Abstract The trust concept becomes more and more popular by paving its way gradually into the modern field. Thus, it becomes a more alluring and attractive solution to secure and protect information sharing against attackers. Indeed, malicious entities can launch intentionally or unintentionally very harmful attacks against the information sharing process causing network paralysis. In this paper, we propose composite trust-based schemes from the perspective of direct experience and entities’ recommendations to enhance the shared threat information in the public and private communities. Therefore, we introduce a first trust-based model defined by several specific dimensions to improve the security of private/targeted communities. Furthermore, a second trust-based scheme is proposed for the public community where the concept of zero-trust is introduced to enhance the shared critical data inside this open environment. Thus, our proposal reveals a new level of defense against the misbehaving entities by introducing a penalty scheme to punish the malicious and suspicious users and to exempt the attackers with continuous misbehaving from participating in the information sharing process. Extensive simulations demonstrate that the proposed trustbased model provides high stability and resistance in a heavily hostile environment for the public and private communities.
The success of disaster management efforts demands meaningful integration of data that is geographically dispersed and owned by stakeholders in various sectors. However, the difficulty in finding, accessing and reusing interoperable vocabularies to organise disaster management data creates a challenge for collaboration among stakeholders in the disaster management cycle on data integration tasks. Thus the need to implement FAIR principles that describe the desired features ontologies should possess to maximize sharing and reuse by humans and machines. In this review, we explore the extent to which sharing and reuse of disaster management knowledge in the domain is inline with FAIR recommendations. We achieve this through a systematic search and review of publications in the disaster management domain based on a predefined inclusion and exclusion criteria. We then extract social-technical features in selected studies and evaluate retrieved ontologies against the FAIR maturity model for semantic artefacts. Results reveal that low numbers of ontologies representing disaster management knowledge are resolvable via URIs. Moreover, 90.9% of URIs to the downloadable disaster management ontology artefacts do not conform to the principle of uniqueness and persistence. Also, only 1.4% of all retrieved ontologies are published in semantic repositories and 84.1% are not published at all because there are no repositories dedicated to archiving disaster domain knowledge. Therefore, there exists a very low level of Findability (1.8%) or Accessibility (5.8%), while Interoperability and Reusability are moderate (49.1% and 30.2 % respectively). The low adherence of disaster vocabularies to FAIR Principles poses a challenge to disaster data integration tasks because of the limited ability to reuse previous knowledge during disaster management phases. By using FAIR indicators to evaluate the maturity in sharing, discovery and integration of disaster management ontologies, we reveal potential research opportunities for managing reusable and evolving knowledge in the disaster community.
Open source software (OSS) is currently a widely adopted approach to developing and distributing software. Many commercial companies are using OSS components as part of their product development. For instance, more than 58% of web servers are using an OSS web server, Apache. For effective adoption of OSS, fundamental knowledge of project development is needed. This often calls for reliable prediction models to simulate project evolution and to envision project future. These models provide help in supporting preventive maintenance and building quality software. This chapter reports on a systematic literature survey aimed at the identification and structuring of research that offers prediction models and techniques in analysing OSS projects. The study outcome provides insight into what constitutes the main contributions of the field, identifies gaps and opportunities, and distils several important future research directions. This chapter extends the authors' earlier journal article and offers the following improvements: broader study period, enhanced discussion, and synthesis of reported results.
Access to integrated disaster-related data through querying is still a problem due to associated semantic barriers. The disaster domain largely relies on the top–down approach of ontology development. This limits reuse due to associated commitments and complex alignments within ontologies. Therefore, there is a need to utilize a bottom-up approach that reuses patterns for representing disaster knowledge. To bridge the availability gap of patterns for representing disaster knowledge, this study identifies existing and emerging patterns for reuse while organizing disaster data from multiple sector stakeholders. Based on the eXtreme Design (XD) methodology and key informant interviews, competency questions (CQs) were elicited from domain stakeholders. The CQs are matched with existing patterns from other contexts. Emerging patterns (e.g the Event Classification and Quality Dependence Description for Objects) are also developed for CQs not captured and subsequently tested using SPARQL queries characterising the CQs. It is in this context that this paper presents a characterisation of disaster risk knowledge using CQs and corresponding patterns (reusable and emerging) covering the knowledge. Accordingly, we illustrate a pattern-driven use case to organise drought hazard data for early warning purposes. This provides a powerful use case for adopting a pattern-based approach to knowledge representation in the disaster domain.
