Software Engineering Institute Carnegie Mellon

Annual Report FY 2004

Conferences (FY2004)   |  SEI-Published Documents

Journal Articles   |   Book Chapters   |   Proceedings   |   Keynote Presentations   |  Tutorials

Press Releases   |   Media Coverage  |  Government Testimony

Technical Leadership Positions

SEI-Published Documents

Anderson, B.; Estrin, L.; & Buhman, C.
Selecting Advanced Software Technology in Two Small Manufacturing Enterprises (TN), www.sei.cmu.edu/publications/documents/03.reports/03tn020.html

Anderson, L.; Fisher, M.; & Gross, J.
Case Study: IRS Business System Modernization Process Improvement (TR), www.sei.cmu.edu/publications/documents/04.reports/04tr002.html

Bachmann, F.; Bass, L.; Carney, D.; Dietrich, S.; Feiler, P.; Garcia, S.; Klein, M.; Lattanze, T.; McHugh, J.; Meyers, B. C.; Morris, E.; Place, P.; Plakosh, D.; & Seacord, R.
SEI Independent Research and Development Projects (TR),
www.sei.cmu.edu/publications/documents/03.reports/03tr019.html

Bachmann, F.; Bass, L.; & Klein, M.
Preliminary Design of ArchE: A Software Architecture Design Assistant (TR), www.sei.cmu.edu/publications/documents/03.reports/03tr021.html

Barbacci, M.; Ellison, R.; Lattanze, A.; Stafford, J.; Weinstock, C.; & Wood, W.
Quality Attribute Workshops (QAWs), Third Edition (TR),
www.sei.cmu.edu/publications/documents/03.reports/03tr016.html

Bergey, J.; Cohen, S.; Jones, L.; & Smith, D.
Software Product Lines: Experiences from the Sixth DoD Software Product Line Workshop (TN), www.sei.cmu.edu/publications/documents/04.reports/04tn011.html

Bergey, J.; Dietrich, S.; Firesmith, D.; Forrester, E.; Jordan, A.; Kazman, R.; Lewis, G.; Lipson, H.; Mead, N.; Morris, E.; O'Brien, L.; Siviy, J.; Smith, D.; & Woody, C.
Results of SEI Independent Research and Development Projects and Report on Emerging Technologies and Technology Trends (TR),
www.sei.cmu.edu/publications/documents/04.reports/04tr018.html

Bernard, T.; Gallagher, B.; Bate, R.; & Wilson, H.
CMMI Acquisition Module (TR),
www.sei.cmu.edu/publications/documents/04.reports/04tr001.html

Brown, M.
Illuminating Patterns of Perception: An Overview of Q Methodology (TN),
www.sei.cmu.edu/publications/documents/04.reports/04tn026.html

Brownsword, L.; Carney, D.; Fisher, D.; Lewis, G.; Meyers, C.; Morris, E.; Place, P.; Smith, J.; & Wrage, L.
Current Perspectives on Interoperability (TR),
www.sei.cmu.edu/publications/documents/04.reports/04tr009.html

Caralli, R.
The Critical Success Factor Method: Establishing a Foundation for Enterprise Security Management (TR),
www.sei.cmu.edu/publications/documents/04.reports/04tr010.html

Carney, D.; Morris, E.; & Place, P.
Identifying Commercial Off-the-Shelf [COTS] Product Risks: The COTS Usage Risk Evaluation (TR),
www.sei.cmu.edu/publications/documents/03.reports/03tr023.html

Chastek, G. & Donohoe, P.
Product Line Analysis for Practitioners (TR),
www.sei.cmu.edu/publications/documents/03.reports/03tr008.html

Chastek, G.; Donohoe, P.; & McGregor, J.
A Study of Product Production in Software Product Lines (TN),
www.sei.cmu.edu/publications/documents/04.reports/04tn012.html

Chrissis, M.; Wemyss, G.; Goldenson, D.; Konrad, M.; Smith, K.; & Svolou, A.
CMMI Interpretive Guidance Project: Preliminary Report (SR),
www.sei.cmu.edu/publications/documents/03.reports/03sr007.html

Cohen, S.; Zubrow, D.; & Dunn, E.
Case Study: A Measurement Program for Product Lines (TN),
www.sei.cmu.edu/publications/documents/04.reports/04tn023.html

Comella-Dorda, S.; Dean, J.; Lewis, G.; Morris, E.; Oberndorf, P.; & Harper, E.
A Process for COTS Software Product Evaluation (TR),
www.sei.cmu.edu/publications/documents/03.reports/03tr017.html

Ellison, R.; Moore, A.; Bass, L.; Klein, M.; & Bachmann, F.
Security and Survivability Reasoning Frameworks and Architectural Design Tactics (TN), www.sei.cmu.edu/publications/documents/04.reports/04tn022.html

