<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>T. Hovorushchenko);</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Method for determining the security level of software⋆</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Tetiana</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Hovorushchenko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Voichur</string-name>
          <email>voichury@khmnu.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dmytro</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Medzatyi</string-name>
          <email>medza@ukr.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Artem</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Boyarchuk</string-name>
          <email>a.boyarchuk@taltech.ee</email>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alina Hnatchuk</string-name>
          <email>alinahnatchuk@ukr.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Khmelnytskyi National University</institution>
          ,
          <addr-line>Institutska str., 11, Khmelnytskyi, 29016</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Prague University of Economics and Business</institution>
          ,
          <addr-line>Winstona Churchilla str., 1938/4, Prague, 13067</addr-line>
          ,
          <country country="CZ">Czech Republic</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Tallinna Tehhnikaülikool</institution>
          ,
          <addr-line>Ehitajate tee, 5, Tallinn, 12616</addr-line>
          ,
          <country country="EE">Estonia</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>1857</year>
      </pub-date>
      <volume>000</volume>
      <fpage>0</fpage>
      <lpage>0003</lpage>
      <abstract>
        <p>Currently, there is an increase in the complexity of software, an increase in the responsibility assigned to it, and tightening requirements for software quality and security on the part of users, so predicting and determining the level of software security (as one of the characteristics of software quality) based on requirements using AI components is an urgent task, the solution of which is the purpose of this study. The analyzed AI-based methods and tools for predicting the level of software security and quality have great potential, but they do not establish the dependence of software security on quality attributes, do not form a predicted numerical value of software security based on attributes, and do not provide a prediction of the level of software security based on the obtained numerical value. The developed method for determining the security level of software establishes the dependence of software security on quality attributes, forms a predicted numerical value of software security based on attributes, provides a prediction of the level of software security based on the obtained numerical value, and provides a comparison of software requirements specifications by predicted level of security of developed software (of course, if the bugs are not made at the next lifecycle stages) and a possibility of rejection form unsuccessful specifications.</p>
      </abstract>
      <kwd-group>
        <kwd>Software security</kwd>
        <kwd>software security level</kwd>
        <kwd>initial level of security</kwd>
        <kwd>medium level of security</kwd>
        <kwd>sufficient level of security</kwd>
        <kwd>high level of security</kwd>
        <kwd>software quality</kwd>
        <kwd>software quality characteristics</kwd>
        <kwd>software security subcharacteristics</kwd>
        <kwd>software quality attributes 1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Now various business and industrial enterprises use software. The need of software is emerged
through the existing technological breakthroughs. The need of software increase for a wide
range of enterprises and economy sectors. “Statista” shows that software spending is currently
estimated at USD 491 billion, and the size of the USA software market is USD 285 billion [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ].
      </p>
      <p>
        Under such circumstances, when software engineering is crucial and software becomes more
complex, creating high-quality software is the most crucial undertaking for the software
domain's expansion and high reputation, as software quality is a growing concern for users.
The stakeholder satisfaction is associated with software quality assurance, because if the
consumer is pleased with the product, then this product is quality. According to standard,
software quality shows the degree to which the software meets the user’s needs in the different
conditions [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
      </p>
      <p>
        Nowadays, software has become one of the most expensive industries, and any bottlenecks
in the development process can lead to undesirable consequences. Multiple software faults and
failures still occur uninvited due to errors and defects remaining in the software. For every
invested $1 billion, software companies lose an average of $97 million due to poor software
quality [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. The price of low-quality software in 2020 amounted to 260 billion US dollars
(compared to 177.5 billion US dollars in 2018) [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. In general, about 10-20% of all software
projects are not completed, 40-60% of projects are completed 150-200% late, 40-55% of projects
require additional costs, 25-40% of projects do not fully realize their objectives, 20% of projects
do not take into account all changes on the part of the customer [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <p>Because it is impossible to find and fix all software defects, it is important that the negative
effect of defects will be detected, resolved, and minimized as early as possible. The early finding
and fixing the software defects provide minimizing the damage caused by software defects,
because the amount of time and money increases when there are defects in the software.
