Latest
Call for Papers: Vol. 42 closes 30 JuneNew: Quantum Security Summit registration openAxiom Standard 7042-2024 now ratifiedGrant cycle 2025 — $4.2M committedFellows election voting opens 15 JulyCall for Papers: Vol. 42 closes 30 JuneNew: Quantum Security Summit registration openAxiom Standard 7042-2024 now ratifiedGrant cycle 2025 — $4.2M committedFellows election voting opens 15 July
Digital Library

Research Archive

Search across 2.4 million peer-reviewed documents from journals, conferences, and standards.

Showing 2 of 2,418,902 results

Journal Article Subscription Software Architecture

Evolutionary Architecture Governance: Managing Technical Debt, Architectural Fitness Functions, and Incremental Modernization in Long-Lived Enterprise Systems

Enterprise software systems routinely operate for decades beyond their initial design lifetime, accumulating technical debt that progressively impedes feature delivery, increases operational risk, and raises maintenance costs. Architectural modernization -- the structured evolution of such systems toward contemporary architectural patterns -- is one of the highest-stakes and least-understood challenges in software engineering practice. This paper presents a longitudinal study of architectural modernization programs at six large enterprises, tracking architecture evolution decisions, fitness function definition and measurement, and technical debt quantification over a 3-year observation period. Drawing on 88 interviews and quarterly architecture review artifact analysis, we develop a grounded theory of Evolutionary Architecture Governance (EAG), comprising three core practices: Continuous Fitness Function Monitoring (automated measurement of architectural properties such as coupling metrics, cyclomatic complexity, and deployment independence), Technical Debt Heat Mapping (priority-weighted visualization of debt concentration across system components), and Strangler Fig-Guided Incremental Modernization (structured extraction of bounded functionality from monolithic cores into independently deployable units). Organizations implementing all three EAG practices demonstrate 61% higher architecture conformance rates and 44% lower severity-1 incident rates attributable to architectural violations compared to organizations relying on periodic architecture review cycles. We provide an EAG implementation toolkit and a validated architectural fitness function library spanning 24 properties.

Seun Bello, Anna Magnusson, Shuji Watanabe, Catarina Rodrigues· Nov 2022· 287 citations
Journal Article Open Access Cybersecurity

Supply Chain Security in DevOps: Taxonomy, Risk Assessment, and Automated Mitigation Strategies for Software Dependency Vulnerabilities

High-profile software supply chain attacks — most notably the SolarWinds SUNBURST incident and the Log4Shell vulnerability — have exposed critical security gaps in DevOps pipelines that rely on third-party and open-source dependencies. This paper provides a comprehensive treatment of software supply chain security within the context of DevOps, presenting a threat taxonomy, a quantitative risk assessment methodology, and a suite of automated mitigation strategies. We analyze 1,240 software supply chain incidents reported between 2018 and 2022, categorizing attack vectors across six dimensions: dependency confusion, typosquatting, compromised maintainer accounts, malicious commit injection, build pipeline compromise, and artifact tampering. We introduce the Supply Chain Risk Score (SCRS), which aggregates dependency provenance, maintainer reputation, patch velocity, and transitive exposure into a single risk signal consumable by CI/CD gates. We evaluate the SCRS against a holdout dataset of 180 known malicious packages, achieving 87.4% detection precision at 92.1% recall. We further describe an SBOM-integrated DevSecOps reference architecture implementing SLSA Level 3 attestation and demonstrate its deployment in a Fortune 500 organization. This work provides both theoretical grounding and concrete engineering guidance for addressing supply chain threats in high-velocity delivery environments.

Ngozi Eze-Williams, Maximilian Bauer, Sora Kim, Abdul-Rahman Hassan· Oct 2022· 537 citations