-
2
-
-
46749114635
-
Practical experiences of safety- and security-critical technologies
-
Mar
-
P. Amey and A. J. Hilton. Practical experiences of safety- and security-critical technologies. Ada User Journal, 22(1), Mar. 2001.
-
(2001)
Ada User Journal
, vol.22
, Issue.1
-
-
Amey, P.1
Hilton, A.J.2
-
4
-
-
85178855091
-
In-flight upset event, 240 km north-west of Perth, WA, Boeing Company 777-200, 9M-MRG
-
Australian Transport Safety Bureau, 1 August, Mar, available at
-
Australian Transport Safety Bureau. In-flight upset event, 240 km north-west of Perth, WA, Boeing Company 777-200, 9M-MRG, 1 August 2005, Mar. 2007. Reference number Mar2007/DOTARS 50165, available at http://www.atsb.gov. au/publications/investigation.reports/2005/AAIR/aair200503722.aspx.
-
(2005)
Reference number Mar2007/DOTARS
, pp. 50165
-
-
-
5
-
-
1542300205
-
Multi-legged arguments: The impact of diversity upon confidence in dependability arguments
-
San Francisco, CA, June, IEEE Computer Society
-
R. Bloomfield and B. Littlewood. Multi-legged arguments: The impact of diversity upon confidence in dependability arguments. In The International Conference on Dependable Systems and Networks, pages 25-34, San Francisco, CA, June 2003. IEEE Computer Society.
-
(2003)
The International Conference on Dependable Systems and Networks
, pp. 25-34
-
-
Bloomfield, R.1
Littlewood, B.2
-
6
-
-
85178869145
-
-
M. Bozzano and A. Villafiorita. Improving system reliability via model checking: The FSAP/NuSMV-SA safety analysis platform. In S. Anderson, M. Felici, and B. Littlewood, editors, SAFECOMP 2003: Proceedings of the 22nd International Conference on Computer Safety, Reliability, and Security, number 2788 in Lecture Notes in Computer Science, pages 49-62, Edinburgh, Scotland, Sept. 2003. Springer-Verlag.
-
M. Bozzano and A. Villafiorita. Improving system reliability via model checking: The FSAP/NuSMV-SA safety analysis platform. In S. Anderson, M. Felici, and B. Littlewood, editors, SAFECOMP 2003: Proceedings of the 22nd International Conference on Computer Safety, Reliability, and Security, number 2788 in Lecture Notes in Computer Science, pages 49-62, Edinburgh, Scotland, Sept. 2003. Springer-Verlag.
-
-
-
-
8
-
-
85178865307
-
-
Common Criteria for Information Technology Security Evaluation, Jan. 2004. Version 2.2, CCIMB-2004-01-001, 002, 003
-
Common Criteria for Information Technology Security Evaluation, Jan. 2004. Version 2.2, CCIMB-2004-01-001, 002, 003.
-
-
-
-
9
-
-
38349033566
-
-
PhD thesis, Department of Computer Science, University of York, York, UK
-
P. Conmy. Safety Analysis of Computer Resource Management Software. PhD thesis, Department of Computer Science, University of York, York, UK, 2005.
-
(2005)
Safety Analysis of Computer Resource Management Software
-
-
Conmy, P.1
-
11
-
-
85178857880
-
-
and, editors, Bad Malente, Germany, Sept, Springer-Verlag
-
W.-P. de Roever, H. Langmaack, and A. Pnueli, editors. Compositionality: The Significant Difference (Revised lectures from International Symposium COMPOS'97), volume 1536 of Lecture Notes in Computer Science, Bad Malente, Germany, Sept. 1997. Springer-Verlag.
-
(1997)
Compositionality: The Significant Difference (Revised lectures from International Symposium COMPOS'97), volume 1536 of Lecture Notes in Computer Science
-
-
-
12
-
-
0020226119
-
Using branching time temporal logic to synthesize synchronization skeletons
-
E. A. Emerson and E. M. Clarke. Using branching time temporal logic to synthesize synchronization skeletons. Science of Computer Programming, 2:241-266, 1982.
-
(1982)
Science of Computer Programming
, vol.2
, pp. 241-266
-
-
Emerson, E.A.1
Clarke, E.M.2
-
13
-
-
85178866778
-
-
Federal Aviation Administration. System Design and Analysis, June 21, 1988. Advisory Circular 25.1309-1A.
-
Federal Aviation Administration. System Design and Analysis, June 21, 1988. Advisory Circular 25.1309-1A.