Although software defects monitoring and repair are also both costly and time-consuming to
complete procedures.</p>
      <p>So, the software quality assurance is usually results in more money and time. The software
developers generally consider software quality assurance as an additional lengthy and
documentation-intensive operation with little value to the client, however, they are wrong,
because clients are interested in the high quality of the product they will have to work with, on
which their health and even life may depend.</p>
      <p>
        Now we have not only increasing scale of software, but the rapid development of artificial
intelligence also. Artificial intelligence is the best tool for analysis of the vast amount of data
and saving of human effort, in particular for significantly reducing the time and increasing the
efficiency in the development of complicated software. The world quality report estimates that
64% of the companies implement artificial intelligence for the software quality assurance
processes [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>So, now software quality is the key aspect and priority of functioning every software
organization. Software quality prediction is performed at various stages of software projects.
As the size of software is constantly growing, software quality prediction and assessment is
becoming more complex. The accurate software quality prediction and assessment will help
software developers and software engineers to develop the high-quality software. Early (based
on the specification of software requirements) prediction of software quality is used to select
certain preventive measures to reduce the number of software failures and malfunctions during
its operation. High-quality requirements engineering leads to an increase in software quality
and security and reduces the risk of software project failure (exceeding development time,
exceeding development cost, lack of planned functions).</p>
      <p>
        According to the ISO 25010:2011 standard [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], software security is one of the characteristics
of software quality and, like other characteristics, is determined on the basis of certain quality
attributes from the ISO 25023:2016 standard [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. Measurement of such attributes is mainly
performed for the finished source code, but all these attributes, along with their values, should
be specified in the software requirements specification so that developers are obliged to ensure
the presence and value of each attribute in their software for its further verification and
validation. Thus, based on the values of the attributes contained in the requirements, it is
realistic to predict the level of software security.
      </p>
      <p>
        The ontology of software security as a software quality characteristic based on the ISO 25010
standard is shown in Fig. 1 [
        <xref ref-type="bibr" rid="ref10 ref9">9, 10</xref>
        ].
      </p>
      <p>
        Fig. 2 [
        <xref ref-type="bibr" rid="ref10 ref9">9, 10</xref>
        ] shows a weighted ontology of software security as a software quality
characteristic based on the ISO 25010 standard (an ontology in which all attributes have certain
weighting factors). The weighting factors for software quality attributes were determined
according to the method for estimating factor weights proposed in [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
      </p>
      <p>Thus, at present, there is an increase in the complexity of software, an increase in the
responsibility assigned to it, and tightening requirements for software quality and security on
the part of users, so predicting and determining the level of software security (as one of the
characteristics of software quality) based on requirements using AI components is an urgent
task, the solution of which will be the purpose of this study.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Survey of Research</title>
      <p>Let's consider known AI-based methods and tools for predicting the level of software
security and quality.</p>
      <p>
        Paper [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] proposes the software structure and function protection using recurrent
neural networks with good protection effect, that can be applied to information misuse,
information anomaly and security response.
      </p>
      <p>
        Paper [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] proposes the deep learning-based method for vulnerability detection, that
can learn and automatically generate the vulnerability pattern, and the graph neural
network-based method for slice-level vulnerability detection and interpretation. These
methods normalize the source code, extract slices to reduce the interference of redundant
information, and the vulnerability slices are fed into the vulnerability interpreter to obtain
the concrete lines of vulnerability code. These methods correctly detect 59 real
vulnerabilities in the four open-source software.
      </p>
      <p>
        Authors of [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] develop the methodology for analyzing the software security and
detecting security incidents, the deep learning-based and artificial immune-based model for
security incidents identification, the artificial immune-based and convolutional neural
network-based method for optimization and classification of security incidents, and the
software package for detecting the software security incidents.
      </p>
      <p>
        Paper [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] propose the various machine learning models for predicting the software
faults, the performance of which depends on quality of set of data, on data issues (data
dimensionality, class overlapping, class imbalance, missing data) and can be enhanced by
enhancing the dataset quality, including data quality, data pre-processing, data modeling,
data performance. etc.
