
Software Engineering Research and Practice,/I is a compendium of articles and papers that were presented at SERP '13, an international conference that serves researchers, scholars, professionals, students, and academicians. Selected topics include:* Novel Applications, Methodologies and Case Studies + Intellectual Property Issues + Education* Software Systems, Requirements + Middle-Ware + Software Development Process + Modeling and Architecture Description Languages* Software Architecture + Design Patterns* Unified Modeling Language / UML, Object Oriented Methods, and Case Studies* Usability Studies + Cost Estimation and Management + Software Testing, Analysis, Validation, and Verification + Performance Studies* Software Engineering and Management + Code Reuse + Software Maintenance Methods + Release Planning + Software Productivity and Quality* Agile Software Methods* Software Engineering and Embedded Systems* Software Engineering + Maintenance, Legacy Codes, Metrics, Collaborative Work, Software Process Improvement and Models, SOA, Case Studies
Using automated software tools is essential for successful planning and managing of projects. Many automated software tools have been developed in the industry. The literature on how to select the appropiate project management software tools is quite limited. This paper provides a comparison of a set of project management software tools (PMST). In this study, first, we developed criteria to determine which PMSTs would be subject to our analysis. Then, we developed criteria to compare and evaluate these PMSTs. Finally, we present our findings in a tabular format. Our findings will help project managers to assess the strengths and weaknesses of these tools. Keywords— Project Management, Project Management Software Tools, PMST
To meet the demand and stay competitive, many systems were traditionally pieced together without much consideration given to their quality, modifiability, scalability, security, or maintainability. This has since littered the computing landscape with brittle applications with high maintenance and complexity. Over time, these maligned systems have propagated in size and merged or integrated to become too complex and fragile to amend or administer. To combat this misalignment, the Software Architecture (SA) discipline promises to answer and realign IT with its origins of productivity and proficiency. In this paper we will (1) introduce SA, (2) decompose SA into its unique styles and quality attributes, (3) present a case study to gauge each style, (4) and finally assess and compare SA methodologies. In this paper we will compare alternative architectures and measure their effectiveness in order to identify and compute factors that affect SA by utilizing Aspect Oriented Programming (AOP).
The reasons for software project failures are mostly project management related issues. Without analyzing these issues in failed projects or capturing the best practices in successful ones, repeating mistakes is inevitable. We developed a project management modeling language (PROMOL) that helps us to plan, understand, analyze and document management of software projects. PROMOL is a formal and visual modeling language. In this paper, we present an overview of PROMOL, provide a simple example and discuss how PROMOL can be used to analyze and capture functional and dysfunctional behavior in software projects.
We introduce a methodology and research tools for visual exploratory software analysis. VERDICTS combines exploratory testing, tracing, visualization, dynamic discovery and injection of requirements specifications into a live quick-feedback cycle, without recompilation or restart of the system under test. This supports discovery and verification of software dynamic behavior, software comprehension, testing, and locating the defect origin. At its core, VERDICTS allows dynamic evolution and testing of hypotheses about requirements and behavior, by using contracts as automated component verifiers. We introduce Semantic Mutation Testing as an approach to evaluate concordance of automated verifiers and the functional specifications they represent with respect to existing implementation. Mutation testing has promise, but also has many known issues. In our tests, both black-box and white-box variants of our Semantic Mutation Testing approach performed better than traditional mutation testing as a measure of quality of automated verifiers.
Evaluation of Interaction with Commercial Educational Games when Used by Children with Autism
We propose a formal method to automatically integrate security rules regarding an access control pol- icy (expressed in Or-BAC) in Java programs. Given an untrusted application and a set of Or-BAC security rules, our method derives corresponding AspectJ aspects. Derived aspects modify the behaviour of the underlying program so as to meet the policy. Then, these aspects are weaved into the target program (using the AspectJ compiler). The result is a trusted program on which the security policy is enforced. This approach was applied in order to secure the behaviour of a travel agency application.
According to our research, communication is the most important area in managing software projects. Analyzing and improving communication practices may help us succeed in software projects. Developing frameworks and models of project communications is an important step in guiding us to conduct studies in project communications and project management. In this study, we developed a simple framework for project communications. The components of this simple framework include stakeholders, project information, communication capabilities, and project environment. Using this framework we were able to develop a project communications effectiveness measure as a part of project management effectiveness metric for software projects. This paper describes this simple framework.
In today’s organizations, a vast amount of existing software systems is insecure, which results in compromised valuable assets and has negative consequences on the organizations. Throughout the years, many attempts have been made to build secure software systems, but the solutions proposed were limited to a few add-on fixes made after implementation and installation of the system.The contribution of the research in this thesis is a software security engineering methodology, called Controlled Security Engineering Process, which provides support to developers when developing more secure software systems by integrating software lifecycle and security lifecycle, and enhancing the control in the engineering process. The proposed methodology implements security in every phase of general software system engineering, i.e., requirement, design, implementation, and testing, as well as operation and maintenance to certify that software systems are built with security in mind.The Controlled Security Engineering Process methodology addresses security problems in the development lifecycle. Construction of a secure software system involves specific steps and activities, which include security requirements specifications of system behavior, secure software design, an analysis of the design, implementation, with secure coding and integration, and operating and maintenance procedures.The methodology incorporates software security patterns and control of the engineering process. The software security patterns can be used as security controls and information sources to demonstrate how a specific security task should be performed or a specific security problem solved. Many patterns can be implemented in an automated way, which can facilitate the work of software engineers.The control of the engineering process provides visibility over the development process. The control assures that authorised developers access legitimate and necessary information and projects’ documents by using authentication, and authorization.To support implementation of automated patterns and provide control over the engineering process, a design of a multi-agent system is provided. The multi-agent system supports implementation of patterns and extracting security information, and provides traceability in the engineering process. The security information is requirements, threats and security mechanisms that are provided by matching project documents, and traceability is achieved by monitoring and logging services.The Controlled Security Engineering Process methodology has been evaluated through interviews with developers, security professionals, and decision makers in different types of organizations but also through a case study which was carried out in an organization.
This paper presents comparisons of the MinimalMUMCUT logic criterion and prime path coverage. A theoretical comparison of the two criteria is performed in terms of (1) how well tests satisfying one criterion satisfy the other and (2) fault detection. We then compare the criteria experimentally. For 22 programs, we develop tests to satisfy Minimal-MUMCUT and prime path coverage. We use these tests in two separate experiments. First we measure the effectiveness of the tests developed for one criterion in terms of the other. Next we investigate the ability of the test sets to find actual faults. Faults are seeded via a mutation tool and then supplemented with mutants created by DNF logic mutation operators. We then measure the number of non-equivalent mutants killed by each test set. Results indicate that while prime path-adequate test sets are closer to satisfying Minimal-MUMCUT than vice versa, the criteria had similar fault detection and MinimalMUMCUT required fewer tests.
prefer, distribuer et vendre des theses partout dans le monde, a des fins commerciales ou autres, sur support microforme, papier, electronique et/ou autres formats.