<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Scenario-Based Elicitation, Specification, and Comprehension of Transient Software Behavior</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Sebastian Frank</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alireza Hakamian</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Samuel Beck</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Christoph Zorn</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>André van Hoorn</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>University of Hamburg.</institution>
          <addr-line>Hamburg</addr-line>
          ,
          <country country="DE">Germany</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2021</year>
      </pub-date>
      <fpage>9</fpage>
      <lpage>10</lpage>
      <abstract>
        <p>Modern, microservice-based software systems are subject to frequent change while operating in production, leading to so-called transient behavior. Changes can arise from outside, e.g., workload peaks and changing user behavior, or inside the system, e.g., autoscaling and deployment of new (versions of) services. The satisfaction of a software system's users can be heavily afected if the system is not resilient to such changes. Therefore, it is crucial to specify resilience requirements and comprehend the system's transient behavior. However, the changes causing transient behavior often happen unexpectedly, making such requirements hard to elicit. Since transient behavior can be complex and dificult to anticipate, it is also challenging for software architects to create precise and quantifiable specifications.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Objective</title>
    </sec>
    <sec id="sec-2">
      <title>Method</title>
      <p>Our vision in the DiSpel project is to develop an interactive approach for continuous
elicitation, specification, and refinement of resilience requirements at runtime in the domain of
microservice-based software systems. As part of this vision, we aim to support stakeholders
in eliciting and specifying precise and quantifiable resilience requirements by developing new
(interactive) techniques and adopting established techniques from other domains, e.g., risk
analysis, visualization, and human-computer interaction.</p>
      <p>
        In our work, we use scenarios as described by the Architecture Tradeof Analysis Method
(ATAM) [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] as the foundation for specification, since they represent both essential parts of
a resilience requirement: the incidents and the expected response. We aim to interactively
transform the elicitation-friendly scenarios into more formal representations, e.g., Probabilistic
Computation Tree Logic [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], in order to disambiguate them and make them quantifiable.
      </p>
      <p>
        We use system traces to automatically extract architectural information and hazards as starting
points for the elicitation process. Additionally, we combine visualizations of the architecture
and transient behavior with assistance by chatbots. For the visualization and specification of
the expected response, we rely on resilience curves — our recent works are based on Bruneau’s
resilience triangle [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] as a simplification.
      </p>
    </sec>
    <sec id="sec-3">
      <title>Results</title>
      <p>
        We have achieved the following complementary intermediate results towards our overall vision:
• Resirio [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] — a tool that is able to import execution traces and conducts a
CHAZOPSbased [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] hazard analysis on the extracted architectural model. The results are presented
in a graph-based architecture visualization intended to help users in interactive elicitation
of resilience scenarios. In a conversation with a chatbot, the user can then specify
the resilience scenario. We conducted a user study with participants from industry
and academia to evaluate Resirio’s usability, efectiveness, and support. The evaluation
shows that the developed prototype gives novice requirements engineers a foundation
for fast requirements elicitation and that Resirio complements traditional requirements
engineering approaches.
• TransVis [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] — a tool focused on the specification of expected responses and
comprehension of transient behavior. TransVis presents a graph-based visualization of the system’s
services that indicates potential violations. For each service, the violations and
measurements can be visually investigated and compared against simple specifications based
on Bruneau’s resilience triangle model. An integrated chatbot assists the user in her
tasks, e.g., adding, deleting, and showing specifications. A user study revealed that the
developed visualizations are efective for specifying and exploring transient behavior.
      </p>
      <p>
        However, the chatbot was rarely utilized by the participants.
• Currently, we are also developing concepts and editors for the interactive transformation
of ATAM-based scenarios into more formal representations. While still under
development, early versions of some of the planned prototypes are already available. This step
is intended to extend the requirement elicitation workshop, which we presented in a
previous work [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
    </sec>
    <sec id="sec-4">
      <title>Conclusion</title>
      <p>While the evaluations of Resirio and TransVis showed that they can support users in the
elicitation and specification of resilience requirements as well as comprehension of transient
behavior, they also revealed some limitations. The chatbots were not well accepted by the
participants — except for quick replies — and only simple scenarios can be specified. Therefore,
we aim to enhance and extend our concepts to support the specification of more sophisticated
scenarios.