-
-
-
-
14
-
-
85178863752
-
-
Federal Aviation Administration, June 1998. Available at
-
Federal Aviation Administration. Order 8040.4: Safety Risk Management, June 1998. Available at http://www.faa.gov/library/manuals/ aviation/risk_management/ss_handbook/media/app.g_1200.PDF.
-
Order 8040.4: Safety Risk Management
-
-
-
15
-
-
85178865313
-
Reusable Software Components
-
Federal Aviation Administration, Dec. 7
-
Federal Aviation Administration. Reusable Software Components, Dec. 7, 2004. Advisory Circular 20-148.
-
(2004)
Advisory Circular
, pp. 20-148
-
-
-
16
-
-
0004578098
-
The jury observation fallacy and the use of Bayesian networks to present probabilistic legal arguments
-
June, Available at
-
N. Fenton and M. Neil. The jury observation fallacy and the use of Bayesian networks to present probabilistic legal arguments. Mathematics Today (Bulletin of the IMA), 36(6):180-187, June 2000. Available at http://www.dcs.qmul.ac.uk/~norman/papers/jury.fallacy.pdf.
-
(2000)
Mathematics Today (Bulletin of the IMA)
, vol.36
, Issue.6
, pp. 180-187
-
-
Fenton, N.1
Neil, M.2
-
17
-
-
14344264412
-
Assume-guarantee reasoning for hybrid I/O-automata by over-approximation of continuous interaction
-
Atlantic, Bahamas, Dec
-
G. Frehse, Z. Han, and B. Krogh. Assume-guarantee reasoning for hybrid I/O-automata by over-approximation of continuous interaction. In 43rd IEEE Conference on Decision and Control (CDC 2004), volume 1, pages 479-484, Atlantic, Bahamas, Dec. 2004.
-
(2004)
43rd IEEE Conference on Decision and Control (CDC 2004)
, vol.1
, pp. 479-484
-
-
Frehse, G.1
Han, Z.2
Krogh, B.3
-
18
-
-
33746233219
-
Proof vs. testing in the context of safety standards
-
Washington, DC, Oct
-
A. Galloway, R. F. Paige, N. J. Tudor, R. A. Weaver, I. Toyn, and J. McDermid. Proof vs. testing in the context of safety standards. In 24th AIAA/IEEE Digital Avionics Systems Conference, volume 2, Washington, DC, Oct. 2005.
-
(2005)
24th AIAA/IEEE Digital Avionics Systems Conference
, vol.2
-
-
Galloway, A.1
Paige, R.F.2
Tudor, N.J.3
Weaver, R.A.4
Toyn, I.5
McDermid, J.6
-
19
-
-
33845258410
-
Software static code analysis lessons learned
-
Nov. 2003. Available at
-
A. German. Software static code analysis lessons learned. Crosstalk, Nov. 2003. Available at http://www.stsc.hill.af.mil/crosstalk/ 2003/11/0311German.html.
-
Crosstalk
-
-
German, A.1
-
21
-
-
34547150779
-
Synergy: A new algorithm for property checking
-
Portland, OR, Nov, ACM Press
-
B. S. Gulavani, T. A. Henzinger, Y. Kannan, A. V. Nori, and S. K. Rajamani. Synergy: A new algorithm for property checking. In Proceedings of the 14th Annual Symposium on Foundations of Software Engineering (FSE), pages 117-127, Portland, OR, Nov. 2006. ACM Press.
-
(2006)
Proceedings of the 14th Annual Symposium on Foundations of Software Engineering (FSE)
, pp. 117-127
-
-
Gulavani, B.S.1
Henzinger, T.A.2
Kannan, Y.3
Nori, A.V.4
Rajamani, S.K.5
-
22
-
-
16244387957
-
Generating efficient test sets with a model checker
-
Beijing, China, Sept, IEEE Computer Society
-
G. Hamon, L. de Moura, and J. Rushby. Generating efficient test sets with a model checker. In 2nd International Conference on Software Engineering and Formal Methods (SEFM), pages 261-270, Beijing, China, Sept. 2004. IEEE Computer Society.
-
(2004)
2nd International Conference on Software Engineering and Formal Methods (SEFM)
, pp. 261-270
-
-
Hamon, G.1
de Moura, L.2
Rushby, J.3
-
23
-
-
0006562330
-
A practical tutorial on modified condition/decision coverage
-
NASA Langley Research Center, Hampton, VA, May 2001. Available at
-
K. J. Hayhurst, D. S. Veerhusen, J. J. Chilenski, and L. K. Rierson. A practical tutorial on modified condition/decision coverage. NASA Technical Memorandum TM-2001-210876, NASA Langley Research Center, Hampton, VA, May 2001. Available at http://www.faa.gov/certification/aircraft/av-info/software/ Research/MCDC%20Tutorial.pdf.
