannes Holvitie |
PROFES | 2 |
| 2017 | Tightroping between APT and BCI in small enterprisesabstractPurpose The contemporary internet provisions increasingly sophisticated security attacks. Besides underlining the advanced nature of these attacks, the concept of an advanced persistent threat (APT) catalyzes the important perspective of longitudinal persistence; attacks are not only carefully planned and targeted but the subsequent exploitation period covers long periods of time. If an APT successfully realizes into such exploitation, information assets may be continuously monitored for harvesting business-critical information (BCI). These threats are relevant for the security of small enterprises, and this study aims to examine the qualitative factors that shape the security mindsets among these. Design/methodology/approach The data are collected with semi-structured interviews of six enterprises in a small regional market segment. The analysis is based on a fourfold taxonomy that delivers three mindset profiles, while particular emphasis is placed on the subjective security notions that shape the typical strategizing among enterprises. Findings APT is poorly understood among the observed segment, which tends to often also explicitly downplay the strategic relevance of the concept, but a more pressing challenge relates to the observation that business data is often perceived to have no value. The delivered results can be used to improve the situation. Originality/value This study is among the firsts to explore perceptions of small enterprises toward APT and BCI. The results reveal problematic mindsets and offers new avenues for practitioners as well as academics to study and improve the situation. Jesse Kaukola, Jukka Ruohonen, Antti Tuomisto, Sami Hyrynsalmi, Ville Leppänen |
Inf. Comput. Secur. | 4 |
| 2016 | Case Study of Security Development in an Agile Environment: Building Identity Management for a Government AgencyabstractIn contemporary software development projects and computing tasks, security concerns have an increasing effect, and sometimes even guide both the design and the project's processes. In certain environments, the demand for the security becomes the main driver of the development. In these cases, the development of the product requires special security arrangements for development and hosting, and specific security-oriented processes for governance. Compliance with these requirements using agile development methods may not only be a chance to improve the project efficiency, but can in some cases, such as in the case discussed in this paper, be an organizational requirement. This paper describes a case of building a secure identity management system and its management processes, in compliance with the Finnish government's VAHTI security instructions. The building project was to be implemented in accordance to the governmental security instructions, while following the service provider's own management framework. Project itself was managed with Scrum. The project's steering group required the use of Scrum, and this project may be viewed as a showcase of Scrum's suitability to multi-teamed, multi-site, security standard-compliant work. We also discuss the difficulties of fulfilling strict security regulations regarding both the development process and the end product in this project, and the difficulties utilizing Scrum to manage a multi-site project organization. Evaluation of the effects of the security work to project cost and efficiency is also presented. Finally, suggestions to enhance the Scrum method for security-related projects are made. Kalle Rindell, Sami Hyrynsalmi, Ville Leppänen |
ARES | 2 |
| 2016 | Exploring the clustering of software vulnerability disclosure notifications across software vendorsabstractThis exploratory empirical paper investigates annual time delays between vulnerability disclosure notifications and acknowledgments by means of network analysis. These delays are approached through a potential clustering effect of vulnerabilities across software vendors. The analysis is based on a projection from bipartite vendor-vulnerability structures to one-mode vendor-vendor networks, while the hypothesized clustering effect is approached with a conventional community detection algorithm. According to the results, (a) vulnerabilities cluster across vendors, (b) which also explains a portion of the time delays, although (c) the clustering is not stable annually. The computed network (d) clusters can be also interpreted by reflecting these against common software security attack surfaces. The results can be used to contemplate (e) practical means with which the efficiency of vulnerability disclosure could be improved. Jukka Ruohonen, Johannes Holvitie, Sami Hyrynsalmi, Ville Leppänen |
AICCSA | 3 |
