Software Engineering Institute Carnegie Mellon

SEI Annual Report FY07

Publications

SEI in the Community

 


The 2007 SEI Annual Report describes the accomplishments of the SEI during FY07
(October 1, 2006 through September 30, 2007).

Reports

Alberts, C., Anderson, B., Bass, L., Bass, M., Boxer, P., Brownsword, L., Chaki, S., Feiler, P., Fisher, D., Forrester, E., Garcia, S., Greenhouse, A., Hansson, J., Herbsleb, J., Ivers, J., Lee, P., Linger, R., Longstaff, T., Manadhata, P., Meyers, C., Phillips, M., Sledge, C., Smith, J., Wallnau, K., Walton, G., Wing, J., & Zeilberger, N.
Results of SEI Independent Research and Development Projects
www.sei.cmu.edu/publications/documents/07.reports/07tr006.html

Alberts, C., Dorofee, A., & Marino, L.
Executive Overview of SEI MOSAIC: Managing for Success Using a Risk-Based Approach
www.sei.cmu.edu/publications/documents/07.reports/07tn008.html

Anderson, W., Boxer, P., & Brownsword, L.
An Examination of a Structural Modeling Risk Probe Technique
www.sei.cmu.edu/publications/documents/06.reports/06sr017.html

Bachmann, F., Bass, L., & Nord, R.
Modifiability Tactics
www.sei.cmu.edu/publications/documents/07.reports/07tr002.html

Band, S., Cappelli, D., Fisher, L., Moore, A., Shaw, E., & Trzeciak, R.
Comparing Insider IT Sabotage and Espionage: A Model-Based Analysis
www.sei.cmu.edu/publications/documents/06.reports/06tr026.html

Bandor, M.
Quantitative Methods for Software Selection and Evaluation
www.sei.cmu.edu/publications/documents/06.reports/06tn026.html

Bass, L., Nord, R., Wood, W., & Zubrow, D.
Risk Themes Discovered Through Architecture Evaluations
www.sei.cmu.edu/publications/documents/06.reports/06tr012.html

Beynon, D.
Interpreting Capability Maturity Model Integration (CMMI) for Business Development Organizations in the Government and Industrial Business Sectors
www.sei.cmu.edu/publications/documents/07.reports/07tn004.html

Blanchette, S. & Bergey, J.
Progress Toward an Organic Software Architecture Capability in the U.S. Army
www.sei.cmu.edu/publications/documents/07.reports/07tr010.html

Cappelli, D., Desai, A, Moore, A., Shimeall, T., Weaver, E., & Willke, B.
Management and Education of the Risk of Insider Threat (MERIT): Mitigating the Risk of Sabotage to Employers Information, Systems, or Networks
www.sei.cmu.edu/publications/documents/06.reports/06tn041.html

Caralli, R., Stevens, J., Wallen, C., White, D., Wilson, W., & Young, L.
Introducing the CERT Resiliency Engineering Framework: Improving the Security and www.sei.cmu.edu/publications/documents/07.reports/07tr009.html

Caralli, R., Stevens, J., Young, L., & Wilson, W.
Introducing OCTAVE Allegro: Improving the Information Security Risk Assessment Process
www.sei.cmu.edu/publications/documents/07.reports/07tr012.html

Chaki, S. & Hissam, S.
Certifying the Absence of Buffer Overflows
www.sei.cmu.edu/publications/documents/06.reports/06tn030.html

Chaki, S., Ivers, J., Lee, P., Wallnau, K., & Zeilberger, N.
Certified Binaries for Software Components
www.sei.cmu.edu/publications/documents/07.reports/07tr001.html

Chaki, S. & Sinha, N.
Assume-Guarantee Reasoning for Deadlock
www.sei.cmu.edu/publications/documents/06.reports/06tn028.html

Ciampa, R., Day, D., Franks, J., & Tsuboi, C.
Global Information Grid Survivability: Four Studies
www.sei.cmu.edu/publications/documents/06.reports/06sr008.html

CMMI Architecture Team
Introduction to the Architecture of the CMMI Framework
www.sei.cmu.edu/publications/documents/07.reports/07tn009.html

CMMI Guidebook for Acquirers Team
Understanding and Leveraging a Supplier’s CMMI Efforts: A Guidebook for Acquirers
www.sei.cmu.edu/publications/documents/07.reports/07tr004.html

Collins, M. P. & Weaver, R.
Fishing for Phishes: Applying Capture-Recapture to Phishing Populations
www.cert.org/netsa/publications/ecrimes07-collins-weaver-fish-for-phish.pdf

Collins, M., Shimeall, T. J., Faber, S., Janies, J., Weaver, R., & De Shon, M.
Predicting Future Botnet Addresses with Uncleanliness
www.cert.org/netsa/publications/IMC07-collins,etc-predicting-future-botnet-addresses-unclean.pdf

Collins, M. P. & Reiter, M. K.
Hit-List Worm Detection and Bot Identification in Large Networks Using Protocol Graphs
www.cert.org/netsa/publications/raid2007-collins-hit-worm-detect-bot-indent-sep07-1.pdf

Collins, M. P., Coull, S. E., Wright, C. V., Monrose, F., & Reiter, M. K.
Playing Devil's Advocate: Inferring Sensitive Information from Anonymized Network Traces

/www.ece.cmu.edu/~reiter/papers/2007/NDSS1.pdf

Danyliw, R. & Cain, P.
Mitigating Network Events Through Structured Information Sharing

www.cert.org/netsa/publications/RSA07-danyliw-mitigating-networks-structured-info-Feb07.pdf

