<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Multimodel-Driven Software Engineering for Evolving Enterprise Systems (Position Paper)</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Richard F. Paige</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Radu Calinescu</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dimitrios S. Kolovos</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nicholas Matragkas</string-name>
          <email>nicholas.matragkasg@york.ac.uk</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dave Cli</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Computer Science, University of Bristol</institution>
          ,
          <country country="UK">UK</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Department of Computer Science, University of York</institution>
          ,
          <country country="UK">UK</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>We advocate the use of multimodel-driven software engineering for the principled evolution of enterprise systems whose stakeholder concerns are captured using multiple interdependent models. Enterprise systems that evolve are increasingly common in healthcare, transportation, e-government and defense. These important systems must be regularly extended with new components satisfying interdependent functional, governance and quality-of-service (QoS) requirements that are modelled using di erent domain-speci c languages. We describe key challenges associated with modelling, reasoning about QoS properties, and evolving such systems. The concepts of this engineering paradigm are presented in the context of a statistical reporting project carried out in collaboration with healthcare organisations.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        The recent advent of technologies ranging from cloud and mobile computing
to smart sensor networks has led to the emergence of new types of data and
applications at an extremely fast rate. This trend is ampli ed further by equally
rapid changes in public information governance. The open data movement, in
part spearheaded by the UK Government [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] and recently embraced by all G8
Governments [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], has opened up a wide range of public datasets for research and
commercial use. Healthcare, transportation, education and local government are
only a few of the areas in which new public datasets are released (e.g., data.gov,
data.gov.uk) on a daily basis.
      </p>
      <p>
        These developments have created business and research exploitation
opportunities for both public and commercial organisations. To exploit these
opportunities { and to comply with changes in information governance and other
requirements { such organisations must evolve their enterprise systems on a
regular basis. Information systems supporting new business processes must be
engineered and integrated on the y with existing enterprise systems, and must
then be updated frequently in response to new stakeholder requirements and
governance policies. Plausible examples of such evolving enterprise systems are
encountered in the health and social care domain. In the UK for instance, the
recently enacted Health and Social Care Act 2012 [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] required an organisation
to \establish and operate a system for the collection or analysis of information
of a description speci ed in the request " of \any person", at any time.
      </p>
      <p>The stringent demands of evolving enterprise systems cannot be achieved
using today's software engineering approaches. Traditional enterprise system
engineering approaches comprise manual processes that cannot respond to such
demands in a timely manner, and are costly and error prone. Model-driven software
engineering - which automates development processes by synthesising software
artefacts from models - is challenging to apply, as the concerns of new
information systems (e.g., functionality, governance and quality-of-service) cannot easily
be captured by a single model.</p>
      <p>We envisage that overcoming the limitations of existing approaches and
achieving the goals of evolving enterprise systems requires multimodel-driven
software engineering (MMSE). This software engineering paradigm will
automate key processes of evolving enterprise systems whose concerns are described
by multiple interdependent models, when these models are speci ed by di erent
stakeholders, in di erent domain-speci c languages. Signi cant research
challenges must be addressed to achieve this vision. A key concern is integrating QoS
models throughout the engineering lifecycle. In particular, the research
community will need to address the open research questions of how to devise multimodel
transformation techniques that consider inter-model dependencies (where some
are QoS models), and how to co-evolve sets of interdependent metamodels.
Another key challenge is the joint analysis of quality-of-service (QoS) models for
dependability, performance and resource usage, to identify system con gurations
that deliver e ective QoS trade-o s.</p>
      <p>Our paper summarises these key challenges, and sets a research agenda for
the delivery of the software engineering formalisms, techniques and tools needed
to automate the development, analysis, adaptive con guration and evolution of
information systems speci ed by sets of interdependent functional, governance
and QoS models.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Background</title>
      <p>
        Recent advances in model-driven software engineering (MDSE) address many
challenges of developing traditional software systems. MDSE is a software
development paradigm that aims to use (software) models as the main development
artefact instead of code [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. Achieving this aim within a problem domain involves
the use of domain-speci c languages (DSLs) to de ne models of the systems to
develop [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Automated transformations can be applied to them to generate
models of lower abstraction levels, which ultimately can be transformed into code.
The advantages of MDSE over other approaches to software development
include signi cant improvements in software quality and development e ciency,
and increased reusability of software components [
        <xref ref-type="bibr" rid="ref4 ref5">4, 5</xref>
        ]. The research e orts to
exploit these advantages produced a broad range of e ective MDSE modelling
languages and tools (e.g., [
        <xref ref-type="bibr" rid="ref6 ref7">6, 7</xref>
        ]).
