Irum Rauf

dblp:89/3839 · DBLP profile ↗
← Back
11ranked-venue papers
6as first author
3since 2021 · last 2026
0000-0002-6650-0679ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 4 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1Security and privacy · 1Databases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Usable security · 67% Systems and software security · 33%
Software engineering, system software, and programming languages
1 paper
Empirical software engineering · 100%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Usable security › security behavior
developer security behavior
0.612022
The Case for Adaptive Security Interventions · ACM Trans. Softw. Eng. Methodol. 2022
Systems and software security › secure software development
secure coding
0.612022
The Case for Adaptive Security Interventions · ACM Trans. Softw. Eng. Methodol. 2022
Usable security
security interventions
0.612022
The Case for Adaptive Security Interventions · ACM Trans. Softw. Eng. Methodol. 2022
Empirical software engineering
developer studies
0.212022
The Case for Adaptive Security Interventions · ACM Trans. Softw. Eng. Methodol. 2022

Methods — techniques the papers use, named apart from their topics

meta-analysis · 1.1cognitive psychology · 1.1
YearPublicationVenuePosition
2026 Temporal awareness and ethical reflection: Chronopolitical considerations for HCI research
abstract
HCI increasingly engages with the concept of time, with many studies focusing on how temporal relations are produced and reconfigured through computing technologies. However, less attention is paid to the impact of temporality on researchers themselves and specifically their capacity for ethical reflection and action. This paper explores the interplay between temporal features and ethical reflection in HCI research projects. Through a reflective multi-ethnography of nine research projects, we examine how temporal features can influence ethical capacity across the lifecycle of research. The study employs infrastructural and chronopolitical analysis (after Star and Sharma) and offers a range of considerations for researchers to help activate greater temporal awareness for everyday wisdom, to acknowledge temporal power, mobilise responsibility, counter isolation in interdisciplinarity, and promote collective action and dynamic methodologies for temporal research. The study responds to calls for more ethnographic approaches to temporality that address specific HCI needs and focus on practice.
Marguerite Barry, Fiona McDermott, Daniel Snow, Jacinta Jardine, Maria Murray, Irum Rauf, Shelby Hagemann, Camille Nadal, Sarah Robinson
DIS6
2024 Children's perspectives on pain-logging: Insights from a Co-Design Approach
abstract
Pain is an essential indicator of health and guides clinical treatments. Logging pain is important in supporting this. However, there is little research into pre-adolescent children's pain logging tools. Utilising the Bluebells method to engage children as co-designers, we gathered children's perspectives on pain-logging tools; in the first workshop by using tangible design approaches to support creative thinking, and in the second workshop by discussing developed prototypes based on the children's designs. Our findings highlight design concepts that the research team – despite many years of pain-related research – had not considered in the context of paediatric logging, namely a) prioritizing children's privacy in social settings while using pain-logging tools; b) emphasizing personalization to boost engagement; and c) logging general well-being of children alongside pain intensity to collect more insightful data. These findings thus demonstrate the value of co-designing pain-logging technologies with children.
Linda Price, Irum Rauf, Daniel Gooch, Dmitri S. Katz, Oliver Pearce, Blaine A. Price
Conference on Designing Interactive Systems2
2022 The Case for Adaptive Security Interventions
abstract
Despite the availability of various methods and tools to facilitate secure coding, developers continue to write code that contains common vulnerabilities. It is important to understand why technological advances do not sufficiently facilitate developers in writing secure code. To widen our understanding of developers' behaviour, we considered the complexity of the security decision space of developers using theory from cognitive and social psychology. Our interdisciplinary study reported in this article (1) draws on the psychology literature to provide conceptual underpinnings for three categories of impediments to achieving security goals, (2) reports on an in-depth meta-analysis of existing software security literature that identified a catalogue of factors that influence developers' security decisions, and (3) characterises the landscape of existing security interventions that are available to the developer during coding and identifies gaps. Collectively, these show that different forms of impediments to achieving security goals arise from different contributing factors. Interventions will be more effective where they reflect psychological factors more sensitively and marry technical sophistication, psychological frameworks, and usability. Our analysis suggests “adaptive security interventions” as a solution that responds to the changing security needs of individual developers and a present a proof-of-concept tool to substantiate our suggestion.
Irum Rauf, Marian Petre, Thein Tun, Tamara Lopez, Paul Lunn, Dirk van der Linden, John N. Towse, Helen Sharp, Mark Levine, Awais Rashid, Bashar Nuseibeh