      </p>
      <p>
        The authors of [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] investigates the prediction for software efficiency and quality
analysis, for evaluation of each software component efficiency parameters and for analysis
of basic aspects before the software design stage using enhanced feed-forward neural
network machine learning classification with CatBoost.
      </p>
      <p>Paper [17] discuss some models, methods, tools and standards of software quality and
quality assurance by using machine learning-based approaches for forecasting,
optimization, features identifying and enhancing the effectiveness of software defects
prediction.</p>
      <p>The authors of [18] develop the optimized machine learning-based model for software
fault prediction with the purpose of the software quality improving. The software important
features are selected with ant colony optimization technique, after that the selected features
are fed to support vector machine as its inputs.</p>
      <p>The goal of study [19] is the prediction of the software quality with higher accuracy than
previous methods and tools. The authors of this study prove that machine learning
algorithms with data pre-processing and feature extraction on datasets with the software
metrics provide more accurate results in the software quality prediction.</p>
      <p>Paper [20] research the impact of software domain and software quality attributes in
software quality prediction by deep learning methods with using different datasets. The
value of this research is in raising the identifying the quality attributes in requirements
preparation and help requirements engineers understand what requirements' issues to
focus.</p>
      <p>Authors of [21] analyze the relationship between the improvement of software
requirements and the software quality. Analysis shows that software quality depends on
the measures of metrics from ISO/IEC 25010, IS\IEC 25023 standards. The study
empirically shows that the improvement of the requirements leads to the improvement of
the software quality.</p>
      <p>Authors of [22] develop the software defect prediction model and software
maintainability prediction model, which based on the decision tree as a more efficient
classifier. In addition, authors develop the framework on the basis of the set of guidelines
for improving the software quality.</p>
      <p>Authors of [23] use the generalized regression neural network with the improved cuckoo
search algorithm for mapping the nonlinear relationship between software metrics and
software quality characteristics, and propose the GRNN-based software quality prediction
model for improving the accuracy of the software defects prediction.</p>
      <p>Paper [24] proposes the framework of the single-layer radial basis function network
with thin-plate spline RBF (as its activation function) for software quality prediction. The
proposed network was verified for five unknown software samples and was demonstrated
that the predicted quality is very close to the actual software quality.</p>
      <p>Authors of [25] develop the seven-ensemble machine learning model for software defect
prediction based on the Cat boost. The obtained results prove that the proposed Cat boost
model provides the high performance for all the three defects datasets though decreasing
the overfitting and reducing the training time.</p>
      <p>Paper [26] empirically demonstrates performance of defects prediction by ten ensemble
predictors. It used 15 software projects from PROMISE repository and results of
experiments demonstrate that ensemble predictors improve the performance of defects
detection.</p>
      <p>Authors of [27, 28] use the firefly optimization methodology and propose the objective
function for prediction of the software quality with superior results on MATLAB with actual
data.</p>
      <p>The analyzed AI-based methods and tools for predicting the level of software security
and quality have great potential, but they do not establish the dependence of software
security on quality attributes, do not form a predicted numerical value of software security
based on attributes, and do not provide a prediction of the level of software security based
on the obtained numerical value.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Method for Determining the Security Level of Software</title>
      <p>
        From Figs. 1, 2, it can be seen that software security (as a characteristic of software quality)
depends on 5 subcharacteristics (Confidentiality, Integrity, Non-Repudiation, Accountability,
Authenticity), each of which depends on certain quality attributes. Thus, according to ISO 25010
[
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] and ISO 25023 [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ], software security (as a characteristic of software quality) depends on 23
quality attributes, but on 15 different quality attributes.
