Open Access. Powered by Scholars. Published by Universities.®

Software Engineering Commons™

Open Access. Powered by Scholars. Published by Universities.®

Air Force Institute of Technology

Discipline
Keyword
Publication Year
Publication
Publication Type

Articles 1 - 30 of 124

Full-Text Articles in Software Engineering

Integrating Blockchain Technology Into The Software Development Life Cycle To Satisfy The Software Bill Of Materials Requirement For Government Software Systems, Walter T. Scott Ii Sep 2024

Integrating Blockchain Technology Into The Software Development Life Cycle To Satisfy The Software Bill Of Materials Requirement For Government Software Systems, Walter T. Scott Ii

Theses and Dissertations

This thesis explores the integration of Blockchain Technology (BT) into the Software Development Life Cycle (SDLC) to satisfy the Software Bill of Materials (SBOM) requirement for government software systems. This study begins by synthesizing a standard SDLC definition from various government and industry references, which may provide the foundation for future efforts to standardize software development practices across the government software development community. This study proceeds to define working definitions for the software supply chain (SSC) and software supply chain management (SCM) before introducing and detailing the SBOM requirement as well as providing an overview of prior research regarding SBOMs …


Exporting Sysml Designs To Simulink, Drew Q. Broadbent Jun 2024

Exporting Sysml Designs To Simulink, Drew Q. Broadbent

Theses and Dissertations

Various software systems have been developed to aid a systems engineer in evaluating system requirements, such as Dassault’s Magic System of Systems Architect (MSOSA) and MathWorks’ Simulink. Both software packages have different strengths; therefore, it is beneficial to export models from one software package to another. MSOSA provides a built-in tool that facilitates this transfer, built upon the Extension for Physical Interaction and Signal Flow Simulation (SysPhS) standard. However, the process is often unreliable and error prone and online documentation is largely lacking. This research used extensive trial and error to fill in the documentation gaps and create a method …


Deconstructing The Software Factory: A Practical Application Of Interorganizational Network Analysis, Zachary O. Ryan, Mark Reith, Clay Koschnick Oct 2023

Deconstructing The Software Factory: A Practical Application Of Interorganizational Network Analysis, Zachary O. Ryan, Mark Reith, Clay Koschnick

Faculty Publications

Over the past 5 years, the number of DoD software organizations that employ nontraditional organizational structures has increased. These organizations, commonly referred to as software factories, often employ the network-based organizational structures found within high-technology industries. This article details ways in which network analysis techniques can be used to create a big picture view of these nontraditional organizations. Drawing on methodologies employed by network researchers, the authors develop and present an interorganizational analysis process that highlights a program's social and economic structures. Following the case history approach, they demonstrate the applicability of this approach by analyzing an emergent DoD software …


The Characteristics Of Successful Military It Projects: A Cross-Country Empirical Study, Helene Berg, Jonathan D. Ritschel Jul 2023

The Characteristics Of Successful Military It Projects: A Cross-Country Empirical Study, Helene Berg, Jonathan D. Ritschel

Faculty Publications

In the armed forces, successful digitalization is crucial to ensure effective operations. Much of the existing literature on project factors during the planning and execution phases of public IT projects do not focus specifically on military sector projects. Therefore, the paper aims to provide empirical insights into the characteristics of successful military IT projects. Data from such projects in NATO countries and agencies were collected through interviews and project documents. The findings relating to the main variable of interest, “delivery of client benefit,” supported previous findings on IT project performance. Medium-sized projects performed better than small and large projects, and …


Safe And Reliable Software And The Formal Verification Of Prim's Algorithm In Spark, Brian S. Wheelhouse Mar 2023

Safe And Reliable Software And The Formal Verification Of Prim's Algorithm In Spark, Brian S. Wheelhouse

Theses and Dissertations

Despite evidence that formal verification helps produce highly reliable and secure code, formal methods, i.e., mathematically based tools and approaches for software and hardware verification, are not commonly used in software and hardware development. The limited emphasis on formal verification in software education and training suggests that many developers have never considered the benefits of formal verification. Despite the challenging nature of their mathematical roots, software verification tools have improved; making it easier than ever to verify software. SPARK, a programming language and a formal verification toolset, is of particular interest for the AFRL, and will be a primary focus …


Accelerating A Software Defined Satnav Receiver Using Multiple Parallel Processing Schemes, Logan Reich, Sanjeev Gunawardena, Michael Braasch Jan 2023

Accelerating A Software Defined Satnav Receiver Using Multiple Parallel Processing Schemes, Logan Reich, Sanjeev Gunawardena, Michael Braasch

Faculty Publications

Excerpt: Satnav SDRs present many benefits in terms of flexibility and configurability. However, due to the high bandwidth signals involved in satnav SDR processing, the software must be highly optimized for the host platform in order to achieve acceptable runtimes. Modules such as sample decoding, carrier replica generation, carrier wipeoff, and correlation are computationally intensive components that benefit from accelerations.