-
NASA Technical Memorandum TM-2001-210876
-
-
Hayhurst, K.J.1
Veerhusen, D.S.2
Chilenski, J.J.3
Rierson, L.K.4
-
25
-
-
33745366421
-
-
E. Hollnagel, D. D. Woods, and N. Leveson, editors, Ashgate
-
E. Hollnagel, D. D. Woods, and N. Leveson, editors. Resilience Engineering. Ashgate, 2005.
-
(2005)
Resilience Engineering
-
-
-
26
-
-
85178851131
-
-
Information Assurance Directorate, National Security Agency, Fort George G. Meade, MD 20755-6000. U.S. Government Protection Profile for Separation Kernels in Environments Requiring High Robustness, July 2004. Version 0.621
-
Information Assurance Directorate, National Security Agency, Fort George G. Meade, MD 20755-6000. U.S. Government Protection Profile for Separation Kernels in Environments Requiring High Robustness, July 2004. Version 0.621.
-
-
-
-
29
-
-
33746265011
-
A proposal for model-based safety analysis
-
Washington, DC, Oct
-
A. Joshi, S. Miller, M. Whalen, and M. Heimdahl. A proposal for model-based safety analysis. In 24th AIAA/IEEE Digital Avionics Systems Conference, volume 2, Washington, DC, Oct. 2005.
-
(2005)
24th AIAA/IEEE Digital Avionics Systems Conference
, vol.2
-
-
Joshi, A.1
Miller, S.2
Whalen, M.3
Heimdahl, M.4
-
30
-
-
0022582303
-
An empirical study of failure probabilities in multi-version software
-
Vienna, Austria, July, IEEE Computer Society
-
J. C. Knight and N. G. Leveson. An empirical study of failure probabilities in multi-version software. In Fault Tolerant Computing Symposium 16, pages 165-170, Vienna, Austria, July 1986. IEEE Computer Society.
-
(1986)
Fault Tolerant Computing Symposium
, vol.16
, pp. 165-170
-
-
Knight, J.C.1
Leveson, N.G.2
-
31
-
-
1342344540
-
A new accident model for engineering safer systems
-
Apr
-
N. Leveson. A new accident model for engineering safer systems. Safety Science, 42(4):237-270, Apr. 2004.
-
(2004)
Safety Science
, vol.42
, Issue.4
, pp. 237-270
-
-
Leveson, N.1
-
32
-
-
0034292031
-
The use of proof in diversity arguments
-
Oct
-
B. Littlewood. The use of proof in diversity arguments. IEEE Transactions on Software Engineering, 26(10):1022-1023, Oct. 2000.
-
(2000)
IEEE Transactions on Software Engineering
, vol.26
, Issue.10
, pp. 1022-1023
-
-
Littlewood, B.1
-
33
-
-
34247587082
-
The use of multi-legged arguments to increase confidence in safety claims for software-based systems: A study based on a BBN analysis of an idealised example
-
May
-
B. Littlewood and D. Wright. The use of multi-legged arguments to increase confidence in safety claims for software-based systems: a study based on a BBN analysis of an idealised example. IEEE Transactions on Software Engineering, 33(5):347-365, May 2007.
-
(2007)
IEEE Transactions on Software Engineering
, vol.33
, Issue.5
, pp. 347-365
-
-
Littlewood, B.1
Wright, D.2
-
35
-
-
0033100636
-
Controllers for reachability specifications for hybrid systems
-
March
-
J. Lygeros, C. Tomlin, and S. Sastry. Controllers for reachability specifications for hybrid systems. Automatica, 35(3), March 1999.
-
(1999)
Automatica
, vol.35
, Issue.3
-
-
Lygeros, J.1
Tomlin, C.2
Sastry, S.3
-
36
-
-
84976828744
-
Synthesis of communicating processes from temporal logic specifications
-
Z. Manna and P. Wolper. Synthesis of communicating processes from temporal logic specifications. ACM Trans. Program. Lang. Syst., 6(1):68-93, 1984.
