{"title":"Database Internal Security Controls for SOX Law Certification","authors":"Kamilla Dória da Silveira, R. Fidalgo","doi":"10.1145/3229345.3229393","DOIUrl":"https://doi.org/10.1145/3229345.3229393","url":null,"abstract":"Section 404 of the SOX Act requires companies to certify to the effectiveness of their internal control over financial reporting. After investigating this context considering the scope of Database Security (DB), it was verified that the related works explore in detail the strategic vision of the internal controls, but neglect their operational and practical aspects. Aiming to give a contribution to this problem, this work proposes a guide of operational and technical controls to evaluate the security of the DB according to the SOX Act. As a proof-of-concept, the guide is used to the development of the tool SOXSecurity4DB, which was used in a case involving a multinational company of the retail industry.","PeriodicalId":284178,"journal":{"name":"Proceedings of the XIV Brazilian Symposium on Information Systems","volume":"23 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2018-06-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"115120077","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"AutoCosmic: COSMIC Automated Estimation and Management Tool","authors":"Miguel Ecar, Fabio Kepler, J. P. S. D. Silva","doi":"10.1145/3229345.3229409","DOIUrl":"https://doi.org/10.1145/3229345.3229409","url":null,"abstract":"Software size estimation may be costly due to the time spent in estimation, even using referenced method, such as, Functional Size Measurement methods. This research objective is to reduce estimation cost in the very early stage of software development life cycle based on user stories and COSMIC method. We propose automated size estimation in order to reduce estimation cost and increase the accuracy. We conducted a quasi-experiment where the control group is composed of certified professionals and the experimental group is actually the proposed automated estimation tool. Results show promising evidence of success in terms of estimation precision. Based on these preliminary results we conclude that user story size automation is valuable and may be more objective and precise that manual estimation.","PeriodicalId":284178,"journal":{"name":"Proceedings of the XIV Brazilian Symposium on Information Systems","volume":"48 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2018-06-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"127288069","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Pedro S. Lopes, Eduardo Lasmar, R. L. Rosa, D. Z. Rodríguez
{"title":"The Use of the Convolutional Neural Network as an Emotion Classifier in a Music Recommendation System","authors":"Pedro S. Lopes, Eduardo Lasmar, R. L. Rosa, D. Z. Rodríguez","doi":"10.1145/3229345.3229389","DOIUrl":"https://doi.org/10.1145/3229345.3229389","url":null,"abstract":"Currently, social networks has been used for its users, and exploited by mechanisms of quality measurement systems and recommendation of products and services. The Recommendation Systems (SR) have used the data of the social networks and in parallel they have applied the sentiment and affective analysis in such data. However, there is still a concern in increasing the accuracy of the sentiment and affective analysis. This article introduces an SR, which extracts the texts of the users of the social networks and suggests musical styles based on the sentiment analysis by lexical approach and based on the affective analysis through the machine learning. The Convolutional Neural Network algorithm used for the emotion classification of hapiness, sadness, anger, fear, disgust and surprise presented a precision higher than the found in related works. Classification results of the F-Measure were of 0.98 e 0.96 for the emotion of sadness and anger, respectively. In addition, SR was assessed by means of subjective tests and the experimental results show that 97% of users approved the SR proposal.","PeriodicalId":284178,"journal":{"name":"Proceedings of the XIV Brazilian Symposium on Information Systems","volume":"42 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2018-06-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"126449276","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Natan B. Morais, Rafael M. D. Frinhani, B. Kuehne, Dionisio Machado Leite Filho, M. Peixoto, B. Batista
{"title":"Performance Evaluation of Heuristics for Cloud Workload Balancing","authors":"Natan B. Morais, Rafael M. D. Frinhani, B. Kuehne, Dionisio Machado Leite Filho, M. Peixoto, B. Batista","doi":"10.1145/3229345.3229417","DOIUrl":"https://doi.org/10.1145/3229345.3229417","url":null,"abstract":"Cloud computing introduces a new level of flexibility and scalability for providers and clients, because it addresses challenges such as rapid change in Information Technology (IT) scenarios and the need to reduce costs and time in infrastructure management. However, to be able to offer quality of service (QoS) guarantees without limiting the number of requests accepted, providers must be able to dynamically and efficiently scale service requests to run on the computational resources available in the data centers. Load balancing is not a trivial task, involving challenges related to service demand, which can shift instantly, to performance modeling, deployment and monitoring of applications in virtualized IT resources. In this way, the aim of