Software specialists increasingly find themselves in situations where their application programming interface (API)-related decisions have implications on software business. We present a strategic API framework to aid in consideration of business concerns when designing, updating, or maintaining APIs.
Software specialists increasingly find themselves in situations where their API-related decisions have strong implications on software business. Through long-lasting research collaboration with API-responsible software specialists and several large software-intensive companies, we have established a strategic API framework to aid in consideration of business concerns when designing, updating, or maintaining APIs. We provide the following actionable insights in this article: 1) our framework combines multiple layers and perspectives that provided value for our partners in their in API design, 2) the framework helps API designers to better organize their design decisions amongst various business and technical concerns and 3) the framework supports development of holistic API strategies, as it supports: APIs as objects of digital innovation, allowing to derive important boundary objects; BAPO perspective on API development; and consideration of API governance. We use anonymized examples from our partners to illustrate the application of the framework.
Traditionally, software APIs (application programming interfaces) have been viewed from a technical perspective, as a means to separate implementation from functional calls, and as a way to define a contract of software functionality. The technical benefits of APIs have been reported in numerous studies. Several reports from industry offer useful practical design considerations for APIs, including advice on collecting usage data, monetization strategies, and at what point to open an API to external parties. Although this advice can be useful, the focus is still often on the API, only without considering the role the API plays in the wider organization or how it fits into an organizational strategy. Our industrial experiences show that more information is needed about the challenges and best practices of API design and management in an organizational context. Furthermore, it has become apparent that APIs are able to play a key role as part of a strategic business plan for software-intensive companies. In this report, we present the results of our work with companies to build a framework that synthesizes and summarizes API strategies from several perspectives, including: strategic API lifecycle, lifecycle stage characteristics, lifecycle use cases and transition points, API layered architecture, BAPO, value modeling, ecosystem mapping with goal models, API metrics, goal models with metrics, and API governance guidance. Our research was carried out with an industry-academic collaboration. The framework was developed iteratively through workshops and discussions with company partners. We show how conceptual frameworks can be used to drive API strategy development, drawing on our research with several companies in practice.
One of the grand challenges of disaster management is for stakeholders to be able to discover, access, integrate and analyze task-appropriate data together with their associated algorithms and work-flows. Even with a growing number of initiatives to publish data in the disaster management sector using open principles, integration and reuse are still difficult due to existing interoperability barriers within datasets. Several frameworks for assessing data interoperability exist but do not generate best practice solutions to existing barriers based on the assessment they use. In this study, we assess interoperability for datasets in the disaster management sector in Uganda and identify generic solutions to interoperability challenges in the context of disaster management. Semi-structured interviews and focus group discussions were used to collect qualitative data from sector stakeholders in Uganda. Data interoperability was measured to provide an understanding of interoperability in the sector. Interoperability maturity is measured using qualitative methods, while data compatibility metrics are computed from identifiers in the RDF-triple model. Results indicate high syntactic and technical interoperability maturity for data in the sector. On the contrary, there exists considerable semantic and legal interoperability barriers that hinder data integration and reuse in the sector. A mapping of the interoperability challenges in the disaster management sector to solutions reveals a potential to reuse established patterns for managing data interoperability. These include; the federated pattern, linked data patterns, broadcast pattern, rights and policy harmonization patterns, dissemination and awareness pattern, ontology design patterns among others. Thus a systematic approach to combining patterns is critical to managing data interoperability barriers among actors in the disaster management ecosystem.
The success of disaster risk management efforts depends on the ability of multiple stakeholders to share disaster-related information. Semantic integration of such heterogeneous information requires ontology building. The top-down approach of ontology building has several disadvantages to knowledge representation. To support the process of ontology engineering, a bottom-up-approach that utilizes modular Ontology Design Patterns (ODPs) with weak dependencies can be used to overcome the disadvantages of the top-down approach. To bridge the availability gap of patterns for representing disaster knowledge, the study identifies existing and emerging patterns that can be used to organize disaster knowledge. Based on the eXtreme Design (XD) methodology and key informant interviews, Competency Questions (CQs) were listed from domain stakeholders. Consequently, corresponding patterns covering the CQs were also identified and developed. This study identifies emerging patterns such as Event Type ODP for representing risky and hazardous events. The QualityCausation ODP is also identified for representing the causality nature of vulnerability. The resulting patterns are aligned to the DOLCE foundational ontology and can be used to organize data in the disaster domain.