      </p>
      <p>
        More recently, the MDSE paradigm was extended to also cover the
postdevelopment stages of the software lifecycle. In this extended MDSE approach,
models continue to be used as the primary artifact in the maintenance and
evolution of software systems. A key challenge of using MDSE in this context
is that the models and metamodels used at di erent levels of abstraction may
change asynchronously as the software system evolves, creating ripple e ects
on related artefacts such as model transformations and validation constraints.
Di erent aspects of this challenge have been addressed by recent research on
model management [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ], model-metamodel co-evolution [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ], and incremental and
bidirectional model synchronisation [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ].
      </p>
      <p>
        In parallel with these advances, the performance (or QoS ) engineering area
of MDSE uses performance, reliability and cost models as key artifacts in all
stages of the software lifecycle [
        <xref ref-type="bibr" rid="ref11 ref12">11, 12</xref>
        ]. Model-driven QoS engineering aims to
ensure that software systems satisfy their QoS requirements \by construction"
when initially delivered [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], and continue to do so as they self-adapt in response
to changes in environment, requirements or internal state [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. QoS models may
be developed explicitly or may be synthesised from annotated variants of the
structural and behaviour models used in the traditional MDSE process [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ],
and typically need to be updated continually at run time based on the observed
system behaviour [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. Such e orts can be linked to relevant modelling standards
such as the MARTE and QoS pro les for UML [
        <xref ref-type="bibr" rid="ref17 ref18">17, 18</xref>
        ].
3
      </p>
    </sec>
    <sec id="sec-3">
      <title>A motivating scenario</title>
      <p>In the UK, there are organisations responsible for accumulating and managing
data related to health and social care. They act as a trusted repository and
broker for such information, and also provide statistical expertise and domain
knowledge relevant to such data. In particular, they may produce and provide
statistical reports on health and social care data to a variety of stakeholders.
Stakeholders may include casual browsers of health and social care data { who
may simply be interested in learning what information or reports are available {
to sophisticated commercial users of data/reports, who may base important
commercial decisions on what they acquire from this trusted broker. Additionally,
the organisation may be required to provide information to government
departments or ministers. As such, information in the form of customised reports and
data may be requested by commercial, public or governmental stakeholders, at
any time, and the organisation must be able to respond to such requests. In
particular:
{ QoS requirements may be applicable to requests coming from stakeholders,
e.g., a certain data quality, a report available within a certain hard or
software deadline.
{ Information governance requirements and policies may also be applicable,
requiring the health and social care organisation to determine whether
prospective customers are permitted to access either raw data, or pseudonymised
data, of a certain type or kind. Checking compliance with information
governance policies is particularly time consuming; it would be bene cial to be
able to determine if a customer was permitted to access particular data items
before continuing with the rest of the procurement process, but sometimes
this is not possible { research (see the next point) may need to be carried
out in parallel with checking compliance.
{ A customer may request an existing type of report, or a report that is similar
to one that is currently available. But they may also request reports that
are new and novel, for which a research process must be carried out. In such
a process, the organisation may have to `buy in' expertise it may not have,
may need to investigate new statistical methods or practices, and may need
to synchronise the research process with parallel business processes that are
in place to ensure proper billing and compliance with governance policies
and regulations.</p>
      <p>Such an organisation would potentially bene t from the application of di
erent models: for capturing business processes; for capturing QoS properties and
requirements; for capturing data and interrelationships; and for capturing
information governance rules. Such models could be used for understanding the
complexity of the organisation, analysing the e ectiveness or potential bottlenecks
in a particular stakeholder interaction, and for analysing the e ects of
evolution, e.g., through new QoS requirements or stakeholder requirements. However,
the stakeholders interested in the organisation's research, data and results can
change at any time, leading to new report/data requirements. As such, the
models relevant to the organisation should be considered highly volatile, and may be
subject to evolution at any time.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Multimodel-driven software engineering</title>
      <p>Fast and robust evolution represents a key requirement for a growing number
of important enterprise systems. Achieving this requirement needs software
engineering technology capable of developing \on demand" information systems
that satisfy the overlapping concerns of di erent stakeholders, and of
integrating them into evolving enterprise systems on the y. We envisage that this role
will be played by multimodel-driven software engineering (MMSE) { a novel
software engineering approach that will combine:
{ multimodel-driven automated code generation |to take advantage e ectively
of interdependent models associated with di erent but overlapping areas of
concern, and speci ed by di erent classes of stakeholders in distinct and
co-evolving domain-speci c languages;
{ multimodel-driven QoS engineering |to ensure that evolving enterprise
systems achieve the performance, dependability and cost-related requirements
speci ed across the interdependent models mentioned above.</p>
      <p>
        Signi cant research is required to provide the theoretical foundation for the
MMSE vision and open-standards MMSE tools that realise this theory.
