
One of the most successful architectural styles nowadays is service oriented architecture (SOA). In this type of architecture there are a lot of dependencies between services, but each service is an independent element of the system. In this situation we need some way to ensure that every service is working correctly and to take actions when something goes wrong to evolve the architecture as fast as we can. For example, if one of the lower level services of the service composition stops working, it could lead to a total or partial system malfunction. In this situation there is a need to be able to build reliable SOA systems. Our proposal, SALMon, is based on monitoring the services for service level agreement (SLA) violations. The SALMon architecture is composed of three types of components: Monitors that are composed of measure instruments, the measured quality attributes being taken from an ISO/IEC 9126-1-based service oriented quality model; analyzers that check the SLA rules; and decision makers that perform corrective actions to satisfy SLA rules again. These 3 types of components are mostly technology-independent and they act as services inside of a SOA system making our architecture very scalable and comfortable for its purpose.
The reuse of knowledge obtained during the elicitation of requirements for different COTS projects is a subject that still needs more research to be done. In this work we propose the use of Patterns of Requirements for the first steps of the COTS selection processes and the software life cycle.
This paper treats security from a software engineering point of view. Security issues of software components are usually handled at the two levels of development abstractions: by the security experts during the component design, and by the software engineers during the composition of an application system. Security experts identify the threats of the component, define the security policies and functions. On the other hand, the software engineers are more interested in the compositional impact and conformity of the security properties designed and implemented by the security experts. This paper identifies a third level of abstraction: security from the end-users' perspective. This paper argues that the end-users of the system should know the specific security objectives actually achieved at the system-level. This paper makes the following three specific contributions in this regard: (i) a need for a separate view of security at the end-user level; (ii) the formulation of security goals; (iii) the derivation of security goals for automatic processing.
Nowadays components-based development and requirements engineering (RE) are very active and growing fields in software engineering (SE). In this paper we present the preliminary ideas for a proposal of a component selection method whose development is fast, agile and requirements driven. The presented method is called COTSRE and it is based on SIREN, which is a method of RE based on the standards of this discipline and the use of reuse requirements catalogs. The final aim of our proposal is to achieve an RE method that guides the selection, the development and the composition of a set of independent software components, and whose application is the simplest possible. In this paper we also present some simples examples related to the domain of electronic mail applications.
Much work has been done in the area of Service-centric Software Engineering and Service oriented Architectures (SOA). However, comprehensive guidance on how to compose dynamic and context-aware services in order to be able to self-adapt and self-configure at run-time is rarely given. This paper provides such guidance in the form of an ISO/IEC 24744-based methodology, which includes the work that is expected to be performed (by people and by machines), the products to be involved, and the agents that participate. By using this methodology, Service-centric Software Engineering approaches can come closer to delivering tangible results.
As systems have grown larger and more complex into systems of systems, the community has learned much about what works and what doesn't when designing for interoperability. These lessons learned can help in identifying and predicting problems early in the development lifecycle. This workshop will bring together practitioners who have insights into addressing systems of systems interoperability. The session will focus on diagnosing interoperability issues within software systems; prognosticating interoperability challenges given a proposed system design or architecture; and the resulting impact on the system of systems design. The key questions to be addressed by the workshop are: “how can system interoperability issues be identified and addressed as early as possible; and how can this be confirmed?” Positions are invited from industry and academia that look at interoperability from the following perspectives: quantifiable requirements, architecture, design practices, analysis, testing, and lessons learned from successes and failures. Insights from traditional software systems and non-traditional environments that apply to system of systems development are particularly welcome. The proposed format is a 6 hour workshop comprised of 4-5 20 minute position papers combined with a healthy discussion component. The workshop seeks to leverage insights and identify proposed areas for further development and research.
Service oriented architecture (SOA) is becoming a standard de facto and a solution for defining interoperable architectures. Web Services (WS) platform is one of the most widely accepted implementations of this kind of service architectures. In this context there is a huge amount of specifications for a broad range of topics. This paper is focused on the growing importance of security, the increase of collaboration amongst organizations and the emergent need of modelling SOA and security aspects. This paper presents a modelling framework based on Eclipse platform for modelling and designing security aspects in SOA and a derivation mechanism in order to automatically generate Web service security elements. This approach is illustrated with an example.