this paper is to develop and evaluate the performance of different load balancing heuristics for a cloud environment in order to establish a more efficient mapping between the service requests and the virtual machines that will execute them, and to ensure the quality of service as defined in the service level agreement. By means of experiments, it was verified that the proposed heuristics presented better results when compared with traditional and artificial intelligence heuristics.","PeriodicalId":284178,"journal":{"name":"Proceedings of the XIV Brazilian Symposium on Information Systems","volume":"45 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2018-06-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"132665957","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Goal-Oriented Model Conversion to Automated Planning Problem Using Hierarchical Task Networks","authors":"Allisson M. R. Barros, V. Nunes, C. Ralha","doi":"10.1145/3229345.3229402","DOIUrl":"https://doi.org/10.1145/3229345.3229402","url":null,"abstract":"Specifying systems adhering to stakeholders' goals is a topic of great research interest. This scenario becomes even more challenging when it is expected that systems will be able to adapt in a timely manner to the situations experienced by them in order to promote adherence to organizational and individual expectations. In this sense, this papers works with goal-oriented modeling to promote the understanding and requirements' analysis focused on agents' interests. During the systems project, we advocate the use of automated planning to support the selection of requirements or to support the adaptation of its functionalities at runtime. As a first step, this paper provides a goal-oriented automatic model converter (Tropos model) using RGM (Runtime Goal Model) rules for real-time adaptation to a planning model based on hierarchical tasks network. The converter was tested using three generic examples and a real scenario of a mobile application for public transport. The converter was promising and adherent to the representation of reality.","PeriodicalId":284178,"journal":{"name":"Proceedings of the XIV Brazilian Symposium on Information Systems","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2018-06-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"128282127","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Gevã Martins, Welington Veiga, Fernanda Campos, Victor Ströele, J. M. David, Regina M. M. Braga
{"title":"Building Educational Games from a Feature Model","authors":"Gevã Martins, Welington Veiga, Fernanda Campos, Victor Ströele, J. M. David, Regina M. M. Braga","doi":"10.1145/3229345.3229349","DOIUrl":"https://doi.org/10.1145/3229345.3229349","url":null,"abstract":"We present BROAD-PLG, a Software Product Line to support the construction of educational games, with a set of features that will integrate the artefact to be developed. The evaluation was based on the development of the infrastructure and the generation of new products. It followed two steps: the development of a game for teaching Logic using the defined features and, in the second step, we describe the game in use in two virtual learning environments - the Moodle (free platform) and youKnow (private platform). For evaluation in a real learning environment the game was wrapped as a service. The results point to the feasibility of using the solution and the set of features for automatic or semi automatic generation of educational games.","PeriodicalId":284178,"journal":{"name":"Proceedings of the XIV Brazilian Symposium on Information Systems","volume":"30 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2018-06-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"132781123","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Peterson Luiz da R. Rodrigues, Miguel Ecar, S. V. Menezes, J. P. S. D. Silva, Gilleanes Thorwald Araujo Guedes, E. Rodrigues
{"title":"Empirical Evaluation of Formal Method for Requirements Specification in Agile Approaches","authors":"Peterson Luiz da R. Rodrigues, Miguel Ecar, S. V. Menezes, J. P. S. D. Silva, Gilleanes Thorwald Araujo Guedes, E. Rodrigues","doi":"10.1145/3229345.3229401","DOIUrl":"https://doi.org/10.1145/3229345.3229401","url":null,"abstract":"Agile approaches are known by making the use of informal elicitation techniques for requirements specification. The exclusive use of these techniques may cause some issues, such as ambiguous specifications and information lack. In this work we investigate better approaches to specify requirements in agile projects. Thus, we conducted an empirical evaluation about applicability of a formal method as specification technique, using mathematical logic as a possibility to solve limitations of informal specification. Initially, we conducted a survey to obtain the agile team practitioners opinion. Furthermore, we conducted two separated case studies in two agile teams to evaluate the applicability of Z notation in the requirements specification. Our initial results pointed out that formal specification assists on making complex requirements clearer and decreasing the time to understand their meanings.","PeriodicalId":284178,"journal":{"name":"Proceedings of the XIV Brazilian Symposium on Information Systems","volume":"6 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2018-06-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"122143565","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Guilherme Ermel, Kleinner Farias, L. Gonçales, Vinícius Bischoff