Estrin, L.; Anderson, B.; Elm, J.; Garcia, S.; Foreman, J.; Robert, J.; & Schenker, F.
Working with Small Manufacturing Enterprises: An Analysis of TIDE Demonstration Projects (TR),
www.sei.cmu.edu/publications/documents/04.reports/04tr005.html

Feiler, P.
Real-Time Application Development with OSEK: A Review of the OSEK Standards (TN), www.sei.cmu.edu/publications/documents/03.reports/03tn004.html

Feiler, P.; Gluch, D.; Hudak, J.; & Lewis, B.
Embedded Systems Architecture Analysis Using SAE AADL (TN),
www.sei.cmu.edu/publications/documents/04.reports/04tn005.html

Fenves, S.; Sriram, R.; Choi, Y.; Elm, J.; & Robert, J.
Advanced Engineering Environments for Small Manufacturing Enterprises: Volume I (TR), www.sei.cmu.edu/publications/documents/03.reports/03tr013.html

Fenves, S.; Sriram, R.; Choi, Y.; Elm, J.; & Robert, J.
Advanced Engineering Environments for Small Manufacturing Enterprises: Volume II (TR), www.sei.cmu.edu/publications/documents/04.reports/04tr007.html

Firesmith, D.
Common Concepts Underlying Safety, Security, and Survivability Engineering (TN), www.sei.cmu.edu/publications/documents/03.reports/03tn033.html

Goethert, W. & Fisher, M.
Deriving Enterprise-Based Measures Using the Balanced Scorecard and Goal-Driven Measurement Techniques (TN),
www.sei.cmu.edu/publications/documents/03.reports/03tn024.html

Goethert, W. & Siviy, J.
Applications of the Indicator Template for Measurement and Analysis (TN),
www.sei.cmu.edu/publications/documents/04.reports/04tn024.html

Goldenson, D. & Gibson, D.
Demonstrating the Impact and Benefits of CMMI: An Update and Preliminary Results (SR),
www.sei.cmu.edu/publications/documents/03.reports/03sr009.html

Herndon, M.; Moore, R.; Phillips, M.; Walker, J.; & West, L.
Interpreting Capability Maturity Model Integration (CMMI) for Service Organizations—a Systems Engineering and Integration Services Example (TN), www.sei.cmu.edu/publications/documents/03.reports/03tn005.html

Hissam, S.; Hudak, J.; Ivers, J.; Klein, M.; Larsson, M.; Moreno, G.; Northrop, L.; Plakosh, D.; Stafford, J.; Wallnau, K.; & Wood, W.
Predictable Assembly of Substation Automation Systems: An Experiment Report, Second Edition (TR),
www.sei.cmu.edu/publications/documents/02.reports/02tr031.html

Hissam, S. & Klein, M.
A Model Problem for an Open Robotics Controller (TN),
www.sei.cmu.edu/publications/documents/04.reports/04tn030.html

Ivers, J. & Sharygina, N.
Overview of ComFoRT: A Model Checking Reasoning Framework (TN),
www.sei.cmu.edu/publications/documents/04.reports/04tn018.html

Kasunic, M.
Army Strategic Software Improvement Program (ASSIP) Survey of Army Acquisition Managers (TR), www.sei.cmu.edu/publications/documents/04.reports/04tr003.html

Kasunic, M. & Anderson, W.
Measuring Systems Interoperability: Challenges and Opportunities (TN),
www.sei.cmu.edu/publications/documents/04.reports/04tn003.html

Kazman, R.; Kruchten, P.; Nord, R.; & Tomayko, J.
Integrating Software-Architecture-Centric Methods into the Rational Unified Process (TR), www.sei.cmu.edu/publications/documents/04.reports/04tr011.html

Kazman, R.; Nord, R.; & Klein, M.
A Life-Cycle View of Architecture Analysis and Design Methods (TN),
www.sei.cmu.edu/publications/documents/03.reports/03tn026.html

Kazman, R.; O'Brien, L.; & Verhoef, C.
Architecture Reconstruction Guidelines, Third Edition (TR),
www.sei.cmu.edu/publications/documents/02.reports/02tr034.html

Killcrece, G.; Kossakowski, K.; Ruefle, R.; & Zajicek, M.
Organizational Models for Computer Security Incident Response Teams (CSIRTs) (HB),
www.sei.cmu.edu/publications/documents/03.reports/03hb001.html

Killcrece, G.; Kossakowski, K.; Ruefle, R.; & Zajicek, M.
State of the Practice of Computer Security Incident Response Teams (CSIRTs) (HB),
www.sei.cmu.edu/publications/documents/03.reports/03tr001.html

Lewis, G.; Mahatham, T.; & Wrage, L.
Assumptions Management in Software Development (TN),
www.sei.cmu.edu/publications/documents/04.reports/04tn021.html

Lewis, G. & Meyers, B.
A Model Problem Approach to Measurement-to-Track Association (TR),
www.sei.cmu.edu/publications/documents/03.reports/03tr020.html

