4,951 papers · page 139 of 248
Yin Liu, Ana L. Milanova
We propose a mechanism for object access control which is based on the UML. Specifically, we propose use of ownership and immutability constraints on UML associations and verification of these constraints through reverse engineering. These constraints inherently support software …
Simone Livieri, Yoshiki Higo, Makoto Matsushita, Katsuro Inoue
The increasing performance-price ratio of computer hardware makes possible to explore a distributed approach at code clone analysis. This paper presents D-CCFinder, a distributed approach at large-scale code clone analysis. D-CCFinder has been implemented with 80 PC workstations …
Stephanie Ludi
Undergraduate software engineering courses aim to prepare students to deliver software in a variety of domains. The manner in which these courses are conducted varies, though team projects with real or imaginary stakeholders are common. While the key course concepts vary from the…
Neil A. M. Maiden, Cornelius Ncube, Suzanne Robertson
Requirements engineering is a creative process in which stakeholders work together to create ideas for new software systems that are eventually expressed as requirements. This paper reports a workshop that integrated creativity techniques with different types of use case and syst…
Rupak Majumdar, Koushik Sen
We present hybrid concolic testing, an algorithm that interleaves random testing with concolic execution to obtain both a deep and a wide exploration of program state space. Our algorithm generates test inputs automatically by interleaving random testing until saturation with bou…
Sam Malek, Chiyoung Seo, Sharmila Ravula, Brad Petrus, Nenad Medvidovic
It has been widely advocated that software architecture provides an effective set of abstractions for engineering (families of) complex software systems. However, architectural concepts are seldom supported directly at the level of system implementation. In embedded environments …
Leonardo Mariani, Sofia Papagiannakis, Mauro Pezzè
Software engineers frequently update COTS components integrated in component-based systems, and can often chose among many candidates produced by different vendors. This paper tackles both the problem of quickly identifying components that are syntactically compatible with the in…
Marius Marin, Leon Moonen, Arie van Deursen
Understanding crosscutting concerns is difficult because their underlying relations remain hidden in a class-based decomposition of a system. Based on an extensive investigation of crosscutting concerns in existing systems and literature, we identified a number of typical impleme…
David B. Martin, John Rooksby, Mark Rouncefield, Ian Sommerville
In this paper we report on an ethnographic study of a small software house to discuss the practical work of software testing. Through use of two rich descriptions, we discuss that 'rigour' in systems integration testing necessarily has to be organisationally defined. Getting requ…
Aleksandar Milicevic, Sasa Misailovic, Darko Marinov, Sarfraz Khurshid
This paper describes the Korat tool for constraint-based generation of structurally complex test inputs for Java programs. Korat takes: (1) an imperative predicate that specifies the desired structural integrity constraints and (2) a finitization that bounds the desired test inpu…
Shiva Nejati, Mehrdad Sabetzadeh, Marsha Chechik, Steve M. Easterbrook, Pamela Zave
Model Management addresses the problem of managing an evolving collection of models, by capturing the relationships between models and providing well-defined operators to manipulate them. In this paper, we describe two such operators for manipulating hierarchical Statecharts: Mat…
T. H. Ng, Shing-Chi Cheung, W. K. Chan, Yuen-Tak Yu
One claimed benefit of deploying design patterns is facilitating maintainers to perform anticipated changes. However, it is not at all obvious that the relevant design patterns deployed in software will invariably be utilized for the changes. Moreover, we observe that many well-k…
Carlos Pacheco, Shuvendu K. Lahiri, Michael D. Ernst, Thomas Ball
We present a technique that improves random test generation by incorporating feedback obtained from executing test inputs as they are created. Our technique builds inputs incrementally by randomly selecting a method call to apply and finding arguments from among previously-constr…
Marco Pistoia, Stephen J. Fink, Robert J. Flynn, Eran Yahav
Modern multiuser software systems have adopted role-based access control (RBAC) for authorization management. This paper presents a formal model for RBAC policy validation and a static-analysis model for RBAC systems that can be used to (i) identify the roles required by users to…
Damith C. Rajapakse, Stan Jarzabek
Server page technique is commonly used for implementing Web application user interfaces. Server pages can represent many similar Web pages in a generic form. Yet our previous study revealed high rates of repetitions in Web applications, particularly in the user interfaces. Code d…
Murali Krishna Ramanathan, Ananth Grama, Suresh Jagannathan
Function precedence protocols define ordering relations among function calls in a program. In some instances, precedence protocols are well-understood (e.g., a call to pthread_mutex_init must always be present on all program paths before a call to pthread_mutex_lock). Oftentimes,…
Filippo Ricca, Massimiliano Di Penta, Marco Torchiano, Paolo Tonella, Mariano Ceccato
Proponents of design notations tailored for specific application domains or reference architectures, often available in the form of UML stereotypes, motivate them by improved understandability and modifiability. However, empirical studies that tested such claims report contradict…
Bradley S. Rubin, Bhabani S. Misra
This paper discusses our experiences developing and delivering a computer security curriculum in a graduate software engineering program. It describes our program and student backgrounds, our approach to teaching computer security aimed towards a software engineering audience wit…
Per Runeson, Magnus Alexandersson, Oskar Nyholm
Defect reports are generated from various testing and development activities in software engineering. Sometimes two reports are submitted that describe the same problem, leading to duplicate reports. These reports are mostly written in structured natural language, and as such, it…
Halvard Skogsrud, Boualem Benatallah, Fabio Casati, Farouk Toumani
We present a software tool and a framework for security protocol change management. While we focus on trust negotiation protocols in this paper, many of the ideas are generally applicable to other types of protocols. Trust negotiation is a flexible approach to access control that…