<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta />
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>from unhealthy state; and Self-prote tion is the prote ting itself from atta ks
editor tool for this language is provided to reate, view, edit and store SelfMML
Management Modelling Language (SelfMML) for the modelling of self-management
Software Systems intended to provide servi es usually should be operative at
Obtaining su h apabilities in a servi e-oriented system is not a trivial work
performan e and the e ien y; Self- onguration is the automati onguring of
management[1℄.
providing visual representations related to the spe i ation of them. A visual
and require a ostly engineering eort. This work ould be fa ilitated if the
developer had spe ialised tools whi h support the denition of those
apabiliand as ading errors, with anti ipatory or rea tive a tions [1℄.
ties. To support this laim, this paper studies the impa t of applying the
Selftomati looking and nding of opportunities to tune the system to improve the
operations in a faster and more a urate way. This apability is alled
selfaging themselves without human intervention, sin e a system ould done su h
The Self-Management Modelling Language (SelfMML) is a language whi h
The hosen ase study for applying SelfMML is based on a well known s
ements. Therefore, it is desired that su h systems have the apability of
manspe i ations. This tool an be downloaded at http://selfmml.sf.net.
apability requirements in a servi e-oriented system.
peak performan e 24/7 to meet the end-user needs and the business
requireintends to assist in the engineering of self-management apability requirements,
nario in servi e-oriented omputing: the re-binding. Spe i ally, the re-binding
self- onguration, self-healing and self-prote tion[1℄. Self-optimisation is the
authe system following high level poli ies; Self-healing is the automati re overing
The self-management denition is detailed by its four aspe ts: self-optimisation,
related to the automati re-binding features in servi es whi h illustrates
Abstra t. This paper introdu es a language alled Self-Management
and analyses the language usage in servi e-oriented systems.
management apability requirements. The paper presents a ase study
Modelling Language (SelfMML) whi h supports the modelling of
selfthat is, self-management apability requirements. This language is made from
The Self-Management Modelling Language (SelfMML) is a language to be used
from the Kernel pa kage for the denition of the elements.
in the modelling of self-management apabilities that a system should have,
The language is des ribed below (see gures 1, 2 and 3).
UML 2.2 Superstru ture, on retely, opies all elements from the Use Cases and
A tivities pa kages and extends them with new elements. Also imports elements
The language has a meta-model that denes its abstra t syntax. Further
information about the meta-model an be found in http://selfmml.sf.net.</p>
    </sec>
    <sec id="sec-2">
      <title>2 The Self-Management Modelling Language (SelfMML)</title>
      <p>Fig. 1. SelfMML (1)
self-management requirement spe i ation. A self-management apability
repreSe tion 3 presents a ase study used as illustrative example of the language
It is important to remark that we fo us on the modelling aspe ts, not in
this language. Se tion 5 introdu es the on lusions.
the requirement engineering pro ess. Hen e, we intend to provide a modelling
system a ording to the spe ied expe ted behaviour, analogous to the
realiin some way during the hosen development pro ess. During the realisation of
these, the engineer an identify elements and design the ar hite ture of the nal
to realise and verify self-management requirements modelled by SelfMML is not
engineering pro ess that uses this language. The SelfMML s ope is limited to the
This work is stru tured as follows. Se tion 2 des ribes the language SelfMML.
sation of use ases. The developer ould onsider some framework or referen e
language.
sents an expe ted behaviour from the system, whi h should be implemented
ar hite ture for self-management or just develop an ad-ho solution. A method
management requirement, but we do not provide assistan e for the requirement
language that permits a developer to ee tively apture and spe ify a
selfmanagement apability requirement that will be modelled using the proposed
apability requirement in an on-line blog system, whi h is onsidered as a
selfusage. Se tion 4 shows some related work that has been taken into a ount for
study in this work.
ities of systems to do management operation by themselves on themselves.
This element is provided for the representation of self-management apability
requirements in a system.
Self-Management Capability. Self-Management Capabilities are the
abil</p>
    </sec>
    <sec id="sec-3">
      <title>Failure. This element des ribes a failure that ould happen in the system.</title>
      <p>Misuse Case. This element des ribes a misuse of a system that an user
system shows when some failure has happened (failure modes in FMEA).