May, C.; Baker, M.; Gabbard, D.; Good, T.; Grimes, G.; Holmgren, M.; Nolan, R.; Nowak, R.; & Pennline, S.
Advanced Information Assurance Handbook (HB),
www.sei.cmu.edu/publications/documents/04.reports/04hb001.html

Merson, P.
A Template for Documenting Prediction-Enabled Component Technologies (TN), www.sei.cmu.edu/publications/documents/03.reports/03tn030.html

Morris, E.; Levine, L.; Meyers, C.; Place, P.; & Plakosh, D.
Systems of Systems Interoperability (TR),
www.sei.cmu.edu/publications/documents/04.reports/04tr004.html

Nord, R.; Barbacci, M.; Clements, P.; Kazman, R.; Klein, M.; O'Brien, L.; & Tomayko, J.
Integrating the Architecture Tradeoff Analysis Method (ATAM) with the Cost Benefit Analysis Method (CBAM) (TN),
www.sei.cmu.edu/publications/documents/03.reports/03tn038.html

Nord, R.; Wood, W.; & Clements, P.
Integrating the Quality Attribute Workshop (QAW) and the Attribute-Driven Design (ADD) Method (TN),
www.sei.cmu.edu/publications/documents/04.reports/04tn017.html

O'Brien, L. & Tamarree, V.
Architecture Reconstruction of J2EE Applications: Generating Views from the Module Viewtype (TN),
www.sei.cmu.edu/publications/documents/03.reports/03tn028.html

Rogers, L.
Survivable Functional Units: Balancing an Enterprise's Mission and Technology (TN),
www.sei.cmu.edu/publications/documents/04.reports/04tn004.html

Sai, V.
COTS Acquisition Evaluation Process: Preacher's Practice (TN),
www.sei.cmu.edu/publications/documents/04.reports/04tn001.html

Smith, J.
An Alternative to Technology Readiness Levels for Non-Developmental Item (NDI) Software (TR),
www.sei.cmu.edu/publications/documents/04.reports/04tr013.html

Steves, M. & Frechette, S. (edited by Foreman, J. & Anderson, W.)
Viewing Technologies for Computer-Aided Design Models (TN),
www.sei.cmu.edu/publications/documents/03.reports/03tr022.html

Stoermer, C.; Bachmann, F.; Verhoef, C.
SACAM: The Software Architecture Comparison Analysis Method (TR),
www.sei.cmu.edu/publications/documents/03.reports/03tr006.html

Subramanyam, V.; Sambuddha, D.; Krishnaswamy, P.; & Ghosh, R.
An Integrated Approach to Software Process Improvement at Wipro Technologies: veloci-Q (TR),
www.sei.cmu.edu/publications/documents/04.reports/04tr006.html

Tyson, B.; Albert, C.; & Brownsword, L.
Interpreting Capability Maturity Model Integration (CMMI) for COTS-Based Systems (TR),
www.sei.cmu.edu/publications/documents/03.reports/03tr022.html

Weinstock, C. Goodenough, J.; & Hudak, J.
Dependability Cases (TN),
www.sei.cmu.edu/publications/documents/04.reports/04tn016.html

Wood, W. & Cohen, S.
DoD Experience with the C4ISR Architecture Framework (TN),
www.sei.cmu.edu/publications/documents/03.reports/03tn027.html

Zubrow, D. & Chastek, G.
Measures for Software Product Lines (TN),
www.sei.cmu.edu/publications/documents/03.reports/03tn031.html

Software Engineering Institute
Code of Professional Conduct for SEI Services, Version 1.0 (SR),
www.sei.cmu.edu/publications/documents/04.reports/04sr009.html

Conferences (FY2004)   |  SEI-Published Documents

Journal Articles   |   Book Chapters   |   Proceedings   |   Keynote Presentations   |  Tutorials

Press Releases   |   Media Coverage  |  Government Testimony

Technical Leadership Positions

Journal Articles

Allen, J.
article series, "Governing for Enterprise Security," October 2003-September 2004

Basili, V.; Boehm, B.; Davis, A.; Humphrey, W.; Leveson, N.; Mead, N.; Musa, J.; Parnas, D.; Pfleeger, S.; & Weyuker, E.
"Quality Time," IEEE Software 21, 2 (January/February 2004): 12-13

Baskerville, R.; Ramesh, B.; Levine, L.; Pries-Heje, J.; & Slaughter, S.
"Is Internet-Speed Software Development Different?" IEEE Software 206 (November/December 2003): 70-77

Blanchette, Jr., S.
"Carnegie Mellon Software Engineering Institute Focuses Expertise on the Transformation of Army Acquisition," Program Manager 32, 5 (September-December 2003): 30-34