{"title":"Supporting the Composition of UML Component Diagrams","authors":"Guilherme Ermel, Kleinner Farias, L. Gonçales, Vinícius Bischoff","doi":"10.1145/3229345.3229404","DOIUrl":"https://doi.org/10.1145/3229345.3229404","url":null,"abstract":"Fast-changing business environments have become enterprise information systems more heterogeneous and complex. This extreme uncertainty leads to continuous development and integration of architecturally relevant components developed in parallel. In this context, the proper composition of such components is critical to reduce the development effort. However, the current composition tools are still considered imprecise and inflexible for this purpose. This article, therefore, proposes MoCoTo, a model composition tool to support the integration of UML component diagrams. It exploits equivalence relationships between the UML component elements to improve integration precision and accuracy. Developers and system analysts can benefit from using MoCoTo when evolving or maintaining architectural models of enterprise information systems. MoCoTo was implemented as an Eclipse platform plug-in. The tool was used to support the composition of architectural components in three realistic evolution scenarios of a Software Product Line. Our preliminary results indicated that MoCoTo was able to integrate architectural models represented with UML component diagrams. The metrics used to evaluate the effectiveness of the proposed tool (i.e., precision, recall and F-measure) presented values higher than 0.6 in all evaluation scenarios.","PeriodicalId":284178,"journal":{"name":"Proceedings of the XIV Brazilian Symposium on Information Systems","volume":"17 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2018-06-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"125314796","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Marília M. B. Cerqueira, Ana Patrícia Fontes Magalhães, H. Saba, Eduardo M. F. Jorge
{"title":"A Software Development Process for Super Agile Projects","authors":"Marília M. B. Cerqueira, Ana Patrícia Fontes Magalhães, H. Saba, Eduardo M. F. Jorge","doi":"10.1145/3229345.3229399","DOIUrl":"https://doi.org/10.1145/3229345.3229399","url":null,"abstract":"Increasing in the creative economics, growth in the demand of mobile applications, and necessity of rapid product availability to the customer promote arising from projects that have a life cycle of a few days. These type of projects are called super agile. Among them are innovation projects with emphasis in mobile application and elaboration of proof of concept to study the technical viability or others projects developed, for example, by startups. However, the field of super agile software development still is in its initial stages, maybe because it is a recent problem faced by companies and startups. Thereby, this article proposes a development process that meets the features of projects with short life cycles of up to 2 weeks. The proposed process based on market demands, identified in field research, integrates the most current used agile methods and methodologies. An initial evaluation in three organizations showed that the process is adherent to necessities of these companies.","PeriodicalId":284178,"journal":{"name":"Proceedings of the XIV Brazilian Symposium on Information Systems","volume":"33 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2018-06-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"125562079","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
A. D. P. A. Tramontin, Isabela Gasparini, Roberto Pereira
{"title":"Recommender Systems with Social Elements: A Systematic Mapping","authors":"A. D. P. A. Tramontin, Isabela Gasparini, Roberto Pereira","doi":"10.1145/3229345.3229350","DOIUrl":"https://doi.org/10.1145/3229345.3229350","url":null,"abstract":"Recommendation Systems (RS) deal of the overload of information online, allowing the user to find desirable items quickly, without being surprised by irrelevant information. Individual preference and interpersonal influence are important contextual factors for social recommendations, as they affect users' decisions about information retention. The goal of this paper is to identify the state of the art in RS with the use of social elements. For this, a systematic mapping of the literature was conducted, revealing a growing trend in the number of articles published in the last ten years, especially in China, and with more frequent proposals for new models, systems and frameworks for recommendation. Almost half of the mapped articles present as a domain Entertainment or Product Review/Evaluation, with the collaborative filtering approach being the most common of the approaches used, and the similarity of friends as the most common of the social components considered. As an evaluation strategy, more than half of the mapped articles use offline experiments in a previously populated database to simulate user actions. The mapping showed that although RSs are considering social elements, there is still a lack of works that explore these elements in real contexts of use.","PeriodicalId":284178,"journal":{"name":"Proceedings of the XIV Brazilian Symposium on Information Systems","volume":"24 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2018-06-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"126301730","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}