      </p>
      <p>For determining the level of software security based on quality attributes from software
requirements, we should first calculate the predicted numerical value of software security based
on the values of the 15 attributes defined in Figs. 1, 2, taking into account their
interdependencies, which is a difficult formalized task. According to the Hecht-Nielsen
theorem, to establish and take into account the interdependencies between the values of quality
attributes from software requirements and the value of software security (as a characteristic of
software quality), let's use the artificial neural network (ANN) of the "multilayer perceptron"
type, which will receive as inputs the values of 15 quality attributes on which software security
depends (Figs. 1, 2) and, after their approximation, will determine the predicted numerical value
of software security in the interval [0; 1].</p>
      <p>The described concept of determining the software security based on quality attributes from
software requirements is based on the concept of predicting the software quality characteristics
based on quality attributes using ANN, which was developed by the authors in [29] and is
shown in Fig. 3.</p>
      <p>The ANN is trained in such a way that, based on the values of the relevant attributes, it
generates a predicted numerical value of software security pnvss in the interval [0;1], where the
value "0" means the worst level of software security, and the value "1" means the best level of
software security as a characteristic of software quality. However, it is difficult for both the
customer and even the developer to correctly interpret the obtained numerical value of software
security, and therefore it is difficult to correctly assess the level of software security based on
the obtained from ANN value.</p>
      <p>Therefore, in order to simplify unambiguous interpretation of the predicted numerical value
of software security, it is first necessary to determine the thresholds by which the conclusion
about the level of software security (as a quality characteristic) will be generated.</p>
      <p>For establishing such thresholds, we analyzed 230 available specifications of software
requirements to find the values of quality attributes on which software security depends, for
which ANN determined the predicted numerical value of software security, as well as 230
corresponding finished programs written according to these requirements, for which the
security level (one of four – initial, medium, sufficient, high) was determined during
certification. The specifications of software requirements and finished programs were provided
for analysis by software companies in Khmelnytskyi (Ukraine) as part of scientific cooperation
with the Department of Computer Engineering and Information Systems of Khmelnytskyi
National University.</p>
      <p>As a result of the conducted analysis, let's form the threshold values of the predicted
numerical value of software security pnvss for determining the level of software security (as a
characteristic of software quality):</p>
      <sec id="sec-3-1">
        <title>1. initial level of security – pnvss  [0; 0,22).</title>
        <p>medium level of security – pnvss  [0,22; 0,49).</p>
      </sec>
      <sec id="sec-3-2">
        <title>3. sufficient level of security – pnvss  [0,49; 0,89).</title>
      </sec>
      <sec id="sec-3-3">
        <title>4. high level of security – pnvss  [0,89; 1].</title>
        <p>Taking into account the concept of determining the software security based on quality
attributes from software requirements and the formed thresholds of the predicted numerical
value of software security pnvss for determining the level of software security, the method for
determining the security level of software consists of the following steps:
1. preprocessing of software requirements – representation of the requirements
specification in a form suitable for analysis for finding the values of quality attributes
2. analysis of software requirements to find the values of 15 quality attributes on which
software security depends (Fig. 3)
3. preparation of the found values of 15 quality attributes, on which software security
depends, for submitting them to the ANN input – at this stage, the ANN input vectors
are prepared taking into account the fact that security subcharacteristics depend on 23
attributes, including 15 different attributes (Fig. 1, 2), and the ANN inputs are formed as
5 sets (for 5 software security subcharacteristics) of 1, 2, 8, 10, and 2 attributes according
to the ontologies presented in Figs. 1, 2
4. processing of attribute values by an artificial neural network
5. analysis of the result of the ANN – the predicted numerical value of the software
security pnvss
6. forming a conclusion about the predicted level of software security based on the
following rules:
 if pnvss  [0; 0,22), then the software is predicted to have an initial level of security;
 if pnvss  [0,22; 0,49), then the software is predicted to have a medium level of
security;
 if pnvss  [0,49; 0,89), then the software is predicted to have a sufficient level of
security;
 if pnvss  [0,89; 1], then the software is predicted to have a high level of security.</p>
        <p>The ANN was implemented in the Matlab. The gensim(net) operator generated a
visualization of the developed ANN in the Simulink (Fig. 4-8).</p>
        <p>For training the resulting ANN, a training sample of 4750 vectors and a testing sample of 867
vectors were formed based on the analysis of existing software requirements and corresponding
offthe-shelf programs with a known level of security provided by software companies from
Khmelnytskyi (Ukraine). For calculating the required training sample size for the ANN to be trained
h  g 20  23
with an error of about 0,1, we use the formula: N    4600 , where g is the number
e0 0,1
of input neurons of the ANN (g=23); h is the number of neurons of the hidden layers of the ANN
(h=12+8=20), e0 is the permissible training error (e0=0,1). Thus, training sample vectors are enough
to train an ANN to recognize possible situations with a given accuracy. The process of training and
testing the ANN is shown in Figs. 9, 10, where the blue curve is the ANN training schedule, the
green curve is the ANN testing schedule, and the black line is the ANN training goal, which, as can
be seen from Figs. 9, 10 was achieved.</p>
        <p>For selecting the optimal ANN training algorithm, we analyzed the ANN's training process
by the different algorithms using different quality criteria. The results of the analysis are shown
in Table 1.</p>
        <p>The conducted analysis has shown that the worst ANN's training result is obtained by the
training quality criterion mae in combination with all training algorithms, and the best result is
obtained by the training quality criterion msereg. The analysis of the training results using
msereg training quality criterion makes it possible to determine that the most accurate result is
obtained by the training algorithms traincgb, trainlm, trainscg. The analysis of the ANN training
and testing results proved that the network trained with the specified accuracy.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Results &amp; Discussion</title>
      <p>Let's consider 10 specifications of software requirements prepared by 10 different software
companies in Khmelnytskyi (Ukraine) as a result of the stage of collecting and analyzing
requirements for the same software. Each of the specifications went through a preprocessing
stage, during which it was prepared for analysis to find the values of quality attributes. Next,
each specification was analyzed to find the values of 15 quality attributes on which software
security depends. After that, the input vectors of the ANN were formed and transferred to the
artificial neural network for processing.</p>
      <p>Based on the processing of the attributes' values, the ANN provided the following values of
the predicted numerical value of software security pnvss for the 10 analyzed specifications (Fig.
11): pnvss1 = 0,12; pnvss2 = 0,93; pnvss3 = 0,45; pnvss4 = 0,67; pnvss5 = 0,34; pnvss6 = 0,09; pnvss7 =
0,78; pnvss8 = 0,98; pnvss9 = 0,41; pnvss10 = 0,53.</p>
      <p>Next, we analyzed the obtained predicted numerical values of software security pnvss1-pnvss10,
which resulted in the conclusions about the predicted level of software security for the 10
analyzed specifications: 1) since pnvss1  [0; 0,22), the software that will be developed according
to specification 1 is predicted to have an initial level of security; 2) since pnvss2  [0,89; 1], the
software that will be developed according to specification 2 is predicted to have a high level of
security; 3) since pnvss3  [0,22; 0,49), the software that will be developed according to
specification 3 is predicted to have a medium level of security; 4) since pnvss4  [0,49; 0,89), the
software that will be developed according to specification 4 is predicted to have a sufficient level
of security; 5) since pnvss5  [0,22; 0,49), the software that will be developed according to
specification 5 is predicted to have a medium level of security; 6) since pnvss6  [0; 0,22), the
software that will be developed according to specification 6 is predicted to have an initial level of
security; 7) since pnvss7  [0,49; 0,89), the software that will be developed according to
specification 7 is predicted to have a sufficient level of security; 8) since pnvss8  [0,89; 1], the
software that will be developed according to specification 8 will predictably have a high level of
security; 9) since pnvss9  [0,22; 0,49), the software that will be developed according to
specification 9 is predicted to have a medium level of security; 10) since pnvss10  [0,49; 0,89), the