Active Attestation Of Embedded Systems, Mark M. Stephenson, Patrick A. Reber, Patrick J. Sweeney, Scott R. Graham Nov 2022

Active Attestation Of Embedded Systems, Mark M. Stephenson, Patrick A. Reber, Patrick J. Sweeney, Scott R. Graham

AFIT Patents

An active attestation apparatus verifies at runtime the integrity of untrusted machine code of an embedded system residing in a memory device while it is being run/used with while slowing the processing time less than other methods. The apparatus uses an integrated circuit chip containing a microcontroller and a reprogrammable logic device, such as a field programmable gate array (FPGA), to implement software attestation at runtime and in less time than is typically possible with comparable attestation approaches, while not requiring any halt of the processor in the microcontroller. The reprogrammable logic device includes functionality to load an encrypted version …


An Entity-Component System Based, Ieee Dis Interoperability Interface, Noah W. Scott Mar 2022

An Entity-Component System Based, Ieee Dis Interoperability Interface, Noah W. Scott

Theses and Dissertations

In practice, there are several different methods of organizing data within a given software to fulfil its function. The method known as the Entity-Component System (ECS) is a software architecture where data components define entities. These components are stored as organized lists which are operated upon by systems to inject the system's desired behavior. Data is sent across the networks to communicate between simulation nodes as Protocol Data Units (PDUs). When sending PDUs across a network protocol, each simulation represents a common understanding of the world at the desired level of detail. DIS-compliant simulations are commonly written using an Object-Oriented …


Formal Spark Verification Of Various Resampling Methods In Particle Filters, Osiris J. Terry Mar 2022

Formal Spark Verification Of Various Resampling Methods In Particle Filters, Osiris J. Terry

Theses and Dissertations

The software verification in this thesis concentrates on verifying a particle filter for use in tracking and estimation, a key application area for the Air Force. The development and verification process described in this thesis is a demonstration of the power, limitation, and compromises involved in applying automated software verification tools to critical embedded software applications.


An Investigation Of Data Storage In Entity-Component Systems, Bailey V. Compton Mar 2022

An Investigation Of Data Storage In Entity-Component Systems, Bailey V. Compton

Theses and Dissertations

Entity-Component Systems (ECS) have grown vastly in application since their introduction more than 20 years ago. Providing the ability to efficiently manage data and optimize program execution, ECSs, as well as the wider field of data-oriented design, have attained popularity in the realms of modeling, simulation, and gaming. This manuscript aims to elucidate and document the storage frameworks commonly found in ECSs, as well as suggesting conceptual connections between ECSs and relational databases. This formal documentation of the in-memory storage formats of entity-component systems affords the United States Air Force, the Department of Defense, and the software engineering community a …


Investigating Collaboration In Software Reverse Engineering, Allison M. Wong Mar 2022

Investigating Collaboration In Software Reverse Engineering, Allison M. Wong

Theses and Dissertations

Reverse engineering (RE) is a rigorous process of exploration and analysis to support software design recovery and exploit development. The process is often conducted in teams to divide the workload and take full advantage of engineers' individual expertise and strengths. Collaboration in RE requires versatile and reliable tools that can match the environment's unpredictable and fluid nature. While studies on collaborative software development have indicated common best practices and implementations, similar standards have not been explored in reverse engineering. This research conducts semi-structured interviews with reverse engineering experts to understand their needs and solutions while working in a team. The …


Formal Verification For High Assurance Software: A Case Study Using The Spark Auto-Active Verification Toolset, Ryan M. Baity Mar 2021

Formal Verification For High Assurance Software: A Case Study Using The Spark Auto-Active Verification Toolset, Ryan M. Baity

Theses and Dissertations

Software is an increasingly integral and sophisticated part of safety- and mission-critical systems. Poorly written software can lead to information leakage, undetected cyber breaches, and even human injury in cases where the software directly interfaces with components of a physical system. These systems may range from power facilities to remotely piloted aircraft. Software bugs and vulnerabilities can lead to severe economic hardships and loss of life in these domains. As fast as software spreads to automate many facets of our lives, it also grows in complexity. The complexity of software systems combined with the nature of the critical domains dependent …


Two Published Flight Dynamics Models Rewritten In Rust And Structures As An Ecs, Chad A. Willis Mar 2021