ACM Trans. Softw. Eng. Methodol.1
2018 Generating Cloud Monitors from Models to Secure Clouds
abstract
Authorization is an important security concern in cloud computing environments. It aims at regulating an access of the users to system resources. A large number of resources associated with REST APIs typical in cloud makes an implementation of security requirements challenging and error-prone. To alleviate this problem, in this paper we propose an implementation of security cloud monitor. We rely on model-driven approach to represent the functional and security requirements. Models are then used to generate cloud monitors. The cloud monitors contain contracts used to automatically verify the implementation. We use Django web framework to implement cloud monitor and OpenStack to validate our implementation.
Elena Troubitsyna, Irum Rauf
DSN2
2018 Formal Verification of Stateful Services with REST APIs Using Event-B
abstract
REST APIs are being increasingly used in the industry including their application in safety-critical domain and in the IoT world. They offer basic CRUD (create, retrieve, update and delete) interfaces. However, REST APIs can be used to build services with more advanced scenarios. Developing such services with REST constraints requires rigorous approaches that are capable of creating services that can be trusted for their behavior. In this work, we present an approach based on formal verification technique for a development of REST services using Event-B. We focus on deriving a correct system architecture by refinement and consistency verification of service design models. We illustrate our approach on a Hotel Reservation System.
Irum Rauf, Inna Vistbakka, Elena Troubitsyna
ICWS1
2016 Perceived obstacles by novice developers adopting user interface APIs and tools
abstract
An Application-Programming Interface or API provides a set of program functions that can be used to build new applications. In this paper, we study how to use the expectation-confirmation theory (ECT) to identify API usability problems, and what obstacles a novice developer faces when learning a new API and its accompanying development tools. We conduct a study over the impact of using a visual editor on API usability and then use the expectation-confirmation theory to study perceptions about the API and the editor. We finally present a list of obstacles found in the study that can be used by others to create more usable APIs and development tools.
Irum Rauf, Pekka Perala, Jouni Huotari, Ivan Porres
VL/HCC1
2014 An Integrated Approach for Designing and Validating REST Web Service Compositions
abstract
We present an integrated approach to design and validate RESTful composite web services. We use the Unified Modeling Language (UML) to specify the requirements, behavior and published resources of each web service. In our approach, a service can invoke other services and exhibit complex and timed behavior while still complying with the REST architectural style. We show how to transform service specifications into UPPAAL timed automata for verification and test generation. The service requirements are propagated to the UPPAAL timed automata during the transformation. Their reachability is verified in UPPAAL and they are used for computing coverage level during test generation. We validate our approach with a case study of a holiday booking web service.
Irum Rauf, Faezeh Siavashi, Dragos Truscan, Ivan Porres
WEBIST (1)1
2013 Consistency of UML Class and Statechart Diagrams with State Invariants
Ali Hanzala Khan, Irum Rauf, Ivan Porres
MODELSWARD2
2011 Towards Behaviorally Enriched Semantic RESTful Interfaces Using OWL2
Irum Rauf, Ivan Porres
ICWE1
2010 From Nondeterministic UML Protocol Statemachines to Class Contracts
abstract
A UML protocol state machine describes a behavioral interface for a class as a number of states and transitions between states triggered by method calls. In this paper, we present an approach to generate behavioral class interfaces in the form of class contracts from UML protocol state machines. The generated contracts can be used for documentation, test case generation, test case oracle, and as run-time assertions and thus help to test and validate the implementation of a class against its interface. We formalize protocol state machines with its structure and semantics for generating class contracts. The state invariants of the source and target states are considered along with the pre- and post-conditions of the transitions. Different types of transitions like simple, join, fork, high-level, and self transitions are supported, as well as non-deterministic behavior. The approach is supported by a tool to generate automatically the contracts from UML models.
Ivan Porres, Irum Rauf
ICST2
2008 UML Based Modeling of Web Service Composition - A Survey
abstract
Web service composition is an emerging trend in the field of service oriented architecture, where a new Web service is developed using existing Web services. Developing a composite Web service is a complex task. There are a number of reported techniques for modeling Web service compositions to specify the exact requirements, identify errors, and eliminate the conflicts in the development of a composite Web service at design level. In this paper, we study and classify various UML based approaches for modeling web service compositions. We also present a detailed analysis of all such approaches.
Irum Rauf, Muhammad Zohaib Z. Iqbal, Zafar I. Malik
SERA1