Defence Materiel Organisation, Australian Department of Defence
+SAFE, V1.2: A Safety Extension to CMMI-DEV, V1.2
www.sei.cmu.edu/publications/documents/07.reports/07tn006.html

Dorofee, A., Killcrece, G., Ruefle, R., &Zajicek, M.
Incident Management Capability Metrics Version 0.1
www.sei.cmu.edu/publications/documents/07.reports/07tr008.html

Feiler, P.
Modeling of System Families
www.sei.cmu.edu/publications/documents/07.reports/07tn047.html

Feiler, P. & Rugina, A.
Dependability Modeling with the Architecture Analysis & Design Language (AADL)
www.sei.cmu.edu/publications/documents/07.reports/07tn043.html

Fisher, D., Meyers, B., & Place, P.
Conditions for Achieving Network-Centric Operations in Systems of Systems
www.sei.cmu.edu/publications/documents/07.reports/07tn003.html

Gennari, J., Hedrick, S., Long, F., Pincar, J., & Seacord, R.
Ranged Integers for the C Programming Language
www.sei.cmu.edu/publications/documents/07.reports/07tn027.html

Kasunic, M.
The State of Software Measurement Practice: Results of 2006 Survey
www.sei.cmu.edu/publications/documents/06.reports/06tr009.html

Kendall, R., Post, D., Carver, J., Henderson, D., & Fisher, D.
A Proposed Taxonomy for Software Development Risks for High-Performance Computing (HPC) Scientific/Engineering Applications
www.sei.cmu.edu/publications/documents/06.reports/06tn039.html

Kendall, R., Post, D., & Mark, A.
Case Study of the NENE Code Project
www.sei.cmu.edu/publications/documents/06.reports/06tn044.html

Lewis, G., Meyers, C., & Wallnau, K.
Workshop on Model-Driven Architecture and Program Generation
www.sei.cmu.edu/publications/documents/06.reports/06tn031.html

Mead, N.
How to Compare the Security Quality Requirements Engineering (SQUARE) Method with Other Methods
www.sei.cmu.edu/publications/documents/07.reports/07tn021.html

Meyers, C.
Risk Management Considerations for Interoperable Acquisition
www.sei.cmu.edu/publications/documents/06.reports/06tn032.html

Meyers, C. & Sledge, C.
Schedule Considerations for Interoperable Acquisition
www.sei.cmu.edu/publications/documents/06.reports/06tn035.html

Moore, A. & Antao, R.
Modeling and Analysis of Information Technology Change and Access Controls in the Business Context
www.sei.cmu.edu/publications/documents/06.reports/06tn040.html

Morris, E., Place, P., & Smith, D.
System-of-Systems Governance: New Patterns of Thought
www.sei.cmu.edu/publications/documents/06.reports/06tn036.html

Nord, R.
Proceedings of the Second Software Architecture Technology User Network (SATURN) Workshop
www.sei.cmu.edu/publications/documents/06.reports/06tr010.html

Ozkaya, I., Kazman, R., Klein, M.
Quality-Attribute-Based Economic Valuation of Architectural Patterns
www.sei.cmu.edu/publications/documents/07.reports/07tr003.html

Simanta, S. & Lewis, G.
T-Check for Technologies for Interoperability: Open Grid Services Architecture
(OGSA)—Part 1

www.sei.cmu.edu/publications/documents/07.reports/07tn016.html

Sledge, C.
Army ASSIP System-of-Systems Test Metrics Task
www.sei.cmu.edu/publications/documents/06.reports/06sr011.html

Smith, J.
Topics in Interoperability: Structural Programmatics in a System of Systems
www.sei.cmu.edu/publications/documents/06.reports/06tn037.html

Smith, J. & Phillips, M.
Interoperable Acquisition for Systems of Systems: The Challenges
www.sei.cmu.edu/publications/documents/06.reports/06tn034.html

Trammell, B. & Boschi, E.
Bidirectional Flow Export Using IPFIX
tools.ietf.org/html/draft-ietf-ipfix-biflow-05

Trammell, B., Boschi, E., Mark, L.; Zseby, T. & Wagner, A.
An IPFIX-Based File Format
tools.ietf.org/html/draft-trammell-ipfix-file-05

Wall, D., McHale, J., & Pomeroy-Huff, M.
Case Study: Accelerating Process Improvement by Integrating the TSP and CMMI
www.sei.cmu.edu/publications/documents/07.reports/07tr013.html

Walton, G., Longstaff, T., & Linger, R.
Technology Foundations for Computational Evaluation of Software Security Attributes
www.sei.cmu.edu/publications/documents/06.reports/06tr021.html

Westby, J. & Allen, J.
Governing for Enterprise Security (GES) Implementation Guide
www.sei.cmu.edu/publications/documents/07.reports/07tn020.html

Wojcik, R., Bachmann, F., Bass, L., Clements, P., Merson, P., Nord, R., & Wood, B.
Attribute-Driven Design (ADD), Version 2.0
www.sei.cmu.edu/publications/documents/06.reports/06tr023.html

Wood, W.
A Practical Example of Applying Attribute-Driven Design (ADD), Version 2.0
www.sei.cmu.edu/publications/documents/07.reports/07tr005.html

Woody, C.
Applying OCTAVE: Practitioners Report
www.sei.cmu.edu/publications/documents/06.reports/06tn010.html

 

 

Annual Report Archives: 2002 | 2003 | 2004 | 2005 | 2006