Extending the applicability of MDSE to large-scale, evolving software systems whose
characteristics spread multiple domains is a hard open problem [
        <xref ref-type="bibr" rid="ref4">4, 19</xref>
        ], whose
solution involves addressing several major challenges:
1. Transformations of interdependent models. Identifying the dependencies among
multiple concern-speci c models and devising model transformations that
comply with these dependencies is notoriously di cult and error prone [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
2. Co-evolution of interdependent metamodels. Managing the co-evolution of
heterogeneous sets of interdependent metamodels and the synchronisation
of their associated models is a complex problem that is not addressed by
existing MDSE approaches [19].
3. Cross-analysis of interrelated QoS models. Analysing the relationships and
tradeo s between interacting performance, dependability and cost attributes
speci ed across multiple models is a complex and non-scalable task that is
deemed a major challenge for QoS engineering [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
      </p>
      <p>The research agenda in the next section suggests research objectives that need
to be pursued by the software enginnering community in order to tackle these
challenges and to realise the vision of multimodel-driven software engineering.
5</p>
    </sec>
    <sec id="sec-5">
      <title>MMSE research agenda</title>
      <p>Research objective 1. To develop a theoretical foundation comprising
formalisms, algorithms, model transformations and techniques for multimodel-driven
software development, and for the management and co-evolution of
interdependent metamodel and model sets.</p>
      <p>
        Addressing this objective requires the development of new techniques for
multi-modelling, including the following multimodel-aware code generators and
co-evolution approaches:
1. DSLs for modelling the architecture, business processes and governance rules
associated with enterprise information systems. These DSLs must be de ned
using generic modelling concepts (generic in the sense that they can be used
throughout the enterprise domain, and derived from existing modelling
languages or frameworks such as ArchiMate and TOGAF), wherein metamodels
are speci ed in terms of required arguments. This will allow substantial
sharing between DSLs.
2. Formalism based on OCL and OCL extensions such as the Epsilon
Validation Language [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ], for de ning generic inter-dependencies between the DSLs
from (1). These formalisms must allow instantiation of the generic modelling
concepts from (1) and support the speci cation of strong (i.e., must-hold)
and weak (i.e., may-hold) consistency rules on models. These formalisms
need to be elaborated to allow such rules to be de ned for QoS models.
3. A theory of generic code generation for transforming multi-models into
platform-speci c enterprise information systems application code. The
transformations must be capable of instantiating generic parameters and of
producing monitors to be used to detect whenever QoS properties (not
guaranteed to hold via construction) have been violated. The novelty here is that
the code generation must take into account QoS models as well as other
enterprise systems domain models.
4. A theory of co-evolution for generic multi-models, investigating patterns of
generic metamodel change (including changes to parameters), as well as
de ning strategies for co-evolving generic models, metamodels and
interdependencies (from (1) and (2)) and code generators (from (3)).
Research objective 2. To devise a suite of scalable QoS engineering techniques
for: (i) co-analysing the relationships between QoS concerns speci ed through
multiple mathematical models; and (ii) identifying e ective tradeo s between
con icting QoS concerns. The real challenge here is to be able to manage QoS
models in a structurally identical way to other MDSE models.
      </p>
      <p>
        Achieving this objective will require the use of a combination of stochastic,
Markovian and queueing models to co-analyse QoS properties including: (i)
dependability (e.g., availability and reliability); (ii) performability (e.g., response
time and throughput); and (iii) resource usage (e.g., battery power, data storage
capacity, bandwidth and cost). New research results are needed to enable the
co-analysis of interdependent QoS attributes speci ed by heterogeneous
mathematical models, in order to identify and exploit e ective tradeo s between the
dependability, performability and resource usage requirements of complex
software systems. To accomplish this, the research must develop the following new
theoretical contributions for the co-analysis of interdependent QoS models:
1. Techniques for the automated co-extraction of stochastic, Markovian and
queueing QoS models from enhanced structural models speci ed using
QoSrelated UML pro les [
        <xref ref-type="bibr" rid="ref17 ref18">20, 17, 18</xref>
        ]. These techniques could build on results from
[
        <xref ref-type="bibr" rid="ref12 ref15">21, 22, 12, 15, 23</xref>
        ], extending them with support for extracting new types of
QoS models, and with the ability to identify and encode the
interdependencies among multiple QoS models.
