torstai 11. kesäkuuta 2015

The Missing Measurement of Usability, Privacy, Security and Accountability Interplay

Usability and Security concepts combined
The human pilot locked the door after the commander left the cockpit for an urgent need. The door cannot be opened by any human from outside the cockpit. Unfortunately, we all know how this story ends. What went wrong? The engineering and management of the security system did not take into account the human experiences and factors, in this story the pilot, the commander and the cabin crew. Similarly Jade from Montreal, traveling to Istanbul via Paris airport, had gone to the ATM to withdraw money. She inserted her credit card and punched her code several times. Then she waited for the cash but to her surprise, there was neither the money nor the receipt nor the card, only a frustrating message “you can request your card from your bank”, meaning in Quebec, not at the Charles de Gaulle Airport.
 
These stories highlighted the importance of the interplay and the required trade-off between security and human factors. Control access security systems, like the cockpit door or the ATM, have to implement the security policies. They have to be usable, accessible and they should not have any impact on the privacy and safety of humans. Certainly, the commander needs a more usable security, or the credit card problems should not occur. But who are the humans and organizations responsible for such disasters when they happened? Privacy and accountability are also human quality factors awaiting for further considerations.

ISO Standards such 25000 and 27000 both list usability and security as two quality attributes for software-intensive systems. The neglected concern is the intimate relationship between usability/quality in use and security. Maintaining an acceptable compromise between usability and security needs first to avoid the current security and software engineering practices suggesting that usability and security can be treated by two different teams. The first team is the Human Computer Interaction (HCI). Their role is to ensure that an acceptable level of usability and a variety of user experiences are supported. The second team is the software and the security engineering developers. Their role is to ensure that the system is secure while available and confidential with the system-held information.

The goal of our research at Lappeenranta University of Technology is to develop a new generation of methods and tools to designing, engineering and testing software-intensive product, service and systems that are usable yet secure, safe and economically valuable. The practical outcomes include standardization recommendations for identifying and modeling the intimate relationships between usability and security characteristics, and their integration into the development of a large variety of security systems and services. Fundamental research agenda includes the development and validation of concepts, metrics, patterns, methods and tools all embedded into an integrative human-centric framework. The framework should also supports the experiences security policy makers and usability experts, as they are humans too and responsible for engineering the right security and ensuring that the usability is right.

Did you find this research proposal interesting? Please contact Prof. Ahmed Seffah, ahmed.seffah@lut.fi


tiistai 21. huhtikuuta 2015

AgiES project concluded



The AgiES project concluded at the end of March 2015. The project worked on the adaption and adoption of agile and lean product development methods into embedded system development and measurement of their effects on well-being at work. The project was carried out in collaboration of the research partners University of Turku and Finnish Institute of Occupational Health and the industry partners Ericsson, BA Group, Lindorff Finland, Nextfour Group, Nordic ID, Neoxen Systems and FiSMA.

The core of the project included several industrial pilot projects directed by University of Turku and well-being at work measurements executed by Finnish Institute of Occupational Health. The pilot projects started with review of initial state in the companies, continuing with introduction and development of agile and lean practices, utilization and observation of these practices in real R&D projects and finally reviewing the end state. The effects on well-being at work were analyzed through interviews, questionnaires as well as through strain and recovery measurements. The collected results where cultivated into the main result of the project, Sulautettujen järjestelmien ketterä käsikirja (Agile handbook of embedded systems), and into several academic articles published during and after the project. The handbook, which has received positive reception, can be downloaded from

