API trustworthiness: an ontological approach for software library adoption

被引:4
|
作者
Eghan, Ellis E. [1 ]
Alqahtani, Sultan S. [1 ]
Forbes, Christopher [1 ]
Rilling, Juergen [1 ]
机构
[1] Concordia Univ, Dept Comp Sci & Software Engn, Montreal, PQ, Canada
关键词
Software quality; Trustworthiness; Code reuse; License violations; API breaking changes; Software security vulnerabilities; SEMANTIC WEB; PATTERNS;
D O I
10.1007/s11219-018-9428-4
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
The globalization of the software industry has led to an emerging trend where software systems depend increasingly on the use of external open-source external libraries and application programming interfaces (APIs). While a significant body of research exists on identifying and recommending potentially reusable libraries to end users, very little is known on the potential direct and indirect impact of these external library recommendations on the quality and trustworthiness of a client's project. In our research, we introduce a novel Ontological Trustworthiness Assessment Model (OntTAM), which supports (1) the automated analysis and assessment of quality attributes related to the trustworthiness of libraries and APIs in open-source systems and (2) provides developers with additional insights into the potential impact of reused libraries and APIs on the quality and trustworthiness of their project. We illustrate the applicability of our approach, by assessing the trustworthiness of libraries in terms of their API breaking changes, security vulnerabilities, and license violations and their potential impact on client projects.
引用
收藏
页码:969 / 1014
页数:46
相关论文
共 50 条
  • [21] Trustworthiness in software environments
    Harauz, John
    Voas, Jeffrey
    Hurlburt, George F.
    [J]. IT Professional, 2009, 11 (05) : 35 - 40
  • [22] An Approach of Trustworthiness Evaluation of Software Behavior Based on Multidimensional Fuzzy Attributes
    Li, Zhen
    Tian, Junfeng
    [J]. JOURNAL OF COMPUTERS, 2012, 7 (10) : 2572 - 2577
  • [23] An ontological-based approach to analyze software production methods
    Pastor, Oscar
    Espana, Sergio
    Gonzalez, Arturo
    [J]. INFORMATION SYSTEMS AND E-BUSINESS TECHNOLOGIES, 2008, 5 : 258 - 270
  • [24] An Ontological Approach for Identifying Software Variants: Specialization and Template Instantiation
    Reinhartz-Berger, Iris
    Zamansky, Anna
    Wand, Yair
    [J]. CONCEPTUAL MODELING, ER 2016, 2016, 9974 : 98 - 112
  • [25] A Distributed Ontological Approach as a Basis for Software in the Context of Academic Programs
    Hackelbusch, Richard
    Appelrath, H.-Juergen
    [J]. TIMES OF CONVERGENCE: TECHNOLOGIES ACROSS LEARNING CONTEXTS, PROCEEDINGS, 2008, 5192 : 122 - 127
  • [26] Why is it so hard to predict software system trustworthiness from software component trustworthiness?
    Voas, J
    [J]. 20TH IEEE SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS, PROCEEDINGS, 2001, : 179 - 179
  • [27] Applying a Software Development Product Cycle to Library Technology Adoption and Development
    Costello, Laura
    [J]. JOURNAL OF LIBRARY ADMINISTRATION, 2018, 58 (04) : 334 - 345
  • [28] A survey of software trustworthiness measurements
    Tao, Hongwei
    Chen, Yixiang
    Wu, Hengyang
    Deng, Rumei
    [J]. International Journal of Performability Engineering, 2019, 15 (09) : 2364 - 2372
  • [29] Software assurance, trustworthiness, and rigor
    O'Neill, Don
    [J]. CrossTalk, 2014, 27 (05): : 25 - 29
  • [30] An Analysis to Understand Software Trustworthiness
    Tan, Thomas
    He, Mei
    Yang, Ye
    Wang, Qing
    Li, Mingshu
    [J]. PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE FOR YOUNG COMPUTER SCIENTISTS, VOLS 1-5, 2008, : 2366 - 2371