"Transforming Army Acquisition," Army AL&T (July-August 2004): 82-85

Boeckle, G.; Clements, P.; McGregor, J.; Muthig, D.; & Schmid, K.
"Calculating ROI for Software Product Lines," IEEE Software 21, 3 (May-June 2004): 23-31

Cappelli, D.
"CERT/CC Insider Threat Study," Cipher—Electronic Newsletter of the IEEE Computer Society Technical Committee on Security and Privacy, 62 (September 19, 2004)

Carleton, A.
"Applications of Statistics in Software Engineering," The Journal of Systems and Software 73, 2 (October 2004): 181-182

Davis, N.; Humphrey, W.; Redwine, Jr., S.; Zibulski, G.; & McGraw, G.
"Processes for Producing Secure Software: Summary of U.S. National Cybersecurity Summit Subgroup Report," IEEE Security & Privacy 2, 3 (May/June 2004): 18-25

Estrin, L. & Foreman, J.
"A Review of the TIDE Program: Activities and Accomplishments," Dynamic Business 58,10 (December 2003): 20-21

Ferguson, R.
"A Project Risk Metric," CrossTalk 17, 4 (April 2004): 12-15

Firesmith, D.
“Creating A Project-Specific Requirements Engineering Process,” Journal of Object Technology 3, 5 (May/June 2004): 31-44

“Engineering Safety Requirements, Safety Constraints, and Safety-Critical Requirements,” Journal of Object Technology 3, 3 (March/April 2004): 27-42

“Prioritizing Requirements,” Journal of Object Technology 3, 8, (September/October 2004): 35-47

“Specifying Reusable Security Requirements,” Journal of Object Technology 3, 1 (January/February 2004): 61-75

Heinz, L.
"CMMI Myths and Realities," Crosstalk 17, 6 (June 2004): 8-10

Hissam, S.
"Predictable Assembly From Certifiable Components," CrossTalk 17, 5 (June 2004): 16-19

Killcrece, G.; Ruefle, R.; & Zajicek, M.
"Rationale for Developing Computer Security Incident Response Teams (CSIRT),”Electronic Banking Law and Commerce Report 9, 1 (May 2004)

Mead, N.
“Who is Liable for Insecure Systems?” IEEE Computer 37, 7 (July 2004): 27-34

Merson, P.
"Managing J2EE Risks,"
Software Development, July 2004

Sharygina, N.; Browne, J.; Xie, F.; Kurshan, R.; & Levin, V.
"Lessons Learned from Model Checking a NASA Robot Controller," Formal Methods in System Design 52, 2-3 (September/November 2004): 241-270

Tilley, S.; Gerdes, J.; Hamilton, T.; Huang, S; Müeller, H.; & Smith, D.
"On the Business Value and Technical Challenge of Adopting Web Services," Journal of Software Maintenance and Evolution Research and Practice 16, 1/2 (January-April 2004): 31-50

Conferences (FY2004)   |  SEI-Published Documents

Journal Articles   |   Book Chapters   |   Proceedings   |   Keynote Presentations   |  Tutorials

Press Releases   |   Media Coverage  |  Government Testimony

Technical Leadership Positions

Book Chapters

Chrissis, M.; Levine, L.; & Shrum S.
"Entries for Software Engineering Institute (SEI), Capability Maturity Model (CMM), and CMM Integration (CMMI)," Blackwell Encyclopedia of Management, Management Information Systems Volume. Minnesota, MN: Blackwell Publishers, 2004 (ISBN 0-6312331-7-2)

Kazman, R.
Berkshire Encyclopedia of Human-Computer Interaction, Great Barrington, MA: Berkshire Publishing Group, 2004 (ISBN 0-9743091-2-5)

Mead, N.
"Industrial Input to the Computing Curriculum," Irons, A. & Alexander, S. Effective Learning and Teaching in Computing. New York, NY: RoutledgeFalmer, 2004 (ISBN: 0-4153350-0-0)

Conferences (FY2004)   |  SEI-Published Documents

Journal Articles   |   Book Chapters   |   Proceedings   |   Keynote Presentations   |  Tutorials

Press Releases   |   Media Coverage  |  Government Testimony

Technical Leadership Positions

Proceedings

Andersen, D.; Cappelli, D.; Gonzalez, J.; Mojtahedzadeh, M.; Moore, A.; Rich, E.; Sarriegui, J.; Shimeall, T.; Stanton, J.; Weaver, E.; & Zagonel, A.
"Preliminary System Dynamics Maps of the Insider Cyber-Threat Problem," Proceedings of the 2004 International Conference of the System Dynamics Society, Oxford, England, July 25-29, 2004

Bachmann, F.; Bass, L.; Klein, M.; & Shelton, C.
"Experience Using an Expert System to Assist an Architect in Designing for Modifiability," Fourth Working IEEE/IFIP Conference on Software Architecture (WICSA 2004), Oslo, Norway, June 12-15, 2004