http://embedded.utu.fi/kasikirja 


XP2015 Conference in Helsinki 25.5–29.5, at Marina Congress Center



The 16th International Conference on Agile Software Development (XP2015) gathers together an international audience of industrial experts and academics on agile and lean software development. The mission of the conference is to further the state of agile and lean software development by providing a forum at which experts and novices from both industry and academia can meet and learn from each other.
The theme of the conference, "Delivering Value" refers to the fact that many companies using agile and lean software development approches are moving from cyclic delivery of features towards continuous delivery, i.e. compressing the release cycle from months or weeks to days or hours.
The conference program includes keynote speeches by Linda Rising, Harri Oikarinen, and Brian Fitzgerald. There are several pre- and post-conference workshops, tutorials, and tranings available. The different tracks of the conference cover a wide area of interests, for example large-scale agile and lean, and measurement and metrics for agile projects and processes. The conference calls for reports on experiences in addition to original research results. The local organizers are from Aalto University.
More information and registration:

maanantai 2. maaliskuuta 2015

TTY Porin laitoksen ohjelmistotekniikan projekteja 2014

SHOK

Tekes

EAKR (ELY-keskus)

Ehdokkaita

  • Energiahävikkien monitorointi ja ennakoiva kontrollointi (EMEK) 
  • Arviointia ja avoimuutta pk-yritysten tarpeisiin (AjATar)

Ohjelmistotekniikan projektitoiminnan yhteyshenkilö: Jari Soini

maanantai 22. joulukuuta 2014

Desired Quality in Cloud Application Development

Leah Riungu-Kalliosaari, Ossi Taipale and Kari Smolander have released an article on cloud applications and quality. This research publication is a part of ongoing STX project, which is partially funded by FiSMA. More information on this article, and other STX publications can be found from the address http://www2.it.lut.fi/project/STX/ or by contacting the project manager Ossi Taipale (D.Sc.) via email at ossi.taipale@ lut.fi

Abstract from the paper: ”This qualitative case study describes how software development organizations reach for their own context - dependent quality in cloud application development. The study collected the data from selected organizations through interviews and applied the grounded theory method in the analysis. The study concludes that the desired quality varies among the organizations. However, usability was found to be an important quality characteristic n all the organizations. The organizations involved a set of three similar activities to attain the desired quality characteristics. These activities are summarized as (1) Selecting a suitable life-cycle model, during which (2) the customer is engaged and (3) the most suitable tools are used. The organizations incorporated these activities so as to establish supportive working practices for acquiring the desired quality."

ALDES - Agile and Lean Development of Embedded Systems

FiSMA is one party in the international consortium for the ALDES project. For applying funding the project plan was submitted in mid-September for EU’s ECSEL program and for Tekes as well. The fundamental idea of ALDES is to tackle the challenges on ever increasing complexity and diversity of safety-critical cyber-physical systems (CPS) by developing Agile and Lean product development practices for European CPS industry. Agile and Lean methods are utilised on several domains and their positive impact on product development efficiency has been widely recognised. ALDES brings these methods into development of complex safety-critical CPSs. ALDES consortium consists of 45 organisations from 12 European countries enabling broad applicability and extensive collaboration on developing common practices related research, development and innovation (R&D&I).

The main objectives of ALDES are:
  • Development of Agile and Lean methods for CPS industry
  • Development of practices to handle safety-critical requirements in Agile and Lean processes
  • Development of practices for smooth and efficient collaboration of remote stakeholders
  • Dissemination and exploitation of the results extensively among the European CPS industry
Commercial advantages to be achieved include:
  • Better products with decreased time-to-market
  • More frequent deliveries and reduced failure demand
  • New markets and
  • Decreased development and certification costs.

keskiviikko 17. joulukuuta 2014

FiSMA Research Forum kokous 16.12.

Tutkimusfoorumin kokous pidettiin 16.12. Innopoli 2:ssa. FiSMA blogia testataan parhaillaan. Leah Riungu-Kalliosaari esitteli väitöskirjansa: Empirical study on the adoption, use and effects of cloud-based testing.

Seuraava kokous on 3.3.2015 klo 10:15 Innopoli 2:ssa, Espoossa. Pääaihe on tulevan tutkimusyhteistyötä kehittävän työpajan valmistelu, käsiteltävien tutkimusaihoiden valinta ja viimeistely.

FiSMAn jäsenille aineisto on jakelussa: Research Forum: https://fismary.atlassian.net/wiki/x/C4AW