| 2016 | Adoption and Suitability of Software Development Methods and PracticesabstractIn seeking to complement consultants' and tool vendors' reports, there has been an increasing academic focus on understanding the adoption and use of software development methods and practices. We surveyed practitioners working in Brazil, Finland, and New Zealand in a transnational study to contribute to these efforts. Among our findings we observed that most of the 184 practitioners in our sample focused on a small portfolio of projects that were of short duration. In addition, Scrum and Kanban were used most; however, some practitioners also used conventional methods. Coding Standards, Simple Design and Refactoring were used most by practitioners, and these practices were held to be largely suitable for project and process management. Our evidence points to the need to properly understand and support a wide range of software methods. Sherlock A. Licorish, Johannes Holvitie, Sami Hyrynsalmi, Ville Leppänen, Rodrigo O. Spínola, Thiago Souto Mendes, Stephen G. MacDonell, Jim Buchan |
APSEC | 3 |
| 2016 | Trading exploits online: A preliminary case studyabstractA software defect that exposes a software system to a cyber security attack is known as a software vulnerability. A software security exploit is an engineered software solution that successfully exploits the vulnerability. Exploits are used to break into computer systems, but exploits are currently used also for security testing, security analytics, intrusion detection, consultation, and other legitimate and legal purposes. A well-established market emerged in the 2000s for software vulnerabilities. The current market segments populated by small and medium-sized companies exhibit signals that may eventually lead to a similar industrialization of software exploits. To these ends and against these industry trends, this paper observes the first online market place for trading exploits between buyers and sellers. The paper adopts three different perspectives to study the case. The paper (a) portrays the studied exploit market place against the historical background in the software security industry. A qualitative assessment is made to (b) evaluate the case against the common characteristics of traditional online market places. The qualitative observations are used in the quantitative part (c) for predicting the price of exploits with partial least squares regression. The results show that (i) the case is unique from a historical perspective, although (ii) the online market place characteristics are familiar. The regression estimates also indicate that (iii) the pricing of exploits is only partially dependent on such factors as the targeted platform, the date of disclosure of the exploited vulnerability, and the quality assurance service provided by the market place provider. The results allow to contemplate (iv) practical means for enhancing the market place. Jukka Ruohonen, Sami Hyrynsalmi, Ville Leppänen |
RCIS | 2 |
| 2016 | The influence of developer multi-homing on competition between software ecosystemsabstractHaving a large number of applications in the marketplace is considered a critical success factor for software ecosystems. The number of applications has been claimed to determine which ecosystems holds the greatest competitive advantage and will eventually dominate the market. This paper investigates the influence of developer multi-homing (i.e., participating in more than one ecosystem) in three leading mobile application ecosystems. Our results show that when regarded as a whole, mobile application ecosystems are single-homing markets. The results further show that 3% of all developers generate more than 80% of installed applications and that multi-homing is common among these developers. Finally, we demonstrate that the most installed content actually comprises only a small number of the potential value propositions. The results thus imply that attracting and maintaining developers of superstar applications is more critical for the survival of a mobile application ecosystem than the overall number of developers and applications. Hence, the mobile ecosystem is unlikely to become a monopoly. Since exclusive contracts between application developers and mobile application ecosystems are rare, multi-homing is a viable component of risk management and a publishing strategy. The study advances the theoretical understanding of the influence of multi-homing on competition in software ecosystems. Sami Hyrynsalmi, Arho Suominen, Matti Mäntymäki |
J. Syst. Softw. | 1 |
| 2015 | Security and Privacy in Cloud Computing via Obfuscation and Diversification: A SurveyabstractThe development of cloud computing has facilitate the organizations with its services. This makes the security and privacy of the cloud even more significant. Diversification and obfuscation approaches are of the most promising proactive techniques that protect computers from harmful malware, by preventing them to take advantage of the security vulnerabilities. There is a large body of research on the use of diversification and obfuscation techniques for improving the security in various domains, including cloud computing. Cloud computing provides an excellent setting for applying diversification/obfuscation, as the computing platforms (virtual machines) are implemented in software. The main objective of this study is to determine in what ways obfuscation and diversification techniques are