Failure Case. This element des ribes what is the wrong behaviour that a
does whi h an lead to a failure[5,6,7℄.
language provides elements to model possible problems in the system following
These elements are:
(see gure 2). Quality Goals an be onne ted to des ribe ontribution with the
is provided to des ribe what quality goals are in luded in a spe i quality level
Problems are the target of self-prote tion and self-healing apabilities. The
related to Quality Requirements and Use Cases, by the using of the relationships
The language lets developers model how self-management apabilities are
ontribute for quality goals and require for use ases. Also the in lude relationship
ontribute relationship too.
the philosophy from the Failure Modes and Ee t Analysis methods (FMEA)[4℄.
des ribes the hara teristi or fa tor related to the quality requirements, and
also has a satisfa tion property that des ribes how the quality goal is satised
what are a eptable values for the quality metri s related to the quality
su h as Obje t Constraint Language (OCL). Su h expressions ould des ribe
by the using of some expression in natural language or another language
requirement, following the IEEE 1062-1998 Standard re ommendations.
goals that the system should maintain.
a goal that the system should maintain. It has a hara teristi property that
Quality Level. This element represents a quality level whi h groups quality
Quality Goal. This element represents a quality requirement des ribed as
(see gure 1).
maintainability, portability, reliability, usability, availability, among others [2,3℄,
Goal and Quality Level elements for the representation of quality requirements
Self-Management Capabilities are usually related to quality requirements as
in a way that ontribute to the satisfa tion of them. The language has the Quality
Fig. 2. SelfMML (2)
as ading failures that they ould ause.
fun tionality des ribed in the se ond ones. Failures, misuse ases and atta ks
of the se ond ones. Failures an be onne ted to failure ases with the a tivate
ould also have the intention to omplete or update a ertain onguration
parations and hange events:
with the dea tivate relationship indi ating that the apability dea tivates the
A self-management apability, as a self-healing apability, an be onne ted
isolate relationship to indi ate that the system isolates su h failures to avoid the
wrong behaviour of the system.
relationship indi ating that the rst ones a tivate the wrong behaviour des ribed
the threaten relationship indi ating that the rst ones threaten the satisfa tion
management, a self-management apability ould have the intention to tune a
re overs the system from the failure. Also, it an be onne ted to a failure ase
to a failure with the re overFrom relationship indi ating that the apability
ne ted to problems (failures, misuse ase and atta ks) to indi ate that the
aLikelihood relationships respe tively. Also, as a self-prote tion apability, the
elements an be onne ted to atta ks with the defend relationship to indi ate
rameters following high level poli ies, in rea tion to hange events in the system
relationship indi ating that the rst ones ae t the normal operation of the
or in the environment. SelfMML provides two elements to model su h
onguan be onne ted to failures with the ause relationship indi ating that the rst
A ording to the self- onguration and self-optimising aspe t of the
selfA failure, a misuse ase or an atta k an be related to a quality goal with
pability takes anti ipatory a tions to avoid, redu e the onsequen e or redu e
in the se ond ones. Also failures an be onne ted to use ases with the ae t
that the system rea ts to su h atta ks; and an be related to failures with the
the likelihood of su h problems using the avoid, redu eConsequen e and redu
eA self-management apability, as a self-prote tion apability, an be
onones ause the se ond ones.
ertain onguration parameters to improve the performan e of the system, and</p>
    </sec>
    <sec id="sec-4">
      <title>Conguration . This element des ribe a onguration des ription.</title>
      <p>Change Event. This element des ribes a hange event in a system.</p>
    </sec>
    <sec id="sec-5">
      <title>Atta k. This element des ribes an atta k against the system.</title>
      <p>to a hange event with treat relationship indi ating that the apability treats
a self-management apability using a tivities diagrams (see gure 3). A
selfSelfMML provides a set of a tivity nodes to spe ify the abstra t pro ess of
toring, analysis, planning, and plan exe ution. In monitoring phase the
interesttry to tune, ompete or update the onguration. A apability ould be related
following relationships: tune, omplete and update, indi ating that the apability
management pro ess usually has a stru ture a ording to four phases[1℄:
moniin order to infer some needed knowledge; in the planning phase the obtained
the event.
ing information is gathered; in the analysis phase, the information is pro essed
A self-management apability ould be related to a onguration with the
the plan exe ution phase the sele ted or built plan is exe uted.
knowledge is used to de ide what plan exe utes or to build a new one; nally in</p>
    </sec>
    <sec id="sec-6">
      <title>In order to spe ify the plan exe ution a tivities the language provides the</title>
      <p>following elements (see gure 3):</p>
    </sec>
    <sec id="sec-7">
      <title>Plan Sele tion Guard Node. This element is to onstrain the exe ution</title>
      <p>opies all in oming tokens to all outgoing edges, but the ontinuity of su h
Plan Constru tion Node. This element des ribes a plan onstru tion a
Guard Node.