Software frameworks enable modular, large-scale reuse by both providing a core architecture addressing recurring concerns in a certain domain and a set of variability options. However, the high volatility of requirements nowadays often imposes a number of framework changes with an architecture-wide impact. In order to avoid the framework design erosion, the modularity and stability of its core architecture implementation must be preserved. With aspect-oriented programming (AOP) promising superior software evolvability, there is a need for verifying its efficacy to enhance or not framework architecture stability. This paper presents a systematic case study where we have compared the evolution of 00 and aspectual versions of a code mobility framework, called MobiGrid. Our analysis was driven by the application of heterogeneous evolutionary changes to MobiGrid, such as feature extensions and compositions with a second framework. Our analysis is also rooted at a comprehensive suite of conventional quantitative stability and modularity indicators.
Software product lines (SPL) are a powerful way of ensuring quality, economic efficiency, and manageability of software system families. In SPL, a key aspect is the domain implementation, whose goal is to provide the implementation of reusable assets (components). However, current approaches present some gaps in this direction, such as the lack of definition on how to implement and document software components in a systematic way. In this context, this paper presents a method for domain implementation in software product lines. The method is based on a well defined set of guidelines, inputs, outputs, and roles, and uses OSGi as the main implementation technology. An experimental study evaluates the viability of the use of the method and the impact of applying it to a software development project.
In this paper we propose a solution that improves the synchronization and effectiveness of sending and receiving of goods and merchandise by transport companies. We use a service-oriented architecture for the exchange of information related to the reception of products, such as the predicted time when the delivery should take place or the delay in the arrival. Our solution is based on fleet management systems widely used in the transport companies. The main objective of this paper is to improve the interoperability between providers and consumers, thereby creating a communication environment versed in delivery plans. Another feature revised here is the analysis of vehicle tracking information to obtain accurate knowledge of the movement pattern followed by drivers and usefulness for the companies.
Business-Driven Development(BDD) is a research field that provides techniques and mechanisms for designing software systems starting from the business processes of the companies. Companies are in continuous evolution to adapt to market changes, thus, current process engineers redesign the processes every time that is needed using ad hoc techniques. This situation motivates that these changes, called runtime variability, must be managed. Some authors have used Software Product Lines (SPL) ideas to manage it. Current approaches for documenting runtime variability in SPL and BDD, proposes different model representations. Unfortunately, we have determined that the expressiveness level in BDD is not adequate, and that SPL solutions needs for adaptation to BDD context for describing under which circumstances a business evolves. In this paper, we present a model for representing runtime variability in BDD systems. The main contributions of this proposal are: (i) it presents the enough expressiveness level for representing runtime variability; and (ii) process engineers can represent and understand under which events a business evolves and how this evolution is managed, which is not present in current approaches. We call this approach Product Evolution Model (PEM).
This presentation will discuss interoperability and, specifically, Enterprise Interoperability from a broad European perspective. It will summarise the achievements of the enterprise interoperability cluster to date, and its plans for the future. It will introduce the research direction of the new FP7 projects that belong to the cluster. In addition, the presentation will outline the R&D paths that the commission wish to explore in the field of enterprise interoperability for the next FP7 ICT Work Programme 2009-2010. The presentation will conclude with critical issues pertaining to advancing interoperability for enterprises in a period of profound market and structural change, unleashed by new ideas and processes of innovation, and in anticipation of Future Internet enterprise systems, services and communication networks.
Software product line engineering is often a more laborious process than anticipated beforehand, not in the least due to a growing demand for product features and an ever increasing complexity of the dependencies between functional components. One of the main ideas in software product line engineering is to delay variant binding, i.e., to delay the composition of particular product features to a later moment in the development or deployment process. Delaying variant binding affects testability, e.g., a full integration test is not possible before all the appropriate product variants have been bound. This paper suggests a variability and testability interaction model (VTIM) to better anticipate the software product line testing process. VTIM is applied in a case study in expressing the relationship between variability and testability for several variation points in a large-scale software product line of magnetic resonance imaging scanners developed by Philips Medical Systems. The case study illustrates how VTIM can be used as an analysis tool in everyday software engineering practice.