used to enhance the security and privacy of the cloud computing, and discover the potential avenues for the further research. To achieve this goal, we systematically review and report the papers that discuss/propose a technique to enhance the security and privacy of the cloud, using diversification and obfuscation techniques. As the result of the search we collected 43 papers published on the topic. In this report we present the process of data collection, analysis of the results, and classification of the related studies. The classification is done based on how the diversification/obfuscation techniques are used to enhance the security in cloud computing environment. The presented study gives a clear view of the state of the art of the existing works in the field, and sheds light on the areas remained intact which could be avenues for further research. The existing works cover surprisingly a small set of the wealth of opportunities for diversification/obfuscation. Shohreh Hosseinzadeh, Sami Hyrynsalmi, Mauro Conti, Ville Leppänen |
CloudCom | 2 |
| 2015 | The potential development impact of mobile application vendors in developing countriesabstractThis study focuses on the state of application development in developing countries. The first objective is to estimate the existence of application vendors locating in developing countries. The second objective is to identify some reasons for developing country software vendors to enter mobile application markets rather than more traditional software markets. We argue that app stores offer a possibility for developing countries to pass some of the problems that come with industrialisation by partly post-industrialising directly. This study is divided to two phases which study the existence of application vendors in developing countries and their characteristics from different viewpoints. The first phase focuses on the analysis of the most popular applications in Google Play, Apple Store and Windows Phone Store. The second phase starts by analysing the email addresses of application vendors who sell their products in Google Play marketplace for devices using Android operating system and continues by sending questionnaire to those application vendors whose email addresses has country domain belonging to developing country. Our study shows that mobile applications are developed in developing countries, although, the biggest part of application vendors is located in developed countries. Among developing countries, most important mobile application producers belong to upper-middle income economies, such as China or Russia, or to lower-middle income economies, such as India. However, there appears to be few application vendors who operate from low income economies, such as Bangladesh or Kenya. According to our results, application vendors located in developing countries choose to develop mobile applications largely due to same reasons than application vendors located in developed countries. They prefer mobile application marketplaces, because they offer easy access to large amount of potential customers. Android platform is appreciated for its low development and access cost, however, it is criticized for the wide range of customer interfaces. Tuomas Tanskanen, Anne-Marie Tuikka, Sami Hyrynsalmi, Kai Kimppa |
ISTAS | 3 |
| 2015 | The sigmoidal growth of operating system security vulnerabilities: An empirical revisit
Jukka Ruohonen, Sami Hyrynsalmi, Ville Leppänen |
Comput. Secur. | 2 |
| 2015 | Time series trends in software evolutionabstractAbstract Background The laws of software evolution were formulated to describe time series trends in software over time. Objective Building on econometrics, the paper relates the laws theoretically to the concept of stationarity. The theoretical argumentation builds on the fact that in a stationary time series, the mean and variance remain constant. The concept is further elaborated with different statistical types of time series trends. These provide the objective for the empirical experiment that evaluates whether software size measures in a typical software evolution dataset are stationary. Method The time series analysis is based on conventional statistical tests for the evaluation of stationarity. Results The empirical dataset contains time series extracted from the version control systems used in Vaadin and Tomcat between circa 2006 and 2013. The results establish that the observed time series are neither stationary nor follow simple mathematical functions that would translate into stationarity. Conclusion The testing framework presented in the paper allows evaluating the stationarity of software evolution time series. The results can be interpreted theoretically against the laws of software evolution. These methodological and theoretical contributions improve the foundations of predictive time series modeling of software evolution problems. Copyright © 2015 John Wiley & Sons, Ltd. Jukka Ruohonen, Sami Hyrynsalmi, Ville Leppänen |
J. Softw. Evol. Process. | 2 |
| 2014 | Sources of value in application ecosystems
Sami Hyrynsalmi, Marko Seppänen, Arho Suominen |
J. Syst. Softw. | 1 |