Bachmann, F.; Goedicke, M.; Leite, J.; Nord, R.; Pohl, K.; Ramesh, B.; & Vilbig, A.
"A Meta-Model for Representing Variability in Product Family Development," Proceedings of the Fifth International Workshop on Product Family Engineering (PFE-5), Siena, Italy, November 4-6, 2003

Bass, L.; John, B.; Adams, R.; & Sanchez, M.
"Bringing Usability Concerns to the Design of the Software Architecture," International Federation of Information Processing (IFIP), Hamburg, Germany, July 11-13, 2004

Brown, M. & Anderson, W.
“Joint Capability: Cost & Risk Factors for Systems Integration,” Society of Cost Estimating and Analysis (SCEA), Los Angeles, CA, June 15-18, 2004

“Revealing Cost Drivers for Systems Integration and Interoperability Through Q Methodology,” Conference on International Society of Parametric Analysts, Frascati, Italy, May 10-14, 2004

"Revealing Cost Drivers for Systems Integration and Interoperability: A Study Using Q Methodology," Systems and Software Technology Conference, Salt Lake City, UT, April 19-22, 2004

Bühne, S.; Chastek, G.; Käkölä, T.; Knauber, P.; Northrop, L.; & Thiel, S.
"Exploring the Context of Product Line Adoption," Product Family Engineering Workshop 5 (PFE5) Proceedings, Berlin, Germany, November 4-6, 2003

Carney, D. & Oberndorf, P.
“Integration and Interoperability Models for Systems of Systems,” Systems and Software Technology Conference, Salt Lake City, UT, April 21, 2004

Carpenter, J.
“CERT/CC Vulnerability Handling,” Consortium of CERT in Korea (CONCERT ) Seminar, Seoul, Korea, November 19-20, 2003

Collins, M.
“An Empirical Analysis of Target Resident DDoS Filters,” Proceedings of IEEE Conference on Security and Privacy,”Oakland, CA, May 2004

Feiler, P.; Gluch, D.; Hudak, J.; & Lewis, B.
“Pattern-Based Analysis of an Embedded Real-Time System Architecture,” Proceedings IFIP Workshop on ADLs, Toulouse, France, August, 2004

Feiler, P.; Hudak, J.; & Gluch, D.
“Embedded System Architecture Analysis Using the SAE AADL,” FAA Software Tools Forum, Daytona Beach, FL, May 2004

Fisher, D.
“Humanistic Approach to Knowledge Processing,“ Znalosti 2004 Third Annual Knowledge Conference, Brno CZ, February 22-25, 2004

“Reasoning with Property Based Types,” The IASTED International Conference on Artificial Intelligence and Applications (AIA 2004), Innsbruck, Austria, February 16-18, 2004

Fithen, B.
“Forum of Incident Response and Security Teams (FIRST),” Annual Conference, Budapest, Hungary, June 16, 2004

Goodenough, J. & Weinstock, C.
"Dependability Cases," Proceedings of the International Conference on Dependable Systems and Networks, Florence, Italy, June 28, 2004-July 1, 2004

Greenhouse, A.; Halloran, T.; & Scherlis, W.
“Observations on the Assured Evolution of Concurrent Java Programs,” Proceedings of the 2004 Workshop on Concurrency and Synchronization in Java Programs, Newfoundland, Canada, July 25-26, 2004

Hissam, S.
"PECTs: Putting the `PLAY' Back in `Plug-n-Play’,” Systems & Software Technology Conference (SSTC) 2004 Proceedings, Salt Lake City, UT, April 18-21, 2004

Houle, K.
“A Database Approach to Malicious Code Identification,”Sixth Association of Anti-Virus Asia Researchers Conference (AVAR 2003), Sydney, Australia, November 2-9, 2003

Kautz, K.; Levine, L.; Hefley, B.; Johansen, J.; Kristensen, C.; & Nielsen, P.
"Networked Technologies: The Role of Networks in the Diffusion and Adoption of Software Process Improvement (SPI) Approaches," Proceedings of the IFIP 8.6 Working Conference on the Diffusion and Adoption of Networked Information Technologies, Boston, MA, October 6-8, 2003

Kazman, R. & Bass, L.
“Bridging the Gaps II: Bridging the Gaps Between Software Engineering and Human-Computer Interaction,” Proceedings of the 26th International Conference on Software Engineering, ICSE 2004, Edinburgh, Scotland, May 23-28, 2004

Kazman, R.; In, P.; & Chen, H.
"From Requirements Negotiation to Software Architecture Decisions," Proceedings of the Second International Conference on Software Engineering Research, Management and Applications (SERA2004), Los Angeles, CA, May 5-7, 2004

Kazman, R.; Klein, M.; & Nord, R.
"Tailorable Architecture Methods," Proceedings of the IEEE/NASA Software Engineering Workshop, Greenbelt, MD, December 3-4, 2003