Two Published Flight Dynamics Models Rewritten In Rust And Structures As An Ecs, Chad A. Willis

Theses and Dissertations

This thesis explores using the Entity-Component System (ECS) architecture to implement a Flight Dynamics Model (FDM) by re-implementing two published versions in the Rust programming language using the Specs Parallel ECS (SPECS) [1] for military simulation advancement. One FDM is based on Grant Palmers published textbook titled Physics for Game Programmers [2], and another is based on David Bourgs textbook titled Physics for Game Developers [3]. Furthermore, this thesis uses these models within an interactive flight simulator.The ECS architecture is based on the Data-Oriented Design (DOD) paradigm, where Components contain the data and the Systems implement the behavior which transforms …


Agile Software Development: Creating A Cost Of Delay Framework For Air Force Software Factories, J. Goljan, Jonathan D. Ritschel, Scott Drylie, Edward D. White Jan 2021

Agile Software Development: Creating A Cost Of Delay Framework For Air Force Software Factories, J. Goljan, Jonathan D. Ritschel, Scott Drylie, Edward D. White

Faculty Publications

The Air Force software development environment is experiencing a paradigm shift. The 2019 Defense Innovation Board concluded that speed and cycle time must become the most important software metrics if the US military is to maintain its advantage over adversaries.1 This article proposes utilizing a cost-o­f-d­elay (CoD) framework to prioritize projects toward optimizing readiness. Cost-­of-d­elay is defined as the economic impact resulting from a delaying product delivery or, said another way, opportunity cost. In principle, CoD assesses the negative impacts resulting from changes to the priority of a project.


Analytic Provenance For Software Reverse Engineers, Wayne C. Henry Sep 2020

Analytic Provenance For Software Reverse Engineers, Wayne C. Henry

Theses and Dissertations

Reverse engineering is a time-consuming process essential to software-security tasks such as malware analysis and vulnerability discovery. During the process, an engineer will follow multiple leads to determine how the software functions. The combination of time and possible explanations makes it difficult for the engineers to maintain a context of their findings within the overall task. Analytic provenance tools have demonstrated value in similarly complex fields that require open-ended exploration and hypothesis vetting. However, they have not been explored in the reverse engineering domain. This dissertation presents SensorRE, the first analytic provenance tool designed to support software reverse engineers. A …


Sliver: Simulation-Based Logic Bomb Identification/Verification For Unmanned Aerial Vehicles, Jake M. Magness Mar 2020

Sliver: Simulation-Based Logic Bomb Identification/Verification For Unmanned Aerial Vehicles, Jake M. Magness

Theses and Dissertations

This research introduces SLIVer, a Simulation-based Logic Bomb Identification/Verification methodology, for finding logic bombs hidden within Unmanned Aerial Vehicle (UAV) autopilot code without having access to the device source code. Effectiveness is demonstrated by executing a series of test missions within a high-fidelity software-in-the-loop (SITL) simulator. In the event that a logic bomb is not detected, this methodology defines safe operating areas for UAVs to ensure to a high degree of confidence the UAV operates normally on the defined flight plan. SLIVer uses preplanned flight paths as the baseline input space, greatly reducing the input space that must be searched …


Metrics To Meet Security & Privacy Requirements With Agile Software Development Methods In A Regulated Environment, Torrey J. Wagner, Thomas C. Ford Feb 2020

Metrics To Meet Security & Privacy Requirements With Agile Software Development Methods In A Regulated Environment, Torrey J. Wagner, Thomas C. Ford

Faculty Publications

This work examines metrics that can be used to measure the ability of agile software development methods to meet security and privacy requirements of communications applications. Many implementations of communication protocols, including those in vehicular networks, occur within regulated environments where agile development methods are traditionally discouraged. We propose a framework and metrics to measure adherence to security, quality and software effectiveness regulations if developers desire the cost and schedule benefits of agile methods. After providing an overview of specific challenges that a regulated environment imposes on communications software development, we proceed to examine the 12 agile principles and how …


Ion Software-Defined Radio Metadata Standard Final Report, Sanjeev Gunawardena, Alexander Rugamer, Muhammad Subhan Hameed, Markel Arizabaleta, Thomas Pany, Javier Arribas Sep 2019

Ion Software-Defined Radio Metadata Standard Final Report, Sanjeev Gunawardena, Alexander Rugamer, Muhammad Subhan Hameed, Markel Arizabaleta, Thomas Pany, Javier Arribas