outgoing edges. The ontinuity of the token depends on the Plan Sele tion
the outgoing edges only if the OCL expression des ribed in the spe i ation
Plan Sele tion Pro ess Node. This element des ribes a sele tion whi h
is done by a more sophisti ated pro ess that annot be expressed by OCL. It
Plan Sele tion Node. This element is for the sele tion of plans using OCL
expression, it re eives tokens from the in oming edge and opy one for ea h
tokens depends on the evaluation of the guards on the outgoing edges. Then,
tivity.
property is evaluated to true.
a simple terms in guards an be used to des ribe what plan is sele ted.
of plans, it re eives tokens from the in oming edge and presents them to
the following (see gure 3):
The provided elements to model the sele tion or onstru tion of plans are</p>
    </sec>
    <sec id="sec-8">
      <title>Plan Step Exe ution Node. This element des ribes a step of a ertain</title>
      <p>plan to be exe uted.
it ontinually generates tokens after ea h monitoring y le. The method to
method.
any other kind or variant; the node does not imply the using of any parti ular
edge from the monitoring reports.
Analysis Node. This element des ribes the analysis a tivity to infer
knowlobtain information by monitoring ould be pulling, pushing, inter eption or
Monitoring Node. This element des ribes the monitoring a tivities and</p>
    </sec>
    <sec id="sec-9">
      <title>The elements for monitoring and analysis are the following (see gure 3):</title>
      <p>Fig. 3. SelfMML (3)
Fig. 4. Failures and Quality Goals diagram
plan to be
3 Case Study: The Servi e Re-binding
se ond requirement onstrains the reliability in a fault response likelihood value
the publishing servi e in a value that should be equal or greater than 98%. The
ity level for standard users. The rst requirement onstrains the availability of
the servi e: the used storage servi e be omes unavailable; and the used storage
only four of them. There are two failures that an ae t the normal operation of
ability and the reliability. Both requirements are in luded in an a eptable
qualequal or less than 0.05 (see gure 4).
and atta h to the post any kind of les. It will use an external storage servi e
ause other two: the unavailability and the unreliability of the publishing servi e
servi e gives too many fault responses, be oming unreliable. Both failures an
to store the atta hed les.
The studied system is a blog system su h as blogger. om. Publisher an submit
posts using a publishing servi e. This publishing servi e lets users write a post
Several problems an ae t the requirements fullment, this paper identied
This servi e is onstrained by two quality requirements related to the
availrespe tively, and an threaten the quality requirements satisfa tion des ribed
before (see gure 4).
the system answers with an unexpe ted error when the publisher is submitting a
Both failures in the publishing servi e a tivate two failure ases (see gure
Unavailable, please try later.
new post. The Publishing Servi e Unavailable des ribes that when the publisher
a esses to the servi e the system shows the message The Publishing Servi e is
4). The Frequent Error Responses Submitting Posts des ribes that randomly
Plan Exe ution Node. This element des ribes an undened
exe uted (useful when the plan is onstru ted).
thus the apability needs the lo ation of this registry as input. The Congure
gure 5). Therefore, the apability ontributes to the satisfa tion of both
qualing Servi e Unavailable and Publishing Servi e Be omes Unreliable failures (see
gure 6).
the self-healing aspe t of the apability (see gure 5).
in availability and reliability attributes, it redu es the likelihood of the
Publishavailable and Storage Servi e Be omes Unreliable failures. It also dea tivates the
servi es to the bla k list be ause it was dete ted by another system. The Manage
failure ases aused indire tly by the failures. These intentions are related to
The apability requires the development of some use ases in order to operate
ity requirements: the high availability and the high reliability of the servi e (see
bla k list at run-time. But even, the administrator ould need add problemati
servi es ould be healed and the administrator ould need remove it from the
properly (see gure 6). The alternative storage servi es are found in a Registry,
Sin e the apability sele ts the servi e whi h oers the highest quality level
Registry Lo ation use ase des ribes the fun tionality of onguring the lo ation
of the registry. The apability will manage a bla k list of servi es, but problemati
The apability will try to re over the system from the Storage Servi e
Unan alternative Storage Servi e, following a given sele tion riteria based on the
In order to treat these problems, there is a requirement: The system should
problemati servi es from the list given by the Registry. This apability should
by an administrator. In order to avoid the re-sele tion of a problemati servi e
related to the availability and the reliability. But, when the sele tion is not
The system should try to sele t the servi e that oers the highest quality level
be present in the provider software agents of the Publishing Servi e.
the system will manage a bla k list of them and will use the list to subtra t
have the apability of dete ting su h problems and automati ally re-bind to
quality levels oered by them. It assumes that exist a Registry that have a
highest reliability, or otherwise) the system should follow the poli y des ribed
lear (be ause exist an alternative with the highest availability but without the
full des ription of Storage Servi es that an be used by the Publishing Servi e.