Levine, L. & Saunders, K.
"Software Patents: Innovation or Litigation," Proceedings of the IFIP 8.6 Working Conference on IT Innovation for Adaptability and Competitiveness, Boston, MA, May 30-June 2, 2004

Lewis, G. & Wrage, L.
"A Case Study in COTS Product Integration Using XML," Proceedings of the Third International Conference on COTS-Based Systems, Redondo Beach, CA, February 1-4, 2004

Linger, R.; Fung, C.; Hung, P.; & Walton, G.
“Extending Business Process Execution Language for Web Services with Service Level Agreements Expressed in Computational Quality Attributes,” Proceedings of 38th Hawaii International Conference on System Sciences (HICSS-38), 2005, IEEE Computer Society Press, Los Alamitos, CA

Linger, R.; Hevner, A.; Walton, G.; & Pleszkoch, M.
“Flow-Service-Quality (FSQ) Engineering: Foundations for High-Assurance Network Systems Development,” Proceedings of High Assurance Systems Engineering Conference (HASE 2004), Tampa, FL, March, 2004, IEEE Computer Society Press, Los Alamitos, CA

Linger, R. & Pleszkoch, M.
“Function Extraction (FX) Technology: Automated Calculation of Program Behavior for High Assurance Systems,” Proceedings of High Assurance Systems Engineering Conference (HASE 2004), Tampa, FL, March, 2004, IEEE Computer Society Press, Los Alamitos, CA

“Improving Network System Security with Function Extraction Technology for Automated Calculation of Program Behavior,” Proceedings of 37th Hawaii International Conference on System Sciences, Hawaii, January, 2004

Linger, R. & Prowell, S.
“Developing Secure Software with Cleanroom Software Engineering,” Improving Security Across the Software Development Lifecycle, Task Force Report, Volume II, National Cyber Security Summit, March, 2004

Manion, A.
”Internet Explorer: Unsafe in Any Zone,” Congreso de Seguridad en Computo, Mexico City, Mexico, May 28, 2004

Morda, D.
”Forum of Incident Response and Security Teams (FIRST) Annual Conference,” Budapest, Hungary, June 16, 2004

Mularz, D.; Smith II, J.; & Hybertson, D.
"Enterprise Architecture and COTS-Intensive System Acquisition Strategies," Proceedings of the Systems & Software Technology Conference (STSC), Salt Lake City, UT, April 19-22, 2004

Nord, R.; Han, M.; & Hoffmeister, C.
"Reconstructing Software Architecture for J2EE Web Applications," Proceedings of the 10th Working Conference on Reverse Engineering (WCRE 2003), Victoria, BC, November 13-17, 2003

Northrop, L.
"Software Product Lines," 14th Annual IBM Centers for Advanced Studies Conference (CASCON), Toronto, Ontario, October 7, 2003

O'Brien, L.; Stoermer, C.; & Verhoef, C.
"Architectural Views through Collapsing Strategies," International Workshop on Program Comprehension, Bari, Italy, June 24-26, 2004

Place, P. & Smith, D.
"TTV Framework of Technologies,” IDGA Second Conference on DoD Architectures, Washington, DC, September 27-29, 2004

Rafail, J.
"CERT/CC Vulnerability Handling,” Secure 2003, Warsaw, Poland, November 5-6, 2003

Sharygina, N.; Chaki, S.; Clarke, E.; Ouaknine, J.; & Sinha, N.
“State/Event-Based Software Model Checking,” Proceedings of IFM (Integrated Formal Methods) 2004 International Conference, Lecture Notes in Computer Science 2999, p. 128-147

Siviy, J.
"Your Six Sigma Measurement Infrastructure...And Beyond!" Proceedings of the Six Sigma for Software Development Conference, Boston, MA, October 16-17, 2003

Sledge, C. & Willis, Jr. R.
"Regional Collaborative Clusters: Building on Trusted Relationships to Increase IA Capacity," ADMI 2004 Symposium: The Symposium on Computing at Minority Institutions: Asserting Our Role in Information Assurance, Orlando, FL, May 20-22, 2004

Smith II, J.
"An Alternative to TRLs for COTS Software-Intensive Systems," Acquisition of Software-Intensive Systems Conference (ASIS) 2004, Crystal City, VA, January 26-28, 2004

"Technology Maturity Assessments for COTS-Intensive Software Systems," Systems & Software Technology Conference (SSTC), Salt Lake City, UT, April 19-22, 2004

Takenaka, A.; Port, D.; Kazman, R.; & Garg, A.
"Managing Misalignments Between Business and IT," Proceedings of 2004 International Conference on Software Engineering Research and Practice, Las Vegas, NV, June 21-24, 2004

Trammell, B.
"Preparing RIR Allocation Data for Network Security Analysis Tasks," North American Network Operators' Group (NANOG31), San Francisco, CA, May 23-25, 2004