-
(1984)
ACM Trans. Program. Lang. Syst
, vol.6
, Issue.1
, pp. 68-93
-
-
Manna, Z.1
Wolper, P.2
-
37
-
-
84976743475
-
Tolerating failures of continuous-valued sensors
-
Nov
-
K. Marzullo. Tolerating failures of continuous-valued sensors. ACM Trans. Comput. Syst., 8(4):284-304, Nov. 1990.
-
(1990)
ACM Trans. Comput. Syst
, vol.8
, Issue.4
, pp. 284-304
-
-
Marzullo, K.1
-
38
-
-
35248843137
-
Proving the shalls
-
K. Araki, S. Gnesi, and D. Mandrioli, editors, International Symposium of Formal Methods Europe, FME 2003, of, Pisa, Italy, Mar, Springer-Verlag
-
S. P. Miller, A. C. Tribble, and M. P. E. Heimdahl. Proving the shalls. In K. Araki, S. Gnesi, and D. Mandrioli, editors, International Symposium of Formal Methods Europe, FME 2003, volume 2805 of Lecture Notes in Computer Science, pages 75-93, Pisa, Italy, Mar. 2001. Springer-Verlag.
-
(2001)
Lecture Notes in Computer Science
, vol.2805
, pp. 75-93
-
-
Miller, S.P.1
Tribble, A.C.2
Heimdahl, M.P.E.3
-
39
-
-
24944447883
-
Formal safety analysis of a radio-based railroad crossing using deductive causeconsequence analysis (DCCA)
-
5th European Dependable Computing Conference EDDC, number in, Budapest, Hungary, Springer-Verlag
-
F. Ortmeier, W. Reif, and G. Schellhorn. Formal safety analysis of a radio-based railroad crossing using deductive causeconsequence analysis (DCCA). In 5th European Dependable Computing Conference (EDDC), number 3463 in Lecture Notes in Computer Science, pages 210-224, Budapest, Hungary, 2005. Springer-Verlag.
-
(2005)
Lecture Notes in Computer Science
, vol.3463
, pp. 210-224
-
-
Ortmeier, F.1
Reif, W.2
Schellhorn, G.3
-
42
-
-
0024864157
-
On the synthesis of a reactive module
-
New York, NY, USA, ACM Press
-
A. Pnueli and R. Rosner. On the synthesis of a reactive module. In POPL '89: Proceedings of the 16th ACM SIGPLAN-SIGACT symposium on Principles of programming languages, pages 179-190, New York, NY, USA, 1989. ACM Press.
-
(1989)
POPL '89: Proceedings of the 16th ACM SIGPLAN-SIGACT symposium on Principles of programming languages
, pp. 179-190
-
-
Pnueli, A.1
Rosner, R.2
-
43
-
-
0024479313
-
The control of discrete event systems
-
Jan
-
P. J. G. Ramadge and W. M. Wonham. The control of discrete event systems. Proceedings of the IEEE, 77(1):81-98, Jan. 1989.
-
(1989)
Proceedings of the IEEE
, vol.77
, Issue.1
, pp. 81-98
-
-
Ramadge, P.J.G.1
Wonham, W.M.2
-
44
-
-
85178867118
-
-
Requirements and Technical Concepts for Aviation, Washington, DC. DO-178B: Software Considerations in Airborne Systems and Equipment Certification, Dec. 1992. This document is known as EUROCAE ED-12B in Europe.
-
Requirements and Technical Concepts for Aviation, Washington, DC. DO-178B: Software Considerations in Airborne Systems and Equipment Certification, Dec. 1992. This document is known as EUROCAE ED-12B in Europe.
-
-
-
-
45
-
-
85178865841
-
-
Requirements and Technical Concepts for Aviation, Washington, DC. DO-297: Integrated Modular Avionics (IMA) Development Guidance and Certification Considerations, Nov. 2005.
-
Requirements and Technical Concepts for Aviation, Washington, DC. DO-297: Integrated Modular Avionics (IMA) Development Guidance and Certification Considerations, Nov. 2005.
-
-
-
-
46
-
-
0028257391
-
Critical system properties: Survey and taxonomy
-
J. Rushby. Critical system properties: Survey and taxonomy. Reliability Engineering and System Safety, 43(2):189-219, 1994.
-
(1994)
Reliability Engineering and System Safety
, vol.43
, Issue.2
, pp. 189-219
-
-
Rushby, J.1
-
47
-
-
0003894467
-
Partitioning for avionics architectures: Requirements, mechanisms, and assurance
-
CR-1999-209347, NASA Langley Research Center, June, Available at, also issued by the FAA
-
J. Rushby. Partitioning for avionics architectures: Requirements, mechanisms, and assurance. NASA Contractor Report CR-1999-209347, NASA Langley Research Center, June 1999. Available at http://techreports.larc.nasa.gov/ltrs/ PDF/1999/cr/NASA-99-cr209347.pdf; also issued by the FAA.