software that will be developed according to specification 10 is predicted to have a sufficient level
of security.</p>
      <p>Thus, the software developed according to specifications 2 and 8 is predicted to have a high
level of security (of course, if the bugs are not made at the next lifecycle stages), so the customer
is recommended to order software development from software companies that have prepared
requirements' specifications 2 and 8.</p>
      <p>Taking into account the results of the experimental studies, it was concluded that the
developed method for determining the security level of software establishes the dependence of
software security on quality attributes, forms a predicted numerical value of software security
based on attributes, provides a prediction of the level of software security based on the obtained
numerical value, and provides a comparison of software requirements specifications by
predicted level of security of developed software (of course, if the bugs are not made at the next
lifecycle stages) and a possibility of rejection form unsuccessful specifications.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusions</title>
      <p>Currently, there is an increase in the complexity of software, an increase in the responsibility
assigned to it, and tightening requirements for software quality and security on the part of
users, so predicting and determining the level of software security (as one of the characteristics
of software quality) based on requirements using AI components is an urgent task, the solution
of which is the purpose of this study.</p>
      <p>The analyzed AI-based methods and tools for predicting the level of software security and
quality have great potential, but they do not establish the dependence of software security on
quality attributes, do not form a predicted numerical value of software security based on
attributes, and do not provide a prediction of the level of software security based on the obtained
numerical value.</p>
      <p>The developed method for determining the security level of software establishes the
dependence of software security on quality attributes, forms a predicted numerical value of
software security based on attributes, provides a prediction of the level of software security
based on the obtained numerical value, and provides a comparison of software requirements
specifications by predicted level of security of developed software (of course, if the bugs are not
made at the next lifecycle stages) and a possibility of rejection form unsuccessful specifications.
[17] J. Mona, R. Al-Sagheer, S. Alghazali. Software Quality Assurance Models and Application
to Defect Prediction Techniques. International Journal of Intelligent Systems and
Applications in Engineering 11 1 (2023) 169 – 178.
[18] M. Shafiq, F. H. Alghamedy, N. Jamal, T. Kamal, Y. I. Daradkeh, M. Shabaz, Scientific
programming using optimized machine learning techniques for software fault prediction
to improve software quality. IET Software (2023). doi:10.1049/sfw2.12091.
[19] A. A. Ceran, Y. Ar, Ö. Ö. Tanrıöver, S. Seyrek Ceran, Prediction of software quality with
Machine Learning-Based ensemble methods, Mater. Today (2022).
doi:10.1016/j.matpr.2022.11.229.
[20] G. Airlangga, A. Liu. Investigating Software Domain Impact in Requirements Quality
Attributes Prediction. Journal of Information Science and Engineering 38 2 (2022) 295 –
316. doi: 10.6688/JISE.202203_38(2).0002.
[21] L. Canchari, P. Angeleri, A. Dávila, Requirements Validation in the Information System
Software Development Lifecycle: A Software Quality in Use Evaluation, Program. Comput.</p>
      <p>Software 49 8 (2023) 610–624. doi:10.1134/s0361768823080054.
[22] B. Desai, R. K. Sungkur, Software Quality Prediction Using Machine Learning, Int. J. Softw.</p>
      <p>Innov. 10 1 (2022) 1–35. doi:10.4018/ijsi.297997.
[23] L. Liu, P. Han, Application of improved cuckoo algorithm to optimize generalized
regression neural network in software quality prediction, in: Proceedings of R. Tiwari,
International Conference on Neural Networks, Information, and Communication
Engineering NNICE 2022, SPIE, 2022. doi:10.1117/12.2639204.
[24] Ritu, O. Sangwan. Radial Basis Function Network Based Intelligent Scheme for Software
Quality Prediction. Communications in Computer and Information Science 1572 (2022) 327
– 340. doi: 10.1007/978-3-031-05767-0_26.
[25] Y. K. Saheed, O. Longe, U. A. Baba, S. Rakshit, N. R. Vajjhala, An Ensemble Learning
Approach for Software Defect Prediction in Developing Quality Software Product.
Communications in Computer and Information Science (2021) 317–326.
doi:10.1007/978-3030-81462-5_29.
[26] F. Yucalar, A. Ozcift, E. Borandag, D. Kilinc, Multiple-classifiers in software quality
engineering: Combining predictors to improve software fault prediction ability. Eng. Sci.</p>
      <p>Technol. Int. J. 23 4 (2020) 938–950. doi:10.1016/j.jestch.2019.10.005.