Fig. 5. The Publishing Servi e Re-binding Capability treating problems diagram
Fig. 6. The Publishing Servi e Re-binding Capability onne ted to fun tional and
quality requirements diagram
itself to some heartbeat signal.
produ ed at run-time.
The Analysis Of the Needs to Rebind a tivity de ides if the rebinding is
Bla k List use ase des ribes this fun tionality. Also the apability requires the
Congure QoS Criteria for Sele tion use ase to let the administrator ongure
metri fault-response-likelihood of the Storage Servi e; and the latter monitors
a better de ision al ulating how the estimated period of time in unavailability
what QoS riteria the apability should take into a ount to sele t alternatives;
Storage Servi e Availability Monitoring ould monitor the using, but also ould
and Storage Servi e Availability Monitoring. The former monitors the number
This apability is detailed by a self-management pro ess model (gure 7, 8
and 9). There are two monitoring a tivities: Storage Servi e Faults Monitoring
too. These monitoring a tivities generate reports whi h are onsumed by the
the fun tionality of viewing, by the administrator, the re-binding logs that are
and also requires the View Re-binding Result Report use ase whi h des ribes
will be needed. However, the Storage Servi e ould have a noti ation system
lishing Servi e will de rease, and if the Storage Servi e be omes unavailable the
(see gure 7). The plan sele tion is made he king if there are available servi es
Analysis Of the Needs to Rebind. The Storage Servi e Faults Monitoring a tivity
needed or not. The de ision is made using the monitoring reports and the
qualthat inform to its lients of temporary unavailability for administration purpose.
the urrent operational status (available, unavailable) of the Storage Servi e
rebinding is not needed is when there is already a rebinding in exe ution.
an ae t the quality level of the Publishing Servi e. Another ase where the
ity requirements of the storage servi e. If the fault-response-likelihood metri
do the monitoring either dire tly asking to the Storage Servi e, or subs ribing
will monitor the using of the Storage Servi e in order to at h faults, and the
of faults in a period of time in order to update the urrent value of the quality
of the Storage Servi e is equal or greater than 0.05 the reliability of the
PubThen the analysis a tivity ould take into a ount su h informations to make
Publishing Servi e will get into failure. Therefore, in these ases the rebinding
If the rebinding is needed, then the pro ess get into a plan sele tion phase
ow is the plan sele tion guard node that ontains the OCL spe i ation whi h
The gure 8 shows the diagram of the part orresponding to the sele tion
of elements in the ow are the updating of the bla k list with the urrent
storpro ess will stop ompletely, even the monitoring a tivities.
from the rest of the system. The Final Node indi ates that the self-management
and exe ution of the plan when there are no andidates. The rst elements in the
age servi e, the unavailability noti ation and the unregistering to isolate itself
onstrains the opy of the token to the outgoing edge. In this ase, the
onstraint is: if the andidates list is empty then lets the token ontinue. The rest
Fig. 7. The Publishing Servi e Re-binding Pro ess (1) diagram
Fig. 8. The Publishing Servi e Re-binding Pro ess (2) diagram
of the publishing servi e, and do nothing, be ause there are no andidates; or
update the bla k list and rebind, be ause there is at less one andidate.
andidates or not. There are two plans: update the bla k list, blo k the using
to the outgoing edge. When there is at less one andidate in the list the token is
updates the bla k list and noties a temporary unavailability for administration
exe ution of the plan when there is at less one andidate. As before, the rst
elements in the ow is the plan sele tion guard that onstrains the opy of the token
The gure 9 shows the diagram of the part orresponding to the sele tion and
purpose. After that, sele ts one servi e a ording to the given sele tion riteria
and rebinds the publishing servi e to it. Finally, noties the availability. The
opy and the ow ontinue through the rest of plan step a tivities. The plan rst
Flow Final Node indi ates that the ow stop, but not the pro ess.
Fig. 9. The Publishing Servi e Re-binding Pro ess (3) diagram
4 Related Work</p>
    </sec>
    <sec id="sec-10">
      <title>The Risk Assessment part is to be used for risk assessment modelling, but</title>
      <p>among others. Our work will in lude fault toleran e, sin e the fault toleran e
servi e requirements but rather any kind of software quality requirements that
Finally, the Fault Toleran e Mitigation meta-model and Prole part is for
parts: an UML Prole and a Catalog for Quality of Servi e; an UML Prole for
stru tures that will enable a system to support faults. It in ludes the modelling
apability ould require. This dieren e allows the modelling of self-management
The Related Work fo us on the works whi h try to develop a language that an
One of them is the UML Prole for Modelling Quality of Servi e and Fault
ould be related to self-management.