In our talk, we will give an overview of the vision and current activities in the DiSpel project for
elicitation and specification of resilience requirements. We present preliminary results, i.e., the
concepts, prototypes, evaluation results, and lessons learned regarding Resirio and TransVis.
Furthermore, we provide an insight into the currently developed editors.</p>
    </sec>
    <sec id="sec-5">
      <title>Acknowledgement References</title>
      <p>This research is funded by the Baden-Württemberg Stiftung (Orcas project) and the German
Federal Ministry of Education and Research (Software Campus 2.0 — Microproject: DiSpel).</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>R.</given-names>
            <surname>Kazman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Klein</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Barbacci</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Longstaf</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Lipson</surname>
          </string-name>
          ,
          <string-name>
            <surname>J. Carriere,</surname>
          </string-name>
          <article-title>The architecture tradeof analysis method</article-title>
          ,
          <source>in: Proc. 4th IEEE Int. Conf. on Engineering of Complex Computer Systems (ICECCS)</source>
          ,
          <year>1998</year>
          , pp.
          <fpage>68</fpage>
          -
          <lpage>78</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>H.</given-names>
            <surname>Hansson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Jonsson</surname>
          </string-name>
          ,
          <article-title>A logic for reasoning about time and reliability</article-title>
          ,
          <source>Formal aspects of computing 6</source>
          (
          <year>1994</year>
          )
          <fpage>512</fpage>
          -
          <lpage>535</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>M.</given-names>
            <surname>Bruneau</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. E.</given-names>
            <surname>Chang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. T.</given-names>
            <surname>Eguchi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. C.</given-names>
            <surname>Lee</surname>
          </string-name>
          ,
          <string-name>
            <surname>T. D. O'Rourke</surname>
            ,
            <given-names>A. M.</given-names>
          </string-name>
          <string-name>
            <surname>Reinhorn</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Shinozuka</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          <string-name>
            <surname>Tierney</surname>
            ,
            <given-names>W. A.</given-names>
          </string-name>
          <string-name>
            <surname>Wallace</surname>
            ,
            <given-names>D. Von</given-names>
          </string-name>
          <string-name>
            <surname>Winterfeldt</surname>
          </string-name>
          ,
          <article-title>A framework to quantitatively assess and enhance the seismic resilience of communities</article-title>
          ,
          <source>Earthquake spectra 19</source>
          (
          <year>2003</year>
          )
          <fpage>733</fpage>
          -
          <lpage>752</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>C.</given-names>
            <surname>Zorn</surname>
          </string-name>
          ,
          <article-title>Interactive Elicitation of Resilience Scenarios in Microservice Architectures, Master's thesis</article-title>
          , University of Stuttgart, Germany,
          <year>2021</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>J.</given-names>
            <surname>Earthy</surname>
          </string-name>
          ,
          <article-title>Hazard and operability studies as an approach to software safety assessment</article-title>
          ,
          <source>in: IEE Computing and Control Division Colloquium on Hazard Analysis</source>
          ,
          <year>1992</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>S.</given-names>
            <surname>Beck</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Frank</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. A.</given-names>
            <surname>Hakamian</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Merino</surname>
          </string-name>
          ,
          <string-name>
            <surname>A. van Hoorn</surname>
          </string-name>
          ,
          <article-title>TransVis: Using visualizations and chatbots for supporting transient behavior in microservice systems</article-title>
          ,
          <source>in: 2021 Working Conference on Software Visualization (VISSOFT)</source>
          , IEEE,
          <year>2021</year>
          , pp.
          <fpage>65</fpage>
          -
          <lpage>75</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>S.</given-names>
            <surname>Frank</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Hakamian</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Wagner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Kesim</surname>
          </string-name>
          , J. von
          <string-name>
            <surname>Kistowski</surname>
            ,
            <given-names>A. van Hoorn</given-names>
          </string-name>
          ,
          <article-title>Scenario-based resilience evaluation and improvement of microservice architectures: An experience report</article-title>
          ,
          <source>in: 5th International Workshop on Formal Approaches for Advanced Computing Systems (FAACS@ECSA)</source>
          ,
          <year>2021</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>