[27] D. Pankwar, G. L. Saini, P. Agarwal, P. Singh, Firefly Optimization Technique for Software
Quality Prediction. Soft Computing: Theories and Applications (2022) 263–273.
doi:10.1007/978-981-19-0707-4_25.
[28] B. Iegorov, Y. Kravchyk, S. Rybalko, I. Ivashkiv, A. Chub. The Methodical Approach of the
Substantiation of the Evaluation Indicators System of the Agro-Industrial Complex
Development. Universal Journal of Agricultural Research 9 5 (2021) 191 - 199. doi:
10.13189/ujar.2021.090506.
[29] T. Hovorushchenko, D. Medzatyi, Y. Voichur, M. Lebiga, Method for forecasting the level
of software quality based on quality attributes, J. Intell. &amp; Fuzzy Syst. (2022) 1–15.
doi:10.3233/jifs-222394.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Software</surname>
          </string-name>
          ,
          <year>2022</year>
          . URL: https://www.statista.com/markets/418/topic/484/software/.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>M.</given-names>
            <surname>Chornobuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Dubrovin</surname>
          </string-name>
          , L. Deineha,
          <source>Cybersecurity: Research on Methods for Detecting DDOS Attacks, Comput. Syst. Inf. Technol. № 4</source>
          (
          <year>2023</year>
          )
          <fpage>6</fpage>
          -
          <lpage>9</lpage>
          . doi:
          <volume>10</volume>
          .31891/csit-2023
          <source>-4-1.</source>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3] ISO/IEC 25010:
          <year>2011</year>
          .
          <article-title>Systems and software engineering. Systems and software Quality Requirements and Evaluation (SQuaRE)</article-title>
          .
          <source>System and software quality models</source>
          .
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>Success</given-names>
            <surname>Rates Rise</surname>
          </string-name>
          ,
          <year>2017</year>
          . URL: https://www.pmi.org/-/media/pmi/documents/ public/pdf/learning/thought-leadership/pulse/pulse
          <article-title>-of-the-profession-2017</article-title>
          .pdf.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <source>[5] The Cost of Poor Software Quality in the US: A 2020 Report</source>
          ,
          <year>2020</year>
          . URL: https://www.itcisq.org/pdf/CPSQ-2020
          <source>-report.pdf.</source>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <article-title>[6] Pulse of the Profession 2023: Power Skills</article-title>
          ,
          <source>Redefining Project Success</source>
          ,
          <year>2023</year>
          . URL: https://www.pmi.org/-/media/pmi/documents/public/pdf/learning/thoughtleadership/pmi
          <article-title>-pulse-of-the-</article-title>
          <string-name>
            <surname>profession-</surname>
          </string-name>
          2023
          <source>-report.pdf?</source>
          v=
          <fpage>7933da8f</fpage>
          -304b
          <string-name>
            <surname>-</surname>
          </string-name>
          4fe3
          <string-name>
            <surname>-</surname>
          </string-name>
          a655
          <source>- 78dace54174a&amp;rev=427949fcdb684485a020cc72ea219f32.</source>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>S.</given-names>
            <surname>Ramchand</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Shaikh</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Alam</surname>
          </string-name>
          ,
          <source>Role of Artificial Intelligence in Software Quality Assurance. Lecture Notes in Networks and Systems</source>
          (
          <year>2021</year>
          )
          <fpage>125</fpage>
          -
          <lpage>136</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>030</fpage>
          - 82196-8_
          <fpage>10</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <source>[8] ISO</source>
          <volume>25023</volume>
          :
          <year>2016</year>
          .
          <article-title>Systems and software engineering. Systems and software Quality Requirements and Evaluation (SQuaRE). Measurement of system and software product quality</article-title>
          .