Foundations function as a vital institutional support infrastructure for many of the most successful open-source projects, but the different roles played by these support entities are understudied in Free/Libre and Open Source Software (FLOSS) research. Drawing on Open Hub (formerly known as Ohloh) data, this paper empirically investigates how these entities support projects and interact with other projects. This study was conducted using the Theoretical Saturation Grounded Theory approach given the large volume of data on hand. The findings are synthesized as a taxonomy of support entities, a categorization of support mechanisms and a set of dynamics of the interactions between different FLOSS support entities.
APIs provide value beyond technical functionality. They enable and manage access to strategic business assets and play a key role in enabling software ecosystems. Existing work has begun to consider the strategic business value of software APIs, but such work has limited analysis capabilities and has not made use of established, structured modeling techniques from software and requirements engineering. Such modeling languages have been used for strategic analysis of ecosystems and value exchange. We believe these techniques expand analysis possibilities for APIs, and we apply them as part of a cross-company case study focused on strategic API planning and analysis. Results show that goal, value, and workflow modeling provide new, API-specific benefits that include mapping the API ecosystem, facilitating incremental API planning, understanding dynamic API-specific roles, identifying bottlenecks in API change workflows, and identifying API value.
Crowdfunding campaigns enable individuals to bring their ideas to production by appealing directly to the end-market and the global community. A number of these projects are open source, seemingly, counteracting the funding process. We interviewed founders, developers and managers of 13 crowdfunding initiatives involving open source products to determine how communities, crowdfunding campaigns and open source are associated. Our findings verified the existence of common characteristics among the cases, the emergence of a family-like relationship between the organizers and the community, as well as the community perceived as a success factor. We suggest that the development of certain niche products inherently leads to the adoption of open source as a licensing model and crowdfunding as the capital gathering process.
Problem: The involvement of external stakeholders in capstone projects and project courses is desirable due to its potential positive effects on the students. Capstone projects particularly profit from the inclusion of an industrial partner to make the project relevant and help students acquire professional skills. In addition, an increasing push towards education that is aligned with industry and incorporates industrial partners can be observed. However, the involvement of external stakeholders in teaching moments can create friction and could, in the worst case, lead to frustration of all involved parties. Contribution: We developed a model that allows analysing the involvement of external stakeholders in university courses both in a retrospective fashion, to gain insights from past course instances, and in a constructive fashion, to plan the involvement of external stakeholders. Key Concepts: The conceptual model and the accompanying guideline guide the teachers in their analysis of stakeholder involvement. The model is comprised of several activities (define, execute, and evaluate the collaboration). The guideline provides questions that the teachers should answer for each of these activities. In the constructive use, the model allows teachers to define an action plan based on an analysis of potential stakeholders and the pedagogical objectives. In the retrospective use, the model allows teachers to identify issues that appeared during the project and their underlying causes. Drawing from ideas of the reflective practitioner, the model contains an emphasis on reflection and interpretation of the observations made by the teacher and other groups involved in the courses. Key Lessons: Applying the model retrospectively to a total of eight courses shows that it is possible to reveal hitherto implicit risks and assumptions and to gain a better insight into the interaction between external stakeholders and students. Our empirical data reveals seven recurring risk themes that categorise the different risks appearing in the analysed courses. These themes can also be used to categorise mitigation strategies to address these risks proactively. Additionally, aspects not related to external stakeholders, e.g., about the interaction of the project with other courses in the study programme, have been revealed. The constructive use of the model for one course has proved helpful in identifying action alternatives and finally deciding to not include external stakeholders in the project due to the perceived cost-benefit-ratio. Implications to Practice: Our evaluation shows that the model is a viable and useful tool that allows teachers to reason about and plan the involvement of external stakeholders in a variety of course settings, and in particular in capstone projects.