2. A high-level formalism for specifying (i) the QoS constraints that an
information system must comply with at all times; and (ii) the utility associated
with the achievable trade-o s between the dependability, performability and
resource usage of these systems.
3. Algorithms for translating the QoS constraints and utility levels that system
developers and operators provide in the high-level formalism from (2) into
veri able low-level properties expressed in temporal logics augmented with
probabilities, event rates, costs and rewards.
4. Quantitative analysis techniques for the co-analysis of the formally expressed
sets of QoS properties from (3) against the mathematical QoS models from (1).
These techniques will need to take into account the dependencies among
multiple QoS models, in order to identify trade-o s between
performability, dependability and resource usage that satisfy the QoS constraints and
achieve a high utility.
      </p>
      <p>Research objective 3. To develop an open-standards MMSE platform.</p>
      <p>This multimodel-driven software engineering platform needs to include:
1. An integrated toolset supporting multimodel-driven software development,
QoS engineering and metamodel/model management. Some of this
technology already exists, but extensions to existing model management platforms
(such as ATL or Epsilon) need to be made to fully support QoS models,
particularly for code generation.
2. A methodology comprising methods for the e ective engineering of evolving
enterprise systems.</p>
      <p>The MMSE platform must integrate, implement and hide the complexity of the
formalisms, algorithms and techniques devised by the research described under
the research objectives 1 and 2, enabling developers of large-scale evolving
software systems to exploit these theoretical results e ectively without the need for
expert training. Extending an established platform (e.g., the Eclipse platform)
for achieving this would speed up the adoption of MMSE considerably.
Research objective 4. To employ MMSE in the development of exemplar
evolving enterprise systems.</p>
      <p>It is essential that emerging MMSE techniques and tools are evaluated in the
development of real-world evolving enterprise systems, as part of joint projects
between the research community and organisations whose business processes
are supported by such systems. The wide dissemination of the results of these
projects, ideally as open-sourced exemplars, is essential to the early adoption of
the much needed MMSE technology.
6</p>
    </sec>
    <sec id="sec-6">
      <title>MMSE technology delivery in health and social case</title>
      <p>
        We recently embarked on a new project to devise MMSE technology
components, and to use them for the development of a prototype evolving enterprise
system, in collaboration with a health and social care partner. This will allow
us to validate, re ne and extend our preliminary version of several MMSE
technology components, and to contribute signi cantly to the e orts to achieve the
objectives stated in the UK Health and Social Care Act 2012 [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. As part of
this, our planned MMSE platform will be instantiated with speci c types of
models relevant to a health and social care industry partner. In particular, we
envision building QoS models relevant to assessing the timeliness of treatment or
care, information governance models capturing the policies, rules and procedures
related to health and social care, etc. This approach is summarised in Fig. 1.
      </p>
      <p>Our research will be carried out while being driven by scenarios and use cases
from the health and social care domain. A plausible use case that we have
available involves using multimodel-driven software engineering to support reporting
scenarios. Such scenarios involve collecting di erent types of raw pseudonymised
data (e.g., number of incidents of stroke in a particular region) as well as
statistical data (e.g., percentage of residents of a certain age being supported by a
care provider in a region). Such data may need to be collated and presented in
a report for a particular stakeholder group - like a health trust (who may have
responsibility for reporting care outcomes to government), or even a government
minister.</p>
      <p>The data and statistics either gathered or produced for these reports must
be audited and validated, produced within strict time bounds, for speci c costs
(for example, some reports may be produced for a commercial organisation for
a fee). The type, quantity and complexity of the data that is being managed,
and the reports that are being generated, may change at any time { that is, new
IT systems may be brought in to the report-generating organisation (e.g., from
new health care providers) and integrated into the report generating process.</p>
      <p>Such systems clearly require handling of multiple models and QoS concerns,
as well as the need to handle evolution of models. What is particularly
challenging about this scenario is that the types of models evolve in di erent ways and
at di erent rates. Consider Fig. 1: the architecture of such an enterprise system
at one of our health and social care partners does not change frequently, but the
QoS requirements do (e.g., on a problem-by-problem basis: di erent customers
require their results at di erent rates), and the information governance rules
also change frequently (though not as frequently as QoS models) due to new
legislation and Department of Health rules. As such, the multimodel evolution
problem is extremely challenging in this context.
