Score
Designs, implements, and composes middleware components and frameworks that mediate communication, provide interception and enforcement points, and expose extensibility hooks and adapters for existing stores and services. Builds integration layers and connectors for target platforms, validates middleware behavior in realistic deployments, and engineers enforcement and control mechanisms to maintain interoperability and policy guarantees.
To address the challenges of complex security control configuration, difficult policy enforcement, and delayed response in networked systems, this paper proposes a Security Capability Model (SCM). The SCM establishes, for the first time, a computable abstract framework integrating information and data models, formally specifying rule semantics, policy parsing mechanisms, and data representations for filtering- and channel-protection–based controls. Leveraging UML/SysML modeling, Model-Driven Engineering (MDE), and a multi-granularity security control description language, the approach enables automated policy refinement, cross-heterogeneous-device (e.g., firewalls, encrypted gateways) configuration generation, and event-driven response. Experimental evaluation demonstrates a threefold improvement in policy deployment timeliness and a 40% increase in configuration accuracy, thereby filling a critical gap in the formal foundations for automated security policy enforcement.
Lack of portable Layer-3 (L3) network policy enforcement mechanisms across heterogeneous infrastructures hinders data-plane traffic security and cross-environment policy consistency. Method: We propose a novel paradigm that deeply integrates L3 network policies into the service mesh data plane, building an IP-overlay network atop Kubernetes/Istio. Policy enforcement points (PEPs) perform routing and key-based authorization for access control, while service mesh proxies uniformly enforce policies—eliminating dependence on underlying network capabilities. Contribution: This work presents the first infrastructure-agnostic, portable L3 policy enforcement mechanism. It enables unified L3–L7 policy specification and end-to-end governance. Our prototype introduces less than 1 ms latency overhead while matching the expressiveness of Kubernetes native NetworkPolicy. Experimental evaluation validates consistent, cross-cloud and hybrid-environment policy enforcement feasibility.
This work addresses the challenge of efficiently and accurately translating high-level security intents into deployable device-level policies in complex heterogeneous networks, where topological reachability and device capabilities often lead to misconfigurations and delayed responses. To overcome these limitations, the authors propose an end-to-end automated framework that uniquely integrates network topology, device capabilities, and real-time cyber threat intelligence (CTI). By leveraging formal modeling, policy compilation, and constraint solving, the approach automatically refines abstract security intents into concrete, network-compliant filtering rules. Experimental validation in real-world environments demonstrates the system’s ability to correctly generate both packet-filtering and web-filtering policies, confirming its practicality, correctness, and dynamic adaptability to emerging threats.
This study addresses the challenges posed by the proliferation, complexity, and expanding scope of regulatory requirements in software engineering, which hinder their systematic integration into development processes. To tackle this issue, the paper proposes a viewpoint-centered, artifact-based approach to regulatory requirements engineering. The approach innovatively integrates viewpoint analysis with artifact modeling to develop the AM4RRE (Artifact Modeling for Regulatory Requirements Engineering) framework, which facilitates cross-functional collaboration and ensures consistency in compliance-driven design. Preliminary validation demonstrates that AM4RRE effectively bridges the gap between organizational regulatory processes and software development practices, enabling a shift from ad hoc compliance responses toward systematic integration. This foundational work paves the way for further empirical investigation into scalable and sustainable regulatory compliance in software engineering.
In software design, paradigm-implied semantic expectations—such as data abstraction consistency and feedback-control closed-loop behavior—are often left implicit, leading to design deviations and verification challenges. To address this, we introduce the concept of *design obligations*: explicit, logically formalizable, and verifiable specifications that codify such implicit constraints inherent to design paradigms. Leveraging formal modeling and paradigm semantics analysis, we establish two obligation frameworks—one for data-abstraction-based systems and another for feedback-driven adaptive systems—precisely capturing their core semantic requirements. We demonstrate that common design flaws stem from obligation violations and show how these obligations enable rigorous compliance verification and pedagogical application. This work bridges the semantic gap between design intent and implementation, providing both theoretical foundations and a methodological framework for paradigm-driven design assurance.
Current harness designs for large language model agents lack a formal foundation, hindering guarantees of compositional correctness, property preservation, and systematic cross-framework comparison. This work introduces the first formal theory of harnesses, modeling them as categorical triples (G, Know, Φ) that integrate coalgebraic state representations, operator composition, and compilation functors. The framework incorporates structural replay and integrity gating mechanisms to ensure certificate-preserving behavior. Building on this theory, we implement a configuration compiler supporting Swarms, DeerFlow, Ralph, Scion, and LangGraph, which preserves three classes of structural certificates. End-to-end experiments demonstrate that the proposed quality-driven upgrade pathway is agnostic to underlying model parameters.
This work addresses the challenge of reliably conveying intent, requirements, and constraints in human–AI–tool collaborative software development by proposing a specification-centric Bosque API (BAPI) ecosystem. The system introduces a highly expressive specification language that, for the first time, enables cross-language interoperability, automated test generation, formal verification, and execution sandboxing across the entire API lifecycle—from requirement definition and implementation to invocation and validation. By providing end-to-end specification guarantees, BAPI significantly enhances system correctness, security, and the efficiency of human–AI collaboration, offering a novel infrastructure for software development in the era of AI agents.
This work addresses the high latency, resource overhead, and challenges in enforcing Layer-7 security policies inherent in traditional sidecar-based service meshes. The authors propose Meshlib, a sidecar-free service mesh architecture that embeds a lightweight library directly into application processes to enforce Layer-7 security policies in-process, while leveraging Cilium’s eBPF data plane for transport-layer identity authentication and routing. This design preserves full policy semantics while enabling low-latency communication. Meshlib is the first sidecar-less solution to support seamless interoperability with unmodified services and allow incremental deployment. Evaluated on the TrainTicket benchmark (37 services, 126 policies), Meshlib demonstrates significantly lower end-to-end latency than Istio, Linkerd, and native Cilium, with comparable resource overhead.
This study addresses the unclear practical adoption of agentic software engineering methodological frameworks within large-scale code repositories. To investigate this, we conduct the first empirical examination across 116,000 GitHub repositories, integrating mining software repositories techniques, stratified sampling, quantitative artifact detection, and qualitative coding analysis to systematically evaluate the prevalence, co-occurrence, and rule characteristics of eight coordination mechanisms. Our findings reveal an overall presence rate of at least one mechanism at 21.7%, rising to 65.3% among highly starred projects. However, fully integrated systems remain rare, as current practices are predominantly confined to the isolated application of individual mechanisms. This work provides foundational empirical evidence regarding how multi-agent coordination paradigms are currently operationalized in open-source software development, highlighting a significant gap between theoretical agentic frameworks and their holistic real-world implementation.
This work addresses the challenge of aligning real-world data processing practices in distributed systems with the purpose limitation principle under the General Data Protection Regulation (GDPR). To this end, it introduces the first formal framework that integrates multiparty session types with GDPR compliance. The approach models data processing purposes as structured interaction protocols among participants, employing a process calculus enriched with private data semantics to capture system behavior. A novel type system is developed to enforce subject reduction and purpose fidelity, ensuring that runtime execution strictly adheres to declared purposes. Formal verification guarantees alignment between stated purposes and actual behavior. The framework’s effectiveness is demonstrated through its application to a healthcare system case study, offering an engineering-oriented theoretical foundation for privacy-by-design.