Wilson, W.
"In Pursuit of Adequate Security," SecureIT Conference, San Francisco, CA, April 27-29, 2004

Wiik, J; Gonzalez, J.; Lipson, H; & Shimeall, T.
“Dynamics of Vulnerability—Modeling the Life Cycle of Software Vulnerabilities,” Proceedings of the 2004 International Conference of the System Dynamics Society, Oxford, England, July 25-29, 2004

Yan, H.; Garlan, D.; Schmerl, B.; Aldrich, J.; & Kazman, R.
"DiscoTect: A System for Discovering Architectures from Running Systems," Proceedings of the 26th International Conference on Software Engineering (ICSE 26), Edinburgh, Scotland, May 23-28, 2004

Zajicek, M.
"Overview of the Fundamentals of Incident Handling," Ohio Library Council (OLC) Network Security Workshop, Columbus, OH, August 25, 2004

"Computer Security Incident Response Teams (CSIRTS),” Corrections Technology Association (CTA) Conference, Pittsburgh, PA, May 24, 2004

Conferences (FY2004)   |    SEI-Published Documents

Journal Articles   |   Book Chapters   |   Proceedings   |   Keynote Presentations   |  Tutorials

Press Releases   |   Media Coverage  |  Government Testimony

Technical Leadership Positions

Keynote Presentations

Bass, L.
"Achieving Business Goals through the Design of Software Architecture," Fifth Dutch Architecture Conference, Niewwegin, The Netherlands, November 26, 2003

“Usability and Software Engineering: Experience with the Mars Exploratory Rover Project,” 2004 Argentine Symposium on Software Engineering, Córdoba, Argentina, September 20-22, 2004

Carney, D. & Oberndorf, P.
“Toward a Reference Model of Interoperability and Integration,” International Conference on Software and System Engineering and Applications, Paris, November 30-December 2, 2003

Chittister, C.
“CMMI Strategy and Status,” Ninth Annual European SEPG Conference 2004, London, England, June 14-17, 2004

Chrissis, M.
“CMMI Today,” Software and Systems Engineering Process Group Australia Conference, 2004, Adelaide, Australia, September 27-29, 2004

"Improving the Software Process with CMMI," Telelogic User Group Conference, Las Vegas, NV, October 29, 2003

Clements, P.
"Getting FCS into the Family Way," One Team Partners Software Conference for Future Combat Systems, Long Beach, CA, November 18, 2003

keynote address, Computer Society of India Software Conference, Mumbai, India, December, 2004

Garcia, S.
“Implementing CMMI in Small Settings: Results from the Huntsville, Alabama, Pilots,” Second Software Engineering Process Group Australia Conference, Adelaide, Australia, September 28, 2004

Humphrey, W.
“Development Principles for Secure Software,” First Annual Hampton University Information Assurance Symposium, Hampton, VA, February 28, 2004

“Security Changes Everything,” Ninth Annual European SEPG Conference 2004, London, England, June 14-17, 2004

"The Future of Software Engineering," TSP User Group (TUG) Meeting 2004, Pittsburgh, PA, September 27-28, 2004

Konrad, M.
"CMMI: Success and Opportunities Ahead," Second Annual QAAM/QAI Conference, Baltimore, MD, October 23, 2003

Lindner, M.
"The Ever-Changing Landscape of Internet Security: A Global Perspective," TechMentor Conference, New Orleans, LA, April 4, 2004

Nielsen, P.
“Initial Impressions: Why I Came to the Software Engineering Institute,” Team Software Process User Group Meeting (TUG 2004), Pittsburgh, PA, September 27-28, 2004

Oberndorf, P.
"COTS-Based Systems: The Road We're On,” Third International Conference on COTS-Based Software Systems, Redondo Beach, CA, February 1-4, 2004

Pethia, R.
"Computers Under Attack: What Can We Do?" Critical Infrastructure Coordination Annual Conference, Albany, NY, April 21, 2004

Shimeall, T.
"Survivability—A New Executive Perspective," National Oceanic and Atmospheric Administration (NOAA) Information Technology (IT) Conference, Silver Springs, MD, May 5, 2004

Willett, A.
"TSP Excel Tool Update," TSP User Group (TUG) Meeting 2004, Pittsburgh, PA, September 27-28, 2004

Conferences (FY2004)   |    SEI-Published Documents

Journal Articles   |   Book Chapters   |   Proceedings   |   Keynote Presentations   |  Tutorials

Press Releases   |   Media Coverage  |  Government Testimony

Technical Leadership Positions

Tutorials

Allen, J.
"Building a Practical Framework for Enterprise-Wide Security Management," Blue Cross/Blue Shield Information Security Advisory Group, Washington, DC, June 16, 2004; MIS Training Institute InfoSec World Conference CISO Summit, Orlando, FL, March 21, 2004; SecureIT Conference, San Francisco, CA, April 27-29, 2004