7</p>
    </sec>
    <sec id="sec-7">
      <title>Conclusions</title>
      <p>We have motivated the need for and the challenges of multimodel-driven software
development (MMSE), particularly focusing on evolving enterprise systems. We
have described a research agenda for developing the MMSE theory and tools
required to work with such systems, as well as a motivating scenario in the health
and social care domain. Currently, we are developing the MMSE infrastructure
for addressing the research objectives of this agenda in the health and social
care domain, and are identifying suitable enterprise systems scenarios with two
practicing health and social care partners.
19. Ian Sommerville, Dave Cli , Radu Calinescu, Justin Keen, Tim Kelly, Marta
Kwiatkowska, John McDermid, and Richard Paige. Large-scale complex IT
systems. Commun. ACM, 55(7):71{77, 2012.
20. Object Management Group. UML Pro le for Schedulability, Performance and</p>
      <p>Time v1.1, 2005.
21. Radu Calinescu and Marta Kwiatkowska. CADS*: Computer-aided development
of self-* systems. In FASE 2009, pages 421{424, 2009.
22. M. L. Drago, C. Ghezzi, and R. Mirandola. Towards quality driven exploration of
model transformation spaces. In MoDELS 2011, pages 2{16.
23. Murray Woodside, Dorina C. Petriu, Dorin B. Petriu, Hui Shen, Toqeer Israr, and
Jose Merseguer. Performance by uni ed model analysis (PUMA). In 5th Intl.
Workshop on Software and Performance, pages 1{12. ACM, 2005.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>Nigel</given-names>
            <surname>Shadbolt</surname>
          </string-name>
          ,
          <string-name>
            <surname>Kieron O'Hara</surname>
            ,
            <given-names>Tim</given-names>
          </string-name>
          <string-name>
            <surname>Berners-Lee</surname>
            , Nicholas Gibbins,
            <given-names>Hugh</given-names>
          </string-name>
          <string-name>
            <surname>Glaser</surname>
            , Wendy Hall, and
            <given-names>M. C.</given-names>
          </string-name>
          <string-name>
            <surname>Schraefel</surname>
          </string-name>
          .
          <article-title>Linked open government data: Lessons from data</article-title>
          .
          <source>gov.uk. IEEE Intelligent Systems</source>
          ,
          <volume>27</volume>
          (
          <issue>3</issue>
          ):
          <volume>16</volume>
          {
          <fpage>24</fpage>
          ,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>UK</given-names>
            <surname>Cabinet</surname>
          </string-name>
          <article-title>O ce. G8 Open Data Charter and Technical Annex, G8 communique and documents</article-title>
          ,
          <year>June 2013</year>
          . https://www.gov.uk/government/uploads/system/ uploads/attachment_data/file/207772/Open_Data_Charter.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <source>The Health and Social Care Information Centre, Part 9, Chapter 2 of the Health and Social Care Act</source>
          <year>2012</year>
          ,
          <year>2012</year>
          . Available at http://www.legislation.gov.uk/ ukpga/2012/7/enacted.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <given-names>Robert</given-names>
            <surname>France and Bernhard Rumpe</surname>
          </string-name>
          .
          <article-title>Model-driven development of complex software: A research roadmap</article-title>
          .
          <source>In ICSE Workshop Future of Softw. Eng.</source>
          , pages
          <volume>37</volume>
          {
          <fpage>54</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <given-names>M.</given-names>
            <surname>Fowler.</surname>
          </string-name>
          Domain-Speci c Languages.
          <string-name>
            <surname>Addison-Wesley</surname>
          </string-name>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Dimitrios</surname>
            <given-names>S</given-names>
          </string-name>
          . Kolovos, Richard F. Paige, and
          <string-name>
            <given-names>Fiona</given-names>
            <surname>Polack</surname>
          </string-name>
          .
          <article-title>The Epsilon transformation language</article-title>
          .
          <source>In ICMT 2008</source>
          , pages
          <fpage>46</fpage>
          {
          <fpage>60</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <given-names>Dave</given-names>
            <surname>Steinberg</surname>
          </string-name>
          , Frank Budinsky, Marcelo Paternostro, and Ed Merks.
          <source>EMF: Eclipse Modeling Framework. Addison-Wesley</source>
          ,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Dimitrios</surname>
            <given-names>S</given-names>
          </string-name>
          . Kolovos, Richard F. Paige,
          <string-name>
            <surname>Louis M. Rose</surname>
          </string-name>
          , and
          <string-name>
            <surname>James</surname>
            <given-names>R.</given-names>
          </string-name>
          <string-name>
            <surname>Williams</surname>
          </string-name>
          .