-
(1999)
NASA Contractor Report
-
-
Rushby, J.1
-
48
-
-
84947287460
-
Bus architectures for safety-critical embedded systems
-
T. Henzinger and C. Kirsch, editors, EMSOFT 2001: Proceedings of the First Workshop on Embedded Software, of, Lake Tahoe, CA, Oct, Springer-Verlag
-
J. Rushby. Bus architectures for safety-critical embedded systems. In T. Henzinger and C. Kirsch, editors, EMSOFT 2001: Proceedings of the First Workshop on Embedded Software, volume 2211 of Lecture Notes in Computer Science, pages 306-323, Lake Tahoe, CA, Oct. 2001. Springer-Verlag.
-
(2001)
Lecture Notes in Computer Science
, vol.2211
, pp. 306-323
-
-
Rushby, J.1
-
49
-
-
85178858181
-
-
J. Rushby. Modular certification. NASA Contractor Report CR-2002-212130, NASA Langley Research Center, Dec. 2002. Available at http://techreports.larc. nasa.gov/Itrs/ PDF/2002/cr/NASA-2002-cr212130.pdf.
-
J. Rushby. Modular certification. NASA Contractor Report CR-2002-212130, NASA Langley Research Center, Dec. 2002. Available at http://techreports.larc. nasa.gov/Itrs/ PDF/2002/cr/NASA-2002-cr212130.pdf.
-
-
-
-
50
-
-
84974693449
-
An overview of formal verification for the time-triggered architecture
-
W. Damm and E.-R. Olderog, editors, Formal Techniques in Real-Time and Fault-Tolerant Systems, of, Oldenburg, Germany, Sept, Springer-Verlag
-
J. Rushby. An overview of formal verification for the time-triggered architecture. In W. Damm and E.-R. Olderog, editors, Formal Techniques in Real-Time and Fault-Tolerant Systems, volume 2469 of Lecture Notes in Computer Science, pages 83-105, Oldenburg, Germany, Sept. 2002. Springer-Verlag.
-
(2002)
Lecture Notes in Computer Science
, vol.2469
, pp. 83-105
-
-
Rushby, J.1
-
51
-
-
0036466927
-
Using model checking to help discover mode confusions and other automation surprises
-
Feb
-
J. Rushby. Using model checking to help discover mode confusions and other automation surprises. Reliability Engineering and System Safety, 75(2):167-177, Feb. 2002.
-
(2002)
Reliability Engineering and System Safety
, vol.75
, Issue.2
, pp. 167-177
-
-
Rushby, J.1
-
52
-
-
34547229860
-
Harnessing disruptive innovation in formal verification
-
D. V. Hung and P. Pandya, editors, Pune, India, Sept, IEEE Computer Society
-
J. Rushby. Harnessing disruptive innovation in formal verification. In D. V. Hung and P. Pandya, editors, Fourth International Conference on Software Engineering and Formal Methods (SEFM), pages 21-28, Pune, India, Sept. 2006. IEEE Computer Society.
-
(2006)
Fourth International Conference on Software Engineering and Formal Methods (SEFM)
, pp. 21-28
-
-
Rushby, J.1
-
53
-
-
85178851819
-
-
J. Rushby and R. DeLong. Toward an Integration Protection Profile for MILS. Computer Science Laboratory, SRI International, Menlo Park, CA, 2007. To appear.
-
J. Rushby and R. DeLong. Toward an Integration Protection Profile for MILS. Computer Science Laboratory, SRI International, Menlo Park, CA, 2007. To appear.
-
-
-
-
54
-
-
0035299765
-
How to reconcile faulttolerant interval intersection with the Lipschitz condition
-
May
-
U. Schmid and K. Schossmaier. How to reconcile faulttolerant interval intersection with the Lipschitz condition. Distributed Computing, 14(2):101-111, May 2001.
-
(2001)
Distributed Computing
, vol.14
, Issue.2
, pp. 101-111
-
-
Schmid, U.1
Schossmaier, K.2
-
55
-
-
46749114227
-
Abstractions for hybrid systems
-
To appear, available at
-
A. Tiwari. Abstractions for hybrid systems. Formal Methods in Systems Design, 2007. To appear, available at http://www.csl.sri.com/~tiwari/new. pdf.
-
(2007)
Formal Methods in Systems Design
-
-
Tiwari, A.1
-
57
-
-
85178852251
-
-
UK Air Investigations Branch. AAIB Special Bulletin S1/2005: Airbus A340-642, G-VATL, 2005. Available at http://www.aaib.dft.gov.uk/ cms_resources/G-VATL_Special_Bulletinl.pdf.
-
UK Air Investigations Branch. AAIB Special Bulletin S1/2005: Airbus A340-642, G-VATL, 2005. Available at http://www.aaib.dft.gov.uk/ cms_resources/G-VATL_Special_Bulletinl.pdf.
-
-
-
|