Allen, J.; Caralli, R.; & Wilson, W.
"The Critical Success Factors Technique: Establishing a Foundation for Enterprise Security Management," SecureIT Conference, San Francisco, CA, April 27-29, 2004

Caralli, R.
"Applying Critical Success Factors to Information Security Planning," SecureIT Conference, San Francisco, CA, April 27-29, 2004

"Enterprise Security Management (ESM) Methodology," Information Systems Audit and Control Association (ISACA) Texas Chapter, Southwest Regional Symposium on Business Continuity, Information Security, and IT Audit, Austin, TX, September 27, 2004

Cohen, S.; Chastek, G.; & Zubrow, D.
“Developing a Measurement Program for Software Product Lines,” Software Product Lines Conference (SPLC), Boston, MA, August 30-September 2, 2004

Davis, N.
"The Team Software Process Initiative with an Emphasis on Secure Software Development," Federal Deposit Insurance Corporation (FDIC) Technology Seminar, Washington, DC, September 21, 2004

Dietrich, S. & McHugh, J.
”Distributed Denial of Service: Background, Diagnosis, and Mitigation,” Annual Computer Security Applications Conference 2003, Las Vegas, NV, December 8-12, 2003

Donohoe, P. & Chastek, G.
“Product Line Analysis” Software Product Lines Conference (SPLC), Boston, MA, August 30-September 2, 2004

Feiler, P. & Lewis, B.
“Embedded Systems Engineering with SAE AADL,” SAE Avionics Systems Division Meeting, Edinburgh, Scotland, July 2004; SAE Avionics Systems Division Meeting, St. Louis, MN, April 2004; International Workshop on ADL, IFIP, Toulouse, France, August 2004

Feiler, P.; Lewis, B.; & Gluch, D.
"Embedded Systems Engineering with SAE AADL," Digital Avionics Systems Conference, Indianapolis, IN, October 12-16, 2003

Gluch, D.; Feiler, P.; & Lewis, B.
“Dependable Systems Engineering with SAE AADL,” The International Conference on Dependable Systems and Networks, Florence, Italy, June 2004

John, B. & Bass, L.
“Usability Supporting Architectural Patterns," International Conference on Software Engineering (ICSE) 2004, Edinburgh, Scotland, May 23-28, 2004

Killcrece, G.; Zajicek, M.; & Ruefle, R.
"Creating a Process Map for Incident Management," 16th Annual FIRST Conference, Budapest, Hungary, June 13-18, 2004

"Creating and Managing a CSIRT," 16th Annual FIRST Conference, Budapest, Hungary, June 13-18, 2004

Little, R.
"1516—The Future of the HLA," Simulation Interoperability Standards Organization (SISO) Euro-Simulation Interoperability Workshop, Edinburgh, Scotland, June 28-July 1, 2004; "IEEE 1516—The Future of HLA," 2004 Spring Simulation Interoperability Workshop, Crystal City, VA, April 18, 2004

Nord, R. & Stafford, J.
"Software Architecture Documentation with the Unified Modeling Language (UML)," European Conference on Object-Oriented Programming (ECOOP) / Working IEEE/IFIP Conference on Software Architecture (WICSA), Edinburgh, Scotland, June 12-15, 2004

Northrop, L.
"Achieving Product Qualities through Software Architecture Practices," 17th Conference on Software Engineering Education and Training (CSEE&T) 2004, Norfolk, VA, March 3, 2004

Northrop, L. & Clements, P.
“An Introduction to Software Product Lines,” Software Product Lines Conference (SPLC), Boston, MA, August 30-September 2, 2004

Northrop, L. & Jones, L.
“Adopting Software Product Lines,” Software Product Lines Conference (SPLC), Boston, MA, August 30-September 2, 2004

Rosenstein, R.
"CERT/CC Analysis Center Activity and Cooperation with U.S. Law Enforcement," U.S. Department of Justice (DoJ) Cybercrime Conference, Hanoi, Vietnam, August 27, 2004

Ruefle, R.
"Implementing an Effective Incident Response Capability," SecureIT Conference, San Francisco, CA, April 27-29, 2004

“Creating a Computer Security Incident Response Team (CSIRT)," EDUCAUSE 2003, Anaheim, California, November 4-7, 2003

Stevens, J.
"Which Best Practices Are Best for Me?" SecureIT Conference, San Francisco, CA, April 27-29, 2004

Zajicek, M.
"Creating and Managing Computer Security Incident Response Teams (CSIRTs)," Asia Pacific Regional Conference on Operational Technologies (APRICOT), Kuala Lumpur, Malaysia, February 18-27, 2004

"Creating and Managing Computer Security Incident Response Teams (CSIRTs)," Asia Pacific Security Incident Response Coordination Conference (APSIRC) 2004, Kuala Lumpur, Malaysia, February 23-25, 2004