          <article-title>Integrated model management with Epsilon</article-title>
          .
          <source>In ECMFA 2011</source>
          , pages
          <fpage>391</fpage>
          {
          <fpage>392</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <given-names>Louis</given-names>
            <surname>Rose</surname>
          </string-name>
          , Dimitrios Kolovos, Richard Paige, and
          <string-name>
            <given-names>Fiona</given-names>
            <surname>Polack</surname>
          </string-name>
          .
          <article-title>Model migration with Epsilon Flock</article-title>
          .
          <source>In ICMT, LNCS 6142</source>
          .
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <given-names>H.</given-names>
            <surname>Giese</surname>
          </string-name>
          and
          <string-name>
            <given-names>R.</given-names>
            <surname>Wagner</surname>
          </string-name>
          .
          <article-title>From model transformation to incremental bidirectional model synchronization</article-title>
          .
          <source>Softw. &amp; Syst. Modeling</source>
          ,
          <volume>8</volume>
          (
          <issue>1</issue>
          ):
          <volume>21</volume>
          {
          <fpage>43</fpage>
          ,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <given-names>R.</given-names>
            <surname>Calinescu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Ghezzi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Kwiatkowska</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R.</given-names>
            <surname>Mirandola</surname>
          </string-name>
          .
          <article-title>Self-adaptive software needs quantitative veri cation at runtime</article-title>
          .
          <source>Commun. ACM</source>
          ,
          <volume>55</volume>
          (
          <issue>9</issue>
          ):
          <volume>69</volume>
          {
          <fpage>77</fpage>
          ,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Stephen</surname>
            <given-names>Gilmore</given-names>
          </string-name>
          , Laszlo Gonczy, Nora Koch, Philip Mayer, Mirco Tribastone, and Daniel Varro.
          <article-title>Non-functional properties in the model-driven development of service-oriented systems</article-title>
          .
          <source>Softw. &amp; Syst. Modeling</source>
          ,
          <volume>10</volume>
          (
          <issue>3</issue>
          ):
          <volume>287</volume>
          {
          <fpage>311</fpage>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Ste</surname>
            en Becker, Heiko Koziolek, and
            <given-names>Ralf</given-names>
          </string-name>
          <string-name>
            <surname>Reussner</surname>
          </string-name>
          .
          <article-title>The Palladio component model for model-driven performance prediction</article-title>
          .
          <source>J. of Systems &amp; Softw.</source>
          ,
          <volume>82</volume>
          (
          <issue>1</issue>
          ):3 {
          <fpage>22</fpage>
          ,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Radu</surname>
            <given-names>Calinescu</given-names>
          </string-name>
          , Lars Grunske, Marta Kwiatkowska,
          <article-title>Ra aela Mirandola, and Giordano Tamburrelli. Dynamic QoS management and optimisation in service-based systems</article-title>
          .
          <source>IEEE Trans. Software Eng.</source>
          ,
          <volume>37</volume>
          (
          <issue>3</issue>
          ):
          <volume>387</volume>
          {
          <fpage>409</fpage>
          , May
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <given-names>M.</given-names>
            <surname>Tribastone</surname>
          </string-name>
          and
          <string-name>
            <given-names>S.</given-names>
            <surname>Gilmore</surname>
          </string-name>
          .
          <article-title>Automatic translation of UML sequence diagrams into PEPA models</article-title>
          .
          <source>In QEST 2008</source>
          , pages
          <fpage>205</fpage>
          {
          <fpage>214</fpage>
          ,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16. I. Epifani,
          <string-name>
            <given-names>C.</given-names>
            <surname>Ghezzi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Mirandola</surname>
          </string-name>
          , and
          <string-name>
            <given-names>G.</given-names>
            <surname>Tamburrelli</surname>
          </string-name>
          .
          <article-title>Model evolution by runtime adaptation</article-title>
          .
          <source>In ICSE 2009</source>
          , pages
          <fpage>111</fpage>
          {
          <fpage>121</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17. Object Management Group.
          <source>UML Pro le for Modeling Quality of Service and Fault Tolerance Characteristics and Mechanisms v1.1</source>
          ,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          18. Object Management Group.
          <article-title>UML Pro le for Modelling and Analysis of Real-Time and Embedded Systems (MARTE</article-title>
          )
          <year>v1</year>
          .
          <fpage>1</fpage>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>