Faculty Publications

The ION GNSS SDR Metadata Standard describes the formatting and other essential PNT-related parameters of sampled data streams and files. This allows processors to seamlessly consume such data without the need to input these parameters manually. The technical development phase of the initial version of the standard has now been deemed complete and is currently undergoing the last remaining procedural steps towards adoption as a formal standard by the Institute of Navigation. This paper reports on the activities of the working group since September 2018 and summarizes the final products of the standard. It also reports on examples of early …


The Effect Of Modeling Simultaneous Events On Simulation Results, John M. Carboni Mar 2019

The Effect Of Modeling Simultaneous Events On Simulation Results, John M. Carboni

Theses and Dissertations

This thesis explores the method that governs the prioritizing process for simultaneous events in relation to simulation results for discrete-event simulations. Specifically, it contrasts typical discrete-event simulation (DES) execution algorithms with how events are selected and ordered by the discrete-event system specification (DEVS) formalism. The motivation for this research stems from a desire to understand how the selection of events affects simulation output (i.e., response). As a particular use case, we briefly investigate the processing of simultaneous events by the Advanced Framework for Simulation, Integration and Modeling (AFSIM), a military discrete-event combat modeling and simulation package. To facilitate the building …


Near Real-Time Rf-Dna Fingerprinting For Zigbee Devices Using Software Defined Radios, Frankie A. Cruz Mar 2019

Near Real-Time Rf-Dna Fingerprinting For Zigbee Devices Using Software Defined Radios, Frankie A. Cruz

Theses and Dissertations

Low-Rate Wireless Personal Area Network(s) (LR-WPAN) usage has increased as more consumers embrace Internet of Things (IoT) devices. ZigBee Physical Layer (PHY) is based on the Institute of Electrical and Electronics Engineers (IEEE) 802.15.4 specification designed to provide a low-cost, low-power, and low-complexity solution for Wireless Sensor Network(s) (WSN). The standard’s extended battery life and reliability makes ZigBee WSN a popular choice for home automation, transportation, traffic management, Industrial Control Systems (ICS), and cyber-physical systems. As robust and versatile as the standard is, ZigBee remains vulnerable to a myriad of common network attacks. Previous research involving Radio Frequency-Distinct Native Attribute …


Instantaneous Bandwidth Expansion Using Software Defined Radios, Nicholas D. Everett Mar 2019

Instantaneous Bandwidth Expansion Using Software Defined Radios, Nicholas D. Everett

Theses and Dissertations

The Stimulated Unintended Radiated Emissions (SURE) process has been proven capable of classifying a device (e.g. a loaded antenna) as either operational or defective. Currently, the SURE process utilizes a specialized noise radar which is bulky, expensive and not easily supported. With current technology advancements, Software Defined Radios (SDRs) have become more compact, more readily available and significantly cheaper. The research here examines whether multiple SDRs can be integrated to replace the current specialized ultra-wideband noise radar used with the SURE process. The research specifically targets whether or not multiple SDR sub-band collections can be combined to form a wider …


Developmental Test And Requirements Best Practices Of Successful Information Systems Efforts Using Agile Methods, Jeremy D. Kramer, Torrey J. Wagner Jan 2019

Developmental Test And Requirements Best Practices Of Successful Information Systems Efforts Using Agile Methods, Jeremy D. Kramer, Torrey J. Wagner

Faculty Publications

This article provides insights into the current state of developmental testing (DT) and requirements management in Department of Defense information systems employing Agile development. The authors describe the study methodology and provide an overview of Agile development and testing. Insights are described for requirements, detailed planning, test execution, and reporting. This work articulates best practices related to DT and requirements management strategies for programs employing modernized Software Development Life Cycle practices.


Progressive Network Deployment, Performance, And Control With Software-Defined Networking, Daniel J. Casey Mar 2018

Progressive Network Deployment, Performance, And Control With Software-Defined Networking, Daniel J. Casey

Theses and Dissertations

The inflexible nature of traditional computer networks has led to tightly-integrated systems that are inherently difficult to manage and secure. New designs move low-level network control into software creating software-defined networks (SDN). Augmenting an existing network with these enhancements can be expensive and complex. This research investigates solutions to these problems. It is hypothesized that an add-on device, or "shim" could be used to make a traditional switch behave as an OpenFlow SDN switch while maintaining reasonable performance. A design prototype is found to cause approximately 1.5% reduction in throughput for one ow and less than double increase in latency, …


An Analysis Of Multi-Domain Command And Control And The Development Of Software Solutions Through Devops Toolsets And Practices, Mason R. Bruza Mar 2018

An Analysis Of Multi-Domain Command And Control And The Development Of Software Solutions Through Devops Toolsets And Practices, Mason R. Bruza