Over the past decade, the complexity of new and acquired systems of systems has increased dramatically. Until now, research has mainly focused on the properties of systems of systems. Recently, paradigms such as service oriented architecture (SOA) and Grid computing are being adopted to implement systems of systems. Additionally, techniques such as SoS Navigator are being developed to identify complexrelationships among organizations participating insuch systems of systems. However, there is no unifiedbody of knowledge that captures the engineeringpractices necessary for creating and managing systemsof systems. Further research is required to build this body of knowledge, but two main challenges must be addressed.
Summary form only given. This workshop is a key part of the ICCBSS transition and will determine the future focus for the conference. The necessity for the transition is a reflection of community's recognition that the complexity of the systems and their sizes have grown tremendously, and that, while COTS-based systems are vital in today's business, the hardest part of successful COTS-based development often has little to do with the "C" $"commercial" - in "COTS". The workshop will generate a robust discussion about the challenges - whether technological, organizational, or cultural $for constructing, acquiring, deploying, and sustaining software-intensive systems of systems that require interoperation among a wide variety of components or constituent systems. The objective of the workshop is to develop and organize the challenges into areas that are in need of further research and to provide some indications of the directions such research might take. Workshop contributions and results will be published as an SEI-NRC Technical Report
Service oriented computing represents the convergence of technology with an understanding of cross-organizational business processes. A service license describes the terms and conditions for the use and access of the service in a machine interpretable way. Generally, a service provider defines individual services with corresponding service licenses which consumers have to follow. Often, service consumers are interested in selecting a service based on certain licensing terms and/or in composing individual services depending on their needs. Thus, consumer-specified licenses become pivotal in service composition as this allows consumers to make a preference on what their service licenses should be and whether they can compose certain services together in a composition satisfying their specified licensing terms. In this paper, we propose an approach allowing service consumers to specify service licensing terms and select services that match licenses and implement this approach within a semi-automated service composition framework. Furthermore, we present a directional matchmaking algorithm to compare a consumer-specified service license with provider-specified service licenses and produce a composite service license satisfying the consumer-specified license.
Product line engineering and plug-in techniques pursue different but complementary goals. Software product line engineering strives for modeling the variability of software systems on different levels of abstraction, whereas plug-in systems support software extensibility, customizability, and evolution. We present an approach demonstrating the benefits of integrating those two areas and discuss the integration of a plug-in platform for enterprise software with an existing product line engineering tool suite. The plug-in platform provides extensibility as well as runtime reconfiguration and adaptation mechanisms on the .NET platform. Automatic runtime adaptations are attained by using the knowledge documented in variability models. We discuss several usage scenarios developed in cooperation with our industry partner illustrating the need of our approach in the enterprise software domain. Finally, we validate the approach on a commercial ERP system of our industry partner.
Models and model-based transformations are a key part of effective automated software development approaches. Unfortunately, early enthusiasm for Model Driven Architecture (MDA) has dissipated to the point that many people are openly skeptical of the value of any model-driven approach. This paper argues that to be successful, an MDA approach must be executed in context of a sound Enterprise Architecture providing an integrated business architecture and governance structure that enables an organization to respond to business requirements quickly and appropriately. The paper examines the practical realities of MDA, and provides examples, best practices, and heuristics for achieving success with MDA based on IBM's extensive experiences with MDA tooling and technologies.
In previous work, we proposed the use of software quality models for driving the formulation of requirements in the context of software package selection. Now, we report two related projects of construction of software quality models in the domains of document management, entreprise content management and Web content management. These domains may be considered particular cases of a more general category sometimes labeled as content management. The goals of these projects are several. First, to assess the scalability of our methods and artifacts. Second, to investigate the degree of reusability when working on domains so closely related. Third, in relation to the previous one, to gain more knowledge of the adequacy and effectiveness of our notion of software domains taxonomy. Fourth, to evaluate the suitability and usability of our DesCOTS system proposed as tool-support for these activities.
When creating systems by composing individual components, even if those ones behave as promised by its developer, unexpected situation may arise due to the composition operation itself. These situations, that may cause system failures or unsatisfied requirements occur because component providers have not foreseen the whole environments in which their own components may be deployed. They also do not know which third-party components their own components will be combined with. Here we present a framework for component development which promotes a system constructor (integrator) to adapt components at runtime, i.e., to adjust their behaviors to the needs of a component assembly. Components are equipped with appropriate mechanisms to adjust its behavior to assembly requirements and constraints without accessing to its source code. Only the component's behavioral model is reconsidered and thus, adapted so that it operates in conformance with the rest of the designed assembly.