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>T.</given-names>
            <surname>Hovorushchenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Pomorova</surname>
          </string-name>
          ,
          <article-title>Methodology of evaluating the sufficiency of information on quality in the software requirements specifications</article-title>
          ,
          <source>in: Proceedings of 2018 IEEE 9th International Conference on Dependable Systems, Services and Technologies DESSERT2018</source>
          , Kyiv,
          <year>2018</year>
          , pp.
          <fpage>385</fpage>
          -
          <lpage>389</lpage>
          . doi:
          <volume>10</volume>
          .1109/dessert.
          <year>2018</year>
          .
          <volume>8409161</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>T.</given-names>
            <surname>Hovorushchenko</surname>
          </string-name>
          ,
          <article-title>Information Technology for Assurance of Veracity of Quality Information in the Software Requirements Specification</article-title>
          .
          <source>Advances in Intelligent Systems and Computing</source>
          <volume>689</volume>
          (
          <year>2018</year>
          )
          <fpage>166</fpage>
          -
          <lpage>185</lpage>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>319</fpage>
          -70581-1_
          <fpage>12</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>E.</given-names>
            <surname>Zaitseva</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Hovorushchenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Pavlova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Voichur</surname>
          </string-name>
          ,
          <article-title>Identifying the Mutual Correlations and Evaluating the Weights of Factors and Consequences of Mobile Application Insecurity</article-title>
          ,
          <source>Systems 11 5</source>
          (
          <year>2023</year>
          )
          <article-title>242</article-title>
          . doi:
          <volume>10</volume>
          .3390/systems11050242.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Mi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Gao</surname>
          </string-name>
          ,
          <source>Information Sharing Security Protection System Based on Artificial Intelligence, in: Proceedings ofv2022 IEEE 2nd International Conference on Mobile Networks and Wireless Communications</source>
          , IEEE,
          <year>2022</year>
          . doi:
          <volume>10</volume>
          .1109/icmnwc56175.
          <year>2022</year>
          .
          <volume>10031986</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>Y.-T.</given-names>
            <surname>Hu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.-Y.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <surname>Y.-M. Wu</surname>
            ,
            <given-names>D.-Q.</given-names>
          </string-name>
          <string-name>
            <surname>Zou</surname>
            ,
            <given-names>W.-K.</given-names>
          </string-name>
          <string-name>
            <surname>Li</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          <string-name>
            <surname>Jin</surname>
          </string-name>
          .
          <article-title>A Slice-level vulnerability detection and interpretation method based on graph neural network</article-title>
          .
          <source>Journal of Software 34</source>
          <volume>6</volume>
          (
          <year>2023</year>
          )
          <fpage>2204</fpage>
          -
          <lpage>2221</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>A.</given-names>
            <surname>Tanwar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Sundaresan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Ganesan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Ravi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Karthik</surname>
          </string-name>
          ,
          <article-title>Proximal Instance Aggregator networks for explainable security vulnerability detection</article-title>
          ,
          <source>Future Gener. Comput. Syst</source>
          . (
          <year>2022</year>
          ). doi:
          <volume>10</volume>
          .1016/j.future.
          <year>2022</year>
          .
          <volume>04</volume>
          .008.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>K.</given-names>
            <surname>Bhandari</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Kumar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. L.</given-names>
            <surname>Sangal</surname>
          </string-name>
          ,
          <article-title>Data quality issues in software fault prediction: a systematic literature review</article-title>
          ,
          <source>Artif. Intell. Rev</source>
          . (
          <year>2022</year>
          ).
          <source>doi:10.1007/s10462-022-10371-6.</source>
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>D.</given-names>
            <surname>Sudharson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. S.</given-names>
            <surname>Kailas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Vignesh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Senthilnathan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Poornima</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Vijay</surname>
          </string-name>
          ,
          <article-title>Software Quality Prediction by CatBoostFeed-Forward Neural Network in Software Engineering. System Reliability and Security (</article-title>
          <year>2023</year>
          )
          <fpage>207</fpage>
          -
          <lpage>218</lpage>
          . doi:
          <volume>10</volume>
          .1201/
          <fpage>9781032624983</fpage>
          -
          <lpage>11</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>