Skip to main content
QUICK REVIEW

[论文解读] Source Data for the Focus Area Maturity Model for API Management

Max Mathijssen, Michiel Overeem|arXiv (Cornell University)|Jul 21, 2020
Software Engineering Research参考文献 3被引用 5
一句话总结

本文提出了应用 Application Programming Interface(API)管理焦点领域成熟度模型(API-m-FAMM),这是一个通过系统文献综述、专家访谈和案例研究开发的结构化框架,包含六个焦点领域中的81项实践和20项能力。该模型使组织能够从1级到10级评估、改进并基准化其API管理成熟度,所有实践均经过标准化以确保清晰性和可实施性。

ABSTRACT

We define API Management as an activity that enables organizations to design, publish and deploy their APIs for (external) developers to consume. API Management capabilities such as controlling API lifecycles, access and authentication to APIs, monitoring, throttling and analyzing API usage, as well as providing security and documentation. These capabilities are often implemented through an integrated platform. This data set describes the API Management Focus Area Maturity Model (API-m-FAMM). In a structured manner, this model aims to support organizations that expose their API(s) to third-party developers in their API management activities. Through a thorough Systematic Literature Review (SLR), 114 practices and 39 capabilities were collected. Subsequently, these practices and capabilities were categorized into 6 focus areas. Next, the practices and capabilities were analyzed and verified through inter-rater agreement and four validation sessions with all involved researchers. Then, the collection of practices and capabilities was verified by using information gathered from supplemental literature, online blog posts, websites, commercial API management platform documentation and third-party tooling. As a result, the initial body of practices and capabilities was narrowed down to 87 practices and 23 capabilities. These practices are described by a practice code, name, description, conditions for implementation, the role responsible for the practice, and the associated literature in which the practice was originally identified. Capabilities and focus areas are described by a code, description and, optionally, the associated literature in which it was originally identified. Using the API-m-FAMM, organizations may evaluate, improve upon and assess the degree of maturity their business processes regarding the topic of API management have.

研究动机与目标

  • 开发一个全面且基于实证的API管理成熟度模型,以指导组织改进其API实践。
  • 识别并验证与第三方API发布和管理相关的可操作、可实施的实践和能力。
  • 通过标准化、基于证据的框架,支持从业者和研究人员评估和基准化API管理成熟度。
  • 通过专家验证、案例研究和使用结构化反馈循环进行迭代优化,确保模型的有效性和实际相关性。

提出的方法

  • 开展系统文献综述(SLR),从学术文献和灰色文献中识别API管理的基础实践和能力。
  • 进行11次半结构化专家访谈,基于实践相关性和可用性,验证并优化初步的实践和能力集合。
  • 通过研究人员和从业者之间的迭代讨论会议,就实践分类、描述和成熟度等级分配达成共识。
  • 使用Google Drawings的卡片排序技术,对模型各组成部分在不同焦点领域和成熟度等级之间的结构进行整理和重组。
  • 通过五个商业软件产品的案例研究评估该模型,以测试其在现实世界中的适用性并识别实施差距。
  • 通过去除模糊的实践、更新描述以提高清晰度,并统一术语的句法结构(例如,动词-名词格式),对最终模型(v1.0)进行优化。

实验结果

研究问题

  • RQ1在向外部开发者公开API的组织中,哪些关键实践和能力定义了有效的API管理?
  • RQ2如何通过结合系统文献综述、专家访谈和案例研究的混合方法研究,系统地开发和验证API管理成熟度模型?
  • RQ3专家从业者在多大程度上就API管理实践的相关性和成熟度等级分配达成一致?
  • RQ4如何通过迭代优化确保模型的实际可用性,并与现实世界中的实施挑战保持一致?

主要发现

  • 最终的API-m-FAMM包含81项经验证的实践和20项能力,按六个焦点领域组织,每项实践均被分配1至10级的成熟度等级。
  • 通过专家反馈对模型进行了优化,因与现有实践(如“实施传输层加密”)存在冗余,移除了“防止敏感数据暴露”这一实践。
  • “执行请求频率限制”这一实践得到增强,增加了错误率限制,以反映生产系统中观察到的实际实现模式。
  • “监控资源使用情况”的描述得到扩展,增加了非度量近似值,提升了清晰度和实际适用性。
  • “实施预测性扩展”的描述已更新,排除了手动实现,以符合行业对自动化的期望。
  • 通过六个软件产品的案例研究对最终模型进行了验证,确认了其实际相关性,并识别出对描述和范围的可操作优化建议。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。