a treatment of problems is not well des ribed by an use ase but rather by an
the modelling language of the treatment of risk by use ases and a tors. The
modelling fault toleran e me hanisms for the system. It is mainly for modelling
dedi ated entity, e.g. the ase study presented in this work, the rebinding ould
apabilities that ould not require any use ase. But also there are ases when
and the treatments as use ases too. The onne tion with QoS is the modelling
be used to model self-management aspe ts. There are some works that are more
quality of servi e modelling. SelfMML lets developers model not only quality of
se urity analysis[9℄. The interesting part for this work is the meta-model and
related to the topi of this paper.
also in luded treatment of risks. This part is based on the CORAS method for
system to do some management operation by itself and the use ases that su h a
of risks that ould ae t the QoS Level of the system. The treatment of risk is
Risk Assessment; an UML Prole for Fault Toleran e Mitigation.
not be well des ribed if only use ases are used.
threats are personied and modelled as a tors, the threat s enarios as use ases,
Toleran e Chara teristi s and Me hanisms Spe i ation [8℄. This one has three
of redundan y onguration, monitoring ollaborations, fault dete tion poli ies,
spe ied by use ases. SelfMML makes a dieren e between a apability of the
The QoS part is for modelling QoS requirements. This prole is limited to
that an be used in the modelling of self-management apabilities in servi
ethe language to model self-management requirements in servi e-oriented systems.
poli ies are used to make the sele tion ould be interesting to have. Also, the
The requirement required the spe i ation of some poli ies in order to make a
sele tion. A model of what poli y options the administrator has and how the
with SelfMML is an open issue for future work. We would also like to explore
a more ompleted language.
but the language at this moment did not provide any spe i way to do it.
this gap. We would like to study both issues as future works in order to develop
A method for realising and verifying self-management requirement spe ied
model to model transformation from self-management elements to design
elelo ation of the apability ould be inferred by the name of the apability, but it
This work has presented the Self-Management Modelling Language as a language
the ase study as a requirement in the system, fa ilitating the apturing and
the ase study, whi h would be interesting to model in servi e-oriented systems,
ar hite ture model. The integration of SelfMML with a language that an be used
to model servi e ar hite tures like Soa Modelling Language (SoaML), ould ll
spe i ation of it. However, there are other issues, that ould be identied in
This language has enabled the modelling of a self-management apability in
would be interesting to asso iate the apability to a spe i servi e in a servi e
oriented systems. Also a ase study has been presented to study the appli ation of
5 Con lusion
as soft-goal). Also the languages provide another on epts, whi h an help in
part of the work presented here.
ould be onsidered as part of autonomi omputing [3℄, spe ially when it is
e.g. misuse ase, mitigates, threat, or threatens. It was used to inspire
as goals. However, these languages la k ertain elements whi h an help in the
porting goal-oriented requirement engineering. Some of them are i* [10℄,
TROmaintenan e of health is not addressed by the language presented here, but will
an represent fun tional requirements and non-fun tional requirements (named
be onsidered in future works.
related to the spe i ation of self-management pro esses.
failures, their auses and their ee ts, the require relationship, and the elements
ships . Using these languages, self-management requirements an be modelled
requirement engineering works, su h as: a tor, task (or plan) and several
relationa meta-model, what makes that work more informal, but denes a graphi al
are provided by SelfMML, spe i ally, elements and relationships for modelling
language that suggest a on epts related to some aspe t of self-management,
related with self-prote tion and self-healing. The stru ture of systems for the
Finally, there are several works whi h present graphi al languages for
supPOS [11℄ and GRL[12℄. In these works requirements are identied as goals whi h
apturing, tra ing and spe i ation of these kind of requirements. Some of them
Another work omes from Ian Alexander [7℄. This work does not propose
ments to support more ompletely the engineering of self-management
apamapped to design elements related to agent approa hes.
bilities of a target system. Spe i ally, sin e agents are suitable to realise
selfmanagement apabilities [1,13℄, self-management elements seem suitable to be</p>
    </sec>
    <sec id="sec-11">
      <title>A knowledgements</title>
      <p>Referen es
omputing a means of a hieving
depend</p>
    </sec>
    <sec id="sec-12">
      <title>Comunidad de Madrid" with grant CCG07-UCM/TIC-2765, and the proje t</title>
      <p>This work has been developed with support of the program "Grupos
UCMogy.
TIN2005-08501-C03-01, funded by the Spanish Coun il for S ien e and Te
hnol</p>
    </sec>
  </body>
  <back>
    <ref-list />
  </back>
</article>