Theses and Dissertations

Multi-Domain Command and Control (MDC2) is the exercise of command and control over forces in multiple operational domains (namely air, land, sea, space, and cyberspace) in order to produce synergistic effects in the battlespace, and enhancing this capability has become a major focus area for the United States Air Force (USAF). In order to meet demands for MDC2 software, solutions need to be acquired and/or developed in a timely manner, information technology infrastructure needs to be adaptable to new software requirements, and user feedback needs to drive iterative updates to fielded software. In commercial organizations, agile software development methodologies and …


Quality Of Service Impacts Of A Moving Target Defense With Software-Defined Networking, Samuel A. Mayer Mar 2018

Quality Of Service Impacts Of A Moving Target Defense With Software-Defined Networking, Samuel A. Mayer

Theses and Dissertations

An analysis of the impact a defensive network technique implemented with software-defined networking has upon quality of service experienced by legitimate users. The research validates previous work conducted at AFIT to verify claims of defensive efficacy and then tests network protocols in common use (FTP, HTTP, IMAP, POP, RTP, SMTP, and SSH) on a network that uses this technique. Metrics that indicate the performance of the protocols under test are reported with respect to data gathered in a control network. The conclusions of these experiments enable network engineers to determine if this defensive technique is appropriate for the quality of …


A Tree Locality-Sensitive Hash For Secure Software Testing, Camdon J. Cady Sep 2017

A Tree Locality-Sensitive Hash For Secure Software Testing, Camdon J. Cady

Theses and Dissertations

Bugs in software that make it through testing can cost tens of millions of dollars each year, and in some cases can even result in the loss of human life. In order to eliminate bugs, developers may use symbolic execution to search through possible program states looking for anomalous states. Most of the computational effort to search through these states is spent solving path constraints in order to determine the feasibility of entering each state. State merging can make this search more efficient by combining program states, allowing multiple execution paths to be analyzed at the same time. However, a …


Automated Software Testing In The Dod: Current Practices And Opportunities For Improvement, Darryl K. Ahner, James Wisnowski, James R. Simpson Sep 2017

Automated Software Testing In The Dod: Current Practices And Opportunities For Improvement, Darryl K. Ahner, James Wisnowski, James R. Simpson

Faculty Publications

The concept of automating the testing of software-intensive systems has been around for decades, but the practice of automating testing is scarce in many industries, especially in the government defense sector. A one-year project initiated by the Office of the Secretary of Defense (OSD), Scientific Test and Analysis Techniques Center of Excellence (STAT COE) and sponsored by Navy OPNAV N94 set out to:

  • study the degree to which the Department of Defense (DoD) has adopted automated software testing (AST);
  • share the best software practices used by industry; and
  • develop and distribute an AST implementation guide intended for program management and …


Analysis Of Software Design Patterns In Human Cognitive Performance Experiments, Alexander C. Roosma Mar 2016

Analysis Of Software Design Patterns In Human Cognitive Performance Experiments, Alexander C. Roosma

Theses and Dissertations

As Air Force operations continue to move toward the use of more autonomous systems and more human-machine teaming in general, there is a corresponding need to swiftly evaluate systems with these capabilities. We support this development through software design improvements of the execution of human cognitive performance experiments. This thesis sought to answer the following two research questions addressing the core functionality that these experiments rely on for execution and analysis: 1) What data infrastructure software requirements are necessary to execute the experimental design of human cognitive performance experiments? 2) How effectively does a central data mediator design pattern meet …


Using Software-Based Decision Procedures To Control Instruction-Level Execution, William B. Kimball Dec 2013

Using Software-Based Decision Procedures To Control Instruction-Level Execution, William B. Kimball

AFIT Patents

An apparatus, method and program product are provided for securing a computer system. A digital signature of an application is checked, which is loaded into a memory of the computer system configured to contain memory pages. In response to finding a valid digital signature, memory pages containing instructions of the application are set as executable and memory pages other than those containing instructions of the application are set as non-executable. Instructions in executable memory pages are executed. Instructions in non-executable memory pages are prevented from being executed. A page fault is generated in response to an attempt to execute an …


Emulation-Based Software Protection, William B. Kimball, Rusty O. Baldwin Oct 2012

Emulation-Based Software Protection, William B. Kimball, Rusty O. Baldwin

AFIT Patents

A method of emulation-based page granularity code signing comprising the steps of: copying guest operating system instructions and associated hash message authentication codes and/or digital signatures of each guest operating instruction from an untrusted guest operating system memory into a trusted host operating system memory; recomputing the hash message authentication codes using a secret key in the trusted host operating system memory; maintaining the secret key in the trusted host operating system memory and inaccessible by the untrusted guest operating system instructions; translating each guest operating system instruction that has a valid hash message authentication code to a set of …