Driven by business interests, (product/customer) value has become a critical topic in system and software engineering as well as enterprise planning. The conceptual modeling community has responded to this challenge with several modeling approaches, including e(3) value modeling, focusing on capturing and analyzing value flows in value networks. This modeling approach has risen from practical e-commerce experiences and has been further studied in an academic context. In this experience paper, we report the advantages and disadvantages of applying e(3) value modeling as part of a cross-company case study focusing on understanding the internal and external value of APIs from a strategic perspective. We found that value modeling was generally well-received and understood by the company representatives, but also found drawbacks when used in our context, including challenges in modeling internal value networks, capturing problematic or missing values, finding quantitative value measures, and showing underlying motivations for flows. Our findings can help to improve language aspects, methods and tools, and can help to guide future value analysis in similar contexts.
[Context] The market for software targeting children, both for education and entertainment, is growing. Existing work, mainly from HCI, has considered the effectiveness of elicitation techniques for eliciting requirements from children as part of a design process. [Objective] However, we are lacking work which compares requirements elicitation techniques when used with children. [Methods] This study compares five elicitation techniques, taking into consideration the effectiveness and efficiency of each technique. Techniques were used with a total of 54 children aged 8-13, eliciting requirements for a museum flight simulator. We compare techniques by looking at the number and type of requirements discovered, perceived participant satisfaction, resources required, perceived usefulness, and requirements coverage of domain specific categories. [Conclusions] We observed notable differences between the techniques, including the effectiveness of observations and relative ineffectiveness of questionnaires. We present a set of guidelines to aid industry in eliciting requirements for child-friendly software.
Reuse of patterns is a self-evident approach for managing interoperability concerns. Although patterns for resolving interoperability barriers exist in the literature, no study exists on adoption of interoperability patterns by Geographic Information Systems (GIS) practitioners in industry. Thus there is limited understanding of pattern re-usability, yet the advantages offered by interoperability patterns provide a reasonably sound justification for their usage. This paper examines the adoption of proven interoperability best practices in the GIS industry. An empirical study that involved the use of semi-structured interviews was employed to gather data from GIS developers on domain interoperability best practices. Results indicated that industry and communities of practice have been converging on the technical level to ensure interoperability of GIS concerns. Semantic interoperability and related patterns are least understood, yet semantic barriers still exist. This is partly due to the complexity associated with the top-down approach used to develop semantic interoperability solutions. Therefore, this study proposes research into resolving barriers in the adoption of interoperability patterns that reduce complexity while solving semantic interoperability barriers.
Assessing the quality of an API is important in many different aspects: First, it can assist developers in deciding which API to use when they are faced with a list of potential APIs to choose from, by comparing the benefits and drawbacks of each option [1]; we refer to this as the API selection problem. Second, it can help guide the design process and expose problem areas in early stages of API design, even before implementing the actual API [2]; we refer to this as the API design problem. In order to assess the quality of an API, various evaluation methods have been used: some are based on empirical laboratory studies, gathering feedback from API users; others are based on inspection methods where experts evaluate the quality of an API based on a list of design guidelines [3] [4] such as Nielsen's heuristics and the cognitive dimensions framework [2] [5]. In this paper, we are particularly interested in extending Steven Clarke's approach of measuring API usability based on the cognitive dimensions framework [5]. The usability of an API is assessed by comparing the API (what it actually offers) with the profiles of its potential users (what they expect out of it).
Software clustering is a common technique applied to simplify reverse engineered software models. These algorithms commonly classify similarity between nodes based on their relationships. However little research exists that discusses the importance of the direction of these relationships. In this paper we provide empirical data for how treating direction in entity relationships affect the recovery accuracy of hierarchical clustering algorithms. We test variations of a hierarchical clustering algorithm on several open source systems and compare their results, and conclude that relationship direction does not have a significant impact on recovery accuracy. As such, researchers may opt to implement hierarchical clustering algorithms using only one direction of relations instead of both, and still get similar results for less computational cost.
Foundations function as vital institutional support infrastructures for many of the most successful open source projects, but the role of these support entities remains an understudied phenomenon in FLOSS research. Drawing on Open Hub (formerly known as Ohloh) data, this paper empirically investigates the different ways these entities support projects and interact with different projects and with each other.
We investigate the different aspects of measuring trust in Open Source Software (OSS) communities. In the theoretical part we review seminal works related to trust in OSS development. This investigation provides background to our empirical part where we measure trust in a community (in terms of kudo) . Our efforts provide further avenues to develop trust-based measurement tools. These are helpful for academics and practitioners interesting in quantifiable traits of OSS trust.
Tarja Systa合作论文数Tampere University of Technology;Institute of Software Systems9